Seika Personal Data Processing Policy
Version 0.2 · Last updated: September 25, 2026
This policy is prepared under Colombian Law 1581 of 2012, Decree 1074 of 2015 (which compiles Decree 1377 of 2013) and other Colombian rules, and is aligned with international data-protection principles (e.g. Regulation (EU) 2016/679, "GDPR", and its United Kingdom equivalent). The Spanish version prevails in case of discrepancy.
1. Data controller
COROZO S.A.S., address Calle 43 # 27 - 161, Santa Marta, Magdalena, Colombia. Channel to exercise your rights: soporte@seikaapp.com. Responsible area: Product Management.
We act in two roles:
- Controller of your Seika account data (identity, authentication, security, preferences, subscription and support).
- Processor of the customer, appointment and team data that each business records in its calendar: the business is the controller of that data toward its customers and we process it on its behalf and under its instructions. If you are a business's customer, you may also contact that business.
In addition, Paddle.com (Paddle), the Merchant of Record that processes payments for plans and add-ons, is an independent controller of billing and payment data (see section 7).
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Identification and contact | First name and surnames, email, phone when the business records it | You or the business |
| Account and authentication | Password (only its protected form is stored), sign-in provider (Google), verifications and OTP codes | You |
| Time zone and country | The time zone and country of your account and of your business; used to show times, apply the book-within-the-same-country rule and calculate taxes | You |
| Appointment use | Business, service, dates and times, status, cancellation reasons, notes | You or the business |
| Subscription | Plan, status, renewal or trial-end dates, transaction and subscription identifiers, billing country, free-trial use | You and Paddle |
| Sessions and devices | Browser and system (User-Agent), approximate location (country/city), last activity. We do not store your IP address in your profile | Automatic |
| Technical and security | Request identifiers, security events, error logs | Automatic |
| Communications | Support and contact messages | You |
We do not request sensitive data (health, ethnic origin, orientation, biometrics, etc.). If a business records sensitive data in notes, it is responsible for holding any authorization the law requires; we recommend not including it. We do not receive or store card data: payment data (card, billing address, tax identification) is collected directly by Paddle. If we need other personal data for billing in the future, we will inform you and ask for your specific authorization.
Minors: the Service is for people aged 18 or over. We do not knowingly process minors' data; if we detect a minor's account, we will close it.
3. Purposes
- Create and manage your account, verify your identity and protect access.
- Let you schedule, confirm, reschedule, cancel and attend appointments.
- Send operational messages: codes, confirmations, reminders, plan-usage and subscription notices, and security notices.
- Ensure security, prevent fraud and abuse (including repeated use of the free trial) and keep audit trails.
- Manage your subscription: apply your plan's limits and rights and reflect what Paddle confirms about payments, refunds and disputes.
- Handle support requests, petitions, complaints and claims.
- Generate aggregated operating metrics for the business and improve the Service.
- Comply with legal, accounting and tax obligations and respond to requirements from competent authorities.
- With your separate express authorization: send commercial communications or news.
We do not sell your personal data and do not use it for automated decisions with legal effects on you.
4. Authorization and legal basis
We process your data with your prior, express and informed authorization, given by ticking the acceptance box when you register, activate an invitation or book. We record the version of this policy you accepted and when. Using Google Sign-In does not imply authorization by itself: we always ask for express acceptance. Data strictly necessary to perform the contract or comply with the law is processed without relying on your consent to the extent the rules allow. For people under the GDPR, the bases are performance of the contract, compliance with legal obligations, consent where requested, and our legitimate interest in security and in preventing fraud and abuse.
5. Free trial: email fingerprint
Each email address is entitled to a single free trial in its lifetime. To enforce this we store a one-way cryptographic fingerprint of the normalized email (not the readable email). That fingerprint is kept even if you delete your account, for a single purpose: preventing abuse of the trial. The basis is our legitimate interest in preventing fraud and abuse. If you try to start a second trial, we will tell you with a clear message.
6. Your rights
Under article 8 of Law 1581 of 2012 (and, where applicable, the GDPR), you may:
- Know, update and correct your data.
- Request proof of the authorization given.
- Be informed about how your data has been used.
- File complaints with the Superintendence of Industry and Commerce (SIC) for infringements, after going through us first.
- Revoke the authorization and/or request deletion of your data when principles are not respected or there is no legal or contractual duty to keep it.
- Access your data free of charge.
- Where the GDPR applies: portability, restriction and objection, and lodging a complaint with your local supervisory authority.
Before deleting your account you can download your data as a JSON file from "Account".
How to exercise them: write to soporte@seikaapp.com stating your identity and request. Queries are answered within 10 business days and claims within 15 business days (extendable as the law allows). We may ask for information to verify your identity. For payment data held by Paddle, you may also contact Paddle under its privacy notice.
7. Paddle, Merchant of Record and independent controller
Payments for plans and add-ons are processed by Paddle.com, our online reseller and Merchant of Record. Paddle is an independent controller of the billing and payment data it collects to sell, charge, calculate taxes, issue receipts, refund and handle disputes; it processes them under its own privacy policy. COROZO is the controller of your account and Service data.
- What we send to Paddle: the business identifier, the owner's contact email and the country.
- What we receive from Paddle: the subscription status, the transaction and subscription identifiers, and the country; never card data.
8. Retention and account deletion
We keep data while you have an account or the business needs it for its operational history, and for as long as the law or the defense of rights requires. Sessions and their device data are deleted when the session expires or is closed.
Account deletion: when you request it, the account stays 30 days in grace (you can reactivate it by signing in); after that we permanently delete your identity, sign-in providers, encrypted email, sessions, notifications, memberships and customer relationships and, if you chose so, your business and its team. In other businesses' records your name is replaced with "Deleted customer" so as not to break their history.
What is kept after deletion, without readable personal data: (a) the free-trial fingerprint (section 5); (b) transaction and subscription identifiers, for the period required by Colombian accounting and tax rules; and (c) aggregated metrics.
9. Processors, providers and international transfers
To operate Seika we use providers that process data on our behalf, under contracts requiring confidentiality and security:
- Amazon Web Services (hosting, database, queues and infrastructure messaging), United States region.
- Vercel Inc. (web-app hosting and aggregated analytics), United States.
- Cloudflare, Inc. (network, security and Turnstile anti-bot verification), United States.
- Resend (transactional email delivery), United States.
- Google LLC (Google sign-in, when you choose it), United States.
- Paddle.com (payments; independent controller, section 7), with international operations.
This involves international transfer and/or transmission of data to countries that may not offer a level of protection equivalent to Colombia's. We do so with your authorization (article 26 of Law 1581) and, where applicable, through data-transmission contracts and standard contractual clauses or other appropriate safeguards equivalent to those of the GDPR. Beyond these providers, we share data only with authorities when the law requires it, with the business you book with, and with whomever you authorize.
10. Security
We apply reasonable technical and organizational measures: encryption in transit, passwords protected with strong algorithms, expiring and rotating sessions, isolation between businesses, role-based access control, audit logs and anti-abuse controls. No system is infallible; if an incident affects your data, we will act as the law requires and, where applicable, notify you and report to the SIC.
11. Cookies and similar technologies
We use cookies and local storage as explained in the Cookie Policy, where you can manage your preferences.
12. National Database Registry
Our databases will be registered or updated in the SIC's National Database Registry (RNBD) when the law requires.
13. Users outside Colombia
If you access from another country, your data is processed in Colombia and in our providers' countries. We respect the non-waivable rights your local law grants you, including those under the GDPR for people in the European Economic Area and the United Kingdom. We do not sell or share personal information for cross-context behavioral advertising (including for purposes of California law).
14. Changes to this policy
If it changes materially, we will notify you and, where the law requires, ask for new authorization. The current version and date are at the top.
15. Contact
COROZO S.A.S.
Calle 43 # 27 - 161, Santa Marta, Magdalena, Colombia
Queries and data-subject rights: soporte@seikaapp.com
Support: soporte@seikaapp.com