Experience OS

Privacy and control of your data

Privacy Notice

This privacy notice explains what data Softentgroup processes, why it is used, which providers may process it, how long it is retained and how you can exercise your rights.

Last updated: July 13, 2026

01 · Identity

Responsible party, public domicile and contact

Yoscihey Espinosa Roa, an individual conducting business under the Softentgroup commercial name, is responsible for the personal-data processing described in this privacy notice. Softentgroup is the commercial name used for these technology services and is not presented as a separate legal entity.

The responsible party's public domicile is Pachuca de Soto, Hidalgo, Mexico. For privacy matters, ARCO rights or security-incident reports, email privacidad@softentgroup.com.

02 · Information

Personal and technical data we may process

Diagnosis request

Required data consists of name, email address and a description of the challenge, need or workflow to be reviewed. Optional context may include company or organization, role, phone or WhatsApp, website, industry, department, project type, desired timeline and approximate budget range.

Technical and attribution data

To route requests, maintain security and measure their source, we may process landing page, navigation referrer, UTM parameters, language, form name, a site-generated session identifier, IP address, user agent, date, time, delivery status and operational security indicators.

Chatbot, email and WhatsApp

When you use the assistant, we may process your messages, generated responses, date and time, language, page, follow-up action, contact intent and, when you provide them to request human assistance, email or phone details. A conversation is not recorded merely because the assistant opens or displays its greeting; a normalized version may be submitted after a substantive message or contact request.

We also process information you choose to send by email or WhatsApp. These channels may involve providers selected by you and, for WhatsApp, its own privacy terms.

Information you should not submit

We do not intentionally request sensitive personal data, passwords, credentials, confidential third-party information or trade secrets. Do not include them, or unnecessary information about other people, in free-text fields, messages, email or WhatsApp. If you submit such information voluntarily, it may be processed through the same channels needed to handle your request.

03 · Use

Processing purposes

We process information only to:

  • receive, review and answer requests;
  • perform an initial diagnosis and provide requested or reasonably related follow-up;
  • manage requests, conversations and operational continuity in the CRM;
  • generate applied-AI chatbot responses;
  • operate the website, form, email, chatbot and contact channels;
  • prevent abuse, enforce limits, protect the service and investigate failures;
  • measure basic attribution and request source; and
  • meet applicable contractual, tax or legal obligations and handle privacy rights and security incidents.

Marketing use is disabled. We do not use this data for promotional campaigns, newsletters, advertising, profiling, cross-selling or unsolicited prospecting.

04 · Operation

Processors, corporate engagement and international processing

Inmobrok CRM and EBM INMOBROK

EBM INMOBROK, S.A. de C.V. operates Inmobrok CRM as a data processor for general Softentgroup diagnosis requests, leads, chatbot conversations and follow-up. It processes that data only under the responsible party's documented instructions and may not use it independently for Inmobrok marketing, real-estate sales or unrelated purposes.

Optional corporate engagement

When a prospect expressly chooses or requires a project to be contracted and invoiced through EBM INMOBROK, S.A. de C.V., the relevant information may be communicated to that company. From that point, and only for that relationship, EBM INMOBROK acts as an independent controller for precontractual, contractual, billing, accounting, tax, legal and service-delivery purposes. This does not happen automatically for every lead; the applicable contractual and privacy information will be provided.

Hostinger

Provides hosting and email infrastructure. The primary region is reported as Mexico, but infrastructure and subprocessors may process information in other jurisdictions; we do not claim exclusive Mexican data residency.

Groq

Processes conversation content to generate chatbot responses. It does not receive diagnosis-form submissions. Contact details can reach it only when a person voluntarily writes them inside a message. We do not claim zero retention.

Email and WhatsApp

Email delivery uses Hostinger infrastructure and the email providers involved. WhatsApp is an external channel that processes information shared through it under its own terms.

Processors, external providers, their subprocessors and communication channels may involve processing outside Mexico. We limit transmitted data to what is needed for the relevant purpose and subject access to applicable instructions and controls. General Inmobrok CRM records are processed under the responsible party's instructions; records for an expressly selected corporate engagement remain distinguishable under EBM INMOBROK's independent role.

05 · Technology

Local storage, identifiers and logs

The site may use localStorage, without advertising cookies, to retain for up to 90 days five UTM parameters, the first available navigation referrer and a site-generated session identifier. These records expire or rotate after that period and can also be removed through browser controls.

Technical and security logs may include IP address, date and time, status, technical identifiers, user agent and synchronization results. Request-limiting controls may use derived identifiers. These records support security, abuse prevention and troubleshooting.

06 · Lifecycle

Retention periods

InformationMaximum period or rule
Browser attribution and site-generated session ID90 days
Chat without contact or a valid opportunity90 days
Qualified chat or lead24 months after the last meaningful interaction
Diagnosis request and CRM lead24 months after the last meaningful interaction
Prospect email copies24 months
Technical and security logs90 days
Stale request-limit files30 days
Deployment backups30 days
Active-client contractual dataRelationship duration plus applicable contractual, legal and tax periods

We may delete information sooner when it is no longer needed. At the end of the applicable period, it is deleted or suppressed; when an obligation or claim requires retention, it is blocked and its use restricted for the relevant period before deletion.

07 · Your choices

ARCO rights, limitation and withdrawal

You may request access, rectification, cancellation, blocking or deletion of your data, and you may object to processing. You may also ask us to limit its use or disclosure and withdraw consent when consent is the applicable basis, without retroactive effect and subject to obligations requiring retention.

Email your request to privacidad@softentgroup.com and include:

  • your name and a channel for our response;
  • the right or action you want to exercise;
  • enough detail about the data or interaction; and
  • the minimum information needed to locate the record.

We will verify identity in proportion to risk and avoid requesting or retaining additional documents when another reasonable method is sufficient. If a representative acts for you, their authority will also be verified proportionally.

Our target is to communicate a determination within 20 business days after receiving a complete and verifiable request and, where applicable, carry out the action within the following 15 business days. These periods may be extended once where justified and applicable; if so, we will explain the reason.

08 · Protection

Security, incidents and people under 18

We apply proportionate administrative, technical and operational measures, including access controls, data validation and limits, private-directory protection, method restrictions, request limits and log minimization. No system provides absolute security.

If we identify a significant incident that may materially affect people's rights, we will assess its scope, containment and corrective measures. Where applicable, we will notify affected people through an available channel with information about the nature of the incident, possible consequences and recommended action. Reports are received at privacidad@softentgroup.com.

The site is intended for business users and people 18 years of age or older. We do not intentionally offer these services to minors or seek to collect their data. If we identify a minor's information, we will assess blocking or deletion.

09 · Effective date

Changes, effective date and contact

This privacy notice is effective and was last updated on July 13, 2026. Changes will be published on this page with the applicable date. When a change is material and an appropriate channel is available, we may also communicate it through the site or available contact information.

For questions about this privacy notice, an ARCO request, limitation, withdrawal or a security report, email privacidad@softentgroup.com.