This page describes the technical and organisational measures that Datametrics Technology S.A.C. ("Datametrics") applies to protect the data it processes on the website data-metrics.pro, in its professional services and in its applications connected to messaging platforms — including Chato (chato.lat). It complements our Privacy Policy, Terms and Data Processing Agreement.
1. Overview
Datametrics is a small, specialised team. Security is owned directly by the founder, who acts as security officer and is accountable for the measures described here; there is no layer between the person responsible and the systems. Our security practices are aligned with ISO 27001 principles (risk assessment, access control, change management, incident management, supplier management), proportionate to the size of the company and the sensitivity of the data we handle. We do not currently hold a formal certification and we do not claim one.
An independent vulnerability assessment / penetration test report is available to clients and platform partners under NDA on request. Security questions and reports: security@data-metrics.pro.
2. Encryption
2.1 In transit
All endpoints — the website, application interfaces, webhooks that receive events from platforms and outbound calls to platform APIs — are served exclusively over HTTPS with TLS 1.2 or higher. HTTP Strict Transport Security (HSTS) is enabled so browsers never fall back to plain HTTP. Certificates are issued and renewed automatically (Let's Encrypt).
2.2 At rest
- Production data and backups reside on encrypted storage volumes at our hosting provider (DigitalOcean).
- Platform access and refresh tokens (Meta, TikTok, Google, LinkedIn and similar) are stored encrypted at the application layer with a separate application key that is not stored alongside the database.
- Secrets (API keys, database credentials, encryption keys) live in environment configuration on the servers, never in source code or the code repository.
3. Access control
- Role-based access with the principle of least privilege: each person and each service component can only reach the data it needs for its function.
- Servers accept SSH key authentication only; password login is disabled.
- Multi-factor authentication is mandatory on every administrative account: cloud provider, code repository, platform developer consoles (Meta, TikTok, Google), and corporate email.
- All access to client data — by staff or by automated components — is logged, with the identity, timestamp and operation recorded.
- Client end users' data is accessed by Datametrics staff only for support, debugging or supervision explicitly requested or authorised by the client.
4. Infrastructure
- Hosting: DigitalOcean, datacentre in London, United Kingdom.
- Services run as containerised workloads (Docker) with separate containers per service and per-client isolation of application instances and credentials.
- Host firewall (UFW) with only ports 22 (SSH), 80 and 443 exposed; all internal services listen on private interfaces only.
- Daily automated backups, encrypted, retained for 30 days and periodically test-restored.
- Production and development environments are separated; no production data is used in development.
5. Vulnerability management
- Automated dependency scanning on every build (npm audit / Dependabot-style alerts) for the application code and container base images.
- Security patches are applied within 7 days for critical vulnerabilities and within 30 days for all others; operating-system security updates are applied automatically.
- An annual external vulnerability assessment of the public-facing systems; the report is available to clients and platform partners under NDA.
6. Incident response
We maintain a documented incident-response plan covering detection, triage, containment, eradication, recovery and lessons learned. In the event of a suspected security incident:
- triage begins within 24 hours of detection;
- affected clients are notified within 72 hours of confirming an incident that involves their data, with the known facts, the impact and the measures taken;
- platform partners (Meta, TikTok, Google and others) are notified according to their developer terms where their platform data is involved;
- competent authorities are notified where the applicable law requires it;
- every incident closes with a written post-mortem and corrective actions.
7. Data segregation
Each client is a separate tenant. Isolation is enforced at the application layer (every request and every automated job is scoped to a single client) and at the database layer (client identifiers on all records, separate credentials and encryption keys per deployment where applicable). There is no cross-client access: no client, and no automated reply, can read or act on another client's conversations, contacts or tokens.
8. Personnel
- All staff and contractors sign a confidentiality agreement (NDA) before receiving any access.
- Everyone with access to client data completes security-awareness training (phishing, credential handling, data classification) at onboarding and annually.
- Offboarding revokes all access the same day: SSH keys, cloud, repository, platform consoles, email and internal tools.
9. Data minimisation and retention
We request only the platform permissions strictly required for the contracted function and store only the data needed to operate it. In summary (full detail in the Privacy Policy):
- platform access tokens are deleted immediately when the client disconnects or revokes authorisation;
- conversation data (messages, contacts, attachments) is kept while the application is connected and for at most 30 days after termination, unless the client requests earlier deletion;
- technical logs are kept for 90 days; backups for 30 days.
Deletion requests are handled as described on the Data Deletion page.
10. Platform compliance
Our applications use only the official APIs of each platform and comply with their developer terms: the Meta Platform Terms and Developer Policies (including the WhatsApp Business and Messenger policies), the TikTok Developer Terms of Service and the TikTok for Business Messaging policies, and the Google API Services User Data Policy including its Limited Use requirements. Platform data is never sold, used for advertising, or used to train artificial-intelligence models.
11. Responsible disclosure
If you believe you have found a vulnerability in any Datametrics system, please email security@data-metrics.pro with a description and steps to reproduce. We acknowledge every report within 72 hours, keep you informed of the fix, and will not take legal action against good-faith researchers who avoid accessing or altering other people's data and give us reasonable time to remediate.
12. Contact
Datametrics Technology S.A.C. · RUC 20611645971 · Cal. Enrique Palacios 360, Int. 608, Miraflores, Lima 15074, Peru · Security: security@data-metrics.pro · Privacy: privacy@data-metrics.pro · General: sergio@data-metrics.pro · +51 933 363 169