1. Who is responsible
Draf IT Services, with offices at Carrera 16 #76-55, Bogotá, Colombia, is the data controller for the information described in this policy. You can reach us at hello@drafit.net for anything related to your personal data.
Products
Shelli Full ERP and point of sale for stores, supermarkets and restaurants.Shelli Cloud Your point of sale in the cloud, with nothing to install.Shelli Menu Your menu as a PDF, at a link that never changes.Solutions
Custom development Software designed around your operation, not the other way round.Technology talent The right engineers, working inside your team.Choose language
This policy explains what we do with personal data on the drafit.net website and in our services. It is written to be read, not to be survived.
The short version: this website collects almost nothing, we do not track you across the internet, we do not sell anything to anybody, and the data inside your own installation of our software never reaches us.
Draf IT Services, with offices at Carrera 16 #76-55, Bogotá, Colombia, is the data controller for the information described in this policy. You can reach us at hello@drafit.net for anything related to your personal data.
If you write to us through the contact form, we receive what you type: name, company, email, optional phone, country, the topic you selected and your message. We also record the language you were browsing in and the page you sent it from, so we can reply appropriately.
Our servers keep standard technical logs — IP address, browser, time of request — for security and troubleshooting. There are no advertising trackers, analytics profiles or third-party marketing pixels on this site.
We use two things, both strictly functional and both stored on your own device:
A cookie that remembers the language you chose, so the site does not reset to English on every visit. A local storage entry that remembers whether you prefer the light or dark theme.
That is the complete list. No advertising cookies, no cross-site tracking, no consent banner needed because there is nothing to consent to.
To answer your message and follow up on it, to prepare a proposal you asked for, to run and secure the website, and to comply with legal obligations.
We will not add you to a marketing list because you wrote to us with a question. If we ever want to send you commercial communications, we will ask first.
This is the important distinction. When you run our software on your own equipment or servers, the data in it — your sales, your customers, your employees — stays there. We do not receive it, we cannot see it, and we have no copy of it. You are the controller of that data and responsible for it, as set out in our terms of service.
Where we host a service for you, we act as a processor on your instructions, under the contract signed with you. In that case we encrypt sensitive data in transit and at rest, and we access it only to operate the service, resolve an incident you reported, or comply with a legal order.
We do not sell, rent or trade personal data. We share it only with service providers who make our own operation possible — hosting, email delivery, and similar — bound by confidentiality and processing only what they need, and with authorities when a valid legal order requires it.
Some of these providers may be located outside Colombia. Where that happens we require contractual guarantees of an adequate level of protection.
Contact enquiries are kept while the conversation is active and for a reasonable period afterwards in case you come back, and then deleted. Data related to a contract is kept for as long as commercial and tax law requires. Technical logs are kept for a short period for security purposes.
Under Colombian Law 1581 of 2012 and its regulations, you may ask us to confirm what data we hold about you, to correct it, to update it, to delete it, and to revoke any authorisation you gave us. You may also complain to the Superintendencia de Industria y Comercio.
Write to hello@drafit.net and we will respond within the legal timeframe. We may ask you to confirm your identity before acting on a request.
We encrypt sensitive data in transit and at rest on the systems we host, limit access to the people who need it, and keep our infrastructure patched. No system is completely secure, and we do not claim otherwise; if a breach ever affects your personal data, we will notify you and the authorities as the law requires.
If this policy changes, the updated version appears on this page with a new date. For changes that materially affect how we handle your data, we will make the change visible rather than quiet.