Legal
Privacy Policy
Effective date: 29 August 2026 Applies to: vizumapps.com and the services reached through it — the app store, the developer portal, licensing, and Managed AI.
This policy describes what we actually do. Where a safeguard is not yet in place, this policy says so instead of describing an intention as a fact.
1. Who is responsible
1.1 Controller of record
| Controller | Enrique Echeverría, acting as a natural person |
| Trading name | Vizum Apps |
| Website | https://vizumapps.com |
| Establishment | Colombia and the United States |
| Contact for all privacy matters | support@vizumapps.com |
| Person in charge of the data protection function | The controller, at the address above (Decreto 1377 de 2013, art. 23) |
The service is operated today by a natural person. No company has been incorporated. If the operation is transferred to a company, this section is replaced and the rest of this policy stands unchanged.
1.2 How we refer to ourselves
Everywhere below, "Vizum Apps", "we" and "us" mean the controller identified in section 1.1.
1.3 Which laws we apply
We apply three regimes at the same time, and where they differ we apply the one that gives you more protection:
- Colombia — Ley 1581 de 2012 and Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015).
- European Union / EEA — Regulation (EU) 2016/679 (GDPR), which reaches us through Article 3(2) because we offer services to people in the Union. The United Kingdom equivalent applies on the same terms.
- United States — there is no general federal privacy statute. Where you are a California resident, the CCPA as amended by the CPRA applies. Where you live in another US state with a comprehensive consumer privacy law, we apply the procedure in section 9 to your request.
2. The two roles. This is the part that matters most
We hold two different legal positions depending on which part of the product is involved. Read this before section 3; it determines who you should ask, and what we are allowed to do with your data.
2.1 We are the controller of store and account data
For everything to do with vizumapps.com itself — your store account, the developer portal, the registration of your Odoo instance, purchases, licences, Managed AI billing, and product telemetry — we decide why and how the data is processed. We are the controller (in Colombian terms, the Responsable del Tratamiento). Sections 3.1 to 3.4 and sections 4 to 9 apply to you directly.
2.2 We are the processor of what you index into Managed AI
For Managed AI and retrieval-augmented generation — the prompts you send, the documents you index, the text extracted from those documents, and the vectors built from them — we do not decide anything about that content. It belongs to the customer whose instance sent it. The customer is the controller (in Colombian terms, the Responsable); we are the processor (the Encargado del Tratamiento), and we act on that customer's instructions and on the terms of the agreement with them.
Practical consequence: if your personal data appears inside a document that one of our customers indexed, we are not the party who can decide to delete it. Address the customer. If you contact us instead, we will tell you which customer holds the instance where the data sits, or forward your request to them, and we will not act on the content ourselves except on their instruction or where the law obliges us to act directly.
2.3 Where we have no role at all
Vizum Window Manager and the Apps Platform are Odoo modules that a customer installs in their own database, on their own server. Data handled there does not reach us and we do not process it. This policy does not cover it.
3. What personal data we process
3.1 Store account and portal (we are the controller)
| Data | When it is collected |
|---|---|
| Name | Account signup |
| Email address | Account signup and sign-in |
| Password | Account signup — see the note below |
| IP address | Account signup and every sign-in. The IP address is read from the request and passed explicitly into the account routine; it is not incidental logging |
| IP address and email address in failed sign-in attempts | Anti-abuse counters (section 3.4) |
| Contact and billing details | Your customer record in the portal (Odoo res.partner) |
Passwords are never stored in readable form. They are handed to Odoo's user model and hashed with PBKDF2-SHA512. We cannot read your password and cannot recover it for you.
3.2 Instance registry and licensing (we are the controller)
When your Odoo installation links itself to the store we record the instance name, the database UUID of your Odoo, the customer record it belongs to, a secret access token, and whether the instance is a development database. This is what every licence and every Managed AI charge binds to.
3.3 Payments (we are the controller of the record, not of the card)
Card numbers never reach our servers. Payment runs through Stripe Checkout Sessions and Payment Intents; the card details travel from your browser to Stripe. We keep Stripe identifiers, the amount, the status, and the resulting invoice or licence — not the card number.
3.4 Product and security telemetry (we are the controller)
- Desktop telemetry — a roll-up of how the installed desktop is used.
- Anti-abuse counters — a per-IP-address and per-email-address failure counter used to stop brute-force and credential-stuffing attempts against the sign-in and signup routes. Five failures within five minutes block that key for fifteen minutes. The signup route is throttled per source IP address; the checkout route allows ten requests per five minutes.
- Managed AI usage and charges — consumption counters, transactions and charge records that produce your bill.
3.5 Managed AI content (we are the processor)
Prompts, indexed documents, the text extracted from them, the vectors built from that text, and the retrieval context assembled to answer a question. Whatever personal data a customer places in those documents, we process on their behalf. We do not use this content to train models, to build profiles, or for any purpose of our own.
3.6 What we do not process
We do not run analytics, advertising pixels, or third-party trackers on vizumapps.com. We do not build advertising profiles. We do not process special categories of data (health, biometrics, political opinions and the like) as part of the store; if a customer places such data inside a document they index, they do so as controller under section 2.2 and it is their responsibility to have a basis for it.
4. Why we process it, and what makes it lawful
4.1 How Colombian authorization and GDPR legal bases fit together
These two regimes are built differently, and a document that pretends otherwise ends up contradicting itself. Here is how they combine.
Colombia works by authorization. Ley 1581 de 2012 requires your prior, express and informed authorization before we may process your data, with only the narrow exceptions its Article 10 lists. The authorization is the instrument that makes the processing lawful, and it is the same instrument for every purpose.
The GDPR works by legal basis, and consent is only one of six. Under the GDPR, processing that is necessary to deliver a service you asked for must rest on Article 6(1)(b) — performance of a contract — and not on consent. That rule exists to protect you: it prevents us from presenting as "consent" something you could not refuse without losing the service, and it stops us from claiming that withdrawing consent is impossible.
So the same act carries different weight in each regime. When you create an account, having had this policy available to you, that affirmative act is:
- in Colombia, the authorization required by Ley 1581 — the thing that makes the processing lawful (Decreto 1377, art. 7: authorization may be given by unequivocal conduct; silence is never authorization);
- under the GDPR, evidence that you were informed — not the legal basis. The legal basis for each purpose is the one named in the table in section 4.2.
We do not rely on GDPR consent as the legal basis for any purpose described in this policy.
What this means for you in practice:
- If you are in Colombia, you may revoke your authorization at any time. The effect is that we stop processing and the service relationship ends, except for records we are required to keep by a legal or contractual duty (Decreto 1377, art. 9 — revocation and deletion do not proceed where the Titular has a legal or contractual duty to remain in the database).
- If you are in the EEA or the UK, there is nothing to withdraw for the purposes based on Article 6(1)(b): you end the contract instead. For the purposes based on Article 6(1)(f) you have the right to object under Article 21, and we stop unless we can show compelling legitimate grounds that override your interests.
4.2 Purposes and legal bases
| Purpose | Data used | GDPR basis | Colombian position |
|---|---|---|---|
| Create your account, authenticate you, and give you the store and portal | Name, email, password hash | Art. 6(1)(b) — performance of a contract | Authorization, given on account creation |
| Protect the sign-in and signup routes against brute force and credential stuffing | IP address, email address, failure counters | Art. 6(1)(f) — our legitimate interest in the security of the service and of your account | Authorization, informed by this policy |
| Register your Odoo instance and issue and validate licences | Instance name, database UUID, customer record, access token | Art. 6(1)(b) | Authorization |
| Sell apps and subscriptions, and take payment | Billing details, Stripe identifiers, amounts, status | Art. 6(1)(b) | Authorization |
| Bill Managed AI by usage | Consumption counters, transactions, charge records | Art. 6(1)(b) | Authorization |
| Understand how the installed desktop is used | Desktop telemetry | Art. 6(1)(f) — our legitimate interest in maintaining and improving the product | Authorization |
| Answer support requests | Your correspondence and account context | Art. 6(1)(b) and Art. 6(1)(f) | Authorization |
| Keep accounting, tax and payment records | Invoices, payment records | Art. 6(1)(c) — legal obligation | Legal duty; this survives revocation |
| Send your data to infrastructure located in the United States | All of the above | Chapter V — see section 6 | Ley 1581, art. 26(e), and art. 26(a) where express authorization is given — see section 6 |
For Managed AI content (section 2.2) we do not assert a legal basis of our own. The customer who sent the content is the controller and holds the basis; ours is the contract with them, which is what Article 28 of the GDPR and Article 18 of Ley 1581 require.
4.3 We do not sell or share your personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA as amended by the CPRA. We have not sold or shared personal information in the preceding twelve months. We do not process sensitive personal information for purposes that would trigger your right to limit its use.
5. Who else touches the data
These are our processors and sub-processors, named individually with what each one does.
5.1 Infrastructure and payments
| Provider | What it does | Where |
|---|---|---|
| DigitalOcean | All hosting: the web and application servers, the managed PostgreSQL database, the transcription worker, and file storage in DigitalOcean Spaces | United States — New York (nyc1), file storage in nyc3 |
| Stripe | Payment processing, checkout, the billing portal, subscriptions, and payment webhooks | United States and Stripe's own network |
5.2 AI providers
Managed AI sends content to a model provider. Which provider receives your content depends on the configuration chosen by the customer whose instance sent it — the model is selected per application, so we cannot and do not promise a single destination. These are the providers the platform can reach:
| Provider | Function |
|---|---|
| OpenAI | Text generation, embeddings |
| Anthropic | Text generation |
| Google — Gemini | Text generation, embeddings |
| Google — Cloud Vision | Optical character recognition |
| xAI | Text generation, embeddings |
| MiniMax | Text generation |
| Ollama | Text generation and embeddings, either through Ollama's hosted service or through an Ollama server the customer runs and configures themselves. Open models including Mistral are served through this path |
If a customer configures a self-hosted Ollama server, content goes to that server and not to a third party.
5.3 When the customer supplies their own provider key
A customer may store their own provider API key with us. When they do, their Managed AI traffic is sent to that provider under the customer's own account and is billed to them by that provider directly. The key is stored encrypted, is never written to logs, and is never returned to the caller. The destination is still the provider named in the table above.
6. Where your data is, and what makes the transfer lawful
6.1 The fact, stated plainly
All processing on our own infrastructure happens in the United States. Every server, the managed database and the file storage are hosted by DigitalOcean in New York. There is no European or Colombian copy. If you are in the EEA, the UK or Colombia, your data leaves your country the moment you use the service.
One thing is not on our infrastructure, and we say it here rather than leave it to be found. When you use Managed AI, the content of your request goes to the AI provider you selected for that application. Not all of those providers are established in the United States — Annex III of the Data Processing Agreement names each one and says where — so content routed to a provider you select may be processed outside the United States as well.
6.2 If you are in the EEA or the United Kingdom
This is a transfer to a third country under Chapter V of the GDPR. It is not occasional and it is not incidental, so the derogations in Article 49 are not the right instrument for it: a systematic transfer of this kind needs the appropriate safeguards of Article 46.
What we rely on: the data processing terms published by DigitalOcean and by Stripe for customers outside the United States, which set out the transfer mechanism each of them offers.
What is not yet in place, stated rather than glossed:
- We have not carried out or documented a transfer impact assessment for these transfers.
- We have not signed individually negotiated data processing agreements with the AI providers in section 5.2. Content sent to them travels under each provider's standard published business or API terms and nothing more.
We are stating this because a policy that claims safeguards it does not have is worse than one that does not claim them. If this matters to your decision to use the service, it should weigh in that decision.
6.3 If you are a Titular in Colombia
Article 26 of Ley 1581 de 2012 prohibits transferring personal data to countries that do not offer adequate levels of data protection, and then lists the cases in which the transfer is permitted anyway. We rely on:
- Article 26(e) — the transfer is necessary to perform the contract between you and us. It is not possible to deliver the store, your licences or Managed AI without processing your data on the infrastructure described in section 6.1; and
- Article 26(a), where you have given express and unequivocal authorization for the transfer.
We are telling you the destination country explicitly so that any authorization you give is an informed one.
6.4 Registration of databases in Colombia
Under Decreto 1074 de 2015 as amended by Decreto 090 de 2018, the duty to register databases in the Registro Nacional de Bases de Datos falls on companies and non-profit entities with total assets above 100,000 UVT and on public-law legal persons. The controller identified in section 1.1 is a natural person and falls outside that scope, so no registration exists. This changes if the operation is transferred to a company, and we will register the databases when it does.
7. How long we keep it
| Data | Retention |
|---|---|
| Managed AI vectors and indexed documents | 30 days after a subscription is cancelled, then destroyed. The period is configurable and its default is 30 days |
| Managed AI balance | Kept after cancellation. It is money on account, not stored content, and remains usable until it reaches zero |
| Desktop telemetry | 730 days, enforced by a job that runs daily |
| Abandoned draft purchases | 7 days by default, swept daily. Paid, failed and refunded records are kept |
| Anti-abuse counters | The counter for a key is deleted as soon as a sign-in with that key succeeds. A counter for a key that never succeeds is not deleted on a schedule |
| Invoices, payment records and licences | For as long as accounting and tax law requires |
| Store accounts and the personal data attached to them | No automatic deletion period is set. An account and its records are kept for as long as the account exists, and until you ask us to delete it under section 9 |
The last row is the honest statement of a gap, not a policy choice we are defending. Setting a retention period for dormant accounts is outstanding work. Your right to ask for deletion (section 9) does not depend on it.
The databases described in this policy remain active for as long as the relationship with the Titular lasts and for the periods set out in this table (Decreto 1377, art. 13(6)).
8. How we protect it
These are measured facts about the production service, not aspirations:
- All traffic is served over TLS with certificates from Let's Encrypt.
- HTTP Strict Transport Security is enforced for two years, including subdomains.
X-Frame-Options,X-Content-Type-Options,Referrer-Policy,Permissions-PolicyandCross-Origin-Opener-Policyare set on responses.- Passwords are hashed with PBKDF2-SHA512 and are never stored in readable form.
- Sign-in and signup are rate limited: five failures in five minutes block that IP address or email address for fifteen minutes. Checkout allows ten requests per five minutes.
- Third-party apps run inside a sandboxed frame that is denied the same-origin permission, and with their own content security policy inside the frame. They cannot read the page, the session, or your cookies.
- Card numbers never reach our servers (section 3.3).
No system is immune. These measures reduce risk; they do not eliminate it.
9. Your rights, and how to exercise them
9.1 What you can ask for
If you are a Titular under Colombian law (Ley 1581, art. 8), you may: know, update and rectify your data; ask us for proof of the authorization you gave, except where the law dispenses with authorization; be told, on request, what use we have made of your data; revoke your authorization and ask for deletion, subject to section 4.1; access your data free of charge, at least once each calendar month; and lodge a complaint with the Superintendencia de Industria y Comercio.
If you are in the EEA or the UK (GDPR, arts. 15 to 22), you may: obtain access and a copy; rectify inaccurate data; erase data; restrict processing; obtain your data in a portable form; object to processing based on legitimate interest, including on grounds relating to your particular situation; and lodge a complaint with your national supervisory authority.
If you are a California resident (CCPA/CPRA), you may: know what we collect, use, disclose and retain; obtain a copy; correct inaccurate information; delete personal information; opt out of the sale or sharing of personal information — we do neither (section 4.3); limit the use of sensitive personal information; and not be discriminated against for exercising any of these rights. You may use an authorised agent.
If you live in another US state with a comprehensive consumer privacy law, you have rights that are broadly equivalent. Make the request the same way and we will apply the shortest deadline that your state's law and this policy allow.
9.2 How to make a request
- Write to
support@vizumapps.com. Put "Privacy request" in the subject line. - Send it from the email address registered on your account. That is normally all the proof of identity we need, and it is the option that requires you to give us the least additional data.
- If you cannot write from that address, or if you are acting for someone else, tell us: the email address or account the request concerns, enough detail for us to find the record, and — for a representative, an heir, or an authorised agent — the document that shows you are entitled to act. We ask for identity documents only where a reasonable doubt about identity remains, and we do not keep them for longer than the request requires.
- Say what you want. Access, correction, deletion, a copy, revocation of authorization, objection, or restriction. If you are not sure, describe the situation and we will treat it as the request that fits.
- We answer at the address you wrote from, unless you ask us to answer somewhere else.
If the request concerns content indexed into Managed AI by one of our customers, section 2.2 applies: we are the processor, and we will route the request to the controller rather than act on the content ourselves.
9.3 How long we take
| Regime | Type of request | Deadline |
|---|---|---|
| Colombia | Consulta — access, or being told what use we made of your data | 10 business days. If we cannot answer in time we tell you why before the deadline, and answer within 5 further business days (Ley 1581, art. 14) |
| Colombia | Reclamo — correction, update, deletion, revocation, or an alleged breach of the law | 15 business days. If we cannot answer in time we tell you why and give you a date, which cannot exceed 8 business days after the first deadline (Ley 1581, art. 15). If your claim is incomplete we ask you to complete it within 5 days of receiving it. While the claim is open, the record is labelled "reclamo en trámite" |
| EEA / UK | Any right under Articles 15 to 22 | 1 month, extendable by 2 further months where the request is complex or there are several. We tell you about any extension within the first month (GDPR, art. 12(3)) |
| California | Any CCPA/CPRA right | We acknowledge within 10 business days and answer within 45 calendar days, extendable once by a further 45 days with notice to you |
Access is free. We do not charge for exercising any of these rights, and we do not treat you differently for having exercised them.
9.4 If you are not satisfied
- Colombia — you may complain to the Superintendencia de Industria y Comercio. Colombian law requires you to raise a consulta or reclamo with us first; the complaint to the SIC is admissible only once that step has been exhausted (Ley 1581, art. 16).
- EEA — you may complain to the supervisory authority of the country where you live, where you work, or where the alleged infringement happened. You may also go to court.
- United Kingdom — you may complain to the Information Commissioner's Office.
- United States — you may contact the attorney general of your state.
Complaining to a regulator does not require our permission and does not require you to tell us first, except for the Colombian rule stated above.
10. Children
Vizum Apps is a product for businesses and developers. It is not directed at children, and we do not knowingly collect personal data from them.
- Colombia — Ley 1581, art. 7 and Decreto 1377, art. 12 forbid processing the data of children and adolescents except where it is of a public nature and where the processing respects the superior interest of the child and their fundamental rights. We do not process data of people under 18 through the store.
- EEA — we do not offer these services directly to a child under 16.
- United States — we do not knowingly collect personal information from a child under 13 (COPPA).
If we learn we hold a child's personal data, we delete it. If you believe a child has given us data, write to support@vizumapps.com and we will act on it as a reclamo under section 9.3.
11. Automated decisions and profiling
We do not make decisions about you by automated means that produce legal effects or that similarly significantly affect you. We do not profile you.
There is one automated mechanism you should know about, described here because it can affect whether you get in: the anti-abuse throttle in section 3.4 blocks an IP address or an email address for fifteen minutes after five failed attempts in five minutes. It is temporary, it is reversible, it decides nothing about you beyond that pause, and if you believe it has been applied to you wrongly, write to support@vizumapps.com.
Managed AI generates text; it does not decide anything. If one of our customers uses AI output to make a decision about a person, that customer is the controller of that decision and is responsible for the safeguards Article 22 of the GDPR requires. We are the processor and we take no part in it.
12. Security incidents
If a security incident affects your personal data:
- EEA / UK — we notify the competent supervisory authority within 72 hours of becoming aware of the breach where it is likely to result in a risk to your rights and freedoms (GDPR, art. 33), and we notify you without undue delay where the risk to you is high (art. 34).
- Colombia — we report the incident to the Superintendencia de Industria y Comercio as Ley 1581, art. 17(n) requires, and we inform affected Titulares.
- United States — we notify you and the authorities that the law of your state requires, within the deadlines that law sets.
We will tell you what happened, what data was involved, what we are doing about it, and what you can do.
13. Changes to this policy
We may update this policy. When we do, we change the effective date at the top and publish the new text at https://vizumapps.com/privacy. For a change that materially alters the purposes, the recipients, or the destination of your data, we will tell registered account holders by email before it takes effect, and — where Colombian law requires a new authorization for the new purpose — we will ask you for it rather than assume it.
14. Contact
Write to support@vizumapps.com for any question about this policy, to exercise any right in section 9, or to raise a complaint.
If you contacted us and did not get an answer within the deadline in section 9.3, say so in a new message with the date of your first one. That is a reclamo, and it restarts the clock in your favour rather than ours.