Privacy Policy
Last updated: 26 July 2026
This Privacy Policy describes the processing of personal data carried out in connection with access to and use of the Whilehaus client portal, available at app.whilehaus.net (the "Portal"), and forms part of the Terms of Use.
The data controller is Martin Bonafede, Argentine tax ID (CUIT) 20-33215496-7, registered under the simplified tax regime (monotributo), domiciled at Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Republic of Argentina, trading under the business name Whilehaus. Contact address for the purposes of this Policy: hola@whilehaus.net.
The Portal does not sell personal data, displays no advertising, does not disclose personal data for advertising purposes and does not use it to train artificial intelligence models.
1. Scope
1.1. This Policy applies to personal data processed through the Portal, its application programming interfaces and its connectors for artificial intelligence agents.
1.2. It does not apply to third-party sites, applications or services accessed from the Portal, including the Studio’s other applications, which are governed by their own policies.
2. Dual role: controller and processor
2.1. In respect of account data, contact data of clients and prospects, and Portal usage data, Whilehaus acts as data controller.
2.2. In respect of third-party personal data that the user uploads to the Portal as part of the content of a project, Whilehaus acts as processor and the user as controller. In that case, Whilehaus processes such data in accordance with the instructions received, does not apply it to unrelated purposes and deletes or returns it at the end of the relationship, on the terms of section 25 of Argentine Law 25.326.
3. Categories of data processed
3.1. Data supplied by the user or by the client it represents:
- Identification and contact data: first and last name, email address, telephone number where provided, and the organisation to which the user belongs and the position held.
- Credentials: passwords are stored exclusively by means of a hash function, never in readable form. Where access is effected through Google or GitHub, the account identifier and associated email address are received from the provider.
- Project content: documentation, files, specifications, deliverables, messages and notes, together with any third-party personal data the user chooses to include in them.
- Communications: the content of enquiries, conversations and requests made through the Portal or sent to the Studio.
3.2. Data generated by use of the Portal:
- Technical and connection data: IP address, user agent, session identifiers, timestamps, access logs and error logs.
- Usage data: actions performed within the Portal and activity of authorised artificial intelligence agents.
3.3. Commercial management data: in the case of prospects, contact details, source of the enquiry, status of the opportunity and a record of the interactions held, processed for the purpose of managing the commercial relationship.
3.4. Data obtained from third parties: data supplied by federated authentication providers, with the scope described above, and data the client provides when requesting an account for a person in its organisation.
4. Purposes and lawful bases
- Provision of the Portal: creating and administering the account, hosting and displaying content, managing access permissions. Basis: performance of the contract under which access is granted and legitimate interest in coordinating the professional relationship.
- Provision of the contracted professional services and management of the client relationship. Basis: performance of the contract.
- Commercial management of enquiries and prospect opportunities. Basis: consent of the data subject in contacting the Studio and legitimate interest.
- Transactional communications: email address verification, password reset, invitations and notices concerning the Portal. Basis: performance of the contract.
- Security and integrity: access logs, usage limits, detection and prevention of unauthorised access. Basis: legitimate interest.
- Compliance with legal, accounting and tax obligations, and the exercise or defence of rights. Basis: compliance with legal obligations and legitimate interest.
4.1. No mass commercial communications or newsletters are sent through the Portal.
4.2. No automated decisions are taken that produce legal effects concerning the data subject or otherwise significantly affect them.
5. File hosting in the Studio’s Google Drive
5.1. Files uploaded to the Portal are held in a Google Drive account owned by the Studio and linked to the application, within a folder created and administered by it. Users should take this into account when deciding what information to upload to the Portal.
5.2. Access to those files occurs through the Portal, which delivers them from its own domain by means of links of limited validity. No permissions over the Studio’s Google Drive account are shared and users are granted no access to its remaining content.
5.3. Deleting a file from the Portal moves it to the trash of that account, where it is subject to the provider’s retention periods.
6. Google API integration and Limited Use
6.1. The Portal integrates with Google APIs for two distinct purposes: sign-in with a Google account and hosting of files in the Google Drive account linked by the Studio.
6.2. The permissions requested and their purpose are as follows:
- openid and userinfo.email: identification of the account and retrieval of the associated email address, solely in order to establish the session or to identify in the interface the linked storage account.
- drive.file: restricted access, limited exclusively to files and folders that the application itself creates, or that are deliberately opened with it. This permission does not grant access to the remainder of the linked account’s Google Drive content: the application cannot read, list, modify or delete files or folders it did not create.
6.3. This application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6.4. In particular, with respect to data obtained from Google APIs:
- It is used exclusively to provide and improve the user-facing features of the Portal.
- It is not transferred to third parties, except to the extent strictly necessary to provide those features, where required by law or by a competent authority, or where express consent is given.
- It is not used for advertising purposes, nor disclosed to advertising platforms, data brokers, information resellers or market intelligence providers.
- It is not read by humans, unless express consent is given for a specific support operation, it is necessary for security purposes, including the investigation of abuse or vulnerabilities, or it is required by law.
- It is not used to train generalised artificial intelligence models.
6.5. Access and refresh credentials issued by Google are stored encrypted and are used solely to operate the application’s folder within the linked account.
6.6. Access may be revoked at any time from the Portal’s storage settings or from the Google account administration at myaccount.google.com/permissions. Revocation does not delete files already held in Google Drive.
7. Artificial intelligence features and authorised agents
7.1. Where features assisted by artificial intelligence are used, the data strictly necessary to execute the requested operation is transmitted to the relevant model provider, which acts as processor or as independent controller depending on the case. The Studio uses its own provider credentials for this purpose.
7.2. The Portal exposes connectors allowing artificial intelligence agents to access content: an operations connector, reserved to the Studio, and a client connector, read-only and confined to the content of the client to which the token has been associated. Operations executed by agents are logged for security and audit purposes.
7.3. Each agent’s provider processes the information it accesses in accordance with its own policies, which are outside the Studio’s control.
7.4. Whilehaus does not use the content to train artificial intelligence models, whether its own or third parties’, and does not authorise its providers to do so.
8. Access to other Studio applications
8.1. The Portal acts as an access point to other Studio applications. When that feature is used, a signed, short-lived identifier containing the user’s email address is transmitted to the destination application, allowing the session to be established without requesting credentials again.
8.2. Each destination application processes data in accordance with its own privacy policy.
9. Recipients and processors
9.1. Data is not disclosed to third parties, save for the providers necessary to operate the Portal, which act as processors and are contractually bound to process data in accordance with instructions, subject to confidentiality and with adequate security measures:
- Supabase Inc.: database and authentication. Infrastructure hosted on Amazon Web Services, region us-east-1 (Northern Virginia, United States).
- Vercel Inc.: application hosting, content delivery network and application logs (United States).
- Google LLC: federated authentication and file hosting in Google Drive, in accordance with sections 5 and 6.
- GitHub, Inc.: federated authentication, where the user opts for it.
- Resend: transactional email delivery.
- Anthropic PBC and other artificial intelligence model providers: with the scope set out in section 7.
9.2. Data may be disclosed to competent administrative or judicial authorities upon a reasoned request, and to professional advisers bound by confidentiality, to the extent necessary for the exercise or defence of rights.
9.3. In the event of corporate reorganisation or transfer of the business unit, data may be transferred to the successor, which will be bound by this Policy.
10. International transfers
10.1. The Portal’s principal infrastructure is hosted in the United States of America. Certain processors may process data in other jurisdictions.
10.2. The United States is not covered by a general adequacy finding under section 12 of Argentine Law 25.326. Transfers therefore rely on the informed consent of the data subject, on the necessity of the transfer for performance of the contract, and on contractual commitments entered into with each processor replicating the protection standards required by Argentine law and, where applicable, by Regulation (EU) 2016/679, by means of standard contractual clauses.
11. Retention periods
- Account data: retained while access to the Portal remains enabled.
- Project content: retained during the professional relationship and thereafter for the period necessary to address legal obligations, warranties or potential claims, and in no case beyond what the applicable services agreement provides.
- Account deletion: data is removed from production systems within thirty (30) calendar days of the request, except data whose retention is legally required. Encrypted backups may subsist for up to a further ninety (90) days until rotated.
- Commercial management data of prospects that do not result in an engagement: up to twenty-four (24) months from the last interaction, unless the data subject objects earlier.
- Accounting and supporting documentation: for the period required by Argentine tax and commercial law, which may extend to ten (10) years.
- Technical and security logs: up to twelve (12) months, unless required for the investigation of an incident.
12. Security measures
12.1. Technical and organisational measures appropriate to the risk are applied, including: encryption of communications by means of TLS, encryption of reversible secrets at rest, isolation of data at database level, storage of passwords by means of a hash function, role-based access control, operation logging and restriction of internal access to the minimum necessary.
12.2. No system is invulnerable. Should a security incident affecting personal data occur, containment measures will be adopted and the notifications required by applicable law will be given to data subjects and to the supervisory authority within the prescribed periods.
13. Cookies
13.1. The Portal uses only technically necessary cookies and local storage: the session cookie supporting authentication, the cookie recording the selected language and those preserving interface preferences. Disabling them prevents the Portal from functioning.
13.2. The Portal displays no advertising, incorporates no advertising or cross-site tracking cookies, and shares no data with advertising platforms.
14. Rights of the data subject
14.1. The data subject may exercise the rights of access, rectification, updating, deletion, portability and, where applicable, objection and restriction of processing, by request to hola@whilehaus.net. Requests are handled within the statutory periods, following reasonable verification of the requester’s identity.
14.2. Where the request concerns data in respect of which Whilehaus acts as processor, it will be referred to the controller of that content, to whom it falls to resolve it.
14.3. Under Argentine law, the data subject is entitled to exercise the right of access to their data free of charge at intervals of no less than six months, unless a legitimate interest to the contrary is established, pursuant to section 14, subsection 3 of Law 25.326.
14.4. The Agencia de Acceso a la Información Pública, as the supervisory body under Law 25.326, has the power to hear complaints and claims brought by persons whose rights are affected by non-compliance with the rules in force on personal data protection.
14.5. Data subjects domiciled in the European Economic Area or the United Kingdom additionally hold the rights conferred by Regulation (EU) 2016/679 and by equivalent United Kingdom legislation, including the right to lodge a complaint with the supervisory authority of their jurisdiction.
15. Minors
15.1. The Portal is directed exclusively at persons aged eighteen (18) or over, in the context of a professional relationship. Data concerning minors is not knowingly collected.
16. Amendments to this Policy
16.1. This Policy may be updated. Material amendments will be notified to the registered email address or by notice within the Portal, with reasonable advance notice of their taking effect. The date of the last update is stated at the beginning of the document.
17. Contact
Enquiries regarding this Policy and the exercise of rights: hola@whilehaus.net. Martin Bonafede (Whilehaus), CUIT 20-33215496-7, Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Republic of Argentina.
This Policy was drafted in Spanish, which is the governing version for all purposes. Translations into other languages are provided for information only: in the event of discrepancy, the Spanish version prevails.