Skip to content

Legal

Privacy policy

This policy explains what data KINTI SYSTEMS S.A.S. processes when you use MERP or visit this site, what for, who it is shared with, and what you can require of us. It is deliberately written in plain language.

Last updated:

This document is deliberately written in plain language. If anything is unclear, write to us and we will explain it.

Who the controller is

KINTI SYSTEMS S.A.S., tax ID 0195176736001, domiciled in Ecuador, is the controller for the personal data described in this policy.

For anything concerning your data, message us on WhatsApp from the footer of this site, or from Technical support inside MERP if you are already a customer.

What data we process

There are three groups, and they are worth keeping apart because the rules differ.

Account data
Name, email address and profile picture, provided by Google when you sign in. We never receive or store your Google password.
Company data
Legal name, tax ID, legal form, tax regime, business activity, address, logo and, where applicable, the shareholder structure with ownership percentages. You provide these at sign-up or from Business settings.
Operational data
Everything you record inside MERP: clients, products, stock, invoices, purchases, bank movements and journal entries. This includes personal data of third parties — your clients, suppliers and staff — for which you are the controller and we are the processor.

What we cannot read

Vault entries are the exception, and not as a matter of policy but of construction. Each password is encrypted on your own device before it leaves it, with a key derived from a secret in your system keystore combined with your PIN. What reaches our servers is an unreadable block.

Neither Kinti nor your company administrator can open it. It is not that we choose not to: the mechanism does not exist, not even if an authority demanded it. That is why creating your vault gives you a rescue key, which is the only thing that restores access if you lose your device or clear your browser data. Keep it yourself: we hold no copy.

What we use it for

Providing the service
The primary purpose: without this data MERP cannot issue an invoice, compute a journal entry or show you your stock.
Meeting legal obligations
Issuing and retaining electronic tax documents and transmitting them to the Ecuadorian tax authority when you use electronic invoicing.
Billing you
Issuing your subscription invoice and processing payment.
Notifying you
Operational system notifications, billing notices and replies to your support tickets. We do not send third-party advertising.

Who we share it with

We do not sell personal data, nor pass it to third parties for their advertising. These are the providers involved in delivering the service, and there are no others:

Google Cloud Platform
Hosting for the application and for the files you upload.
Supabase
Authentication and database.
Google (Gmail API)
Sending the system’s transactional email.
PayPhone
Processing your subscription payment. We do not store your card: those details are entered directly into their gateway.
Ecuadorian tax authority (SRI)
Transmission of electronic tax documents when you use that module. This is a legal obligation, not our choice.

How long we keep it

For as long as your account is active. If your account is suspended for non-payment, your data is kept for 3 months before it is purged, leaving ample room to come back or to take your information with you.

Electronic tax documents are the exception: they are kept for 7 years even after you stop being a customer, because Ecuadorian regulations require it. We cannot delete them sooner even if you ask.

Your rights

Ecuador’s Organic Law on Personal Data Protection grants you rights of access, rectification, updating, erasure, objection, portability, and not to be subject to automated decisions. You can exercise them through the channels above.

Most of them do not require writing to us: inside MERP you can view and correct your data and your company’s at any time, and export your information with the Reports module.

If you believe your request has not been handled properly, you may go to Ecuador’s data protection authority.

How we protect it

Encryption in transit
Everything travels over HTTPS. In addition, request bodies travel inside an encrypted envelope (AES-256-GCM, with the key wrapped in RSA-OAEP) from web and desktop; not yet on iOS and Android.
Separation between companies
Every record carries the company it belongs to and every query is scoped to yours. The reporting engine goes further: it runs the query under a read-only database role with per-company policies, so a malformed query cannot reach another customer’s data.
Encryption at rest
Notes content is encrypted in the database. There we do hold the key, unlike the Vault, and the interface says so plainly so nobody stores a password in Notes believing it is equally protected.
Permissions
Each person in your company sees what their role allows, and you define the roles.

Cookies and measurement

This website sets no advertising or tracking cookies, and carries no third-party analytics. That is why there is no cookie banner: there is nothing to consent to.

The application at merp.kintisystems.com does use browser local storage, solely to keep you signed in and to remember preferences such as your sidebar order. It is not shared with anyone.

Minors

MERP is a business management tool and is not directed at minors. We do not knowingly collect data from minors.

Changes to this policy

If we change anything material we will announce it inside the application using the same notice system we use for everything else, and we will update the date in the header. We will not make a substantive change quietly.

Other documents

Terms and conditions