Skip to content
Client access

Privacy Policy

Last updated: September 28, 2026

At Kamaya Secure S.A.C. (“Kamaya Secure”, “we”, “us”) protecting information is at the core of our work. This Privacy Policy explains clearly and transparently what personal data we process, for what purpose, on what legal basis, for how long, and what rights you have as the data subject, in accordance with Law No. 29733, the Peruvian Personal Data Protection Law, its Regulation approved by Supreme Decree No. 016-2024-JUS, and other applicable Peruvian regulations.

We process your data under the principles of legality, consent, purpose, proportionality, quality, security, availability of recourse, and adequate level of protection.

1. Data controller

  • Owner of the data bank: Kamaya Secure S.A.C.
  • Address: Prolongación Los Gladiolos 121, Lima, Peru.
  • Privacy contact: privacidad@kamayasecure.com
  • Website: kamayasecure.com

Kamaya Secure is responsible for the personal data banks it manages in the course of its commercial activities and the provision of cybersecurity services, which are (or will be) registered with the National Authority for Personal Data Protection (ANPD).

2. Data we collect

Depending on your relationship with us, we may process the following categories of data:

  • Identification data: name, surname, job title, and the company or organization you represent.
  • Contact data: email address and phone number.
  • Browsing data: IP address, browser type and version, operating system, pages visited, and date/time of access, collected via cookies and similar technologies (see section 9).
  • Data arising from cybersecurity services, where a contract or engagement exists with your organization:
    • Access credentials that your organization provides to run penetration tests, on a strictly temporary basis.
    • Technical documentation of the infrastructure within the authorized scope.
    • Vulnerability findings and test evidence (screenshots, logs, tool output).

This technical data may incidentally contain personal data of third parties (for example, user accounts within your organization). Your organization acts as the controller of such data, and Kamaya Secure processes it solely on your behalf, under confidentiality and only within the scope authorized in writing.

We do not request or process sensitive data (health, ethnic origin, beliefs, biometric data used for identification, etc.) unless strictly necessary, with your explicit consent and the reinforced safeguards required by law.

3. Purpose of processing

We process your personal data to:

  1. Respond to inquiries, quotes, and requests for information.
  2. Manage the contractual relationship and provide our cybersecurity services.
  3. Run penetration tests and continuous monitoring strictly within the scope authorized by your organization.
  4. Send you communications about services, events, and relevant content, where you have consented in advance.
  5. Comply with legal, contractual, and regulatory obligations.
  6. Improve our services through internal and statistical analysis.

We do not use your data for purposes other than those described without informing you and, where applicable, obtaining your consent.

4. Legal basis for processing

  • Your consent, given freely, in advance, informed, express, and unambiguous (for example, for commercial communications or non-essential cookies).
  • Performance of a contract or pre-contractual measures at your request (provision of services).
  • Compliance with legal obligations applicable to Kamaya Secure.
  • Other grounds set out in Law No. 29733 and its Regulation that permit processing without consent in specific cases.

You may withdraw your consent at any time, without retroactive effect, as described in section 8.

5. Retention period

  • Contact and business-relationship data: for the duration of the relationship and then for up to 5 years.
  • Access credentials for pentesting: destroyed immediately upon completion of the engagement.
  • Findings and test evidence: destroyed within 30 days after the engagement ends, unless a written extended-retention agreement is in place.
  • Final reports: kept for 12 months for reference, unless otherwise agreed.
  • Browsing data (cookies): according to each cookie’s lifetime and your settings (see section 9).

Once the periods elapse, data is securely deleted or anonymized.

6. Data transfers

  • Legal obligations or requirements from competent authorities.
  • Service providers (for example, technology infrastructure or email) acting as data processors under contract and confidentiality and security obligations equivalent to those in this policy.
  • Cross-border data flows: if we use cloud services located outside Peru, we adopt the safeguards required by Peruvian law to ensure an adequate level of protection.

We never sell or assign your personal data for purposes other than those described.

7. Data security

  • General technical measures: encryption in transit and at rest, role-based access control, multi-factor authentication, and audit logs.
  • Specific measures for pentesting data: isolated storage per engagement, access restricted to the assigned team only, and an audit log of all access and actions on that information.
  • Incident management: in the event of a breach affecting personal data, we activate our response procedure and, where required by law, notify affected data subjects and the National Authority for Personal Data Protection within the legal deadline (under the current Regulation, within 48 hours of becoming aware).

8. Your rights

  • Access your data and information about its processing.
  • Rectify inaccurate or outdated data.
  • Cancel (delete) your data where applicable.
  • Object to processing on justified grounds.
  • Data portability, as recognized by Supreme Decree No. 016-2024-JUS.
  • Withdraw the consent given.

How to exercise them: send your request to privacidad@kamayasecure.com with your full name, identity document number, the right you wish to exercise, and a means of contact. We may ask you to verify your identity. We will respond within the period set by law (for reference, within 10 business days, extendable in the cases provided by law). If you believe your rights have not been addressed, you may contact the National Authority for Personal Data Protection.

9. Cookies and tracking technologies

  • Essential cookies: required for the site to function (no consent needed).
  • Analytics cookies: help us measure and improve site performance; used with your consent.

You can accept or manage your preferences from our consent banner and, at any time, from your browser settings.

10. Contact

  • Email: privacidad@kamayasecure.com
  • Address: Prolongación Los Gladiolos 121, Lima, Peru.

11. Changes

Kamaya Secure may update this Privacy Policy to reflect regulatory or operational changes. We will publish the current version on this page, indicating the last-updated date. Continued use of the site or our services after a change implies your awareness of the current version.

Chat on WhatsApp (opens in a new tab)