Bogas Solutions LLC ("Bogas", "we") builds and operates business software,
including the Bogas ERP, a business operating platform our client
organizations ("tenants") use to run their operations. Each tenant accesses the platform
under its own workspace and, in some cases, its own domain. This policy explains what
personal data we collect through this website and through the platform, how we use and
protect it, and the rights you have.
Bogas also operates business messaging integrations on behalf of its
tenants. Acting as a technology provider, we connect a tenant's own WhatsApp Business,
Instagram, and Facebook Messenger accounts to their Bogas workspace so the tenant can
receive and reply to messages from their own customers. Section 4 explains what this
involves and how that data is handled.
1. Who we are
Bogas Solutions LLC is a software consulting and products company based in Puerto Rico
(United States). Website: bogassolutions.com.
Privacy and security contact: security@bogassolutions.com.
2. Data we collect
On this website
- Contact and lead information you submit voluntarily through our forms:
name, email, phone, company, and details about your project or request.
On the Bogas ERP platform
- Account data for platform users: name, email, role within the tenant
organization.
- Business operational data the tenant organization records in its own
workspace: customers, quotes, invoices, payments, service reports, inventory, and similar
records. This data belongs to the tenant.
- Financial account data connected through Plaid (see section 3).
- Business messaging data from a tenant's connected WhatsApp, Instagram,
and Facebook Messenger accounts (see section 4).
3. Financial data connected through Plaid
For accounting and bank-reconciliation features, the platform lets a tenant's authorized
administrators connect the organization's bank accounts using Plaid Inc.,
a specialized provider of secure financial connections:
- Connections are initiated voluntarily, with your consent, through
Plaid's secure widget (Plaid Link). We never see or store your bank login
credentials; authentication happens directly between you, your bank, and
Plaid.
- Through Plaid we receive read-only account and transaction data
(balances and movements), used exclusively for bank reconciliation and financial
reporting inside the owning tenant's workspace.
- This data is never sold, rented, licensed, or shared with third
parties. It is encrypted at rest; Plaid access tokens are stored in an encrypted vault
with per-organization ownership controls.
- A connected bank account can be disconnected at any time from the platform; doing so
revokes access at Plaid and deletes the stored credential. Deletion of already-imported
data can be requested at the contact address below.
- Plaid's own handling of your data is governed by the
Plaid End User
Privacy Policy.
4. Messaging via Meta platforms (WhatsApp, Instagram, Messenger)
For customer-communication and CRM features, the platform lets a tenant's authorized
administrators connect the organization's own WhatsApp Business,
Instagram, and Facebook Messenger accounts. In this
arrangement Bogas Solutions LLC acts as a technology provider for the
tenant, and the tenant is the business the end customer is choosing to message.
- Connections are made voluntarily, with the tenant's consent, through
Meta's official authorization flow. We never receive or store any Meta account
passwords; access is granted through Meta-issued tokens.
- When an end customer messages the tenant's connected account, we receive the
message content and metadata needed to deliver it into the tenant's
inbox: the message text and any attachments, the sender's platform-scoped ID and public
profile name, the phone number (for WhatsApp), and timestamps.
- This data is used only to route conversations into the owning tenant's
workspace, let the tenant reply, and keep the customer's conversation history so the
tenant can serve them. It is processed on behalf of that tenant and is
never sold, rented, licensed, or used for advertising.
- Any automated or assisted replies are sent on the tenant's behalf, from the tenant's
own connected account, and only in response to a customer who has messaged that account.
- An end customer can stop the conversation at any time through the messaging app itself
(for example, by blocking the account or replying "stop"). A tenant can disconnect a
Meta account at any time from the platform, which revokes our access at Meta.
- Meta's own handling of your data is governed by the
WhatsApp and
Meta privacy
policies. Deletion of messaging data we hold can be requested as described in
our data deletion instructions.
5. How we use data
- To provide, operate, and support the contracted service.
- To respond to inquiries and follow up on requests you send us.
- To secure the platform (authentication, audit logging, abuse prevention).
- We do not sell personal data, and we do not use tenant business,
financial, or messaging data for advertising or any purpose other than operating the
service.
6. Service providers
We rely on a small set of infrastructure and service providers that process data on our
behalf under their own security commitments, including Google Cloud (hosting, in the
United States), Supabase (managed database), Plaid (bank connections), and payment/
accounting integrations a tenant chooses to enable (e.g., Stripe, QuickBooks), and Meta
Platforms for the messaging integrations described in section 4. Providers
may only use the data to render their service to us. We may also disclose information
where required by law.
7. Security
All traffic is encrypted in transit (HTTPS/TLS with HSTS). Data is encrypted at rest.
Access is role-based with least privilege, enforced server-side on every request, with
tenant isolation at the database layer (row-level security). Third-party credentials live
in an encrypted vault, never in code or logs. Our security program is documented in the
Bogas Solutions Information Security Policy (available to customers and partners on
request).
8. Data retention & deletion
We retain data while the tenant relationship is active. On verified request or contract
termination, tenant data (including Plaid-sourced and Meta messaging data) is deleted from
production systems within 30 days. Disconnecting an integration deletes its stored
credentials immediately. For step-by-step deletion of messaging data, see our
data deletion instructions.
9. Your rights
You may request access, correction, or deletion of your personal data, and you may ask us
to stop contacting you at any time, by writing to the contact address below.
10. Children
Our website and products are directed to businesses and adults. We do not knowingly
collect data from minors.
11. Changes
We may update this policy from time to time. The current version is always published on
this page with its revision date.