1. Scope and who we are
This Privacy Policy explains how SHOMON AUTOMATIONS OPC ("SHOMON," "we," "us," or "our") handles personal information in connection with our website, business communications, software, automation services, and authorized integrations with third-party platforms.
SHOMON AUTOMATIONS OPC is located at 2nd Unit, Indiana Town Square, Pajac Drive, Pajac, Lapu-Lapu City, Cebu 6015, Philippines.
When we process information on behalf of a business customer, that customer may determine the purposes and means of processing. In those circumstances, the customer's own privacy notices and instructions may also apply.
2. Information we may handle
The information we handle depends on the service used, the customer's configuration, and the permissions the customer grants. It may include:
- Basic account and contact information, such as a name, business name, business email address, account identifier, and role.
- Customer-provided information, including business records or workflow information submitted to or processed through a service.
- Authorized third-party platform information. If a customer chooses to connect a platform such as Meta, this may include Facebook Login for Business identifiers, Facebook Page identifiers and Page data, permission details, and other data made available under the permissions approved by the customer and platform.
- Webhook and integration events, including event content, identifiers, timestamps, and delivery status made available by a connected service.
- Operational and security logs, such as timestamps, event records, device or browser details, network address information, error records, and activity relevant to reliability, troubleshooting, abuse prevention, and security.
- Communications, including information provided when a person or business contacts us about support, privacy, security, or services.
We aim to collect and process only information that is reasonably relevant to a defined business, operational, legal, or security purpose.
3. Sources of information
We may receive information directly from business customers and their authorized users, through use of SHOMON services, from connected services selected by a customer, and from providers that support our operations.
When SHOMON connects to third-party platforms such as Meta, access is subject to the customer's authorization and the third-party platform's permissions and policies. A customer controls whether to initiate the connection and which available permissions to approve. Third-party platforms may independently collect and use information under their own privacy policies.
4. Purposes of processing
Our approach follows data minimization and purpose limitation: we seek to handle only information reasonably necessary for a defined purpose and not use it for an unrelated or incompatible purpose.
Subject to the context in which information is received, we may process information to:
- provide, configure, maintain, and support requested software and automation services;
- authenticate users and connected business accounts;
- perform customer-authorized integrations and process relevant webhook events;
- communicate about services, support requests, privacy requests, and security matters;
- monitor reliability, diagnose errors, protect systems, and prevent abuse or fraud;
- comply with applicable law, enforce agreements, and establish or defend legal claims; and
- improve the safety, usability, and performance of our services using information appropriate for that purpose.
We use information only for specified and legitimate purposes, or for compatible purposes permitted by applicable law. Depending on the circumstances, processing may be based on consent, performance of a contract, compliance with a legal obligation, or legitimate interests that are not overridden by applicable data protection rights.
5. Sharing and service providers
We do not sell personal information. We may disclose limited information:
- to service providers or processors that support hosting, cloud infrastructure, communications, security, maintenance, or other necessary operations, subject to appropriate contractual or confidentiality obligations;
- to connected platforms when a customer directs or authorizes an integration;
- to professional advisers where reasonably necessary;
- where required by law, legal process, or a competent authority; or
- to protect rights, safety, systems, customers, or the public, or in connection with a legitimate corporate transaction.
Service providers are permitted to handle information only for the services they provide to us or as otherwise allowed by applicable law.
6. Cloud and cross-border processing
Information may be processed or stored using cloud or service providers located outside the Philippines when reasonably necessary to deliver or support a service. Privacy and data protection requirements can differ between jurisdictions. Where applicable, we use reasonable contractual, organizational, or other safeguards appropriate to the information and processing involved.
7. Security practices
We use reasonable administrative, technical, and organizational measures appropriate to the nature of the information and the risks involved. These may include access controls, limiting access to authorized personnel or service providers, protecting credentials in storage and transit as appropriate, and maintaining operational and security records.
No method of transmission, storage, or processing is completely secure. We therefore cannot guarantee absolute security. Customers and users should also protect their own devices, accounts, and credentials and notify us of suspected unauthorized activity.
8. Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including providing requested services, maintaining security and integrity, resolving disputes, meeting contractual commitments, and satisfying legal, regulatory, tax, or accounting obligations.
Retention periods vary according to the type of information, the service context, customer instructions, applicable legal requirements, and backup cycles. When information is no longer required, we take reasonable steps to delete or anonymize it.
9. Authorization, revocation, and disconnection
A business customer may revoke platform permissions or disconnect an integration using controls made available by the relevant third-party platform and, where available, within the SHOMON service. Revoking or disconnecting access stops or limits future access according to the platform and service configuration.
Disconnection does not necessarily delete information already received. Historical records may be retained where reasonably necessary for security, legal, fraud-prevention, accounting, dispute-resolution, backup-cycle, or other legitimate obligations. A separate deletion request may be submitted as described in our Data Deletion Instructions.
10. Privacy rights and choices
Subject to applicable law and the relevant processing context, individuals may have rights to request access to, correction of, deletion or blocking of, or information about the processing of their personal information; to object to or restrict certain processing; to withdraw consent where consent is the basis for processing; and to data portability where applicable.
To make a privacy or deletion request, email privacy@ciomon.com. Please identify the relevant business or account and describe the request. We may request reasonable verification to protect information and prevent unauthorized access or deletion.
If we process information solely on behalf of a business customer, we may direct the requester to that customer or assist the customer in responding. Requests are subject to applicable exceptions and retention obligations. Individuals may also have the right to raise a concern with the Philippine National Privacy Commission or another competent authority.
11. Children's privacy
Our business services are not directed to children, and we do not knowingly seek to collect personal information from children through this corporate website.
12. This website
This public corporate website does not provide forms that collect personal information and does not use analytics, advertising trackers, or cookies. If a visitor chooses to contact us by email, the visitor's email provider and our email service providers will process the communication as necessary to transmit and respond to it.
13. Policy updates
We may update this Privacy Policy to reflect changes in our services, practices, legal obligations, or other operational needs. We will post the revised policy on this page and update the effective date. Where appropriate, we may provide additional notice.
14. Contact us
For privacy inquiries or requests, contact:
SHOMON AUTOMATIONS OPC2nd Unit, Indiana Town Square
Pajac Drive, Pajac
Lapu-Lapu City, Cebu 6015
Philippines
Email: privacy@ciomon.com