Privacy Policy
Last updated: September 2026
This Privacy Policy describes how Percus SpA ("Percus", "we", "us") collects, uses, and protects information when you use the Percus platform, including the Backoffice application.
1. Information we collect
Through single sign-on (Microsoft Entra ID or Google)
When you sign in to the Percus Backoffice with your Microsoft Entra ID or Google account, we receive the following information from your identity provider:
| Data | Purpose |
|---|---|
| Email address | Used as your unique identifier within the platform |
| Full name | Displayed in the user interface |
| Identity provider account ID | Used to link your identity provider account to your Percus account |
| Profile picture | Displayed in the user interface (optional) |
We do not receive your password or access to any service beyond your basic profile.
Account and usage data
| Data | Purpose |
|---|---|
| Role assignments | Determine what actions you are authorized to perform |
| Session activity | Security monitoring and session management |
End-customer personalization data
Percus offers two personalization models, and they differ in whether this data reaches Percus at all:
- Client-side personalization — the data is processed entirely in the viewer's browser and is never transmitted to Percus servers.
- Percus-hosted render data — the client uploads personalization data in advance and Percus stores it, keyed by a token the client chooses and which is opaque to Percus. It is deleted when the associated project is archived.
Under the standard integration, personalization data is delivered by API at viewing time and is not stored by Percus. Where a client opts for hosted render data, Percus stores it as a processor acting on the client's instructions. See Data Handling for the technical detail of each model, and the Data Protection Addendum for Percus's obligations as processor.
Viewing analytics
When an end customer watches a video, Percus records playback and interaction events with a pseudonymized identifier computed in the browser, a session ID, device and browser type, and country. Percus does not record the viewer's name, the client's identifier for that viewer, or their IP address. See Identity Model.
What we do not collect
- Payment information.
- Data from your Google Drive, Gmail, Calendar, or any other Google service.
2. How we use your information
We use the information collected solely to:
- Authenticate your identity and manage your session
- Enforce role-based access control within your organization
- Display your name and profile in the Backoffice interface
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Data storage and security
Your account data is stored in Amazon Aurora Serverless v2 (PostgreSQL), in the AWS us-east-1 region (United States), within an AWS VPC not accessible from the public internet. All data in transit is protected by TLS 1.2 or higher.
Access to stored data is restricted to authorized Percus personnel and the application services that require it to function.
4. Data retention
Your account data is retained for as long as your account is active within the platform. If you are removed from all organizations, your account record may be retained for audit purposes for a period defined by applicable law or organizational policy.
5. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account data (subject to audit retention requirements)
To exercise any of these rights, contact security-compliance@percus.cl.
6. Third-party services
Percus uses the following third-party services that may process data on our behalf:
| Service | Purpose |
|---|---|
| Microsoft Entra ID | Authentication (when your organization signs in with Microsoft) |
| Google OAuth 2.0 | Authentication (when your organization signs in with Google) |
| Amazon Web Services (AWS) | Infrastructure and data storage |
Each service operates under its own privacy policy. Percus maintains data processing agreements with its infrastructure providers as required.
7. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the platform. The "Last updated" date at the top of this page reflects the most recent revision.
8. Contact
For privacy-related questions or requests:
Email: security-compliance@percus.cl
Company: Percus SpA, Santiago, Chile