Seika Personal Data Processing Policy
Version 0.1 (draft) · Last updated: September 21, 2026
Document status: draft. Items in square brackets [ ] are to be completed by COROZO S.A.S., and a lawyer must review it before publication. This policy is prepared under Colombian Law 1581 of 2012, Decree 1074 of 2015 (which compiles Decree 1377 of 2013) and other Colombian rules, and is aligned with international data-protection principles (e.g. Regulation (EU) 2016/679, "GDPR"). The Spanish version prevails in case of discrepancy.1. Data controller
COROZO S.A.S., tax ID [NIT], address [ADDRESS]. Channel to exercise your rights: [PRIVACY_EMAIL]. Responsible area: [AREA_OR_ROLE].
We act in two roles:
- Controller of your Seika account data (identity, authentication, security, preferences, support).
- Processor of the customer, appointment and team data that each business records in its calendar: the business is the controller of that data toward its customers and we process it on its behalf and under its instructions. If you are a business's customer, you may also contact that business.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Identification and contact | First name and surnames, email, phone when the business records it | You or the business |
| Account and authentication | Password (only its protected form is stored), sign-in provider (Google), verifications and OTP codes | You |
| Appointment use | Business, service, dates and times, status, cancellation reasons, notes | You or the business |
| Sessions and devices | Browser and system (User-Agent), approximate location (country/city), last activity. We do not store your IP address in your profile | Automatic |
| Technical and security | Request identifiers, security events, error logs | Automatic |
| Communications | Support and contact messages | You |
We do not request sensitive data (health, ethnic origin, orientation, biometrics, etc.). If a business records sensitive data in notes, it is responsible for holding any authorization the law requires; we recommend not including it. If identity documents, address or other billing data are required in the future, we will inform you and ask for your specific authorization.
Minors: the Service is for people aged 18 or over. We do not knowingly process minors' data; if we detect a minor's account, we will close it.
3. Purposes
- Create and manage your account, verify your identity and protect access.
- Let you schedule, confirm, reschedule, cancel and attend appointments.
- Send operational messages: codes, confirmations, reminders and security notices.
- Ensure security, prevent fraud and abuse and keep audit trails.
- Handle support requests, petitions, complaints and claims.
- Generate aggregated operating metrics for the business and improve the Service.
- Comply with legal obligations and respond to requirements from competent authorities.
- With your separate express authorization: send commercial communications or news.
We do not sell your personal data and do not use it for automated decisions with legal effects on you.
4. Authorization / legal basis
We process your data with your prior, express and informed authorization, given by ticking the acceptance box when you register, activate an invitation or book. We record the version of this policy you accepted and when. Using Google Sign-In does not imply authorization by itself: we always ask for express acceptance. Data strictly necessary to perform the contract or comply with the law is processed without relying on your consent to the extent the rules allow (GDPR: contract, legal obligation and legitimate interest).
5. Your rights
Under article 8 of Law 1581 of 2012 (and, where applicable, the GDPR), you may:
- Know, update and correct your data.
- Request proof of the authorization given.
- Be informed about how your data has been used.
- File complaints with the Superintendence of Industry and Commerce (SIC) for infringements, after going through us first.
- Revoke the authorization and/or request deletion of your data when principles are not respected or there is no legal or contractual duty to keep it.
- Access your data free of charge.
- Where the GDPR applies: portability, restriction and objection, and lodging a complaint with your local supervisory authority.
How to exercise them: write to [PRIVACY_EMAIL] stating your identity and request. Queries are answered within 10 business days and claims within 15 business days (extendable as the law allows). We may ask for information to verify your identity.
6. Retention
We keep data while you have an account or the business needs it for its operational history, and for as long as the law or the defense of rights requires. Sessions and their device data are deleted when the session expires or is closed. When you close your account, we delete or anonymize data that need not be kept. [RETENTION_PERIODS]
7. Processors, providers and international transfers
To operate Seika we use providers that process data on our behalf, under contracts requiring confidentiality and security:
- Amazon Web Services (hosting, database, queues and infrastructure messaging), United States region.
- Vercel Inc. (web-app hosting and aggregated analytics), United States.
- Cloudflare, Inc. (network, security and Turnstile anti-bot verification), United States.
- Resend (transactional email delivery), United States.
- Google LLC (Google sign-in, when you choose it), United States.
This involves international transfer and/or transmission of data to countries that may not offer a level of protection equivalent to Colombia's. We do so with your authorization (article 26 of Law 1581) and, where applicable, through data-transmission contracts and standard contractual clauses. Beyond these providers, we share data only with authorities when the law requires it, with the business you book with, and with whomever you authorize.
8. Security
We apply reasonable technical and organizational measures: encryption in transit, passwords protected with strong algorithms, expiring and rotating sessions, isolation between businesses, role-based access control, audit logs and anti-abuse controls. No system is infallible; if an incident affects your data, we will act as the law requires and, where applicable, notify you and report to the SIC.
9. Cookies and similar technologies
We use cookies and local storage as explained in the Cookie Policy, where you can manage your preferences.
10. National Database Registry
Our databases will be registered or updated in the SIC's National Database Registry (RNBD) when the law requires. [RNBD_REGISTRATION_NUMBER]
11. Users outside Colombia
If you access from another country, your data is processed in Colombia and in our providers' countries. We respect the non-waivable rights your local law grants you. We do not sell or share personal information for cross-context behavioral advertising (including for purposes of California law).
12. Changes to this policy
If it changes materially, we will notify you and, where the law requires, ask for new authorization. The current version and date are at the top.
13. Contact
COROZO S.A.S. · [ADDRESS] · [PRIVACY_EMAIL]