Privacy Policy
How we collect, use and protect personal data of those who use the KAIXO application.
Index
1. Data controller and KAIXO ownership
The KAIXO application is the intellectual property of Víctor Manuel Lasheras Benito. Its commercialization, operation and provision of services to users are carried out by Ideia Soluciones Tecnológicas S.A.C., under an exclusive license granted by the rights holder.
The data controller of personal data collected through the KAIXO application is:
Ideia Soluciones Tecnológicas S.A.C.
Tax ID (RUC): 20610917586
Registered address: Panamericana Norte Km 164, Végueta, Huaura, Lima, Peru
Legal representative: Víctor Manuel Lasheras Benito
Contact: [email protected]
2. Data we collect
We only collect the data essential for KAIXO to function and to comply with applicable legal obligations.
2.1. Data you provide directly
- Account data: phone number, name or alias, password (stored as bcrypt hash), preferred language, country.
- Profile picture: optional.
- Communication content: messages, audio, photos, videos, calls and posts on Mundo (Latidos). Stored encrypted.
- Verification documents: if you request creator or business verification. Deleted after the verification decision.
- Payment data: handled directly by Stripe. KAIXO never stores the full card number.
2.2. Data generated during use
- Technical identifiers: session token, device identifier for push notifications, operating system, app version.
- Logs: timestamps, IP address, endpoints. Anonymized or deleted within 30-90 days.
- Activity metrics: number of messages, calls, translations. Required for technical management and paid plans.
2.3. Data temporarily processed for AI translation
- Audio you send to KAIXO Direct and text to be translated are transmitted to external AI services (section 5) only for the time strictly necessary to return the response. Afterwards, KAIXO discards the data.
3. Processing purposes
- Providing the service (chats, calls, translation, Mundo, CRM, KAIXO Direct).
- Authenticating the user and protecting the account.
- Processing payments and managing subscriptions.
- Verifying identity or business when requested.
- Sending technical notifications and, with consent, commercial ones.
- Complying with legal obligations (taxation, judicial requests).
- Detecting and preventing abuse and fraud.
- Improving the product based on aggregated and anonymous metrics.
4. Legal basis
| Type of data | Legal basis |
|---|---|
| Account data and communication content | Contract performance (Terms of Service) |
| Verification documents | Explicit user consent |
| Payment data | Contract performance + legal obligation (invoice) |
| Logs and metrics | Legitimate interest (security and service improvement) |
| Commercial communications | Consent (revocable) |
5. Third-party services (processors)
To provide KAIXO we use specialized vendors acting as data processors. We have signed the corresponding data processing agreements:
| Provider | Function | Data shared |
|---|---|---|
| MongoDB Atlas | Encrypted database | Persistent data |
| Render | Application server | HTTP traffic |
| Cloudinary | Image and video storage | Photos, videos, documents |
| LiveKit | Voice and video calls | Real-time streams (not recorded) |
| Anthropic (Claude) | AI translation | Text to translate (discarded after response) |
| OpenAI | Voice synthesis and translation | Text/audio (discarded after response) |
| Deepgram | Voice transcription | Audio (discarded after transcription) |
| Stripe | Payments | Card and billing data |
| FCM / Apple Push | Push notifications | Device token |
Some providers are based outside Peru or the EU. International transfers are made with the safeguards required by applicable regulations (Standard Contractual Clauses or equivalent).
6. Retention periods
- Account and content: while the account is active. If you close it, deleted within 90 days.
- Verification documents: deleted immediately after the decision.
- Billing data: 5 years (accounting and tax obligation).
- Technical logs: 30-90 days, then anonymized or deleted.
- Audio sent to AI: discarded as soon as processing ends (seconds).
7. Your rights
You have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data. Instructions at delete account.
- Restrict or object to processing.
- Port your data (you will receive an exportable file).
- Withdraw consent when this is the legal basis.
- Lodge a complaint with the Peruvian National Authority for Personal Data Protection if you reside in Peru, the Spanish Data Protection Agency (AEPD) if you reside in Spain, or the equivalent authority in your country of residence.
To exercise these rights: [email protected]. We will respond within 30 days.
8. Security measures
- TLS 1.2+ on all communications (HTTPS).
- Passwords with bcrypt hash — we never store them in plain text.
- Messages and content encrypted in transit and at rest.
- Administrative access restricted by roles (RBAC) with immutable audit log.
- Continuous monitoring of external services.
- Encrypted, geo-replicated backups.
9. Minors
KAIXO is not directed at children under 13. Between 13 and 16 (where applicable) it requires consent of a parent or legal guardian. If you detect a minor using it without proper consent, write to [email protected] to delete the account.
10. Changes to this policy
We may update this policy when functionalities, providers or regulations change. If changes are substantial we will notify through the app or email at least 14 days in advance. The "Last updated" date at the top reflects the current version.
11. Contact
Ideia Soluciones Tecnológicas S.A.C.
Email: [email protected]
Address: Panamericana Norte Km 164, Végueta, Huaura, Lima, Peru