Privacy Policy — AI 24/7
Effective date: 22 August 2026
Replaces: October 2025 version
Website: https://www.ai247saas.com
Service: AI 24/7 (also referred to as “AI 24/7 powered by AGG”)
Address: 301 AIC Burgundy Empire Tower, ADB Ave., Ortigas, Pasig City, Philippines
Privacy contact: [email protected]
By creating an account, clicking “I agree,” or using the Service, you acknowledge that you have read this Privacy Policy and consent to the practices described here, including our transfer of data to the third-party platform host and other subprocessors listed in Section 8.
1. Introduction
This Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have.
It is issued to meet applicable law and our obligation, as a reseller of a third-party business platform, to maintain a privacy program no less protective than that platform host’s program, including notices, consent, security, retention, breach handling, and data-subject rights.
Primary law: the Philippines Data Privacy Act of 2012 (R.A. 10173) and its IRR. Where it applies, we also follow GDPR / UK GDPR, and U.S. state laws such as the CCPA/CPRA, VCDPA, CPA, UCPA, and CTDPA. Payment processing is handled so that we do not store full card numbers (see Section 9). We are not a bank and do not provide tax, legal, or medical advice.
This Policy is not the privacy policy of our United States CRM and communications platform host. When we send data to that host so the Service can run, that host’s terms and privacy notice also apply to that processing. A current list of named subprocessors is available on request at the privacy contact above.
2. Who this Policy covers and our roles
Website visitors and account holders (members). We are the personal information controller (and, where GDPR applies, the controller) for account, billing, support, and marketing data you give us.
End users of our members (leads, contacts, chat participants, buyers). For names, contact details, messages, bookings, and similar data that you collect in the Service, you are the controller. We (and our platform host and other subprocessors) are processors / personal information processors. We process that data only to provide the Service, on your instructions, and as described here.
If a subprocessor receives a request from your end user, they may forward it to us, and we may forward it to you. You must answer it on time.
Your duty to your customers. If you give anyone access to the Service, or collect their data through forms, funnels, calendars, SMS, email, messaging apps, or checkout, you must:
Publish your own terms and a privacy notice at least as protective as this Policy and as required by law.
Get valid consent (and keep records) before you collect or message them.
Authorize us to provide their data to the subprocessors in Section 8, including the United States platform host.
Not upload data you do not have the right to process (including children’s data and, unless you have a separate written agreement with us, protected health information).
3. Personal data we collect
3.1 Data you give us
Account and identity: name, email, username, password (hashed), member/user IDs.
Business and billing: phone, company, role, billing address, subscription plan, wallet or payment references. Full card data is collected by the payment processor, not stored by us.
Support: tickets, emails, call notes, diagnostics.
User Content: contacts/leads, messages, campaign and social content, media, knowledge-base materials, forms, calendar bookings, invoices, product catalog data, and settings you configure.
3.2 Data collected automatically
IP address, device and browser type, approximate location derived from IP, pages viewed, feature use, cookies and similar IDs, log files, and security events.
3.3 Data from third parties and integrations
United States CRM and communications platform host: contacts, conversations, workspaces, users, connected social accounts, products, invoices, and event notifications needed to run CRM, messaging, calendars, funnels/sites, social posting, and related features.
Social networks you connect (for example Facebook, Instagram, Google, LinkedIn): account IDs, page/profile names, and posting metadata, under that network’s terms. Use of Google user data (if you connect Google) follows the Google User Data Policy, including Limited Use.
Payments: PayDollar / PesoPay (AsiaPay) and related acquirers — transaction status, amount, currency, merchant references; not full PAN/CVV.
Commerce sync: product titles, SKUs, prices, and images from your connected catalog so we can list products and build checkout links.
AI providers: see Section 7.
3.4 Sensitive or special data
Do not submit government IDs, full bank credentials, or health/medical files unless a feature expressly requires it and you have a lawful basis.
Checkout or insurance-related forms may collect date of birth, nationality, occupation, address, and beneficiary details. Treat that as sensitive. You must have authority and consent before you collect it. We do not offer a U.S. health-privacy business associate agreement unless we sign one with you in writing. If you process U.S. protected health information without that agreement, you must not use the Service for that purpose.
4. Legal bases (where a legal basis is required)
Purpose
Typical basis
Create the account, provide CRM/messaging/AI/payments, bill you
Contract
Tax, accounting, lawful requests, security logs
Legal obligation
Security, fraud prevention, product reliability, aggregated analytics
Legitimate interests (balanced against your rights)
Marketing emails/SMS to you; optional cookies; some international transfers
Consent (withdraw anytime)
End-user messaging (SMS, email, messaging apps, voice)
Your consent/records as controller; we process as processor
If we ask for data that is required for the contract, we will say so. If you do not provide it, we may be unable to provide that part of the Service.
5. How we use personal data
Provide, host, secure, and support the Service (accounts, CRM, conversations, social publishing, calendars, funnels, knowledge bases, AI replies, checkout).
Provision and maintain your workspace on the third-party platform host (workspace, users, configuration templates, integrations).
Process subscriptions, credits, and product checkout; detect fraud.
Send transactional mail (receipts, security, service changes). Marketing only with consent or as allowed by law; every marketing message includes an opt-out.
Moderate or review content where we have a safety or acceptable-use reason (for example team content publishing).
Comply with law and enforce our Terms.
Improve the Service using aggregated or de-identified usage metrics. We do not sell your personal data for money.
We may generate technical usage data (feature use, performance). The platform host may also collect usage data under its own policy and may use anonymized, aggregated data that does not identify you or your customers.
6. Communications (SMS, email, voice, messaging apps)
The Service can send SMS, MMS, RCS, email, in-app or social messaging, and voice (including features such as voicemail drop). You, not AI 24/7 and not the platform host, are the sender / advertiser / telemarketer for those messages.
You represent that you have obtained the consent required by the TCPA, Telemarketing Sales Rule, CAN-SPAM, CASL, GDPR, Philippines rules, carrier/10DLC rules, and any similar law before you contact anyone, and that you will keep records.
Text / similar messaging opt-in data and consent records are used only to provide that messaging. We do not sell or share them with third parties except the aggregators and providers that deliver the messages (and the platform host as needed to send them). We do not use that consent for unrelated marketing.
7. Artificial intelligence
If you enable AI features (auto-reply, follow-up, knowledge-base retrieval, image description, content moderation, caption rewrite, product lookup):
Conversation text, relevant knowledge-base excerpts, and necessary contact fields are sent to our AI subprocessors (currently OpenAI; other listed providers only if we enable them) to generate a reply or embedding.
We use AI only to provide the feature you turned on. We do not use your personal data or User Content to train generalized public AI models. We instruct providers not to use that data to train their public models where the provider offers that control.
AI output can be wrong. You remain responsible for what is sent to your contacts.
Do not collect card numbers, CVV, OTP, passwords, or bank details in chat.
You must only enable AI in jurisdictions where that use is lawful, and you must not use AI to generate unlawful, discriminatory, or deceptive content.
8. Sharing and subprocessors
We share personal data only as follows.
Affiliates. For the same purposes as this Policy.
Service providers / subprocessors (under contract, limited to our instructions):
Recipient
Role
Location (typical)
Third-party CRM and communications platform provider that hosts each member workspace (conversations, contacts, calendars, funnels/sites, social posting, users, products, invoices)
Processor / platform host
United States
OpenAI, L.L.C. (and successors)
Chat completions, embeddings, optional image understanding
United States
AsiaPay / PayDollar / PesoPay
Checkout and payment confirmation
Hong Kong / Philippines / region of the acquirer
Cloud hosting and storage (application hosting, backups, media and preview images)
Processor
[confirm region]
Email / SMS / voice carriers and aggregators
Deliver messages you initiate
Various
Analytics and security vendors we engage
Site analytics, fraud, abuse
Various
Named legal entities for the platform host and other subprocessors are available on request from the privacy contact.
Integrations you connect (Facebook, Instagram, Google, LinkedIn, payment apps, etc.) receive the data needed for that connection, under their terms.
Legal and safety: courts, regulators, or law enforcement when required or when we reasonably believe disclosure is necessary to protect rights, safety, or the Service.
Corporate transactions: merger, acquisition, or asset sale, with protections consistent with this Policy.
At your direction: when you click connect, export, share a checkout link, or otherwise ask us to send data.
We do not sell personal data for money. Some advertising cookies or analytics may be “sharing” or “sale” under California/U.S. state law. You may opt out under Section 13.
The platform host may access or monitor workspaces for support, security, and to perform its agreement with us. By using the Service you consent to that access as needed to operate the hosted platform.
9. Payments and card data
Subscriptions and product checkout use third-party processors. We store tokens, status, amounts, and order metadata. We do not store full primary account numbers or CVV. Processors apply their own PCI DSS controls. You are responsible for tax calculation, invoices to your buyers, and any consumer disclosures required for your sales.
10. International transfers
We are based in the Philippines. The Service cannot operate without transferring data to the United States (platform host and current AI provider) and to other countries where subprocessors run.
Where required, we use appropriate safeguards: contracts (including standard contractual clauses or equivalent), provider certifications or frameworks where available, and least-privilege access. You consent to these transfers when you use the Service and when you upload end-user data.
You must not use the Service if you are in a comprehensively sanctioned jurisdiction or are a prohibited party under U.S. or Philippine export/sanctions rules, and you must not send the Service data that those rules forbid transferring.
11. Cookies and similar technologies
We use:
Strictly necessary cookies (login, security, load balancing).
Analytics cookies (understand traffic and feature use).
Preference cookies (language, UI).
Marketing cookies only if we enable them and, where required, after consent.
You can block cookies in the browser. Blocking necessary cookies will break login. We do not respond to “Do Not Track” browser signals. Where required (EU/UK), non-essential cookies wait for consent. A fuller cookie table can be published as a separate Cookie Policy; until then this section is the notice.
12. Retention and deletion
Data
Typical period
Account and billing
Life of the account + period required for tax and dispute (often up to 10 years in the Philippines)
User Content in our systems
While the account is active; then deletion or anonymization within a commercially reasonable period after closure
Data on the platform host
The host may retain workspace data for about 90 days after the workspace is cancelled, then may permanently delete it
AI logs / prompts
Only as needed to provide the feature, debug abuse, and meet legal duties; then delete or aggregate
Checkout prefill tokens
Limited time (on the order of days to a few weeks, then expiry)
Security logs
Typically 12–24 months unless an investigation requires longer
Marketing lists
Until you opt out or the account is deleted
You must not keep end-user data longer than your purpose and the law allow. When an end user asks you to delete, you must delete or anonymize their data in the Service and tell us if you need our help.
After your account ends, we may keep limited records (invoices, fraud, legal holds). Backups age out on a rolling cycle.
13. Your rights
Depending on where you live, you may request:
Access and a copy (portability where applicable).
Correction.
Deletion (subject to legal holds).
Restriction or objection (including objection to marketing and, where applicable, to processing based on legitimate interests).
Withdrawal of consent (does not undo prior lawful processing).
Appeal of a refused request (U.S. state laws).
Opt out of “sale,” “sharing,” or targeted advertising.
Non-discrimination for exercising privacy rights.
How to ask: email [email protected] with “Privacy Request,” your name, account email, the right you want, and enough detail for us to find the data. We may need to verify you. An authorized agent may act for you with proof.
Timing: we aim to respond within 30 days (PH DPA / GDPR) or within the shorter period your state law requires (often 45 days in California, extendable as allowed). We will say if we need more time.
End-user requests: if you are a lead or buyer of a member, contact that member first. We will assist the member as processor.
Complaints: National Privacy Commission (Philippines); your EU/UK supervisory authority; or the privacy regulator in your state or country.
14. U.S. state privacy notice (summary)
In the last 12 months we have collected the categories in Section 3 (identifiers, commercial information, internet activity, professional information, and inferences such as product interest). We disclose them to the parties in Section 8 for the business purposes in Section 5.
We do not sell personal data for money. We may “share” identifiers and internet activity with analytics or ads partners if those tools are on. Opt out via the privacy email or any “Do Not Sell or Share My Personal Information” link we display.
We do not use sensitive data for profiling that produces legal or similarly significant effects solely by automated means.
We do not share text-message opt-in data except as described in Section 6.
15. Children
The Service is for business use by persons 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.
16. Security
We use administrative, technical, and physical measures appropriate to the risk: access control, encryption in transit, hashed passwords, least-privilege access to production, and vendor contracts. No system is 100% secure. You must use a strong password, keep credentials confidential, and turn on two-factor authentication where offered.
Breach. If we discover an incident that involves personal data we process, we will investigate, contain it, and notify you and regulators as required by the DPA, GDPR, and other law. If the data belongs to your end users, you remain responsible for notices to those individuals and to regulators, unless the law assigns that duty to us. We will give you the facts we reasonably can so you can notify. You must tell us promptly if you discover a breach affecting data in the Service.
17. Third-party sites and your own properties
Links and embedded tools (social networks, payment pages, the hosted platform interface) are governed by those parties’ policies. We are not responsible for their practices. Pages, funnels, and forms you publish must carry your privacy notice and collect consent before you take personal data.
18. User Content license (operations only)
You keep ownership of User Content. You grant us a non-exclusive, worldwide, royalty-free license to host, copy, process, transmit, and display it only to operate, secure, support, and improve the Service and to pass it to subprocessors in Section 8. This is not a license for us to use your content in unrelated advertising.
19. Changes
We may update this Policy. The new effective date will appear at the top. Material changes will be notified by email or in-product notice. Continued use after the effective date is acceptance, except where the law requires a fresh consent.
20. Contact
Privacy requests, DPO contact, and complaints:
AI 24/7
301 AIC Burgundy Empire Tower, ADB Ave., Ortigas, Pasig City, Philippines
Email: [email protected]
For platform-host data that we cannot access, we will point you to the right channel or submit the request as processor.
Send us a message to get answers to any of your questions & we’ll
get back to you right away!
It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout.
Copyright 2025. Philippines. All rights reserved.