Privacy policy
Last updated: October 9, 2026
1. Who is responsible
[LEGAL NAME] (“Kosawi”), located at [ADDRESS], operates the Kosawi platform: the kosawiapp.com website, the admin.kosawiapp.com web console and the Kosawi mobile app for iPhone and Android.
For any privacy matter, email us at app@kosawi.com or call+52 662 367 2149, Monday to Saturday, 9:00 a.m. to 5:00 p.m.
This policy is issued under Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties, published in the Official Gazette (DOF) on March 20, 2025.
2. Kosawi’s two roles
Kosawi is business management software, so it handles personal data in two different roles:
- As controller of the data we need to provide the service to our customers: user accounts, each business’s subscription and billing records, and messages sent to us through the website. This policy describes that processing.
- As processor of the data each business that subscribes to Kosawi enters on the platform: its customers, employees, students, suppliers, appointments, sales, invoices and files. That business is the controller of that data. Kosawi only provides the infrastructure to store and process it, on the business’s behalf and under its instructions.
3. If a business entered your data in Kosawi
If you are a customer, employee, student or supplier of a business that uses Kosawi, that business, not Kosawi, is responsible for your data. It decides what data it collects, what it uses it for, how long it keeps it and who it shares it with, and it must give you its own privacy notice. To access, correct or delete your data, object to its use or withdraw your consent, contact that business directly.
For that data, Kosawi commits to:
- Process it only to provide the service to the business and according to its instructions.
- Never use it for our own purposes: we don’t sell it, use it for advertising or combine it with other businesses’ data.
- Keep it confidential, including after our relationship with the business ends.
- Apply the safeguards described under Security.
- Not disclose it to third parties, except to the providers listed under Service providers or when required by a competent authority.
- When the service ends, give the business a copy of its data if requested and then delete it, except for what the law requires us to keep.
If we receive a request about that data, we forward it to the right business and help it respond. If a business enters sensitive data (for example, about its employees’ health), it is responsible for getting your express written consent.
4. Data we control
- User account: name, email, password (stored only as a hash, never in readable form), optional profile photo, role, assigned branches and, if you turn it on, two-step verification.
- Sign in with Google, if you use it: only your email and whether Google has verified it. We don’t create accounts from it; your business adds you first.
- Business subscription: business name, branches, contact details of the person who manages it and the record of its subscription payments. We don’t store card data.
- Website contact form: name, company, email, modules of interest and message, plus the IP address and browser it was sent from, to filter abuse.
- Technical data: platform access logs (date, path, IP address, business and user) and, in the app, crash reports with no data that identifies you.
As controller, we don’t process sensitive personal data.
5. How we use it
We use that data for purposes needed to provide the service:
- Create and manage your account, verify your identity when you sign in and protect access.
- Provide the service, give support and tell you about changes to the service or your account.
- Manage each business’s subscription and billing.
- Reply to people who write to us through the website and follow up on demo requests.
- Detect errors, prevent fraud and abuse, and keep the platform secure.
- Meet legal obligations and respond to requests from authorities.
We currently don’t use your data for secondary purposes such as advertising or marketing. If we ever do, we’ll tell you first and you can opt out by emailing app@kosawi.com, without affecting the service.
6. Service providers and transfers
We use the following providers to operate. They process data only on our behalf or the business’s, for the purpose listed, and we require them to protect it as this policy does. Some are outside Mexico.
| Provider | Purpose | Location |
|---|---|---|
| Hostinger | Servers that hold the database and files; email; domain | [DATA CENTER COUNTRY] |
| Backblaze | Encrypted off-site backup copy | [REGION] |
| Facturapi | Stamping CFDI invoices with Mexico’s tax authority (SAT), when the business invoices | Mexico |
| Conekta | Online payments, when the business connects its own account | Mexico |
| Meta (WhatsApp) | Payment reminders over WhatsApp, when the business turns them on | United States |
| Sign in with Google | United States | |
| Mapbox | Maps in the web console (fleets module) | United States |
| Sentry | Mobile app crash reports, with no data that identifies you | [REGION] |
We don’t sell or rent personal data and we make no transfers to third parties that require your consent. We would only disclose data to an authority that lawfully requires it. Sending invoices to the SAT is a tax obligation of the business that issues them.
7. Cookies and local storage
- kosawiapp.com website: no cookies, analytics or trackers. It only stores your theme (light or dark) in your browser if you choose one.
- Web console: uses an essential session cookie to keep you signed in, protected so no script can read it and valid for 24 hours, plus preference cookies (theme, language, layout). No advertising or third-party tracking cookies. If you block cookies you won’t be able to sign in.
- Mobile app: keeps your session encrypted in the phone’s secure storage (Keychain on iPhone, encrypted storage on Android). No analytics, advertising or cross-app tracking.
8. Security
- All communication is encrypted (HTTPS).
- Passwords are stored with a one-way hash, and sensitive keys and credentials are encrypted in the database.
- We offer two-step verification with an authenticator app.
- Each business sees only its own data, and within a business each user sees only what their role and branches allow.
- We keep audit logs of financial movements and invoices.
- We back up daily to three locations; the off-site copy is encrypted.
- Server access is limited to authorized staff.
No system is perfect. If a breach significantly affects your rights, we’ll tell you without delay.
9. Retention
- Account data: while the account is active. Deleting it removes it from the live database.
- Data entered by a business: while the business has the service. When it ends, the business can ask for a copy; we then delete it within [90] days.
- Contact form messages: up to [12] months.
- Technical access logs: up to [90] days.
- Backups: they rotate automatically and the oldest are deleted after 12 months at most.
- Anything the law requires us to keep longer, such as tax records, is kept for the legal period and only for that purpose.
10. Deleting your account
In Kosawi, user accounts are created by the business you work for, not by the app. To delete your account, ask your business’s administrator: they can remove it from the console, which permanently deletes it along with its roles and sessions.
You can also ask us directly, without installing the app, by emailing app@kosawi.comwith the subject “Delete my account” from the account’s email address. We’ll confirm your identity, let the business know and delete it within 20 business days at most.
Deleting the account removes your name, email, password, photo and sign-in settings. Records you created within the business (sales, transactions, invoices) belong to the business and are kept under its own policy and tax obligations. Backup copies are deleted automatically within 12 months at most.
11. Your rights
For the data we control, you can access, correct or delete it, object to its use, withdraw your consent or limit its use. Email us at app@kosawi.com with:
- Your name and an email address for our reply.
- A document that proves your identity or, if you act for someone else, your representative’s.
- Which right you want to exercise and over which data.
- Anything that helps us find it, such as the business your account belongs to.
We reply within 20 days at most, free of charge. If you disagree with our answer, you can go to Mexico’s Ministry of Anti-Corruption and Good Governance (Secretaría Anticorrupción y Buen Gobierno), the data protection authority.
12. Minors
Kosawi isn’t meant for minors and its accounts are for adults. When a school or other business enters data about minors, such as students, that business is the controller and must get consent from parents or guardians.
13. Changes to this policy
We’ll post any change on this page with its update date. If a change is significant, we’ll also notify each business’s administrators by email or within the platform.
Versión en español: Aviso de privacidad.