Legal
Subprocessors and third parties.
Who processes your data on our behalf, and (the part unique to this product) what the third-party tool provider your agent calls actually receives.
01
Why this page exists
Omnial MCP is a reseller. When your agent calls a tool, the input for that call is sent to the third-party company that operates it; that is what executing the call means, not an incidental data share. GDPR Article 28 requires us to disclose who processes personal data on our behalf, and honesty requires the same thing for a service whose entire product is routing your calls to someone else's API.
Two kinds of third party receive data here, and they are listed separately because they are different in kind: the infrastructure that keeps the product running, and the provider your agent specifically chose to call.
02
The infrastructure providers
Each of these receives only what its job requires, and none of them is a party you chose; they run the product for every customer, the same way.
Stripe
- Role
- Payment processing
- What it receives
- Card details (held by Stripe, never by us), billing name and country, and your payment history.
Hetzner
- Role
- Server hosting (the API, the worker, the database)
- What it receives
- Everything the service stores while it runs: your account, run history, ledger, and API keys live on infrastructure this provider hosts for us.
Vercel
- Role
- Marketing-site hosting
- What it receives
- Standard request data such as IP address and browser type, for the public pages of this site. This deployment holds no database and no account data of its own.
Brevo
- Role
- Transactional email
- What it receives
- The email address a sign-in link, a billing notice, or a reply from us is sent to, and the message itself.
| Provider | Role | What it receives |
|---|---|---|
| Stripe | Payment processing | Card details (held by Stripe, never by us), billing name and country, and your payment history. |
| Hetzner | Server hosting (the API, the worker, the database) | Everything the service stores while it runs: your account, run history, ledger, and API keys live on infrastructure this provider hosts for us. |
| Vercel | Marketing-site hosting | Standard request data such as IP address and browser type, for the public pages of this site. This deployment holds no database and no account data of its own. |
| Brevo | Transactional email | The email address a sign-in link, a billing notice, or a reply from us is sent to, and the message itself. |
Where these actually run is not uniform. Hetzner Online GmbH is a German company, and the production server that stores your account, run history, ledger and API keys is confirmed running in Hetzner's Nuremberg, Germany datacenter; that data lives in the EU, not the US, regardless of where you are. Brevo (formerly Sendinblue) is a French company. Stripe and Vercel are both US companies, and the services listed above (card processing and this site's public marketing pages) run on their US infrastructure.
We have not independently verified every region a provider might further mirror or process data in beyond what is confirmed above: a payment sub-region, a CDN edge, and so on. If you need that confirmed for a specific provider, ask using the contact below.
03
The tool provider your agent calls
This is the row that is genuinely different from a normal SaaS subprocessor list, and it is structured to stay true as the catalog grows rather than to be rewritten on the day it does:
Whichever third-party company operates the tool your agent called receives the input for that specific call: the parameters your agent sent, nothing about your account beyond what is needed to route and bill the call, and no other run's data. That provider's own privacy practices govern what happens to it on their side; each tool's usage doc is where that provider's own handling should be disclosed, and the terms of service already states that we do not audit or guarantee a provider's own conduct.
Naming a provider here is a separate fact from whether it is synthetic: most are — an invented vendor on a reserved test host that resolves to nothing — but two are not. Our first provider integration is a genuine vendor account, and we ran a small number of real, paid calls to it ourselves during integration and certification, the verification step every real provider passes through before it is ever opened to customer use. Echoco is not a vendor account at all: it is an internal fixture that calls a free public test endpoint solely to prove the pipeline end to end, and nothing about it is for sale. See the data sources and rights notice for what that processing can include. This page describes the mechanism honestly rather than waiting for it to matter: this is the row that applies to any real provider, whether or not it has yet been promoted to live, with no rewrite needed either way.
Unlike the infrastructure providers above, whose primary country of incorporation is confirmed above, country of operation for a tool provider varies: for the first-launch category of tools that source data from a third party rather than from you, that provider is incorporated in Delaware, United States, confirmed against its own public privacy policy, which also discloses separately appointed EU and UK data-protection representatives for that provider — context about that provider's own compliance posture, not a safeguard for our own use of it on your behalf. As noted above, we have not independently verified every region an infrastructure provider might further process data in beyond its primary country either, so this is about primary country of operation specifically, not about residency or processing more broadly. See the data sources and rights notice for the fuller version of this disclosure.
- We do not send a provider anything about you beyond what routing and billing that call requires.
- A provider only ever sees the input for calls made to it: never your workspace balance, your other runs, or any other provider's traffic.
- Fields that look like a credential or a secret are redacted from what we store about the call before it is written to your run history, and are never forwarded to a provider unless they are the actual parameter that call requires.
04
Keeping this list honest
If we add, remove, or change what an infrastructure provider above receives, we will update this page. A subprocessor list that goes stale the day a vendor changes is worse than no list at all, and we treat it accordingly.
Questions about a specific provider or a specific call go to pixellabsweb3@gmail.com. See also the privacy policy, the terms of service, and the data sources and rights notice.
