Skip to content

Security and Data Protection

Last updated: August 23, 2026

1. Introduction

OFIMATIC SRL recognizes that the security, confidentiality, integrity, and availability of information are fundamental to the provision of OBMessage and its modules and services, including Omnify, Aless, and SmartQueue.

This page provides a high-level description of the measures and principles used to protect information processed through OBMessage.

The information published here is general and is not intended to disclose configurations, architecture, credentials, addresses, internal mechanisms, or other details whose disclosure could increase security risks to the platform.

2. Scope

Security measures apply, where appropriate, to:

  • Infrastructure used to provide OBMessage.
  • Associated applications and services.
  • APIs and integrations.
  • Customer administrative information.
  • Data processed on behalf of customers.
  • Technical and audit records.
  • Backups.
  • Credentials and technical configurations administered by OFIMATIC.

Specific measures may vary according to the service, functionality, type of information, and applicable level of risk.

3. Security principles

OFIMATIC applies an approach designed to protect information against:

  • Unauthorized access.
  • Improper disclosure.
  • Unauthorized modification.
  • Loss.
  • Destruction.
  • Misuse.
  • Interruptions that may affect service delivery.

Controls are evaluated according to the nature of the information, functionality used, identified risks, and applicable obligations.

4. Access control

Access to systems and data administered by OFIMATIC is restricted according to applicable roles and responsibilities.

OFIMATIC seeks to apply controls designed to:

  • Restrict access to authorized personnel.
  • Prevent unnecessary use of privileges.
  • Separate administrative functions where appropriate.
  • Disable access that is no longer required.
  • Maintain authentication mechanisms appropriate to the level of risk.
  • Record certain administrative access and activity where applicable.

Customers are responsible for properly managing users, roles, and permissions configured within their own OBMessage accounts.

5. Credentials and authentication

Credentials used to access OBMessage must be kept confidential.

Customers and users must:

  • Use individual credentials where appropriate.
  • Not share passwords or tokens with unauthorized persons.
  • Protect API keys and integration credentials.
  • Revoke credentials that are no longer required.
  • Report any suspected account or credential compromise.

OFIMATIC may apply additional authentication or verification mechanisms where necessary to protect the platform or certain operations.

6. Communications and integration protection

OBMessage uses technical mechanisms designed to protect communications between users, applications, APIs, and integrated services as appropriate to each implementation.

Credentials, tokens, API keys, and integration settings must be treated as confidential information.

Customers must not publish such information in:

  • Public repositories.
  • Public documentation.
  • Open messages.
  • Publicly accessible source code.
  • Unauthorized systems.

7. Information segregation

OBMessage is designed to manage information belonging to different customers.

OFIMATIC applies controls intended to prevent one customer from obtaining unauthorized access to information belonging to another customer.

Proper configuration of users, permissions, integrations, and accounts is also the Customer's responsibility.

8. Logging and auditing

OFIMATIC may maintain technical records related to:

  • Access.
  • Administrative operations.
  • Application activity.
  • Integrations.
  • Errors.
  • Security events.
  • Diagnostics and support.

These records may be used to:

  • Investigate incidents.
  • Diagnose issues.
  • Maintain service stability.
  • Detect anomalous activity.
  • Support audit requirements.
  • Comply with legal or contractual obligations.

Access to such records is restricted according to their purpose and sensitivity.

9. Backups and continuity

OFIMATIC may use backup mechanisms designed to support service continuity and recovery.

Backups are subject to access controls and technical retention cycles.

Deletion of information from active systems does not necessarily result in immediate deletion from all backups.

Residual information will be deleted or overwritten according to the applicable technical cycle.

See:

User Data Deletion Instructions

10. Vulnerability management and updates

OFIMATIC performs maintenance activities intended to preserve the security and stability of systems used to provide OBMessage.

These activities may include, where appropriate:

  • Software updates.
  • Security fixes.
  • Dependency updates.
  • Configuration reviews.
  • Remediation of identified vulnerabilities.
  • Preventive changes to maintain compatibility and security.

Where a vulnerability presents a significant risk, OFIMATIC may prioritize changes, restrictions, or updates.

11. Security monitoring

OFIMATIC may use logs, alerts, and other technical mechanisms to identify anomalous behavior or events that may present risks to:

  • The platform.
  • Customers.
  • Users.
  • Integrations.
  • Processed information.

The nature and scope of monitoring may vary according to the service and risk level.

12. Incident management

OFIMATIC maintains procedures designed to evaluate and manage incidents that may affect information security or service continuity.

Where a relevant incident is detected, OFIMATIC may perform, as appropriate:

  • Identification.
  • Analysis.
  • Containment.
  • Mitigation.
  • Recovery.
  • Investigation.
  • Documentation.
  • Corrective action.

Where a legal or contractual notification obligation exists, OFIMATIC will provide the corresponding communications in accordance with applicable requirements.

13. Providers and subprocessors

Certain OBMessage components may depend on technology providers used for infrastructure, messaging, storage, or other services.

OFIMATIC seeks to select providers appropriate to the nature of the service and apply reasonable contractual conditions or controls relating to confidentiality and information protection.

See:

Subprocessors and Technology Providers

14. Retention and deletion

OFIMATIC retains information only for as long as necessary to provide the service, fulfill contractual obligations, support security and auditing, comply with legal requirements, or satisfy other legitimate purposes.

When information is no longer required, deletion, anonymization, or expiration procedures are applied as appropriate.

See:

15. Customer responsibilities

OBMessage security is a shared responsibility.

The Customer is responsible for:

  • Properly managing users.
  • Configuring appropriate permissions.
  • Protecting credentials.
  • Protecting API keys and tokens.
  • Promptly disabling users who no longer require access.
  • Maintaining secure devices and networks.
  • Properly configuring integrations and automations.
  • Reporting suspicious behavior or access.
  • Complying with security requirements and policies of third-party services used.

16. Reporting incidents or vulnerabilities

If you identify a potential security incident, anomalous behavior, or vulnerability related to OBMessage, contact:

seguridadtic@ofimatic.com

You must not attempt to exploit a vulnerability, access third-party information, perform destructive testing, or affect service availability.

17. Updates

OFIMATIC may update this page to reflect changes in its services, security measures, regulatory obligations, or operational practices.

18. Contact

For security and data protection inquiries:

📍 C. Nicolás Ureña de Mendoza 3, Santo Domingo 10132
📞 (809) 540-8151
🌐 https://obmessage.ai
✉️ soporte@ofimatic.com

OBMessage is a platform developed and operated by OFIMATIC SRL.