Last updated: July 1, 2026
This policy describes what personal data Got Koffee processes, for what purposes, and with which providers, in compliance with Peru's Personal Data Protection Law (Law 29733) and, where applicable, the GDPR.
Account data: name, email, and login data. Usage data: platform activity, campaign metrics, and technical logs. Billing data is handled by Paddle (Merchant of Record); we do not store card numbers.
Prospect data: the B2B information you upload or the platform researches (name, role, company, business email) is processed on your behalf — you are the data controller and Got Koffee acts as processor.
Providing the service (research, campaign sending and tracking), operating billing, improving the product with aggregate metrics, and communicating with you about the service. We do not sell personal data.
We use infrastructure and service providers that may process data outside Peru: Vercel (hosting), Supabase (database and authentication), Paddle (payments), Resend (transactional email), SmartLead (sending infrastructure), and AI model providers for assisted copywriting. Each processes data under its own contractual safeguards.
We retain data while the account is active and for legally required periods after closure. We apply encryption in transit, per-tenant isolation (Row-Level Security), and role-based access control.
You may exercise access, rectification, erasure, and objection rights (and portability where GDPR applies) by writing to franco@gotkoffee.com. We respond within statutory deadlines. If you received an email sent by one of our customers, every message includes an opt-out mechanism.
We use strictly necessary cookies for session and language preference. We do not use third-party advertising cookies.