This page collects the technical and organisational measures with which we protect your data and the data protection rule that governs in each of the four countries where we offer the service: Colombia, Costa Rica, Ecuador and the Dominican Republic. Each measure links the clause of the instrument that declares it, so you can check it instead of taking our word.
HTTPS Encryption
All data transmitted between your browser and our servers is encrypted using TLS/SSL, ensuring your information remains private and secure.
Secure Authentication
Password hashing with bcrypt and secure session management protect your account from unauthorized access.
Data Privacy
Your data belongs to you. We do not disclose your data to third parties for purposes of their own; the processors listed in Section 10 of the personal data processing policy handle it on our behalf, under our instructions and with the data processing agreement each one incorporates into its terms. That Section says, one by one, who they are and what each receives.
Role-Based Access Control
Granular permissions ensure that users only access the information they need. The firm owner and its lawyers each have appropriate access levels: a lawyer sees the matters they are assigned to or collaborate on.
AES-256-GCM Encryption
Sensitive data (personal information, case notes) is encrypted with AES-256-GCM before storage. Even in case of unauthorized database access, the information remains unreadable.
Ephemeral originals
Custodio processes uploaded originals ephemerally. It retains traceable matter knowledge, not the file, a cloud link, or a provider identifier.
Audit Records
The relevant actions on personal data are recorded with timestamp, responsible user and change details, and those records are not deleted: Section 11 of the personal data processing policy expressly leaves them out of erasure, because they are the proof that we comply.
Habeas Data Compliance
We process your data under the data protection legislation of each country where we offer the service: Ley 1581 de 2012 and Decreto 1377 de 2013 (Colombia), Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP (Costa Rica), the LOPDP and its Decreto Ejecutivo 904 (Ecuador) and Ley núm. 172-13 (Dominican Republic). What each one says for you is set out by your country's annex to our personal data processing policy. We implement the data processing principles: legality, purpose, freedom, accuracy, transparency, access, restricted circulation, security and confidentiality. For the data of the platform's users we are the data controller; for the data of a firm's clients that live in its matters, the firm is the controller and we are the processor, on the terms of the processing-on-behalf clause of the terms of service.
ARCO Rights
We handle the rights of access, rectification and cancellation of all data subjects, and that of opposition where the law of the country recognizes it —in Costa Rica it does not exist as a right of its own, and what stands in for it is revoking your consent, as the Costa Rican annex explains—. You can also download a structured, machine-readable copy of your account data. You can exercise them from 'My account > Your privacy' or by writing to our privacy team. The term within which we answer, and the reach of each right, are set by the law of the country where you live: Section 7 of our personal data processing policy says how they are exercised, and the annexes for Colombia, Costa Rica, Ecuador and the Dominican Republic each say how long we take to answer and under which article. This page does not repeat those figures, so that they do not age before the instrument that declares them.
Data Retention Policy
We retain your data only for as long as necessary to fulfill the processing purposes and legal obligations, under Section 11 of our personal data processing policy. After the service ends, data is deleted or anonymized within the following ninety (90) days, unless a legal obligation requires keeping it; the records of authorization, audit and data subject requests are kept as proof of compliance.
International Data Transfers
When we send data outside the country where you live we do so with the safeguard the law of that country recognizes, and only with it. Which destinations exist and what backs each sending is said, destination by destination, by Section 9 of our personal data processing policy; which safeguard each law recognizes — including which countries its authority has declared to have an adequate level of protection, where it has done so — is said by the annexes for Colombia, Costa Rica, Ecuador and the Dominican Republic. This page does not list them, because what is true today can stop being true with one resolution.
Security Incident Notification Protocol
In the event of a security breach affecting personal data that poses a real risk to the rights and freedoms of data subjects, Custodio Legal will notify:
- (1) The supervisory authority that applies, where your country's law designates one and imposes that notice on us.
- (2) Affected data subjects, without undue delay.
- (3) The controller firm, when the incident affects data of its matters, within the following two (2) business days, so it can meet its own notification obligations.
Which authority applies in each country, and within how many days we notify it and you, is declared by our personal data processing policy in the annexes for Colombia, Costa Rica, Ecuador and the Dominican Republic — where we also say when the term is set by law and when we set it ourselves. This page does not repeat those figures.
The notification will include: the nature of the incident, categories of data affected, likely consequences, measures taken or proposed, and contact details of the controller or the data protection officer. We keep a record of every security incident, including those that do not require notification.
Data Protection Officer (DPO)
Custodio Legal has appointed as data protection officer, under Articles 48 and 49 of Ecuador's LOPDP, Nicolás Rodríguez Lasso, the same person who appears as data controller in our personal data processing policy. In Colombia that same person heads the personal data protection area that Law 1581 of 2012 requires, and in the Dominican Republic he handles data subject queries and complaints, because Ley núm. 172-13 requires no equivalent figure. You can contact him at [email protected] or through the platform at 'My account > Your privacy'. Data subject requests are handled within the legal deadlines of each country, which that country's annex declares.