Privacy Policy

What we collect, why we collect it, who else sees it, how long we keep it, and how to make us delete it. Written to be read, not to be survived.

Last updated · 5 August 2026

01Who is responsible for your data

Thallo Digital is the data controller (responsable del tratamiento) for the personal data described here. Our details are at the foot of this page, and privacy requests reach a person at contact@thallodigital.com.

This policy is issued under Law 1581 of 2012 and Decree 1377 of 2013 of the Republic of Colombia, which govern the protection of personal data (habeas data).

02What we collect

We only collect what a specific purpose needs. In practice that is three things.

  • When you contact us — your name, email address, company and whatever you write in your message. You choose what to put in it.
  • When you run the free visibility scan — the brand name, website domain and category you enter. These are business details, not personal ones. If you choose to unlock the full report, we also receive the email address you give us.
  • When you become a client — the contact and billing details needed to run and invoice the engagement, plus whatever access you grant us to do the work.

We do not ask for, and have no use for, sensitive personal data as Law 1581 defines it. Please do not send it to us. We do not knowingly collect data from children.

03Your IP address is not stored

The scanner has to know that one visitor is not running it a hundred times a day. It does that without keeping your address: the address is combined with a secret salt and hashed, and only the hash is written to the database. The hash cannot be reversed into an address, so the table cannot be used to work out who ran a scan — only that two scans came from the same visitor.

04Cookies and tracking

This website runs no analytics, no tag manager, no advertising pixel and no tracking cookie. We do not build a profile of you, we do not follow you across other sites, and we do not sell or rent data to anyone — ever.

Our blog runs on WordPress at the /blog/ path and may set functional cookies of its own — for example if you leave a comment or log in. Those serve the blog’s own operation and are not used for tracking.

05Why we are allowed to use it

  • Your authorisation — given when you submit a form or an email address to unlock a report. You can withdraw it at any time.
  • To perform a contract — running, supporting and invoicing an engagement you have with us.
  • Our legitimate interest in operating the site securely, including the abuse limits described in clause 3.
  • Legal obligations — accounting and tax records we are required to keep.

06Who else sees it

We share personal data only with the providers that make the service work, and only with what they need:

  • AI model providers — the scan sends its category questions to third-party models through OpenRouter (which routes to providers such as OpenAI, Anthropic and Google) and to Perplexity. The questions contain the brand, domain and category being scanned. Your email address is never sent to them.
  • Hosting — our website, blog and scan database are hosted by our hosting provider, which stores the data on our behalf.
  • Payment processing — card payments are handled by Stripe under its own privacy policy. We never receive or store your full card number.
  • Authorities — where a law or a court order requires it.

Some of these providers operate outside Colombia, so using this site involves an international transfer of data to countries whose rules may differ. We only use providers that commit contractually to protecting the data to a standard comparable with Law 1581.

07How long we keep it

  • Scan working data — the questions, the answers and the hashed visitor identifier — is deleted automatically after the retention period set in the tool, which is 14 days by default.
  • An email address given to unlock a report is kept until you ask us to delete it, or until it is clear you are no longer interested in hearing from us.
  • Client records are kept for the life of the engagement and afterwards for as long as accounting and tax law requires.
  • Emails you send us are kept while they are useful to the conversation, and deleted when they are not.

08Your rights

Under Law 1581 of 2012, at any time and free of charge, you may:

  • Know what personal data of yours we hold, and where it came from.
  • Update or correct anything that is wrong, incomplete or out of date.
  • Delete it, where there is no legal obligation for us to keep it.
  • Withdraw the authorisation you gave us, which we act on unless the law requires otherwise.
  • Ask for proof of the authorisation you gave.
  • Complain to the Superintendencia de Industria y Comercio (SIC) if you believe we have not respected these rights.

Write to contact@thallodigital.com and we will answer within the periods the law sets: 10 business days for a query, 15 business days for a complaint, extendable once where we tell you why. We may ask you to confirm your identity first, so that nobody else can act on your data.

09Keeping it safe

Data is transmitted over encrypted connections and access to it is limited to the people who need it. API keys and secrets are held on the server and are never exposed to the browser. No system is perfectly secure, but if a breach affects your personal data we will notify you and the SIC as the law requires.

10Changes

We update this policy when what we do with data changes. The date at the top shows when this version was issued; material changes are announced on this page before they take effect.

Who you are contracting with

Company
Thallo Digital