Privacy Policy & Personal Data Protection
Data processing framework, Habeas Data compliance, and international standards
Regulatory Framework
SERVICES BUSINESS S.A.S. (NIT: 901343449, "SerBusiness"), in compliance with Colombian Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013, and the guidelines of the Superintendency of Industry and Commerce (SIC), establishes the following guidelines for the collection, storage, use, and deletion of personal data on the Landing Hunter platform.
1.Roles in Data Processing
- SerBusiness as Data Controller: For identification, usage, technical support, and traceability data of registered Users of the Landing Hunter platform.
- Polar (polar.sh) as Merchant of Record and delegated payment custodian: All transaction collection, international billing, tax compliance (VAT, Sales Tax), and payment method custody is operated exclusively by Polar under its terms of service (https://polar.sh/legal/terms). SerBusiness and Landing Hunter do not collect, process, store, or retain credit card numbers, expiration dates, or CVV/CVC codes; the entire transactional infrastructure operates under PCI-DSS Level 1 security certification custodied by Polar.
- SerBusiness as Data Processor for leads: For data captured through forms on landing pages published by Users. The User acts as sole Data Controller with respect to their own landing page visitors.
2.Categories of Data Collected
- Account holder data: Name, surname, identification document, company name, email address, country, technical IP records, and access logs. SerBusiness expressly declares that it does NOT store, does NOT collect, and does NOT have access to card numbers, banking credentials, or CVV codes.
- Operational content & generative inputs: Prompts, brand guidelines, uploaded reference documents (PDF, Word, TXT), and logos. SerBusiness does not use this information to train public Artificial Intelligence models and does not sell or trade its data with third parties.
- Measurement & tracking identifiers: Technical identifiers voluntarily inserted by the User (Meta Pixel ID, Meta CAPI tokens, Google Tag Manager, Google Analytics 4). This data travels directly between the visitor's browser and the respective provider's servers.
- Sub-processors: To operate the Service, SerBusiness relies on the following technology providers, each under its own data protection framework: Google Cloud / Firebase (hosting, authentication and database), our Artificial Intelligence infrastructure provider (for processing the generative assets described above, operated under a generic engine without a publicly disclosed brand affiliation), Polar.sh (payments, see Section 1), Resend (transactional communications), and Upstash (infrastructure caching). SerBusiness selects providers offering contractual data protection guarantees and may update this list as the Service infrastructure evolves.
3.Purposes of Data Processing
- Managing the creation, authentication, and administration of the User's account.
- Synchronizing subscription status and top-ups with the Polar platform.
- Enabling the technical operation of the generation, publishing, and code export engine.
- Providing technical support, handling requests, and delivering mandatory operational notifications.
- Sending commercial communications about updates (with a voluntary opt-out option in every message).
- Safeguarding infrastructure security and preventing fraudulent activity.
4.International Data Transmission and Transfer
For the proper delivery of the SaaS service and the management of global billing through Polar, the User expressly authorizes the transmission or transfer of data to computing centers, cloud servers, and payment processors located abroad (including the United States and the global infrastructure of the sub-processors listed in Section 2), under providers that guarantee rigorous cybersecurity and confidentiality standards endorsed by applicable regulations. Where the data subject is located in the European Economic Area, such transfer is safeguarded by the European Commission's Standard Contractual Clauses (SCCs) and/or the Data Processing Addenda executed with each sub-processor, mechanisms the data subject may request to review through the procedure described in Section 6.
5.International Data Subject Rights Matrix (Multi-Jurisdictional)
SerBusiness guarantees data subjects the binding exercise of their privacy rights under a rigorous multi-jurisdictional standard:
- Colombia & LATAM (Law 1581 of 2012 / Habeas Data): Knowing, updating, and correcting personal data held by SerBusiness, requesting proof of the authorization granted, being informed of its specific use, filing complaints with the Superintendency of Industry and Commerce (SIC), revoking authorization or requesting data deletion where no legal or contractual retention duty exists, and free access to one's personal data.
- European Union & United Kingdom (GDPR / UK GDPR): Rights of Access (Art. 15), Rectification (Art. 16), Erasure / Right to be Forgotten (Art. 17), Restriction of Processing (Art. 18), Data Portability (Art. 20), and Objection to Processing (Art. 21). Processing is based on contractual necessity (Art. 6.1.b) and legitimate interest.
- California / United States (CCPA / CPRA): The right to know the categories and specific elements of personal information collected, the right to request deletion of personal information, the right to correct inaccurate information, and the right to non-discrimination for exercising these rights. SerBusiness expressly declares it does NOT sell or share personal information in exchange for monetary or other valuable consideration ("Do Not Sell or Share My Personal Information").
- Brazil (LGPD - Law 13.709/2018): Confirmation of the existence of processing, access to data, correction of incomplete or inaccurate data, anonymization, blocking or deletion of unnecessary or excessive data, and data portability to another service provider in accordance with ANPD regulations.
6.Procedure for Exercising Data Subject Rights
To exercise the rights described in section 5 (Habeas Data, GDPR/UK GDPR, CCPA/CPRA and LGPD), the data subject or their successors may file a request by email to privacy@landinghunter.com, indicating their full name, identification document, a description of the facts, and the specific request sought:
- Inquiries: Addressed within a maximum term of ten (10) business days from the date of receipt. If this term cannot be met, the requester will be informed before its expiration, stating the reason and the response date, which shall not exceed five (5) additional business days.
- Complaints: Resolved within a maximum term of fifteen (15) business days from the day following complete receipt. If an extension is required, the requester will be notified for a period not exceeding eight (8) additional business days.
- Applicable deadlines: the deadlines above are those of Colombian law, without prejudice to the deadlines set by the law applicable to the data subject's place of residence (for example, the GDPR or the LGPD).
7.Information Security and Retention
SerBusiness adopts administrative, technical, and technological measures (encryption in transit via HTTPS/TLS protocols, strict access controls, and periodic backups) to mitigate risks of alteration, loss, or unauthorized access. Account data is retained for the duration of the contractual relationship and, after its termination, for the period legally required for the preservation of accounting, tax, and legal support records.
