Custodio Legal respects the personal data and information provided by its current, past, and potential clients. This Personal Data Protection Policy establishes the purposes, measures, and procedures for our databases, as well as the mechanisms available to data holders to know, update, rectify, delete provided data, or revoke the authorization granted with the acceptance of this policy, in accordance with Ley Estatutaria 1581 de 2012, Colombia's data protection statute, and Decreto 1377 de 2013, with Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP) and its Decreto Ejecutivo 904, with the Dominican Republic's Ley núm. 172-13, with Costa Rica's Ley N° 8968, on the protection of the person with regard to the processing of their personal data, and its Reglamento (Decreto Ejecutivo N° 37554-JP), and with Uruguay's Ley N° 18.331, on personal data protection and the «Habeas Data» action, as amended by Ley N° 19.670, and with Argentina's Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001, and with Brazil's Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais (LGPD), the seven countries in which we offer the service. The rules are named as their own official gazettes publish them, in Spanish, so you can check each one against the source; the gloss that follows a name the first time it appears says what it is.
If your data lives in the matter of a firm that uses Custodio, you can exercise your rights here: Exercise your habeas data rights
1. Data Controller and Data Processor
Custodio Legal, identified with NIT 1057602936, with domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia, provides the service. You can contact us at [email protected] or by phone at +57 333 431 8597; the area that handles queries and claims is the Personal Data Protection Area, at that same email address.
This policy distinguishes two situations, because the law gives you a different counterpart in each one:
- (i) When you use the platform -you sign up, belong to a firm, work in it-, Custodio Legal is the controller of your personal data: it decides what it is processed for and answers to you for it.
- (ii) When your personal data appears in a matter a firm manages through the platform -as a client, opposing party or interested party in a proceeding-, the controller is that firm, which decided to process it and must have obtained the authorization the law requires, and Custodio Legal acts as processor: it processes that data on the firm's behalf, under the service contract and its instructions, and does not decide on it on its own. If you write to us to exercise a right over data held in a matter, we forward your request to the responsible firm within the following two business days, tell you we did, and give you its contact details so you can approach it directly.
Collected data will be processed legally, lawfully, confidentially, and securely, respecting the principles of purpose, freedom, truthfulness, transparency, restricted access, security, and confidentiality.
2. Purpose of Processing
The processing of personal data has the following purposes:
- a) Provision of contracted legal and administrative management services.
- b) Managing the contractual relationship with clients, lawyers, and collaborators.
- c) Sending service-related communications, updates, and legal notifications.
- d) Billing, collection, and accounting management.
- e) Conducting satisfaction surveys and service improvement.
- f) Compliance with legal obligations and requirements from competent authorities.
- g) Fraud prevention and platform security.
- h) Answering the one-off lookup of a public court record asked for by a person with no account, in the countries where the Service offers that lookup.
The emails we send you are of two kinds, and what separates them is what each one rests on:
- Service emails. They tell you the state of your own account —that your email address is unconfirmed, that you have not created your first matter yet, that a matter of yours has no active judicial surveillance— and they teach you to use what you contracted, including what the Artificial Intelligence described in Section 14 does and does not do. They rest on the contractual relationship and on purposes a), b), c) and e) of this section, and they do not depend on any advertising authorization. They are the ones that set your account up: the first remind you to confirm your address, in the hours after you register, and the rest go out over the fifteen (15) days following that confirmation. Each one of them carries its unsubscribe link.
- Promotional emails. They offer you a higher plan, a discount or a feature you did not contract, or tell you about product news. They are advertising and go out only if you ticked the optional box of Section 4.
No service email offers you a plan, a discount or a feature you have not contracted: the moment a message did, it would be promotional and would ask for that box.
Looking up a court record with no account. This policy describes that lookup before the site turns it on, and that is on purpose: we would rather tell you what we will do with your data before we process it than afterwards. When the lookup is available —it starts with Uruguay and Costa Rica, and each country offers it only if that country's annex says so— this is how it works:
- What we process. The case number you type, the country you pick, and your IP address. The IP address is used only to limit how many lookups come from one place; not to identify you, not to recognize you if you come back, and not to build a profile of you.
- An anti-abuse check before we look anything up. So that an automated program cannot drain this free lookup, before asking the portal we check that the person looking up is a person. That check is run by Cloudflare, which is already the network all of this site's traffic passes through and appears in our list of subprocessors. To run it, your browser talks directly to Cloudflare, which processes — according to what Cloudflare publishes in its Turnstile privacy policy, consulted on September 19, 2026 — your IP address, the technical fingerprint of your encrypted connection, the identification of your browser and this site's public key; Cloudflare states that it cannot directly identify an individual from those signals. We get exactly one thing back: whether the check passed. We do not send Cloudflare the number you looked up, nor any other datum of the lookup. That check writes no cookie, according to what Cloudflare publishes and the configuration we have it enabled with; we have not verified whether it uses any other browser storage, and so we do not claim that it does not.
- What we do not ask you for. Not your name, not your email, not your ID document, not an account. The lookup is by case number and never by a person's name: there is no way to ask this site who has cases. Nor do we write any new cookie for this lookup; the cookies the site uses are the ones declared in the Cookie Policy, and none of them stores what you looked up.
- On what legal ground. Your country's annex states it: it is that country's rule that allows —and on what condition— processing without your consent a datum a judiciary already publishes. This lookup is not offered in a country whose annex does not sustain it.
- What we keep, and for how long. The lookup is written into an ephemeral row that lives at most two (2) hours, and an automatic sweep deletes it when it expires. That row carries no datum that identifies you: not who asked, not from where. Of what the portal answers we keep less than the portal publishes: the parties are masked and only the latest filing is kept, not the history.
- No Artificial Intelligence. Nothing you look up is sent to the text generation provider of Section 14, or to any other Artificial Intelligence provider. The lookup is not summarized, not analyzed, and trains nothing.
- The parties' data is neither yours nor ours. Who decides to publish it is the judiciary that holds the case file. We do not republish it as it stands: we mask it, and we do not keep it beyond those two hours.
3. Rights of Data Subjects
As the holder of your personal data, you have the following rights, which you may exercise free of charge and at any time:
- (i) ACCESS: Know what personal data we process about you, the purpose of processing, and who we share it with.
- (ii) RECTIFICATION: Update and correct partially accurate, incomplete, or outdated data.
- (iii) CANCELLATION/DELETION (Habeas Data): Request deletion of your data when it is no longer necessary for the purpose that justified its processing, or when you have revoked your consent, subject to legally mandated retention obligations.
- (iv) OBJECTION: Object to the processing of your data for marketing, profiling, or automated decision-making purposes.
- (v) PORTABILITY (LOPDP Ecuador, Art. 17; LGPD Brazil, Article 18, V, «de acordo com a regulamentação da autoridade nacional, observados os segredos comercial e industrial»): Download a structured, machine-readable copy of your account data -your personal information, your consent history, and the record of your own actions on the platform- from 'My account > Your privacy'. This automatic download does not currently include the matters or documents your firm manages about you; to access that information, submit an access request through the channels in Section 7. If your data is held in a matter and you are not a user of the platform, Section 1 (ii) applies: the controller is the firm, and we forward your request to it.
- (vi) File complaints with your country's supervisory authority, where your country has one. Which one it is, how to write to it and what it requires of you before you turn to it is stated by your country's annex, which also says whether your country created none and what route is left to you then.
- (vii) Withdraw consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
4. Authorization and Consent
The processing of personal data requires the free, prior, express, and informed consent of the data holder. By registering on the platform and accepting this policy, you declare that:
- (i) The data provided is truthful and accurate.
- (ii) You have the legal capacity and authority to authorize its processing.
- (iii) You understand the purposes of the processing.
- (iv) You have been informed of your rights as a data holder.
Authorization may be revoked at any time following the procedure established in this policy.
The authorization to receive promotional emails is a separate, optional and unticked box: silence and inaction do not count as a yes, and leaving it unticked limits no feature of the platform for you. What you decide with it are the promotional messages described in Section 2; the service emails of that same section do not depend on it, because they rest on the contractual relationship. You may withdraw it whenever you want from the unsubscribe link carried by the promotional emails and by the account set-up service emails described in Section 2, or from "My account > Your privacy", and the withdrawal takes effect from the moment we receive it.
5. Information Security
We implement technical, administrative, and organizational security measures to protect your data:
- (i) AES-256-GCM encryption of the most sensitive data we store: document number, address and phone; description, objective and internal notes of matters; and the content of your conversations with the artificial intelligence assistant.
- (ii) Encrypted transmission over TLS.
- (iii) Role-based access control (RBAC).
- (iv) Audit records of the relevant actions over your data, kept for the term Section 11 declares.
- (v) Database backups on the infrastructure of the hosting provider described in Section 10.
- (vi) Watching for improper access patterns, such as bursts of failed sign-in attempts or unusual downloads of information.
These measures answer what Ley 1581 de 2012, the LOPDP, Article 5, paragraph 5, and Article 13, paragraph 2, of the Dominican Republic's Ley núm. 172-13, Article 10 of Costa Rica's Ley N° 8968 — which orders that «las medidas de índole técnica y de organización necesarias para garantizar la seguridad de los datos de carácter personal» be adopted — and Article 12 of Uruguay's Ley N° 18.331, in the wording given to it by Article 39 of Ley N° 19.670, which requires the controller and the processor to adopt «privacidad desde el diseño, privacidad por defecto, evaluación de impacto a la protección de datos, entre otras» and to demonstrate that they are effectively implemented — Article 9 of Argentina's Ley 25.326, which requires «las medidas técnicas y organizativas que resulten necesarias para garantizar la seguridad y confidencialidad de los datos personales» to be adopted, which Article 25, subsection b), of Decreto 1558/2001 makes enforceable against the processor as well, and Article 46 of Brazil's Lei nº 13.709/2018 (LGPD), which requires the «agentes de tratamento» to adopt «medidas de segurança, técnicas e administrativas aptas a proteger os dados pessoais de acessos não autorizados e de situações acidentais ou ilícitas de destruição, perda, alteração, comunicação ou qualquer forma de tratamento inadequado ou ilícito», and which reaches the processor too because Article 5º, IX of that same law defines «agentes de tratamento» as «o controlador e o operador», and follow industry good practice.
If we detect a security incident that puts your personal data at risk, we notify you without undue delay and inform your country's supervisory authority, where your country has one to present it to. Which authority we inform, within what term, within what term we notify you, and whether that term is set by a rule or adopted by our own decision, is stated by your country's annex.
6. Attention Channel (Habeas Data)
To exercise your rights as a data holder, you can contact us through:
- (i) Email: [email protected]
- (ii) Through your account in 'My account > Your privacy'.
Which procedures your law distinguishes, within how many days we answer each of them, from when they are counted and what extension they admit is stated by your country's annex, each term with the rule that sets it or with the warning that it is ours and not the law's.
While we handle a claim, the corresponding record is flagged as "claim in process" within the following two business days, so that no one treats it as if it were unchallenged. If your claim is incomplete, we tell you within the following five (5) business days so you can complete it; if two months pass without your replying, we understand that you withdrew it, and you may file it again whenever you like. We do those three things the same way in all seven countries.
7. How to Exercise Your Rights (ARCO)
You can exercise your rights to Access, Rectify, Cancel, and Oppose directly from your account in 'My account > Your privacy'. You can also send a written request to [email protected] indicating:
- (i) Your full name and identity document.
- (ii) Description of facts and request.
- (iii) Physical or electronic address for notifications.
- (iv) Supporting documents if applicable.
8. Sensitive Data and Data of Minors
Custodio Legal may process sensitive data only when strictly necessary for the provision of legal services and with your express authorization. Sensitive data includes data revealing racial or ethnic origin, political orientation, religious convictions, union membership, health data, sexual life, and biometric data. This data will receive enhanced protection.
A judicial case file may contain sensitive data and also data of children and adolescents. Custodio Legal neither asks you for that data nor collects it on its own: it arrives at the platform inside the case file the firm manages, and it is the firm -as controller- that must have obtained the authorization the law requires to process it. You are not obliged to authorize the processing of sensitive data and no one may condition a service on your doing so; data of minors may only be processed respecting their best interests and their fundamental rights, and it is their legal representative who exercises their rights. We process it with the same security measures of Section 5, without using it for any purpose other than managing the matter it appears in.
9. International Data Transfer
Your data may be transferred and processed in third countries. Our hosting and infrastructure provider, transactional email provider, payment gateway, technical monitoring provider, the network and protection provider for the site and the application, and the vector representation (embeddings) provider, all described in Section 10, are located in the United States, and so is Google, which is not a processor but an independent controller and is covered by Section 15. The Artificial Intelligence text generation provider described in Sections 10 and 14 is domiciled in the Netherlands and declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model.
Those destinations are the same for the data subjects of every country in which we offer the Service. What changes with your country is the safeguard that backs each sending: whether your law recognizes countries with an adequate level of protection and which ones they are, whether sending to a processor counts as a transfer at all, and which article permits the one that does. Your country's annex states that, with the rule that sustains it, in its international transfer section.
Two things hold the same in all seven countries, and that is why they are here and not in an annex: by accepting this policy you give your express and informed consent to the transfer, knowing the destination and which safeguard backs it; and Section 14 (iii) states, provider by provider, which guarantee is actually written down and which is not.
10. Data Processors
To provide our services, we share data with third-party data processors who act under our instructions. The full list, with what each one receives, the safeguard each transfer travels under and the retention each one publishes, is published separately and reviewed at least once a year: it is our list of subprocessors, and the ones this section enumerates are the same ones. Each one incorporates into its terms of service a data processing agreement that we accept when contracting it and that obliges it to process your data on our behalf and not for its own purposes. Not every third party we exchange data with is a processor: Google is not, which is why it is not on this list but in Section 15.
- (i) Railway (United States) - Hosting of the platform: the servers, the database, the task queue and their backups. It is the processor that hosts all the data the platform stores.
- (ii) Resend (United States) - Transactional email delivery: it receives your email address and the content of the notices.
- (iii) Polar.sh (United States) - Payment gateway and billing: it receives the contact email and the firm's name.
- (iv) Nebius B.V., a Dutch company domiciled at Schiphol Boulevard 165, 1118 BG Schiphol, the Netherlands, which operates the Nebius Token Factory service - Text generation with the GLM-5.3-Flash model for the Artificial Intelligence features: document drafting, questions with citations over your documents, and the fact extraction and matter reevaluation that run without a click under Section 14 (viii). That service's terms are governed by the law of the Netherlands and its disputes are submitted to the courts of Amsterdam. The provider declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model, states each model's country in its catalog, and publishes the list of the sub-processors it appoints.
- (v) Voyage AI (United States) - Generation of the vector representations (embeddings) of your document text, which make the semantic search behind the questions with citations (Q&A) feature possible.
- (vi) Alternate text generation providers, registered in the platform and carrying no traffic today: Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD., domiciled at 10 Anson Road #26-03, Singapore, which operates the z.ai service. Neither receives any of your data: the platform keeps their connections configured so we can fall back to them if the provider in item (iv) becomes unavailable. Activating one would change the processor and the jurisdiction of the transfer, so we would not do it without raising the version of this policy and asking you for a new authorization, as required by Section 12.
- (vii) Sentry (United States) - Technical error monitoring: it receives the route where the error occurred and your internal user identifier; before each event is sent we strip your email, your name and your IP address.
- (viii) Cloudflare (United States) - Delivery and protection network for the site and the application: all traffic between your browser and us goes through its network, so it processes in transit the IP address and the metadata of each connection; it also controls access to our internal documentation.
We do not claim to have negotiated with any of them clauses beyond those their own terms incorporate, nor to hold a separately signed contract, nor that they hold security certifications we have audited: Section 14 (iii) states exactly what is written down for the Artificial Intelligence providers. We do not keep the original file you upload to a matter: it is processed transiently to extract its content and is then deleted. What we retain is the extracted text, so the matter can be searched and consulted; the file itself is never shared with these processors. The optical character recognition (OCR) of that text runs on our own service, within our own infrastructure, and is never sent to an external provider.
The provider of an external assistant your firm connects through the MCP protocol, if it connects one, is not on this list or on the list of subprocessors: it does not process data on our behalf or under our instructions. Section 16 says who chooses it and who answers for it.
11. Data Retention and Deletion
We retain your personal data for as long as a relationship exists with the firm that provides you the service and for as long as the legal and contractual obligations that justify keeping it remain in force. We do not delete data automatically based on the passage of time: it is deleted or anonymized when appropriate, for example when we approve a cancellation request from you (Section 3, Habeas Data). When your firm's account ends, we delete or anonymize the data the platform holds for that firm within the ninety (90) days following termination, unless a legal retention obligation applies. There is one deliberate exception: the records of your consent, of our audits, and of your own ARCO requests survive that deletion, even after the rest of your data is anonymized, because they are the evidence that we comply with this policy. We do not keep them indefinitely, nor because we decide to: how long each one is kept, and the rule that requires or limits it, is stated by your country's annex in its «Retention After Termination» section, which is the text that governs over this Section.
The lookup with no account is kept apart, and barely at all. The ephemeral row described in Section 2 waits for no termination and for no request of yours: it lives at most two (2) hours and an automatic sweep deletes it when it expires. It carries no identifier of whoever asked, so nothing is left to anonymize afterwards.
12. Validity and Modifications
The version of this policy in force is 0.0.24, effective as of September 22, 2026. Version 0.0.24 adds Section 16, which describes the channel through which your firm may connect an external Artificial Intelligence assistant to Custodio Legal through the MCP protocol: who authorizes it and how, which data leave towards that assistant and when, that the assistant's provider is not our processor and that Custodio Legal is not responsible for the processing that provider carries out, what we keep of each connection and how it is revoked; and it adds to Section 10 that this provider is not on its list. The channel already existed and Section 22 of the Terms of Service governed it; this policy did not say so. Because the change states whom your data may reach, we ask you for a new authorization over this text, on the same criterion with which 0.0.7 asked for one when it described Google as an independent controller, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.23, which was in force from September 19, 2026. Version 0.0.23 states in Section 2, inside the no-account case lookup that 0.0.22 had just described, that before we ask the portal an anti-abuse check is run, and says who runs it and what it processes: it is run by Cloudflare —which already was, and from before this version, the network all of this site's traffic passes through, and already appeared on the list of subprocessors—, your browser talks to it directly, and for that check it processes your IP address, the technical fingerprint of your encrypted connection, the identification of your browser and this site's public key, signals from which Cloudflare states it cannot directly identify an individual. It also states what does not happen: we do not send it the number you looked up or any other datum of the lookup, and that check writes no cookie. What we did not verify —whether it uses any other browser storage— is stated as unverified rather than asserted. That purpose processes no data of a registered data subject: whoever looks up has no account, and none of the data you gave us enters it. It does not change who processes your data, nor where, nor on what ground, nor for what, nor any deadline of yours. That is why we do not ask you for a new authorization and the one you gave over 0.0.22 —or over 0.0.21, 0.0.20, 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.22, which was in force from September 19, 2026. Version 0.0.22 describes in Section 2 a new purpose —the one-off lookup of a public court record asked for by a person with no account— and states what is processed in it: the case number that person types, the country they pick, and their IP address, the latter only to limit how many lookups come from one place. The legal ground for that lookup is declared by each country's annex, which is where the rule that sustains it lives; Section 11 states that the row the lookup writes lives at most two (2) hours and an automatic sweep deletes it, and Section 14 adds that nothing of that lookup goes out to any Artificial Intelligence provider. This version is published before the lookup is turned on, and not after. That purpose processes no data of a registered data subject: whoever looks up has no account, and none of the data you gave us enters it. It does not change who processes your data, nor where, nor on what ground, nor for what, nor any deadline of yours. That is why we do not ask you for a new authorization and the one you gave over 0.0.21 —or over 0.0.20, 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.21, which was in force from September 18, 2026. Version 0.0.21 writes into Section 2 the distinction between service emails —those that tell you the state of your own account and teach you to use what you contracted, while your account is being set up— and promotional emails, and details in Section 4 that the box authorizing the latter is separate, optional and unticked, that leaving it unticked limits no feature for you, and that both kinds carry an unsubscribe link. No processing is added, and it does not change who processes your data, or where, or on what basis, or for what, or any term: purposes a), b), c) and e) of Section 2 are the same ones that were already there, and what changes is that the text says which of them sustains each kind of email. That is why we do not ask you for a new authorization and the one you gave over 0.0.20 —or over 0.0.19, 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.20, which was in force from September 16, 2026. Version 0.0.20 details in Section 14 (ii) what the questions with citations and the document drafting send to the text generation provider, and details it only about the matter you are working on: its record, its state, its timeline, its attention items, the extracted facts with the fragment that supports them, the metadata of its documents, the corrections your firm approved in that same matter and the entries of your firm's memory typed in by hand or born in it. They are data of the same matter, they go to the same provider and the reevaluation of item (viii) already processed them. No processing is added, and it changes not who processes your data, nor where, nor on what basis, nor for what, nor any term; and it remains true that no feature sends data of another matter. That is why we do not ask you for a new authorization and the one you gave over 0.0.19 —or over 0.0.18 or 0.0.17— still covers this text, with your record intact. It replaces version 0.0.19, in force since September 16, 2026. Version 0.0.19 stops listing the case and service summary and the deep analysis among the Artificial Intelligence features, because the platform no longer runs them. It does so in Section 10 (iv) and in Section 14 —its heading and items (i), (ii) and (viii)—, and what remains named is what runs: document drafting and questions with citations, which you start, and the indexing, the fact extraction and the matter reevaluation, which run without a click and which item (viii) already described. No processing is added, and it changes not who processes your data, nor where, nor on what basis, nor for what, nor any term: what changes is that the text stops describing two features that do not exist. That is why we do not ask you for a new authorization and the one you gave over 0.0.18 —or over 0.0.17— still covers this text, with your record intact. It replaces version 0.0.18, in force since September 16, 2026. Version 0.0.18 corrects two sentences the text itself contradicted. The first is in Section 13: it said we also publish an English translation of this policy, when since September 16, 2026 we publish a Portuguese one as well; the clause now names both, and the Spanish version still prevails. The second is in Section 5 (iv): it said the audit records «are never deleted», which is exactly what 0.0.12 removed from Section 11 when it tied that retention to the term your country's annex declares; it now refers to that term, as Section 11 does. It changes not who processes your data, nor where, nor for what, nor any term: what changes is that the text stops saying two different things about the same retention. That is why we do not ask you for a new authorization and the one you gave over 0.0.17 —hours earlier— still covers this text, with your record intact. It replaces version 0.0.17, in force since September 16, 2026. Version 0.0.17 adds Brazil: the service is now offered in seven countries and this policy also names Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais (LGPD) —, with the Brazilian annex that says what they mean for you: the ANPD as the supervisory authority, a regulatory agency since Lei nº 15.352, de 25 de febrero de 2026; the fifteen (15) calendar days within which we handle your rights, with the immediate confirmation and simplified access of Article 19, I; the three (3) business days of the incident notice of Resolução CD/ANPD nº 15/2024 and the twenty-four (24) hours within which we undertake to notify you; and the international transfer backed by the cláusulas-padrão contratuais of Annex II of Resolução CD/ANPD nº 19/2024, adopted whole and unaltered, with a Brazilian forum. It also names Article 46 of that law among the rules the security measures of Section 5 answer to, adds the portability of Article 18, V to right (v) of Section 3, and corrects to seven the two lines that counted six countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization over this text, on the same criterion 0.0.15 used when Argentina was added and 0.0.14 when Uruguay was. It replaces version 0.0.16, which was in force since September 13, 2026. Version 0.0.16 changes how the data controller is identified in Section 1: where it used to read that «Custodio Legal is the trade name under which» a natural person provides the service, the controller is now Custodio Legal, identified with the same NIT 1057602936 and with the same domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia. The identification number, the address, the phone number and the contact email are the same, and the area that handles your queries and claims is still the Personal Data Protection Area. It changes neither who processes your data, nor where, nor what for, nor any deadline, nor any processor. Even so we ask you for a new authorization of this text, because the identification of the controller is part of what you authorize —it is who you exercise your rights before— and the platform would rather ask again than take as given an authorization made over a different wording; the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.15, in force from September 13, 2026. Version 0.0.15 adds Argentina: the service is now offered in six countries and this policy also names Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001, with the Argentine annex saying what they mean for you — the AAIP as supervisory authority, the registration of the database with the Registro Nacional de Bases de Datos, the ten calendar days for access and the five business days for rectification, erasure and blocking, and why that regime has no right to object, no portability, no data protection officer and no statutory duty to notify a breach. It also names Article 9 of that law among the rules the security measures of Section 5 come from, with Article 25, subsection b), of Decreto 1558/2001 extending it to the processor, and corrects to six the two lines that counted five countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, on the same criterion 0.0.14 applied when it added Uruguay and 0.0.9 when it added Costa Rica. It replaces version 0.0.14, in force from September 12, 2026. Version 0.0.14 adds Uruguay: the service is now offered in five countries and this policy also names Ley N° 18.331, on personal data protection and the «Habeas Data» action, and its amending Ley N° 19.670, with the Uruguayan annex saying what they mean for you — the URCDP as supervisory authority, the registration of the database before it, the five business days within which we handle your rights and the three clocks of a security incident. It also names Article 12 of that law, in the wording of Ley N° 19.670, among the rules the security measures of Section 5 come from, and corrects to five the two lines that counted four countries. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, on the same criterion 0.0.9 applied when it added Costa Rica: the platform would rather ask again than take as given an authorization made over a different wording, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.13, in force from September 11, 2026. Version 0.0.13 changes neither who processes your data, nor where, nor what for, nor any deadline: it takes the list of processors that Section 10 and Section 14 (iii) wrote out in prose and publishes it separately, as our list of subprocessors, with the same information and a declared review at least once a year. The processors are the same, the safeguards are the same and what is sent to each one is the same: what changes is where the list can be read, and that a data processing agreement can now cite it. That is why we do not ask you for a new authorization, and the one you gave over 0.0.12 — or over any of the earlier ones already carried forward — still covers this text, with your record intact. It replaces version 0.0.12, in force from September 10, 2026. Version 0.0.12 corrects what Section 11 promised beyond what the country annexes allow: it said the records of your consent, of our audits and of your ARCO requests «are never deleted», while the annexes —which have governed over this trunk since 0.0.8— tie them to a rule and to a term. The Dominican annex binds them to the limitation period of the liabilities arising from the processing (Ley núm. 172-13, Article 15, the Dominican personal data protection statute) and the Costa Rican one to the ten-year ceiling of Article 11 of the Reglamento to Ley N° 8968, Decreto Ejecutivo N° 37554-JP. «Never» is longer than either of those allows, so the trunk stops setting that window and refers to the one in your country's annex, where it is written with the rule that sustains it. It changes neither who processes your data, nor where, nor what for, nor the two windows your annex publishes —notice sixty (60) days after the relationship ends and deletion at ninety (90)—: what changes is that this trunk stops promising a retention longer than your own law admits. That is why we do not ask you for a new authorization, and the one you gave over 0.0.11 — or over 0.0.10 or 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.11, in force from September 10, 2026. Version 0.0.11 corrects two places where the text contradicted itself. The first: Sections 6 and 9 still counted three countries when there have been four since 0.0.9 — the very version that names four of them in the preamble, in Section 12 and in Section 13. The second lives only in the English translation, and it is the one that matters for checking us: the rules of Colombia and Ecuador were translated — «Statutory Law 1581 of 2012», «Executive Decree 904» — next to those of the Dominican Republic and Costa Rica, which were transcribed. A translated rule cannot be checked against the official gazette that published it. From this version the four are named as their own source publishes them, in Spanish, with an English gloss the first time, which is what the eight country annexes already did. Not one piece of data, one destination, one deadline or one processor changes: that is why we do not ask you for a new authorization, and the one you gave over 0.0.10 — or over 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.10, in force from September 10, 2026. Version 0.0.10 completes with the Dominican and Costa Rican rules a line that enumerated only two countries from before there was a third: Section 5 now names, alongside Law 1581 and the LOPDP, Articles 5 and 13 of Ley núm. 172-13 and Article 10 of Ley N° 8968 as the rules the security measures we already applied come from. It changes not one measure, nor who processes your data, nor where, nor any deadline: what changes is that your own rule is written with its article instead of being covered by a general formula. That is why we do not ask you for a new authorization: the one you gave over 0.0.9 still covers this text, and your authorization record is kept intact. It replaces version 0.0.9, in force from 10 September 2026. Version 0.0.9 adds Costa Rica: the service is now offered in four countries and this policy also names Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP, with the Costa Rican annex saying what they mean for you. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, because the platform would rather ask again than take as given an authorization made over a different wording, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.8, in force since 9 September 2026. Version 0.0.8 changes not one piece of data, not one destination and not one deadline: it splits the same text between this trunk and your country's annex. Since the three annexes were published, the supervisory authority, the deadlines for handling your rights, the incident notice and the basis of the international transfer were stated twice, once here in general terms and once in the annex with the rule that sustains it. This trunk now states the rule that held the same in the three countries offered at the time and refers to the annex, and the annex states what your law makes concrete. What you authorize is the same; what changes is that it is written once, in the document that cites your rule. It replaces version 0.0.7, in force since 9 September 2026, which corrects Google's legal figure: until 0.0.6 this policy listed it among the data processors of Section 10, under a heading stating that every third party on that list acts under our instructions and holds a data processing agreement with us. It does not. The two uses we make of it -sign-in and the public-site Ads tag- are governed by terms between independent controllers, which the new Section 15 cites by version and explains: what changes in the safeguard of the transfer, that no instrument of theirs obliges them to notify us of a breach, and before whom you exercise your rights. No data sent to it and no destination changes: what changes is what this policy claimed about it, which was not accurate. It replaces version 0.0.6, in force from 4 September 2026, version 0.0.5, which was in force from September 2026, version 0.0.4, which was in force from September 2026, version 0.0.3, which was in force from August 2026, version 0.0.2, which was in force from August 2026, and version 0.0.1, which was in force from February 2026. Version 0.0.6 named, one by one, data processors that earlier versions described generically or did not mention -the hosting provider, the email provider, the payment provider, the monitoring provider, Google and Cloudflare-, declares our role as processor over the data held in a firm's matters, and corrects the response deadlines, the incident notification and the safeguards for each destination. Since the list of processors you authorize changes, the platform will ask you for a new authorization of this text, and your previous authorization record is kept intact as evidence of what you authorized at the time. Version 0.0.5 only declared Zero Data Retention with the text generation provider, changing neither the processor nor the jurisdiction, which is why it did not ask for a new authorization; version 0.0.4 changed the processor that generates the text for the Artificial Intelligence features and the jurisdiction of that transfer -from JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore) to Nebius B.V. (the Netherlands)- and did ask for one. Each version remains in effect until replaced by a new one. We reserve the right to modify this policy at any time. We will notify you of any material changes by email or through a prominent notice on the platform at least 15 days in advance. When the change alters what you authorize -who processes your data, where, or for what-, notice alone is not enough: the platform will ask you for a new authorization of the text in force before you can continue, and the record of your previous authorization is kept intact. In every other case, continued use of the service after notification constitutes acceptance of the changes.
13. Applicable Legal Framework and Language
This policy is governed by Ley Estatutaria 1581 de 2012 and Decreto 1377 de 2013 (Colombia), by the Ley Orgánica de Protección de Datos Personales and its Decreto Ejecutivo 904 (Ecuador), by Ley núm. 172-13, on the comprehensive protection of personal data (Dominican Republic), by Ley N° 8968 on the protection of the person with regard to the processing of their personal data and its Reglamento, Decreto Ejecutivo N° 37554-JP (Costa Rica), and by Ley N° 18.331, on personal data protection and the «Habeas Data» action, and its amending Ley N° 19.670 (Uruguay), and by Ley 25.326, on the protection of personal data, and its implementing Decreto 1558/2001 (Argentina), and by Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais, LGPD (Brazil), the seven countries in which we offer the service; each data holder is covered by the regulations of their country of residence, which that country's annex details. This policy is drafted in Spanish and we also publish English and Portuguese translations so you can read it in those languages; in case of any discrepancy between the versions, the Spanish version prevails.
14. Artificial Intelligence (AI) Processing
Custodio Legal offers Artificial Intelligence features (currently: document drafting and questions with citations over your documents, known as Q&A; the matter state and the facts extracted from its documents run without a click and are described in item (viii)) that are optional and user-initiated. None of them takes part in the lookup with no account described in Section 2: nothing of that lookup goes out to any Artificial Intelligence provider. AI processing is governed by the following principles:
- (i) LEGAL BASIS: Express consent, given in two ways depending on what triggers the operation. For the features you start yourself -document drafting and questions with citations- consent is given by executing each operation on the case or service you are working on, a voluntary act that draws down your firm's token allowance. For the processing that runs without a click, listed one by one in item (viii), it is given by accepting this policy -which describes them- and by uploading the document or updating the matter that triggers them. In both cases the processing is limited to what is necessary to provide the contracted service.
- (ii) DATA MINIMIZATION: Only what the requested operation needs is sent to each provider, and what is sent depends on the feature. For the document drafting we send the text of the active case or service -description, parties, a bounded number of the most recent case activities and the corrections your firm approved in that same matter-, and we do NOT send the file attachments. For the questions with citations (Q&A) feature we DO send the content of your documents: when your plan enables it, once optical character recognition (OCR) of a document finishes its text is sent to Voyage AI to generate its vector representation, and when you ask a question the assistant looks up, only within the matter you are asking about, the most relevant document fragments, the matter's record (its description and the names of its person in charge, its parties and its collaborators), its state, its timeline, its attention items, the extracted facts with the fragment that supports them and the metadata of its documents (name, type and page count), as well as the entries of your firm's memory that someone typed in by hand or that were born in that same matter, and sends them to the text generation provider together with your question, the latest messages of the conversation and the citations the answer must carry. For fact extraction, which runs on its own once a document finishes processing, a bounded extract of the text extracted from that document is sent to the text generation provider to identify parties, dates, amounts, identifiers, obligations and deadlines. For the matter reevaluation we send those already-extracted facts together with the data of the case or service and its case activities, not the full text of the documents. The concrete caps -how many case activities and how many characters- are set by the platform's current configuration and may change without changing what you authorize: in no case is more sent than the operation you asked for needs. No feature ever sends metadata of other cases, information about other clients, or data from other firms.
- (iii) AI PROVIDERS AND WHAT GUARANTEE EACH ONE CARRIES: The full list of who processes data on our behalf lives in our list of subprocessors. Text generation is provided by Nebius B.V. (the Netherlands), which operates the Nebius Token Factory service, with the GLM-5.3-Flash model; the vector representations (embeddings) behind semantic search are provided by Voyage AI (United States); Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore, the z.ai service) are registered as alternate text generation providers and receive none of your data today. We tell you, guarantee by guarantee, what is written down and what is not: (a) the text generation provider incorporates a data processing agreement into its own terms of service, with the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 for transfers outside the European Economic Area, and states in its published legal guide that customer content is not used to train or fine-tune models (verified on 3 September 2026); the embeddings provider applies the opt-out we have contracted; (b) traffic to all of them travels encrypted in transit over TLS, which is how they publish their interfaces; (c) the text generation provider publicly claims ISO 27001, ISO 27701 and SOC 2 Type II certifications and publishes its sub-processor list, but that is its own claim, which we have neither audited nor checked against the certificates, and we do NOT claim to have negotiated clauses with it beyond those its own terms incorporate, nor to hold a separately signed contract.
- (iv) RETENTION AT PROVIDER: Zero Data Retention is enabled on our organization with the text generation provider as of 4 September 2026. According to what that provider publishes, with Zero Data Retention enabled the inputs (the text sent to it) and the outputs (the text it returns) are not stored on its systems after each request is processed, are not used for speculative decoding, and are not used to train, fine-tune, or improve any model, whether its own or a third party's; the option applies at the organization level and covers all of its projects and endpoints (Nebius published legal guide, "Legal Quick Guide", consulted on 4 September 2026 on the provider's documentation site). We also tell you, with the same precision, what that guarantee does NOT settle: it is a statement published by the provider and not a control we have audited; it operates going forward and does not reach submissions made before 4 September 2026, over which the default processing of its terms of service (version of 20 August 2026) continued to apply, keeping inputs and outputs to train small models used for speculative decoding; its published documents do NOT say whether Zero Data Retention reaches any records the provider may keep to detect abuse of the service, nor whether it applies in the same way to responses delivered as a stream, so we claim neither of those two things; and enabling it is up to us, so if we ever disabled it we would update this section before doing so. The embeddings provider applies zero retention through the opt-out we have had active since 12 August 2026, which operates going forward and not over earlier submissions.
- (v) INTERNATIONAL TRANSFER: AI processing occurs on servers located outside the countries in which we offer the Service. Text generation is contracted and billed by Nebius B.V., domiciled in Schiphol (the Netherlands), under Dutch law and with the courts of Amsterdam as the forum; the provider declares that it runs inference in data centers in the European Union, Israel or the United States depending on the model. Embeddings are processed in the United States. The safeguard that backs each of those sendings is the one in Section 9: your country's annex states it, destination by destination and with the rule that sustains it.
- (vi) AUTOMATED DECISIONS: AI outputs are supporting material; no legal or contractual decisions are made fully automatically. The professional judgment of the attorney is irreplaceable (see Terms of Service, Section 17).
- (vii) APPLICABLE ARCO RIGHTS: You may exercise access, rectification, deletion, and opposition rights over data processed by AI. Deletion in our own systems is immediate. For the text generation provider, the Zero Data Retention described in item (iv) means that, as of 4 September 2026 and according to what it publishes, no inputs or outputs remain stored to be deleted once each request has been processed. What we still cannot offer you is a contractual deletion deadline of our own or enforceable deletion evidence: that guarantee is a published statement of the provider that we have not audited, and it does not reach submissions made before that date. If you ask us through the channels of Section 6, we pass the request on to the provider and tell you its answer.
- (viii) WHAT RUNS ON YOUR CLICK AND WHAT RUNS ON ITS OWN: The features that produce a result for you to read -document drafting and questions with citations- require an express click by you on the case or service being worked on, so not using them is equivalent to authorizing no such processing at all. Three kinds of processing do run without a click, always over data from your own firm's matters and never over another firm's: (a) the indexing behind questions with citations (Q&A), which runs when a document finishes optical character recognition (OCR) if your plan enables it; (b) the extraction of facts from the document just processed, which identifies parties, dates, amounts, identifiers, obligations and deadlines; and (c) the matter reevaluation, which refreshes its state and its attention items when a document arrives, when you edit the case or service, or when a query to the judicial portal brings in a new case activity. All three operate over the documents and matters your firm uploads or updates under its declaration that it holds the authorization of the data subjects whose data they contain: the firm is the controller of that data, as Section 1 (ii) says, and Custodio Legal processes it on the firm's behalf. All three consume your firm's monthly token allowance and stop when that allowance runs out. Which features exist for your firm is also determined by your plan. If you do not want this automatic processing to run over your firm's matters, the firm owner can turn each one off from the firm settings, under 'My practice > Settings > AI without a click': the change takes effect immediately and is recorded. Turning the Q&A indexing off also erases the fragments already indexed. You may also object by writing to [email protected], and that route remains available: the objection is handled under the procedure and within the deadlines of Section 6.
- (ix) SENSITIVE DATA: You must not deliberately send sensitive third-party data (health, sexual orientation, ethnic origin, biometrics) to AI features without prior authorization from the data subject.
- (x) LIABILITY LIMIT: AI models may produce errors or 'hallucinations'. All output must be verified by a professional before use. Custodio Legal is not responsible for decisions made without human verification.
15. Independent Controllers
Not every third party the platform exchanges personal data with is a data processor. Google LLC (United States) does not process your data on our behalf or under our instructions: it is an independent controller that determines for itself the purposes and means of its own processing. That is why it is not on the list in Section 10, and why we hold no processing agreement with it for the two uses the product makes of it:
- (i) Sign-in with your Google account, if you choose that option: Google hands us your email and your name, and processes the data of your Google account as a controller in its own right. The relationship is governed by Google's Controller-Controller Data Protection Terms (version 11), to which item 3.i of the Google APIs Terms of Service refers, and whose item 4.1 states that each party is "an independent controller" of the data and "will individually determine the purposes and means of its processing".
- (ii) The Google Ads tag on the public site -not on the application-, which loads with ads consent denied by default and only enables it if you accept all cookies, as our Cookie Policy describes. It is governed by the Ads Controller-Controller Data Protection Terms (version 8.0), whose item 4.1 says the same.
What this means for you, said plainly:
- (a) Sending data to Google is a transfer between controllers, not a transmission to a processor. It rests on your express and informed consent and on the controller-to-controller standard contractual clauses those terms incorporate; the basis your own law gives it —a list of adequate countries, an authorization of yours, whichever article permits it— is stated by your country's annex in its international transfer section. It does not rest on the data processing agreement that backs the sending to the processors in Section 10, which is a different thing.
- (b) No Google instrument obliges it to notify us of a security breach occurring on its side: terms between independent controllers do not regulate it. We say so because it is different from what governs the processors in Section 10, and because Section 5 promises to notify you of the incidents we become aware of.
- (c) For the data Google processes as a controller in its own right, you exercise your rights before Google, through its own channels and under its own privacy policy. The data we process -the email and the name we receive at sign-in- remain ours and you exercise your rights before us, under Section 7.
- (d) A Google Ads processor agreement does exist, but it covers only a published list of processor services -Analytics, Tag Manager, Enhanced Conversions and the like- and the product uses none of them. If we ever enabled one, we would accept that agreement before the first data point and update this policy.
You cannot opt out of the Ads tag other than by rejecting non-necessary cookies, and you are not required to use Google sign-in: the platform accepts email and password, and that is the path on which Google plays no part.
16. External Assistants Connected through MCP
On the plans that include it, your firm may connect to Custodio Legal an external Artificial Intelligence assistant —for example Claude or ChatGPT— compatible with the MCP protocol (Model Context Protocol), to consult the firm's information from that assistant. This section says what leaves through that channel, towards whom, under which authorization and how it is cut off. The contractual conditions of the channel are in Section 22 of the Terms of Service.
- (i) WHO AUTHORIZES THE CONNECTION: Nothing leaves through this channel without an express act by a person. The connection is authorized by a member of the firm, signed in, on Custodio Legal's authorization screen (OAuth 2.1 with PKCE), which shows the name the application registered with, the firm it will act for and what each scope it asks for allows. Each authorization belongs to one person over one firm: the assistant sees no more than that person can see in that firm with their role, and nothing of another firm. On the plans that do not include the channel, the connection cannot be authorized.
- (ii) WHAT LEAVES TOWARDS THE ASSISTANT: Only what the assistant asks for, within the authorized scopes and at the moment it asks. With the matters reading scope, the data of the matters —their record, their parties, their status, their deadlines, their attention items, their timeline and their recent changes—; with the matter intelligence reading scope, their state and the extracted facts with the document fragment that supports them; with the knowledge search scope, fragments of the text extracted from the firm's documents and entries of its memory; and with the preparation scope, no additional data: the assistant only leaves an action prepared —a draft, a follow-up or a task— that is not carried out until a person of the firm approves it inside the Service. Through this channel no assistant can write, modify or delete the firm's data without that approval. What leaves may include personal data of the clients, the counterparties and the other persons who appear in the matters, and of the firm's members. To answer a knowledge search, the text of the assistant's query goes through the embeddings provider of Section 10, just as a search made inside the Service does; beyond that, what is delivered to the assistant goes through none of our Artificial Intelligence providers.
- (iii) WHO ANSWERS FOR WHAT THE ASSISTANT DOES: The assistant's provider is not our processor: we do not engage it, we do not instruct it and it is not on the list of Section 10 or on the list of subprocessors. It is chosen by the firm, which is the controller of the data of its matters (Section 1 (ii)), and the data are delivered to it only on the firm's instruction, given by one of its members on the authorization screen. What the assistant does with what it receives —where it processes it, how long it keeps it, whether it uses it to train models— is governed by the terms and the privacy policy of its provider, which the firm or its member accept with that provider, and Custodio Legal is not responsible for that processing. If that provider is outside your country, that transfer is decided by the firm, and the safeguard that backs it is the one the firm has with its provider, not those of Section 9. Before connecting an assistant, the firm must make sure it may send the data of its matters to that provider, with the authorization its own law requires of it.
- (iv) WHAT WE KEEP: The record of the application that connected —the name it registered with and its redirect addresses—; the authorization —who gave it, for which firm, with which scopes, when and, if it was revoked, when—, which we keep as the record of that authorization under the rule of Section 11; the act of authorizing, in the firm's audit log; the access codes and tokens, which we never store in the clear but as a cryptographic fingerprint, and which are deleted thirty (30) days after they stop being usable; and one row for each call by the assistant —which tool, who, when and with what result—, without the content delivered to it, of which we keep only a fingerprint.
- (v) HOW IT IS CUT OFF: You may revoke at any time, from your account, under «Authorized applications», the authorization of any application you connected: it is cut off at once, with all its tokens. The assistant itself may revoke its credentials through the protocol's revocation endpoint, and resetting your password revokes every authorization of your account. You may also ask us in writing at [email protected] to revoke the authorization of any application, and we handle it without delay. Revoking cuts off what leaves from that moment on; it does not recover what the assistant already received, which remains under its provider's policy: the rights over that copy are exercised before that provider.
Your country's annex completes this document
Each country has its own authority, its own deadlines and its own statute. Choose yours to read them here:
Colombia annex
It governs the general clauses of this document that refer to it.
Colombia Annex · Applicable Law and Supervisory Authority
The processing of personal data of subjects domiciled in Colombia is governed by Statutory Law 1581 of 2012 and Decree 1377 of 2013, today compiled into Single Decree 1074 of 2015 (Articles 2.2.2.25.1.1 and following).
The supervisory authority is the Superintendence of Industry and Commerce (SIC), which the law charges with overseeing the processing of personal data (Articles 19 and 21) and with which you may file complaints [✉ [email protected]]. The law asks you to exhaust the query or the claim before us first: that is the admissibility requirement of Article 16.
Colombia Annex · Deadlines for Answering Your Rights (ARCO)
A query is answered within a maximum term of ten (10) business days (Law 1581 of 2012, Article 14). A claim is answered within a maximum term of fifteen (15) business days counted from the day following its receipt (Article 15).
We count both terms from the business day following your request. For the claim that is what Article 15 says; for the query, whose Article 14 counts "from the date of its receipt", it is the reading we have always applied, and it is one day more for us, so we say it instead of leaving it implied.
The law allows both terms to be extended by telling you the reasons for the delay and the new date: up to five (5) further business days for the query and up to eight (8) for the claim (Articles 14 and 15). If we ever have to use that extension, we write it to you before the first term expires.
Colombia Annex · Security Incident Notification
If we detect a security incident that puts your personal data at risk, we inform the Superintendence of Industry and Commerce: that is the duty of Article 17 (n) of Law 1581 of 2012, which orders the authority to be informed of breaches of the security codes and of risks in the administration of the subjects' information.
That duty carries no term in the law. The only one the Superintendence has set are the fifteen (15) business days that External Circular 002 of 2015 gives for reporting an incident in the National Registry of Databases, counted from its detection and from its being made known to the area in charge of handling it, and which binds those who must register in it. We apply that same term by our own decision, whatever the channel through which it must be filed.
Colombia Annex · International Transfer
The United States and the Netherlands appear, by name, on the Superintendence of Industry and Commerce's list of countries with an adequate level of protection: item 3.2 of Chapter Three of Title V of the Single Circular, which External Circular 005 of 2017 added and External Circular 008 of 2017 replaced with the version in force. Israel is not named on that list: it enters through the clause that closes that same item, which recognizes as adequate "the countries that have been declared to have an adequate level of protection by the European Commission", among which Israel stands by Decision 2011/61/EU. Towards Israel the transfer further counts, as reinforcement, on the Standard Contractual Clauses that the provider's data processing agreement incorporates and on your express and informed consent.
In addition, since the processors the policy names act on our behalf and not as controllers, the sending towards them is a transmission of data backed by the data processing agreement each one incorporates into its terms, which is the contract of Article 25 of Decree 1377 of 2013 (Decree 1074 of 2015, Article 2.2.2.25.5.2); that is why Article 24 (2) of the same decree does not require that transmission to be reported to you or a separate consent to be asked of you. The sending of data to Google is different: it is not a transmission to a processor but a transfer between independent controllers, which Section 15 of the trunk covers. For Colombia that transfer rests on the United States being named on the adequacy list cited above, on the controller-to-controller standard contractual clauses that Google's terms incorporate, and on your express and informed consent.
Colombia Annex · Retention After Termination
When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Law 1581 of 2012 sets no retention periods for a controller such as us, only the purpose principle (Article 4 (b)), which Decree 1377 of 2013 turns into a temporal limit in its Article 11 (Decree 1074 of 2015, Article 2.2.2.25.2.8): data is kept only for the time that is reasonable and necessary for the purposes that justified collecting it, and once those purposes are fulfilled it is suppressed, unless a legal or contractual obligation requires keeping it.
After the suppression we keep the records the law requires us to keep:
- The consent log, because Article 17 (b) obliges us to request and keep a copy of the authorization you granted, and Decree 1377 of 2013 requires us to be able to prove it in its Article 8 (Decree 1074 of 2015, Article 2.2.2.25.2.5).
- The audit trail, because Article 17 (d) obliges us to keep the information under security conditions that prevent its adulteration, loss, consultation, unauthorized use or access, and that trail is the proof that those conditions existed.
- Subject rights requests and their resolution, which are the proof of having met the terms of Articles 14 and 15, and on which the complaint you may later file with the Superintendence depends.
- The billing trail, because the Commercial Code obliges the merchant to keep its books and papers for at least ten (10) years (Article 60), and the Tax Statute obliges it to keep the information and evidence of its returns (Article 632) until the income tax return supported by them becomes final, under the term set for it by Article 46 of Law 962 of 2005.
Ecuador annex
It governs the general clauses of this document that refer to it.
Ecuador Annex · Applicable Law and Supervisory Authority
The processing of personal data of subjects domiciled in Ecuador is governed by the Organic Law on Personal Data Protection (LOPDP) and its General Regulation (RGLOPDP), issued by Executive Decree 904.
The supervisory authority is the Personal Data Protection Superintendency (SPDP), which Article 76 of the LOPDP defines as the body that controls and oversees this matter, and with which you may file complaints.
Who the personal data protection delegate is. It is the controller, Custodio Legal, which Section 1 of the trunk identifies by its NIT and its domicile, and you write to it at [email protected]. There is no person other than the controller for you to address, and that is why we say it this way instead of pointing you to a name this policy does not publish.
Article 48 of the LOPDP lists the cases in which a delegate shall be designated: processing carried out by those who make up the public sector of Article 225 of the Constitution; activities that require "un control permanente y sistematizado por su volumen, naturaleza, alcance o finalidades del tratamiento"; large-scale processing of special categories of data; and processing that does not concern national security and State defence data that is classified or secret. Article 49 sets the delegate's functions: advising the controller and its staff, overseeing compliance with the law and with whatever the Superintendency issues, advising on risk analysis and impact assessment, and cooperating with the Superintendency as its point of contact.
The Superintendency's Regulation on the personal data protection delegate (Resolution SPDP-SPD-2025-0028-R) adds cases, and the one that looks most like us requires a delegate from private-law legal persons that provide information technology services, including those devoted to developing or deploying artificial intelligence (Article 10, item 13). Custodio Legal has not been incorporated as a company -Section 1 of the trunk identifies it by its NIT and its domicile, not by a corporate name or a commercial registry entry- so by its letter that item does not impose the designation on it. We made it anyway, and that is why the delegate is stated here.
What state the registration of the designation is in: it has not been filed. Article 5 of that same regulation requires the appointment to be registered with the Superintendency within a term of fifteen (15) days after the designation, and expressly allows it to be accepted later -late registration counts as a failure to comply with a legal security measure, not as the absence of a delegate-. Ours has not been filed. We do not say "in process" or "coming soon": there is no registration number to cite to you, and no notice or public document of ours states that the delegate is registered. The day the registration exists, this annex publishes it with its date and moves up a version. What does not depend on it is who you write to: the email address above answers you today.
Ecuador Annex · Deadlines for Answering Your Rights
In Ecuador we answer within the fifteen (15) days following receipt of the request, which is the term the LOPDP gives each of the four rights: access (Article 13), rectification and updating (Article 14), erasure (Article 15) and objection (Article 16). The law calls them a plazo and does not qualify them as business days, so we count calendar days, which is the reading that favors you most.
Beyond those four, Article 17 of the LOPDP recognizes the right to portability: you may download from 'My account > Your privacy' a structured, machine-readable copy of your account data. That article sets no term of its own; we answer portability within the same fifteen days.
Ecuador Annex · Security Incident Notification
If we detect a security incident that puts your personal data at risk, we notify the Personal Data Protection Superintendency and the Telecommunications Regulation and Control Agency as soon as possible and, at the latest, within the término of five (5) days from when we become aware of it (Article 43 of the LOPDP). We notify you without delay when the incident carries a risk to your fundamental rights, within the término of three (3) days counted from when we learn of that risk (Article 46 of the LOPDP).
Ecuador Annex · International Transfer
The providers listed in Section 10 of the trunk act as processors, not as controllers. Article 23 of the Superintendency's General Rule on transfers (Resolution SPDP-SPD-2026-0004-R, of January 28, 2026) states that, under Ecuadorian law, a processing mandate is neither a transfer nor a communication of personal data; what backs those sendings, then, is the data processing agreement each processor incorporates into its terms, with confidentiality and security obligations.
The sending to Google is different, because Google is not a processor but an independent controller, as Section 15 of the trunk explains: that one is an international transfer. The Personal Data Protection Superintendency has not declared, as far as we have been able to verify by walking its list of resolutions on September 9, 2026, any country with an adequate level of protection; Articles 11 to 19 of that same general rule set the procedure for declaring one, and it has not been used yet. That transfer relies on your explicit and informed consent (Article 60, item 2, of the LOPDP), which you give by accepting this policy knowing the destination and the safeguard, and on the independent-controller terms Section 15 cites by version.
One precision about contractual clauses, so that you do not read more into them: the Standard Contractual Clauses of European Commission Implementing Decision (EU) 2021/914 that the text generation provider's agreement incorporates govern the transfers that provider makes outside the European Economic Area, and they are not the standard clauses Ecuador recognizes. Articles 20 and 22 of the Superintendency's general rule recognize as an adequate guarantee the model contractual clauses of the Ibero-American Data Protection Network, and we do not claim to have those signed.
Ecuador Annex · Artificial Intelligence and Automated Decisions
The artificial intelligence features that Section 14 of the trunk describes are an artificial intelligence system within the meaning of Resolution No. SPDP-SPD-2026-0009-R of the Personal Data Protection Superintendency, «General rule for guaranteeing the right to personal data protection in the use of artificial intelligence systems», signed in Quito on February 12, 2026. That rule applies regardless of where the system and the provider are located (Article 1), so it governs this processing even though the inference runs outside Ecuador.
Before it, Custodio Legal acts as a deployer —the one who, by using an artificial intelligence system, carries out the provision of a service (Article 2, item 2)— and as an implementer —the one who implements it in its internal processes (Article 2, item 4)—. It neither develops nor trains models, and so it is not a developer within the meaning of that rule.
None of those features takes decisions with legal effects on you, or that similarly affect you, without human intervention. Article 20 of the LOPDP grants you the right not to be subject to a decision based solely or partly on automated assessments that produces such effects, and Article 4 of the resolution requires that right to be guaranteed at all times: artificial intelligence results are supporting material that a professional verifies before using, and Section 14 of the trunk describes feature by feature what each one does, what data leaves and what runs on your click.
You may object to the artificial intelligence processing that runs without a click of yours —indexing for questions with citations, fact extraction and matter reassessment, which item (viii) of Section 14 lists— by writing to [email protected], and through whatever means the platform makes available to you for that. The features that produce a result to read run only when you execute them, so not using them amounts to not authorizing them. Objections are answered within the fifteen (15) days this annex declares above.
The inference runs on the infrastructure of the providers Section 10 of the trunk lists: text generation at Nebius B.V. (Netherlands) and the vector representations of semantic search at Voyage AI (United States). Both act as processors, and what backs those sendings is what the «International Transfer» section of this annex says above.
We keep the record of the processing activities carried out through artificial intelligence systems —with the automated decisions that may generate legal impacts or affect rights and freedoms— and the personal data protection impact assessment of these features, which Articles 5 and 7 of the resolution require. Both are at the disposal of the Personal Data Protection Superintendency.
Ecuador Annex · Retention After Termination
Data is kept for no longer than is necessary to fulfil the purpose of its processing (Article 10, letter i, of the LOPDP). When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: the LOPDP sets the retention principle, not the periods.
After the suppression we keep four records, for three reasons, and we say which is which. The consent log and the audit trail, because Article 10, letter k, of the LOPDP requires us to demonstrate to you and to the Superintendency that the processing complied with the law, and that evidence is the only thing that demonstrates it. Subject rights requests and their resolution, for the same reason and with respect to the fifteen days above. And the billing trail, because of the provider's accounting and tax obligations, which are not Ecuadorian: Custodio Legal is domiciled in Colombia, as Section 1 of the trunk declares, and it is the Colombian accounting and tax rules that set how long he must keep his own books and receipts.
the Dominican Republic annex
It governs the general clauses of this document that refer to it.
Dominican Republic Annex · Applicable Law and Supervisory Authority
The processing of personal data of subjects domiciled in the Dominican Republic is governed by Ley núm. 172-13, on the comprehensive protection of personal data held in files, public registries, databanks and other technical means of data processing, of December 13, 2013 (Gaceta Oficial núm. 10737 of December 15, 2013). Its rules are of public order and apply throughout the national territory (article 3), to personal data recorded in any databank capable of processing, in the public and in the private sphere (article 2).
Your authorization. Article 5, paragraph 4, requires that the processing and the assignment of your data have your free, express and conscious consent, which must be given in writing or by an equivalent medium and which -when given together with other declarations- must appear expressly and prominently. That consent follows the duty to inform of paragraph 3 of the same article: the purpose and the recipients, the existence of the file and the identity and address of whoever answers for it, and the possibility of exercising the rights of access, rectification and deletion. That is what the consent screen shows you before you accept, and what is frozen, with its date, in the consent log.
The authority. Ley núm. 172-13 did not create a general-purpose data protection authority. Its supervisory body, the Superintendencia de Bancos de la República Dominicana, supervises "los archivos, registros o bancos de datos, públicos o privados, destinados a proveer informes crediticios" (article 29), and the entities that must register with it are the Sociedades de Información Crediticia (article 43). Custodio Legal is not a credit information company and does not provide credit reports, so there is today no regulator in the country with which we register databases, request transfer authorization or answer for this processing. What the law does require of us, and we comply with, is having information policies that guarantee the security and control measures of article 42, and the duties of article 13: keeping information securely, updating, rectifying or deleting it in good time, handling your queries and complaints, and maintaining an internal manual of policies and procedures.
You may write to [email protected] to exercise your rights. If you are not satisfied, the law opens the judicial hábeas data action to you (articles 7, 17 and 21), which follows the amparo procedure and is heard by the judge of the defendant's domicile (article 20).
As of September 9, 2026 Ley núm. 172-13 is still the only Dominican personal data protection statute, and no later law amended or repealed it: we verified that against the complete repertoire of the Consultoría Jurídica del Poder Ejecutivo. If a reform ever creates a supervisory authority, we will update this annex and tell you before the change reaches you.
Dominican Republic Annex · Deadlines for Answering Your Rights (ARCO)
Ley núm. 172-13 does set deadlines, and they are the ones we apply:
- Access: five (5) business days from your request. Article 10 imposes it on the user of the databank, and article 12, after setting that same term for the credit report, says expressly that "igual disposición aplica para las demás entidades que manejan bancos de datos, públicos o privados". We are one of them.
- Rectification, updating and cancellation: ten (10) business days from our receiving your complaint or noticing the error, under article 8, and at no cost to you. If we had already communicated the datum to a third party, we notify it of the rectification or the deletion within the following five (5) business days.
- Objection: Ley núm. 172-13 sets no term of its own for it. Said the other way round from how it sounds: article 9 recognises objection as a right independent of the other three -"no puede entenderse que el ejercicio de ninguno de ellos sea requisito previo para el ejercicio de otro"- but it does not say within how many days it must be answered, and no other article of the law says so either. We answer it within the same ten (10) business days of article 8. That term is ours, not the law's, and that is why we write it here instead of citing an article to you that does not exist.
If the deadline passes without our answering, article 8 entitles you to bring the hábeas data action with no further requirement.
Two limits the law itself sets, and that we would rather you read here than meet unannounced: while we verify a datum you challenged, when reporting on it we record that it is under review (articles 8 and 21); and deletion does not proceed where it could harm the rights or legitimate interests of third parties, or where a contractual or legal obligation to keep the data exists (articles 8 and 15).
Beyond those four rights, you may download from 'My account > Your privacy' a structured, machine-readable copy of your account data. Ley núm. 172-13 recognizes no right of portability: we give you that copy by our own decision.
Dominican Republic Annex · Security Incident Notification
Ley núm. 172-13 imposes the duty of security -adopting the technical, organizational and security measures that prevent alteration, loss, processing, consultation or unauthorized access: article 5, paragraph 5, and article 13, paragraph 2- but it sets no incident notification deadline and no authority to file one with for a controller such as us. By our own decision, and not because a Dominican rule imposes it, if we detect an incident that puts your personal data at risk we tell you without undue delay and, in any event, within the three (3) days following confirmation, with what we know and what we are doing.
Dominican Republic Annex · International Transfer
Operating the Service means transmitting your data outside Dominican territory, which is what article 6, paragraph 20, of Ley núm. 172-13 calls an international transfer of data. The Dominican Republic publishes no list of countries with an adequate level of protection, and the law requires no prior authorization from any authority: article 80 lists the cases in which the transfer proceeds, and ours relies on two of them.
The first is your own authorization: paragraph 1 admits the transfer where the natural person, "libre y conscientemente", decides to authorize it of their own will, and that is what you do by accepting this policy knowing the destination and the safeguard. The second is paragraph 6: the transfer necessary for the performance of the contract between the data subject and the controller, without which there is no Service to render.
To that are added the contractual guarantees each provider incorporates into its terms: confidentiality and security obligations and -for the text generation provider- the Standard Contractual Clauses of European Commission Implementing Decision (EU) 2021/914 that agreement incorporates for transfers outside the European Economic Area. They are not a Dominican requirement: they are the safeguard we do have, and that you can verify.
The same holds for the sending of data to Google, which is not a processor of ours but an independent controller, as Section 15 of the trunk explains: Ley núm. 172-13 does not make the basis of a transfer depend on the figure of whoever receives the data, so that sending rests on the same two items of Article 80, and further on the controller-to-controller standard contractual clauses that Google's terms incorporate.
Dominican Republic Annex · Retention After Termination
When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Ley núm. 172-13 sets no retention periods for a controller such as us.
What outlives the suppression, and why:
- The evidence of your authorization and of the processing -the consent log and the audit trail- because article 5, paragraph 4, requires consent to be given in writing or by an equivalent medium, and article 15 orders that what is cancelled be blocked and kept at the disposal of the branches of the State, for the liabilities arising from the processing, throughout their limitation period.
- Subject rights requests and their resolution, which are the evidence of having met the deadlines of articles 8 and 12.
- The billing trail, because the Tax Code (Ley núm. 11-92), in its article 50, subparagraph h) -as amended by article 105 of Ley núm. 155-17- requires keeping in orderly form, for a period of ten (10) years, the accounting books, the receipts or proofs of payment and any document, physical or electronic, relating to the taxpayer's operations and activities. That duty is your firm's as a Dominican taxpayer; we keep the proof so that it can meet it.
Over all of them runs the same limit of article 8: deletion does not proceed where a contractual or legal obligation to keep the data exists.
Costa Rica annex
It governs the general clauses of this document that refer to it.
Costa Rica Annex · Applicable Law and Supervisory Authority
The processing of personal data of data subjects domiciled in Costa Rica is governed by Ley N° 8968, on the protection of the person with regard to the processing of their personal data, published in La Gaceta N° 170 of September 5, 2011, and by its Reglamento, Decreto Ejecutivo N° 37554-JP of October 30, 2012, amended by decretos ejecutivos N° 40008-JP of 2016 and N° 41582 of 2019. Both pieces are named together because the deadlines that reach you -the five business day term, the breach notice- live in the regulation, not in the law.
Your authorization. Ley N° 8968 makes consent the door to processing: its article 30, subparagraph a), makes it a serious offence to "recolectar, almacenar, transmitir o de cualquier otra forma emplear datos personales sin el consentimiento informado y expreso del titular de los datos". That is what the consent screen asks you for before you accept, and what is frozen, with its date, in the consent log. You can revoke it whenever you want, through the mechanism article 7 of the Reglamento requires us to give you: prompt, simple and free of charge.
The authority. It is the Agencia de Protección de Datos de los Habitantes (PRODHAB), a maximum deconcentration body attached to the Ministerio de Justicia y Paz which article 15 of Ley N° 8968 created. It is the authority you complain to if you are not satisfied with what we do, and you can also write to us at [email protected].
And how you complain, so that you do not have to look it up. Article 24 of Ley N° 8968 gives the complaint to anyone with a subjective right or a legitimate interest who considers that a database is acting against the rules or the principles of the law. Article 25 sets the procedure: PRODHAB gives us three business days to state whether the charges are true and to file evidence -and if we do not file that report, "se tendrán por ciertos los hechos acusados"-, it may require information from us, inspect our databases on site and order interim measures, and must issue the final decision no later than one month after the complaint; against it there is a request for reconsideration within the third day, resolved in eight days. If you are right, article 26 orders the immediate deletion, rectification, addition or clarification of the data, or bars its transfer or disclosure. Article 27 also lets it open a sanctioning procedure of its own motion. Articles 58 to 72 of the Reglamento develop that procedure with the same terms.
On the registration of databases, and why we did not do it. Article 21 of Ley N° 8968 orders the registration before PRODHAB of "toda base de datos, pública o privada, administrada con fines de distribución, difusión o comercialización". Custodio Legal does not distribute, disseminate or commercialise third party data: it processes it on behalf of a firm, which is the party that decides about it. Under that reading there is no database to register, and the annual two hundred dollar levy of article 33 does not run either, because that article imposes it on "las personas responsables de bases de datos que deban inscribirse ante la Prodhab, de conformidad con el artículo 21". This is our reading of the text, not a confirmation from PRODHAB nor the opinion of a Costa Rican lawyer. If the legal review of this annex concludes otherwise, we will register the database, pay the levy and say so here.
As of September 10, 2026 Ley N° 8968 is still in force with no amendment whatsoever: PRODHAB itself states so on its regulations page, updated on September 9, 2026. What we could not verify is whether a reform bill is before the Asamblea Legislativa -its site did not respond on the day this legislation was read- so we assert neither that there is one nor that there is not. If a reform changes what this annex promises, we will update it and tell you before the change reaches you.
Costa Rica Annex · Looking up a court record with no account
In Costa Rica the Service will offer a one-off lookup of a case file by its number to someone with no account, which Section 2 of this policy's trunk describes. What follows is what Costa Rican law says about it, with its articles and with its reservation.
On what ground. On article 5, point 2, item b) of Ley N° 8968, which dispenses with express consent when «se trate de datos personales de acceso irrestricto, obtenidos de fuentes de acceso público general», and on article 3, item c), which defines that data as «los contenidos en bases de datos públicas de acceso general, según dispongan leyes especiales y de conformidad con la finalidad para la cual estos datos fueron recabados».
And with a written reservation, because that item sets two conditions and we treat only one as met. The purpose one, yes: we look up so that it can be looked up, which is the reason the Poder Judicial publishes the state of a case file. The «ley especial» one we have not verified: we did not find in SINALEVI a Costa Rican statute declaring the lookup of court records to be of general public access, and we do not claim one. What is true and does not depend on it is that we do not process the parties' identity: they come back masked, and article 9, point 3, takes out of the unrestricted category data «cuyo tratamiento pueda afectar los derechos y los intereses de la persona titular». Masking is what makes that classification decide nothing.
The rest of the law keeps running. The article 5 exception is an exception to consent, not to the rest: article 6 requires the datum to be adequate to the purpose for which it was collected and to be deleted when it stops being relevant, and that is what the masking and the ephemeral row do. The IP address of whoever looks up is processed only to limit how many lookups come from one place, and the row is deleted after two (2) hours.
And about registration with PRODHAB. This annex's applicable-law section already explains why, on our reading, there is no database to register, and this lookup does not change that reading: article 21 requires registering a database «administrada con fines de distribución, difusión o comercialización», and article 2, item j), of the Reglamento defines those words as requiring «un fin de comercializar el dato o medie el lucro con la base de datos». A free lookup that neither sells the datum nor profits from the database stays, on that reading, outside article 21. It is our reading and not PRODHAB's —we read no resolution of theirs on this point— and if legal review concludes otherwise we register the database, pay the fee of article 78 of the Reglamento, and say so here.
The articles in this section were read verbatim on SINALEVI on September 19, 2026 —Ley N° 8968, ficha 70975, version 85989; Reglamento, Decreto Ejecutivo N° 37554-JP, ficha 74352, version 115361— with HTTP 200.
Costa Rica Annex · Deadlines for Answering Your Rights (ARCO)
Ley N° 8968 sets a single deadline, for everything: its article 7 requires answering "de manera gratuita, y resolver en el sentido que corresponda en el plazo de cinco días hábiles". Article 18 of the Reglamento is the one that says from when it is counted: "cinco días hábiles, contados a partir del día siguiente en que la misma haya sido recibida". That is the one we apply, because it is the one that yields a concrete day.
- Access: five (5) business days from the day after your request (Law, article 7.1; Reglamento, articles 18 and 21).
- Rectification: five (5) business days, on the same terms (Law, article 7.2; Reglamento, articles 18, 23 and 24).
- Erasure or deletion: five (5) business days (Law, article 7; Reglamento, articles 18, 25 and 26).
- Revocation of consent: five (5) business days to execute it, and within that same term we notify anyone we had transferred your data to, who have another five to execute it on their side (Reglamento, article 8).
- Confirmation that the processing ceased: three (3) business days, free of charge, if you ask us for it (Reglamento, article 9). It is the shortest term in this section.
Objection and portability do not exist in Costa Rican law, and this annex does not promise them to you: neither Ley N° 8968 nor its Reglamento names them. What you can do, and what stands in for the first, is revoke your consent. And from 'My account > Your privacy' you can download a structured, machine-readable copy of your account data: we give you that copy by our own decision, not because a Costa Rican rule requires it.
Two counting rules the rule itself imposes, and we would rather you read them here than when they reach you. The first: if your request arrives incomplete or unclear, we may ask you once only, within the first five business days, for the missing details; you have five business days to answer, and if you answer a fresh five day term starts on the following day. If you do not answer, the request is treated as not filed (Reglamento, article 19). The second: between two access requests of yours there must be a minimum interval of six months, unless you set out to us, with reasons, why you believe your rights are being infringed (Reglamento, article 21).
One more limit, and it is the one that supports the retention section of this annex: article 26 of the Reglamento excludes from erasure the data "que deban ser mantenidos por disposición constitucional, legal o resolución de órgano judicial". Data a law requires us to keep is not deleted on request; what we do is tell you which law that is.
If the Costa Rican business day calendar for the year is not loaded in the platform, your request is filed all the same and we attend to it: what we do is mark the due date as estimated rather than certain, instead of giving you a date we cannot compute.
Costa Rica Annex · Security Incident Notification
Costa Rica does set a breach notice deadline, and it is not in the law but in article 38 of its Reglamento: the controller must inform the data subject "sobre cualquier irregularidad en el tratamiento o almacenamiento de sus datos, tales como pérdida, destrucción, extravío, entre otras, como consecuencia de una vulnerabilidad de la seguridad", and has five business days from the moment the vulnerability occurred to do so. Within that same term the exhaustive review opens, to measure the impact and decide the corrective measures.
Two things about that deadline, said plainly. The first: it runs from when the incident occurred, not from when we detected it, which is stricter than the "without undue delay from knowledge" the trunk's incident protocol is written to. In Costa Rica we apply the Costa Rican deadline. The second: the recipient is twofold -you and PRODHAB- and both are told the same thing, which is what article 39 of the Reglamento enumerates: the nature of the incident, the personal data compromised, the corrective actions taken immediately, and the means or the place where you can obtain further information.
Costa Rica Annex · International Transfer
Operating the Service means transmitting your data outside Costa Rican territory. Costa Rica solves that with a single door, and it is article 14 of Ley N° 8968: controllers of databases "solo podrán transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y válidamente tal transferencia", and provided the transfer does not infringe the principles and rights that same law recognises.
There are no other bases. Costa Rica publishes no list of countries with an adequate level of protection, and its law does not recognise standard contractual clauses as the basis of the transfer. What supports it is your express authorization, and that is why we ask you for it where it can genuinely be given: on the consent screen, naming the destination and the safeguard, before the data leaves.
The data of the firm's clients and opposing parties is a different matter, and it is worth being clear about whose duty it is. Over that data the controller is the firm, not Custodio Legal: it is the firm that has the relationship with the data subject and that obtains their express authorization to process and to transfer it, and that is what the firm declares when it accepts the third party data declaration, which cites Ley N° 8968 as its basis. We are its processor and act on its instructions.
To that are added the contractual guarantees each provider incorporates into its terms: confidentiality and security obligations and -for the text generation provider- the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 which that agreement incorporates for transfers outside the European Economic Area. They are not the basis of the Costa Rican transfer -that is your authorization, and it alone- they are the additional safeguard we do have and that you can verify.
The same holds for the data sent to Google, which is not a processor of ours but an independent controller, as Section 15 of the trunk explains: Ley N° 8968 does not distinguish the basis of the transfer by the role of whoever receives the data, so that sending rests on the same express authorization of article 14, and additionally on the controller-to-controller standard contractual clauses that Google's terms incorporate.
Why we take this so seriously: transferring data against the rules of chapter III of the law is a serious offence under article 30, subparagraph b), with a fine of five to twenty base salaries (article 28, subparagraph b). The consequence of getting this wrong is not an observation: it is a penalty.
Costa Rica Annex · Bar Association Check
When you open your firm —and afterwards, from Settings— you may enter your membership number of the Colegio de Abogados y Abogadas de Costa Rica. It is optional: if you do not enter it, we check nothing, and your firm works the same. If you do, we ask the public member search the bar publishes at abogados.or.cr, and what we do with the answer is show a badge on your firm's profile.
What leaves here for the bar is the number and nothing else: your name does not travel, nor your firm's, nor any of your clients'. What comes back is a page with the result, and from that page we keep exactly three things: whether the bar knows the number, the condition it records —in good standing or suspended— and the date we asked. Nothing more. The bar's search prints, next to each member, their full name, national id number, address, email and phone: none of that is stored, and the program that reads the answer discards it before it reaches the database. This is the information-quality principle of article 6 of Ley N° 8968: only the datum the purpose needs is kept, and the purpose here is showing a badge.
Asking once is the rule, and only when the number changes. If the bar does not answer, the badge says it could not be checked and that is where it stops: we do not insist.
You can withdraw the number whenever you want, by leaving the field blank in Settings. Doing so deletes the whole row —the number, the condition and the date— and the badge disappears.
The badge decides nothing. A number the bar does not know, one with a suspension recorded, and a bar that does not answer all give exactly the same access to the Service: what changes is what the profile says. We do not close the door on you because of what a third party's page says — or fails to say.
Costa Rica Annex · Retention After Termination
When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Ley N° 8968 sets no retention periods for a controller such as us. What its Reglamento sets, in article 11, is a ceiling: the retention of personal data that may affect its subject "no deberá exceder el plazo de diez años, desde la fecha de terminación del objeto de tratamiento del dato, salvo disposición normativa especial que establezca otro plazo". None of the windows in this annex exceeds it.
What outlives the suppression, and why:
- The evidence of your authorization and of the processing -the consent log and the audit trail- because processing without informed and express consent is a serious offence (Ley N° 8968, article 30, subparagraph a) and proving that we had it requires keeping the record. Article 26, subparagraph b), of the Reglamento is what allows keeping it after suppressing the rest: data that must be kept by legal provision is not deleted.
- The data subject requests and their resolution, which are the evidence of having met the five business days of article 7 of the Law and article 18 of the Reglamento.
- The billing trail, for five years, and by two routes that reach the same number. The Código de Comercio requires the merchant to "conservar los libros de contabilidad desde que se inician hasta cinco años después del cierre del negocio y conservar igualmente la correspondencia, las facturas y los demás comprobantes, por un período no menor de cinco años, contado a partir de sus respectivas fechas, salvo que hubiera juicio pendiente en que esos documentos se hubieran ofrecido como prueba" (article 234, subparagraph d), and repeats the five years for a business being wound up in its article 270. The Código de Normas y Procedimientos Tributarios reaches the same term through the taxpayer's duty: "los contribuyentes o los responsables deberán conservar los duplicados de estos documentos por un plazo de cinco años" (article 109). That duty is your firm's, as a Costa Rican merchant and taxpayer; we keep the receipt so it can comply.
One clarification about the number, because it is easy to confuse: the Código de Normas y Procedimientos Tributarios sets the statute of limitations of the Tax Administration's action at four years (article 51). Four years is what it has to collect; five is what has to be kept. The window this annex promises is the retention one.
Uruguay annex
It governs the general clauses of this document that refer to it.
Uruguay Annex · Applicable Law and Supervisory Authority
The processing of personal data of data subjects domiciled in Uruguay is governed by Ley N° 18.331, on the Protection of Personal Data and the «Habeas Data» Action, of August 11, 2008, and by its amending statute, Ley N° 19.670 of October 15, 2018. They are implemented by Decreto N° 414/009 of August 31, 2009 and Decreto N° 64/020 of February 17, 2020; the four pieces are named together because the numbers that concern you — the registration, its terms, the hours of an incident — live in the decrees and not in the statute.
The principles. Article 5 of the statute lists seven and makes them the criterion for interpreting everything else: legality, truthfulness, purpose, prior informed consent, security of the data, confidentiality and accountability.
Your authorisation. Article 9 requires consent to be «free, prior, express and informed, and it must be documented»: that is what the consent screen asks you for, and what is frozen with its date in the consent log. That same article, in its letter D), is what allows your firm to upload its own clients' data to the platform without asking them again, because it derives from a professional relationship and is necessary to perform it. It does not serve the international transfer, which has its own list and its own section below.
Confidentiality, and why it weighs more here than elsewhere. Article 11 requires whoever processes data from a database to use it «confidentially and exclusively for the ordinary operations of its line of business», and subjects to professional secrecy — with an express reference to article 302 of the Criminal Code — every person taking part in any stage of the processing. That duty survives the end of the relationship. It reaches whoever operates the platform, not only your firm.
Accountability. Article 12, in the wording given by article 39 of Ley N° 19.670, names the controller and the processor in the same sentence and orders them to adopt «privacy by design, privacy by default, data protection impact assessment, among others» and to demonstrate their effective implementation. The processor is not liable less than the controller: it is liable the same.
Two things this regime has and none of our others does. The first: article 2 extends the protection to legal persons where applicable, so your firm is a data subject itself and not only a controller of its clients' data. The second: article 6 makes registration the gateway to lawfulness — «the formation of databases shall be lawful when they are duly registered» — and that is why this annex devotes a whole section to it.
Why Uruguayan law reaches us. Article 37 of Ley N° 19.670 and article 1 of Decreto N° 64/020 subject to this law a controller or processor not established in the country when the offering of services is directed at inhabitants of the Republic. The regulation assesses that direction through elements such as the language, the reference to payment in national currency or the provision of related services, and adds that under no circumstances may the contracting parties exclude the application of national law where it applies. Offering you the Service is what triggers it, and we do not treat that as arguable.
The authority. It is the Unidad Reguladora y de Control de Datos Personales (URCDP), a decentralised body of AGESIC. It is the authority you complain to if you are not satisfied with what we do, and you can also write to us at [email protected]. Complaining to the URCDP does not take away the habeas data action before the Uruguayan courts, nor the other way round.
Uruguay Annex · Looking up a court record with no account
In Uruguay the Service will offer a one-off lookup of a case file by its IUE to someone with no account, which Section 2 of this policy's trunk describes. What follows is what Uruguayan law says about it, with its articles.
On what ground. On article 9, item A) of Ley N° 18.331, which dispenses with prior consent when «los datos provengan de fuentes públicas de información, tales como registros o publicaciones en medios masivos de comunicación», read together with article 9-BIS, which lists what counts as a public source. The judiciary's portal is not named in items A) to C) of that article, and we do not hide it: what reaches it is item D), the residual one —«todo otro registro o publicación en el que prevalezca el interés general en cuanto a que los datos personales en ellos contenidos puedan ser consultados, difundidos o utilizados por parte de terceros»— and that item ends with a condition we meet before invoking it: «en caso contrario, se podrá hacer uso del registro o publicación mediante técnicas de disociación u ocultamiento de los datos personales».
That is why the parties come back masked, and it is not decoration. Masking is the technique that item prescribes, and dissociation is defined by article 4, item G): «todo tratamiento de datos personales de manera que la información obtenida no pueda vincularse a persona determinada o determinable». We do not return the parties' identity, so we do not depend on settling whether «el interés general» prevails in the publicity of a case file.
The purpose principle keeps running. Article 8 forbids using the datum for «finalidades distintas o incompatibles con aquellas que motivaron su obtención», and the URCDP applied it to data that came from a public source (Resolución N° 94/014, of 31 July 2014, collected in its «Principales criterios administrativos 2009-2015», where it also writes that it is advisable that «el tratamiento de los datos personales no esté vinculado con la identidad de su titular»). The purpose for which the judiciary publishes the state of a case file —so that it can be looked up— and this lookup's purpose are the same, which is why no history is kept and nothing is built out of what was looked up.
And about whoever looks up. Their IP address is processed only to limit how many lookups come from one place, and the row the lookup writes is deleted after two (2) hours. That is article 8 in its second paragraph: data «deberán ser eliminados cuando hayan dejado de ser necesarios o pertinentes a los fines para los cuales hubieren sido recolectados».
What this section does not claim. That the ephemeral row is not a «base de datos» for the purposes of this law. Article 4, item A), sets no permanence threshold —«cualquiera que fuere la modalidad de su formación, almacenamiento, organización o acceso»— and item M) counts the consulta among processing operations: we assume it is one, which is why it falls within what the next section says about registration with the URCDP. Nor have we read any URCDP resolution or opinion about a private third party that looks up the judicial portal and publishes the result with the parties masked; if one appears and says otherwise, this annex changes before the change reaches you.
The articles in this section were read verbatim in the text of Ley N° 18.331 that IMPO publishes, on September 19, 2026, and the compilation of criteria on the URCDP's site the same day.
Uruguay Annex · Registration of the Database with the URCDP
This is the duty no other country of the Service imposes on us, and that is why it is written here with all its parts.
Who it reaches. Articles 28 and 29 of Ley N° 18.331 require every database to be registered, and article 2 of Decreto N° 64/020 says it of us in so many words: controllers and processors not established in the territory «must comply with the obligations set out in Ley N° 18.331 […] including the registration of their databases and providing the corresponding contact information to the Unidad Reguladora y de Control de Datos Personales». It is not a reading of ours: it is the text of the regulation.
What the registration declares. Article 16 of Decreto N° 414/009 sets its content, and article 29 of the statute lists what cannot be missing: identification of the database and of its controller, nature of the data, procedures for obtaining and processing it, security measures, exercise of rights, destination of the data and to whom it may be transmitted, retention period and how to access and rectify. And it brings a limit worth reading: «no data user may hold personal data of a nature other than that declared in the register».
The two terms and the display. Registration is filed within 90 days of the start of activities (Decreto N° 414/009, article 17), is updated quarterly (article 20) and the number and date of the resolution approving it are displayed in a visible, accessible place (article 19). The procedure is online and free of charge.
The number of our resolution is not here yet. This gap — URCDP resolution number: pending; date: pending — is deliberate and is filled the day the procedure completes, in this annex and in the site footer. While it says «pending», what you are reading is that the procedure has not been completed, not that it exists and we do not publish it.
And what we could not verify, said as such. The procedure requires a Uruguayan electronic identity — Usuario gub.uy, digital DNI, Identidad Digital Abitab or TuID Antel — and the procedure page does not document a route for a foreign company with no representative in the country. We claim neither that it can be done nor that it cannot: it is the first question of this annex's legal review, and on its answer depends whether registration is a form or a local mandate.
The lookup with no account falls in here. The ephemeral row that lookup writes is, in the terms of article 4, item A), an organized set of personal data subject to processing, and it therefore falls within the registration this section declares pending. We do not leave it out for lasting two hours: no Uruguayan rule we have read exempts a database for being ephemeral.
Uruguay Annex · Deadlines for Handling Your Rights (ARCO)
Ley N° 18.331 does set a deadline, and it is the same for everything: five (5) business days.
- Access: five business days «from having been requested» (article 14, paragraph 3). Once the term expires without an answer, or if it is denied without justified reason, the habeas data action becomes available.
- Rectification, updating, inclusion and erasure: five business days «from receipt of the request», or the same term to tell you why we believe it does not apply (article 15, paragraph 2). They are free of any charge to you.
- Information to a data subject whose data was not collected from them: five business days from receipt of the request (article 13, paragraph 2).
- Propagation: if we had already communicated or transferred the data, we notify the rectification, inclusion or erasure to whoever received it within the fifth business day of processing it (article 15, paragraph 6).
The count starts on the same day as your request, not the next one. The articles say «from having been requested» and «from receipt of the request», without the word «following» that the regulations of other countries where we operate do have, and in case of doubt we count the way that favours you.
Two further rules the statute itself sets. Free access is exercised «at six-month intervals», unless a legitimate interest arises anew (article 14): it is an admissibility requirement for the second request, not a term. And while we verify, rectify or include a datum, on a third party's request we record that the information is under review (article 15, paragraph 5).
Objection and portability do not exist as standalone rights in the Uruguayan regime. We searched for the words in the current text of the statute and of Decreto N° 414/009 and they do not appear. If you ask us for either, we file it and answer you; what we do not do is promise you a statutory deadline Uruguayan law does not set.
What the platform computes today, and what it does not yet. The Uruguayan business calendar is loaded — the public holidays of Decreto Ley N° 14.977, their shift to Mondays under Ley N° 16.805, Carnival and Tourism Week derived from Easter, and the two judicial recesses of article 86 of Ley N° 15.750 — so your request is born with a due date computed over Uruguayan business days and not over calendar days. Two reservations, said before they reach you: the computation rests on our reading of articles 14 and 15, which no Uruguayan lawyer has curated yet, and the holiday table does not contain the judicial officer's day — we found no statute or court ruling declaring it a holiday — nor a holiday declared by a statute within the year, which goes in when it is published.
Uruguay Annex · Automated Processing and Artificial Intelligence
This section is more explicit than its counterpart in the other countries of the Service, and not by taste: Uruguayan law requires it in so many words.
What the law orders us to tell you. Article 13 of Ley N° 18.331, in the wording given by article 62 of Ley N° 20.075 of October 20, 2022, requires us to inform you beforehand, expressly, precisely and unequivocally, of «the existence or absence of international data transfers» (letter F) and, in the automated processing of article 16, of «the assessment criteria, the processes applied and the technological solution or program used» (letter G).
What the artificial intelligence feature does. Over the text of a matter and the fragments of the documents your firm uploads, the platform generates summaries, analyses, drafts and answers with a citation to the source. The technological solution is a third party's language model, to which that text is sent through a programming interface and which returns text. Who those third parties are, what each one receives and under which safeguard it travels is in the processors section of the trunk of this policy and, one by one, in the sub-processor list the Service publishes. There is an international transfer in that sending, and the next section says what it rests on.
Which criteria are applied, and which are not. The model produces text from the text it is given; it does not score, does not classify people, does not compute risk and does not profile anyone's conduct, solvency or reliability, and its output decides nothing on its own: a lawyer reads and uses it. When the platform proposes a deadline or a status, it proposes it with the rule or the fact that sustains it, and the decision remains with whoever runs the matter.
Your right to challenge. Article 16 gives you the right not to be subject to a decision with significant legal effects «based on automated processing of data intended to evaluate certain aspects of their personality», to challenge the private decision whose sole basis is that processing, and to obtain information about the assessment criteria and the program used. That article sets no deadline, so we do not promise you one: write to us at [email protected] and we answer with the criteria and the program. As the platform takes no decisions with legal effects over anybody, we expect this right to have nothing to challenge; if one day it did, this annex would say so first.
And what you can switch off. The artificial intelligence features have their own switches in the platform: a firm may leave them off and use the rest of the Service. Switched off, no text is sent to the generation provider.
Uruguay Annex · Security Incident Notification
Uruguay does not have one breach clock: it has three, and only two run on our side. It is worth knowing which is which, because the third is yours; and behind the three there is a fourth duty, the later report, which has no clock.
- Twenty-four (24) hours to start mitigating. Once an incident causing disclosure, destruction, loss, alteration or unauthorised access to personal data is confirmed, the controller and the processor must start the procedures needed to minimise its impact «within the first 24 hours of confirmation» (Decreto N° 64/020, article 3). That clock runs for us.
- Immediately, to tell you. When the breach becomes known to the processor — us — «it shall communicate it immediately to the controller» (Decreto N° 64/020, article 4, paragraph 3). That notice reaches you with the date and time the incident happened and not only with when we learned of it, because your own term depends on that datum.
- Seventy-two (72) hours to the URCDP, and they are yours. The controller must communicate the breach to the URCDP «within a maximum of 72 hours from becoming aware of it» (Decreto N° 64/020, article 4), with the certain or estimated date, the nature, the data affected and the possible impacts; and must communicate it in clear, plain language to the data subjects significantly affected. Over the data your firm uploads, the controller is you: that communication is yours and we give you the inputs. Article 38 of Ley N° 19.670 adds that the URCDP coordinates the course of action with CERTuy.
- The detailed report afterwards. Once the breach is resolved, the controller draws up a report of the breach and of the measures adopted and communicates it to the URCDP (Decreto N° 64/020, article 4, last paragraph). If the incident was ours, we give you that report in writing.
Over the data of your own account — your email, your billing, your consent log — the controller is us, and there the three clocks run on our side.
Uruguay Annex · International Transfer
Operating the Service entails transmitting your data outside Uruguayan territory. Uruguay regulates that in article 23 of Ley N° 18.331, and it has to be read in full because it opens with a prohibition: the transfer «with countries or international organisations that do not provide adequate levels of protection» is prohibited.
The United States is not among the adequate ones. URCDP Resolution N° 23/021, of June 8, 2021, considers appropriate the members of the European Union and the European Economic Area, Andorra, Argentina, the private sector of Canada, Guernsey, the Isle of Man, the Faroe Islands, Israel, Japan, Jersey, New Zealand, the United Kingdom and Switzerland. The United States is not on that list, and that same resolution withdrew the Privacy Shield as an enabling instrument. We tell you because the infrastructure hosting the platform is in the United States.
What the transfer rests on, then. On the two doors article 23 itself opens and that fit this contract: letter A), your unequivocal consent to the transfer, which is what we ask you for on the consent screen, naming the destination before the datum leaves; and letter B), that the transfer is necessary to perform the contract between you and us, which is what the Service is. And we do not stop there: the same article accepts that the safeguards «may derive from appropriate contractual clauses», and URCDP Resolution N° 41/021, of September 8, 2021, recommended those of its Annex I. Those clauses are not prose in this annex: they are the data processing agreement your firm accepts, published as an instrument of its own, with the list of sub-processors named inside it.
Of the other countries where the Service is offered, only Argentina is on that list. Colombia is not, nor Ecuador, nor the Dominican Republic, nor Costa Rica, nor Brazil. It matters the day a Uruguayan firm shares data with a firm from one of those five countries inside the platform: that transfer needs its own basis under article 23, and this annex does not take it for granted.
The data of your firm's clients and counterparties is another matter. Over it the controller is you and we are your processor, acting on your instruction; it is you who has the relationship with the data subject and who obtains what article 23 requires. That is what you declare when you accept the third-party data declaration.
Uruguay Annex · Accountability: Impact Assessment and Data Protection Officer
The impact assessment is the entry obligation, and it is done. Article 6 of Decreto N° 64/020 requires the impact to be assessed before processing starts when, among other cases, a stable processing of «data linked to the commission of criminal, civil or administrative offences» may be projected (letter b) or data may be transferred to States without an adequate level of protection (letter f). Both reach the Service from the first Uruguayan firm: a court case file is the former and the infrastructure in the United States is the latter. The assessment, with the minimum content of article 7, lives in Custodio Legal's internal security documentation and is reviewed when what it describes changes. Should it reveal «a potential and significant risk» to the rights of data subjects, that same article requires it to be brought to the URCDP's attention with the detail of the measures, and we would do so.
The data protection officer is not an entry condition, and we say why. Article 40 of Ley N° 19.670 and article 10 of Decreto N° 64/020 require one from public entities, from private entities processing sensitive data as their principal business and from those processing large volumes of data. The regulation closes both: sensitive data is that of article 4, letter E), of Ley N° 18.331 — racial and ethnic origin, political preferences, religious or moral convictions, trade union membership, health and sex life — and a civil, commercial or employment case file is none of those categories even if it may contain one; and the large volume is defined with a number, «more than 35,000 persons». Neither case is met today. The second is a threshold crossed without warning, and what crosses it is the count of distinct data subjects, not of firms. We measure it, and this is how: every day we count the distinct data subjects we process in each country, and we warn our compliance officer when the Uruguayan count reaches 80 % of those 35,000 persons and again when it crosses them. We count people and not firms, with the same criterion we use to identify whoever exercises their rights — name and document when there is a document, name when there is not — so the number is approximate in both directions and we treat it as an early signal and not as an exact figure. The day it is crossed there are 90 days to communicate the appointment (article 14 of the same decree) and the officer must evidence legal knowledge specialised in data protection (article 12). This annex would say so before it happens.
Uruguay Annex · Retention After Termination
When the relationship with a firm ends we notify its owner after sixty (60) days and suppress its data after ninety (90); the thirty days in between are the margin to come back.
Those two windows are platform policy, and Uruguayan law does not contradict them — it is the only country of the Service whose statute sets an explicit ceiling. Article 30 of Ley N° 18.331 orders that «once the contractual performance is complete the personal data processed must be destroyed», and allows it to be kept «for a period of up to two years» only with the express authorisation of the party on whose behalf the services were provided. We do not ask you for that authorisation and we do not use it: ninety days sit comfortably below that ceiling and do not need it.
The line between the two hats, which is the part that matters. Over the data your firm uploads — its clients, its counterparties, its case files — we are the processor and the whole of article 30 runs on us, including its first prohibition: not to apply it to a purpose other than the one stated in the services contract «nor to assign it to other persons, not even for its safekeeping». That is why every third party processing that data on our behalf is named in the data processing agreement, and not merely published in the sub-processor list: publishing it is not enough in Uruguay. Over the data of your firm's account — its owner, its billing, its consent log — we are the controller, and there article 8 applies: the datum is deleted when it ceases to be necessary or relevant for the purpose that motivated obtaining it.
What survives the suppression, and why:
- The proof of your authorisation and of the processing — the consent log and the audit log — because article 9 requires consent to be documented and article 12, in the wording of Ley N° 19.670, requires the controller and the processor to demonstrate the effective implementation of their measures.
- The data subject rights requests and their resolution, which are the proof of having handled them within the five business days of articles 14 and 15.
- The billing trail, which is data about your firm as our customer and not data processed on your behalf: we keep it for as long as it is necessary for the relationship and to be able to prove it (articles 8 and 12). We still do not promise you a period, and we can now say why with more precision. The Uruguayan tax period was read: article 70, letter C), of the Código Tributario (Ley N° 14.306) orders books, documents and records to be kept in an orderly manner «during the limitation period of the tax», and article 38 sets that period at five years counted from the end of the calendar year in which the taxable event occurred, extended to ten in the cases that same article lists. That duty is the Uruguayan taxpayer's — your firm, when it has to withhold on the payment abroad — and not ours: Custodio Legal is not a taxpayer in Uruguay, so that article gives us no period to promise you. The commercial period is still unread from official sources, now with the reason written down: IMPO does not publish the text of the Código de Comercio without a subscription, and the Parliament site did not answer. When it is read, this annex brings the number with its article.
Argentina annex
It governs the general clauses of this document that refer to it.
Argentina Annex · Who the Controller Is
Custodio Legal, holder of tax number NIT 1057602936 of the Republic of Colombia, with legal domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia, provides the Service. You can write to us at [email protected] or call +57 333 431 8597; the team that handles enquiries and complaints is the Personal Data Protection Area, at that same email address.
We have no establishment and no representative domiciled in Argentina. This section is here under its own heading, and not as a pointer to the trunk, because Resolución AAIP 126/2024 lists among its very serious infringements «omitir denunciar, con motivo del tratamiento de datos personales en Internet, el domicilio legal y demás datos identificativos del responsable, sea ante el Registro Nacional de Bases de Datos como así también en su política de privacidad, de modo tal que mediante dicha conducta afecte el ejercicio de los derechos del titular del dato y la actividad de contralor» of the authority. The offence needs both halves —the omission and its effect— and that is why we are not interested in arguing whether a given case would complete it: we tell you who we are and where we are.
Argentina Annex · Applicable Law and Supervisory Authority
The processing of personal data of data subjects domiciled in Argentina is governed by Ley 25.326 on the protection of personal data, of October 4, 2000, and by its implementing Decreto 1558/2001.
The supervisory authority is the Agencia de Acceso a la Información Pública (AAIP). It is the authority you complain to if you are not satisfied with what we do, and you can also write to us at [email protected].
Article 44 of the law says two different things and both reach you. First, that its chapters I to IV «son de orden público y de aplicación en lo pertinente en todo el territorio nacional» (are of public order and apply throughout the national territory). And then, in a separate sentence, that «la jurisdicción federal regirá respecto de los registros, archivos, bases o bancos de datos interconectados en redes de alcance interjurisdiccional, nacional o internacional» (federal jurisdiction shall govern registers, files or databases interconnected in networks of inter-jurisdictional, national or international reach). The Service is exactly that: twenty-four provincial regimes do not apply to you, one does.
Two things about this regime differ from the other countries where the Service is offered, and they are worth saying here:
- Legal persons are data subjects. Article 2 defines the data subject as «toda persona física o persona de existencia ideal con domicilio legal o delegaciones o sucursales en el país» (any natural person or legal entity with legal domicile, branches or subsidiaries in the country). Your firm, if it is a company, is itself a data subject and not only responsible for third parties' data: it can exercise against us the same rights an individual exercises.
- Consent is by default express and in writing, not tacit. Article 5 paragraph 1 says it must be given «por escrito, o por otro medio que permita se le equipare, de acuerdo a las circunstancias» (in writing, or by another means that can be treated as equivalent, according to the circumstances).
Argentina Annex · Registration of the Database with the RNBD
Article 3 of Ley 25.326 says that the formation of data files «será lícita cuando se encuentren debidamente inscriptos» (shall be lawful when they are duly registered). This is not a formality separate from lawfulness: it is the lawfulness. And article 21 requires registration in the register the authority sets up, declaring —among nine other things— the purpose of the file, the nature of the data, the recipients and how long the data is kept.
Article 21 paragraph 1 names private files «destinados a proporcionar informes» (intended to provide reports), which could be read as if it only reached those who sell information. It does not, and what closes the question is article 1 of Decreto 1558/2001: private files are within that concept when they «exceden el uso exclusivamente personal» (exceed exclusively personal use) or have the transfer of personal data as their purpose, whether the information circulates for a fee or free of charge. A platform that processes the matters of several firms exceeds exclusively personal use, so the register reaches us. We say it here because the opposite reading would be the convenient excuse.
The register is the AAIP's Registro Nacional de Bases de Datos, and registration runs on two sides:
- Yours, for your own database: your case files and your clients' data are your file, and you are its controller.
- Ours, through the route the AAIP opened for controllers not established in Argentine territory. It is a web form with the character of a sworn statement, free of charge and with no expiry, which asks for the company's articles of incorporation and an authorised person or attorney-in-fact, and which asks for neither a CUIT nor a tax key.
What state our filing is in today: it has not been submitted. We do not say "in progress" or "coming soon": the registration has not been started, we have no resolution number and therefore there is no number to cite to you. The day one exists, this annex publishes it with its date and goes up a version.
And what it means today, said with the gravity it has and not with the one that sounds better. Anexo I of Resolución AAIP 126/2024 has two entries about this, and the one that describes our situation is the milder: it is a minor infringement to «efectuar tratamiento de datos personales sin encontrarse inscripto ante el Registro Nacional de Bases de Datos en infracción a lo dispuesto por el artículo 3° de la Ley N° 25.326», and a serious one to fail to register «cuando haya sido requerido para ello» (when the authority has required it). No such requirement has been made. What does not depend on the gravity, and is what really matters, is article 3: while it is not registered, the formation of the file is not lawful, and that is not fixed by paying a fine.
We tell you this here and not in a footnote because article 14 of Decreto 1558/2001 gives you the right to ask us: literal f) includes within the right of access «saber si el archivo está registrado conforme a las exigencias de la Ley Nº 25.326» (knowing whether the file is registered as Ley No. 25.326 requires). If you ask us today, the answer is the one in this paragraph.
And because paragraph 3 of article 21 is a living obligation and not one of registration alone: no user may hold data of a nature different from the one declared. What we declare in the register has to say the same as this annex, including the retention period.
Argentina Annex · What Legitimises the Processing
Article 5 paragraph 2 of Ley 25.326 lists the cases in which consent is not necessary, and two of them are what hold up the entire Service. We cite them with their wording instead of summarising them:
- Literal a), «fuentes de acceso público irrestricto» (sources of unrestricted public access). This is what holds up judicial surveillance. What the Service reads from a case file —the caption, the published parties, the filings— is published by a judiciary's portal for anyone, with no registration and no password.
- Literal d), data that «deriven de una relación contractual, científica o profesional del titular de los datos, y resulten necesarios para su desarrollo o cumplimiento» (derive from a contractual, scientific or professional relationship of the data subject, and are necessary for its development or performance). This is what holds up your firm's case file: the data of your clients, of their counterparties and of the third parties who appear in their matters derive from your professional relationship with them and are necessary to carry it on.
Outside those two cases paragraph 1 applies and consent has to be free, express and informed, in writing or by an equivalent means. Your acceptance of this policy and of the processing agreement on the platform is frozen, with its date and its full text, in an immutable row of our consent log; that is the equivalent means with which we answer if it ever has to be proved.
There is a third piece that is not a legal basis but a warning. Article 11 paragraph 4 says that the transferee «quedará sujeto a las mismas obligaciones legales y reglamentarias del cedente y éste responderá solidaria y conjuntamente por la observancia de las mismas» (shall be subject to the same legal and regulatory obligations as the transferor, and the latter shall be jointly and severally liable for their observance) before the authority and before the data subject. It is a rule per transfer, and in this relationship there are two chained: you transfer to us and we transfer to each subprocessor. It is developed in the subprocessors section below, because in Argentina it reaches you.
Argentina Annex · When We Are Processors and When We Are Controllers
This annex separates two kinds of processing that Argentine law subjects to different articles, and no other annex of the Service separates them that way.
What we process on your behalf —the case file, the parties, the documents you upload and the text we extract from them— makes us processors under article 25 of Ley 25.326. Over that data we decide nothing: it is not applied to a purpose other than the one stated in the contract, it is not transferred to anyone «ni aun para su conservación» (not even for its safekeeping), and it is destroyed once the service is performed. That is what the Argentine processing agreement develops clause by clause.
Your account data —the name, email and phone of the person who signed up, the consent log, your rights requests and the billing trail— makes us controllers. Nobody entrusted it to us: we collected it ourselves in order to provide you the Service. That processing does not fall under article 25 but under article 4 paragraph 7 —data «deben ser destruidos cuando hayan dejado de ser necesarios o pertinentes a los fines para los cuales hubiesen sido recolectados» (must be destroyed when they have ceased to be necessary or relevant to the purposes for which they were collected)— and under article 16 paragraph 7, which subjects it to the periods of the applicable provisions or of the contract.
They are two different retention regimes, and the retention section of this annex counts them separately.
Argentina Annex · Deadlines for Handling Your Rights (ARCO)
Ley 25.326 does set deadlines, and it sets two different ones, with two different units. It is the only country of the Service where that happens:
| Right | Deadline | Unit | From | Rule |
|---|---|---|---|---|
| Access | ten (10) days | calendar | the formal demand | Ley 25.326, art. 14 para. 2 |
| Rectification, updating, erasure and blocking | five (5) days | business | receipt of the claim | Ley 25.326, art. 16 para. 2 |
Objection and portability do not exist as autonomous rights in the Argentine regime. It is not that we fail to handle them: the law does not name them and therefore there is no term to count. If you ask us for either of the two we tell you that, and we tell you what we can do.
Two more things the law gives you and that we would rather you read here:
- Access is free at intervals of no less than six months, unless you show a legitimate interest (art. 14 para. 3). If you ask us for a second access sooner, we tell you so citing the article, and if you substantiate the interest we grant it anyway.
- If we rectify or erase data we had already transferred, we have to notify the transferee within the fifth business day (art. 16 para. 4). That propagation is not executed by the platform yet: we do it by hand, with a record, and it is written as such in our internal manual.
Once either of the two deadlines expires, the law does not send you to complain: it lets you sue. Article 14 paragraph 2 says that «quedará expedita la acción de protección de los datos personales o de hábeas data» (the personal data protection or habeas data action shall become available), and article 16 paragraph 3 says that non-compliance «habilitará al interesado a promover sin más» (shall entitle the interested party to bring, without further ado) that same action. There is no prior instance to exhaust.
Those deadlines are not computed by the platform yet, and we would rather tell you: counting Argentine business days requires the calendar of public holidays and judicial recesses, which is not loaded yet. In the meantime your request is filed all the same and we handle it, with the due date marked as estimated and not as certain.
Argentina Annex · Security Incident Notification
Ley 25.326 imposes no general duty today to notify a security breach, neither to you nor to the authority. We do not say it by omission, we say it as an assertion and with its verification:
- Resolución AAIP 47/2018, which approves the security measures for the processing of personal data, sets them out «de modo referencial» (by way of reference) and as recommended; its security incident section speaks of detecting, assessing, containing and responding to them, and does not mention notifying anyone.
- The catalogue of infringements of Resolución AAIP 126/2024 —minor, serious and very serious— does not classify failure to notify an incident as an infringement.
- The duty to notify breaches is new in the reform bill, which has not been enacted. We do not promise it to you as a right in force, because it is not.
What we do, by contract and not because an Argentine statute requires it, is tell you: clause 5 literal i) point ii) of the processing agreement we sign with you obliges us to notify you «sin demora» (without delay) of any accidental or unauthorised access. The notice reaches you with the date and time the incident occurred, not only that of its detection.
What that notice enables you to do is yours and not ours: you decide, as the controller of your database, what you communicate to your data subjects.
And the duty of security is mandatory, even though the catalogue of measures is recommended: article 9 of the law requires the adoption of the necessary technical and organisational measures, and article 25 literal b) of Decreto 1558/2001 says expressly that that article 9 «incumbe también al encargado del tratamiento» (also falls upon the processor).
Argentina Annex · International Transfer
Operating the Service means transmitting your data outside Argentine territory. The platform's infrastructure is in the United States.
Article 12 paragraph 1 of Ley 25.326 prohibits transferring personal data to countries that do not provide adequate levels of protection, and none of the five exceptions in its paragraph 2 covers hosting data in a foreign cloud.
The United States is not on the list of adequate countries. That list is article 3 of Disposición DNPDP 60-E/2016, in the wording given to it by Resolución AAIP 34/2019, and it names the member States of the European Union and of the European Economic Area, the United Kingdom, Switzerland, Guernsey, Jersey, the Isle of Man, the Faroe Islands, Canada only as regards its private sector, Andorra, New Zealand, the Oriental Republic of Uruguay and Israel only as regards data that undergo automated processing. Colombia, Ecuador, the Dominican Republic, Costa Rica and Brazil are not on it either.
The route we use is the one opened by article 12 of Decreto 1558/2001, which recognises an adequate level when the protection derives «del amparo que establezcan las cláusulas contractuales que prevean la protección de datos personales» (from the shelter established by contractual clauses providing for the protection of personal data): the data processing agreement we sign with your firm, which reproduces Annex II of Disposición 60-E/2016 exactly as the authority publishes it. That contract is the instrument of the transfer, and that is why it is accepted together with this policy and not afterwards.
There is a second route that covers one specific part and that is also in that article: no consent is needed to transfer data «desde un registro público que esté legalmente constituido para facilitar información al público» (from a public register legally constituted to provide information to the public). That is what covers what the Service copies from a judicial portal.
Argentina Annex · Subprocessors
The list of the third parties that process data on our behalf, with the country they do it from and what they receive, is published in the Service's subprocessor list and travels attached to the processing agreement every time you accept it, not linked from outside: what is frozen with your acceptance is the text of the contract plus the list in force that day.
In Argentina that is not a courtesy, and the reason has an article. Article 25 paragraph 1 forbids the processor to transfer the data to other persons «ni aun para su conservación» (not even for its safekeeping) beyond what the service contract says, and clauses 5 ll), 5 n) and 10 a) of Annex II require informing you beforehand, obtaining your written consent and sending you without delay a copy of the contract with the subprocessor. Clause 10 d) obliges you to keep that list, updated at least once a year, and to make it available to the authority.
And article 11 paragraph 4 closes the picture, though it is worth reading slowly because it is a chain and not a leap. The rule says the transferee is subject to the same obligations as the transferor «y éste responderá solidaria y conjuntamente por la observancia de las mismas» (and the latter shall be jointly and severally liable for their observance). Applied twice —you transfer to us, we transfer to a subprocessor— you answer together with us and we answer together with it. Put bluntly: each subprocessor of ours ends up being your risk. That is why we name them one by one in the contract instead of hiding them behind a link, and why we do not take on a new one without telling you before it processes your data.
What does soften that chain, and we say it because it plays in your favour: the last paragraph of article 11 of Decreto 1558/2001 says the transferee «podrá ser eximido total o parcialmente de responsabilidad si demuestra que no se le puede imputar el hecho que ha producido el daño» (may be relieved in whole or in part if it shows the act that caused the damage cannot be imputed to it). The joint liability is neither strict nor automatic.
Argentina Annex · Proactive Accountability: Impact Assessment and Data Protection Officer
Two figures that exist in other countries of the Service do not exist in the Argentine regime, and we say it as an assertion and not by omission:
- There is no data protection officer. Neither Ley 25.326 nor Decreto 1558/2001 regulates the figure: there is no duty to appoint one, there is no threshold of data subjects that triggers it and there is no register of officers. The figure appears in the reform bill, which has not been enacted. Who handles your enquiries and your complaints is the Personal Data Protection Area of the section above.
- There is no mandatory prior impact assessment. Neither of the two rules requires one either. We carried one out anyway for the processing with artificial intelligence and for Uruguay, where it is mandatory, and that work is done; but we do not tell you that an Argentine rule requires it of us, because that is not true.
What is mandatory, and we comply with it, is the duty of security of article 9 and the duty of confidentiality of article 10, which subsists «aun después de finalizada» (even after it has ended) the relationship with the owner of the file.
The three figures Argentina does not require —the officer, the duty to notify a breach and the impact assessment— we checked again on September 12, 2026, and we do not take them as settled from an earlier reading: neither of the two words that name the officer appears in the text of Ley 25.326 or of Decreto 1558/2001, nor does the impact assessment; and the consolidated text of the law that InfoLEG publishes carries no note of repeal or replacement. All three would be mandatory under the reform bill, which on that date has four live files and no chamber approval. The day that changes, this annex changes and its version goes up.
Argentina Annex · Retention After Termination
When the relationship with a firm ends we warn its owner at sixty (60) days and erase its data at ninety (90); the thirty days in between are the margin to come back.
Those two windows are platform policy, and Argentine law does not contradict them: over the data your firm loads —its clients, its counterparties, its case files— we act on your behalf, and article 25 paragraph 2 of Ley 25.326 orders them destroyed «una vez cumplida la prestación contractual» (once the contractual service has been performed), allowing them to be kept «por un período de hasta dos años» (for a period of up to two years) only with your express authorisation. We do not ask you for that authorisation and we do not use it: ninety days sit comfortably below that cap.
Once the erasure is done we hand you the certificate of destruction, and we do not file it only for ourselves: clause 12 of the processing agreement obliges us, at your choice, to return the data to you or to destroy it «certificando tal hecho» (certifying that fact).
What outlives the erasure, and why:
- The proof of your authorisation and of the processing —the consent log and the audit log—, because article 5 requires consent to be given in writing or by an equivalent means, and because articles 9 and 10 oblige the controller and the processor to be able to evidence the security and confidentiality measures they adopted.
- The data subject rights requests and their resolution, which are the proof of having handled them within the ten calendar days of article 14.2 and the five business days of article 16.2.
- The billing trail, which is data about your firm as our client and not data processed on your behalf: we keep it for as long as it is necessary for the relationship and to be able to prove it, under article 4 paragraph 7 and article 16 paragraph 7.
On that last point there is an Argentine ten-year period, and it is not ours. Article 328 of the Código Civil y Comercial requires books, other records and supporting instruments to be kept for ten years, and article 33 of Ley 11.683 empowers the federal tax administration to require that the vouchers of transactions be kept for that same term. Both bind whoever keeps accounting books or pays taxes in Argentina — it is your term, not ours: Custodio Legal keeps no Argentine accounting books and is not a taxpayer there. That is why we cite you the rule, which may govern what you have to keep of this relationship, and we promise you no term of our own for the billing trail: it would mean inventing an obligation we do not have in order to justify a retention that has no number.
Brazil annex
It governs the general clauses of this document that refer to it.
Brazil Annex · Who the controller is
Custodio Legal, identified with NIT 1057602936 of the Republic of Colombia, with legal domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia, provides the Service. You can write to us at [email protected] or call us at +57 333 431 8597.
We have no establishment or representative domiciled in Brazil. The LGPD reaches us all the same, and we say so because it is worth your knowing: its art. 3º, II applies it to any processing whose purpose is to offer goods or services to people located in the national territory, and art. 11 § 2º of the Marco Civil da Internet reaches the foreign legal entity that offers a service to the Brazilian public.
Over your firm's data —your account, your billing, your consent log— we are the controller. Over the data your firm uploads into its matters —its clients', its opposing parties' and the third parties who appear in them— we are the operator: we process it on your behalf and on your instruction, and you are the controller. That second processing is governed by the cláusulas-padrão contratuais of Anexo II of Resolução CD/ANPD nº 19/2024, which we sign with you in the data processing agreement.
There is no encarregado designated, and it is not an oversight. Art. 41 of the LGPD says «o controlador deverá indicar encarregado»: the duty is the controller's, and the operator does not appear in the text. Art. 6º of Resolução CD/ANPD nº 18, of July 16, 2024, closes it in so many words: «A indicação de encarregado por operadores é facultativa e será considerada política de boas práticas de governança». The contact channel exists all the same and it is [email protected].
There is something this annex does not claim, and it is worth saying: we are not an «agente de tratamento de pequeno porte» in the sense of Resolução CD/ANPD nº 2/2022. Its art. 2º, II requires registration in a Brazilian commercial registry, which a Colombian company does not have, and its art. 3º, I takes out of the regime anyone carrying out high-risk processing, which we fall into through our use of artificial intelligence. We do not claim a benefit that is not ours.
Brazil Annex · Applicable law and supervisory authority
The processing of personal data of data subjects domiciled in Brazil is governed by Lei nº 13.709, of August 14, 2018 — Lei Geral de Proteção de Dados Pessoais (LGPD).
The supervisory authority is the Agência Nacional de Proteção de Dados (ANPD), which has been a regulatory agency since Lei nº 15.352, of February 25, 2026, which gave new wording to art. 55-A of the LGPD and to art. 5º, VIII. It is before the ANPD that you complain if you are not satisfied with what we do, and you can also write to us at [email protected].
A data subject is always a natural person. Art. 5º, V of the LGPD says so, and it is not a drafting detail: a legal entity does not hold data protection rights in Brazil, unlike in Argentina and Uruguay. The rights this annex describes belong to natural persons.
The legal bases for processing are named, not inferred. Art. 7º of the LGPD lists the hypotheses, and three govern us:
- Art. 7º, V —performance of the contract with the data subject— supports the processing of your account data and of the people in your firm.
- Art. 7º, VI —«para o exercício regular de direitos em processo judicial, administrativo ou arbitral»— supports the processing of the data of parties, opposing parties and third parties who appear in a matter. It is not our reading of a general principle: it is written in those words, and it is the hypothesis a matter occupies exactly.
- Art. 7º, II —compliance with a legal or regulatory obligation— supports what we keep because a rule requires it, and it is in the retention section.
Over all of them run the principles of art. 6º: purpose, adequacy, necessity, free access, quality, transparency, security, prevention, non-discrimination and demonstrated accountability.
The duty that falls on us as operators is in art. 37: keeping a record of the processing operations we carry out. It is a standalone obligation, not derived from the contract, and it is not a filing with the authority: it is our own, and producible when the ANPD asks for it. Brazil has no register of databases before the authority, unlike Argentina and Uruguay.
Brazil Annex · The data the courts publish
The Service reads what the courts publish about a matter in the public e-SAJ case lookups it watches. It is worth saying under what condition, because Brazilian law does not say that public data is free.
Art. 7º, § 3º of the LGPD requires that the processing of publicly accessible personal data «deve considerar a finalidade, a boa-fé e o interesse público que justificaram sua disponibilização», and § 7º repeats the condition for any subsequent processing. It is a condition, not a permission.
What we do falls within that purpose, and we describe it so you can judge it: we read the docket of the matters your firm points us to, so as to alert you to their movements and calculate their deadlines. That is the reason the court publishes the docket.
What we do not do, and this is not a vague promise but the limit the rule imposes: we do not build commercial profiles of the parties with that data, we do not sell it, we do not hand it to third parties outside the provision of the Service and we do not use it to train artificial intelligence models.
Brazil Annex · Your rights and their deadlines
Art. 18 of the LGPD gives you, against the controller: confirmation that processing exists; access to the data; correction of incomplete, inaccurate or out-of-date data; anonymization, blocking or deletion of unnecessary or excessive data or data processed in breach of the law; portability to another provider; deletion of data processed with your consent, save for the exceptions of art. 16; information about the entities with which data was shared; information about the possibility of not giving consent and its consequences; and withdrawal of consent. § 1º adds the right to petition the ANPD.
The deadlines, with the rule that sets them:
| Right | Deadline | Rule |
|---|---|---|
| Confirmation that processing exists, and access, in simplified form | immediate | LGPD, art. 19, I |
| Access by clear and complete statement | fifteen (15) calendar days from your request | LGPD, art. 19, II |
| The other rights of art. 18 | fifteen (15) calendar days | Clause 15.3 of Anexo II of Resolução CD/ANPD nº 19/2024 |
The fifteen days are calendar days and not business days: neither art. 19, II nor Clause 15.3 says «úteis», and Resolução nº 15/2024 does say it when it means it.
There is an asymmetry we would rather tell you than hide: the only deadline the law sets is the one for access. For the other rights, art. 18 § 5º refers to a regulation, and as of the date of this annex we did not find that regulation published. The fifteen days we apply to every right come from the contract the ANPD itself drafted —Clause 15.3 of its cláusulas-padrão—, not from the law, and that is why we can promise them without inventing anything.
If the request reaches us and the controller is your firm. Art. 18 § 3º allows the request to be addressed to any processing agent, the operator included. When that happens, art. 18 § 4º, I gives us the exact way out and we use it: we reply that we are not the agent that decides about that data, we tell you which one is —the firm— and we pass the request on immediately, so it can answer you in time. Clause 15.4 of Anexo II requires the same.
Brazil Annex · Security incident notice
If a security incident occurs that may entail relevant risk or damage to data subjects, we give notice.
The Brazilian clock is short and it has to be stated in hours. Art. 6º of Resolução CD/ANPD nº 15, of April 24, 2024, gives the controller three (3) business days to report the incident to the ANPD, counted from when it knows the incident affected personal data, and art. 9º gives it the same period to report it to the data subjects. That deadline is the controller's —your firm, as to the data it uploads—. Ours is to warn you well before that clock starts squeezing you, with the information you need to comply with it, and to be able to prove when we warned you. Our commitment is to contact you within twenty-four (24) hours of learning that an incident affected your firm's personal data.
In Brazil an incident involving a firm's data is always reportable, and that is not to be argued case by case: art. 5º, V of that resolution declares relevant those incidents involving «dados protegidos por sigilo legal, judicial ou profissional», which is exactly what a matter contains. Art. 7º, II of Lei nº 8.906/1994 covers the lawyer's working instruments and electronic correspondence with inviolability, and its art. 34, VII makes breaking professional secrecy a disciplinary offence.
What the report must contain. Art. 6º § 2º sets out its content, and one of its items names us: item X asks for «a identificação do operador, quando aplicável». That is where we appear, and we give you in writing what you need to fill it in. § 3º allows the information to be completed within twenty (20) business days from the report, and art. 9º § 3º requires that, when individual communication to the data subjects is unfeasible, the public disclosure last at least three months.
The incident log is ours and it lasts five years. Art. 10 of the same resolution requires the incident record to be kept for a minimum of five years, and expressly includes incidents that were not reported. Clause 16.2 of Anexo II places that duty on the importer, that is, on us, and we comply with it.
Brazil Annex · International transfer
Operating the Service means transmitting your data outside Brazilian territory.
The route is that of art. 33, II, b) of the LGPD: the cláusulas-padrão contratuais that the ANPD approved in Anexo II of Resolução CD/ANPD nº 19, of August 23, 2024, which we sign with your firm in the data processing agreement. That model is adopted whole and unaltered: art. 16 of that resolution says the validity of the transfer «pressupõe a adoção integral e sem alteração do texto disponibilizado no Anexo II», and its § 2º forbids any other clause of our contracts from excluding, modifying or contradicting it «direta ou indiretamente».
Why not the adequate-country route. Art. 33, I allows transfers to countries with an adequate level of protection, and that adequacy is declared by the ANPD through a Resolução published on its site (art. 13 of the Regulamento). We looked for that publication and the only one that exists does not reach Colombia: the ANPD recognised the European Union as an adequate international organism through Resolução nº 32, of January 26, 2026, and its own site says it will update the list «conforme outras decisões como essa forem emitidas». No country in the Americas is on it. So that route is not available for this transfer, and even if one appeared, the signed contract would remain standing: an adequacy decision can be revoked, a contract cannot.
And why not the item IX route either. Art. 33, IX allows the transfer «quando necessário para atender as hipóteses previstas nos incisos II, V e VI do art. 7º», and item VI is precisely the regular exercise of rights in judicial proceedings. Read alone, it would seem that a platform like this one can transfer with no contract at all. It is not so: art. 9º of the Regulamento requires both things at once —a legal hypothesis of art. 7º and a valid transfer mechanism—, and anyone using item IX as a substitute for the contract is reading half the rule.
What that contract obliges us to do, and what this annex states because it affects you:
- The forum is Brazilian. Clause 24.1 submits any dispute to the competent courts of Brazil, and 24.2 allows the data subject to sue us before the court of their own residence. Clause 24.3 only admits arbitration held in Brazil.
- If an authority asks us for access to your data, we tell you. Clause 19.1 obliges us to notify you and the data subject, unless the law of the country of processing forbids the notification; and 19.2 obliges us to take legal measures, court actions included, when there is ground to challenge the lawfulness of the request. We also keep the log of those requests that Clause 19.3 requires, with the date, the requester, the purpose, the type of data, how many times it arrived and what we did.
- We answer for our sub-processors as if they were us. Clause 18.2, c) makes us «responsável por eventuais irregularidades praticadas pelo terceiro destinatário», and 18.2, b) obliges us to guarantee by written contract that the safeguards reach them. The list of who they are, with their role and the jurisdiction where the data ends up, travels attached to the data processing agreement every time it is accepted.
- Everything made available to the data subject is in Portuguese. Clause 14.4 requires it. That is why the data processing agreement has its official text in Portuguese, and the Spanish and English versions are courtesy translations.
Brazil Annex · Retention after termination
When the relationship with a firm ends we notify its owner at sixty (60) days and delete its data at ninety (90); the thirty days in between are the margin to come back.
Those two windows are platform policy, and Brazilian law does not contradict them: art. 16 of the LGPD requires personal data to be deleted at the end of its processing and authorizes keeping it —among other things— for compliance with a legal or regulatory obligation of the controller. Clause 20 of Anexo II repeats the four listed exceptions.
What survives deletion, and why:
- The proof of your authorization and of the processing —the consent log and the audit log—, because art. 37 obliges the controller and the operator to keep a record of the processing operations they carry out, and because the burden of proving that consent was obtained rests on the controller (art. 8º § 2º).
- The application access logs, which art. 15 of the Marco Civil da Internet (Lei nº 12.965/2014) requires to be kept under secrecy, in a controlled and secure environment, for six (6) months. It is best not to read it backwards: it is a minimum retention period, not a deadline to delete. And its § 3º says what really matters: those logs are handed over only by court order. We invoke that article directly, and not the «compliance with a legal obligation» exception of the data processing agreement, because that obligation is the controller's and this one is ours.
- The security incident log, including the incidents that were not reported, for the minimum of five (5) years of art. 10 of Resolução CD/ANPD nº 15/2024.
- The log of authority access requests of Clause 19.3 of Anexo II. The rule sets no period for it and the ANPD or your firm may ask for it at any time, so we keep it and we do not promise you a deletion date the rule does not give.
- Data subject rights requests and their resolution, which are the proof of having answered them within the fifteen days of art. 19, II.
- The billing trail, which is data about your firm as our customer and not data processed on your behalf: we keep it for as long as it is necessary for the relationship and to be able to prove it. We do not promise you a period, and now we know why we cannot: we did not read the Código Tributário Nacional in an official source, and the Brazilian period we did read —the five years of art. 206, § 5º of the Código Civil for the fee claims of liberal professionals— is a period of your firm against its clients, not ours against you. Writing it here as if it were ours would be citing a rule that does not govern this relationship.
We do not anonymize the audit log on a fixed schedule, and that is a statement and not an oversight: no Brazilian rule we read sets how long the personal data of an audit line lives. The six months of the Marco Civil are the opposite —a retention floor— and the five years of Resolução nº 15/2024 belong to the incident log. Writing a window with no rule behind it would be inventing it.
Other published annexes: Colombia · Ecuador · the Dominican Republic · Costa Rica · Uruguay · Argentina · Brazil