Privacy Policy
Last updated: May 27, 2026
This Privacy Policy describes how SecretarIA ("we", "our", or "the platform") collects, uses, stores, shares, and protects the information of users who use our appointment scheduling, reminder, and client communication services.
1. Information We Collect
We collect the following types of information:
- Professional's information: name, specialty, contact details, working hours, and account configuration.
- Client information: name, phone number, and appointment data, only as provided by the professional or client through WhatsApp or the public booking form.
- Authentication information: when you sign in with Google, we receive your name, email address, and unique Google identifier.
1.1 Google Data We Collect
When a professional authenticates their account via Google OAuth, SecretarIA accesses the following Google data:
- Google profile information: name, email address, and unique identifier (Google ID).
- Google Calendar: read and write access to the professional's primary calendar, exclusively to create, modify, and query appointment events.
We do not access or collect: Gmail emails, Google contacts, Google Drive files, photos, location, or any other data from your Google account other than those explicitly mentioned above.
1.2 Meta/Facebook and WhatsApp Data
When a professional connects their WhatsApp Business account, we receive an access token that allows SecretarIA to send and receive WhatsApp messages on their behalf. We do not access their personal Facebook profile, friend list, photos, or posts.
2. How We Use Information
- Appointment management: create, modify, query, and cancel appointments via Google Calendar and the control panel.
- Automatic reminders: send appointment reminder messages to clients via WhatsApp.
- Authentication: allow login to the platform via Google OAuth.
- Service improvement: analyze platform usage to improve its performance and fix errors.
2.1 Specific Use of Google Data
Google data is used exclusively for:
- Synchronizing appointments with the professional's Google Calendar (creating events, modifying them, and deleting them as appropriate).
- Authenticating the professional on the platform (name, email, and Google ID).
SecretarIA does not use Google data for any other purpose, including advertising, data selling, market analysis, profiling, or automated decision-making that affects the user.
2.2 Self-Hosted Artificial Intelligence Model
SecretarIA uses a self-hosted artificial intelligence model to process and respond to user requests. This model operates on our own infrastructure and does not transmit user data to third-party AI service providers. This ensures that user information remains under our control at all times.
3. Who We Share Data With
SecretarIA does not sell, rent, or trade personal data of any kind to third parties.
Data is only shared in the following limited circumstances:
- With the professional themselves: their clients' data is available in their control panel.
- With infrastructure providers: we use our own servers to store data; we do not use third-party services for personal data processing.
- With Meta (WhatsApp): messages sent to clients are transmitted through the WhatsApp Business API.
- With Google: appointment events are synchronized with the professional's Google Calendar through the Google API.
We do not share, transfer, or disclose Google data to any third party, except to send data back to Google Calendar (which is the professional's own account).
4. Data Security and Protection
We implement the following security measures to protect personal data and Google data:
- Encryption in transit: all communications use HTTPS/TLS.
- OAuth tokens: Google access tokens are stored securely and transmitted exclusively through encrypted channels.
- Passwords: stored as cryptographic hashes (bcrypt); never in plain text.
- Restricted access: only the authenticated professional can view their own data and their clients' data.
- Revocation: the professional can revoke SecretarIA's access to their Google account at any time from myaccount.google.com/permissions.
5. Data Retention and Deletion
5.1 Professional Data
We retain the professional's data while their account is active. Upon requesting account deletion, all their personal data and access tokens are permanently deleted within a maximum of 30 days.
5.2 Google Data
Google access tokens and refresh tokens are stored only while the professional keeps the Google Calendar integration active. The professional can disconnect their Google account at any time from the settings panel, which will immediately delete all stored Google tokens.
5.3 Client Data
Client data (names, phone numbers, and appointment history) is retained for a maximum period of 12 months after the last interaction, unless the professional or client requests earlier deletion.
6. User Rights
Professionals and clients have the right to:
- Access: request a copy of their personal data.
- Rectification: request correction of inaccurate data.
- Deletion: request deletion of their data from our systems.
- Revocation: withdraw consent for data processing at any time.
To exercise any of these rights, email us at [email protected]. You can also use our Data Deletion page.
7. Changes to This Policy
We may update this Privacy Policy periodically. Significant changes will be notified to registered professionals by email. Continued use of the service after an update implies acceptance of the new version.
8. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us:
- Email: [email protected]
- Website: secretar-ia.com.ar
Google API Compliance
SecretarIA complies with the Google API Services User Data Policy.