En WebToi nos comprometemos a proteger su información personal de acuerdo con el GDPR, CCPA, la Ley 25 de Quebec y PIPEDA.
1. Información que Recopilamos
We collect personal information that you voluntarily provide when you contact us or use our services, including:
- Personal Details: Name, email address, phone number, and contact preferences.
- Business Information: Company name and project requirements shared through contact forms.
- Usage Data: Browser type, IP address, pages visited, and time spent on pages (via analytics cookies).
- Chatbot Interactions: Messages exchanged with our support chatbot, used to improve service quality.
- Google Account Data: When you connect a Google account via OAuth, we store encrypted access and refresh tokens, your Google email address, display name, and profile picture. We do not store the contents of your Gmail, Calendar events, or YouTube data beyond what is necessary to provide the requested service features.
2. Cómo Usamos su Información
We use the information we collect to:
- Provide, operate, and improve our services.
- Send administrative communications and respond to inquiries.
- Send marketing communications (only with your explicit consent).
- Analyze website usage to improve user experience.
- Integrate with Google services (Calendar, Gmail, Meet, YouTube, Business Profile) on your behalf when you authorize this connection.
- Comply with legal obligations.
3. Servicios Google API
Nuestra aplicación usa los Servicios de API de Google para conectar Calendario, Gmail, Google Meet, YouTube y Google Business Profile. Cumplimos con la Política de Datos de Usuario de los Servicios de API de Google.
Specifically regarding Google user data:
- We request only the minimum OAuth scopes necessary to provide the requested features.
- We do not use Google user data to develop, improve, or train generalized AI or ML models.
- We do not sell Google user data to third parties.
- We do not use Google user data for advertising purposes.
- Access tokens and refresh tokens are stored encrypted using AES-256-GCM in Google Cloud Firestore.
- You can revoke our access to your Google account at any time via Google Account Permissions.
Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Compartir Información
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Service Providers: Trusted third-party services that help us operate (e.g., Google Cloud, Firebase). These parties are contractually bound to protect your data.
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with advance notice provided to users.
- With Your Consent: Any other sharing with your explicit prior consent.
5. Sus Derechos
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data (right to be forgotten).
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request restriction of how we process your data.
- Opt-Out: Withdraw consent for marketing communications at any time.
- Google Revocation: Revoke our access to your Google account at myaccount.google.com/permissions.
To exercise these rights, contact us at team@webtoi.com.
6. Retención de Datos
We retain your personal information only as long as necessary to provide our services and comply with legal obligations:
- Account data: Retained while your account is active and for 30 days after deletion request.
- Google OAuth tokens: Deleted immediately upon account disconnection or upon your request.
- Analytics data: Retained for up to 26 months in anonymized form.
- Chatbot records: Retained for up to 12 months to improve service quality.
7. Seguridad
We implement industry-standard technical and organizational measures to protect your personal data:
- OAuth tokens are encrypted at rest using AES-256-GCM.
- All data in transit is protected by TLS 1.2 or higher.
- Access to personal data is restricted to authorized personnel only.
- We use Google Cloud infrastructure, which complies with ISO 27001, SOC 2, and other certifications.
8. Cookies
We use cookies and similar technologies to improve your experience. Types of cookies we use:
- Essential: Required for the website to function. Cannot be disabled.
- Analytics: Help us understand how visitors interact with our website (anonymized).
- Chatbot Records: Enable our support chatbot to maintain conversation context.
9. Delegado de Privacidad
In accordance with Quebec Law 25 and PIPEDA, we have designated a Privacy Officer:
Privacy Officer Contact:
Email: team@webtoi.com
Address: Montreal, Quebec, Canada
Website: https://webtoisitetemplate.web.app
10. Contacto
If you have questions, complaints, or requests regarding this Privacy Policy or our data practices, please contact us at team@webtoi.com. We will respond within 30 days.