Custodio Legal respects the personal data and information provided by its current, past, and potential clients. This Personal Data Protection Policy establishes the purposes, measures, and procedures for our databases, as well as the mechanisms available to data holders to know, update, rectify, delete provided data, or revoke the authorization granted with the acceptance of this policy, in accordance with Ley Estatutaria 1581 de 2012, Colombia's data protection statute, and Decreto 1377 de 2013, with Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP) and its Decreto Ejecutivo 904, with the Dominican Republic's Ley núm. 172-13, with Costa Rica's Ley N° 8968, on the protection of the person with regard to the processing of their personal data, and its Reglamento (Decreto Ejecutivo N° 37554-JP), and with Uruguay's Ley N° 18.331, on personal data protection and the «Habeas Data» action, as amended by Ley N° 19.670, and with Argentina's Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001, and with Brazil's Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais (LGPD), the seven countries in which we offer the service. The rules are named as their own official gazettes publish them, in Spanish, so you can check each one against the source; the gloss that follows a name the first time it appears says what it is.

## 1. Data Controller and Data Processor {#section1}

Custodio Legal, identified with NIT 1057602936, with domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia, provides the service. You can contact us at support@custodio.legal or by phone at +57 333 431 8597; the area that handles queries and claims is the Personal Data Protection Area, at that same email address.

This policy distinguishes two situations, because the law gives you a different counterpart in each one:

- (i) When you use the platform -you sign up, belong to a firm, work in it-, Custodio Legal is the **controller** of your personal data: it decides what it is processed for and answers to you for it.
- (ii) When your personal data appears in a matter a firm manages through the platform -as a client, opposing party or interested party in a proceeding-, the **controller is that firm**, which decided to process it and must have obtained the authorization the law requires, and Custodio Legal acts as **processor**: it processes that data on the firm's behalf, under the service contract and its instructions, and does not decide on it on its own. If you write to us to exercise a right over data held in a matter, we forward your request to the responsible firm within the following two business days, tell you we did, and give you its contact details so you can approach it directly.

Collected data will be processed legally, lawfully, confidentially, and securely, respecting the principles of purpose, freedom, truthfulness, transparency, restricted access, security, and confidentiality.

## 2. Purpose of Processing {#section2}

The processing of personal data has the following purposes:

- a) Provision of contracted legal and administrative management services.
- b) Managing the contractual relationship with clients, lawyers, and collaborators.
- c) Sending service-related communications, updates, and legal notifications.
- d) Billing, collection, and accounting management.
- e) Conducting satisfaction surveys and service improvement.
- f) Compliance with legal obligations and requirements from competent authorities.
- g) Fraud prevention and platform security.
- h) Answering the one-off lookup of a public court record asked for by a person **with no account**, in the countries where the Service offers that lookup.

The emails we send you are of two kinds, and what separates them is what each one rests on:

- **Service emails.** They tell you the state of your own account —that your email address is unconfirmed, that you have not created your first matter yet, that a matter of yours has no active judicial surveillance— and they teach you to use what you contracted, including what the Artificial Intelligence described in Section 14 does and does not do. They rest on the contractual relationship and on purposes a), b), c) and e) of this section, and they do not depend on any advertising authorization. They are the ones that set your account up: the first remind you to confirm your address, in the hours after you register, and the rest go out over the fifteen (15) days following that confirmation. Each one of them carries its unsubscribe link.
- **Promotional emails.** They offer you a higher plan, a discount or a feature you did not contract, or tell you about product news. They are advertising and go out only if you ticked the optional box of Section 4.

No service email offers you a plan, a discount or a feature you have not contracted: the moment a message did, it would be promotional and would ask for that box.

**Looking up a court record with no account.** This policy describes that lookup **before** the site turns it on, and that is on purpose: we would rather tell you what we will do with your data before we process it than afterwards. When the lookup is available —it starts with Uruguay and Costa Rica, and each country offers it only if that country's annex says so— this is how it works:

- **What we process.** The case number you type, the country you pick, and your IP address. The IP address is used **only** to limit how many lookups come from one place; not to identify you, not to recognize you if you come back, and not to build a profile of you.
- **An anti-abuse check before we look anything up.** So that an automated program cannot drain this free lookup, before asking the portal we check that the person looking up is a person. That check is run by **Cloudflare**, which is already the network all of this site's traffic passes through and appears in our [list of subprocessors](/subprocessors). To run it, your browser talks directly to Cloudflare, which processes — according to what Cloudflare publishes in its Turnstile privacy policy, consulted on September 19, 2026 — your IP address, the technical fingerprint of your encrypted connection, the identification of your browser and this site's public key; Cloudflare states that it **cannot directly identify an individual** from those signals. We get exactly one thing back: whether the check passed. **We do not send Cloudflare the number you looked up**, nor any other datum of the lookup. That check **writes no cookie**, according to what Cloudflare publishes and the configuration we have it enabled with; we have not verified whether it uses any other browser storage, and so we do not claim that it does not.
- **What we do not ask you for.** Not your name, not your email, not your ID document, not an account. The lookup is **by case number and never by a person's name**: there is no way to ask this site who has cases. Nor do we write any new cookie for this lookup; the cookies the site uses are the ones declared in the [Cookie Policy](/cookies), and none of them stores what you looked up.
- **On what legal ground.** [Your country's annex](#annex) states it: it is that country's rule that allows —and on what condition— processing without your consent a datum a judiciary already publishes. This lookup is not offered in a country whose annex does not sustain it.
- **What we keep, and for how long.** The lookup is written into an ephemeral row that lives at most **two (2) hours**, and an automatic sweep deletes it when it expires. That row carries no datum that identifies you: not who asked, not from where. Of what the portal answers we keep **less than the portal publishes**: the parties are **masked** and only **the latest filing** is kept, not the history.
- **No Artificial Intelligence.** Nothing you look up is sent to the text generation provider of Section 14, or to any other Artificial Intelligence provider. The lookup is not summarized, not analyzed, and trains nothing.
- **The parties' data is neither yours nor ours.** Who decides to publish it is the judiciary that holds the case file. We do not republish it as it stands: we mask it, and we do not keep it beyond those two hours.

## 3. Rights of Data Subjects {#section3}

As the holder of your personal data, you have the following rights, which you may exercise free of charge and at any time:

- (i) ACCESS: Know what personal data we process about you, the purpose of processing, and who we share it with.
- (ii) RECTIFICATION: Update and correct partially accurate, incomplete, or outdated data.
- (iii) CANCELLATION/DELETION (Habeas Data): Request deletion of your data when it is no longer necessary for the purpose that justified its processing, or when you have revoked your consent, subject to legally mandated retention obligations.
- (iv) OBJECTION: Object to the processing of your data for marketing, profiling, or automated decision-making purposes.
- (v) PORTABILITY (LOPDP Ecuador, Art. 17; LGPD Brazil, Article 18, V, «de acordo com a regulamentação da autoridade nacional, observados os segredos comercial e industrial»): Download a structured, machine-readable copy of your account data -your personal information, your consent history, and the record of your own actions on the platform- from 'My account > Your privacy'. This automatic download does not currently include the matters or documents your firm manages about you; to access that information, submit an access request through the channels in Section 7. If your data is held in a matter and you are not a user of the platform, Section 1 (ii) applies: the controller is the firm, and we forward your request to it.
- (vi) File complaints with your country's supervisory authority, where your country has one. Which one it is, how to write to it and what it requires of you before you turn to it is stated by [your country's annex](#annex), which also says whether your country created none and what route is left to you then.
- (vii) Withdraw consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.

## 4. Authorization and Consent {#section4}

The processing of personal data requires the free, prior, express, and informed consent of the data holder. By registering on the platform and accepting this policy, you declare that:

- (i) The data provided is truthful and accurate.
- (ii) You have the legal capacity and authority to authorize its processing.
- (iii) You understand the purposes of the processing.
- (iv) You have been informed of your rights as a data holder.

Authorization may be revoked at any time following the procedure established in this policy.

The authorization to receive **promotional emails** is a **separate, optional and unticked** box: silence and inaction do not count as a yes, and leaving it unticked limits no feature of the platform for you. What you decide with it are the promotional messages described in Section 2; the service emails of that same section do not depend on it, because they rest on the contractual relationship. You may withdraw it whenever you want from the unsubscribe link carried by the promotional emails and by the account set-up service emails described in Section 2, or from "My account > Your privacy", and the withdrawal takes effect from the moment we receive it.

## 5. Information Security {#section5}

We implement technical, administrative, and organizational security measures to protect your data:

- (i) AES-256-GCM encryption of the most sensitive data we store: document number, address and phone; description, objective and internal notes of matters; and the content of your conversations with the artificial intelligence assistant.
- (ii) Encrypted transmission over TLS.
- (iii) Role-based access control (RBAC).
- (iv) Audit records of the relevant actions over your data, kept for the term Section 11 declares.
- (v) Database backups on the infrastructure of the hosting provider described in Section 10.
- (vi) Watching for improper access patterns, such as bursts of failed sign-in attempts or unusual downloads of information.

These measures answer what Ley 1581 de 2012, the LOPDP, Article 5, paragraph 5, and Article 13, paragraph 2, of the Dominican Republic's Ley núm. 172-13, Article 10 of Costa Rica's Ley N° 8968 — which orders that «las medidas de índole técnica y de organización necesarias para garantizar la seguridad de los datos de carácter personal» be adopted — and Article 12 of Uruguay's Ley N° 18.331, in the wording given to it by Article 39 of Ley N° 19.670, which requires the controller and the processor to adopt «privacidad desde el diseño, privacidad por defecto, evaluación de impacto a la protección de datos, entre otras» and to demonstrate that they are effectively implemented — Article 9 of Argentina's Ley 25.326, which requires «las medidas técnicas y organizativas que resulten necesarias para garantizar la seguridad y confidencialidad de los datos personales» to be adopted, which Article 25, subsection b), of Decreto 1558/2001 makes enforceable against the processor as well, and Article 46 of Brazil's Lei nº 13.709/2018 (LGPD), which requires the «agentes de tratamento» to adopt «medidas de segurança, técnicas e administrativas aptas a proteger os dados pessoais de acessos não autorizados e de situações acidentais ou ilícitas de destruição, perda, alteração, comunicação ou qualquer forma de tratamento inadequado ou ilícito», and which reaches the processor too because Article 5º, IX of that same law defines «agentes de tratamento» as «o controlador e o operador», and follow industry good practice.

If we detect a security incident that puts your personal data at risk, we notify you without undue delay and inform your country's supervisory authority, where your country has one to present it to. Which authority we inform, within what term, within what term we notify you, and whether that term is set by a rule or adopted by our own decision, is stated by [your country's annex](#annex).

## 6. Attention Channel (Habeas Data) {#section6}

To exercise your rights as a data holder, you can contact us through:

- (i) Email: support@custodio.legal
- (ii) Through your account in 'My account > Your privacy'.

Which procedures your law distinguishes, within how many days we answer each of them, from when they are counted and what extension they admit is stated by [your country's annex](#annex), each term with the rule that sets it or with the warning that it is ours and not the law's.

While we handle a claim, the corresponding record is flagged as "claim in process" within the following two business days, so that no one treats it as if it were unchallenged. If your claim is incomplete, we tell you within the following five (5) business days so you can complete it; if two months pass without your replying, we understand that you withdrew it, and you may file it again whenever you like. We do those three things the same way in all seven countries.

## 7. How to Exercise Your Rights (ARCO) {#section7}

You can exercise your rights to Access, Rectify, Cancel, and Oppose directly from your account in 'My account > Your privacy'. You can also send a written request to support@custodio.legal indicating:

- (i) Your full name and identity document.
- (ii) Description of facts and request.
- (iii) Physical or electronic address for notifications.
- (iv) Supporting documents if applicable.

## 8. Sensitive Data and Data of Minors {#section8}

Custodio Legal may process sensitive data only when strictly necessary for the provision of legal services and with your express authorization. Sensitive data includes data revealing racial or ethnic origin, political orientation, religious convictions, union membership, health data, sexual life, and biometric data. This data will receive enhanced protection.

A judicial case file may contain sensitive data and also data of children and adolescents. Custodio Legal neither asks you for that data nor collects it on its own: it arrives at the platform inside the case file the firm manages, and it is the firm -as controller- that must have obtained the authorization the law requires to process it. You are not obliged to authorize the processing of sensitive data and no one may condition a service on your doing so; data of minors may only be processed respecting their best interests and their fundamental rights, and it is their legal representative who exercises their rights. We process it with the same security measures of Section 5, without using it for any purpose other than managing the matter it appears in.

## 9. International Data Transfer {#section9}

Your data may be transferred and processed in third countries. Our hosting and infrastructure provider, transactional email provider, payment gateway, technical monitoring provider, the network and protection provider for the site and the application, and the vector representation (embeddings) provider, all described in Section 10, are located in the United States, and so is Google, which is not a processor but an independent controller and is covered by Section 15. The Artificial Intelligence text generation provider described in Sections 10 and 14 is domiciled in the Netherlands and declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model.

Those destinations are the same for the data subjects of every country in which we offer the Service. What changes with your country is **the safeguard that backs each sending**: whether your law recognizes countries with an adequate level of protection and which ones they are, whether sending to a processor counts as a transfer at all, and which article permits the one that does. [Your country's annex](#annex) states that, with the rule that sustains it, in its international transfer section.

Two things hold the same in all seven countries, and that is why they are here and not in an annex: by accepting this policy you give your express and informed consent to the transfer, knowing the destination and which safeguard backs it; and Section 14 (iii) states, provider by provider, which guarantee is actually written down and which is not.

## 10. Data Processors {#section10}

To provide our services, we share data with third-party data processors who act under our instructions. The full list, with what each one receives, the safeguard each transfer travels under and the retention each one publishes, is published separately and reviewed at least once a year: it is our [list of subprocessors](/subprocessors), and the ones this section enumerates are the same ones. Each one incorporates into its terms of service a data processing agreement that we accept when contracting it and that obliges it to process your data on our behalf and not for its own purposes. Not every third party we exchange data with is a processor: Google is not, which is why it is not on this list but in Section 15.

- (i) Railway (United States) - Hosting of the platform: the servers, the database, the task queue and their backups. It is the processor that hosts all the data the platform stores.
- (ii) Resend (United States) - Transactional email delivery: it receives your email address and the content of the notices.
- (iii) Polar.sh (United States) - Payment gateway and billing: it receives the contact email and the firm's name.
- (iv) Nebius B.V., a Dutch company domiciled at Schiphol Boulevard 165, 1118 BG Schiphol, the Netherlands, which operates the Nebius Token Factory service - Text generation with the GLM-5.3-Flash model for the Artificial Intelligence features: document drafting, questions with citations over your documents, and the fact extraction and matter reevaluation that run without a click under Section 14 (viii). That service's terms are governed by the law of the Netherlands and its disputes are submitted to the courts of Amsterdam. The provider declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model, states each model's country in its catalog, and publishes the list of the sub-processors it appoints.
- (v) Voyage AI (United States) - Generation of the vector representations (embeddings) of your document text, which make the semantic search behind the questions with citations (Q&A) feature possible.
- (vi) Alternate text generation providers, registered in the platform and carrying no traffic today: Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD., domiciled at 10 Anson Road #26-03, Singapore, which operates the z.ai service. Neither receives any of your data: the platform keeps their connections configured so we can fall back to them if the provider in item (iv) becomes unavailable. Activating one would change the processor and the jurisdiction of the transfer, so we would not do it without raising the version of this policy and asking you for a new authorization, as required by Section 12.
- (vii) Sentry (United States) - Technical error monitoring: it receives the route where the error occurred and your internal user identifier; before each event is sent we strip your email, your name and your IP address.
- (viii) Cloudflare (United States) - Delivery and protection network for the site and the application: all traffic between your browser and us goes through its network, so it processes in transit the IP address and the metadata of each connection; it also controls access to our internal documentation.

We do not claim to have negotiated with any of them clauses beyond those their own terms incorporate, nor to hold a separately signed contract, nor that they hold security certifications we have audited: Section 14 (iii) states exactly what is written down for the Artificial Intelligence providers. We do not keep the original file you upload to a matter: it is processed transiently to extract its content and is then deleted. What we retain is the extracted text, so the matter can be searched and consulted; the file itself is never shared with these processors. The optical character recognition (OCR) of that text runs on our own service, within our own infrastructure, and is never sent to an external provider.

The provider of an external assistant your firm connects through the MCP protocol, if it connects one, is not on this list or on the list of subprocessors: it does not process data on our behalf or under our instructions. Section 16 says who chooses it and who answers for it.

## 11. Data Retention and Deletion {#section11}

We retain your personal data for as long as a relationship exists with the firm that provides you the service and for as long as the legal and contractual obligations that justify keeping it remain in force. We do not delete data automatically based on the passage of time: it is deleted or anonymized when appropriate, for example when we approve a cancellation request from you (Section 3, Habeas Data). When your firm's account ends, we delete or anonymize the data the platform holds for that firm within the ninety (90) days following termination, unless a legal retention obligation applies. There is one deliberate exception: the records of your consent, of our audits, and of your own ARCO requests survive that deletion, even after the rest of your data is anonymized, because they are the evidence that we comply with this policy. We do not keep them indefinitely, nor because we decide to: how long each one is kept, and the rule that requires or limits it, is stated by [your country's annex](#annex) in its «Retention After Termination» section, which is the text that governs over this Section.

**The lookup with no account is kept apart, and barely at all.** The ephemeral row described in Section 2 waits for no termination and for no request of yours: it lives at most two (2) hours and an automatic sweep deletes it when it expires. It carries no identifier of whoever asked, so nothing is left to anonymize afterwards.

## 12. Validity and Modifications {#section12}

The version of this policy in force is 0.0.24, effective as of September 22, 2026. Version 0.0.24 adds Section 16, which describes the channel through which your firm may connect an external Artificial Intelligence assistant to Custodio Legal through the MCP protocol: who authorizes it and how, which data leave towards that assistant and when, that the assistant's provider is not our processor and that Custodio Legal is not responsible for the processing that provider carries out, what we keep of each connection and how it is revoked; and it adds to Section 10 that this provider is not on its list. The channel already existed and Section 22 of the Terms of Service governed it; this policy did not say so. Because the change states whom your data may reach, **we ask you for a new authorization** over this text, on the same criterion with which 0.0.7 asked for one when it described Google as an independent controller, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.23, which was in force from September 19, 2026. Version 0.0.23 states in Section 2, inside the no-account case lookup that 0.0.22 had just described, that **before** we ask the portal an anti-abuse check is run, and says who runs it and what it processes: it is run by Cloudflare —which already was, and from before this version, the network all of this site's traffic passes through, and already appeared on the list of subprocessors—, your browser talks to it directly, and for that check it processes your IP address, the technical fingerprint of your encrypted connection, the identification of your browser and this site's public key, signals from which Cloudflare states it cannot directly identify an individual. It also states what does **not** happen: we do not send it the number you looked up or any other datum of the lookup, and that check writes no cookie. What we did not verify —whether it uses any other browser storage— is stated as unverified rather than asserted. **That purpose processes no data of a registered data subject**: whoever looks up has no account, and none of the data you gave us enters it. It does not change who processes your data, nor where, nor on what ground, nor for what, nor any deadline of yours. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.22 —or over 0.0.21, 0.0.20, 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.22, which was in force from September 19, 2026. Version 0.0.22 describes in Section 2 a new purpose —the one-off lookup of a public court record asked for by a person **with no account**— and states what is processed in it: the case number that person types, the country they pick, and their IP address, the latter only to limit how many lookups come from one place. The legal ground for that lookup is declared by each country's annex, which is where the rule that sustains it lives; Section 11 states that the row the lookup writes lives at most two (2) hours and an automatic sweep deletes it, and Section 14 adds that nothing of that lookup goes out to any Artificial Intelligence provider. This version is published **before** the lookup is turned on, and not after. **That purpose processes no data of a registered data subject**: whoever looks up has no account, and none of the data you gave us enters it. It does not change who processes your data, nor where, nor on what ground, nor for what, nor any deadline of yours. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.21 —or over 0.0.20, 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.21, which was in force from September 18, 2026. Version 0.0.21 writes into Section 2 the distinction between **service emails** —those that tell you the state of your own account and teach you to use what you contracted, while your account is being set up— and **promotional emails**, and details in Section 4 that the box authorizing the latter is separate, optional and unticked, that leaving it unticked limits no feature for you, and that both kinds carry an unsubscribe link. No processing is added, and it does not change who processes your data, or where, or on what basis, or for what, or any term: purposes a), b), c) and e) of Section 2 are the same ones that were already there, and what changes is that the text says which of them sustains each kind of email. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.20 —or over 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.20, which was in force from September 16, 2026. Version 0.0.20 details in Section 14 (ii) what the questions with citations and the document drafting send to the text generation provider, and details it only about the matter you are working on: its record, its state, its timeline, its attention items, the extracted facts with the fragment that supports them, the metadata of its documents, the corrections your firm approved in that same matter and the entries of your firm's memory typed in by hand or born in it. They are data of the same matter, they go to the same provider and the reevaluation of item (viii) already processed them. No processing is added, and it changes not who processes your data, nor where, nor on what basis, nor for what, nor any term; and it remains true that no feature sends data of another matter. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.19 —or over 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.19, in force since September 16, 2026. Version 0.0.19 stops listing the case and service summary and the deep analysis among the Artificial Intelligence features, because the platform no longer runs them. It does so in Section 10 (iv) and in Section 14 —its heading and items (i), (ii) and (viii)—, and what remains named is what runs: document drafting and questions with citations, which you start, and the indexing, the fact extraction and the matter reevaluation, which run without a click and which item (viii) already described. No processing is added, and it changes not who processes your data, nor where, nor on what basis, nor for what, nor any term: what changes is that the text stops describing two features that do not exist. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.18 —or over 0.0.17— still covers this text, with your record intact. It replaces version 0.0.18, in force since September 16, 2026. Version 0.0.18 corrects two sentences the text itself contradicted. The first is in Section 13: it said we also publish an English translation of this policy, when since September 16, 2026 we publish a Portuguese one as well; the clause now names both, and the Spanish version still prevails. The second is in Section 5 (iv): it said the audit records «are never deleted», which is exactly what 0.0.12 removed from Section 11 when it tied that retention to the term your country's annex declares; it now refers to that term, as Section 11 does. It changes not who processes your data, nor where, nor for what, nor any term: what changes is that the text stops saying two different things about the same retention. **That is why we do not ask you for a new authorization** and the one you gave over 0.0.17 —hours earlier— still covers this text, with your record intact. It replaces version 0.0.17, in force since September 16, 2026. Version 0.0.17 adds Brazil: the service is now offered in seven countries and this policy also names Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais (LGPD) —, with the Brazilian annex that says what they mean for you: the ANPD as the supervisory authority, a regulatory agency since Lei nº 15.352, de 25 de febrero de 2026; the fifteen (15) calendar days within which we handle your rights, with the immediate confirmation and simplified access of Article 19, I; the three (3) business days of the incident notice of Resolução CD/ANPD nº 15/2024 and the twenty-four (24) hours within which we undertake to notify you; and the international transfer backed by the cláusulas-padrão contratuais of Annex II of Resolução CD/ANPD nº 19/2024, adopted whole and unaltered, with a Brazilian forum. It also names Article 46 of that law among the rules the security measures of Section 5 answer to, adds the portability of Article 18, V to right (v) of Section 3, and corrects to seven the two lines that counted six countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization over this text, on the same criterion 0.0.15 used when Argentina was added and 0.0.14 when Uruguay was. It replaces version 0.0.16, which was in force since September 13, 2026. Version 0.0.16 changes how the data controller is identified in Section 1: where it used to read that «Custodio Legal is the trade name under which» a natural person provides the service, the controller is now **Custodio Legal**, identified with the same NIT 1057602936 and with the same domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia. The identification number, the address, the phone number and the contact email are the same, and the area that handles your queries and claims is still the Personal Data Protection Area. It changes neither who processes your data, nor where, nor what for, nor any deadline, nor any processor. Even so we ask you for a new authorization of this text, because the identification of the controller is part of what you authorize —it is who you exercise your rights before— and the platform would rather ask again than take as given an authorization made over a different wording; the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.15, in force from September 13, 2026. Version 0.0.15 adds Argentina: the service is now offered in six countries and this policy also names Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001, with the Argentine annex saying what they mean for you — the AAIP as supervisory authority, the registration of the database with the Registro Nacional de Bases de Datos, the ten calendar days for access and the five business days for rectification, erasure and blocking, and why that regime has no right to object, no portability, no data protection officer and no statutory duty to notify a breach. It also names Article 9 of that law among the rules the security measures of Section 5 come from, with Article 25, subsection b), of Decreto 1558/2001 extending it to the processor, and corrects to six the two lines that counted five countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, on the same criterion 0.0.14 applied when it added Uruguay and 0.0.9 when it added Costa Rica. It replaces version 0.0.14, in force from September 12, 2026. Version 0.0.14 adds Uruguay: the service is now offered in five countries and this policy also names Ley N° 18.331, on personal data protection and the «Habeas Data» action, and its amending Ley N° 19.670, with the Uruguayan annex saying what they mean for you — the URCDP as supervisory authority, the registration of the database before it, the five business days within which we handle your rights and the three clocks of a security incident. It also names Article 12 of that law, in the wording of Ley N° 19.670, among the rules the security measures of Section 5 come from, and corrects to five the two lines that counted four countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, on the same criterion 0.0.9 applied when it added Costa Rica: the platform would rather ask again than take as given an authorization made over a different wording, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.13, in force from September 11, 2026. Version 0.0.13 changes neither who processes your data, nor where, nor what for, nor any deadline: it takes the list of processors that Section 10 and Section 14 (iii) wrote out in prose and publishes it separately, as our [list of subprocessors](/subprocessors), with the same information and a declared review at least once a year. The processors are the same, the safeguards are the same and what is sent to each one is the same: what changes is where the list can be read, and that a data processing agreement can now cite it. **That is why we do not ask you for a new authorization**, and the one you gave over 0.0.12 — or over any of the earlier ones already carried forward — still covers this text, with your record intact. It replaces version 0.0.12, in force from September 10, 2026. Version 0.0.12 corrects what Section 11 promised beyond what the country annexes allow: it said the records of your consent, of our audits and of your ARCO requests «are never deleted», while the annexes —which have governed over this trunk since 0.0.8— tie them to a rule and to a term. The Dominican annex binds them to the limitation period of the liabilities arising from the processing (Ley núm. 172-13, Article 15, the Dominican personal data protection statute) and the Costa Rican one to the ten-year ceiling of Article 11 of the Reglamento to Ley N° 8968, Decreto Ejecutivo N° 37554-JP. «Never» is longer than either of those allows, so the trunk stops setting that window and refers to the one in your country's annex, where it is written with the rule that sustains it. It changes neither who processes your data, nor where, nor what for, nor the two windows your annex publishes —notice sixty (60) days after the relationship ends and deletion at ninety (90)—: what changes is that this trunk stops promising a retention longer than your own law admits. **That is why we do not ask you for a new authorization**, and the one you gave over 0.0.11 — or over 0.0.10 or 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.11, in force from September 10, 2026. Version 0.0.11 corrects two places where the text contradicted itself. The first: Sections 6 and 9 still counted three countries when there have been four since 0.0.9 — the very version that names four of them in the preamble, in Section 12 and in Section 13. The second lives only in the English translation, and it is the one that matters for checking us: the rules of Colombia and Ecuador were **translated** — «Statutory Law 1581 of 2012», «Executive Decree 904» — next to those of the Dominican Republic and Costa Rica, which were transcribed. A translated rule cannot be checked against the official gazette that published it. From this version the four are named as their own source publishes them, in Spanish, with an English gloss the first time, which is what the eight country annexes already did. Not one piece of data, one destination, one deadline or one processor changes: **that is why we do not ask you for a new authorization**, and the one you gave over 0.0.10 — or over 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.10, in force from September 10, 2026. Version 0.0.10 completes with the Dominican and Costa Rican rules a line that enumerated only two countries from before there was a third: Section 5 now names, alongside Law 1581 and the LOPDP, Articles 5 and 13 of Ley núm. 172-13 and Article 10 of Ley N° 8968 as the rules the security measures we already applied come from. It changes not one measure, nor who processes your data, nor where, nor any deadline: what changes is that your own rule is written with its article instead of being covered by a general formula. **That is why we do not ask you for a new authorization**: the one you gave over 0.0.9 still covers this text, and your authorization record is kept intact. It replaces version 0.0.9, in force from 10 September 2026. Version 0.0.9 adds Costa Rica: the service is now offered in four countries and this policy also names Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP, with the Costa Rican annex saying what they mean for you. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, because the platform would rather ask again than take as given an authorization made over a different wording, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.8, in force since 9 September 2026. Version 0.0.8 changes not one piece of data, not one destination and not one deadline: it splits the same text between this trunk and your country's annex. Since the three annexes were published, the supervisory authority, the deadlines for handling your rights, the incident notice and the basis of the international transfer were stated twice, once here in general terms and once in the annex with the rule that sustains it. This trunk now states the rule that held the same in the three countries offered at the time and refers to the annex, and the annex states what your law makes concrete. What you authorize is the same; what changes is that it is written once, in the document that cites your rule. It replaces version 0.0.7, in force since 9 September 2026, which corrects Google's legal figure: until 0.0.6 this policy listed it among the data processors of Section 10, under a heading stating that every third party on that list acts under our instructions and holds a data processing agreement with us. It does not. The two uses we make of it -sign-in and the public-site Ads tag- are governed by terms between independent controllers, which the new Section 15 cites by version and explains: what changes in the safeguard of the transfer, that no instrument of theirs obliges them to notify us of a breach, and before whom you exercise your rights. No data sent to it and no destination changes: what changes is what this policy claimed about it, which was not accurate. It replaces version 0.0.6, in force from 4 September 2026, version 0.0.5, which was in force from September 2026, version 0.0.4, which was in force from September 2026, version 0.0.3, which was in force from August 2026, version 0.0.2, which was in force from August 2026, and version 0.0.1, which was in force from February 2026. Version 0.0.6 named, one by one, data processors that earlier versions described generically or did not mention -the hosting provider, the email provider, the payment provider, the monitoring provider, Google and Cloudflare-, declares our role as processor over the data held in a firm's matters, and corrects the response deadlines, the incident notification and the safeguards for each destination. Since the list of processors you authorize changes, the platform will ask you for a new authorization of this text, and your previous authorization record is kept intact as evidence of what you authorized at the time. Version 0.0.5 only declared Zero Data Retention with the text generation provider, changing neither the processor nor the jurisdiction, which is why it did not ask for a new authorization; version 0.0.4 changed the processor that generates the text for the Artificial Intelligence features and the jurisdiction of that transfer -from JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore) to Nebius B.V. (the Netherlands)- and did ask for one. Each version remains in effect until replaced by a new one. We reserve the right to modify this policy at any time. We will notify you of any material changes by email or through a prominent notice on the platform at least 15 days in advance. When the change alters what you authorize -who processes your data, where, or for what-, notice alone is not enough: the platform will ask you for a new authorization of the text in force before you can continue, and the record of your previous authorization is kept intact. In every other case, continued use of the service after notification constitutes acceptance of the changes.

## 13. Applicable Legal Framework and Language {#section13}

This policy is governed by Ley Estatutaria 1581 de 2012 and Decreto 1377 de 2013 (Colombia), by the Ley Orgánica de Protección de Datos Personales and its Decreto Ejecutivo 904 (Ecuador), by Ley núm. 172-13, on the comprehensive protection of personal data (Dominican Republic), by Ley N° 8968 on the protection of the person with regard to the processing of their personal data and its Reglamento, Decreto Ejecutivo N° 37554-JP (Costa Rica), and by Ley N° 18.331, on personal data protection and the «Habeas Data» action, and its amending Ley N° 19.670 (Uruguay), and by Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001 (Argentina), and by Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais, LGPD (Brazil), the seven countries in which we offer the service; each data holder is covered by the regulations of their country of residence, which that country's annex details. This policy is drafted in Spanish and we also publish English and Portuguese translations so you can read it in those languages; in case of any discrepancy between the versions, the Spanish version prevails.

## 14. Artificial Intelligence (AI) Processing {#section14}

Custodio Legal offers Artificial Intelligence features (currently: document drafting and questions with citations over your documents, known as Q&A; the matter state and the facts extracted from its documents run without a click and are described in item (viii)) that are optional and user-initiated. None of them takes part in the lookup with no account described in Section 2: nothing of that lookup goes out to any Artificial Intelligence provider. AI processing is governed by the following principles:

- (i) LEGAL BASIS: Express consent, given in two ways depending on what triggers the operation. For the features you start yourself -document drafting and questions with citations- consent is given by executing each operation on the case or service you are working on, a voluntary act that draws down your firm's token allowance. For the processing that runs without a click, listed one by one in item (viii), it is given by accepting this policy -which describes them- and by uploading the document or updating the matter that triggers them. In both cases the processing is limited to what is necessary to provide the contracted service.
- (ii) DATA MINIMIZATION: Only what the requested operation needs is sent to each provider, and what is sent depends on the feature. For the document drafting we send the text of the active case or service -description, parties, a bounded number of the most recent case activities and the corrections your firm approved in that same matter-, and we do NOT send the file attachments. For the questions with citations (Q&A) feature we DO send the content of your documents: when your plan enables it, once optical character recognition (OCR) of a document finishes its text is sent to Voyage AI to generate its vector representation, and when you ask a question the assistant looks up, only within the matter you are asking about, the most relevant document fragments, the matter's record (its description and the names of its person in charge, its parties and its collaborators), its state, its timeline, its attention items, the extracted facts with the fragment that supports them and the metadata of its documents (name, type and page count), as well as the entries of your firm's memory that someone typed in by hand or that were born in that same matter, and sends them to the text generation provider together with your question, the latest messages of the conversation and the citations the answer must carry. For fact extraction, which runs on its own once a document finishes processing, a bounded extract of the text extracted from that document is sent to the text generation provider to identify parties, dates, amounts, identifiers, obligations and deadlines. For the matter reevaluation we send those already-extracted facts together with the data of the case or service and its case activities, not the full text of the documents. The concrete caps -how many case activities and how many characters- are set by the platform's current configuration and may change without changing what you authorize: in no case is more sent than the operation you asked for needs. No feature ever sends metadata of other cases, information about other clients, or data from other firms.
- (iii) AI PROVIDERS AND WHAT GUARANTEE EACH ONE CARRIES: The full list of who processes data on our behalf lives in our [list of subprocessors](/subprocessors). Text generation is provided by Nebius B.V. (the Netherlands), which operates the Nebius Token Factory service, with the GLM-5.3-Flash model; the vector representations (embeddings) behind semantic search are provided by Voyage AI (United States); Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore, the z.ai service) are registered as alternate text generation providers and receive none of your data today. We tell you, guarantee by guarantee, what is written down and what is not: (a) the text generation provider incorporates a data processing agreement into its own terms of service, with the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 for transfers outside the European Economic Area, and states in its published legal guide that customer content is not used to train or fine-tune models (verified on 3 September 2026); the embeddings provider applies the opt-out we have contracted; (b) traffic to all of them travels encrypted in transit over TLS, which is how they publish their interfaces; (c) the text generation provider publicly claims ISO 27001, ISO 27701 and SOC 2 Type II certifications and publishes its sub-processor list, but that is its own claim, which we have neither audited nor checked against the certificates, and we do NOT claim to have negotiated clauses with it beyond those its own terms incorporate, nor to hold a separately signed contract.
- (iv) RETENTION AT PROVIDER: Zero Data Retention is enabled on our organization with the text generation provider as of 4 September 2026. According to what that provider publishes, with Zero Data Retention enabled the inputs (the text sent to it) and the outputs (the text it returns) are not stored on its systems after each request is processed, are not used for speculative decoding, and are not used to train, fine-tune, or improve any model, whether its own or a third party's; the option applies at the organization level and covers all of its projects and endpoints (Nebius published legal guide, "Legal Quick Guide", consulted on 4 September 2026 on the provider's documentation site). We also tell you, with the same precision, what that guarantee does NOT settle: it is a statement published by the provider and not a control we have audited; it operates going forward and does not reach submissions made before 4 September 2026, over which the default processing of its terms of service (version of 20 August 2026) continued to apply, keeping inputs and outputs to train small models used for speculative decoding; its published documents do NOT say whether Zero Data Retention reaches any records the provider may keep to detect abuse of the service, nor whether it applies in the same way to responses delivered as a stream, so we claim neither of those two things; and enabling it is up to us, so if we ever disabled it we would update this section before doing so. The embeddings provider applies zero retention through the opt-out we have had active since 12 August 2026, which operates going forward and not over earlier submissions.
- (v) INTERNATIONAL TRANSFER: AI processing occurs on servers located outside the countries in which we offer the Service. Text generation is contracted and billed by Nebius B.V., domiciled in Schiphol (the Netherlands), under Dutch law and with the courts of Amsterdam as the forum; the provider declares that it runs inference in data centers in the European Union, Israel or the United States depending on the model. Embeddings are processed in the United States. The safeguard that backs each of those sendings is the one in Section 9: [your country's annex](#annex) states it, destination by destination and with the rule that sustains it.
- (vi) AUTOMATED DECISIONS: AI outputs are supporting material; no legal or contractual decisions are made fully automatically. The professional judgment of the attorney is irreplaceable (see Terms of Service, Section 17).
- (vii) APPLICABLE ARCO RIGHTS: You may exercise access, rectification, deletion, and opposition rights over data processed by AI. Deletion in our own systems is immediate. For the text generation provider, the Zero Data Retention described in item (iv) means that, as of 4 September 2026 and according to what it publishes, no inputs or outputs remain stored to be deleted once each request has been processed. What we still cannot offer you is a contractual deletion deadline of our own or enforceable deletion evidence: that guarantee is a published statement of the provider that we have not audited, and it does not reach submissions made before that date. If you ask us through the channels of Section 6, we pass the request on to the provider and tell you its answer.
- (viii) WHAT RUNS ON YOUR CLICK AND WHAT RUNS ON ITS OWN: The features that produce a result for you to read -document drafting and questions with citations- require an express click by you on the case or service being worked on, so not using them is equivalent to authorizing no such processing at all. Three kinds of processing do run without a click, always over data from your own firm's matters and never over another firm's: (a) the indexing behind questions with citations (Q&A), which runs when a document finishes optical character recognition (OCR) if your plan enables it; (b) the extraction of facts from the document just processed, which identifies parties, dates, amounts, identifiers, obligations and deadlines; and (c) the matter reevaluation, which refreshes its state and its attention items when a document arrives, when you edit the case or service, or when a query to the judicial portal brings in a new case activity. All three operate over the documents and matters your firm uploads or updates under its declaration that it holds the authorization of the data subjects whose data they contain: the firm is the controller of that data, as Section 1 (ii) says, and Custodio Legal processes it on the firm's behalf. All three consume your firm's monthly token allowance and stop when that allowance runs out. Which features exist for your firm is also determined by your plan. If you do not want this automatic processing to run over your firm's matters, the firm owner can turn each one off from the firm settings, under 'My practice > Settings > AI without a click': the change takes effect immediately and is recorded. Turning the Q&A indexing off also erases the fragments already indexed. You may also object by writing to support@custodio.legal, and that route remains available: the objection is handled under the procedure and within the deadlines of Section 6.
- (ix) SENSITIVE DATA: You must not deliberately send sensitive third-party data (health, sexual orientation, ethnic origin, biometrics) to AI features without prior authorization from the data subject.
- (x) LIABILITY LIMIT: AI models may produce errors or 'hallucinations'. All output must be verified by a professional before use. Custodio Legal is not responsible for decisions made without human verification.

## 15. Independent Controllers {#section15}

Not every third party the platform exchanges personal data with is a data processor. **Google LLC (United States) does not process your data on our behalf or under our instructions**: it is an independent controller that determines for itself the purposes and means of its own processing. That is why it is not on the list in Section 10, and why we hold no processing agreement with it for the two uses the product makes of it:

- (i) **Sign-in with your Google account**, if you choose that option: Google hands us your email and your name, and processes the data of your Google account as a controller in its own right. The relationship is governed by Google's *Controller-Controller Data Protection Terms* (version 11), to which item 3.i of the *Google APIs Terms of Service* refers, and whose item 4.1 states that each party is "an independent controller" of the data and "will individually determine the purposes and means of its processing".
- (ii) **The Google Ads tag on the public site** -not on the application-, which loads with ads consent denied by default and only enables it if you accept all cookies, as our Cookie Policy describes. It is governed by the *Ads Controller-Controller Data Protection Terms* (version 8.0), whose item 4.1 says the same.

What this means for you, said plainly:

- (a) Sending data to Google **is a transfer between controllers**, not a transmission to a processor. It rests on your express and informed consent and on the controller-to-controller standard contractual clauses those terms incorporate; the basis your own law gives it —a list of adequate countries, an authorization of yours, whichever article permits it— is stated by [your country's annex](#annex) in its international transfer section. It does not rest on the data processing agreement that backs the sending to the processors in Section 10, which is a different thing.
- (b) **No Google instrument obliges it to notify us of a security breach** occurring on its side: terms between independent controllers do not regulate it. We say so because it is different from what governs the processors in Section 10, and because Section 5 promises to notify you of the incidents we become aware of.
- (c) For the data Google processes as a controller in its own right, **you exercise your rights before Google**, through its own channels and under its own privacy policy. The data we process -the email and the name we receive at sign-in- remain ours and you exercise your rights before us, under Section 7.
- (d) A Google Ads processor agreement does exist, but it covers only a published list of processor services -Analytics, Tag Manager, Enhanced Conversions and the like- and **the product uses none of them**. If we ever enabled one, we would accept that agreement before the first data point and update this policy.

You cannot opt out of the Ads tag other than by rejecting non-necessary cookies, and you are not required to use Google sign-in: the platform accepts email and password, and that is the path on which Google plays no part.

## 16. External Assistants Connected through MCP {#section16}

On the plans that include it, your firm may connect to Custodio Legal an external Artificial Intelligence assistant —for example Claude or ChatGPT— compatible with the MCP protocol (Model Context Protocol), to consult the firm's information from that assistant. This section says what leaves through that channel, towards whom, under which authorization and how it is cut off. The contractual conditions of the channel are in Section 22 of the Terms of Service.

- (i) WHO AUTHORIZES THE CONNECTION: Nothing leaves through this channel without an express act by a person. The connection is authorized by a member of the firm, signed in, on Custodio Legal's authorization screen (OAuth 2.1 with PKCE), which shows the name the application registered with, the firm it will act for and what each scope it asks for allows. Each authorization belongs to one person over one firm: the assistant sees no more than that person can see in that firm with their role, and nothing of another firm. On the plans that do not include the channel, the connection cannot be authorized.
- (ii) WHAT LEAVES TOWARDS THE ASSISTANT: Only what the assistant asks for, within the authorized scopes and at the moment it asks. With the matters reading scope, the data of the matters —their record, their parties, their status, their deadlines, their attention items, their timeline and their recent changes—; with the matter intelligence reading scope, their state and the extracted facts with the document fragment that supports them; with the knowledge search scope, fragments of the text extracted from the firm's documents and entries of its memory; and with the preparation scope, no additional data: the assistant only leaves an action prepared —a draft, a follow-up or a task— that is not carried out until a person of the firm approves it inside the Service. Through this channel no assistant can write, modify or delete the firm's data without that approval. What leaves may include personal data of the clients, the counterparties and the other persons who appear in the matters, and of the firm's members. To answer a knowledge search, the text of the assistant's query goes through the embeddings provider of Section 10, just as a search made inside the Service does; beyond that, what is delivered to the assistant goes through none of our Artificial Intelligence providers.
- (iii) WHO ANSWERS FOR WHAT THE ASSISTANT DOES: The assistant's provider is not our processor: we do not engage it, we do not instruct it and it is not on the list of Section 10 or on the [list of subprocessors](/subprocessors). It is chosen by the firm, which is the controller of the data of its matters (Section 1 (ii)), and the data are delivered to it only on the firm's instruction, given by one of its members on the authorization screen. What the assistant does with what it receives —where it processes it, how long it keeps it, whether it uses it to train models— is governed by the terms and the privacy policy of its provider, which the firm or its member accept with that provider, and **Custodio Legal is not responsible for that processing**. If that provider is outside your country, that transfer is decided by the firm, and the safeguard that backs it is the one the firm has with its provider, not those of Section 9. Before connecting an assistant, the firm must make sure it may send the data of its matters to that provider, with the authorization its own law requires of it.
- (iv) WHAT WE KEEP: The record of the application that connected —the name it registered with and its redirect addresses—; the authorization —who gave it, for which firm, with which scopes, when and, if it was revoked, when—, which we keep as the record of that authorization under the rule of Section 11; the act of authorizing, in the firm's audit log; the access codes and tokens, which we never store in the clear but as a cryptographic fingerprint, and which are deleted thirty (30) days after they stop being usable; and one row for each call by the assistant —which tool, who, when and with what result—, without the content delivered to it, of which we keep only a fingerprint.
- (v) HOW IT IS CUT OFF: You may revoke at any time, from your account, under «Authorized applications», the authorization of any application you connected: it is cut off at once, with all its tokens. The assistant itself may revoke its credentials through the protocol's revocation endpoint, and resetting your password revokes every authorization of your account. You may also ask us in writing at support@custodio.legal to revoke the authorization of any application, and we handle it without delay. Revoking cuts off what leaves from that moment on; it does not recover what the assistant already received, which remains under its provider's policy: the rights over that copy are exercised before that provider.