This Privacy Policy explains what personal data Los Bebes Inc. ("Company," "we," "us," or "our") collects when you use Fiap Systems, why we collect it, who else processes it, and what you can ask us to do with it. It covers the fiapsystems.com website, the Fiap Systems web application at app.fiapsystems.com, the Fiap Systems mobile app for Android and iOS, and the Windows desktop editions.
It should be read together with our Terms of Service, which govern the commercial relationship. Where the two overlap on data handling, this Policy gives the detail.
Fiap Systems is business software sold to organizations. That means personal data reaches us in two very different ways, and your rights differ depending on which one applies to you.
When you visit our website, request a demo, or hold an account with us as a subscribing organization, we decide why and how your data is handled. This Policy governs that data directly.
When a subscribing organization (a shop, school, clinic, hotel, restaurant, or rental business) enters records about their students, patients, guests, customers, or employees into the platform, that organization is the Data Controller. We only process those records on their instructions, in order to run the service they bought.
If you are a student, parent, patient, guest, or employee of one of our clients, we are not the organization that decides what happens to your record. Direct access, correction, and deletion requests to that organization first. If you cannot identify or reach them, contact us at support@fiapsystems.com and we will route the request to the correct account holder.
The public website carries no analytics scripts, no advertising pixels, no third-party trackers, and no cookies. We do not profile visitors and we do not build advertising audiences.
The demo request form is deliberately serverless: the details you type (name, email, phone, company, country, staff and branch counts, the industries you are interested in, and your message) are assembled in your own browser and handed to WhatsApp when you press submit. Nothing is written to a database on our side by the act of filling in that form. The message reaches us the same way any WhatsApp message does, and is then handled by Meta Platforms under their own terms.
The site is served by Firebase Hosting (Google). Like any web host, it records standard request logs, which include your IP address, user agent, and the pages requested. We use these only for availability and abuse investigation.
What this contains depends entirely on the edition the organization runs and what its staff choose to enter. It can include sensitive categories:
| Edition | Typical records |
|---|---|
| Retail, bakery, restaurant | Customer names and contacts, orders, invoices, loyalty and layaway records |
| School | Student records including data about minors, guardian contacts, attendance, grades, discipline, fee balances |
| Hospital / clinic | Health data: patient demographics, visits, vitals, diagnoses, prescriptions, lab results, insurance claims |
| Hotel, car rental, event rental | Guest and renter identity, booking history, deposits, damage and incident reports |
| All editions | Employee HR and payroll records, attendance, leave, performance reviews, documents |
We do not mine Client Data for our own purposes, we do not sell it, and we do not use it to build products or profiles unrelated to serving that client.
The mobile app requests only what its features need, and only from the users who need them:
Where consent is the basis (for example, location sharing during a dispatch, or optional marketing email), you may withdraw it at any time without affecting anything processed before withdrawal.
The marketing website sets no cookies. The web application sets only what is strictly necessary to keep you signed in and to remember your language and active branch. We do not use advertising, retargeting, or cross-site tracking cookies anywhere in the product or on the site.
We share data only with the service providers needed to run the platform, and only to the extent required. We do not sell personal data, and we do not disclose it to third parties for their own commercial purposes.
| Processor | Purpose | When it applies |
|---|---|---|
| Cloud infrastructure and hosting providers | Running the application servers, database, and backups | All cloud plans |
| Firebase Hosting (Google) | Serving the public marketing website | Website visitors |
| MTN Mobile Money, Orange Money | Processing mobile-money payments and confirming their status | When a mobile-money payment is made |
| Your own SMTP / email provider | Sending notifications and documents from your account | When the organization configures email |
| WhatsApp Business (Meta Platforms) | Delivering messages you choose to send through WhatsApp, and receiving demo requests from the website form | When enabled, and for website demo requests |
| AI providers (Google Gemini, OpenAI, or Anthropic) | Answering AI-assistant prompts | Only when the optional AI assistant is enabled |
We may also disclose data where we are legally compelled to do so by a competent authority, or where disclosure is necessary to protect the rights, safety, or property of our users or the public. If we are ever required to hand over Client Data, we will inform the account holder unless the law forbids it.
If we are acquired or merged, Client Data may transfer to the successor entity, which would remain bound by this Policy or a successor policy no less protective. Account holders will be notified before any such transfer takes effect.
The AI assistant is an optional add-on, disabled by default. When an organization enables it and supplies a provider key:
Organizations handling health or student records should decide deliberately whether to enable this feature, since doing so means those records may leave our infrastructure.
Our cloud infrastructure and some processors listed above operate servers outside Cameroon. Using the cloud editions therefore involves transferring data across borders. We select providers that offer contractual and technical protections for the data they hold on our behalf. Organizations that need data to stay on their own premises should use the Offline Standalone edition, which runs entirely on the customer's own computer with a local database and no cloud component.
Measures currently implemented in the platform include:
No system can be guaranteed completely secure, and we make no such claim. If we become aware of a confirmed breach that materially affects an organization's data, we will notify that organization without undue delay, with what we know about scope and remediation.
Subject to applicable law, and to the controller/processor distinction in Section 1, you may ask us to:
Write to support@fiapsystems.com (or legal@fiapsystems.com for formal notices). We will respond within thirty (30) days. We may need to verify your identity first, and for Client Data we will refer the request to the organization that controls the record.
To delete your Fiap Systems account and the data associated with it, email support@fiapsystems.com from the address registered to the account, with the subject line "Account Deletion Request", or ask your organization's account owner to raise the request.
Deleting the mobile app from your device removes locally stored credentials and cached data from that device, but does not delete your account on the server.
Fiap Systems is business software and is not directed at children. Nobody under 18 can open an account with us directly. The school edition necessarily holds records about minors; in that case the school is the Data Controller and is responsible for the legal basis, including any parental consent required. We process those records only on the school's instructions and apply the same protections described in Section 9.
We may update this Policy as the product or the law changes. The "Last Updated" date at the top always reflects the current version. For changes that materially affect how personal data is handled, we will notify account holders by email or by an in-app notice before the change takes effect. Continuing to use the Services after that date means you accept the updated Policy.
This Policy is governed by the laws of the Republic of Cameroon, including Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality. Disputes fall under the jurisdiction of the competent courts of Bamenda, Northwest Region, Cameroon.
Privacy and data protection enquiries: support@fiapsystems.com
Formal legal notices: legal@fiapsystems.com
Postal: Los Bebes Inc., Bamenda, Northwest Region, Cameroon