define-itstudio / sf
← Back to siteENES
Legal

Privacy Policy

How define-it collects, uses, stores and protects personal information across our website and the products we own and operate.

Last updated: August 18, 2026

Contents

01Who we are02Scope of this policy03Information we collect04How we use information05Google user data (Define-rees)06Google API Services Limited Use disclosure07Legal bases08Sharing and sub-processors09Data retention10Security11Your rights12International transfers13Children's privacy14Changes to this policy15Contact

01Who we are

define-it S.A.S. ("define-it", "we", "us") is a software studio registered in Santa Fe, Argentina. We build and operate web products and SaaS platforms, including My Turn, Define-rees, Morfan and Define-edu.

We are the data controller for the personal information described in this policy. You can reach us at ventas@define-it.com.ar.

02Scope of this policy

This policy covers the website at define-it.com.ar and the products define-it owns and operates, including Define-rees and its Google Calendar integration.

When we build software for a client, that client is the controller of their end-user data and their own privacy policy applies. This policy then describes only our role as a processor acting on their instructions.

Our site and products link to third-party services we do not control. This policy does not apply to them.

03Information we collect

We keep collection to what a given feature actually needs.

  • Contact data you submit. Name, email address, company, and the content of any message you send through our contact, diagnostic or beta forms.
  • Account data. For products that require an account: name, email address, a hashed password or the identifier of the identity provider you used, role, and workspace membership.
  • Product data. The records you create while using a product — for Define-rees, real estate listings, agency data, leads and appointments.
  • Google account data. Only if you explicitly connect a Google account. See Google user data below.
  • Usage analytics. Aggregated, cookie-less page-view and interaction data collected through a self-hosted Umami instance, plus a low-rate sample of anonymised session recordings with input masking. No advertising or cross-site tracking.
  • Technical logs. IP address, user agent, timestamps and error traces generated by our hosting provider for security, abuse prevention and debugging.

04How we use information

  • To provide, operate and maintain the features you asked for.
  • To answer enquiries, send quotes and provide support.
  • To secure our systems, prevent abuse and investigate incidents.
  • To understand aggregate usage so we can improve the products.
  • To comply with legal, accounting and tax obligations.

We do not sell personal information, we do not serve advertising, and we do not use your data — including any data obtained from Google APIs — to train generalised artificial intelligence or machine learning models.

05Google user data (Define-rees)

Define-rees is our multi-tenant platform for real estate agencies: a single API operated by define-it that powers the independent websites and back-offices of the agencies that use it. Each agency is a separate tenant, and its data is isolated from the rest.

Define-rees offers an optional Google Calendar integration that keeps property viewings and client appointments in a calendar dedicated to Define-rees, inside the Google account the agency team already uses.

The integration is opt-in and is authorised per agency, by a member of that agency. Nothing is accessed until you complete the Google OAuth consent flow and grant the requested scopes. The scopes we request and what each one is used for:

  • https://www.googleapis.com/auth/calendar.app.created — to create a calendar dedicated to Define-rees in your Google account, and to create, read, update and delete the appointment events on that calendar only. This scope does not grant access to any of your pre-existing calendars.
  • https://www.googleapis.com/auth/calendar.freebusy — to check when you are busy, so Define-rees can show real availability and avoid double-booking a viewing. This scope returns busy time ranges only: never the title, attendees, location or description of your events.
  • https://www.googleapis.com/auth/userinfo.email — to read the email address of the Google account you connected, so we can show which account is linked and assign appointments to the right team member.

What we store. OAuth access and refresh tokens (encrypted at rest), the email address of the connected Google account, the identifier of the Define-rees calendar we created in it, and the identifiers of the events we placed on that calendar together with the minimum fields needed to keep them in sync (title, start and end time, attendees, location). Availability is queried in real time and the busy ranges returned are used to compute a result and then discarded — we do not store them, and we do not create a copy of your calendar.

What we never do. We cannot read the contents of your existing calendars: the scopes we request do not allow it, so the limit is technical and not merely a promise. We do not use calendar data for advertising or profiling, do not sell or transfer it, and do not feed it to AI or machine learning models.

Disconnecting. You can revoke access at any time from the Define-rees integration settings, or from myaccount.google.com/permissions. On revocation we delete the stored tokens immediately and the remaining synchronisation data within 30 days. The Define-rees calendar and the events already written to it stay in your Google account, under your control, and you can delete them yourself at any time.

06Google API Services Limited Use disclosure

define-it's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, data obtained through Google APIs is:

  • used only to provide or improve the user-facing features that are prominent in the Define-rees interface and for which you granted access;
  • never transferred to third parties, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition after notice to you;
  • never used for serving advertising, including retargeting, personalised or interest-based advertising;
  • never read by a human, unless we have your explicit consent for a specific case, it is necessary for security purposes or to investigate abuse, it is required by law, or the data is aggregated and de-identified for internal operations.

07Legal bases

We process personal information under Argentine Law No. 25.326 on the Protection of Personal Data and, where the GDPR applies, on the following bases: performance of a contract, our legitimate interest in operating and securing our services, your consent (for optional integrations such as Google Calendar, which you may withdraw at any time), and compliance with legal obligations.

08Sharing and sub-processors

We share personal information only with service providers that help us run the products, under contract and limited to what their function requires:

  • Vercel — application hosting and edge delivery.
  • Google LLC — Google Calendar APIs, only for accounts you connect.
  • Postmark — transactional and notification email.
  • Umami (self-hosted) — privacy-first, cookie-less analytics.
  • Payment processors — for products that take payments, limited to what is needed to process the transaction.

We may also disclose information when required by a valid legal request, or to protect the rights, safety and property of define-it, our clients or the public.

09Data retention

  • Contact form submissions: up to 24 months from the last interaction.
  • Account and product data: for as long as the account is active, then up to 90 days after closure, unless a longer period is required for accounting or legal reasons.
  • Google OAuth tokens: deleted immediately on disconnection or account closure.
  • Google Calendar synchronisation data: deleted within 30 days of disconnection.
  • Technical logs: up to 90 days.

10Security

All traffic runs over TLS. Credentials and OAuth tokens are encrypted at rest. Access to production systems is restricted to the define-it team members who need it, protected by two-factor authentication, and reviewed periodically. No system is perfectly secure, but if a breach affects your personal information we will notify you and the competent authority without undue delay.

11Your rights

You have the right to access, rectify, update, delete and port your personal information, to object to or restrict certain processing, and to withdraw consent for optional integrations.

To exercise any of these, write to ventas@define-it.com.ar. We answer within 30 days. Under Argentine law, access is free of charge at intervals of no less than six months.

The Agencia de Acceso a la Información Pública is the enforcement authority for Law No. 25.326 and handles complaints about breaches of Argentine data protection rules. If the GDPR applies to you, you may also complain to your local supervisory authority.

12International transfers

Our providers operate infrastructure outside Argentina, mainly in the United States and the European Union. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.

13Children's privacy

Our products are intended for businesses and professionals. We do not knowingly collect personal information from children under 13. Where a product is used by an educational institution, the institution is the controller and acts under its own consent and policies. If you believe a child has provided us with personal information, contact us and we will delete it.

14Changes to this policy

We may update this policy as our products evolve. The "last updated" date at the top always reflects the current version. For material changes — in particular any change to the Google data we access or how we use it — we will give notice in the product or by email before the change takes effect.

15Contact

define-it S.A.S. · Santa Fe, Argentina · ventas@define-it.com.ar

Questions about this policy? Write to ventas@define-it.com.ar and we will answer within 30 days.

© 2026 define-it S.A.S. · Santa Fe, AR
Terms of ServiceHome