This English translation is provided for convenience only. In case of any discrepancy, the Spanish version prevails and is the legally binding text.
LegalPrivacy Policy
Last updated: September 22, 2026 · Effective from: June 27, 2026
RP CLOUD SERVICES SAS (hereinafter, “Claria”, “we” or the “Company”) values the privacy of its users, clients and visitors. This Policy describes how we collect, use, store and protect the personal data we process through our website and services, in compliance with Law 1581 of 2012 and Decree 1377 of 2013 (Colombia), the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) where applicable.
1. Data controller
RP CLOUD SERVICES SAS
NIT (Tax ID): 901.919.124
Registered address: Bogotá D.C., Colombia
Email: hola@claria-co.com
Phone / WhatsApp: +57 320 335 0849
2. Data we collect
We collect only the data necessary to provide our services:
- Account data: name, email address, hashed password, and the identifier provided by federated sign-in (Google) where applicable.
- Business contact data: name, email, business name and any other information you share with us when requesting a diagnosis or quote through our forms.
- Usage data: pages visited, dates and IP addresses associated with your session.
- Communications: inquiries you send us by email, WhatsApp or through forms.
- Cookies and similar technologies: see section 9.
3. Purposes of processing
- Creating and managing your account, authenticating you and ensuring the security of the platform.
- Handling your diagnosis or quote requests and managing the business relationship.
- Providing the contracted services and offering you support.
- Sending transactional communications (confirmations, replies to requests, service changes).
- Sending marketing communications about new services or content, only where you have given explicit authorization.
- Complying with legal, accounting and tax obligations and responding to requests from authorities.
- Improving our services through aggregated and anonymous usage analysis.
4. Legal basis and authorization
We process your data on the basis of: (i) your prior, express and informed authorization when you register or tick the corresponding box; (ii) the performance of a contract or of pre-contractual measures when you hire or request a service; (iii) compliance with legal obligations; and (iv) our legitimate interest in operating and improving the platform, provided that your fundamental rights do not prevail.
5. Processors and international transfers
To operate the platform we use technology providers that may process data outside Colombia:
- Google Cloud (Google LLC) (USA) — database and authentication infrastructure.
- Vercel, Inc. (USA) — hosting and delivery of the application.
- Google LLC (USA) — federated authentication (OAuth) and analytics.
- Microsoft Corporation (USA / Ireland) — corporate email and delivery of transactional email (Microsoft 365).
These processors are contractually bound to handle the information under standards equivalent to or higher than those required by Colombian law and the GDPR. By accepting this policy you authorize the international transfer necessary to provide the service.
6. Data retention
We retain your personal data for as long as you maintain an active account or business relationship with Claria, and thereafter for the periods required by tax, accounting and consumer protection regulations (up to 10 years where the Colombian commercial regime applies). We may retain anonymized data indefinitely for statistical purposes.
7. Your rights
As the data subject, you have the right to:
- Access, update and correct your data.
- Request proof of the authorization you granted.
- Be informed about how your data has been used.
- File complaints with the Superintendencia de Industria y Comercio (SIC), Colombia’s data protection authority.
- Revoke your authorization and request deletion where there is no legal or contractual duty to retain the data.
- Additional rights under the GDPR: data portability, objection to processing and restriction of processing.
- Additional rights under the CCPA (California residents): to know, to delete and to opt out of the sale of personal information. Claria does not sell personal data.
8. How to exercise your rights
You can exercise your rights by sending a request to hola@claria-co.com stating your full name, identification and the specific request. We will respond to inquiries within a maximum of 10 business days and to claims within a maximum of 15 business days, in accordance with Colombian law. For EU residents, we will respond within a maximum of 30 days.
9. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and performance cookies to understand aggregate use of the site. You can configure your browser to reject non-essential cookies; however, some features may not work properly.
10. Minors
Our services are intended for people over 18 years of age. We do not knowingly collect data from minors. If we find that we have received data from a minor without the authorization of their legal representative, we will delete it without delay.
11. Security
We apply reasonable technical and organizational measures (TLS encryption in transit, encryption at rest at our processors, role-based access control and audit logs) to protect your information. No system is infallible; in the event of a security incident affecting your data, we will notify you and the competent authorities within the legal deadlines.
12. Changes to this policy
We may update this Policy to reflect regulatory changes or changes to our services. We will publish the current version at this same URL together with the date of the update. Where the changes are substantial, we will notify you by email or through a visible notice on the platform.
13. Google data in CRM GMS — Clar·ia
This section applies to the optional Google connection in CRM GMS — Clar·ia, provided by RP CLOUD SERVICES SAS to the GMS Inmobiliaria team. It is effective from September 22, 2026. For data obtained through Google APIs, the specific purposes and rules of this section prevail over the general descriptions in this Policy.
Data we access and its purpose
- Identity: Google identifier, name, email and verified-email confirmation, used to identify the user and link their own account. Signing in does not by itself grant access to Gmail or Calendar.
- Gmail: with your authorization we use the send permission to transmit to Gmail the recipient, subject and content of the CRM draft. We receive the identifier of the sent message to record the result. This integration does not query your inbox, does not read other messages and does not delete emails.
- Google Calendar: you authorize access to events in your own calendars. The implementation only queries, creates or updates events identified as created by the CRM in your primary calendar: title, description, dates, identifier and event link. It does not import your other events, add attendees or send invitations.
- Authorization credentials: we process access tokens and keep a refresh token to maintain the connection while you are not using the CRM. We never request or store your Google password.
Agent authorization and recipients
In My connections you can separately authorize an agent key to send emails or to create and update events from your account. Without that delegation, a key cannot use your connection. An active delegation allows the action to be carried out without asking for confirmation on each operation. Emails are shared with the recipients chosen through the CRM contacts, and Google receives the data necessary to provide Gmail and Calendar. The delegated agent receives the results of its actions, such as identifiers or links; it does not receive your tokens.
Storage, security and retention
The CRM database is hosted on Google Cloud in the United States. Vercel hosts the application. Refresh tokens are encrypted with AES-256-GCM and the key is kept separately in the server configuration. Access tokens are processed on the server. We keep the connection while it is active and log authorizations and action results for traceability. Drafts and business records are retained in accordance with the service relationship and the applicable obligations of the party responsible for those records.
When you disconnect Google, we delete the active token and the delegations for that account in the CRM. Backups may contain earlier encrypted versions until they are rotated or deleted; they are not used to reactivate a withdrawn authorization. Disconnecting does not delete emails in Gmail or events in Calendar. You can request deletion of associated data and ask about backup retention by writing to hola@claria-co.com; your request will be handled in accordance with your rights and the applicable retention obligations.
Limited use of Google data
The use of information received from Google APIs and its transfer to other applications will comply with the Google API Services User Data Policy, including its Limited Use requirements. We only use this data to provide and improve the connection features requested by the user. It is not sold, not used for advertising and not used to train general-purpose artificial intelligence models. The current integration does not send data obtained from Google to third-party AI model providers.
Support staff do not read Google data except with your affirmative authorization for a specific feature or assistance, for security reasons, to comply with a legal obligation, or in the cases of aggregated and anonymized data permitted by Google’s policy. Transfers are limited to providing or improving the requested features, to security reasons, to legal obligations or, in a permitted business transaction, to the cases and consents required by that policy.
How to withdraw access
You can uncheck agent permissions or disconnect Google from My connections. To also withdraw the authorization in Google, visit your Google Account connections. If a backup is restored, revocations and deletion requests must be reapplied before the integrations are re-enabled.
14. Contact
Any questions about this Policy may be sent to hola@claria-co.com.
Base document aligned with Law 1581/2012, Decree 1377/2013, the GDPR and the CCPA. Review by legal counsel is recommended before final publication.