Privacy policy
Introduction
At Jipsoft we protect the privacy of visitors to jipsoft.com and users of our cloud services (FactuSync, FerroSync, MediSync, and related products). This document explains what data we process, for what purpose, and how you can exercise your rights under applicable law in Ecuador, including the Organic Law on Personal Data Protection (LOPDP) and its Regulation.
By using the site or purchasing our services, you acknowledge that you have read this policy. If you do not agree, please do not continue using the platform.
Data controller
The data controller is Jipsoft, operating through https://jipsoft.com and applications associated with the marketed products. To exercise your rights or ask privacy questions, you may write to [email protected], without prejudice to the other channels indicated at the end of this document.
Data we may collect
Depending on your relationship with us, we may process categories such as:
- Identity and contact: name, business name, tax ID (RUC) or identification, email, phone, role.
- Technical and usage: IP address, device or browser identifiers, access logs, metrics from the dashboard or API.
- Contract performance: access credentials (hashed), settings, documents and metadata you upload or generate for electronic invoicing or business management.
- Communications: content of messages or support tickets you send us.
- User-uploaded content: documents, files, images, and records you or your users enter into the products. Jipsoft stores and processes them on your behalf but does not control or verify their accuracy or lawfulness.
We do not request sensitive data unless required by law or contract; when we process it, we apply the reinforced measures described in the section on health data and special categories.
Health data and special categories
MediSync is a clinical management and remote monitoring product that, by its nature, processes health data. The LOPDP classifies health-related data as sensitive data (a special category) subject to a reinforced protection regime.
This data is processed solely on behalf of the healthcare facility or professional that contracts MediSync —the party responsible for the clinical relationship— and on the basis of the data subject's consent or the legal authorizations applicable to the healthcare field. Jipsoft applies role-based access control, encryption, per-tenant isolation, and audit logs, and does not use this data for purposes other than providing the service.
Purposes and legal basis
We process data to provide and improve services, authenticate users, bill, comply with legal and regulatory obligations (including those related to the SRI and electronic invoicing in Ecuador), prevent fraud, produce aggregate statistics, and respond to data subjects or authorities when appropriate.
Depending on the case, the legal basis for processing may be:
- Performance of the contract or of pre-contractual measures you request.
- Compliance with legal obligations (for example, tax and electronic invoicing obligations).
- Your consent, when we collect it freely and on an informed basis (for example, first-visit analytics or health data).
- Jipsoft's legitimate interest in security, fraud prevention, and service improvement, balanced against your rights.
Data retention
We retain information for as long as necessary for the stated purposes and applicable legal periods. For guidance:
- Electronic vouchers and accounting or tax data: the legal period applicable in Ecuador, up to seven (7) years.
- Consent preference cookie (jipsoft_cmp_v1): up to approximately thirteen (13) months.
- Analytics attribution cookie (jipsoft_attr_v1): up to approximately six (6) months, and only if you accept the analytics category.
- MediSync clinical data: for the duration of the service and the periods required by applicable healthcare regulations.
After cancellation or termination of the service we keep your data for a grace period of up to sixty (60) days so that you can export it; once that period elapses it is deleted or anonymized, except for information we must retain by legal obligation.
Responsibility for uploaded content and data
You are solely responsible for the accuracy, correctness, lawfulness, and legitimacy of the data, documents, and files you upload or generate in the products, as well as for holding the necessary authorizations from your own customers, patients, or third parties. Jipsoft processes that content on your behalf and does not review, validate, or audit it in advance.
Jipsoft is responsible for the security and confidentiality of the processing it performs, but not for the content you enter —including false, inaccurate, or unlawful data and potentially malicious files— nor for the use or management you make of that data outside the platform. You shall hold Jipsoft harmless against third-party claims arising from such content or use.
Processors, sub-processors, and third parties
To provide the service we rely on providers that act as processors or sub-processors, under agreements requiring confidentiality and security measures. Provider categories include:
- Cloud infrastructure and storage (for example, object storage and databases).
- Government services required for electronic invoicing (SRI).
- Notifications and messaging (for example, push notifications, email, and WhatsApp).
- Our own analytics and machine-learning processing for predictions and recommendations.
We do not sell your personal data or share it with third parties for advertising purposes.
Security and international transfers
We apply reasonable technical and organizational measures against unauthorized access, loss, or alteration. Infrastructure may be hosted with cloud providers inside or outside Ecuador; in those cases we use processing agreements or clauses as required by applicable law.
We may disclose data to competent authorities when required by law or a lawful order.
Security incident notification
If a security breach affecting your personal data occurs, we will take containment and assessment measures and notify the Personal Data Protection Authority and, where the risk warrants, the affected data subjects, within the time limits set by the LOPDP (generally without undue delay and no later than seventy-two (72) hours after we become aware).
Minors
The site and services are aimed at companies and professionals; they are not intended for minors, and we do not knowingly collect their data through the site. When a product processes minors' data on the customer's behalf (for example, patients in MediSync), it is the customer's responsibility to obtain the legal guardian's consent as required by law.
Your rights and how to request erasure
You may exercise the rights of access, rectification, updating, erasure (deletion), objection, portability, and the others recognized by the LOPDP by writing to [email protected]. We will respond within applicable legal time limits and may ask you to verify your identity.
You may request deletion of browsing-related data (cookies and attribution) by deleting jipsoft.com cookies in your browser or by requesting it through that channel. When you cancel the service you may request erasure of your data, which we will carry out after the stated grace period, except for information we must retain by legal obligation.
Changes to this policy
We may update this policy; the new version will be published on jipsoft.com with its effective date. Please review it periodically.
