Privacy policy
Introduction
At FLOE, we understand that access to personal data and to information related to our Users' digital activity is not an unrestricted right, but rather a responsibility that we undertake with the highest degree of diligence, security, and transparency.
Our business model is based on the provision of technology services and digital analysis. We do not rely on the commercialization of personal data or intrusive advertising schemes.
The processing of personal data is limited to what is strictly necessary to provide the Services, operate the Platform, ensure its security, and comply with legal obligations.
We do not sell or commercialize Users' personal data.
We implement reasonable technical and organizational measures to protect information and minimize risks.
1. Identification of the controller
This Privacy Policy governs the processing of personal data carried out through the FLOE website, the FLOE application and/or digital platform, and the services offered through those environments.
The controller of personal data is FLOE SRL, Tax ID 30-71938562-8, acting in accordance with the laws in force in the Argentine Republic.
The Controller reserves the right to modify this Privacy Policy at any time. Updated versions will be available on the Platform, indicating the date of the latest update.
2. Scope, acceptance, and sources of information
Access to, registration with, browsing of, and use of the Platform implies that the User has read, understood, and accepted this Privacy Policy.
The User declares that the data provided is truthful, accurate, and up to date, and undertakes to keep it properly updated throughout the relationship with the Platform.
The Platform is mainly based on the analysis of technical information and data provided directly by the User or publicly available on the internet.
Where necessary for the provision of the Services, the Controller may obtain personal data through third parties, always in accordance with applicable law and on the basis of a valid legal basis.
Such sources may include, among others:
- Technology or infrastructure providers necessary for operation of the Platform.
- Analytics, measurement, or technical monitoring tools regarding use of the Platform.
- Integrations with digital services that the User chooses to connect.
- Publicly available information on websites or digital environments, to the extent access to such information is lawful and does not imply breach of legal or technical restrictions.
3. Applicable legal framework
Processing of personal data shall be governed by the laws in force in the Argentine Republic, including:
- Law 25,326 on Personal Data Protection.
- Regulatory Decree 1558/2001.
- Provisions and criteria issued by the Agency for Access to Public Information.
The Company undertakes to process personal data in accordance with the principles of legality, fairness, purpose limitation, proportionality, quality, security, and confidentiality.
4. Scope of processing
This Policy applies to all processing of personal data carried out through the Platform, including that arising from the use of automated functionalities, artificial intelligence systems, technical analysis tools, and interaction mechanisms such as chatbots.
The Company may act:
- As controller, with respect to data necessary to manage the relationship with the User and operate the service; and/or
- As processor, when processing data on behalf of its clients within the framework of the contracted services.
In all cases, personal data processing shall be carried out in accordance with the principles established by applicable law.
5. Personal data collected
The categories of data that may be processed include:
5.1 Identification and account data
- User's full name.
- Email address.
- Access and authentication information.
- Account, profile, and configuration data.
- Information related to roles, permissions, and membership in tenants or clients.
5.2 Organizational and management data
- Information about tenants, clients, and organizational structures created within the Platform.
- Internal account, client, and license identifiers.
- Configuration of plans, quotas, usage limits, and resource allocations.
5.3 Operational and Platform usage data
- Number of users, chatbots, conversations, and active licenses.
- Chatbot configuration.
- System usage data, including actions taken and navigation within the Platform.
- Event and audit log records.
5.4 Technical and security data
- Technical system operation logs.
- Session identifiers.
- Device and authentication information.
- Security records, including two-factor authentication where applicable.
- Information related to active sessions.
5.5 Integration-related data
- Information derived from integrations enabled by the User with third parties.
- Data necessary for the connection and operation of such integrations.
5.6 Contact and communications data
- Information provided through contact forms.
- Inquiries, requests, or messages sent by the User.
- History of communications with the Company.
5.7 Information analyzed by the Platform
- Websites indicated by the User for analysis.
- Technical and structural information of those websites.
- Data obtained through automated technical analysis processes, exclusively on public and accessible information.
5.8 Conversation-related data
Where chatbot functionalities are used, conversations may be stored within the client's environment. The Company does not access or analyze their content except to the extent strictly necessary for the technical operation of the service.
5.9 Exclusion of sensitive data
The Platform is not intended to collect or process sensitive data, unless such processing is strictly necessary, exceptional, and supported by a valid legal basis.
6. Legal basis for processing
The processing of personal data carried out through the Platform is based on valid legal grounds under Law 25,326 and complementary regulations.
In particular, processing may be based on:
- The data subject's consent, where applicable.
- Performance of a contractual relationship, where processing is necessary for provision of the Services offered through the Platform.
- The Controller's legitimate interest, provided that the rights and safeguards of the data subject are not adversely affected.
- Compliance with legal obligations, where processing is required by applicable law or by requests from competent authorities.
7. Purpose of processing
Personal data shall be processed by the Company for the following purposes:
- To provide, operate, maintain, and improve the Services offered, including account, access, configuration, and functionality management.
- To generate analyses, reports, metrics, and insights through the use of technological tools and automated systems.
- To ensure the proper technical functioning, availability, integrity, and security of the Platform.
- To manage the relationship with Users, including support, communications, and operational management.
- To prevent misuse, fraud, unauthorized access, or any activity contrary to these Terms.
- To comply with legal, regulatory, or competent authority requirements.
8. Logs and technical records
In order to ensure the security, integrity, and proper functioning of the Platform, the Company may generate and process technical logs, operational records, and system activity traces.
Such records shall have a limited retention period that shall in no case exceed forty-eight hours, unless it is necessary to extend such period for security reasons, incident detection, or compliance with legal obligations.
Logs shall be used exclusively for technical, security, audit, and service operation purposes.
9. Conversations and chatbot tools
If the Platform includes chatbot functionalities or other automated interaction tools:
- Conversations generated may be stored within the client's environment, depending on the service configuration and the tools used.
- The Company does not access or analyze the content of such conversations except to the extent strictly necessary to ensure the technical functioning of the service, incident resolution, or compliance with legal obligations.
- Under no circumstances shall conversations be used for purposes other than those for which they were generated, nor for training artificial intelligence models, unless expressly authorized in writing by the client.
10. Deletion and retention of data
The User may request deletion of their account and associated personal data at any time.
In such case, the Company shall, within a reasonable period and in accordance with applicable law:
- Delete or anonymize the personal data associated with the User.
- Delete chats, records, configurations, and any information related to the account.
- Delete technical logs, respecting the maximum retention periods established.
However, the Company may retain certain information on a limited basis where:
- There is a legal or regulatory retention obligation.
- It is necessary for the defense of rights in administrative or judicial proceedings.
- It concerns previously anonymized, non-identifiable data.
11. Rights of the data subject
The personal data subject may exercise at any time the rights recognized by applicable law, including:
- Right of access.
- Right of rectification.
- Right of update.
- Right of erasure.
For such purposes, the User must send a request through the contact channels indicated by the Company, proving their identity in accordance with applicable law.
The Company undertakes to respond to such requests within the time limits established by Law 25,326 and complementary regulations.
Likewise, Users are informed that the Agency for Access to Public Information, in its capacity as supervisory authority, has the power to address complaints and claims related to breaches of personal data protection regulations.
12. Automated decisions and use of artificial intelligence
The Platform uses automated systems and artificial intelligence for purposes of analysis, report generation, recommendations, and insights.
It should be noted that such systems:
- Do not adopt automated decisions that produce direct legal effects on the User.
- Do not generate automated profiles with significant impact on the rights of the data subject.
- Operate as support tools, without replacing human judgment or the User's decision-making.
The User acknowledges that the results generated by the Platform are informative and advisory in nature and must be evaluated according to their own context and professional judgment.
13. International transfers of data
The Company does not carry out international transfers of personal data within the framework of the provision of the Services.
Should it become necessary in the future to carry out international transfers for the operation of the Platform, such transfers shall be performed in accordance with applicable law, ensuring adequate levels of personal data protection and adopting the corresponding legal and contractual measures.
14. Information security and cybersecurity
The Company implements reasonable technical and organizational measures aimed at ensuring the security of information processed through the Platform, in line with best-practice cybersecurity standards.
In particular, measures are adopted to protect information against unauthorized access, loss, alteration, or improper disclosure, including:
- Authentication and access control mechanisms.
- Session and credential management.
- Activity and audit records.
- Protective measures over the technological infrastructure.
These measures are aligned with the principles of confidentiality, integrity, and availability.
Nevertheless, the User acknowledges that no computer system is completely secure.
15. Checkout reachability check
When the hosted billing single-sign-on flow is enabled, the Platform may perform a limited browser-side reachability check against `https://www.googletagmanager.com/gtag/js?id=<canary-id>` to detect whether a content blocker is preventing the billing handoff helper from loading. This check is used only to warn the User before opening checkout, does not collect message content or other personal data, and does not persist any database record by itself. If telemetry is enabled for this flow, the Platform only sends the authenticated Scarlett user id together with a coarse technical result (`PASS`, `FAIL`, or `UNKNOWN`) and basic browser family metadata needed to measure the operational impact of blocked billing handoffs.
15. User responsibility regarding security
Without prejudice to the measures adopted by the Company, the User assumes responsibility for maintaining the security of their access to the Platform.
In particular, the User undertakes to:
- Maintain the confidentiality of their access credentials.
- Not share, assign, or allow use of their credentials by third parties.
- Use strong passwords and adopt good security practices.
- Properly protect the devices from which they access the Platform.
- Immediately notify the Company of any unauthorized use, suspected improper access, or security incident.
16. Third-party links
The Platform may contain links, integrations, or references to third-party websites, services, or platforms.
The Company does not control, supervise, or bear responsibility for:
- The content, functioning, or availability of such websites or services.
- The privacy policies or data processing practices of third parties.
- Any damages or losses that may result from their use.
Access to such websites or services is at the User's sole responsibility.
17. Modifications
The Company reserves the right to modify this Privacy Policy at any time.
Modifications shall enter into force upon publication on the Platform.
18. Contact and notices
For any inquiry, request, complaint, or communication related to this Privacy Policy, as well as for the exercise of data protection rights, the User may contact the Company through the following means:
- Email: [email protected]
- Channels enabled within the Platform.
Communications sent by the User through such means shall be considered valid for all legal purposes, provided that they reasonably identify the sender.
Likewise, the User expressly accepts that the Company may send operational, legal, or informational notices related to the service and to the processing of personal data through:
- The email address provided by the User.
- Notifications within the Platform.
- Other suitable electronic means.
In personal data protection matters, the User may exercise their rights of access, rectification, update, and erasure by sending a request to the email address indicated above and proving their identity in accordance with applicable law.