Fiap Systems
All industries Pricing Docs FR Get started
Legal

Privacy Policy

Effective Date: August 25, 2026
Last Updated: August 25, 2026
Company: Los Bebes Inc. (Operating as Fiap Systems)
Jurisdiction: Bamenda, Northwest Region, Republic of Cameroon

This Privacy Policy explains what personal data Los Bebes Inc. ("Company," "we," "us," or "our") collects when you use Fiap Systems, why we collect it, who else processes it, and what you can ask us to do with it. It covers the fiapsystems.com website, the Fiap Systems web application at app.fiapsystems.com, the Fiap Systems mobile app for Android and iOS, and the Windows desktop editions.

It should be read together with our Terms of Service, which govern the commercial relationship. Where the two overlap on data handling, this Policy gives the detail.

1. The Two Roles We Play

Fiap Systems is business software sold to organizations. That means personal data reaches us in two very different ways, and your rights differ depending on which one applies to you.

1.1 We are the Data Controller for our own users

When you visit our website, request a demo, or hold an account with us as a subscribing organization, we decide why and how your data is handled. This Policy governs that data directly.

1.2 We are a Data Processor for Client Data

When a subscribing organization (a shop, school, clinic, hotel, restaurant, or rental business) enters records about their students, patients, guests, customers, or employees into the platform, that organization is the Data Controller. We only process those records on their instructions, in order to run the service they bought.

If you are a student, parent, patient, guest, or employee of one of our clients, we are not the organization that decides what happens to your record. Direct access, correction, and deletion requests to that organization first. If you cannot identify or reach them, contact us at support@fiapsystems.com and we will route the request to the correct account holder.

2. What We Collect

2.1 On the marketing website (fiapsystems.com)

The public website carries no analytics scripts, no advertising pixels, no third-party trackers, and no cookies. We do not profile visitors and we do not build advertising audiences.

The demo request form is deliberately serverless: the details you type (name, email, phone, company, country, staff and branch counts, the industries you are interested in, and your message) are assembled in your own browser and handed to WhatsApp when you press submit. Nothing is written to a database on our side by the act of filling in that form. The message reaches us the same way any WhatsApp message does, and is then handled by Meta Platforms under their own terms.

The site is served by Firebase Hosting (Google). Like any web host, it records standard request logs, which include your IP address, user agent, and the pages requested. We use these only for availability and abuse investigation.

2.2 Account and organization data

  • Identity and contact: name, email address, phone number, job role, and the organization you belong to.
  • Credentials: passwords are stored only as salted one-way hashes; we never store or display them in readable form. Session and refresh tokens are stored hashed.
  • Billing and subscription: plan, edition, branch and user counts, invoice history, and payment references. Card numbers are never entered into or stored by Fiap Systems.

2.3 Client Data entered into the platform

What this contains depends entirely on the edition the organization runs and what its staff choose to enter. It can include sensitive categories:

EditionTypical records
Retail, bakery, restaurantCustomer names and contacts, orders, invoices, loyalty and layaway records
SchoolStudent records including data about minors, guardian contacts, attendance, grades, discipline, fee balances
Hospital / clinicHealth data: patient demographics, visits, vitals, diagnoses, prescriptions, lab results, insurance claims
Hotel, car rental, event rentalGuest and renter identity, booking history, deposits, damage and incident reports
All editionsEmployee HR and payroll records, attendance, leave, performance reviews, documents

We do not mine Client Data for our own purposes, we do not sell it, and we do not use it to build products or profiles unrelated to serving that client.

2.4 Technical and security data

  • Audit trail: the platform records who performed which action, on what record, and when, together with the originating IP address. This is a deliberate security control and cannot be switched off by users; it is what lets an organization investigate misuse of its own account.
  • Operational logs: error and performance logs. These are written to identify records by ID rather than by content.
  • Session data: device type, browser or app version, and the branch context you are working in.

2.5 Mobile app specifics

The mobile app requests only what its features need, and only from the users who need them:

  • Location (precise and approximate), requested only in the emergency dispatch feature and only from responding crew. It is shared while a responder is attending an incident so that dispatch and the patient can see the ambulance approaching. It is not collected in the background, not collected from other users, and not used for advertising or analytics.
  • Photos and files, only at the moment you attach one to a record.
  • Credentials and session tokens, stored in the operating system's secure storage (Keystore / Keychain), not in plain preferences.
  • No advertising identifier is collected and no advertising or tracking SDK is bundled in the app.

3. Why We Use It

  • To provide the service you or your organization subscribed to, including the specific modules enabled for your edition.
  • To authenticate you and enforce role-based permissions, so each user sees only what their role allows.
  • To secure the platform: detect suspicious activity, investigate incidents, and maintain the audit trail.
  • To bill and support: process subscriptions, respond to your support requests, and send service notices such as maintenance or security announcements.
  • To meet legal obligations and to establish, exercise, or defend legal claims.

Where consent is the basis (for example, location sharing during a dispatch, or optional marketing email), you may withdraw it at any time without affecting anything processed before withdrawal.

4. Cookies and Similar Technologies

The marketing website sets no cookies. The web application sets only what is strictly necessary to keep you signed in and to remember your language and active branch. We do not use advertising, retargeting, or cross-site tracking cookies anywhere in the product or on the site.

5. Who Else Processes Your Data

We share data only with the service providers needed to run the platform, and only to the extent required. We do not sell personal data, and we do not disclose it to third parties for their own commercial purposes.

ProcessorPurposeWhen it applies
Cloud infrastructure and hosting providersRunning the application servers, database, and backupsAll cloud plans
Firebase Hosting (Google)Serving the public marketing websiteWebsite visitors
MTN Mobile Money, Orange MoneyProcessing mobile-money payments and confirming their statusWhen a mobile-money payment is made
Your own SMTP / email providerSending notifications and documents from your accountWhen the organization configures email
WhatsApp Business (Meta Platforms)Delivering messages you choose to send through WhatsApp, and receiving demo requests from the website formWhen enabled, and for website demo requests
AI providers (Google Gemini, OpenAI, or Anthropic)Answering AI-assistant promptsOnly when the optional AI assistant is enabled

We may also disclose data where we are legally compelled to do so by a competent authority, or where disclosure is necessary to protect the rights, safety, or property of our users or the public. If we are ever required to hand over Client Data, we will inform the account holder unless the law forbids it.

If we are acquired or merged, Client Data may transfer to the successor entity, which would remain bound by this Policy or a successor policy no less protective. Account holders will be notified before any such transfer takes effect.

6. The AI Assistant

The AI assistant is an optional add-on, disabled by default. When an organization enables it and supplies a provider key:

  • The prompt, and whatever business data is needed to answer it, is transmitted to the AI provider that the organization selected, and is processed under that provider's API terms.
  • The assistant operates inside the same role-based permissions as the user asking. It cannot read what that user could not read.
  • Actions the assistant takes are written to the audit trail like any other action, and actions that change data pass through an approval step.
  • Disabling the assistant stops all transmission to the AI provider immediately.

Organizations handling health or student records should decide deliberately whether to enable this feature, since doing so means those records may leave our infrastructure.

7. International Transfers

Our cloud infrastructure and some processors listed above operate servers outside Cameroon. Using the cloud editions therefore involves transferring data across borders. We select providers that offer contractual and technical protections for the data they hold on our behalf. Organizations that need data to stay on their own premises should use the Offline Standalone edition, which runs entirely on the customer's own computer with a local database and no cloud component.

8. How Long We Keep It

  • Client Data is retained for as long as the account is active. On suspension for non-payment the account becomes read-only for seven (7) days, then fully suspended. If an account stays suspended or cancelled for thirty (30) days, we may permanently delete all associated Client Data. Export your data before cancelling.
  • Audit logs are retained beyond that where needed for security and legal defence.
  • Billing records are kept for the period required by applicable tax and accounting law.
  • Backups roll off on their own schedule, so deleted data may persist in encrypted backups for a limited period after deletion from the live system.

9. Security Measures

Measures currently implemented in the platform include:

  • Encryption in transit (TLS 1.2+) for all cloud traffic.
  • Passwords stored only as salted one-way hashes; refresh tokens stored hashed with reuse detection.
  • Stored third-party credentials (payment gateway, SMTP, messaging keys) encrypted at rest with AES-256-GCM.
  • Strict tenant isolation, so one organization's records are not reachable from another organization's session.
  • Role-based access control across every module, with the narrowest scope applied per route.
  • A full audit trail of actions taken in the account.
  • Secure OS-level credential storage in the mobile app.

No system can be guaranteed completely secure, and we make no such claim. If we become aware of a confirmed breach that materially affects an organization's data, we will notify that organization without undue delay, with what we know about scope and remediation.

10. Your Rights

Subject to applicable law, and to the controller/processor distinction in Section 1, you may ask us to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your data, where we are not required to keep it.
  • Export your data in a portable format.
  • Object to or restrict certain processing, and withdraw consent where consent was the basis.

Write to support@fiapsystems.com (or legal@fiapsystems.com for formal notices). We will respond within thirty (30) days. We may need to verify your identity first, and for Client Data we will refer the request to the organization that controls the record.

11. Account and Data Deletion

To delete your Fiap Systems account and the data associated with it, email support@fiapsystems.com from the address registered to the account, with the subject line "Account Deletion Request", or ask your organization's account owner to raise the request.

  • What is deleted: your user profile, contact details, credentials, session tokens, and, where the request comes from the account owner, the organization's Client Data.
  • What is retained, and why: audit log entries and billing records, kept for the period required for security and by tax and accounting law.
  • Timeline: the account is deactivated on receipt; deletion from live systems completes within thirty (30) days; encrypted backups roll off within a further ninety (90) days.
  • Deletion is irreversible. Export anything you need first.

Deleting the mobile app from your device removes locally stored credentials and cached data from that device, but does not delete your account on the server.

12. Children's Data

Fiap Systems is business software and is not directed at children. Nobody under 18 can open an account with us directly. The school edition necessarily holds records about minors; in that case the school is the Data Controller and is responsible for the legal basis, including any parental consent required. We process those records only on the school's instructions and apply the same protections described in Section 9.

13. Changes to This Policy

We may update this Policy as the product or the law changes. The "Last Updated" date at the top always reflects the current version. For changes that materially affect how personal data is handled, we will notify account holders by email or by an in-app notice before the change takes effect. Continuing to use the Services after that date means you accept the updated Policy.

14. Contact and Governing Law

This Policy is governed by the laws of the Republic of Cameroon, including Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality. Disputes fall under the jurisdiction of the competent courts of Bamenda, Northwest Region, Cameroon.

Privacy and data protection enquiries: support@fiapsystems.com
Formal legal notices: legal@fiapsystems.com
Postal: Los Bebes Inc., Bamenda, Northwest Region, Cameroon

Fiap Systems

All-in-one business management software for retail, schools, hospitals, restaurants, bakeries, hotels, car rentals and event businesses. 100+ modules, priced in your local currency.

Product

  • Industries
  • Features
  • Mobile app
  • Deployment
  • Pricing
  • Terms of service
  • Privacy policy

Ecosystem

  • FiapPay
  • Los Bebes Inc.

Contact

  • sales@fiapsystems.com
  • support@fiapsystems.com

© 2026 Fiap Systems. All rights reserved.

A product of Los Bebes Inc.