1. Data controller
IT CLOUD PROVIDER S.A.S., tax ID (NIT) 901275682-1, with address at CL 58 SUR 66 11, Bogotá, Colombia (hereinafter IT-Cloud), is the controller of the personal data described in this policy.
Contact for personal-data matters: itcloud@it-cloud.com.co
This policy is governed by Colombian Law 1581 of 2012, Decree 1377 of 2013 and the other Colombian personal-data protection rules.
2. Two distinct roles
They are worth separating because the obligations differ:
- Client account data (the owner or manager who uses the application): IT-Cloud acts as the controller.
- Data generated by the sensors installed in the client's property: IT-Cloud acts as the processor, handling it on behalf of and under the instructions of the client, who decides to install the sensors and answers to the people occupying the property.
If guests stay at the property, informing them that sensors exist is the client's responsibility.
3. What data is processed
3.1 Account data
| Data | Purpose | How it is stored |
|---|---|---|
| Email address | sign-in identifier and alert delivery | in the clear (it is the access key) |
| Password | authentication | never stored: only an irreversible Argon2id hash |
| Second factor (MFA) | two-step verification, mandatory for every account (section 7) | secret encrypted |
| Secondary email (optional) | copy of the alerts | encrypted |
| Telegram identifier (optional) | Telegram alerts | encrypted |
| Mobile device token | push notification delivery | encrypted |
3.2 Sensor data
Depending on the equipment installed: people counting and occupancy, temperature, noise level, door opening and closing, water-leak detection, electricity consumption and socket state, and each device's battery level.
3.3 Security data
An audit log of sensitive actions (sign-ins, configuration changes, administrative actions) together with the IP address they were performed from. It exists so that improper access can be investigated, and it is unalterable by design: it cannot be modified or deleted.
3.4 What is NOT processed
- Phone location. The application neither requests nor uses it.
- Biometric data. Fingerprint or face unlock is verified by the phone's own operating system; the application only receives a yes or a no, and never accesses the fingerprint.
- Third-party advertising and analytics. There is no SDK of that kind.
- The property's street address. Properties are identified by an alias the client chooses (e.g. "Apt 101"), not by their address.
4. What it is used for
Only to provide the service: authenticating access, showing sensor status and history, sending alerts by email, Telegram or push notification, producing the property's weekly report (section 4.1), handling support, billing the service and maintaining the security of the platform.
It is not sold, transferred for commercial purposes, or used for advertising.
4.1 The weekly report
Each week the system may produce a written summary of what happened at the property and make it available to the client in their dashboard. It is worth explaining precisely how, because an artificial-intelligence provider is involved and that deserves to be said plainly.
The facts are computed by our own code, not by the model. The noise averages, occupancy hours, door openings, consumption and the indications flagged are obtained by arithmetic over the stored readings. The model receives that already-computed result and its only job is to write it up in Spanish. It does not decide what happened, does not interpret conduct, and has no access to the original readings.
What is sent to the provider: aggregate figures for the week (occupancy, noise, temperature, electricity consumption, number of door openings), the property's alias and the label the client gave each sensor.
What is NOT sent: no name, email, phone number or identity document of any person; no individual reading; no account data; and nothing belonging to another client. The system stores no guest names or contacts, so no such data exists that could be sent.
The report is not an automated decision with effects on anyone: it is a description of what the sensors measured, written in an advisory tone, which the client reads and judges for themselves. The text is forbidden from asserting conduct or identifying people.
How it is delivered: the report is always available in the dashboard and is also emailed to the client on the day and at the hour they choose. Delivery can be paused for a while or switched off entirely; the report is still produced and still readable in the dashboard, it simply does not reach the inbox. The client may also name up to three additional addresses — a co-host, an administrator — which receive the same copy; those addresses are chosen and managed by the client, and are stored encrypted.
The client can turn the weekly report off at any time from the "IA Insights" section of their dashboard, without affecting the rest of the service.
5. Who it is shared with
Only with the providers needed to operate, and only with what is indispensable:
| Provider | Country | Purpose | What it receives |
|---|---|---|---|
| Hostinger | United States | server hosting | the data resides there |
| Resend | United States | sending alert emails and the weekly report | recipient address and the alert or report text |
| Google (Firebase) | United States | push notifications | device token and alert text |
| Google (Drive) | United States | custody of the backups | an encrypted file the provider cannot open (section 5.1) |
| Google (Gemini API) | United States | writing the weekly report | aggregate figures for the week and the aliases of the property and its sensors (sections 4.1 and 5.2) |
| Telegram | outside Colombia | Telegram alerts, only if the client enables it | chat identifier and text |
These providers operate outside Colombia, so there is an international transfer of data, supported by the need to perform the contracted service. Alert messages are written without personal data: they identify the sensor and the property by its alias.
The server hosting the service is located in a datacenter in Boston, United States. In the case of Telegram, the integration is not enabled by default: the client enables it expressly and voluntarily from the application, and may disable it at any time; that act is what authorises sending their alerts to that service.
Data may also be handed over to authorities when required by a judicial or administrative order.
5.1 Backups
A daily backup of the complete database is generated so the service can be restored after a failure or a loss of information. The backup includes everything described in section 3, the audit log included.
The backup is encrypted before it leaves the server, using a public-key scheme: the server holds only the key that encrypts, while the key that decrypts is kept offline and is never installed on it. The provider storing it — Google Drive — therefore receives a file it cannot open, and a third party who gained access to the server could not read previous backups either.
Backups are kept for thirty (30) days at the external provider and the seven (7) most recent on the server itself; after that they are deleted automatically. The effect of this on the retention periods is explained in section 6.
5.2 The artificial-intelligence provider
The weekly report is written with Gemini, from Google, contracted on its paid tier. That distinction is not an administrative detail: on the free tier Google reserves the right to use submitted content to improve its products and to have it reviewed by people. On the paid tier we use, the content is not used to train or improve its models, and is not incorporated into them.
The transfer happens once per week and per property. What travels are the aggregate figures described in section 4.1 — never individual readings, never account data, never information belonging to another client.
6. How long it is kept
| Data | Retention |
|---|---|
| Readings that may reveal presence (occupancy, doors) | 30 days |
| Other detailed readings | 90 days |
| Hourly summaries (average, minimum, maximum) | 13 months |
| Weekly reports (section 4.1) | for as long as the property exists in the account |
| Account data | for as long as the service is active |
| Audit log | indefinitely, given its evidentiary nature |
Deletion of readings is automatic and continuous: it does not depend on anyone requesting or running it.
Weekly reports are deleted along with the property they describe. That is deliberate: a report describing a home no longer in the account is information with nobody left to answer for it. Deleting it costs the historical trail, and that price seems the right one.
6.1 The effect of backups
The periods in the table above are those of the database in use. A backup is a snapshot of the state on the day it was taken, so data already deleted from the database still exists inside backups made before that deletion, until those backups are removed after thirty (30) days.
The real maximum is therefore the period in the table plus thirty days:
| Data | In the live database | Maximum, counting backups |
|---|---|---|
| Readings that may reveal presence | 30 days | 60 days |
| Other detailed readings | 90 days | 120 days |
| Hourly summaries | 13 months | 13 months and 30 days |
Throughout that margin the information remains encrypted and would only be readable by restoring a backup — something only IT-Cloud can do, with the key it keeps offline, and only to recover the service.
6.2 Who can consult the audit log
The log contains IP addresses, so access to it is restricted:
- The client can consult their own history from the application, and that history does not show IP addresses; nor can they see any other client's activity.
- No other user of the application can read it: no screen or feature exposes it. From the application, IT-Cloud staff can only check that the log has not been tampered with, without seeing its contents.
- IP addresses are only reachable through direct technical access to the database, restricted to IT-Cloud infrastructure staff and subject to the server credentials, which are held under restricted custody.
The log is also unalterable by design: it cannot be modified or deleted by any means, and each entry is cryptographically chained to the previous one, so any attempt at tampering becomes evident.
7. How it is protected
- All traffic travels encrypted (HTTPS/TLS).
- Passwords are stored as an Argon2id hash; nobody at IT-Cloud can read them.
- Second factor mandatory for every account.
- The sensitive fields in section 3.1 are stored encrypted.
- Isolation between clients enforced by the database engine itself: no client can see another's data, not even if the application had a bug.
- Administrative actions require re-verification of the second factor and are audited.
8. Rights of the data subject
Under Law 1581 of 2012, any person may access, update, rectify and delete their personal data, request proof of the authorisation, be informed of the use made of it, file complaints with the Superintendencia de Industria y Comercio (the Colombian data-protection authority), and revoke the authorisation.
To exercise them, write to itcloud@it-cloud.com.co stating the name, the account email and the specific request. It will be answered within the legal periods: ten (10) business days for enquiries and fifteen (15) business days for complaints, extendable as provided by law.
9. Deleting the account and the data
The application does not allow the account to be deleted from the device itself. To request it, write to itcloud@it-cloud.com.co from the registered email address.
When the request is processed, the account, its contact details, its registered devices and its sensor readings are deleted. Only the audit log is retained, because it is unalterable and necessary as security evidence, along with any information that must be kept by legal or accounting obligation.
10. Minors
The service is aimed at adults who manage properties. Data on minors is not knowingly collected.
11. Changes
Any substantial change will be communicated to clients at the registered email address at least fifteen (15) days in advance. The date of the last update appears at the top.
12. Contact
IT CLOUD PROVIDER S.A.S. · NIT 901275682-1 · CL 58 SUR 66 11, Bogotá, Colombia itcloud@it-cloud.com.co