Privacy policy
What data we process, what for, who we share it with and what you can ask of us. Written to be understood without being a lawyer.
01Data controller
Zetta is a cloud ERP for Argentine companies. This document explains what personal data is processed through the website zetta.ar, the application app.zetta.ar and the commercial relationship with each customer company.
- Project
- Zetta
- Operating address
- Autonomous City of Buenos Aires, Argentina
- Email for personal data
- privacidad@zetta.ar
- General email
- hola@zetta.ar
Legal entity being incorporated
02Legal framework and supervisory authority
Processing is governed by Law 25.326 on the Protection of Personal Data, its Regulatory Decree 1558/2001 and the provisions of the Agency for Access to Public Information (AAIP), successor to the National Directorate for the Protection of Personal Data.
Zetta's databases are registered and kept up to date in the National Registry of Databases as required by the regulations in force.
03Who is responsible for each piece of data
There are two distinct situations and it is best not to mix them, because they change who is responsible.
Zetta as controller
When the data belongs to the relationship between Zetta and the customer company —each user's login account, contact details, technical and security logs, the website forms— the data controller is Zetta and Zetta is the one who decides about that data.
Zetta as processor
When the customer company enters data about its customers, employees or suppliers into the system, the company is the controller of that data and Zetta is the data processor: it processes it on behalf of and under the instructions of the company, solely to provide the service, and does not use it for any purpose of its own.
In practical terms: if you are a customer, employee or supplier of a company that uses Zetta and you want to access, correct or delete your data, the request goes to that company. If it reaches us, we forward it to the responsible company and assist it so it can respond on time.
04What data we process
Account and access
First and last name, username, email address, phone number if provided, role within the company and account preferences. The password is stored with bcrypt, never in plain text, and cannot be recovered. If the second factor is enabled, the TOTP secret and the recovery codes are also stored.
Company data
Company name, CUIT, VAT status, address, contact and billing details. If the company enables electronic invoicing, its AFIP certificate and private key; if it enables payments, its Mercado Pago token. Both are stored encrypted with AES-256-GCM, as are OAuth tokens.
Operational data entered by the company
Customers, suppliers, employees, documents, products, stock, cash movements and journal entries. This is the company's data; Zetta processes it as a processor and it lives in that company's PostgreSQL schema, separate from any other.
Technical and security data
IP address, browser type and operating system (user agent), date and time of each access, failed login attempts, open sessions and the audit log: every creation, change and deletion is recorded with its author, the entity affected and the detail of what changed. That log exists so that what happened can be reconstructed in the event of a problem or a claim.
Corporate website data
What is filled in on the contact and demo request forms: name, email, company, phone number if provided and the message. In addition, site usage measurement: Vercel Analytics uses no cookies and identifies no one, and Google Analytics 4 is only activated if you accept it. The details are in the cookie policy.
We do not ask for or want sensitive data within the meaning of Article 2 of Law 25.326 (racial or ethnic origin, political opinions, religious beliefs, health or sexual life) beyond what a company may need to enter to run payroll. Nor does Zetta store credit or debit card data: payments are processed in Mercado Pago.
05What we use it for and on what legal basis
Each processing activity has a specific purpose and a basis that permits it. We do not use the data for anything not in this table.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the contracted service and giving each user what their role allows | Account and access, company data, operational data | Performance of the contract (Art. 5, para. 2.d, Law 25.326) |
| Protecting accounts, preventing unauthorised access and being able to reconstruct what happened | Technical and security data, audit log | Duty of security and confidentiality (Arts. 9 and 10, Law 25.326) |
| Responding to support requests and notifying incidents or changes to the service | Account and access, technical data | Performance of the contract |
| Responding to demo and contact requests | What is entered in the form | Consent of the person filling in the form |
| Meeting tax and accounting obligations and requests from a competent authority | Company and billing data | Legal obligation |
| Measuring which pages of the corporate website are read | Aggregated browsing data | Consent (cookie-based analytics) and legitimate interest (cookieless measurement) |
What we do not do: we do not sell data, we do not pass it to advertising networks, we do not combine data across customer companies and we do not access a company's operational data unless it asks us to in order to resolve a specific problem. Any access from the platform panel is recorded in the audit log.
06Who it is shared with
Zetta relies on providers acting as sub-processors: they process data solely to provide us with their service, under the instructions and limits we set. This is the complete list.
| Recipient | Purpose | Where it processes |
|---|---|---|
| Vercel Inc. | Hosting of the corporate website, the ERP front end and the online store | United States and global network |
| Cloudflare, Inc. | Content delivery network, traffic protection and storage of files and backups (R2) | Global network |
| Resend | Transactional email delivery: documents, security notices and access recovery | United States |
| Mercado Pago | Payment processing with the customer company's own account and token. Zetta neither sees nor stores card data | Argentina |
| AFIP | Public body, not a provider: it receives the documents the company issues, with the company's own certificate | Argentina |
| Provider of the assistant's model (Anthropic by default; the installation may point to an OpenAI-compatible provider or to a self-hosted model) | Processing the assistant's conversation and only the data the query needs. Costs, margins, CUIL, CBU and credentials are never sent | United States, or wherever the model the company configures is located |
| Google Ireland Limited (Google Analytics 4) | Measurement of the corporate website. Only activated if you accept measurement cookies | European Union and United States |
The database and the API run on a server managed by Zetta, with PostgreSQL 16 behind Cloudflare. We may also share data when required by a competent judicial or administrative authority; in that case, if the law allows, we notify the affected company.
07International transfers
Several of the providers in the list above process data outside Argentina. That constitutes an international transfer within the meaning of Article 12 of Law 25.326.
The transfer relies on the need to perform the service contract and on the data processing agreements we sign with each provider, with clauses equivalent to the model contracts approved by the AAIP for data transfers and the provision of processing services. In the case of Google Analytics, the basis is your consent, and without it nothing is sent.
If in the future we change a provider or add a new one, we update the list in this policy before it starts processing data.
08How we protect the data
These are the measures actually in place, not a list of intentions.
- Isolation per company: each company has its own PostgreSQL schema. There are no cross-company queries; the only exception is the platform panel, which is recorded in the audit log.
- Short sessions: access travels in httpOnly cookies that the browser does not expose to scripts. The working session lasts 5 minutes and is renewed with a 7-day token that rotates on every use; there is also anti-CSRF verification on every write operation.
- Second factor: TOTP-based 2FA with single-use recovery codes.
- Brute-force protection: the account is locked for 15 minutes after 5 failed attempts, the IP is automatically blocked after 10 failures and there is a per-origin request limit.
- Encryption: HTTPS on all traffic; passwords with bcrypt; AFIP certificate and key and OAuth tokens encrypted with AES-256-GCM.
- Audit in the database: a PostgreSQL trigger records every creation, change and deletion with author, entity and detail of the change. It does not depend on the application remembering to log it.
- Backups: daily in the early hours, encrypted with age —the private key does not live on the server—, stored in a separate bucket, with 7 daily copies and 35 days of weekly copies, and one test restore per week.
- Observability: centralised logs in Loki/Grafana and application errors in a table and a dashboard, to detect anomalous behaviour.
No system is infallible. If you find a vulnerability, write to us at hola@zetta.ar before disclosing it: we respond and tell you how we resolved it.
09How long it is kept
- Account and operational data: for as long as the account is active.
- Audit log: it lives in the company's own database and is kept together with the rest of its data, because it is what makes it possible to reconstruct who did what.
- Backups: deleted data disappears from the copies when their retention periods expire: 7 days for daily copies and 35 days for weekly ones.
- After cancellation: the full export remains available for 30 calendar days from cancellation. Once that period is over, the company's schema and its files are deleted.
- Zetta's billing to the company: invoices and accounting records are kept for the periods required by Argentine tax and commercial law, even if the account has already been cancelled.
10Your rights and how to exercise them
As the data subject you may request, at any time and without giving a reason:
- Access: to know what data of yours we hold and what we use it for. The response is provided within 10 calendar days of receiving the request (Art. 14, Law 25.326).
- Rectification and update: to correct inaccurate or incomplete data.
- Deletion: to delete data, to the extent there is no legal obligation to keep it. Rectification and deletion are resolved within 5 business days (Art. 16, Law 25.326).
Exercising these rights is free of charge. Write to privacidad@zetta.ar with the subject "Exercise of rights", stating your full name, the email you operate with and what you want to do. We may ask you to prove your identity before responding: it is a protection for you.
If the data you are interested in was entered by a customer company (because you are its customer, employee or supplier), the request belongs with that company; we tell you so and forward it.
11Minors
Zetta is a work tool and is not aimed at anyone under 18 years of age. We do not intentionally collect data from minors through the website or the application.
If we detect that we have received data from a minor without the authorisation of their legal representatives, we delete it. If you think that may be the case, let us know at privacidad@zetta.ar.
12Changes to this policy
We may update this policy if regulations change, if we add a provider or if we change the way we process data. The date of the last update appears at the top of the document.
When the change is material —a new purpose, a new recipient or a longer retention period— we notify customer companies by email at least 30 days before it takes effect.
Contact
Write to us and we answer through the same channel.
Personal data and data subject rights
privacidad@zetta.arGeneral enquiries
hola@zetta.arThis document is published in Spanish. If you are reading a translation, the Spanish version is the only binding one.