Legal

Privacy policy

Last updated: May 11, 2026

1. Who we are

Orkasa Technologies ("Orkasa", "we") is a B2B SaaS platform offering a real estate CRM to brokers and agents across Latin America. We operate out of Panama and comply with Panama Personal Data Protection Law 81, as well as the data protection frameworks of every country where our customers operate.

2. What data we collect

  • Account data: name, email, password (hashed), brokerage name, role, phone number.
  • Usage data: properties uploaded, leads captured, posts published, photos uploaded, AI interactions.
  • Technical data: IP address, user agent, session cookies, error logs.
  • Your customers data (leads): name, email, phone, real-estate interests, KYC documents when applicable. This data is yours; you are the data controller before the data subject.

3. What we use the data for

  • Provide the CRM service and keep your account operational.
  • Process portal publications and lead communications on your behalf.
  • Send transactional emails (alerts, confirmations, receipts) and, with your consent, product updates.
  • Improve Orkasa: aggregated, anonymous telemetry and A/B testing.
  • Comply with legal obligations (KYC/AML, requests from authorities).

4. Who we share data with

We work with sub-processors that are SOC 2 / ISO 27001 compliant:

  • Supabasedatabase, authentication, storage.
  • Vercelapplication hosting.
  • AnthropicClaude, used for the listing studio (data is not used for model training).
  • GoogleGemini Flash Image, for photo enhancement.
  • Stripepayment processing.
  • Resendtransactional emails.
  • Meta Platforms (Facebook / Instagram)only when the user voluntarily connects their account, to publish properties on their Facebook Page and/or Instagram Business account. See section 11.

We never sell your data or your customers data. We only share with authorities under a valid legal request.

5. How long we keep the data

For as long as your account is active. If you cancel, you get 30 days to export everything. After 30 days we delete the data, except records we are legally required to retain (billing, KYC) for up to 5 years.

6. Your rights

Under Panama Law 81 and equivalent regulations across other LATAM countries, you can exercise your ARCO rights:

  • Access: request a copy of your data.
  • Rectification: correct inaccurate data.
  • Cancellation: delete your data when no longer needed.
  • Opposition: withdraw consent for non-essential uses.

To exercise these rights, write to privacidad@orkasa.io.

7. Security

Encryption at rest (AES-256) and in transit (TLS 1.3). Postgres RLS scoped by brokerage_id — each brokerage data is isolated. Daily backups with 30-day retention. MFA available for owners. Annual pen-tests.

8. Cookies

We use only strictly necessary cookies (session, language preferences) and, optionally, aggregated anonymous analytics. We do not use third-party advertising tracking cookies.

11. Meta integration (Facebook and Instagram)

Orkasa lets you publish properties directly to your Facebook Page and your Instagram Business account through the Meta API. This integration is completely optional and requires your explicit authorization.

Data we access through Meta:

  • Your Facebook Page name and ID.
  • The Page Access Token, needed to publish on your behalf.
  • Your Instagram Business account ID linked to the Page (if any).

How we use that data:

  • Exclusively to publish the properties you create and approve inside Orkasa on your Facebook Page and/or Instagram Business.
  • Tokens are stored encrypted in our database, never shared with third parties, and never used for any other purpose.

What we do NOT do:

  • We do not read your inbox, messages or comments.
  • We do not access your audience data or your post metrics.
  • We do not publish anything unless you initiate the action from Orkasa.

You can disconnect the integration at any time from Settings → Integrations. When you disconnect, we delete the stored token. To revoke access from the Meta side, visit facebook.com/settings → Apps.

If you have questions about the Meta API usage, write to privacidad@orkasa.io.

12. Account and data deletion

You can request the complete deletion of your Orkasa account and associated data at any time.

How to request it:

Write to privacidad@orkasa.io with the subject "Data deletion request" from the email associated with your account. We respond within 30 days.

What is deleted:

  • Your user account and the brokerage data.
  • Properties, photos, leads, messages and posts.
  • All integration tokens (Meta, WhatsApp, Google) and the data synced from those platforms.
  • If you connected Facebook, Instagram or WhatsApp Business, your tokens are revoked with Meta and all associated data is purged from our systems.

We retain for up to 5 years only the records required by law (billing, KYC/AML) in separated, encrypted storage with no operational access.

You can also revoke Orkasa access from the Meta side by visiting facebook.com/settings → Apps.

9. Changes to this policy

If we make material changes, we will notify you by email at least 30 days in advance. Minor changes are reflected in the "Last updated" date.

10. Contact

Questions, complaints, exercising your rights: privacidad@orkasa.io.

Privacy policy — Orkasa · Orkasa