Skip to content

Legal

Privacy and cookie policy

Perú Software Consulting Group S.A.C. processes personal data in accordance with Peruvian Law No. 29733 on Personal Data Protection and its Regulations, approved by Supreme Decree No. 003-2013-JUS. This document sets out what data is collected, for what purpose and for how long it is retained.

Data controller

The data controller is Perú Software Consulting Group S.A.C., domiciled in the Republic of Peru. For any matter relating to this policy, the data subject may write to contacto@perusoftware.pe.

Platform user data

Creating an account requires the processing of the following data, limited to what is necessary to provide and invoice the service:

  • Name and email address.
  • The password, stored as a cryptographic digest. It is not kept in plain text, and the company therefore cannot read or recover it.
  • The API keys generated by the user, likewise stored as SHA-256 digests, together with a masked preview allowing them to be identified in the dashboard. A lost key cannot be recovered and must be revoked and reissued.
  • The creation date and the last use date of each key, so that the user may identify any that should no longer remain active.
  • A normalised form of the email address, used solely to determine whether an account already exists. It is not used for communications and is not displayed on the platform.

Access through a Google account

The user may register through a Google account instead of setting a password. In that case, Google discloses only three items to the company: name, email address and an internal account identifier.

That identifier is retained because it is a stable value that does not change even if the user alters their email address, and it allows the account to be recognised on subsequent sign-ins. The company does not request access to the user's mail, files, contacts or calendar, and does not retain the credentials issued by Google during authentication.

Accounts created by this route have no associated password in the company's systems. Use of this sign-in method does not provide Google with any information about the lookups performed on the platform.

Billing and payment data

Purchasing a paid plan requires the processing of the data needed to issue the receipt and verify payment: identity document type and number or taxpayer registration number, legal name, address and billing email address, together with the amount, the tax applied and the date of the transaction.

As payment confirmation is carried out manually, the declared payment method, the transaction number and any receipt attached by the user are also retained. That receipt is accessible only to the staff responsible for reviewing the order and is kept as supporting evidence of the transaction.

This data is retained for the period required by applicable tax regulations, including after the account has been closed, as this constitutes a legal obligation of the company.

Data arising from lookups

Each API request is logged with the value looked up, the key used, the service invoked, the response code and the result obtained.

That log serves three purposes: accounting for consumption under the contracted plan, handling incidents, and detecting misuse of a key. The user has access to this history in the dashboard.

As regards records generated in HTML format, the resulting document is not retained, only the record that it was requested.

Source of the information provided

The platform does not generate information: it queries public registries of the Peruvian State, among them those of the national tax and customs authority, the Ministry of Transport and Communications and the mining formalisation registry of the Ministry of Energy and Mines, and delivers it in a structured format.

Those registries are publicly accessible by law. The company does not alter their content; consequently, if a value is incorrect at source it will likewise be incorrect in the response delivered. Rectification must be requested from the publishing authority.

Cached responses

Certain lookups are retained temporarily so that the request to the source is not repeated on every call:

  • Ministry of Transport and Communications certificate and REINFO lookup: up to thirty (30) days.
  • All other lookups are performed in real time and are not cached.
  • Records in HTML format are not retained under any circumstances.

Disclosure to third parties

The company does not sell or transfer personal data to third parties for commercial purposes. Disclosure occurs only where required by a competent authority or imposed by a legal obligation.

Providers involved in delivering the service, in particular hosting and infrastructure providers, act as data processors, on the company's behalf and in accordance with its instructions.

Where the user opts to sign in with a Google account, that authentication takes place on Google's servers and is governed by that provider's privacy policy. The company receives data from Google; it does not send user data to Google.

Rights of the data subject

The data subject may exercise the rights of access, rectification, cancellation and objection granted by Law No. 29733 by writing to contacto@perusoftware.pe. The company will respond to the request within the periods established by the regulations.

If the data subject considers that the request has not been handled in accordance with the law, they may refer the matter to the National Authority for Personal Data Protection of the Ministry of Justice and Human Rights.

Cookies

This site uses no tracking or advertising cookies and incorporates no third-party analytics. The only preference stored in the user's browser is the light or dark display mode, held in local storage: it is not transmitted to any server and may be cleared from the browser itself.

The customer dashboard requires a session cookie to keep the user signed in. It is strictly necessary for its operation and is removed when the session is closed.