Privacy Policy
This Privacy Policy explains how INDELAF S.A. ("we", "us") collects, uses, and protects information when you use the INDELAF TECH platform ("Service"). It applies to visitors of our website and to Customers and their end users (e.g. workers, staff) who use the Service under a Customer's account.
1. Information We Collect
| Category | Examples |
|---|---|
| Account data | Name, email, phone, company, role |
| Operational data | Orders, inventory, employee records, documents you upload (Customer Data) |
| Billing data | Handled by our payment processor (Mercado Pago) — we do not store full card numbers |
| Usage data | Log-ins, device/browser info, pages visited, push-notification tokens |
2. How We Use Information
- To provide, maintain, and secure the Service (including multi-tenant data isolation between different companies).
- To process payments and manage subscriptions, through Mercado Pago.
- To send notifications you've opted into (order status, approvals, reminders) via push notifications, WhatsApp, or email.
- To power AI-assisted features (e.g. reading a receipt photo, answering questions about your data) — these requests are processed by our AI provider, Anthropic, solely to generate the response, and are not used to train their models under our commercial agreement.
- To improve the Service and fix issues, using aggregated or de-identified data where possible.
3. Who We Share Information With
We do not sell personal information. We share data only with service providers ("subprocessors") who help us run the platform, under confidentiality obligations:
- Render, Neon & Cloudflare — application hosting, database, and file storage, respectively.
- Anthropic — processes content you submit to AI-assisted features (e.g. photos of receipts, chat questions) to generate a response.
- Mercado Pago — processes subscription payments via its hosted checkout; we never see full card data.
- Meta (WhatsApp Business Platform) — only if a Customer enables automatic WhatsApp delivery of documents (e.g. payroll receipts) to their own employees.
We may also disclose information if required by law or to protect the rights, safety, or property of INDELAF S.A., our Customers, or others.
4. Data Isolation Between Companies
The Service is multi-tenant: each Customer's data is logically isolated and access-controlled so that one company cannot see another company's data. Within a Customer's account, what an individual user (e.g. a worker) can see depends on the roles and permissions configured by that Customer's administrator.
5. Data Retention
We retain Customer Data for as long as the account is active. If a subscription is cancelled, we retain data for a reasonable period to allow export, after which it is deleted, except where retention is required by law (e.g. accounting records).
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to certain processing. If you are an employee of one of our Customers, please contact that company's administrator first, as they control the account; if you are a Customer, contact us directly at the email below.
7. Cookies
Our marketing website uses minimal cookies/local storage to remember your language preference and, where applicable, basic analytics. The Service application uses local storage to keep you logged in and remember your preferences (e.g. language, dark mode).
8. Security
We use industry-standard measures to protect data, including encrypted connections, hashed credentials (passwords and PINs are never stored in plain text), and access rules that restrict data to the company and role it belongs to. No system is 100% secure, and we encourage Customers to use strong, unique passwords.
9. International Transfers
Our infrastructure providers (Render, Neon, Cloudflare, Anthropic, Mercado Pago) may process data in countries other than yours, including the United States. Where required, we rely on the safeguards those providers offer for international data transfers.
10. Contact
Questions about this Privacy Policy or requests regarding your data can be sent to hola@indelaftech.com.
This document is a general template and does not constitute legal advice. We recommend having it reviewed by a lawyer familiar with data protection laws in the jurisdictions where your customers are located (e.g. state-level US privacy laws, PIPEDA in Canada).