Privacy Policy
Last updated: June 26, 2026 — Version 2.0
1. Data Controller Identity
Renaska is operated by two affiliated entities under common control, which jointly trade under the commercial name Renaska ("Renaska," "we," or "the Company") through renaska.com, renaska.co, renaska.us and their associated applications:
(a) Agencia Leidy Echavarria S.A.S., a company organized under the laws of the Republic of Colombia (NIT 901.147.131-7), with registered address at Calle 34B #65D 43, Medellín, Colombia, legally represented by Andrés Felipe Giraldo Muñoz. It is the operator of the platform (development, technical operation, and support), the owner of the Meta integration (WhatsApp Business, Instagram, and Facebook Messenger), and the Data Controller for the personal data processed through the platform and the managed messaging channels (inbox).
(b) WLM Business Solutions LLC, a limited liability company organized under the laws of the State of Delaware, USA (EIN 32-0770823), with mailing address at 1111B S Governors Ave STE 3961, Dover, DE 19904, USA. It is the entity responsible for the commercialization and billing of the service for the U.S. and international market, and the Data Controller for account and billing data.
Because Agencia Leidy Echavarria S.A.S. is domiciled in Colombia, the processing of platform and messaging-channel data is governed primarily by Colombian Law 1581 of 2012 and Decree 1377 of 2013. For account and billing data processed by WLM Business Solutions LLC, U.S. law additionally applies (Section 5 of the FTC Act and, where its thresholds are exceeded, the California CCPA/CPRA — not currently met; their rights are honored as best practice). Single contact for privacy and to exercise your rights: [email protected]. Office hours: Monday – Friday, 9:00 a.m. – 5:00 p.m.
2. Definitions
For the purposes of this Policy, the following definitions apply, consistent with Colombian Law 1581 of 2012, Decree 1377 of 2013, and the California Consumer Privacy Act (CCPA/CPRA):
(a) Personal Data: any information that identifies or is reasonably linkable to a specific natural person. (b) Sensitive Data: data revealing health information, sexual orientation or gender identity, racial or ethnic origin, political opinions, religious or philosophical beliefs, biometric data, or trade union membership (Renaska does not collect this category). (c) Data Subject / Consumer (CCPA): the natural person whose personal data is processed. (d) Data Controller / Business (CCPA): the entity that determines the purposes and means of processing — in this case, Renaska. (e) Data Processor / Service Provider (CCPA): the entity that processes data on behalf of and under the instructions of the Controller. (f) Processing: any operation performed on personal data — collection, storage, use, disclosure, transfer, deletion, etc. (g) Authorization / Consent: prior, express, and informed consent from the Data Subject. (h) Database: any organized collection of personal data subject to Processing.
3. Personal Data We Collect
Renaska collects only the data necessary to provide the contracted service (data minimization principle):
(a) Registration data: full name, email address, phone number, and country. (b) Business data: company name, tax identification number (NIT or EIN), business address, industry, and number of employees. (c) Payment data: processed directly by Stripe, Wompi, PayPal, or ePayco in accordance with their own policies; Renaska does not store full credit card numbers, CVV codes, or complete banking credentials. (d) Usage and activity data: active modules, actions performed on the platform, event logs, and timestamps. (e) Managed communications data: messages handled through the unified inbox (WhatsApp Business, Instagram Direct, Facebook Messenger, Telegram) belonging to the Subscriber's own business operations. (f) Subscriber employee data: name, job title, email address, and access permissions entered by the account administrator. (g) Technical data: IP address (truncated for analytics purposes), browser type, operating system, pages visited, referrer, time zone, and cookie data (see Section 13).
Renaska does NOT collect sensitive personal data as defined under Colombian Law 1581, Article 5.
4. Purposes of Processing
Personal data is processed for the following authorized purposes:
(a) Providing the contracted SaaS service: ERP, invoicing, inventory, point of sale, unified messaging, and all active modules. (b) Managing the subscription agreement, billing, and payment collection. (c) Sending transactional communications: payment confirmations, system alerts, module notifications, password recovery, and email verification. (d) Sending commercial communications, product updates, and newsletters — only with prior, express, and revocable consent. (e) Technical support and customer service. (f) Platform security, fraud detection and prevention, and abuse monitoring. (g) Service improvement through usage analytics (anonymized data or with explicit consent). (h) Processing queries via artificial intelligence (Google Gemini) within the AI Agent module, using only information voluntarily submitted by the user in the chat. (i) Compliance with legal obligations and responding to lawful requests from competent authorities (DIAN, SIC, IRS, FTC, and other regulators). (j) Customer onboarding, training, and lifecycle management.
5. Legal Basis for Processing
For account and billing data processed by WLM Business Solutions LLC (United States), U.S. law applies. Section 5 of the Federal Trade Commission Act (FTC Act, 15 U.S.C. § 45) prohibits unfair or deceptive acts; every statement in this Policy is a binding commitment enforceable by the FTC. The California Online Privacy Protection Act (CalOPPA, Cal. Bus. & Prof. Code § 22575) applies as soon as any California resident uses the service, requiring us to post this Policy conspicuously and disclose how we respond to Do Not Track signals (see Section 13). CCPA/CPRA rights are included as best practice; they become legally mandatory if Renaska exceeds $26,625,000 in annual gross revenue or processes data of 100,000+ consumers per year — thresholds not currently met.
For processing by Agencia Leidy Echavarria S.A.S. under Law 1581/2012 (Arts. 6, 9, 10): (a) Performance of the subscription contract: the primary basis. (b) Prior, express, and informed consent: obtained at registration or via the cookie banner; silence does not constitute consent (Decree 1377/2013, Art. 7). (c) Legal obligation: record retention. (d) Legitimate interest: platform security and fraud prevention, subordinate to the Data Subject's rights. Renaska does NOT sell or share personal data for cross-context behavioral advertising.
6. Sensitive Data Processing
Renaska does not collect, store, or process sensitive personal data as defined under Colombian Law 1581, Article 5 (health data, sexual orientation, racial or ethnic origin, political opinions, religious beliefs, biometric data, or trade union membership).
Should any future module or feature require processing of sensitive data, Renaska will: (i) obtain separate, explicit consent from the Data Subject; (ii) update this Policy with at least 10 calendar days' advance notice; and (iii) make any required filings with the Colombian Superintendency of Industry and Commerce (SIC) as mandated by applicable law.
7. Sharing with Third Parties (Sub-processors)
Renaska shares personal data exclusively with the following Data Processors (sub-processors), under contractual instructions and Data Processing Agreements (DPAs) that ensure appropriate levels of protection:
(a) Neon Inc. — PostgreSQL database hosting (USA / EU). (b) Cloudflare Inc. — R2 file storage and content delivery (USA / global). (c) Redis Inc. (redis.io) — Redis cache and message queues (USA). (d) Stripe Inc. — international payment processing (USA). (e) Wompi (WOMPI S.A.S.) — payment processing in Colombia. (f) PayPal Holdings Inc. — payment processing (USA). (g) ePayco (EPAYCO.COM S.A.S.) — payment processing in Colombia. (h) Meta Platforms Inc. — WhatsApp Business, Instagram Direct, and Facebook Messenger (USA / Ireland). (i) Telegram FZ-LLC — Telegram messaging (Dubai, UAE). (j) Google LLC — OAuth 2.0 authentication and Gemini AI (USA). (k) SMTP provider configured by Subscriber — transactional email (infrastructure defined by the client).
Renaska does NOT sell, rent, lease, or disclose personal data to third parties for their own purposes unrelated to the contracted service.
8. Data Processed Outside Colombia — Structural Disclosure
Although Agencia Leidy Echavarria S.A.S., the Data Controller, is domiciled in Colombia, the platform's technical infrastructure (databases, file storage, cache, messaging, and processing) is located primarily in the United States and the European Union (see Section 7). Accordingly, using the Service entails the transmission of Colombian data subjects' data to Data Processors located abroad, primarily in the United States — a country that does not hold a formal adequacy determination from the Colombian SIC.
In accordance with Colombian Law 1581, Article 26 and SIC External Circular 003 of December 19, 2025 (which adopts Model Contractual Clauses for international transfers to countries without an adequacy determination), this cross-border processing is supported by: (a) The prior, express, and informed consent of the Data Subject given at the time of registration and acceptance of this Policy; by using the Service, Colombian users expressly consent to their data being processed in the USA. (b) The adoption by Renaska of the Model Contractual Clauses established under SIC External Circular 003/2025, which constitute the adequate guarantee for the international transfer of personal data to the USA. (c) Data Processing Agreements (DPAs) with each sub-processor incorporating equivalent protection obligations consistent with Colombian requirements. (d) Internationally recognized security certifications held by sub-processors (SOC 2 Type II, ISO 27001). Renaska maintains an up-to-date record of sub-processors and their locations, available upon request from the SIC or Data Subject at [email protected].
9. Data Retention
Personal data is retained for the following periods:
(a) Account and business profile data: for the duration of the active subscription. Upon cancellation, retained for 30 days to allow data export, then securely deleted or irreversibly anonymized. (b) Billing and accounting records: up to 10 years in accordance with Colombian fiscal obligations (DIAN) and up to 7 years for U.S. tax-relevant records. (c) Managed communications (inbox): up to 2 years or the retention period configured by the Subscriber in the platform, whichever is shorter. (d) Subscriber employee data: deleted or anonymized within 30 days of contract termination. (e) Security and audit logs: up to 12 months. (f) Cookie consent records: 12 months from the last consent update, renewed upon material policy changes.
Upon expiry of these periods, data is securely deleted using processes that prevent recovery, or irreversibly anonymized. Subscribers may request early deletion by submitting a formal request to [email protected], unless a legal obligation requires continued retention.
10. Rights of Data Subjects
Under Colombian Law 1581 of 2012 (Articles 8 and 16) and, for California residents, under the CCPA/CPRA, Data Subjects have the following rights:
(a) Right to Know (Access): access to the personal data Renaska processes about you and information on its origin, use, purposes, and recipients. (b) Right to Update and Rectify: correct inaccurate, incomplete, or misleading data. (c) Right to Deletion (Right to be Forgotten): request erasure of data when no legal or contractual obligation requires its retention. (d) Right to Revoke Consent: withdraw consent at any time without retroactive effect (Law 1581, Art. 8.e). (e) Right to Object: object to processing based on legitimate interest where there are substantiated grounds. (f) Right to Lodge a Complaint: file a complaint with the Colombian Superintendency of Industry and Commerce (SIC) at www.sic.gov.co | 01 8000 910165.
Additional rights for California residents (CCPA/CPRA): (g) Right to Data Portability: receive a copy of your data in a machine-readable format. (h) Right to Correct Inaccurate Personal Information. (i) Right to Limit Use and Disclosure of Sensitive Personal Information. (j) Right to Non-Discrimination: Renaska will not provide inferior service or penalize you for exercising your privacy rights. (k) Right to Opt-Out of Sale or Sharing: Renaska does not sell personal information or share it for cross-context behavioral advertising; this right is satisfied by design. (l) Right to Lodge a Complaint with the FTC (www.ftc.gov) or the California Attorney General (www.oag.ca.gov).
11. How to Exercise Your Rights
To exercise any of the rights described in Section 10, please:
1. Submit a written request to [email protected] including: (i) your full legal name; (ii) your national ID, passport number, or other verifiable identifier; (iii) a clear description of the right you wish to exercise; (iv) your preferred contact address for the response.
2. Renaska will acknowledge receipt of your request within 2 business days.
3. If your request is incomplete, Renaska will notify you within 5 business days to provide the missing information, without this interrupting the response deadline.
4. Renaska will respond within 15 business days of receiving the complete request. We apply this 15-business-day deadline uniformly to all users, as it is the shorter of Colombian Law 1581 (Art. 14, 15 business days) and the CCPA (§ 1798.130, 45 calendar days).
5. If Renaska cannot respond within the legal deadline, it will communicate the reasons for the delay before the deadline expires.
6. Exercising your rights is free of charge. For requests that are manifestly unfounded or excessive (particularly if repetitive), Renaska may charge a reasonable administrative fee or decline to act, providing written justification.
12. Information Security
Renaska implements technical, organizational, and physical security measures appropriate to the level of risk, to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction:
(a) Encryption in transit: TLS 1.3 for all communications between clients and Renaska servers. (b) Encryption at rest: AES-256 for the database (Neon PostgreSQL) and file storage (Cloudflare R2). (c) Multi-tenant isolation: each company operates on an independent PostgreSQL schema (`tenant_{slug}`), preventing cross-tenant data access. (d) Access control: Role-Based Access Control (RBAC) with owner / admin / agent / viewer roles and the principle of least privilege; short-lived JWT authentication tokens plus httpOnly Secure SameSite refresh token cookies. (e) Two-factor authentication (2FA): available and strongly recommended for all users. (f) Incident response: in the event of a security breach affecting personal data, Renaska will notify affected Data Subjects and the Colombian SIC within 15 business days of becoming aware of the incident (Decree 1377/2013, Art. 17.b). For U.S. users, Renaska will comply with applicable state data breach notification laws. (g) Periodic security reviews and vulnerability management. (h) Employee access restricted on a need-to-know basis.
13. Cookies and Similar Technologies
Renaska uses cookies and similar technologies (pixels, local storage) on renaska.com, renaska.co, and renaska.us. Cookies are classified into the following categories:
(a) Essential: necessary for basic platform operation (user session, CSRF token, language and theme preferences). No prior consent is required; these cannot be disabled. (b) Functional: enhance the user experience (UI preferences). Require prior consent. (c) Analytics: measure platform usage to improve the service. Require prior consent. (d) Marketing and advertising: retargeting and campaign measurement. Require prior consent.
On your first visit to the site, a cookie banner will appear where you can: "Accept All," "Reject Optional," or "Customize" your preferences by category. You can revoke or modify your consent at any time via the "Manage cookies" link in the page footer. In accordance with Colombian Decree 1377/2013, Article 7, silence does not constitute authorization; non-essential cookies are not activated until you expressly click to accept. Consent records are retained for 12 months and renewed upon material policy changes.
California residents: we do not use cookies to sell personal information or for cross-context behavioral advertising without your consent.
Do Not Track (CalOPPA — Cal. Bus. & Prof. Code § 22575(b)(7)): Renaska does NOT currently alter its data collection practices in response to "Do Not Track" or similar signals transmitted by web browsers. This disclosure is required by California law; it does not indicate active tracking behavior.
14. Children's Privacy
Renaska is a business management platform intended exclusively for individuals aged 18 and older and for authorized representatives of business entities. The platform is not directed at minors.
Renaska does not knowingly collect personal data from children under 14 years of age (Colombian Law 2489 of 2025) or from children under 13 years of age (U.S. Children's Online Privacy Protection Act — COPPA, 15 U.S.C. §§ 6501–6506). If we discover that we have inadvertently collected data from a minor without appropriate parental or guardian authorization, we will delete that information immediately. If you believe a minor has provided personal information to Renaska, please contact us at [email protected].
15. Changes to This Policy
Renaska may update this Policy when necessary to reflect changes in our service, applicable law, or data processing practices.
For material changes (new purposes, new sub-processors, changes to Data Subject rights): (a) We will notify Data Subjects at least 10 calendar days in advance by email and/or via a prominent notice on the platform. (b) Where required by Colombian Decree 1377/2013, Article 9, we will request new explicit consent before applying the changes. For non-material changes (typographical corrections, updated contact details): we will simply publish the updated version. All versions include the last-updated date in the header of this page.
16. Data Protection Officer Contact
Data Protection Officer — Colombia (Law 1581/2012):
Email: [email protected] | Subject: "DATA PROTECTION — [Your Name]" | Response time: up to 15 business days (applied uniformly to all users) | Data Controller: Agencia Leidy Echavarria S.A.S. (NIT 901.147.131-7), Calle 34B #65D 43, Medellín, Colombia | Billing entity: WLM Business Solutions LLC, 1111B S Governors Ave STE 3961, Dover, DE 19904, USA.
CCPA / CPRA Privacy Requests — California, USA (CPRA § 1798.130):
Email: [email protected] | Subject: "CCPA REQUEST — [Your Name]" | Response time: up to 15 business days.
Regulatory authorities: Colombia — Superintendency of Industry and Commerce (SIC): www.sic.gov.co | 01 8000 910165. USA — Federal Trade Commission (FTC): www.ftc.gov | California Attorney General: www.oag.ca.gov.
17. Effective Date
This Privacy and Personal Data Processing Policy takes effect on June 26, 2026, and will remain in force until modified, replaced, or revoked by Renaska.
The most current version will always be available at: renaska.us/legal/privacy (English version) and renaska.com/legal/privacy (Spanish version). By using Renaska's services after this date, the Data Subject acknowledges having read, understood, and accepted the content of this Policy.