Legal · Privacy
Privacy Policy
Current policy effective: 15 April 2026 · Resend contact-directory update and owner-directed activation: 27 August 2026
This Privacy Policy describes how Automatika Consulting (“Automatika”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal information when you visit or use our services. It applies to the marketing website at automatika.ph, the client portal at app.automatika.ph, Discovery at discovery.automatika.ph/quote, and the documentation site at docs.automatika.ph, the X24H Outbound™ and X24H Extreme™ Chrome extensions, and their supporting Automatika ActionSuite services at actionsuite.automatika.ph.
We comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and reflect rights modelled after the EU General Data Protection Regulation (GDPR) for visitors from those jurisdictions.
ActionSuite Resend update: By owner decision on 27 August 2026, we activated the minimum ActionSuite Resend Contact directory for reconciliation, suppression integrity, and prevention of duplicate or unwanted delivery. This directory is consent-neutral: its existence and a FREE or PRO tier do not subscribe an account to marketing. Optional marketing still requires a current explicit opt-in.
1. Who we are
- Legal name: Automatika Consulting
- Business ID: 7947755 (New Mexico, United States)
- Headquarters: 1209 Mountain Road PL NE, Albuquerque, New Mexico 87110, USA
- Remote coverage: Australia, Philippines, Singapore
- Phone: +1 (575) 733-8001
- Privacy contact: — this address also serves as our Data Protection Officer (DPO) contact.
2. What personal data we collect
We collect only the data described below. We do not buy, sell, or trade personal data.
2.1 From visitors to automatika.ph (marketing site)
- Server access logs: IP address, browser user-agent, referring URL, requested URL, timestamp. Collected automatically by our hosting provider (Vercel) for security, abuse detection, and operational diagnostics.
- No forms or visitor accounts on the marketing site. Contact and Discovery requests are handled through the separate services described below.
- Meta Pixel analytics and conversion measurement: the marketing site loads Meta Pixel and sends a PageView event plus selected interaction events such as Lead, Contact, ViewContent, Search, and InitiateCheckout. Meta may receive the event name, page URL or referrer, IP address, and browser, device, network, cookie, or similar identifiers under its own privacy terms. We use these events to measure campaign and conversion performance; we do not send form fields, account credentials, or payment details through the Pixel.
- Third-party image requests: case-study photos are served by Unsplash (images.unsplash.com) and on the /pancake-apps page we show logos served by Pancake (pancake.ph, pos.pancake.ph, crm.pancake.ph). When these images load, Unsplash and Pancake see your IP address and user-agent as the requesting browser. We do not receive data from these requests.
2.2 From Discovery (discovery.automatika.ph/quote)
- Basic contact details you submit voluntarily: full name, email address, and phone number.
- Purpose: so we can respond to your inquiry and assess whether an engagement is a fit.
2.3 From the client portal (app.automatika.ph)
The client portal is accessible only by signing in with Google (Google OAuth). When you sign in and use the portal, we collect:
- Google OAuth identity: your name, primary email address, and profile picture. We request the standard OpenID scopes openid, email, and profile. We do not request access to your Gmail, Google Calendar, Google Drive, or any other Google service.
- Business information you provide: company or brand name, your role, business phone number, and business address.
- Project data created during your engagement: engagement scope and milestones, uploaded files (briefs, brand assets, reference materials), meeting notes, written decisions, and project status.
- Billing records: invoices we issue to you, payment status, and (for online payments) transaction IDs returned by our payment processors. Card numbers, card verification values (CVV), and bank account numbers are never stored by us — those are handled directly by Stripe or PayPal (see §4).
2.4 From the X24H Outbound™ and X24H Extreme™ Chrome extensions
X24H Outbound and X24H Extreme are independent helper utilities that let Pancake CRM users configure, schedule, run, verify, and audit follow-up messaging campaigns. Depending on the product and feature used, the extensions process:
- Google sign-in and account state: Google profile name and email address, a Google authentication token during Chrome Identity sign-in, and backend session and subscription status. Backend session state is used for one-active-session enforcement; X24H Extreme also uses backend status for sending warm-up validation.
- Pancake credentials and operational data: a Pancake Access Token supplied by the user; page tokens and page metadata; and Pancake pages, tags, conversations, message metadata, customer identifiers, and visible Pancake interface state needed to target, send, verify, and audit campaigns.
- User-created content and activity: campaign rules, presets, schedules, templates, quick-reply references, page-scoped media content IDs and metadata, settings, disclaimer acceptance, local history, run status, and detailed campaign audit ledgers.
- Aggregate campaign reporting: date, total, sent, failed, status, and savings estimate. Reports sent to ActionSuite do not include message content, customer names, conversation IDs, detailed local audit ledgers, or Pancake tokens.
- Bounded product telemetry: six product-scoped event types — page view, free user, pro user, feature used, upgrade click, and lead intent — are sent to Meta Dataset 916853297780110 through locally constructed image requests to https://www.facebook.com/tr/. Event parameters are allowlisted and aggregate and do not include Google IDs, names, email addresses, phone numbers, message or template text, conversation IDs, tokens, or full page URLs. Meta receives the request and ordinary network information, such as IP address and browser user-agent, under its own terms.
Campaign setup, presets, schedules, templates, page tokens, media metadata, settings, and detailed campaign audit ledgers are stored in Chrome storage or extension-origin IndexedDB on the user's device. Google account and session data, Pancake Access Tokens, and aggregate campaign reports are transmitted over HTTPS to actionsuite.automatika.ph. Pancake Access Tokens are encrypted server-side with AES-256-GCM, are not returned raw after saving, and are never included in telemetry or aggregate campaign reports. Detailed campaign ledgers remain local unless the user explicitly exports them as JSON or CSV.
2.5 From ActionSuite email delivery and the contact directory
By owner decision on 27 August 2026, ActionSuite uses Resend for essential account and service email and a minimum contact directory. The directory may contain an account email address, name when available, an internal or pseudonymous account reference, current FREE or PRO account tier, marketing-preference or topic state, and delivery, bounce, complaint, or suppression status. We do not send Pancake tokens, payment-card details, customer conversations, or detailed campaign ledgers to this directory.
A FREE or PRO label describes product access only. It is not marketing consent, and placing an account in the provider directory does not make that account eligible for a marketing audience. Marketing email requires a separate, current explicit opt-in recorded for that purpose. Provider opt-outs, complaints, bounces, and suppression records take priority over local audience labels.
We rely on the account or service relationship to deliver essential operational email and on our legitimate interests in maintaining a minimal directory, preventing duplicate or unwanted delivery, and honoring suppression records. We limit the fields and access for those purposes and do not use this basis to enroll an account in marketing. You may object or request deletion of eligible directory data through the contact process in §8.
3. How we use your personal data
We use the data described in §2 only for the following purposes:
- Respond to your inquiry (Discovery submissions and emails to ).
- Authenticate you on the client portal via Google OAuth.
- Authenticate extension users and verify access through Google Chrome Identity and ActionSuite, including subscription checks, one-active-session enforcement, and, for X24H Extreme, server-validated sending warm-up status.
- Provide the extensions' single purpose — load the Pancake data the user selects; configure, schedule, run, pause, stop, verify, and audit campaigns; apply user-configured tag and note actions; and provide support and troubleshooting.
- Securely operate ActionSuite — validate and vault Pancake Access Tokens, maintain account and subscription state, sync aggregate campaign summaries, and deliver product services without receiving detailed local audit ledgers.
- Deliver the services you have engaged us for — track engagement milestones, store project files, record decisions.
- Process payments and issue invoices, either manually (bank transfer) or through Stripe or PayPal.
- Send operational communications related to your account or engagement (security, policy, service, billing, delivery, and handover notices). These are not marketing and are handled separately from optional marketing preferences.
- Send optional marketing communications only to recipients for whom we have recorded a current explicit opt-in, while enforcing provider opt-outs, complaints, bounces, and suppression records.
- Comply with legal and tax obligations, including the Bureau of Internal Revenue (BIR) record-keeping requirement.
- Protect our services — detect abuse, investigate suspected fraud, and secure our systems.
We do not sell personal data or use automated decision-making that produces legal or similarly significant effects. Marketing-site Meta Pixel events may be used for campaign attribution, conversion measurement, audience insights, and advertising measurement under Meta's terms and your Meta account controls. The extensions' separate Dataset events are limited to the six product-usage event types and allowlisted parameters described in §2.4.
4. Services and third parties we use
We operate ActionSuite and use providers for hosting, authentication, payments, media delivery, service delivery, and measurement as described below. We do not sell personal data. Each third-party provider processes data under its own privacy terms.
- Automatika ActionSuite — our first-party backend at actionsuite.automatika.ph receives Google account and session data for authentication and subscription access, Pancake Access Tokens for encrypted vaulting, and the aggregate campaign reports described in §2.4. It does not receive message content, customer names, conversation IDs, or detailed local audit ledgers as part of campaign reporting.
- Resend (Plus Five Five, Inc.) — beginning 27 August 2026, acts as our processor for essential ActionSuite account and service email and the minimum contact-directory data described in §2.5, including message-delivery metadata and suppression events, on our instructions. Directory presence and FREE or PRO tier do not establish marketing consent or subscribe an account. Resend's privacy policy and data processing addendum describe its privacy and processor commitments.
- Meta Platforms, Inc. — provides Meta Pixel for PageView and selected interaction-event measurement on the marketing site. Meta may set or read cookies and similar identifiers and use received Business Tools data for measurement, attribution, audience insights, and advertising functions under Meta's terms. Separately, both X24H extensions send the six bounded events described in §2.4 to Meta Dataset 916853297780110 using locally bundled image request code; they do not load Meta Pixel JavaScript or remote analytics code. X24H Extreme may also interact with Facebook or Meta pages for logged-in browser-session sending and page-access checks. Meta's privacy and cookie information: facebook.com/privacy/policy and Meta Cookies Policy.
- Google (Google LLC) — provides the Sign-in with Google identity service on app.automatika.ph and Google sign-in through Chrome Identity for both X24H extensions. The client portal requests openid, email, profile; extension Google tokens are sent over HTTPS to ActionSuite to establish an authenticated product session. Google Fonts used on our websites are self-hosted via Next.js at build time, so Google does not see your IP from font requests on automatika.ph. Booking links may point to Google Calendar when the booking calendar is open (availability notice). If you follow an active Google Calendar booking link and book, Google receives the booking information under their own terms. Google's privacy policy: policies.google.com/privacy.
- Stripe (Stripe, Inc.) — processes online card and alternative payments, including subscription checkout and billing-portal flows opened by the X24H extensions. Stripe handles card details directly; we receive only a transaction identifier and payment or subscription status. Stripe's privacy policy: stripe.com/privacy.
- PayPal (PayPal Holdings, Inc.) — processes online payments via PayPal account or card. PayPal handles payment details directly; we receive only a transaction identifier and payment status. PayPal's privacy policy: paypal.com/legalhub/privacy-full.
- Vercel (Vercel Inc.) — our hosting and content-delivery provider. Vercel maintains the server-access logs described in §2.1 on our behalf. Vercel's privacy policy: vercel.com/legal/privacy-policy.
- Unsplash (Unsplash Inc.) — content delivery network for case-study photos on our marketing site. Only loads images; receives your IP and user-agent when rendering photos. Unsplash's privacy policy: unsplash.com/privacy.
- Pancake / Pages.fm (Pancake Software JSC) — provides the CRM pages, tags, conversations, media, notes, and delivery-readback operations used by the X24H extensions at the user's direction. Brand logos on our /pancake-apps reference page are also served from Pancake's CDN. We are an Official Pancake Philippines Partner, but the extensions are independent helper utilities and are not affiliated with, endorsed by, or officially supported by Pancake. Pancake's privacy policy: pancake.ph/privacy.
Some of these providers process data outside the Philippines (including in the United States and European Union). When they do, we rely on the providers' own lawful-transfer mechanisms (such as Standard Contractual Clauses) to protect your data in transit.
Google API Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
5. Cookies and similar technologies
- The marketing site at automatika.ph does not use an Automatika account-session cookie. Meta Pixel may set or read cookies and similar browser or device identifiers for measurement, attribution, audience insights, and advertising functions under Meta's terms and your browser or Meta account controls.
- The client portal at app.automatika.ph uses a strictly-necessary session cookie to keep you signed in after Google authentication. It contains a session identifier and does not track you across other sites.
- Third-party processors (Stripe, PayPal, Google) may set their own cookies on their own pages when you interact with them (e.g. during checkout or Google sign-in). Those are governed by the respective provider's privacy policy.
- The X24H extensions do not request Chrome's cookies permission or <all_urls>. Their settings, campaign data, and session state use Chrome storage or extension-origin IndexedDB as described in §2.4; those storage mechanisms are not cross-site advertising cookies.
6. How long we keep your data
We retain personal data only as long as necessary for the purposes described in §3, or as required by law.
- Server access logs: up to 90 days.
- Discovery submissions (prospect data): up to 2 years since last interaction, after which they are deleted if no engagement follows.
- Client portal data (business info, project files, notes): for the duration of your engagement and for 2 years after the engagement ends — after which it is deleted unless you request earlier deletion (see §8).
- Local X24H extension data: kept on the user's device until the user clears it or uninstalls the extension. User-exported JSON or CSV files remain wherever the user saved them and must be deleted by the user.
- ActionSuite extension data: account, session, subscription, encrypted Pancake-token, and aggregate campaign-reporting records are retained only as needed for account operation, compliance, fraud prevention, payment records, support, and legal claims, and are deleted or de-identified when no longer needed. Users may request earlier deletion of eligible records through the process in §8.
- Resend contact-directory and delivery data: retained only while needed to operate the account, deliver requested communications, document marketing preferences, and protect delivery integrity. Eligible directory records are deleted when the related ActionSuite account data is deleted or when no longer needed. We or Resend may retain the minimum opt-out, complaint, bounce, or suppression record needed to honor the recipient's choice and prevent accidental re-enrolment or delivery.
- Billing records, invoices, and tax-relevant documents: 10 years from the end of the applicable tax year, as required by the Philippine Bureau of Internal Revenue (Revenue Regulations No. 17-2013).
7. Security
- All traffic to our websites and ActionSuite, including extension-to-server transfers, is encrypted with TLS (HTTPS).
- Access to the client portal is limited to authenticated users via Google OAuth.
- Pancake Access Tokens submitted to ActionSuite are encrypted server-side with AES-256-GCM and are not returned raw to the extension after saving.
- Production X24H packages bundle executable JavaScript locally and do not load Meta Pixel JavaScript, remote analytics scripts, or any other remotely hosted executable code.
- We apply the principle of least privilege: staff access to client data is restricted to those who need it for engagement delivery.
- We do not store payment card numbers, CVV codes, or bank account numbers. These are handled by Stripe and PayPal directly.
- We patch our software dependencies regularly and monitor our hosting provider's security advisories.
No internet service is perfectly secure. If you believe your account has been compromised or you have detected a vulnerability, email with subject “Security issue”.
8. Your rights
Under the Philippine Data Privacy Act (RA 10173) and comparable frameworks, you have the following rights over your personal data:
- Right to be informed about what we collect and why (this Privacy Policy).
- Right of access — request a copy of the personal data we hold about you.
- Right to correction — request that inaccurate data be updated.
- Right to deletion (erasure) — request that we delete your personal data, subject to the retention obligations described in §6. See our Data Deletion page for the exact process.
- Right to object to processing — you may object to our use of your data for specific purposes.
- Right to data portability — receive your data in a machine-readable format.
- Right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines at privacy.gov.ph.
To exercise any of these rights, email . We verify the identity of the requester before acting on a request. We respond within 30 days of receiving a verifiable request.
9. Children's privacy
Our services are intended for use by business representatives aged 18 and older. We do not knowingly collect personal data from children. If you believe a child has submitted personal data to us, email and we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page. When the change is significant, we will notify active clients by email at least 14 days before the change takes effect. The owner-directed ActionSuite directory activation on 27 August 2026 superseded its previously planned waiting period and is recorded contemporaneously in this policy.
11. Contact
- Email (privacy / DPO):
- X24H account-data deletion and support: support@automatika.ph
- Phone: +1 (575) 733-8001
- Headquarters: 1209 Mountain Road PL NE, Albuquerque, New Mexico 87110, USA
- Remote coverage: Australia, Philippines, Singapore
- General contact page: /contact