Courtesy translation. The legally binding text of this policy is the Spanish version. In case of any discrepancy between the two, the Spanish version prevails. Read the Spanish version.
Under Law 1581 of 2012 and Decree 1377 of 2013 of the Republic of Colombia, and the requirements of Meta Platforms’ WhatsApp Business API, Cerostaff SAS sets out its privacy policy and personal data processing notice.
01 Identity of the Data Controller
Legal name: Cerostaff SAS
Tax ID (NIT): 902055075
Registered address: Mosquera, Cundinamarca, Colombia
Email: edson.romero@cerostaff.com
02 Personal Data We Collect
In delivering our services we may collect the following personal data:
- First and last name
- Mobile phone number
- The content of messages sent through WhatsApp, Instagram, Telegram and Facebook
- Usage and interaction data relating to the business’s customer-service automation (frequency, type of enquiry, time of day)
- Any additional information the data subject provides voluntarily during the conversation
03 Purpose of the Processing
The personal data collected is processed exclusively in order to:
- Provide the service and process automation operated by the business, for customer service on behalf of the businesses that engage Cerostaff SAS
- Answer enquiries, book appointments, send quotes and escalate requests to a human agent where necessary
- Improve the quality and personalization of the service
- Comply with applicable legal obligations
04 Legal Basis for the Processing
Your personal data is processed on the basis of the free, prior, express and informed consent you give when you start a conversation with the business’s customer-service automation. By sending a message, you accept the terms of this policy.
05 Third-Party Sub-Processors
To deliver the service, Cerostaff SAS may share data with the following technology providers under strict confidentiality agreements:
- Meta Platforms, Inc. — infrastructure for the WhatsApp Business API, Instagram Direct and Facebook Messenger
- Amazon Web Services, Inc. (AWS) — secure cloud storage (servers in the United States)
- Anthropic, PBC — natural language processing using artificial intelligence models
- Google LLC — Google API services (Calendar, Gmail, Sheets, Docs and Drive) when the Customer voluntarily connects their Google account (see section 6)
All sub-processors hold internationally recognized security certifications and are contractually bound to protect your data in accordance with applicable law.
06 Access to Your Google Account Data
When the Customer voluntarily connects a Google account, Cerostaff SAS accesses only the data strictly necessary to run the functions the Customer configures in their own agent. Access is granted through Google’s OAuth 2.0 consent flow, is limited to the scopes the Customer approves on the consent screen, and can be revoked at any time (see “How to revoke access”).
For each requested permission, the following sets out what data is accessed, what it is used for inside Cerostaff, how and for how long it is stored, and who it is shared with:
-
Google Calendar — view availability and create, edit or delete events.
- Data: events and availability in the Customer’s calendar.
- Purpose within Cerostaff: so the agent can book, reschedule or cancel appointments and check free slots at the request of End Users.
- Storage and retention: event data is processed to carry out the action; only the minimum identifiers needed to track the flow are retained, on AWS infrastructure, for a maximum of 24 months (see §Retention).
- Shared with: AWS (hosting) and the AI provider, solely to deliver the requested function. It is never sold or used for advertising.
-
Basic account information — email address (
userinfo.email) — identify the connected account.- Data: the email address of the connected Google account.
- Purpose within Cerostaff: to display and verify which account is linked, and to associate the connection with the right Customer.
- Storage and retention: stored encrypted on AWS for as long as the connection is active; deleted when the account is disconnected.
- Shared with: no one outside our infrastructure sub-processors. It is never sold or used for advertising.
-
Sending email through Gmail (
gmail.send) — send email on behalf of the connected account. It does not read the inbox.- Data: the emails the agent drafts and sends (recipient, subject, body). Cerostaff does not read, list or access received email.
- Purpose within Cerostaff: to send confirmations, replies, quotes or documents as part of the flows the Customer defines.
- Storage and retention: sent content is recorded only as far as needed for the flow history, encrypted on AWS, for a maximum of 24 months.
- Shared with: Google (to perform the send), AWS, and the AI provider to generate the message. It is never sold or used for advertising.
-
Google Sheets (
spreadsheets) — read and write the Customer’s spreadsheets.- Data: rows and cells in the spreadsheets the Customer uses in their flows.
- Purpose within Cerostaff: to record contacts or orders, look up catalogues and inventory, and update data the agent needs.
- Storage and retention: values are processed to carry out the action; only the minimum flow data is retained, encrypted on AWS, for a maximum of 24 months.
- Shared with: AWS and the AI provider to deliver the function. It is never sold or used for advertising.
-
Google Docs (
documents) — read and write the Customer’s documents.- Data: the content of the documents the Customer uses in their flows.
- Purpose within Cerostaff: to generate or update documents (for example, quotes or summaries) within the configured flows.
- Storage and retention: content is processed to carry out the action; only the minimum flow data is retained, encrypted on AWS, for a maximum of 24 months.
- Shared with: AWS and the AI provider to deliver the function. It is never sold or used for advertising.
-
Drive files chosen by the user (
drive.file) — only the files the Customer selects with the Google Picker.- Data: exclusively the files the Customer picks one by one through the Google Picker. Cerostaff does not see or access the rest of the Drive.
- Purpose within Cerostaff: to open and work with the specific files the Customer connects to a flow (for example, to attach or read a document).
- Storage and retention: the selected file is processed to carry out the action; only the minimum flow identifiers are retained, encrypted on AWS, for a maximum of 24 months.
- Shared with: AWS and the AI provider to deliver the function. It is never sold or used for advertising.
All of this data travels encrypted (TLS 1.3), is stored encrypted at rest and, where a function requires it, is processed by our artificial intelligence provider for the sole purpose of delivering the function the Customer requested. That provider is contractually prohibited from using this data to train or improve its models.
Cerostaff SAS’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, this means that:
- Google data is used only to provide or improve user-facing features within Cerostaff.
- It is not used for advertising of any kind.
- It is not transferred to third parties, except as needed to provide the service, for legal reasons, for security purposes, or as part of a merger or acquisition with prior notice to users.
- No humans read this data, unless the user consents, it is necessary for security, the law requires it, or the data is aggregated and anonymized for internal operations.
07 Cerostaff’s Role Regarding Your Google Data
With respect to the data accessed through the Google account that the Customer voluntarily connects (Calendar, Gmail, Sheets, Docs and the Drive files chosen with the Picker), Cerostaff SAS acts as a Data Processor: it processes that data solely under the Customer’s documented instructions and for the purposes the Customer configures in the Platform. The Customer is the Data Controller for that data.
This means Cerostaff does not determine the purposes or means of processing the Customer’s Google account data on its own account, but carries them out on the Customer’s behalf. The terms of this arrangement are set out in the Data Processing Agreement (DPA). This role is separate from Cerostaff’s role regarding End User data on messaging channels, where it also acts as the Customer’s Processor.
08 How to Revoke Google Access
You can withdraw Cerostaff’s access to your Google account at any time, without affecting the lawfulness of processing carried out before the withdrawal. There are two ways:
- From your Google account: go to your Google account permissions page, select “Cerostaff” and choose “Remove access”.
- From Cerostaff: in the integrations or account settings section inside the app, use the option to disconnect your Google account.
When you revoke access, Cerostaff stops accessing your Google data and deletes the stored access tokens. Any features that depended on that connection will stop working.
09 International Transfers and Transmissions of Data
Given the technical nature of the service, your data may be processed on servers located outside Colombia. In particular, Google LLC, Amazon Web Services and Anthropic process data on infrastructure located primarily in the United States.
Under Colombian data protection rules, we distinguish between:
- International transmission: sending data to a Processor that processes it on the Controller’s behalf (such as AWS, Google or Anthropic providing services to Cerostaff or to the Customer).
- International transfer: sending data to another Controller.
These operations are carried out with the safeguards required by articles 24 and 25 of Decree 1377 of 2013 and, where applicable, under the Standard Contractual Clauses set out in External Circular 003 of 2025 of the Colombian Superintendence of Industry and Commerce (SIC), as well as the processing agreements signed with each provider.
10 Retention Period
Your personal data will be retained for a maximum period of 24 months from the last interaction, or until you request its deletion, whichever comes first. After that period, the data will be securely and irreversibly deleted.
11 Data Subject Rights
Under Law 1581 of 2012 and Decree 1377 of 2013, you have the right to:
- Access: know what personal data Cerostaff SAS holds about you.
- Rectification: request correction of inaccurate or outdated data.
- Erasure or cancellation: ask for your data to be deleted when it is no longer necessary for the authorized purposes or when the processing does not comply with the law.
- Objection: object to the processing of your data where the law permits.
- Portability: receive your data in a structured, commonly used format.
- Withdrawal of consent: withdraw the consent you gave at any time.
- Information about disclosures: know whether your data has been or will be shared with third parties, and for what purpose.
- Information about incidents: be informed, where applicable, of security breaches affecting your personal data (see section 12).
- Complaint: file a complaint with the Superintendence of Industry and Commerce (SIC).
To exercise any of these rights, email edson.romero@cerostaff.com stating your full name, a contact detail (phone number or email) and your specific request. We will respond within the statutory deadlines, at most 15 business days (enquiries) or 15 business days, extendable (complaints), in accordance with Law 1581 of 2012.
12 Security Incident Notification
If a security breach occurs that compromises personal data (unauthorized access, loss or improper disclosure), Cerostaff SAS will activate its internal incident response procedure and, where the law requires it, will notify the Superintendence of Industry and Commerce (SIC) and the affected data subjects, describing the nature of the incident, the data involved and the measures taken to mitigate it. Where Cerostaff acts as Processor, it will also notify the Customer as Controller without undue delay.
13 Data Deletion
You may request at any time the deletion of the personal data Cerostaff SAS holds about you. To do so, follow these steps:
- Email edson.romero@cerostaff.com with the subject “Data deletion request”.
- Include your full name and the phone number you used to interact, so we can identify and verify your information.
- State whether you want all of your data deleted or only a specific part.
We will handle your request within a maximum of 15 business days. Once your identity is verified, we will securely and irreversibly delete your personal data from our systems, except for any information we are legally required to retain. We will confirm by email once the deletion is complete.
14 Security Measures
Cerostaff SAS implements appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration or disclosure, including encryption in transit (TLS 1.3), encryption at rest and role-based access controls.
15 Cookies and Tracking Technologies
The business’s customer-service automation operates mainly through messaging channels (WhatsApp, Instagram, Telegram, Facebook). We do not use tracking cookies on those channels.
16 Contact, Requests and Habeas Data
The area responsible for handling requests, enquiries and complaints about data protection, as well as the data protection function (privacy contact / DPO), is the management of Cerostaff SAS, reachable at:
Habeas data procedure:
- Send your request to the email above, identifying yourself (full name and a contact detail) and describing the request, enquiry or complaint.
- Enquiries are handled within a maximum of 10 business days, extendable by a further 5 business days.
- Complaints are handled within a maximum of 15 business days, extendable by a further 8 business days, in accordance with Law 1581 of 2012.
- If you do not receive a satisfactory response, you may turn to the Superintendence of Industry and Commerce (SIC).
17 Term and Validity of the Database
This policy takes effect from the last-updated date shown at the top of the document. The databases managed by Cerostaff SAS will remain valid for as long as the processing purposes described in this policy subsist and, in any event, for as long as a relationship with the data subject exists or a legal retention obligation applies. Data will be retained in accordance with the periods stated in the Retention Period section.
18 Changes to This Policy
Cerostaff SAS reserves the right to update this privacy policy at any time. Material changes will be communicated through the messaging channels used to provide the service. The current version will always be available on this page.
