Skip to content

Privacy

Privacy notice

Last updated 17 September 2026

Sequro is software for insurance brokerages. We handle two very different things: data about the people who buy Sequro, and data about those brokerages' own customers, which reaches us because an agent collected it on a call. We are the controller of the first and merely a processor of the second, where the brokerage is the controller. That distinction decides who you write to, so it comes first.

01

Who we are

CINCO AM, of Ciudad de México, Mexico, is the controller — *responsable* under Mexico's LFPDPPP — for personal data about our own users: the people who open a Sequro account and work in it.

For anything about privacy: privacidad@sequro.ai.

02

What we collect from our users

The name, email address and hashed password of whoever opens the account. The brokerage's name. The cédula of any adviser they register, because without one the system will not let options be released to a customer.

Usage: which agents exist, how many conversations happened, what moved on the board. The compliance ledger records every act with who performed it.

We do not collect card details. Polar processes payment as merchant of record and payment data never touches our servers.

03

If you are a brokerage's customer

If you spoke to a voice agent and your details are in here, the controller is the brokerage that dealt with you, not us. They decided what to ask and why. We only run the system it was stored in.

Your ARCO rights — access, rectification, cancellation and objection — are exercised with that brokerage. Write to us and we will tell you who to ask; we cannot delete or hand over data we do not control without instruction from whoever does.

04

What we use it for

Running the service: authenticating a session, operating the agents, keeping the board and the compliance ledger, and billing the subscription.

Telling you about your own account: welcome, payments, a limit about to run out. We never send marketing to our customers' customers.

We do not sell data, do not train models on it, and do not pool it across accounts.

05

Who we share it with

The providers the service runs on: Neon (database), Vercel (hosting), ElevenLabs (voice), Resend (email) and Polar (payment). Each receives only what its part needs.

If you connect WhatsApp, conversations pass through Meta under your brokerage's own WhatsApp Business account, with the relationship and the billing directly between Meta and you.

A competent authority, on a properly founded request.

06

Recordings and transcripts

Agents are configured not to retain audio. What is kept is the transcript and the facts the agent captured, because that is the case file.

At the start of a call the agent says it is an automated system and that the conversation is recorded. There is no screen anywhere that switches that notice off.

07

Retention

Account data is kept for as long as the account exists. The compliance ledger is kept separately, because its whole use is being able to reconstruct afterwards who did what.

This is a demonstration build and no automatic deletion policy is enforced yet. It is recorded as outstanding in the project's technical documentation, and we say so here rather than claim otherwise.

08

Security

bcrypt-hashed passwords, signed sessions, encryption in transit, and tenancy enforced on every query.

No system is impregnable. If a breach materially affects your rights, we will tell you.

09

Where data lives

On infrastructure in the United States and Europe, depending on the provider. Using the service means accepting that transfer.

10

Your ARCO rights

If you are a Sequro user, write to privacidad@sequro.ai to access, rectify, cancel or object to the processing of your data, or to withdraw consent. We answer within twenty working days.

You may also approach INAI if you believe a request was not handled properly.

11

Changes

If this changes materially we email the account and update the date above. The version in force is always the one published here.