1. Who we are
Concilo, operated by Cibernética, S.A. ("Concilo", "we"), is an autonomous collections and reconciliation platform domiciled in Panama City, Republic of Panama. We are the controller of the personal data described in this policy, under Law 81 of March 26, 2019 on Personal Data Protection and its regulations (Executive Decree 285 of 2021).
Privacy contact: hola@concilo.ai.
2. What data we process
- Site visitor data: contact details you send us voluntarily (name, email, phone) when requesting a demo or trying the demo widget.
- Concilo customer data: contact and billing details of platform users (name, email, role, company).
- Data processed on behalf of our customers: when a company uses Concilo to manage its receivables, we process data about its debtor customers (name, phone, invoices, payment history and collection conversations) as a data processor, following that company's instructions — the company is the controller.
3. What we use it for
- Responding to demo requests and commercial contact.
- Running the demonstration you yourself request (a single WhatsApp conversation that you start yourself, with no later use).
- Providing the contracted service: automated collections, payment reconciliation, reporting and audit.
- Meeting legal and security obligations.
We don't sell personal data or use it for third-party advertising.
4. Legal basis
We process data based on: (i) your consent, which you can withdraw at any time; (ii) the performance of a contract or pre-contractual steps you request; (iii) legal obligations; and (iv) our legitimate interest in operating and protecting the service, without impairing your rights.
5. Who we share it with
Only with providers we need to operate — cloud infrastructure, messaging (WhatsApp/telephony) and AI processing — under contracts that limit data use to providing the service. Some providers are outside Panama; in those cases we require protections equivalent to Panamanian law. We may also disclose data if a competent authority orders it.
Integrations and third-party trademarks. The names and logos of banks, ERPs and other systems shown on this site are trademarks of their respective owners and appear solely to indicate technical compatibility. Concilo is not affiliated with, associated with, sponsored by or officially endorsed by any of them. We connect to those systems through the host-to-host, REST or file interfaces that the customer has contracted with their own bank or provider and enables for us, using the customer's credentials and under their express authorisation. We do not access any third party's system on our own account, and we hold no contractual relationship with those institutions.
6. How long we keep it
Demo widget data is kept for a maximum of 90 days. Customer data is kept for the duration of the contractual relationship and applicable legal retention periods. Afterwards it is deleted or anonymized.
7. Your rights
Under Law 81 of 2019 you have the right to access, rectify, cancel and object to the processing of your data, and to request its portability ("ARCO+" rights). Write to hola@concilo.ai and we'll respond within the legal deadlines. If you're not satisfied, you can turn to the National Authority for Transparency and Access to Information (ANTAI).
If you're a debtor customer of a company that uses Concilo, the controller of your data is that company; we'll help you route your request to them.
8. Security
We apply reasonable technical and organizational measures: encryption in transit, role-based access control, audit logs and per-customer isolation. No system is infallible; if a breach affecting you occurs, we'll notify you as the law requires.
9. Cookies
This site uses no tracking cookies or third-party analytics. Only what's strictly necessary for the page to work.
10. Changes to this policy
We'll publish any change here, with its date. If the change is substantial and we have a way to contact you, we'll let you know.