Legal
Privacy Policy
Privacy and personal data processing policy of OBMessage, the communications, conversational automation, omnichannel messaging, and queue management platform developed and operated by OFIMATIC SRL. Last updated: August 28, 2026.
1. Introduction
This Privacy Policy describes how OFIMATIC SRL collects, uses, stores, protects and, where applicable, deletes personal information related to the use of OBMessage and its modules and services, including Omnify, Aless, and SmartQueue.
OBMessage is a communications, conversational automation, omnichannel messaging, and queue management platform developed and operated by OFIMATIC SRL.
OFIMATIC is committed to the privacy, confidentiality, and security of information and to compliance with applicable law, including Dominican Republic Law No. 172-13 on Personal Data Protection.
2. Scope
This policy applies to information processed by OFIMATIC in connection with:
- Customers and organizations that contract or use OBMessage.
- Administrative users, agents, and platform operators.
- Contacts and end users who interact with OBMessage customers.
- Individuals using channels connected to the platform, such as email, SMS, WhatsApp, web chat, or other enabled channels.
- Aless and SmartQueue users.
- Integrations, APIs, webhooks, and related services.
3. Data processing roles
OFIMATIC's role may vary depending on the information and purpose of processing.
Administrative and contractual information
For information required to manage accounts, contracts, support, security, billing, commercial relationships, and legal compliance, OFIMATIC may determine the purposes necessary for such processing in accordance with its relationship with the customer.
Data processed on behalf of the customer
When a customer uses OBMessage to process contacts, messages, conversations, files, tickets, end-user information, or other data related to its operations, the customer determines the purposes of that processing and OFIMATIC processes the information to provide the service, subject to applicable instructions and contractual terms.
The customer is responsible for obtaining all authorizations, consents, notices, and other lawful grounds required to collect and process information submitted or transmitted through OBMessage.
4. Information we may process
Depending on the services used, OFIMATIC may process the following categories of information:
Account information
- First and last name.
- Email address.
- Telephone number.
- Company or organization.
- Job title or role.
- Internal user identifiers.
- Account settings and preferences.
Technical and security information
- IP addresses.
- Access records.
- Technical and audit logs.
- Browser or device information.
- Security events.
- Activity and operational metrics.
- Information required to diagnose errors or provide support.
Messaging and service data
Depending on customer configuration:
- Telephone numbers.
- Email addresses.
- Contacts.
- Message and conversation content.
- Attachments and documents.
- Delivery and read statuses.
- Opt-in and opt-out information.
- Ticket, queue, or request information.
- Notes or information entered by agents.
Meta and WhatsApp Business Platform data
When a customer connects Meta or WhatsApp services, we may process technical information required to manage the integration, such as:
- Meta User ID, where applicable.
- Business Portfolio ID.
- WhatsApp Business Account ID (WABA ID).
- Phone Number ID.
- Connected WhatsApp Business numbers.
- Message Templates.
- Webhook configuration.
- Message statuses and integration events.
- Technical settings and credentials required to operate the integration.
SmartQueue information
Depending on the implementation:
- Ticket and queue data.
- Branches, departments, and topics.
- Information provided through kiosks.
- Service history.
- Agent and position data.
- Ticket-related files.
Website and contact form information
When a person uses the Ofimatic corporate website and requests a demo or completes a contact form, we may process the information provided in that form, including:
- Full name.
- Company or organization.
- Business email address.
- What they want to automate (area of interest).
- Whether they already have a similar solution.
- Consent confirmation for processing.
- Visit source information (UTM parameters) and the page from which the request was submitted.
This information is used exclusively to respond to the commercial request, start a conversation with the sales team, and follow up on the interest expressed.
5. Purposes of processing
Information may be used to:
- Create and administer OBMessage accounts.
- Provide contracted services.
- Send and receive communications requested by the customer.
- Process conversations, automations, tickets, and queues.
- Operate integrations and APIs.
- Provide technical support.
- Manage security and access control.
- Detect and prevent fraud, abuse, or misuse.
- Maintain technical and audit records.
- Diagnose incidents or operational issues.
- Comply with legal, regulatory, or contractual obligations.
- Improve the stability, security, and technical operation of the platform.
OFIMATIC will not use data processed on behalf of the customer for purposes incompatible with providing the service, except where required by law or otherwise authorized.
6. Customer data
Contacts, messages, conversations, documents, files, tickets, configurations, and other information provided or generated by the customer through OBMessage remain the property of the customer or their respective owners.
Use of OBMessage does not transfer ownership of such data to OFIMATIC.
OFIMATIC receives only the processing rights necessary to provide, operate, protect, maintain, and support the service, subject to applicable contractual terms and this Privacy Policy.
7. Providers and subprocessors
OFIMATIC does not sell or commercialize personal data.
To provide certain services, OFIMATIC may use technology providers acting only for purposes related to the provision, operation, or security of the service.
Depending on the contracted services, these providers may include:
- Infrastructure and hosting providers.
- Messaging providers.
- Email or SMS providers.
- Communication platforms such as Meta and WhatsApp.
- Storage providers.
- Technical services required to operate integrations.
Provider access is limited to information necessary to perform their function and is subject to applicable contractual and confidentiality obligations.
Where applicable, certain information may be processed in countries other than the customer's country, depending on the infrastructure and providers used and subject to applicable legal requirements.
8. Third-party integrations and services
When a customer connects OBMessage to a third-party service such as Meta, WhatsApp, or another external platform, certain information may be transmitted to that provider to perform the requested integration.
Processing performed directly by that third party is also subject to its own terms, privacy policies, and conditions of use.
OFIMATIC does not control independent data processing practices performed directly by those providers.
9. Data retention
Information will be retained only for as long as necessary to:
- Provide the service.
- Maintain the contractual relationship.
- Handle support requests.
- Comply with legal, tax, regulatory, or contractual obligations.
- Maintain security, audit, or fraud-prevention records.
- Resolve disputes or protect legal rights.
When information is no longer necessary, it will be deleted or anonymized according to applicable procedures.
Residual copies that may exist in backup systems will be deleted or overwritten according to the technical retention cycle for those backups and will remain protected from ordinary access while retained.
For information about deletion procedures, see the User Data Deletion Instructions.
10. Information security
OFIMATIC implements technical, organizational, and administrative measures designed to protect information against:
- Unauthorized access.
- Improper disclosure.
- Alteration.
- Loss.
- Destruction.
- Misuse.
Measures are determined according to the nature of the information, the functionality used, and associated risks.
No system can guarantee absolute security. Customers are also responsible for protecting their accounts, credentials, users, and configurations.
11. Customer responsibilities
The customer is responsible for:
- Determining the lawfulness of processing data submitted to OBMessage.
- Providing required privacy notices.
- Obtaining required consent or other authorization.
- Honoring access, correction, objection, or deletion requests.
- Keeping contact information up to date.
- Properly configuring opt-in and opt-out mechanisms.
- Complying with policies applicable to the channels used.
- Avoiding submission of information whose collection or processing is prohibited.
12. Data subject rights
Subject to applicable law, individuals may request, where appropriate:
- Access to their personal data.
- Correction of inaccurate or outdated information.
- Updating of information.
- Deletion.
- Objection to processing where applicable.
Where OFIMATIC processes information solely under a customer's instructions, an end-user request may require participation by the customer responsible for that information.
OFIMATIC will reasonably assist the customer in responding to such requests in accordance with applicable obligations.
13. Deletion requests
Requests concerning information directly administered by OFIMATIC may be sent to soporte@ofimatic.com.
For the complete procedure, see the User Data Deletion Instructions.
14. Minors and regulated data
Customers are responsible for determining whether their use cases involve information about minors, health information, financial information, or other categories subject to special requirements.
Technical availability of functionality within OBMessage does not mean it is permitted for every category of information or activity.
Customers must implement any additional measures required by applicable law or the policy of the communication channel being used.
15. Changes to this policy
OFIMATIC may update this Privacy Policy to reflect legal, regulatory, technological, or operational changes.
The current version will be published in the official OBMessage documentation.
Where a material change requires notification, OFIMATIC may communicate it through the platform, website, email, or another appropriate method.
16. Contact
For privacy or data protection inquiries:
📍 C. Nicolás Ureña de Mendoza 3, Santo Domingo 10132
📞 (809) 540-8151
🌐 https://obmessage.ai
✉️ legal@ofimatic.com
OBMessage is a platform developed and operated by OFIMATIC SRL.
© OFIMATIC SRL. All rights reserved.