This Privacy Policy explains what personal data we collect, why, who we share it with and what rights you have. It covers the website data-metrics.pro, our professional services and the applications and automations we operate on third-party platforms (Meta, TikTok, LinkedIn, Google and similar).
1. Who is responsible
The data controller is Datametrics Technology S.A.C. ("Datametrics", "we"), Peruvian tax ID (RUC) 20611645971, registered at Cal. Enrique Palacios 360, Int. 608, Miraflores, Lima 15074, Peru.
- Privacy and data-protection contact (questions, rights requests, deletion): privacy@data-metrics.pro
- Security contact (incidents, vulnerability reports): security@data-metrics.pro
- General contact: sergio@data-metrics.pro
- Phone: +51 933 363 169
Datametrics is incorporated in Peru and is governed by Peruvian Personal Data Protection Law No. 29733 and its Regulations. When we serve clients or users in other countries we additionally apply the applicable local law (see section 12).
2. What this policy covers
We process personal data in three distinct contexts, each with its own section below:
- The website data-metrics.pro: forms, resource downloads, meeting scheduling, analytics and cookies.
- Professional services: Odoo ERP implementation, audit and rescue, data engineering, analytics and integrations. Here we normally act as a data processor on behalf of the client.
- Datametrics Applications: software we connect, with the client's authorisation, to third-party platforms in order to (a) automate customer conversations on WhatsApp, Instagram, Facebook Messenger, TikTok and similar channels, and (b) schedule and publish social-media content. Datametrics Applications include Chato (chato.lat), Datametrics' conversational-automation product. These applications access data exclusively through each platform's official APIs.
3. Data we collect on the website
3.1 Data you send us
When you fill in a form (contact, resource download, newsletter) or book a meeting, we collect what you enter: name, email address, phone (optional), company (optional), country and the message or query you write.
3.2 Attribution data
To understand which channel brought you here (search, ad, social network, direct link) we store alongside your request: UTM parameters, advertising click identifiers (gclid, fbclid, ttclid, msclkid, yclid), landing page, the page the form was sent from, referrer, your browser's user agent and — where present — analytics cookie identifiers (_ga, _fbp, _ym_uid). This data is used solely to measure the effectiveness of our marketing and is not shared with third parties beyond the analytics tools that generate it.
3.3 Analytics and advertising data
Subject to your cookie consent, the site uses Google Analytics 4 (audience measurement), Meta Pixel and the Meta Conversions API (campaign measurement on Facebook and Instagram) and PostHog (product analytics, served from our own domain). See section 11 "Cookies".
3.4 Technical data
Our servers keep standard logs of IP address, date and time, requested URL and user agent. They are used for security, abuse detection and troubleshooting and are retained for a maximum of 90 days.
4. Data in professional services
When we implement, audit or integrate systems for a client (Odoo ERP, data warehouses, dashboards, integrations) we access the data that client holds in their systems: contacts, customers, suppliers, employees, invoices, inventory, etc. In this context:
- the client is the data controller and Datametrics acts as processor, following the client's documented instructions in the proposal or services agreement;
- we access only the data needed to perform the contracted work;
- we do not use client data for our own purposes, do not combine it with other clients' data and do not disclose it to third parties;
- at the end of the engagement we return or delete the data as agreed, unless a legal obligation requires retention.
5. Data in Datametrics Applications (third-party platforms)
5.1 What these applications do
We build and operate, for our clients — businesses and professionals — applications that connect to platforms such as Meta (WhatsApp Business Platform, Instagram, Facebook Pages and Messenger), TikTok, LinkedIn and Google through their official APIs and that allow the client to:
- Automate conversations: receive messages that end users send to the client's business account, reply automatically (with rules or with artificial-intelligence models), hand the conversation over to a member of the client's team when appropriate and record the contact in the client's CRM.
- Schedule and publish content: create, schedule and publish posts on the client's social-media accounts and read basic performance metrics.
5.2 Who authorises access
Access to a platform account is always authorised by the client who owns it, or by an administrator with rights over it, through the platform's official authorisation flow (for example Facebook Login for Business or WhatsApp Embedded Signup). We never ask for social-media account passwords. The client can revoke access at any time from the platform's settings or by asking Datametrics (see section 10).
5.3 What data we receive from platforms
We request only the permissions strictly required for the contracted function. Depending on the application we may receive:
- identifiers of the client's page, business account or WhatsApp Business account, its name and the access tokens issued by the platform;
- inbound and outbound messages of the client's business account and their metadata: the writing user's identifier or phone number, profile name, timestamp, delivery status and attachments (images, audio, documents);
- the content of posts scheduled by the client and their basic metrics (reach, engagement);
- basic business-profile information of the client needed to operate the integration.
We do not access friend lists, private messages of personal profiles, data of other pages or accounts that were not authorised, and we do not scrape any platform.
5.3.1 TikTok (Business Messaging API)
When a client connects its TikTok Business Account to a Datametrics Application (Chato) through the TikTok Business Messaging API, we process only the following data:
- TikTok Business Account identifiers obtained through the TikTok OAuth authorisation flow;
- direct-message content and comments exchanged between the client's business account and TikTok users;
- TikTok user identifiers (open_id, conversation ids) needed to maintain conversation threads;
- message timestamps and delivery/read status;
- access and refresh tokens issued by TikTok, stored encrypted.
This data is processed exclusively to deliver and handle conversations on behalf of the business client: receiving messages and comments, generating or routing replies, and recording the contact in the client's CRM. The client operating the TikTok Business Account is the data controller; Datametrics acts as processor under the client's instructions. We do not use TikTok data for advertising targeting, profiling or training of artificial-intelligence models. Data of TikTok users is not sold, rented or shared with third parties other than the sub-processors listed in section 7 and on our Subprocessors page. Our use of TikTok data is subject to the TikTok Developer Terms of Service and the TikTok for Business Messaging policies. Retention and deletion periods are described in sections 9 and 10.
5.4 What we use that data for
- Delivering the contracted service to the client: replying to their users, routing conversations, publishing content, producing activity reports.
- Keeping the application secure, preventing abuse and fixing errors.
- Meeting legal obligations.
We do not use data obtained from platforms for our own advertising, do not sell it, do not disclose it to data brokers and do not use it to train artificial-intelligence models. The client operating the business account is the controller of its end users' data; Datametrics acts as processor and follows the client's instructions only.
5.5 Use of artificial intelligence
To draft automatic replies and summarise conversations we use language models from an external provider: Anthropic (Claude models, accessed through the Anthropic API). For voice-note transcription we use Groq and fal.ai. Message content is sent to the provider solely to generate the reply and is processed under the provider's commercial (API) terms, which exclude the use of the data to train their models. Where the platform or the law requires it, the assistant identifies itself as automated and offers the option to talk to a human. All artificial-intelligence providers are listed on our Subprocessors page.
5.6 Platform-specific statements
- Meta (Facebook, Instagram, Messenger, WhatsApp): Datametrics' use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the WhatsApp and Messenger business-messaging policies (prior user opt-in, messaging windows and no spam). Datametrics does not sell Meta Platform Data.
- Google: Datametrics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- TikTok: Datametrics' use of information received from the TikTok Business Messaging API adheres to the TikTok Developer Terms of Service and the TikTok for Business Messaging policies. We process TikTok data only for the functions authorised by the client, as described in section 5.3.1, and do not sell it.
- LinkedIn: we process data obtained from its APIs only for the functions authorised by the client and in accordance with LinkedIn's developer terms.
6. Legal bases
- Consent: analytics and advertising cookies, newsletter subscription, resource downloads.
- Performance of a contract or pre-contractual steps: answering your enquiry, scheduling a meeting, delivering contracted services and operating Datametrics Applications for the client.
- Legitimate interest: security of our systems, abuse prevention, internal measurement of our marketing.
- Legal obligation: retention of accounting and tax records, responding to lawful requests from authorities.
7. Who we share data with
We do not sell personal data. We share data only with providers that help us operate, each under contract and only for the stated purpose. The full, current list is published on our Subprocessors page. In summary:
- Hosting and infrastructure: DigitalOcean (servers in London, United Kingdom).
- Transactional email and newsletter: Brevo.
- Meeting scheduling: Calendly.
- Analytics and measurement: Google Analytics, Meta (Pixel and Conversions API), PostHog.
- Messaging and platforms: Meta, TikTok, Twilio and other messaging providers depending on the channel the client contracts.
- Artificial intelligence: Anthropic (language models), Groq and fal.ai (audio transcription).
- Internal operations tooling: a private operations console (Discord) and a self-hosted task manager (Planka) where the authorised team of the client and of Datametrics supervises automated conversations. Access is restricted to authorised staff.
- Authorities: where a law or a valid order requires it.
Operational data in our internal tools stays within Datametrics' own infrastructure environment; it is not shared with third parties, including Discord Inc., beyond the technical messaging needed to run the console.
Data Processing Agreement. Clients for whom we process end-user data as processor are covered by our Data Processing Agreement, which sets out the instructions, sub-processor obligations, security measures and deletion commitments described in this policy.
8. International transfers
Our production data — including website leads and Datametrics Applications data — is stored on DigitalOcean servers located in London, United Kingdom. Some of our processors operate in the United States (Anthropic, Twilio, Google, Meta, PostHog) and in the European Union (Brevo). Whenever data leaves your country we make sure adequate safeguards are in place: data-processing agreements with each provider, contractual data-protection clauses and, for clients subject to the GDPR, the European Commission's Standard Contractual Clauses. The location of each provider is listed on our Subprocessors page.
9. How long we keep data
- Website enquiries and leads: up to 24 months from the last contact, or until you ask us to delete them.
- Newsletter subscription: until you unsubscribe.
- Data of contracted clients: for the duration of the business relationship plus the applicable legal (accounting and tax) retention period.
- Datametrics Applications data (messages, contacts, content): while the client keeps the application connected and for at most 30 days after disconnection or end of service, unless the client sets a shorter period or requests immediate deletion. Access tokens are deleted as soon as the client revokes authorisation.
- TikTok and other messaging conversation data (messages, comments, user identifiers): retained while the client's account is active and deleted within 30 days of account termination, disconnection or client request. Access and refresh tokens are deleted immediately upon disconnection.
- Technical logs: 90 days. Backups: 30 days.
10. Data deletion
You can request deletion of your data at any time. Detailed instructions — including those specific to Facebook, Instagram and WhatsApp users and to clients disconnecting an application — are on our Data Deletion page. In short: email privacy@data-metrics.pro (or sergio@data-metrics.pro) with the subject "Data deletion"; we acknowledge with a request number within 72 hours and complete the deletion within 30 days at most.
11. Cookies
When you arrive at the site we show a notice to accept or reject non-essential cookies. You can change your choice at any time via the "Cookies" link in the footer.
| Category | Cookies / technologies | Purpose | Duration |
|---|---|---|---|
| Essential | cookie preference, light/dark theme | Remember your settings; no consent required | 12 months |
| Analytics | _ga, _ga_* (Google Analytics), PostHog | Measure visits and site usage in aggregate | up to 24 months |
| Advertising and attribution | _fbp, _fbc (Meta), click parameters | Measure campaigns and attribute enquiries to their source | up to 90 days |
12. Your rights
You have the right to access your data, rectify it, delete it, object to or restrict its processing, withdraw consent at any time and, where applicable, receive a copy in a portable format. To exercise them, email privacy@data-metrics.pro; we may ask you to verify your identity. We respond within the legally applicable period and never later than 30 days. Deletion requests follow the procedure on our Data Deletion page.
If you believe we have not handled your request properly you may complain to the authority in your country: the National Authority for Personal Data Protection (Peru), INAI (Mexico), the Superintendence of Industry and Commerce (Colombia), the Personal Data Protection Agency (Chile), the Agency for Access to Public Information (Argentina), ANPD (Brazil) or the relevant supervisory authority in the European Union.
If you are an end user of a business that uses a Datametrics Application (for example you wrote to a client company's WhatsApp or Instagram), you may address your request either to that company or to us; we will coordinate with them.
13. Security
We apply technical and organisational measures proportionate to the risk: encryption in transit (TLS), access tokens stored encrypted and with minimum scope, role-based access control, access logging, backups, environment separation and vendor review. Details on our Security page. No system is infallible: if a security breach affects client data we will notify the affected client within 72 hours of confirming the breach, and notify affected individuals and the competent authority within the periods required by law. Security incidents and vulnerabilities can be reported to security@data-metrics.pro.
14. Minors
Our services are aimed at businesses and professionals. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with data, write to us and we will delete it.
15. Changes to this policy
We may update this policy when our services or the law change. We will publish the new version on this page with its effective date and, if the change materially affects you, notify you by email or via a notice on the site.
16. Contact
Datametrics Technology S.A.C. · RUC 20611645971 · Cal. Enrique Palacios 360, Int. 608, Miraflores, Lima 15074, Peru · Privacy: privacy@data-metrics.pro · Security: security@data-metrics.pro · General: sergio@data-metrics.pro · +51 933 363 169