Privacy Policy

Last updated: July 6, 2026

1. Information Collection & Usage

At AJA Sarah Marketer, we prioritize the protection and confidentiality of your enterprise data. We collect information necessary to deliver custom AI Business Operating Systems, including:

  • Contact Information: Name, business email address, phone number, and physical office locations.
  • Operational Data: System credentials, API tokens, database schemas, and current tools configurations shared during the Discovery or Implementation phases.
  • Usage Analytics: Information on how users interact with our dashboards, portal integrations, and cognitive modules to continuously improve performance.

2. Data Protection & Security Architecture

We implement industry-standard encryption and security protocols to safeguard your credentials and company database access keys. All system designs prioritize:

  • Secure API endpoints with authorization token rotation.
  • Encrypted storage of databases via Google Cloud/Firebase Firestore.
  • Restricted role-based access control (RBAC) to system command panels.

We enforce strict internal access limits. Only engineers assigned to your statement of work have access to integration workspaces.

3. Processing of Third-Party Data

As a systems integrator, we configure channels that process your customers' personal information (such as WhatsApp chats, CRM records, and billing profiles). Under these scenarios:

  • The Client acts as the Data Controller, and the Company acts as the Data Processor.
  • We process customer data strictly under your directions and statement of work boundaries.
  • We do not sell, rent, or lease customer lists or operational data to third parties.

4. Cookies & Web Tracking

We use functional cookies and basic tracking tokens to remember user sessions, authorize dashboard entry, and analyze homepage layout performance. You can disable cookies in your browser settings, though doing so may prevent access to certain authenticated integration nodes.

5. Regulatory Compliance & Global Standards

Our operations and systems architectures are engineered to comply with leading national and global privacy regulations:

  • Philippine Data Privacy Act of 2012 (RA 10173): We comply with all provisions of the DPA to safeguard user and customer records. We respect data subject rights, including the right to access, correct, erase, or object to personal data processing.
  • General Data Protection Regulation (GDPR): For EU citizens and entities, we act as a Data Processor under strict instructions from the Client (the Data Controller). We implement robust technical controls to support user data portability, restriction of processing, and erasure requests.
  • Google API Services User Data Policy: Our platform's transfer and use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, share, or use Google user data for advertising, profiling, or unauthorized purposes.

6. Changes to This Privacy Policy

We may update our Privacy Policy periodically to reflect structural technology changes, regulatory developments, or new cloud vendor terms. We will notify you of any changes by posting the new policy on this page and updating the date at the top.

Contact Data Protection Desk

If you have any questions, concerns, or requests regarding your data privacy, please reach out to our Data Protection Officer at:
[email protected]