Privacy Policy, Harpy Agent Portal
Last updated: 27 July 2026
This Privacy Policy explains how Harpy Enterprise Inc. ("Harpy Enterprise", "we", "us", "our") processes personal data in the Harpy Agent Portal at portal.harpy-enterprise.com (the "Portal"), the secure area used by our independent sales agents and by the representatives of the companies we work with ("Principals"). Our public marketing website has its own separate privacy policy.
This policy is available in English, Spanish, German, Portuguese, and French. The English version is the authoritative one; the translations are provided for your convenience.
We process personal data in line with the EU General Data Protection Regulation (GDPR), the Panamanian Personal Data Protection Law (Law No. 81 of 2019), the Brazilian General Data Protection Law (LGPD), and other applicable data protection laws.
1. Who is responsible for your data
The controller is Harpy Enterprise Inc. (lawfully registered as H3 Grob Aircraft Latin America Corporation), a company incorporated under the laws of the Republic of Panama, represented by its CEO Leonardo Schulze Wierling.
- Registered office: Edificio El Colegio, Local 1, Calle José Obaldía, entre calle 8va y 9na Oeste, San Felipe, Panama City, Panama
- Tax/registration number (RUC): 155738741-2-2023 DV 14
- Email: info@harpy-enterprise.com
- Phone: +507 6310 5888
We have not appointed a Data Protection Officer, as we are not legally required to do so. For any data-protection request, contact us at info@harpy-enterprise.com.
2. Who this policy applies to
The Portal is not open to the general public. It is used by:
- Agents, independent representatives who have accepted an invitation and signed an agreement with us.
- Principal representatives, contacts at the companies whose products and services our agents represent.
3. What data we process
- Identity and contact data: name, email address, phone number, postal address, and, where required for an agreement, date of birth and nationality.
- Company data (where you act for a company): company name, country of incorporation, registered address, registration number, and the name and title of the company's representative.
- Account and authentication data: your sign-in is handled by our authentication provider via a magic e-mail link or a password. We never store your password in a readable form.
- Content you provide: documents and files you upload, company profile information, and the commercial opportunities ("Leads") you register.
- Electronic-signature data: information related to the agreements you sign through our e-signature provider.
- Technical and security data: IP address, browser/device information, sign-in and sign-out timestamps, a periodically updated last-active timestamp (used to show our team whether a user is currently online), failed-login and account-lock information, and an audit log of administrative actions (which records the acting user, the action, a timestamp, IP address, and browser identifier).
4. Why we process it, and our legal bases
- To provide the Portal and perform our agreement with you, managing your account, onboarding, document signing, and lead registration. Legal basis: Article 6(1)(b) GDPR (performance of a contract / pre-contractual steps).
- To keep the Portal secure and to run it day to day, authentication, session management, abuse and fraud prevention, audit logging, and the last-active indicator that tells our team whether a colleague or contact is currently working in the Portal. Legal basis: Article 6(1)(f) GDPR (our legitimate interest in a secure, well-run service).
- To comply with legal obligations, for example, retaining signed agreements. Legal basis: Article 6(1)(c) GDPR.
- With your consent, where we specifically ask for it. Legal basis: Article 6(1)(a) GDPR.
We use artificial-intelligence text processing to support our own work, for example to draft and translate text, to sort incoming business correspondence, and to help our team prioritise its commercial follow-up. These results are prepared for our own team, they are reviewed by a person before they are acted on, and they do not produce legal or similarly significant effects for you within the meaning of Article 22 GDPR.
We do not use advertising or analytics tracking in the Portal, and we do not sell your personal data.
5. Cookies and sessions
The Portal uses only strictly necessary cookies and browser storage:
- a session cookie that enforces a maximum session length (you are signed out automatically after 24 hours);
- authentication cookies set by our authentication provider;
- a short-lived technical cookie (about two minutes) that limits how often the last-active timestamp described in section 3 is refreshed;
- a cookie holding your chosen display theme, and your chosen interface language stored in your browser's local storage.
These are required for the Portal to function and do not require consent. There are no advertising or analytics cookies.
6. Who we share data with
We share personal data only with service providers ("processors") that operate the Portal on our behalf, under contracts that require them to protect your data. By category, these are:
- a cloud hosting, database, and authentication provider;
- a workplace email and productivity provider, through which we send and receive business email from our own company mailboxes;
- an electronic-signature provider;
- a transactional email provider (sign-in links and notifications);
- an internal team-messaging / notification provider, used for our own operational alerts (personal email addresses are abbreviated before they are sent, so the full address is not included);
- a customer-relationship-management (CRM) provider, used to manage the business relationship;
- an artificial-intelligence text-processing provider, used inside the Portal to help draft, translate, and classify text (for example, draft outreach emails and profile text). Our requests are configured so that the content we send is not used to train that provider's models. The provider may hold the content briefly under its own standard operating and abuse-prevention practices. The output is always reviewed by a person before it is used, and we do not use it for automated decisions that produce legal or similarly significant effects (see section 4);
- a text-embedding provider, used for search inside the Portal. Short excerpts of stored text are sent to be converted into a numerical representation, so that related material can be found again. Only the excerpt needed for that calculation is sent, and it is processed under that provider's standard business terms;
- an AI-observability provider, hosted in the European Union, used to monitor and troubleshoot that text-processing. The records it holds can include the text sent for processing and the resulting output, and they are kept only for as long as they are useful for that purpose; and
- a source-code and internal knowledge-base hosting provider, where we hold our application code and an internal knowledge base.
We may also disclose data where required by law or to establish, exercise, or defend legal claims. We do not share your data for third-party advertising.
7. International data transfers
We are based in Panama, and several of our processors, including the artificial-intelligence, hosting, and email providers described above, are located in or transfer data to the United States; others are located in the EU. Your personal data may therefore be processed outside your country, including outside the EU/EEA.
Where we transfer personal data of EU/EEA users to a country that does not benefit from a European Commission adequacy decision (such as the United States, absent an applicable framework), we rely on appropriate safeguards under Chapter V GDPR: the European Commission's Standard Contractual Clauses under Article 46 GDPR, and/or the EU-US Data Privacy Framework where the recipient is certified, together with additional technical and organisational measures. You can request a copy of the safeguards we rely on for these transfers using the contact details above.
8. How long we keep your data
- Account and profile data: for the duration of your relationship with us. When an account is closed, the record is kept for a 30-day recovery window and is then deleted, together with the files and images stored with it.
- Signed agreements and related records: for as long as required by law and to defend legal claims.
- Audit log of administrative actions: the entry is pseudonymised after 12 months (the IP address and browser identifier are removed, and any email address in the entry is masked) and deleted in full after 24 months.
- Technical logs held by our hosting and email providers: for the short period those providers apply as standard, after which they expire automatically.
Where the same information has also been recorded in one of the systems described in section 6 (for example our CRM, our internal messaging, or our email mailboxes), we remove it there as well when we act on a deletion request. Copies may remain for a short time in routine backups, and in the technical logs described above, until those expire in the normal course.
9. Your rights
Depending on where you live, you have the right to access your data; to correct it; to erase or cancel it; to restrict or object to processing; to data portability; and to withdraw consent at any time (without affecting processing already carried out). These rights apply under the EU GDPR, Panama's Law No. 81 of 2019, Brazil's LGPD, and other applicable laws.
To exercise any right, contact us at info@harpy-enterprise.com. We will respond within the period required by applicable law. You may also lodge a complaint with a supervisory authority, in the EU/EEA, your local data protection authority; in Panama, the National Authority for Transparency and Access to Information (ANTAI); in Brazil, the National Data Protection Authority (ANPD).
10. How we protect your data
We use appropriate technical and organisational measures, including encryption in transit (HTTPS/TLS), role-based access controls and row-level security on our database, least-privilege access, automatic session expiry, account-lockout on suspicious activity, and audit logging of administrative actions.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date. Where required by law, we will notify you of material changes.
12. Contact
Harpy Enterprise Inc. Edificio El Colegio, Local 1, Calle José Obaldía, San Felipe, Panama City, Panama Email: info@harpy-enterprise.com