Privacy Policy
Last updated: April 18, 2026
1. General Information
Systema ("we", "our", or "the platform") is a SaaS business management platform operated by Skala Marketing. Systema is a Meta-verified technology provider and uses the WhatsApp Business API, Instagram API, and Facebook Messenger API to offer automated messaging services to businesses. This privacy policy describes how we collect, use, store, and protect the personal information of our users, including business owners (Business Admin), staff (Staff), and business customers (Clients).
By using Systema, you accept the practices described in this policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Information provided directly
- Full name and email of the business administrator
- Business name and country of operation
- Business member data: name, email, phone, date of birth
- Profile photos (if provided)
- Membership data and contracted plans
- Attendance records (check-in/check-out)
- Nutritional information and exercise routines (AI functionality)
2.2 Information received from Meta Platform
When a business connects its WhatsApp number, Facebook page, or Instagram account through Systema, we may receive:
- WhatsApp Business phone number and profile name
- Phone numbers of customers sending or receiving messages
- Content of messages sent and received (text, images, documents)
- Message delivery status (sent, delivered, read)
- Access tokens for the WhatsApp Business account, Facebook page, and Instagram
- WhatsApp Business Account Identifiers (WABA ID, Phone Number ID)
- Facebook Ad Account ID and Business Manager
- Facebook Marketing API long-lived access tokens (60-day validity, renewable)
- Campaign, ad set, ad, and creative data managed through the platform
- Campaign metrics and insights (impressions, clicks, spend, CTR, CPC, conversions)
This data is stored securely and in isolation per tenant, and is only used to provide the services contracted by the business (messaging and ad management).
2.2A Information received from Google APIs
When a business connects its Google account to Systema (Google Calendar, Google Business Profile), we may receive:
- Unique Google account ID and primary email address of the business owner
- Calendar availability (occupied slots, no details or attendees)
- Events created, modified, or viewed by Systema in the owner's Google Calendar
- Google OAuth 2.0 access tokens and refresh tokens
- List of Google Business Profile listings managed by the account
- Reviews received on connected listings and replies published through Systema
- Basic information on the listing (name, hours, description, category) when the business updates it from Systema
The full details of the use, storage, and compliance with Google API Services User Data Policy (Limited Use) is described in the section 5A.
2.3 Automatically collected information
- IP address and browser data
- Platform usage data (pages visited, features used)
- Device information for push notifications
- Cookies and similar technologies to maintain sessions
2.4 Payment Information
Payment data (credit/debit cards) is processed directly by Stripe. Systema does not store, process, or have access to full payment card data. We only store Stripe customer and subscription identifiers.
3. Use of Information
We use the information collected to:
- Provide, maintain, and improve our services
- Manage business accounts and their members
- Process payments and billing
- Send relevant notifications (WhatsApp, push notifications)
- Provide artificial intelligence functionalities (virtual coach, nutritional analysis, retention prediction)
- Generate reports and analytics for businesses
- Prevent fraud and improve security
- Comply with legal obligations
4. Multi-Tenant Architecture and Data Isolation
Systema operates with a multi-tenant. This means that each business has its data completely isolated from the rest. We implement:
- Row-Level Security (RLS) in Supabase to ensure that each business only accesses its own data
- Unique identifiers per tenant (
tenant_id) in all tables - Role-based permission validation (Admin, Staff, Client)
- Encryption in transit (HTTPS/TLS) and at rest
5. WhatsApp Business API and Meta Services
Systema is a Meta verified tech providerBusinesses can connect their WhatsApp Business number to our platform using the flow of Embedded Signup from Meta.
5.1 How we use the WhatsApp Business API
- Sending automated notifications (booking confirmations, appointment reminders, payment receipts)
- Conversational bot with artificial intelligence for customer service
- Marketing campaigns and promotional messages (only to users who have given consent)
- Message template management on behalf of the business
- WhatsApp Business Profile Management
5.2 Consent and Opt-in
WhatsApp messages are only sent to users who have voluntarily provided their phone number and have given their consent to receive communications. Users can stop receiving messages at any time by replying "STOP" or by contacting the business directly.
5.3 Wallet System (Collection by message)
Businesses that use the WhatsApp messaging service through Systema operate with a prepaid wallet system. Each message sent is billed according to current rates. Usage history is available in the admin panel.
5.4 Instagram and Facebook Messenger
Systema can also manage Instagram Direct and Facebook Messenger messages on behalf of businesses, using the same AI bot and the same privacy and consent policies that apply to WhatsApp.
5.5 Meta Platform Data
The data received from Meta (message content, phone numbers, delivery statuses, ad account data) is used exclusively to provide the contracted services. We do not sell, share, or use Meta Platform data for our own advertising purposes, AI model training, or any other purpose unrelated to the service.
5.6 Facebook Marketing API (Ad Management)
Systema integrates the Facebook Marketing API to allow businesses to create, publish, and manage Facebook and Instagram ad campaigns directly from our dashboard, without needing to use Meta Ads Manager.
Permisos solicitados:
ads_management— create, edit, pause, and activate campaigns, ad sets, and ads on behalf of the businessads_read— read metrics and insights for campaigns created in Systemabusiness_management— access the specific ad account that the business connectspages_show_listypages_read_engagement— list the business's Facebook pages and associate them with the adsinstagram_basic— post ads on Instagram placements associated with the connected Facebook page
How we use it:
- Create campaigns programmatically when the business designs them in our UI
- Upload creatives (images and videos) to the business ad account
- Read daily and life insights to display them on the business dashboard
- Pause or resume campaigns based on business actions in our panel
Token storage: Marketing API access tokens are stored encrypted at rest in Supabase with restricted access via Row-Level Security. Only the owning tenant and server processes have access to their own tokens. Tokens expire after 60 days and are automatically renewed.
Access scope: Systema nunca accesses ad accounts, pages, or data that the business has not explicitly connected. Each tenant can only view and manage their own connected accounts.
Disconnection: The business can disconnect their ad account at any time from Anuncios IA → Desconectar. This revokes the token immediately in our database. The business can also revoke access directly from their Facebook account's security settings.
Ad spend: All ad spend is charged directly to the business's ad account at Meta. Systema does not charge, receive, or process ad spend payments — the financial relationship is directly between the business and Meta.
5A. Google APIs Services (Calendar, Business Profile, Identity)
Systema integrates various Google APIs to offer optional calendar synchronization, Google Business Profile listing management, and authentication functionalities. All integrations with Google are explicitly initiated by the business owner through Google's official OAuth 2.0 flow.
5A.1 APIs and requested permissions
Systema requests the following Google permissions (scopes) at the time of connection:
openid— unique Google account identifier to link it with the Systema useruserinfo.email— primary email address of the business owner's Google accountcalendar.freebusy— read the availability (busy blocks, no details or attendees) from the owner's Google Calendarcalendar.events— create, read, update, and delete events in the owner's Google Calendar, exclusively to synchronize appointments created in Systemabusiness.manage— list Google Business Profile listings, read and reply to reviews, and update basic business listing information
5A.2 How we use Google data
Google Calendar (two-way appointment synchronization):
- When an end customer books an appointment in Systema (web, WhatsApp or bot), we create the mirror event in the owner's Google Calendar so that it appears in their native Calendar app
- When the owner reschedules or cancels an appointment from Systema, we update or delete the corresponding event in Google Calendar
calendar.freebusyit is used only to show availability and block slots already occupied at the time of booking- We do not read content, attendees, or event details that were not created by Systema
Google Business Profile (reviews and listings):
- List the Google Business Profile listings for the business
- Read received reviews to display them on the Systema dashboard
- Post replies to reviews written or approved by the business (optionally AI-assisted)
- Update basic information on the listing (hours, description) when requested by the business
Identity (openid + userinfo.email):
- Uniquely identify the Google account that is connecting the services
- Show the associated email in the Systema panel so the owner knows which account they have connected
- We do not use email to send communications unrelated to the service
5A.3 Limited Use — Compliance with the Google API Services User Data Policy
Systema's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the requirements of Limited Use.
In particular, Systema no:
- Sell data received from Google APIs
- Use Google APIs data to train generalized artificial intelligence models
- Do not use data from Google APIs for advertising or for any purpose other than the service explicitly requested by the business
- Transfers data from Google APIs to third parties, except when strictly necessary to provide the service (secure storage with infrastructure providers) or when required by law
- Allow humans to read data from Google APIs, except: (a) with explicit and specific user consent, (b) for security purposes (abuse investigation), (c) to comply with applicable law, or (d) when the data has been aggregated and anonymized for internal operations use
5A.4 Storage, encryption, and isolation
- Access tokens (
access_tokenyrefresh_token) from Google are stored encrypted at rest in Supabase - Access is restricted by Row-Level Security: each tenant can only read their own tokens
- Synchronized calendar events are stored linked to the
tenant_idcorrespondiente - Reviews and responses are stored linked to the
tenant_idof the business - Scale IA nunca accesses Google account data that the business has not explicitly connected
5A.5 Revocation and deletion
The business can disconnect Google at any time from:
- Systema Panel → Integraciones → Google Calendar / Google Business Profile → Desconectar
- Google account security settings: myaccount.google.com/permissions
Al desconectar:
- The
refresh_tokenis immediately revoked against Google servers - Tokens stored in Systema are deleted from the database
- Synchronized events and data can be deleted at the business's request
- When canceling the tenant's account, all Google-derived tokens and data are deleted along with the rest of the tenant's data
6. Inteligencia Artificial — Servicio IronMind
Systema uses AI models to offer the IronMind, which includes:
- Virtual Fitness Coach
- Nutritional analysis with image recognition
- Custom routine generation
- Member churn prediction
- Content generation for marketing
6.1 AI Responsibility and Data
⚠️ IMPORTANT CLAUSE
Systema (Skala Marketing) is solely responsible of the artificial intelligence service. Businesses (owners, administrators, and staff) quedan completamente deslindados from any liability arising from the use, recommendations, or results of the AI service.
Data sent to AI services is processed anonymously and is not used to train models. Conversations with the coach are private and are linked to tenant_id correspondiente.
6.2 AI credit plans in the PWA
Business members can purchase AI credit plans directly from the PWA. When doing so, they provide payment data that is processed by Stripe. Systema collects:
- Purchase ID and selected credit plan
- Conversation history with IronMind (securely stored)
- Credit consumption data by period
- Food images submitted for nutritional analysis (processed in real-time, not permanently stored)
6.3 Platform fee
Systema applies a variable commission depending on the processing mode on transactions made through the platform: 0.5% when the business charges via Stripe Connect (funds go directly to its account) and 6.5% when Systema processes the charge through its global account. This information is recorded transparently and can be reviewed by businesses in their billing panel.
7. Data Sharing
We do not sell, rent, or share personal data with third parties for marketing purposes. We only share information with:
- Meta Platform (WhatsApp Business API, Instagram API, Messenger API) — for sending and receiving messages on behalf of businesses. Shared data includes recipient phone numbers and message content
- Meta Platform (Facebook Marketing API) — to create and manage ad campaigns, ad sets, creatives, and read insights on behalf of businesses. Shared data includes ad account identifiers, access tokens, images, and ad texts created by the business
- Google (Calendar API, Business Profile API, OAuth 2.0) — to sync appointments with the owner's Google Calendar and to manage Google Business Profile listings and reviews. Data shared with Google is limited to events that Scale IA creates/edits in the calendar and responses to reviews published by the business. Usage complies with the Google API Services User Data Policy (Limited Use) — see section 5A
- Stripe — for payment processing (business subscriptions, AI credits, and messaging wallet)
- Supabase — as an infrastructure and database provider
- Artificial intelligence providers — Systema uses language and vision models from providers that comply with no-training (Zero Data Retention) policies for data sent via API. Data obtained from Google APIs (Calendar, Business Profile) is never sent to these providers.
- Resend — for sending transactional emails and summaries
- Vercel — as a hosting provider
- Legal authorities when required by law
8. Data Retention
We keep data as long as the business account is active. Upon canceling your subscription:
- Data is retained for an additional 30 days to allow for reactivation
- After 30 days, data may be permanently deleted
- Billing records are kept according to legal requirements
- AI conversations are deleted along with the tenant data
- The data received from Meta Platform (messages, tokens) is deleted along with the tenant's data
- Facebook Marketing API tokens and ad account identifiers are revoked and deleted along with the tenant's data. Campaigns created in Meta Ads Manager remain in the business's account (under its direct control) but are unlinked from Systema
- Google APIs tokens (Calendar and Business Profile) are revoked against Google's servers and deleted from our database. Events created by Systema in the owner's Google Calendar and review replies posted on Google Business Profile remain in the business's Google accounts (under their direct control), but are unlinked from Systema
9. User Rights
Users have the right to:
- Acceso — Request a copy of your personal data
- Rectification — Correct inaccurate or incomplete data
- Deletion — Request the deletion of your data
- Portabilidad — Receive data in a structured format
- Opposition — Object to data processing
To exercise these rights, contact us at info@info.skalastudios.com or via WhatsApp.
To request the complete deletion of your data, please visit our page at Data Deletion.
10. Seguridad
We implemented security measures including:
- TLS/SSL encryption for all communications
- Row-Level Security (RLS) Policies in Databases
- Passwords with minimum requirements of 8 characters with letters and numbers
- Secure authentication with JWT tokens
- Security event and audit monitoring
- Complete data isolation between businesses
11. Cookies
We use cookies and similar technologies exclusively to:
- Keep user sessions active
- Remember configuration preferences
- Basic platform usage analysis
We do not use third-party cookies for advertising tracking.
12. Minors
Systema is not directed at minors under 16. If a business registers underage members, it is the business's responsibility to obtain the corresponding parental or legal guardian consent.
13. Changes to this Policy
We reserve the right to update this policy. We will notify you of significant changes via email. Continued use of the platform after changes constitutes acceptance of the updated policy.
14. Contacto
Systema — Skala Marketing
- 📧 Email: info@info.skalastudios.com
- 💬 WhatsApp: +1 (786) 694-1642
- 🌐 Web: scalesystema.app
© 2026 Skala Marketing LLC · Systema. All rights reserved.