Privacy Policy
Last Updated: August 16, 2026
This Privacy Policy explains what we do with personal data when you visit rekreatedigital.com or our careers site at careers.rekreatedigital.com, contact us, chat with our website assistant, apply for a job with us, or engage us to build and run AI systems for your business. We have written it to describe what actually happens, so where a practice is limited or does not apply, we say so rather than reserving rights we do not use.
Who We Are
Rekreate Digital Marketing Services, a Philippine sole proprietorship of Ryan Kyle Ocampo, trading as Rekreate Digital ("we", "us", "our"), is the personal information controller for the data described in this policy. We build and operate custom AI agent platforms and automation for businesses, and we also provide marketing and web development services.
- Registered name: Rekreate Digital Marketing Services — a Philippine sole proprietorship of Ryan Kyle Ocampo
- Registration: BIR-registered, Revenue District Office No. 027 — Caloocan City. Our TIN appears on official receipts and invoices and is available on request.
- Registered address: 570 Prudencio St., Rubyville Subd., Barangay 160 (Baesa), 1400 Caloocan City, Metro Manila, Philippines
- Data Protection Officer: Ryan Kyle Ocampo — [email protected]
Section 21 of the Philippine Data Privacy Act and its Implementing Rules require a designated Data Protection Officer, and Article 37 of the GDPR requires a contact point for data subjects. The named person above is responsible for handling the requests described in this policy.
Information We Collect
We collect the following, and nothing else:
What you send us directly
- Contact and quote forms: your name, email address, phone number, subject, and the message you write.
- Newsletter signup: your first name, last name, and email address.
- Chat assistant: the messages you type, and — only if you agree to the consent step first — your name, a contact detail, a short note, and a copy of that conversation. See below.
- Email, phone, and social messages: whatever you choose to include.
Technical information
- Your IP address and browser user-agent, which our servers and our security provider receive with every request and use to deliver the page and block abuse.
- When you submit a contact or quote form, sign up to the newsletter, or send us your details through the chat assistant, the IP address and browser user-agent of that submission are stored with the record, so we can trace and block spam and abuse of those forms.
- Which pages you visit, the site you arrived from, any campaign tags in the link you followed, and whether your screen is phone, tablet, or desktop size.
- Cookies and browser storage — every item is listed individually in our Cookie Policy.
What we do not collect here
- No payments are taken on this website. There is no checkout, and we never receive your card or bank details through it. Clients invoiced under a signed service agreement pay by bank transfer or e-wallet, and the billing details involved are handled in that relationship and by the bank — not collected by this site.
- No accounts. This website has no login, no user accounts, and no passwords.
- No sensitive personal information as defined by the Data Privacy Act is requested anywhere on this site. Please do not include health, government ID, financial, or similar details in a form or chat message.
How We Use Your Information
We use the information described above only for these purposes:
Answering you
- Replying to an enquiry, quote request, or chat message
- Arranging and running a free automation audit or a booked call
Delivering our services
- Building, running, and supporting the AI systems and marketing work a client has engaged us for
- Administering the contract, including invoicing and record-keeping
Newsletter
- Sending our newsletter, but only to people who asked for it, and only until they unsubscribe
Running the website
- Counting pageviews so we know which pages are worth keeping
- Blocking bots, spam, and abuse, and keeping the site available
Hiring
- Assessing job applications — see the Job Applicants section below
Legal & security
- Meeting our legal, tax, and accounting obligations
- Establishing, exercising, or defending legal claims
We do not sell your personal information, share it with data brokers, or use it to build advertising profiles. We do not make any decision producing legal or similarly significant effects about you by automated means. Our chat assistant answers questions; it does not decide anything about you.
Legal Bases for Processing (for EU/EEA Users)
Under the GDPR we must name a legal basis for each purpose, and under the Philippine Data Privacy Act we must have a lawful criterion under Sections 12 and 13. This is how they line up:
| What we do | Legal basis |
|---|---|
| Replying to your enquiry, quote request, or chat lead | Your consent, and steps taken at your request before entering a contract (GDPR Art. 6(1)(a) and 6(1)(b); DPA Sec. 12(a), 12(b)) |
| Delivering and administering services to a client | Performance of a contract (GDPR Art. 6(1)(b); DPA Sec. 12(b)) |
| Sending the newsletter | Your consent, withdrawable at any time (GDPR Art. 6(1)(a); DPA Sec. 12(a)) |
| Google Analytics, and any cookie or storage that is not strictly necessary | Your consent through the cookie banner (GDPR Art. 6(1)(a); ePrivacy Directive Art. 5(3)) |
| Our own storage-free pageview counter, and blocking bots and abuse | Legitimate interests in understanding and protecting our own website, balanced against your privacy by storing nothing on your device and storing neither your IP address nor your user-agent in the pageview record — at most a daily-rotating, non-reversible hash derived from them (GDPR Art. 6(1)(f); DPA Sec. 12(f)) |
| Assessing a job application | Steps at your request before a contract of employment, and your consent if we keep your details for future roles (GDPR Art. 6(1)(b), 6(1)(a); DPA Sec. 12(a), 12(b)) |
| Keeping tax, accounting, and contract records | Legal obligation (GDPR Art. 6(1)(c); DPA Sec. 12(c)) |
Where we rely on consent you can withdraw it at any time, and doing so is as easy as giving it. Withdrawal does not affect anything we lawfully did before you withdrew.
Our Chat Assistant ("Arky")
Arky is an AI assistant, not a person, and it says so in the chat window. It is worth being precise about what happens to what you type:
Your messages go to an AI provider. To generate a reply, the recent messages in your conversation are sent to our own server, which passes them to OpenRouter (OpenRouter, Inc., United States), which routes them to the DeepSeek model. We do not send your name or contact details as part of this step unless you typed them into the chat.
If you ask to speak to a person, the chat shows a consent step before anything is saved. If you agree, we save the name, contact detail, and note you enter together with a copy of the recent conversation so the person replying has the context. That record is stored in our database — together with the IP address and browser user-agent the submission came from, kept for abuse prevention — copied to an internal Google Sheet, and announced to our team through a Discord notification and an email. If you decline, nothing is saved.
Please do not type sensitive information into the chat. It is a sales assistant, not a secure channel. Do not share passwords, financial details, government ID numbers, or health information.
Job Applicants
If you apply for a role with us — through our careers pages at careers.rekreatedigital.com, through an application form on this website, or by email — this section explains what happens to your application. This policy covers our careers site as well as this one.
What we collect: your name, email address, phone number, the role you applied for, your CV or résumé and any portfolio or links you provide, your answers to the application questions, and anything else you choose to include.
Why: solely to assess your suitability for the role, to arrange interviews, and to communicate with you about your application. We do not use it for marketing, and we do not screen or rank applicants automatically — a person reads your application.
Who receives it: the people at Rekreate Digital involved in hiring. Technically, your application is submitted through Google Apps Script and recorded in a private Google Sheet (Google LLC) that we use to track applications, and it notifies the hiring team through a private internal Discord channel and by email. Those providers, and where they process data, are listed in the Data Sharing section below.
Spam protection: the application forms — both the one on this website at rekreatedigital.com/careers and the one at careers.rekreatedigital.com — may be protected by Cloudflare Turnstile (Cloudflare, Inc.), which checks that a real person is submitting the form rather than a bot. When it is enabled, it receives your IP address and technical signals about your browser. Cloudflare acts as our processor for this check, states that it does not use the data to build advertising profiles, and Turnstile is designed to work without tracking you across sites. We rely on our legitimate interest in keeping the forms usable.
How long: we keep unsuccessful applications for 12 months after the role is filled, so we can consider you for similar openings, and then delete them. If you are hired, your application becomes part of your employment record and is kept for as long as employment law requires. Tell us at any time if you would rather we deleted your application sooner, and we will.
Please do not send government ID numbers, bank details, photographs, marital status, health information, or other sensitive personal information with your application. We do not need it to assess you, and we will ask separately for anything genuinely required if we make you an offer.
Data Retention
We keep personal data only as long as we actually need it. In practice that means:
| What | How long we keep it |
|---|---|
| Contact and quote enquiries | 24 months from our last contact with you, then deleted |
| Chat leads and the saved conversation | 12 months from the conversation, then deleted |
| Newsletter subscribers | Until you unsubscribe, plus a short record of the unsubscribe so we do not email you again by mistake |
| Job applications (unsuccessful) | 12 months after the role is filled |
| Pageview records from our own counter | 180 days, then automatically deleted. These records contain no lasting identifier — at most a daily-rotating, non-reversible hash that cannot be traced back to you or linked across days. |
| Google Analytics data | Held by Google under our account's retention setting — no longer than 14 months (Google Analytics' maximum event-data retention) |
| Client contracts, invoices, and accounting records | For as long as Philippine tax and accounting law requires us to keep our books, currently ten years |
Where a period above is a range or depends on circumstances, we apply the shortest period that still meets the purpose and any legal obligation. You can ask us to delete your data sooner — see Your Rights.
Data Sharing and Disclosure
We do not sell your personal information and we do not share it with data brokers or advertisers. We do rely on the service providers below to run our website and our business, and this is the complete list of who actually receives visitor and enquiry data. Most act as our processors, handling data only on our instructions. Three act as independent controllers under their own privacy policies once they receive your data: Google Analytics and Google Maps (Google decides how measurement and maps data is used within the settings we choose), and TidyCal (you give it your details directly when you book a call). The table notes which is which.
| Provider | What it receives | Where |
|---|---|---|
| Supabase (Supabase, Inc.) | Our main database. Stores contact and quote enquiries, newsletter signups, and chat leads with their saved conversation — each of those records including the IP address and browser user-agent it was submitted from — plus our storage-free pageview records. Job applications do not go here; they are recorded in the private Google Sheet below. | Asia-Pacific — Singapore |
| OpenRouter (OpenRouter, Inc.) routing to DeepSeek | The messages you type to our chat assistant, in order to generate a reply. Sent from our server, never from your browser. | United States, and the model provider's own infrastructure |
| Google Sheets, Google Apps Script and Google Workspace (Google LLC) | A mirrored copy of enquiries, newsletter signups, chat leads, and job applications, used as our internal working record. Job applications are submitted through Apps Script into a private Sheet. | United States and Google's global network |
| Cloudflare Turnstile (Cloudflare, Inc.) | Optional anti-bot check on our job application forms (this site's /careers page and careers.rekreatedigital.com). When enabled, receives your IP address and technical browser signals to confirm you are a real person. Designed not to track you across sites. | Global edge network |
| Discord (Discord Inc.) | A notification to a private internal channel when a new enquiry, lead, newsletter signup, or job application arrives, including the details submitted. | United States |
| Google Workspace / Gmail (Google LLC) — our email provider | Alert emails to our team containing new enquiry and lead details, and our replies to you, sent from our own Workspace account. | United States and Google's global network |
| Cloudflare (Cloudflare, Inc.) | Sits in front of the website and our API. Sees the IP address and request details of every visit in order to deliver pages and block bots and attacks. | Global edge network, including a location near you |
| Hostinger (Hostinger International Ltd.) | Hosts the website files and our API server (api.rekreatedigital.com), and keeps standard server logs. | Website files: Indonesia (Jakarta). API server: United States (Boston). |
| Google Analytics (Google LLC) — independent controller | Website usage measurement — only if you accept analytics cookies. Receives your IP address and sets its own cookies. Google processes this data as an independent controller under its own privacy policy, within the measurement settings we choose. | United States and Google's global network |
| Google Maps (Google LLC) — independent controller | The map on our contact page — only once you accept functional cookies or press “Load map”. Receives your IP address, which Google processes as an independent controller under its own privacy policy. | United States and Google's global network |
| Cloudinary (Cloudinary Ltd.) | Serves images and videos across the site. Receives your IP address when your browser fetches them. | United States / global delivery network |
| TidyCal (TidyCal / SoloSuite) — independent controller | Only if you click through to book a call. You leave our website and give your details directly to TidyCal, which acts as an independent controller under its own privacy policy. | United States |
Beyond those providers, we may disclose personal data:
- To professional advisers such as our accountant or lawyers, where they need it and are bound by confidentiality.
- To legal or regulatory authorities where we are legally required to do so, or to establish or defend legal claims.
- To a buyer or successor if the business is sold or reorganised, in which case we will tell you and this policy will continue to apply until you are given a new one.
Client data is different. When we build or run AI systems for a client, we handle that client's own data as their processor, strictly under their written instructions and the data-processing terms in our service agreement. That data is not covered by this website policy and is never used for our own purposes, mixed between clients, or used to train AI models.
If you are in the Philippines, you may exercise your rights under the Data Privacy Act of 2012 and may lodge a complaint with the National Privacy Commission (privacy.gov.ph).
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, so we cannot guarantee absolute security.
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access and receive a copy of your personal data
- Rectify inaccurate or incomplete information
- Request deletion of your personal data
- Restrict or object to certain processing activities
- Data portability (receiving your data in a structured, machine-readable format)
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with a supervisory authority
To exercise any of these, email our Data Protection Officer at [email protected] or use the contact details below. You do not have to use any particular form of words, and we will not charge you.
We will respond within 30 days, and sooner where the law requires it. If your request is unusually complex we may need longer, in which case we will tell you why within that first 30 days. We may need to confirm who you are before acting, so that we do not disclose your data to someone else.
Under the Philippine Data Privacy Act you also have the right to data portability, the right to be informed before we process your data, the right to object, the right to damages for inaccurate, false, or unlawfully obtained data, and — for the benefit of your heirs — transmissibility of these rights.
Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.
International Data Transfers
We are based in the Philippines and we serve clients in the Philippines, the United States, and elsewhere, so personal data will cross borders. As the table above shows, several of our providers are in the United States or operate global networks.
If you are in the EU or EEA, transfers out of the EEA are made on the European Commission's Standard Contractual Clauses where the provider offers them in its data-processing terms — most of those listed above do — together with the technical measures described in Data Security. Where a provider offers additional safeguards such as EU data residency or certification under the EU–US Data Privacy Framework, we rely on those as well. One exception: Discord, which we use for internal new-enquiry notifications, does not offer a data-processing agreement or Standard Contractual Clauses. We keep what is sent there to the minimum the team needs to respond, in a private channel, and you can ask us to delete a notification about you at any time.
If you are in the Philippines, Section 21 of the Data Privacy Act keeps us accountable for personal information we transfer to a provider abroad. We remain responsible for it, and we use contractual terms requiring each provider to protect it to a comparable standard.
You can ask us for more detail about the safeguards applying to a particular transfer by contacting our Data Protection Officer.
Changes to This Privacy Policy
We update this policy when what we do changes. Any update is posted here with a new “Last Updated” date at the top.
Where a change materially affects what you agreed to — a new category of data, a new purpose, or a new recipient — we will not rely on your old answer. The cookie preferences panel reappears so you can decide again, and where we hold your email for a service you signed up to, we will tell you directly.
Philippine Data Privacy Act Compliance
We comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations. We have designated a Data Protection Officer, named in the Who We Are section above, and we implement organisational, physical, and technical measures appropriate to the personal information we hold.
Should a personal data breach occur that creates a real risk of serious harm, we will notify the National Privacy Commission and the affected data subjects within 72 hours of becoming aware of it, as required by Section 20(f) of the Act and its Implementing Rules. For data subjects in the EU and EEA, the GDPR applies the same 72-hour standard to notifying the supervisory authority (Article 33), and requires us to tell affected individuals without undue delay where the breach is likely to result in a high risk to them (Article 34).
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Rekreate Digital Marketing Services (sole proprietorship of Ryan Kyle Ocampo), trading as Rekreate Digital
Data Protection Officer: Ryan Kyle Ocampo
Email: [email protected]
Phone: +63 956 064 2329
Address: 570 Prudencio St., Rubyville Subd., Barangay 160 (Baesa), 1400 Caloocan City, Metro Manila, Philippines
If you are not satisfied with our response, you can complain to a regulator. In the Philippines that is the National Privacy Commission (privacy.gov.ph). In the EU or EEA it is the supervisory authority in the country where you live or work. We would rather you came to us first, but you are not required to.
This Privacy Policy was last updated on August 16, 2026.
