Privacy Policy

Automis — AI & Marketing Agency

Last updated: March 30, 2026

1.Introduction and Data Controller

This Privacy Policy describes how Automis ("we", "our", or "the Company"), registered in Estonia (registration no. 17179196), with registered address at Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314, collects, uses, stores, and protects personal data in connection with our services.

Automis is an AI & Marketing Agency providing paid advertising management, AI-powered voice agents, workflow automation, social media automation, and consulting services. Depending on the service and context, Automis may act as:

  • •Data Controller — for data collected directly from website visitors, prospective clients, and individuals who interact with our own platforms (e.g., booking a discovery call, downloading an audit report, contacting us).
  • •Data Processor — for data processed on behalf of our Clients in the course of delivering automation services (e.g., responding to comments/DMs on the Client's Meta pages, handling calls on behalf of the Client, managing the Client's CRM data).

This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the applicable Meta Platform Terms and Developer Policies.

2.Categories of Personal Data We Collect

2.1 Data collected directly from you

When you visit our website, book a discovery call, request a Jumpstart Audit, or otherwise contact us, we may collect:

  • •Full name
  • •Email address
  • •Phone number
  • •Company name, job title, and industry
  • •Information you provide during discovery calls, workshops, or audit requests
  • •Billing and payment information (processed by third-party payment providers)

2.2 Data processed via Meta APIs (on behalf of Clients)

As part of our Social Media Automation Service (automated responses to comments and direct messages on Facebook and Instagram), we process the following categories of end-user data through Meta's official APIs (Instagram Graph API, Facebook Pages API, Messenger API):

  • •Public profile data: username, Meta user ID, display name, profile picture
  • •Comment content: text of comments posted under the Client's Facebook/Instagram posts
  • •Direct message content: messages sent by end-users to the Client's page/profile via Instagram Direct or Facebook Messenger
  • •Interaction metadata: timestamps, interaction type (comment, DM, mention), content IDs
  • •Page/profile insights: aggregated performance metrics (reach, engagement) where accessible via API

2.3 Data processed via Voice AI services (on behalf of Clients)

As part of our Voice AI Service (AI-powered inbound and outbound call handling), we may process:

  • • Call audio and transcripts: recordings and/or real-time transcriptions of phone calls handled by our AI voice agents on behalf of the Client
  • • Caller information: phone number, name (if provided), and any information shared during the call (e.g., appointment requests, service inquiries)
  • • Call metadata: call duration, timestamp, call outcome (booked, transferred, voicemail)
  • •Scheduling data: appointment details, calendar availability, booking confirmations

2.4 Data processed via AI Automations (on behalf of Clients)

As part of our AI Automation Service (lead qualification, nurturing, CRM sync, and workflow automation), we may process:

  • • Lead data: name, email, phone, source, qualification status, lead score
  • • CRM records: contact details, interaction history, deal/pipeline stages synced with the Client's CRM
  • • Communication data: content of automated SMS, WhatsApp messages, and emails sent on behalf of the Client
  • • Workflow data: trigger events, automation logs, task assignments

2.5 Data processed via Paid Ads Management (on behalf of Clients)

As part of our Paid Ads Management Service, we may access and process:

  • • Ad account data: campaign performance metrics, ad spend, audience insights, conversion data accessed via Google Ads, Meta Ads, TikTok Ads, LinkedIn Ads, and other advertising platform APIs
  • • Pixel/tracking data: website visitor behavior data collected through advertising pixels configured on the Client's website
  • • Lead form data: information submitted by end-users through lead generation forms on advertising platforms

2.6 Technical data

  • •IP address, browser type, operating system, device information
  • •Cookies and similar tracking technologies (see Section 12)
  • •Website usage logs and analytics data

3.Purposes of Processing

3.1 Data collected directly

  • •Providing requested services (discovery calls, audits, consulting)
  • •Commercial and marketing communications (with consent)
  • •Improving our website and services
  • •Fulfilling legal and contractual obligations
  • •Fraud prevention and security

3.2 Data processed on behalf of Clients

  • • Social media automation: sending automated replies to comments and DMs on Facebook/Instagram via official Meta APIs
  • • Voice AI: handling inbound/outbound calls, booking appointments, qualifying leads, providing customer support via AI voice agents
  • • Lead qualification and nurturing: screening, scoring, and following up on leads through automated workflows
  • • CRM synchronization: keeping client CRM data accurate and up-to-date across platforms
  • • Appointment management: booking, confirming, rescheduling, and reminder automation
  • • Ad campaign optimization: analyzing campaign performance, audience behavior, and conversion data to improve ROI
  • • Reporting: generating performance reports and analytics for Clients

4.Legal Basis for Processing (GDPR)

We process personal data under the following legal bases pursuant to Article 6 of the GDPR:

  • •Consent (Art. 6.1.a): for marketing communications, demo calls, newsletters, and promotional materials. You may withdraw consent at any time.
  • •Performance of a contract (Art. 6.1.b): for delivering services requested by our Clients and fulfilling contractual obligations.
  • •Legitimate interest (Art. 6.1.f): for improving our services, ensuring system security, preventing abuse, and conducting analytics. When acting as a Data Processor, the legitimate interest belongs to the Client (Data Controller).
  • •Legal obligation (Art. 6.1.c): for complying with tax, accounting, and regulatory requirements.

5.Data Sharing and Sub-Processors

5.1 Platform providers

  • •Meta Platforms, Inc.: as the platform through which social media data is collected and transmitted via API. Meta processes data according to its own Privacy Policy and Terms of Service.
  • •Google (Google Ads, Google Calendar): for ad campaign management and scheduling integrations
  • •TikTok, LinkedIn, X (Twitter): for ad campaign management on respective platforms, where applicable

5.2 Technology and infrastructure providers

  • •n8n (n8n GmbH / n8n Cloud): workflow automation platform used to execute automations
  • •ElevenLabs: AI voice synthesis provider used for Voice AI services
  • •GoHighLevel / LeadConnector: CRM and marketing automation platform
  • •Vercel, GitHub, Supabase: infrastructure and hosting
  • •Twilio: telephony infrastructure for Voice AI
  • •Calendly, Cal.com, Google: scheduling and booking services

5.3 Other recipients

  • • Professional advisors : accountants, lawyers, and legal consultants, strictly as necessary
  • • Law enforcement or regulatory authorities: when required by applicable law

We do not sell, rent, or disclose personal data to third parties for their own direct marketing purposes.

6.International Data Transfers

Some of our sub-processors (including Meta Platforms, Inc., Google LLC, and ElevenLabs) are based in the United States or other countries outside the European Economic Area (EEA). Transfers are conducted on the basis of adequate safeguards under Article 46 GDPR (Standard Contractual Clauses), adequacy decisions by the European Commission where applicable, or the explicit consent of the data subject.

7.Data Retention

We retain personal data for the following periods:

  • • Contact and commercial data : for the duration of the contractual relationship and for 2 years thereafter as required by applicable tax and accounting legislation.
  • • Data processed via Meta APIs: retained only as long as necessary to deliver the automation service. Upon termination of the Client contract, data will be deleted within 60 days, unless a longer retention is required by law.
  • • Voice AI call recordings and transcripts: retained for 90 days after the call, then automatically deleted, unless the Client requests longer retention.
  • • Lead and CRM data: for the duration of the Client engagement. Deleted within 90 days of contract termination.
  • • Ad account data: performance reports are retained for the duration of the engagement plus 3 months. Raw platform data is accessed but not stored long-term by Automis.
  • • Website analytics and logs: up to 12 months.
  • • Marketing data (consent-based): until consent is withdrawn.

In accordance with the Meta Platform Terms, upon cessation of use of Meta APIs or upon Meta's request, we will delete all Platform Data without undue delay.

8.Your Rights (GDPR)

Under the GDPR, you have the right to:

  • •Access: obtain confirmation of processing and a copy of your personal data.
  • •Rectification: request correction of inaccurate or incomplete data.
  • •Erasure: request deletion of your data ("right to be forgotten").
  • •Restriction: request restriction of processing in certain circumstances.
  • •Portability: receive your data in a structured, commonly used, machine-readable format.
  • •Objection: object to processing based on legitimate interest.
  • •Withdraw consent: withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.

To exercise your rights, contact us at: support@automis.ai. We will respond within 30 days.

You also have the right to lodge a complaint with the competent supervisory authority (Estonian Data Protection Inspectorate or the authority of your country of residence).

9.Additional Rights for California Residents (CCPA)

If you are a California resident, you have the right to: know what personal information we collect, request deletion of your data, and not be discriminated against for exercising these rights. We do not sell personal data as defined under the CCPA.

10.Data Security

We implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, destruction, or alteration, including:

  • •TLS/SSL encryption for data in transit
  • •Access restricted to authorized personnel only
  • •Monitoring and access logging
  • •Regular backups and disaster recovery procedures
  • •Periodic security reviews
  • •Compliance with the data security requirements set forth in Section 6 of the Meta Platform Terms

11.Role of Automis in Data Processing

When delivering automation services on behalf of our Clients:

  • • The Client is the Data Controller with respect to end-users who interact with the Client's pages, profiles, phone lines, or forms.
  • • Automis acts as the Data Processor, processing data solely according to the Client's instructions and in compliance with the contract and the Data Processing Agreement (DPA) signed between the parties.

If you have questions about how a specific business processes your data through its Facebook/Instagram page, phone system, or website, please contact that business directly.

12.Cookies

Our website uses technically necessary cookies and, with your consent, analytics and profiling cookies. You can manage your cookie preferences through your browser settings or our cookie banner.

13.References to Third-Party Policies

Data of users on third-party platforms is also processed by those platforms according to their own policies:

Our services do not replace or modify the policies of these platforms applicable to their users.

14.Voice AI — Specific Disclosures

When you interact with an AI voice agent operated by Automis on behalf of a Client:

  • •The call may be handled by an artificial intelligence system, not a human operator.
  • •The call may be recorded and/or transcribed for service delivery and quality purposes.
  • •You may request to speak with a human operator at any time.
  • •Call recordings are stored securely and retained for a limited period as described in Section 7. Retention periods are set by the Client and communicated in the Client's own Privacy Policy.
  • Applicable laws regarding call recording consent vary by jurisdiction. Where required, the AI agent will inform the caller that the call is being recorded and will obtain verbal consent before proceeding.

15.Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Significant changes will be communicated through the website or via email. The date of the last update is indicated at the top of this document.

16.Contact Us

For any questions, requests, or complaints regarding this Privacy Policy:

Automis — AI & Marketing Agency

Email: support@automis.ai

Website: https://automis.ai

Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314

Registration number: 17179196