Legal
Privacy policy
This policy explains what data KINTI SYSTEMS S.A.S. processes when you use MERP or visit this site, what for, who it is shared with, and what you can require of us. It is deliberately written in plain language.
Last updated:
This document is deliberately written in plain language. If anything is unclear, write to us and we will explain it.
Who the controller is
KINTI SYSTEMS S.A.S., tax ID 0195176736001, domiciled in Ecuador, is the controller for the personal data described in this policy.
For anything concerning your data, message us on WhatsApp from the footer of this site, or from Technical support inside MERP if you are already a customer.
What data we process
There are three groups, and they are worth keeping apart because the rules differ.
- Account data
- Name, email address and profile picture, provided by Google when you sign in. We never receive or store your Google password.
- Company data
- Legal name, tax ID, legal form, tax regime, business activity, address, logo and, where applicable, the shareholder structure with ownership percentages. You provide these at sign-up or from Business settings.
- Operational data
- Everything you record inside MERP: clients, products, stock, invoices, purchases, bank movements and journal entries. This includes personal data of third parties — your clients, suppliers and staff — for which you are the controller and we are the processor.
What we cannot read
Vault entries are the exception, and not as a matter of policy but of construction. Each password is encrypted on your own device before it leaves it, with a key derived from a secret in your system keystore combined with your PIN. What reaches our servers is an unreadable block.
Neither Kinti nor your company administrator can open it. It is not that we choose not to: the mechanism does not exist, not even if an authority demanded it. That is why creating your vault gives you a rescue key, which is the only thing that restores access if you lose your device or clear your browser data. Keep it yourself: we hold no copy.
What we use it for
- Providing the service
- The primary purpose: without this data MERP cannot issue an invoice, compute a journal entry or show you your stock.
- Meeting legal obligations
- Issuing and retaining electronic tax documents and transmitting them to the Ecuadorian tax authority when you use electronic invoicing.
- Billing you
- Issuing your subscription invoice and processing payment.
- Notifying you
- Operational system notifications, billing notices and replies to your support tickets. We do not send third-party advertising.
Who we share it with
We do not sell personal data, nor pass it to third parties for their advertising. These are the providers involved in delivering the service, and there are no others:
- Google Cloud Platform
- Hosting for the application and for the files you upload.
- Supabase
- Authentication and database.
- Google (Gmail API)
- Sending the system’s transactional email.
- PayPhone
- Processing your subscription payment. We do not store your card: those details are entered directly into their gateway.
- Ecuadorian tax authority (SRI)
- Transmission of electronic tax documents when you use that module. This is a legal obligation, not our choice.
How long we keep it
For as long as your account is active. If your account is suspended for non-payment, your data is kept for 3 months before it is purged, leaving ample room to come back or to take your information with you.
Electronic tax documents are the exception: they are kept for 7 years even after you stop being a customer, because Ecuadorian regulations require it. We cannot delete them sooner even if you ask.
Your rights
Ecuador’s Organic Law on Personal Data Protection grants you rights of access, rectification, updating, erasure, objection, portability, and not to be subject to automated decisions. You can exercise them through the channels above.
Most of them do not require writing to us: inside MERP you can view and correct your data and your company’s at any time, and export your information with the Reports module.
If you believe your request has not been handled properly, you may go to Ecuador’s data protection authority.
How we protect it
- Encryption in transit
- Everything travels over HTTPS. In addition, request bodies travel inside an encrypted envelope (AES-256-GCM, with the key wrapped in RSA-OAEP) from web and desktop; not yet on iOS and Android.
- Separation between companies
- Every record carries the company it belongs to and every query is scoped to yours. The reporting engine goes further: it runs the query under a read-only database role with per-company policies, so a malformed query cannot reach another customer’s data.
- Encryption at rest
- Notes content is encrypted in the database. There we do hold the key, unlike the Vault, and the interface says so plainly so nobody stores a password in Notes believing it is equally protected.
- Permissions
- Each person in your company sees what their role allows, and you define the roles.
Minors
MERP is a business management tool and is not directed at minors. We do not knowingly collect data from minors.
Changes to this policy
If we change anything material we will announce it inside the application using the same notice system we use for everything else, and we will update the date in the header. We will not make a substantive change quietly.