Legal information
Privacy Policy
This Policy explains which personal data DeROSE eBooks processes, why it uses that data, with whom it may share the data, and how you can exercise your rights.
Last updated:
Data controller
The data controller is HARAPPA S.R.L., CUIT 30-71246285-6, with its registered address at República Árabe Siria 3088, Autonomous City of Buenos Aires, Argentina. We process data in accordance with Personal Data Protection Law No. 25,326 and other applicable regulations.
The only channel for privacy inquiries and exercising your rights is ebooks@derose.app.
Data we process
- Account and identity
- Email address, password hash, language, role, and account creation date. We do not store your password in plain text.
- Data received from Learn DeROSE
- When you choose to sign in or link your account through Learn, we receive your stable identifier, verified email address, avatar, and current status as a student in the DeRose Network.
- Reading preferences
- Theme, font size, PDF zoom, language, and other settings needed to maintain your experience.
- Reading activity
- Books and editions read, location and progress percentage, current section, reading time, and activity dates. This data may reveal philosophical, educational, well-being, or health interests, so we treat it as potentially sensitive information.
- Annotations
- Bookmarks, labels, highlights, selected excerpts, colors, and notes that you choose to save. Shared links are created only when you request to share a location.
- Access and billing
- Access permissions, coupons, purchases, subscriptions, amounts, currencies, statuses, and technical identifiers from Stripe or Mercado Pago.
- Technical and security data
- IP address, browser, device, dates, requested paths, request identifiers, errors, and signals needed to prevent abuse, diagnose failures, and maintain the service.
Where the data comes from
We obtain data directly from you, from your use of the platform, from Learn DeROSE when you authorize authentication, from payment providers when you complete a transaction, and, where applicable, from historical access records migrated from Publica.la. We receive your status as a student in the DeRose Network through Learn; DeROSE eBooks does not automatically import a complete PADMA profile.
How we use the data
- Create, authenticate, protect, and manage your account.
- Determine which books or catalogs you can open and preserve your progress, preferences, and annotations.
- Process purchases, subscriptions, coupons, cancellations, refunds, and payment reconciliation.
- Send access codes and operational communications related to your account or the service.
- Prevent fraud and abuse, investigate incidents, and comply with legal obligations.
- Measure performance, diagnose errors, and improve product security and reliability.
Cookies and storage on your device
We use essential cookies and session data to maintain authentication, remember your sign-in for one year, retain the language and currency, and preserve certain temporary purchase or coupon states.
If you enable offline reading, your browser stores content data, metadata, pending progress, and other resources needed for offline reading on your device.
We do not use marketing cookies or advertising services, and we do not sell personal data to advertisers.
Service providers and recipients
We share only the data necessary to provide, protect, and operate the service, comply with the law, or respond to a valid request. Our providers and related services are:
- Learn DeROSE and PADMA, for authentication and verification of your status as a student in the DeRose Network.
- Railway, for hosting, databases, and files.
- Amazon SES, for delivering operational emails.
- Stripe and Mercado Pago, for payments, subscriptions, refunds, and fraud prevention.
- Cloudflare Turnstile, to protect email and password registration against abusive automation.
- AppSignal, for error and performance monitoring. Request parameters and session content are not sent to AppSignal; browser telemetry is limited to the reading interfaces.
DeROSE eBooks does not receive or store the full card number, security code, or complete payment method credentials. Stripe or Mercado Pago processes that data on their hosted pages.
International transfers
Some providers may process or store data outside Argentina. We limit those transfers to what is necessary to provide the service and endeavor to use providers with appropriate contractual, technical, and organizational safeguards, in accordance with applicable regulations.
Retention and deletion
We retain account, progress, and reading data for as long as necessary to provide the service, unless a valid deletion request requires earlier deletion. We retain contractual, commercial, accounting, acceptance, request, and billing records for ten years, and longer only when required by a legal obligation, dispute, or fraud prevention. Temporary access codes expire and are deleted. In response to a valid request, we will delete or anonymize data that we are not required to retain.
Security
We apply technical and organizational controls designed to protect data against loss, unauthorized access, alteration, or disclosure. You must keep your device, email account, credentials, and session secure.
Changes to this Policy
We may update this Policy to reflect legal, operational, or technological changes. We will publish the current version and the date it was last updated. If a change is material, we will endeavor to provide notice through the platform or by email.
Contact
For questions about these documents or DeROSE eBooks, email us at ebooks@derose.app.
Responsible area: Customer Service.