1. Who is responsible
The data controller is SaaS Holic, S.A., a company incorporated in the Republic of Panama, with offices in Clayton, Ciudad del Saber, Panama. For any privacy question or request, write to [email protected] or call +507 833 9054. This mailbox is also our privacy contact in Microsoft Entra.
2. What this statement covers
This statement applies to:
- Visitors to saas-holic.com.
- Guest users we invite to our Microsoft Entra directory, for example staff of our clients who need access to a project or integration portal.
- Users of the client portals we operate (such as integration dashboards), which are protected with Microsoft Entra or Cloudflare Access.
When we process data on behalf of a client (for example, the orders and customer records of a retailer that flow through an integration we run), the client is the controller and we act as its processor. See section 8.
3. What data we collect
- Website. The site uses no cookies and no advertising or tracking tools. Your light/dark theme choice is stored only in your own browser. Our hosting provider, Cloudflare, processes technical request data (IP address, browser, pages requested) to deliver and protect the site, and gives us aggregated visit statistics that use no cookies.
- Guest identity (Microsoft Entra). Name, email address, organization and the sign-in records Microsoft keeps for the directory: date and time, IP address, application, device or browser, and result of each sign-in.
- Portal access (Cloudflare Access). Your email address and a one-time code sent to it, which expires after 10 minutes, plus a session cookie (
CF_Authorization) that keeps you signed in. - Inside the portals. An activity log of who did what and when, and any feedback or error report you send, which may include a screenshot you choose to attach.
- Technical telemetry. Performance and error data from our applications through Azure Application Insights. The client IP address is used only to derive an approximate location and is then discarded.
- Your messages. What you send us by email or phone.
4. Why we use it and on what basis
- To give you access to the portals and services agreed with your organization, and to support you. Basis: the contractual relationship with your organization and your consent, which you give by accepting the invitation or signing in.
- To keep the services secure, audit who did what, and investigate incidents and errors. Basis: our legitimate interest in protecting the services and our clients' data.
- To answer your messages. Basis: your consent.
- To meet legal obligations and requests from competent authorities.
Providing your name and email is necessary to grant access: without them we cannot create your guest account or let you into a portal. Everything else is optional. We do not sell your data, use it for advertising, or make decisions about you by automated means alone.
6. International transfers
Microsoft and Cloudflare operate data centers in several countries, including the United States, so your data may be processed outside Panama and outside your country. We use these providers because their contracts include safeguards recognized by Panamanian law, such as standard contractual clauses (Executive Decree 285 of 2021, arts. 51 and 53). By accepting the invitation, you also consent to these transfers where your law requires it, as Costa Rica's Law 8968 does.
7. How long we keep it
- Guest account: while your organization needs access. We remove it when the relationship ends or when you ask us to.
- Microsoft Entra sign-in and audit records: up to 30 days, as kept by Microsoft.
- Portal activity log: 395 days.
- Feedback and error reports: 395 days. Attached screenshots are stored privately and deleted after 90 days.
- Application telemetry: 90 days.
- Cloudflare Access session: it expires within hours (24 hours by default) and the one-time code after 10 minutes.
- Emails: as long as needed to answer and follow up on your request.
8. When we process data for our clients
Some of our work consists of running integrations for retail clients, for example between their online store and their point of sale. The orders and customer records of those businesses pass through our systems on behalf of the client, who is the controller of that data and decides why it is processed. We use it only to run the service the client hired, following its instructions. The raw record of each operation, and its retries, is kept for 90 days to diagnose failures.
If you are a customer of one of our clients and want to exercise your rights over that data, please contact that business directly. If you write to us, we will forward your request to it.
9. Your rights
You can ask to access your data, rectify it, cancel (delete) it, object to its use, or receive it in a portable format, and you can withdraw your consent at any time without affecting what was done before. Write to [email protected] from the address we have on file, stating what you are asking for. We answer access requests within 10 business days, as Panamanian Law 81 of 2019 requires, and the other requests as soon as possible within the legal time limits.
10. Complaints
If you are not satisfied with our answer, you can file a complaint with the data protection authority:
- Panama: Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI), Dirección de Protección de Datos Personales, antai.gob.pa.
- Costa Rica: Agencia de Protección de Datos de los Habitantes (PRODHAB), prodhab.go.cr.
If you live elsewhere, you can go to the authority in your country.
11. Security
We protect data with encrypted connections (HTTPS), sign-in through Microsoft Entra or single-use codes, access limited to the people who need it, private storage and activity logs. No system is perfectly secure; if an incident affects your data, we will notify you and the competent authority as the law requires.
13. Changes
We will publish any change on this page with a new version number and effective date. If a change is significant, we will also let affected users know.
14. Notices for our apps
Some of our apps have their own notice, which adds what is specific to each one: what it collects, who is responsible for that data and how long it is kept. Where an app notice and this statement differ, the app notice prevails for that app.