Saltar al contenido principal

Privacy and Personal Data Protection Policy

Last updated: July 24, 2024

1. OBJECTIVE, SCOPE, AND USERS

The objective of this Policy is to explain how JELOU S.A. (hereinafter, "JELOU"), owner and operator of the Pocket trademark, collects, uses, stores, shares, and protects the Personal Data¹ of individuals who interact with its products and services, both physical and digital.

This Policy applies to all databases and/or files containing Personal Data processed by JELOU as Data Controller or Processor, regardless of the means of collection (web forms, WhatsApp, e-mail, contracts, etc.).

The Users of this Policy are end Customers, Merchants, Suppliers, Partners, Employees, Ex-employees, and Candidates, in both Ecuador and Mexico.

¹ "Personal Data" = any information that identifies or makes a natural person identifiable.

2. REGULATORY FRAMEWORK

  • Ecuador: Organic Law on Personal Data Protection (LOPDP) and its Regulations.
  • Mexico: Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
  • ISO/IEC 27001 Standard (reference A.18.1.4) and JELOU's internal information security policies.

3. KEY DEFINITIONS

Data Subject: A natural person to whom the Personal Data belongs.

Data Controller: One who decides on the purpose and processing of Personal Data.

Data Processor: One who processes Personal Data on behalf of the Data Controller.

Sensitive Data: Information that affects the privacy of the Data Subject or whose misuse could lead to discrimination (health, biometrics, ethnic origin, beliefs, etc.).

Authorization / Consent: Free, prior, express, and informed manifestation of the Data Subject for the processing of their Personal Data.

4. GUIDING PRINCIPLES

JELOU is committed to processing Personal Data in accordance with the principles of Legality, Consent, Purpose, Quality, Proportionality, Security, Transparency, Confidentiality, Proactive and Demonstrated Responsibility, and, where applicable, Portability.

5. LEGAL BASIS FOR PROCESSING

5.1 Ecuador (LOPDP)

  • Consent of the Data Subject.
  • Execution of a contract or pre-contractual measures requested by the Data Subject.
  • Compliance with a legal obligation.
  • Legitimate interest, duly weighed.

5.2 Mexico (LFPDPPP)

  • Consent of the Data Subject (tacit or express depending on the type of data).
  • Execution of a contract.
  • Compliance with a legal obligation.
  • Legitimate interest of the Controller or Processor, respecting the rights of the Data Subject.

6. PERSONAL DATA PROCESSED

The data collected varies depending on the relationship with the Data Subject and includes, but is not limited to:

  • Identification and contact: name, identity number (RUC/RFC/INE), email, phone, country, address.
  • Financial and billing: card details, bank accounts, payment history.
  • Employment and academic (employees/candidates).
  • Usage data of services, preferences, and activity logs.
  • Sensitive Data (biometrics) only when essential for authentication.

7. PURPOSES OF PROCESSING

7.1 Necessary purposes (service)

  1. Provision of the contracted products and services.
  2. Authentication and access management to the Platform.
  3. Management of payments and collections, accounting reconciliation, and billing.
  4. Customer service and technical support.
  5. Fraud prevention, identity verification, and risk analysis (KYC/AML).
  6. Compliance with legal and contractual obligations.

7.2 Additional purposes (marketing and improvement)

  1. Sending information about news, promotions, and events from JELOU.
  2. Statistical analysis, market research, and user profiling.
  3. Satisfaction surveys and product improvement.

The Data Subject can opt out of receiving marketing communications at any time.

8. RIGHTS OF DATA SUBJECTS

  • Access to their data.
  • Rectification / Update.
  • Cancellation / Deletion ("Right to be Forgotten" in Ecuador).
  • Objection to processing.
  • Data portability.
  • Revocation of consent.
  • Limitation of use or disclosure (Mexico).
  • Not to be subject to decisions based solely on automated processing.

Exercise of rights

Send a request to claims@jelou.ai indicating:

  1. Full name and identity document.
  2. The right you wish to exercise.
  3. A clear description of the request.
  4. Contact details for a response.

JELOU will respond within the legal deadlines:

  • Ecuador: max. 15 business days.
  • Mexico: max. 20 business days.

9. TRANSFERS AND PROCESSORS

JELOU may transfer Personal Data to:

  • Service providers (payment gateways, hosting, support, messaging) acting as Processors.
  • Competent authorities, when required by law or a court order.
  • Companies of the JELOU group located in other countries, ensuring an adequate level of protection (contracts with standard clauses and ISO 27001 technical measures).

No international transfers of Personal Data to third parties will be made without the consent of the Data Subject, except for the exceptions provided by law.

10. SECURITY MEASURES

JELOU applies physical, logical, and administrative controls aligned with the ISMS ISO/IEC 27001, including:

  • Access control (multi-factor, privilege management).
  • Encryption of data in transit and at rest.
  • Monitoring, logging, and auditing of events.
  • Backup copies and continuity plans.
  • Confidentiality policies and staff training.
  • Secure deletion procedures and incident management.

11. RETENTION PERIODS

Personal Data will be kept only for the time necessary to fulfill the described purposes or as long as there is a legal obligation to retain it:

  • Contractual data: duration of the relationship + up to 10 years for defense against claims.
  • Billing data: current tax period (7 years in Ecuador / 5 years in Mexico).
  • Access and security logs: max. 5 years.

12. POLICY CHANGES

Any substantial modification will be notified to the Data Subjects at least 30 days in advance by email or a notice on the Platform.

13. CONTACT AND SUPPORT CHANNELS

  • General e-mail: soporte.pocket@jelou.ai
  • ARCO / Habeas Data rights requests: claims@jelou.ai

14. LEGISLATION AND JURISDICTION

  • Users in Ecuador: LOPDP; jurisdiction of the Data Protection Authority and courts of Guayaquil.
  • Users in Mexico: LFPDPPP; jurisdiction of the INAI and courts of Mexico City.

Want to create your own AI agents and monetize them?

Program your Pocket allows you to build, deploy and scale conversational agents within the Pocket ecosystem, design solutions for businesses, connect your APIs and earn from each transaction they generate.

Jelou Pagos payment interface showing payment methods like Visa and new card, with transaction processing form