Privacy Policy

Last updated: February 24, 2026

Welcome to Koti - Smart Communities (“we,” “us,” or “our”). Koti - Smart Communities provides tools for administrators and residents of gated communities or apartment buildings to manage day-to-day operations, including QR code generation, package tracking, document management, community calendars, and related services (“Services”). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our mobile application (“App”) and website (“Site”). By accessing or using the App and Site, you agree to the terms of this Privacy Policy.

Data Controller: Build Up Diseño y Construcción S de RL de CV, Playa del Carmen, Mexico. Privacy contact: admin@koti.mx. This policy is governed by Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).

1. Information We Collect
Personal Information:
  • Contact Information: Name, email address, phone number, and other contact details
  • Account Credentials: Usernames and encrypted passwords
  • Community/Property Address: The address of the community or property you are associated with, entered during account setup for service configuration purposes
Usage Data:
  • Information about how you interact with our App, including pages visited, features used, time spent on pages, and logs of activities
  • Device information such as device type, operating system, and unique device identifiers
QR Code Data:
  • Information needed to generate and manage QR codes for visitor entries, package tracking, or other community services
Communication Data:
  • Messages, feedback, or inquiries that you send through the App or Site, including any attachments

We do not process sensitive personal data as defined under the LFPDPPP (such as racial or ethnic origin, health status, genetic information, religious beliefs, or sexual orientation).

2. How We Use Your Information

We use the information we collect for the following purposes:

Necessary Purposes:
  • Provide and maintain our Services, including account management and community operations
  • Facilitate communication between residents, administrators, and service providers
  • Generate and manage QR codes for access control, visitor entries, and package tracking
  • Send you notifications and updates about community events, packages, or other announcements
  • Respond to your inquiries, comments, or feedback
  • Comply with legal obligations and enforce our Terms of Service
Optional/Secondary Purposes:
  • Monitor and analyze usage patterns to develop new features and enhancements
  • Improve and personalize your experience within the App and Site

You may withdraw your consent for optional/secondary purposes at any time by contacting us at admin@koti.mx. Withdrawing consent for secondary purposes will not affect the availability of our core Services.

3. Data Sharing and Third-Party Processors

We do not sell your personal data.

We share personal data only with the following categories of service providers, strictly as necessary to operate our Services:

  • Stripe (United States) — Subscription billing for community administrators only. Resident personal data is never shared with Stripe. This constitutes an international data transfer.
  • Firebase Cloud Messaging (Google, United States) — Push notification delivery only.
  • SendGrid (United States) — Transactional email delivery.
  • Twilio (United States) — WhatsApp notification delivery.
  • Cloud Infrastructure Providers (United States/Mexico) — Hosting and data storage.
  • Analytics Services — Used on the marketing website only. See Section 9 for details.
  • Legal Compliance — We may disclose your information if required by law, court order, or regulatory requirement.
  • Business Transfers — In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
4. Data Retention

We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer need your information, we will securely delete or anonymize it.

5. Data Security

We implement appropriate technical and organizational security measures designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Children's Privacy

Our Services are not intended for individuals under the age of 13 (or other age as required by local law). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information without parental consent, we will take steps to remove such information and terminate the child's account if applicable.

7. Third-Party Services and Links

Our App or Site may contain links to third-party websites or services. We do not control and are not responsible for the content or privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you engage with.

8. Your ARCO Rights

Under Mexico's LFPDPPP, you have the following rights regarding your personal data (known as ARCO rights):

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Cancellation: Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
  • Opposition: Object to the processing of your personal data for specific purposes.
How to Exercise Your Rights
  • Send your ARCO request to admin@koti.mx, including your full name, a description of the data or rights you wish to exercise, and any documentation that helps us locate your information.
  • We will respond to your request within 20 business days. If your request is approved, we will implement the requested changes within 15 additional business days.
  • In-App Account Deletion: You may delete your account directly within the App, which will immediately remove all your associated personal data.
  • Consent Withdrawal: You may withdraw your consent for the processing of your personal data at any time by contacting admin@koti.mx. This will not affect the lawfulness of processing carried out prior to your withdrawal.
  • Right to File a Complaint: If you believe your data protection rights have been violated, you have the right to file a complaint with Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI).
9. Analytics and Tracking Tools

We use analytics tools to understand how users interact with our products. The scope and nature of these tools varies by product:

Marketing Website (koti.mx):
  • Google Analytics 4 — Tracks page views, user engagement, and advertising conversion events. May use cookies and link activity to Google accounts.
  • Meta Pixel — Links website visits to Facebook and Instagram accounts for advertising measurement. This tracking is not anonymous.
  • Hotjar — Records user sessions (mouse movements, clicks, scrolling) and generates heatmaps to improve site usability.
  • Mixpanel — Tracks page views, form interactions, and button clicks. IP address collection is enabled.
Mobile App:
  • Mixpanel — Configured with privacy-focused settings: uses anonymous identifiers not linked to personal information, and automatically strips personally identifiable information from events.
Administration Platform:
  • No external analytics tools are used in the production environment.

A cookie consent mechanism for the marketing website is currently being implemented. In the meantime, you can use your browser's privacy settings, ad blockers, or opt-out tools provided by the analytics vendors to limit tracking.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be effective when we post the revised policy on our Site or App, and we will indicate the “Last Updated” date at the top of this page.

11. Contact / Data Controller

If you have any questions or concerns about this Privacy Policy or our data practices, please contact the data controller:

  • Legal Entity: Build Up Diseño y Construcción S de RL de CV
  • Location: Playa del Carmen, Mexico
  • Email: admin@koti.mx
  • Website: koti.mx
  • Governing Law: Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)