This policy explains how Sixto handles personal data on the website at holasixto.com and in the Sixto app. It applies Colombian data protection law (Ley 1581 de 2012, Decreto 1377 de 2013 and Decreto 1074 de 2015) and is written to be useful to visitors and customers in the European Union, the United States and elsewhere too.
Who we are
Sixto is operated by [Sixto legal entity, S.A.S.], NIT [NIT], registered at [registered address], Medellín, Colombia ("Sixto", "we"). We build software for short-term rental and boutique hotel operators, starting in Colombia.
Contact for privacy matters: [email protected]. This is also the channel for exercising your rights (see below).
Our roles: controller and processor
It matters who decides what happens to data, so we separate two situations.
- Sixto as controller (Responsable del Tratamiento): for data about our website visitors, people who contact us or book a demo, and the people who hold and administer a Sixto account (name, work email, role, billing details, usage of the app).
- Sixto as processor (Encargado del Tratamiento): for the data our customers (hotel and rental operators) put into Sixto about their own guests, staff and business, such as reservations, contact details, identity documents for SIRE and TRA filings, payments and messages. The customer is the controller for that data and decides why and how it is used. Sixto processes it only on the customer's documented instructions under our Data Processing Addendum.
If you are a guest of an operator that uses Sixto, the operator is your first point of contact for your data. If you write to us, we will pass your request to the operator or tell you who to contact.
What we collect
On the website: what you type in the Book a demo and Contact forms (name, email, company, optional WhatsApp number, portfolio size and location, tools you use, what you want to see, your message, your language and the page you came from) and campaign parameters in the link you arrived from (utm_source, utm_medium, utm_campaign). Our hosting and security provider also receives technical request information such as IP address and browser details. See the Cookie Notice for what stays in your browser. Public website analytics use Umami Cloud without cookies. Measurements include pages viewed, referrers, campaigns and general device and location information. The tracker does not run in the app or guest check-in pages and we do not send form contents or guest records to it. Your browser contacts Umami directly. See the Cookie Notice.
In the app, as controller: account details (name, email, role, language), sign-in and security events, billing and subscription information (card data is handled by Stripe and we do not store full card numbers), support conversations, product feedback, and usage and diagnostic data so we can run, secure and improve the service.
In the app, as processor, on behalf of our customers: guest and reservation data (names, contact details, nationality, travel dates, preferences), identity document data and images where the operator uses them for SIRE, TRA or check-in, messages exchanged with guests, payment and invoice records, access information for smart locks (door codes are masked in AI processing), and team member records. Which data is collected is decided by the operator.
Why we use data and our legal bases
As controller we use personal data to: reply to your enquiries and prepare demos (our legitimate interest and your request); create and run your account and deliver the service (performance of the contract); bill you and meet tax obligations (contract and legal obligation); keep Sixto secure, prevent abuse and fix problems (legitimate interest and legal obligation); and improve the product using aggregated or limited usage information (legitimate interest). Under Colombian law, where we need your authorization (Autorización) we ask for it, and it is prior, express and informed.
As processor we use customer data only to provide the service to the customer and follow their instructions. We do not sell personal data, we do not use it for advertising, and we do not use customer data to train AI models.
If you are in the European Union or United Kingdom, the legal bases above correspond to Article 6 of the GDPR (contract, legitimate interests, legal obligation and consent).
AI processing and redaction
Some Sixto features use AI providers, for example to draft replies, classify messages or read documents. Requests reach those providers through a Sixto gateway that redacts sensitive details first, including door codes, labelled secrets and identity document numbers. Guest identity documents are read by AI only after the guest gives explicit consent in the check-in flow, and the image and the result of that reading are not logged or stored by the gateway.
We do not use customer data to train AI models and we contract AI providers on terms that do not allow them to train on it. AI output is a suggestion: the operator reviews it before it is sent or relied on. Customers can connect their own AI agent through API keys; that agent only gets the permissions the customer grants.
Sharing and subprocessors
We share personal data only as needed to run Sixto: with service providers that process data for us (hosting, email delivery, AI providers, payments, error monitoring and customer support tooling), with integrations the customer chooses to connect (such as channel managers, property management systems, smart locks and e-invoicing providers), with authorities when the law requires it, and in a business transfer such as a merger, with notice to you.
Subprocessors are bound by written agreements that require confidentiality, security and use only for our instructions. The categories we use are listed on our Subprocessors page, and the current named list is available on request at [email protected].
Support staff can access a customer's account only with that customer's consent. Access is read-only by default and recorded in an audit log.
International transfers
Sixto and some of our providers process data outside Colombia, including in the United States. Where we transfer personal data internationally we do so as Colombian law allows, under the standards and safeguards set out by the Superintendencia de Industria y Comercio (SIC) and, for data covered by the GDPR, under appropriate safeguards such as standard contractual clauses. Our providers are required to protect the data to at least the level that applies in Colombia.
Retention
We keep data only as long as needed for the purpose it was collected, then delete or anonymize it. Website form submissions are kept while we are talking with you about Sixto and deleted when you ask or when they are no longer useful. Account and billing records are kept while the account is active and afterwards for the period the law requires for tax and accounting.
Customer data processed on behalf of operators is kept while their account is active. After termination it stays available for export for 30 days and is then deleted from active systems, and from backups as they roll off. Operators set their own retention practices for guest data in line with their legal duties, and can delete records in the app.
Security
We protect personal data with encryption in transit, strict separation between customer accounts, role-based permissions, audit logs, a credential vault for integration secrets, and limited, consent-based support access. No system is perfectly secure. If a security incident affects your personal data, we will notify the affected customers and, where the law requires, the authorities, without undue delay. See our Security page.
Your rights as a Titular
Under Ley 1581 de 2012 you have the right to:
- know (conocer) the personal data we hold about you and how it is used;
- update (actualizar) it;
- rectify (rectificar) it when it is inaccurate, incomplete or misleading;
- request proof of the Autorización you gave, except where the law makes it unnecessary;
- be told how your data has been used;
- delete (suprimir) your data and revoke your Autorización when the processing does not respect the law, subject to legal or contractual duties to keep it;
- access your data free of charge;
- file a complaint with the Superintendencia de Industria y Comercio (SIC) once you have first asked us (Habeas Data).
If the GDPR or a similar law applies to you, you can also ask for a copy of your data in a portable format, object to certain processing and restrict it.
To exercise your rights, write to [email protected] from the email linked to your data and say what you want. We may ask you to prove your identity. If you are a guest of an operator, we will forward your request to the operator, who is responsible for it.
We answer queries (consultas) within 10 business days. If we need more time we will tell you why and the new date, which will not be more than 5 additional business days. We answer claims (reclamos) to update, rectify, delete or revoke within 15 business days, extendable once by up to 8 business days with the reason. If a claim is incomplete we will ask you to complete it within 5 days.
Children
Sixto is a business tool and is not directed at children. We do not knowingly collect data from children through the website or for our own purposes. Operators may need to record minors who travel with an adult guest for their legal filings. They do so as controllers, with the authorization of the child's parent or legal guardian where the law requires it, and we process that data only for them.
Changes to this policy
We will post any change here and update the effective date. For material changes affecting customers we will notify them by email or in the app before the change takes effect.
Contact
Questions, requests or complaints about personal data: [email protected]. Postal address: [Sixto legal entity, S.A.S.], [registered address], Medellín, Colombia. We will respond within the times above. You can also contact the Superintendencia de Industria y Comercio (www.sic.gov.co) at any time.
