Skip to content

Privacy policy

Personal Data Processing Policy

Last updated: September 10, 2026

Custodio Legal respects the personal data and information provided by its current, past, and potential clients. This Personal Data Protection Policy establishes the purposes, measures, and procedures for our databases, as well as the mechanisms available to data holders to know, update, rectify, delete provided data, or revoke the authorization granted with the acceptance of this policy, in accordance with Ley Estatutaria 1581 de 2012, Colombia's data protection statute, and Decreto 1377 de 2013, with Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP) and its Decreto Ejecutivo 904, with the Dominican Republic's Ley núm. 172-13, and with Costa Rica's Ley N° 8968, on the protection of the person with regard to the processing of their personal data, and its Reglamento (Decreto Ejecutivo N° 37554-JP), the four countries in which we offer the service. The rules are named as their own official gazettes publish them, in Spanish, so you can check each one against the source; the gloss that follows a name the first time it appears says what it is.

If your data lives in the matter of a firm that uses Custodio, you can exercise your rights here: Exercise your habeas data rights

1. Data Controller and Data Processor

Custodio Legal is the trade name under which Nicolás Rodríguez Lasso, identified with NIT 1057602936, with domicile at Carrera 17 #2-81, Sogamoso, Boyacá, Colombia, provides the service. You can contact us at [email protected] or by phone at +57 333 431 8597; the area that handles queries and claims is the Personal Data Protection Area, at that same email address.

This policy distinguishes two situations, because the law gives you a different counterpart in each one:

  • (i) When you use the platform -you sign up, belong to a firm, work in it-, Custodio Legal is the controller of your personal data: it decides what it is processed for and answers to you for it.
  • (ii) When your personal data appears in a matter a firm manages through the platform -as a client, opposing party or interested party in a proceeding-, the controller is that firm, which decided to process it and must have obtained the authorization the law requires, and Custodio Legal acts as processor: it processes that data on the firm's behalf, under the service contract and its instructions, and does not decide on it on its own. If you write to us to exercise a right over data held in a matter, we forward your request to the responsible firm within the following two business days, tell you we did, and give you its contact details so you can approach it directly.

Collected data will be processed legally, lawfully, confidentially, and securely, respecting the principles of purpose, freedom, truthfulness, transparency, restricted access, security, and confidentiality.

2. Purpose of Processing

The processing of personal data has the following purposes:

  • a) Provision of contracted legal and administrative management services.
  • b) Managing the contractual relationship with clients, lawyers, and collaborators.
  • c) Sending service-related communications, updates, and legal notifications.
  • d) Billing, collection, and accounting management.
  • e) Conducting satisfaction surveys and service improvement.
  • f) Compliance with legal obligations and requirements from competent authorities.
  • g) Fraud prevention and platform security.

3. Rights of Data Subjects

As the holder of your personal data, you have the following rights, which you may exercise free of charge and at any time:

  • (i) ACCESS: Know what personal data we process about you, the purpose of processing, and who we share it with.
  • (ii) RECTIFICATION: Update and correct partially accurate, incomplete, or outdated data.
  • (iii) CANCELLATION/DELETION (Habeas Data): Request deletion of your data when it is no longer necessary for the purpose that justified its processing, or when you have revoked your consent, subject to legally mandated retention obligations.
  • (iv) OBJECTION: Object to the processing of your data for marketing, profiling, or automated decision-making purposes.
  • (v) PORTABILITY (LOPDP Ecuador, Art. 17): Download a structured, machine-readable copy of your account data -your personal information, your consent history, and the record of your own actions on the platform- from 'My account > Your privacy'. This automatic download does not currently include the matters or documents your firm manages about you; to access that information, submit an access request through the channels in Section 7. If your data is held in a matter and you are not a user of the platform, Section 1 (ii) applies: the controller is the firm, and we forward your request to it.
  • (vi) File complaints with your country's supervisory authority, where your country has one. Which one it is, how to write to it and what it requires of you before you turn to it is stated by your country's annex, which also says whether your country created none and what route is left to you then.
  • (vii) Withdraw consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.

4. Authorization and Consent

The processing of personal data requires the free, prior, express, and informed consent of the data holder. By registering on the platform and accepting this policy, you declare that:

  • (i) The data provided is truthful and accurate.
  • (ii) You have the legal capacity and authority to authorize its processing.
  • (iii) You understand the purposes of the processing.
  • (iv) You have been informed of your rights as a data holder.

Authorization may be revoked at any time following the procedure established in this policy.

5. Information Security

We implement technical, administrative, and organizational security measures to protect your data:

  • (i) AES-256-GCM encryption of the most sensitive data we store: document number, address and phone; description, objective and internal notes of matters; and the content of your conversations with the artificial intelligence assistant.
  • (ii) Encrypted transmission over TLS.
  • (iii) Role-based access control (RBAC).
  • (iv) Audit records of the relevant actions over your data, which are never deleted.
  • (v) Database backups on the infrastructure of the hosting provider described in Section 10.
  • (vi) Watching for improper access patterns, such as bursts of failed sign-in attempts or unusual downloads of information.

These measures answer what Ley 1581 de 2012, the LOPDP, Article 5, paragraph 5, and Article 13, paragraph 2, of the Dominican Republic's Ley núm. 172-13 and Article 10 of Costa Rica's Ley N° 8968 require — the latter ordering that «las medidas de índole técnica y de organización necesarias para garantizar la seguridad de los datos de carácter personal» be adopted — and follow industry good practice.

If we detect a security incident that puts your personal data at risk, we notify you without undue delay and inform your country's supervisory authority, where your country has one to present it to. Which authority we inform, within what term, within what term we notify you, and whether that term is set by a rule or adopted by our own decision, is stated by your country's annex.

6. Attention Channel (Habeas Data)

To exercise your rights as a data holder, you can contact us through:

Which procedures your law distinguishes, within how many days we answer each of them, from when they are counted and what extension they admit is stated by your country's annex, each term with the rule that sets it or with the warning that it is ours and not the law's.

While we handle a claim, the corresponding record is flagged as "claim in process" within the following two business days, so that no one treats it as if it were unchallenged. If your claim is incomplete, we tell you within the following five (5) business days so you can complete it; if two months pass without your replying, we understand that you withdrew it, and you may file it again whenever you like. We do those three things the same way in all four countries.

7. How to Exercise Your Rights (ARCO)

You can exercise your rights to Access, Rectify, Cancel, and Oppose directly from your account in 'My account > Your privacy'. You can also send a written request to [email protected] indicating:

  • (i) Your full name and identity document.
  • (ii) Description of facts and request.
  • (iii) Physical or electronic address for notifications.
  • (iv) Supporting documents if applicable.

8. Sensitive Data and Data of Minors

Custodio Legal may process sensitive data only when strictly necessary for the provision of legal services and with your express authorization. Sensitive data includes data revealing racial or ethnic origin, political orientation, religious convictions, union membership, health data, sexual life, and biometric data. This data will receive enhanced protection.

A judicial case file may contain sensitive data and also data of children and adolescents. Custodio Legal neither asks you for that data nor collects it on its own: it arrives at the platform inside the case file the firm manages, and it is the firm -as controller- that must have obtained the authorization the law requires to process it. You are not obliged to authorize the processing of sensitive data and no one may condition a service on your doing so; data of minors may only be processed respecting their best interests and their fundamental rights, and it is their legal representative who exercises their rights. We process it with the same security measures of Section 5, without using it for any purpose other than managing the matter it appears in.

9. International Data Transfer

Your data may be transferred and processed in third countries. Our hosting and infrastructure provider, transactional email provider, payment gateway, technical monitoring provider, the network and protection provider for the site and the application, and the vector representation (embeddings) provider, all described in Section 10, are located in the United States, and so is Google, which is not a processor but an independent controller and is covered by Section 15. The Artificial Intelligence text generation provider described in Sections 10 and 14 is domiciled in the Netherlands and declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model.

Those destinations are the same for the data subjects of every country in which we offer the Service. What changes with your country is the safeguard that backs each sending: whether your law recognizes countries with an adequate level of protection and which ones they are, whether sending to a processor counts as a transfer at all, and which article permits the one that does. Your country's annex states that, with the rule that sustains it, in its international transfer section.

Two things hold the same in all four countries, and that is why they are here and not in an annex: by accepting this policy you give your express and informed consent to the transfer, knowing the destination and which safeguard backs it; and Section 14 (iii) states, provider by provider, which guarantee is actually written down and which is not.

10. Data Processors

To provide our services, we share data with third-party data processors who act under our instructions. Each one incorporates into its terms of service a data processing agreement that we accept when contracting it and that obliges it to process your data on our behalf and not for its own purposes. Not every third party we exchange data with is a processor: Google is not, which is why it is not on this list but in Section 15.

  • (i) Railway (United States) - Hosting of the platform: the servers, the database, the task queue and their backups. It is the processor that hosts all the data the platform stores.
  • (ii) Resend (United States) - Transactional email delivery: it receives your email address and the content of the notices.
  • (iii) Polar.sh (United States) - Payment gateway and billing: it receives the contact email and the firm's name.
  • (iv) Nebius B.V., a Dutch company domiciled at Schiphol Boulevard 165, 1118 BG Schiphol, the Netherlands, which operates the Nebius Token Factory service - Text generation with the GLM-5.3-Flash model for the Artificial Intelligence features: summary, deep analysis, document drafting and questions with citations over your documents. That service's terms are governed by the law of the Netherlands and its disputes are submitted to the courts of Amsterdam. The provider declares that it runs inference in data centers located in the European Union, Israel or the United States depending on the model, states each model's country in its catalog, and publishes the list of the sub-processors it appoints.
  • (v) Voyage AI (United States) - Generation of the vector representations (embeddings) of your document text, which make the semantic search behind the questions with citations (Q&A) feature possible.
  • (vi) Alternate text generation providers, registered in the platform and carrying no traffic today: Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD., domiciled at 10 Anson Road #26-03, Singapore, which operates the z.ai service. Neither receives any of your data: the platform keeps their connections configured so we can fall back to them if the provider in item (iv) becomes unavailable. Activating one would change the processor and the jurisdiction of the transfer, so we would not do it without raising the version of this policy and asking you for a new authorization, as required by Section 12.
  • (vii) Sentry (United States) - Technical error monitoring: it receives the route where the error occurred and your internal user identifier; before each event is sent we strip your email, your name and your IP address.
  • (viii) Cloudflare (United States) - Delivery and protection network for the site and the application: all traffic between your browser and us goes through its network, so it processes in transit the IP address and the metadata of each connection; it also controls access to our internal documentation.

We do not claim to have negotiated with any of them clauses beyond those their own terms incorporate, nor to hold a separately signed contract, nor that they hold security certifications we have audited: Section 14 (iii) states exactly what is written down for the Artificial Intelligence providers. We do not keep the original file you upload to a matter: it is processed transiently to extract its content and is then deleted. What we retain is the extracted text, so the matter can be searched and consulted; the file itself is never shared with these processors. The optical character recognition (OCR) of that text runs on our own service, within our own infrastructure, and is never sent to an external provider.

11. Data Retention and Deletion

We retain your personal data for as long as a relationship exists with the firm that provides you the service and for as long as the legal and contractual obligations that justify keeping it remain in force. We do not delete data automatically based on the passage of time: it is deleted or anonymized when appropriate, for example when we approve a cancellation request from you (Section 3, Habeas Data). When your firm's account ends, we delete or anonymize the data the platform holds for that firm within the ninety (90) days following termination, unless a legal retention obligation applies. There is one deliberate exception: the records of your consent, of our audits, and of your own ARCO requests survive that deletion, even after the rest of your data is anonymized, because they are the evidence that we comply with this policy. We do not keep them indefinitely, nor because we decide to: how long each one is kept, and the rule that requires or limits it, is stated by your country's annex in its «Retention After Termination» section, which is the text that governs over this Section.

12. Validity and Modifications

The version of this policy in force is 0.0.12, effective as of September 10, 2026. Version 0.0.12 corrects what Section 11 promised beyond what the country annexes allow: it said the records of your consent, of our audits and of your ARCO requests «are never deleted», while the annexes —which have governed over this trunk since 0.0.8— tie them to a rule and to a term. The Dominican annex binds them to the limitation period of the liabilities arising from the processing (Ley núm. 172-13, Article 15, the Dominican personal data protection statute) and the Costa Rican one to the ten-year ceiling of Article 11 of the Reglamento to Ley N° 8968, Decreto Ejecutivo N° 37554-JP. «Never» is longer than either of those allows, so the trunk stops setting that window and refers to the one in your country's annex, where it is written with the rule that sustains it. It changes neither who processes your data, nor where, nor what for, nor the two windows your annex publishes —notice sixty (60) days after the relationship ends and deletion at ninety (90)—: what changes is that this trunk stops promising a retention longer than your own law admits. That is why we do not ask you for a new authorization, and the one you gave over 0.0.11 — or over 0.0.10 or 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.11, in force from September 10, 2026. Version 0.0.11 corrects two places where the text contradicted itself. The first: Sections 6 and 9 still counted three countries when there have been four since 0.0.9 — the very version that names four of them in the preamble, in Section 12 and in Section 13. The second lives only in the English translation, and it is the one that matters for checking us: the rules of Colombia and Ecuador were translated — «Statutory Law 1581 of 2012», «Executive Decree 904» — next to those of the Dominican Republic and Costa Rica, which were transcribed. A translated rule cannot be checked against the official gazette that published it. From this version the four are named as their own source publishes them, in Spanish, with an English gloss the first time, which is what the eight country annexes already did. Not one piece of data, one destination, one deadline or one processor changes: that is why we do not ask you for a new authorization, and the one you gave over 0.0.10 — or over 0.0.9 — still covers this text, with your record intact. It replaces version 0.0.10, in force from September 10, 2026. Version 0.0.10 completes with the Dominican and Costa Rican rules a line that enumerated only two countries from before there was a third: Section 5 now names, alongside Law 1581 and the LOPDP, Articles 5 and 13 of Ley núm. 172-13 and Article 10 of Ley N° 8968 as the rules the security measures we already applied come from. It changes not one measure, nor who processes your data, nor where, nor any deadline: what changes is that your own rule is written with its article instead of being covered by a general formula. That is why we do not ask you for a new authorization: the one you gave over 0.0.9 still covers this text, and your authorization record is kept intact. It replaces version 0.0.9, in force from 10 September 2026. Version 0.0.9 adds Costa Rica: the service is now offered in four countries and this policy also names Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP, with the Costa Rican annex saying what they mean for you. It changes neither who processes your data, nor where, nor what for, nor any deadline of the other countries: what changes is the list of laws that govern it. Even so we ask you for a new authorization of this text, because the platform would rather ask again than take as given an authorization made over a different wording, and the record of your previous authorization is kept intact as evidence of what you authorized at the time. It replaces version 0.0.8, in force since 9 September 2026. Version 0.0.8 changes not one piece of data, not one destination and not one deadline: it splits the same text between this trunk and your country's annex. Since the three annexes were published, the supervisory authority, the deadlines for handling your rights, the incident notice and the basis of the international transfer were stated twice, once here in general terms and once in the annex with the rule that sustains it. This trunk now states the rule that held the same in the three countries offered at the time and refers to the annex, and the annex states what your law makes concrete. What you authorize is the same; what changes is that it is written once, in the document that cites your rule. It replaces version 0.0.7, in force since 9 September 2026, which corrects Google's legal figure: until 0.0.6 this policy listed it among the data processors of Section 10, under a heading stating that every third party on that list acts under our instructions and holds a data processing agreement with us. It does not. The two uses we make of it -sign-in and the public-site Ads tag- are governed by terms between independent controllers, which the new Section 15 cites by version and explains: what changes in the safeguard of the transfer, that no instrument of theirs obliges them to notify us of a breach, and before whom you exercise your rights. No data sent to it and no destination changes: what changes is what this policy claimed about it, which was not accurate. It replaces version 0.0.6, in force from 4 September 2026, version 0.0.5, which was in force from September 2026, version 0.0.4, which was in force from September 2026, version 0.0.3, which was in force from August 2026, version 0.0.2, which was in force from August 2026, and version 0.0.1, which was in force from February 2026. Version 0.0.6 named, one by one, data processors that earlier versions described generically or did not mention -the hosting provider, the email provider, the payment provider, the monitoring provider, Google and Cloudflare-, declares our role as processor over the data held in a firm's matters, and corrects the response deadlines, the incident notification and the safeguards for each destination. Since the list of processors you authorize changes, the platform will ask you for a new authorization of this text, and your previous authorization record is kept intact as evidence of what you authorized at the time. Version 0.0.5 only declared Zero Data Retention with the text generation provider, changing neither the processor nor the jurisdiction, which is why it did not ask for a new authorization; version 0.0.4 changed the processor that generates the text for the Artificial Intelligence features and the jurisdiction of that transfer -from JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore) to Nebius B.V. (the Netherlands)- and did ask for one. Each version remains in effect until replaced by a new one. We reserve the right to modify this policy at any time. We will notify you of any material changes by email or through a prominent notice on the platform at least 15 days in advance. When the change alters what you authorize -who processes your data, where, or for what-, notice alone is not enough: the platform will ask you for a new authorization of the text in force before you can continue, and the record of your previous authorization is kept intact. In every other case, continued use of the service after notification constitutes acceptance of the changes.

13. Applicable Legal Framework and Language

This policy is governed by Ley Estatutaria 1581 de 2012 and Decreto 1377 de 2013 (Colombia), by the Ley Orgánica de Protección de Datos Personales and its Decreto Ejecutivo 904 (Ecuador), by Ley núm. 172-13, on the comprehensive protection of personal data (Dominican Republic), and by Ley N° 8968 on the protection of the person with regard to the processing of their personal data and its Reglamento, Decreto Ejecutivo N° 37554-JP (Costa Rica), the four countries in which we offer the service; each data holder is covered by the regulations of their country of residence, which that country's annex details. This policy is drafted in Spanish and we also publish an English translation so you can read it in that language; in case of any discrepancy between the two versions, the Spanish version prevails.

14. Artificial Intelligence (AI) Processing

Custodio Legal offers Artificial Intelligence features (currently: case and service summary, deep analysis, document drafting and questions with citations over your documents, known as Q&A) that are optional and user-initiated. AI processing is governed by the following principles:

  • (i) LEGAL BASIS: Express consent, given in two ways depending on what triggers the operation. For the features you start yourself -summary, deep analysis, document drafting and questions with citations- consent is given by executing each operation on the case or service you are working on, a voluntary act that draws down your firm's token allowance. For the processing that runs without a click, listed one by one in item (viii), it is given by accepting this policy -which describes them- and by uploading the document or updating the matter that triggers them. In both cases the processing is limited to what is necessary to provide the contracted service.
  • (ii) DATA MINIMIZATION: Only what the requested operation needs is sent to each provider, and what is sent depends on the feature. For the summary, the deep analysis and the document drafting we send the text of the active case or service -description, parties and a bounded number of the most recent case activities-, and we do NOT send the file attachments. For the questions with citations (Q&A) feature we DO send the content of your documents: when your plan enables it, once optical character recognition (OCR) of a document finishes its text is sent to Voyage AI to generate its vector representation, and when you ask a question the most relevant document fragments are sent to the text generation provider together with your question and the citations the answer must carry. For fact extraction, which runs on its own once a document finishes processing, a bounded extract of the text extracted from that document is sent to the text generation provider to identify parties, dates, amounts, identifiers, obligations and deadlines. For the matter reevaluation we send those already-extracted facts together with the data of the case or service and its case activities, not the full text of the documents. The concrete caps -how many case activities and how many characters- are set by the platform's current configuration and may change without changing what you authorize: in no case is more sent than the operation you asked for needs. No feature ever sends metadata of other cases, information about other clients, or data from other firms.
  • (iii) AI PROVIDERS AND WHAT GUARANTEE EACH ONE CARRIES: Text generation is provided by Nebius B.V. (the Netherlands), which operates the Nebius Token Factory service, with the GLM-5.3-Flash model; the vector representations (embeddings) behind semantic search are provided by Voyage AI (United States); Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore, the z.ai service) are registered as alternate text generation providers and receive none of your data today. We tell you, guarantee by guarantee, what is written down and what is not: (a) the text generation provider incorporates a data processing agreement into its own terms of service, with the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 for transfers outside the European Economic Area, and states in its published legal guide that customer content is not used to train or fine-tune models (verified on 3 September 2026); the embeddings provider applies the opt-out we have contracted; (b) traffic to all of them travels encrypted in transit over TLS, which is how they publish their interfaces; (c) the text generation provider publicly claims ISO 27001, ISO 27701 and SOC 2 Type II certifications and publishes its sub-processor list, but that is its own claim, which we have neither audited nor checked against the certificates, and we do NOT claim to have negotiated clauses with it beyond those its own terms incorporate, nor to hold a separately signed contract.
  • (iv) RETENTION AT PROVIDER: Zero Data Retention is enabled on our organization with the text generation provider as of 4 September 2026. According to what that provider publishes, with Zero Data Retention enabled the inputs (the text sent to it) and the outputs (the text it returns) are not stored on its systems after each request is processed, are not used for speculative decoding, and are not used to train, fine-tune, or improve any model, whether its own or a third party's; the option applies at the organization level and covers all of its projects and endpoints (Nebius published legal guide, "Legal Quick Guide", consulted on 4 September 2026 on the provider's documentation site). We also tell you, with the same precision, what that guarantee does NOT settle: it is a statement published by the provider and not a control we have audited; it operates going forward and does not reach submissions made before 4 September 2026, over which the default processing of its terms of service (version of 20 August 2026) continued to apply, keeping inputs and outputs to train small models used for speculative decoding; its published documents do NOT say whether Zero Data Retention reaches any records the provider may keep to detect abuse of the service, nor whether it applies in the same way to responses delivered as a stream, so we claim neither of those two things; and enabling it is up to us, so if we ever disabled it we would update this section before doing so. The embeddings provider applies zero retention through the opt-out we have had active since 12 August 2026, which operates going forward and not over earlier submissions.
  • (v) INTERNATIONAL TRANSFER: AI processing occurs on servers located outside the countries in which we offer the Service. Text generation is contracted and billed by Nebius B.V., domiciled in Schiphol (the Netherlands), under Dutch law and with the courts of Amsterdam as the forum; the provider declares that it runs inference in data centers in the European Union, Israel or the United States depending on the model. Embeddings are processed in the United States. The safeguard that backs each of those sendings is the one in Section 9: your country's annex states it, destination by destination and with the rule that sustains it.
  • (vi) AUTOMATED DECISIONS: AI outputs are supporting material; no legal or contractual decisions are made fully automatically. The professional judgment of the attorney is irreplaceable (see Terms of Service, Section 17).
  • (vii) APPLICABLE ARCO RIGHTS: You may exercise access, rectification, deletion, and opposition rights over data processed by AI. Deletion in our own systems is immediate. For the text generation provider, the Zero Data Retention described in item (iv) means that, as of 4 September 2026 and according to what it publishes, no inputs or outputs remain stored to be deleted once each request has been processed. What we still cannot offer you is a contractual deletion deadline of our own or enforceable deletion evidence: that guarantee is a published statement of the provider that we have not audited, and it does not reach submissions made before that date. If you ask us through the channels of Section 6, we pass the request on to the provider and tell you its answer.
  • (viii) WHAT RUNS ON YOUR CLICK AND WHAT RUNS ON ITS OWN: The features that produce a result for you to read -case and service summary, deep analysis, document drafting and questions with citations- require an express click by you on the case or service being worked on, so not using them is equivalent to authorizing no such processing at all. Three kinds of processing do run without a click, always over data from your own firm's matters and never over another firm's: (a) the indexing behind questions with citations (Q&A), which runs when a document finishes optical character recognition (OCR) if your plan enables it; (b) the extraction of facts from the document just processed, which identifies parties, dates, amounts, identifiers, obligations and deadlines; and (c) the matter reevaluation, which refreshes its state and its attention items when a document arrives, when you edit the case or service, or when a query to the judicial portal brings in a new case activity. All three operate over the documents and matters your firm uploads or updates under its declaration that it holds the authorization of the data subjects whose data they contain: the firm is the controller of that data, as Section 1 (ii) says, and Custodio Legal processes it on the firm's behalf. All three consume your firm's monthly token allowance and stop when that allowance runs out. Which features exist for your firm is also determined by your plan. If you do not want this automatic processing to run over your firm's matters, the firm owner can turn each one off from the firm settings, under 'My practice > Settings > AI without a click': the change takes effect immediately and is recorded. Turning the Q&A indexing off also erases the fragments already indexed. You may also object by writing to [email protected], and that route remains available: the objection is handled under the procedure and within the deadlines of Section 6.
  • (ix) SENSITIVE DATA: You must not deliberately send sensitive third-party data (health, sexual orientation, ethnic origin, biometrics) to AI features without prior authorization from the data subject.
  • (x) LIABILITY LIMIT: AI models may produce errors or 'hallucinations'. All output must be verified by a professional before use. Custodio Legal is not responsible for decisions made without human verification.

15. Independent Controllers

Not every third party the platform exchanges personal data with is a data processor. Google LLC (United States) does not process your data on our behalf or under our instructions: it is an independent controller that determines for itself the purposes and means of its own processing. That is why it is not on the list in Section 10, and why we hold no processing agreement with it for the two uses the product makes of it:

  • (i) Sign-in with your Google account, if you choose that option: Google hands us your email and your name, and processes the data of your Google account as a controller in its own right. The relationship is governed by Google's Controller-Controller Data Protection Terms (version 11), to which item 3.i of the Google APIs Terms of Service refers, and whose item 4.1 states that each party is "an independent controller" of the data and "will individually determine the purposes and means of its processing".
  • (ii) The Google Ads tag on the public site -not on the application-, which loads with ads consent denied by default and only enables it if you accept all cookies, as our Cookie Policy describes. It is governed by the Ads Controller-Controller Data Protection Terms (version 8.0), whose item 4.1 says the same.

What this means for you, said plainly:

  • (a) Sending data to Google is a transfer between controllers, not a transmission to a processor. It rests on your express and informed consent and on the controller-to-controller standard contractual clauses those terms incorporate; the basis your own law gives it —a list of adequate countries, an authorization of yours, whichever article permits it— is stated by your country's annex in its international transfer section. It does not rest on the data processing agreement that backs the sending to the processors in Section 10, which is a different thing.
  • (b) No Google instrument obliges it to notify us of a security breach occurring on its side: terms between independent controllers do not regulate it. We say so because it is different from what governs the processors in Section 10, and because Section 5 promises to notify you of the incidents we become aware of.
  • (c) For the data Google processes as a controller in its own right, you exercise your rights before Google, through its own channels and under its own privacy policy. The data we process -the email and the name we receive at sign-in- remain ours and you exercise your rights before us, under Section 7.
  • (d) A Google Ads processor agreement does exist, but it covers only a published list of processor services -Analytics, Tag Manager, Enhanced Conversions and the like- and the product uses none of them. If we ever enabled one, we would accept that agreement before the first data point and update this policy.

You cannot opt out of the Ads tag other than by rejecting non-necessary cookies, and you are not required to use Google sign-in: the platform accepts email and password, and that is the path on which Google plays no part.

Colombia Annex · Applicable Law and Supervisory Authority

The processing of personal data of subjects domiciled in Colombia is governed by Statutory Law 1581 of 2012 and Decree 1377 of 2013, today compiled into Single Decree 1074 of 2015 (Articles 2.2.2.25.1.1 and following).

The supervisory authority is the Superintendence of Industry and Commerce (SIC), which the law charges with overseeing the processing of personal data (Articles 19 and 21) and with which you may file complaints [✉ [email protected]]. The law asks you to exhaust the query or the claim before us first: that is the admissibility requirement of Article 16.

Colombia Annex · Deadlines for Answering Your Rights (ARCO)

A query is answered within a maximum term of ten (10) business days (Law 1581 of 2012, Article 14). A claim is answered within a maximum term of fifteen (15) business days counted from the day following its receipt (Article 15).

We count both terms from the business day following your request. For the claim that is what Article 15 says; for the query, whose Article 14 counts "from the date of its receipt", it is the reading we have always applied, and it is one day more for us, so we say it instead of leaving it implied.

The law allows both terms to be extended by telling you the reasons for the delay and the new date: up to five (5) further business days for the query and up to eight (8) for the claim (Articles 14 and 15). If we ever have to use that extension, we write it to you before the first term expires.

Colombia Annex · Security Incident Notification

If we detect a security incident that puts your personal data at risk, we inform the Superintendence of Industry and Commerce: that is the duty of Article 17 (n) of Law 1581 of 2012, which orders the authority to be informed of breaches of the security codes and of risks in the administration of the subjects' information.

That duty carries no term in the law. The only one the Superintendence has set are the fifteen (15) business days that External Circular 002 of 2015 gives for reporting an incident in the National Registry of Databases, counted from its detection and from its being made known to the area in charge of handling it, and which binds those who must register in it. We apply that same term by our own decision, whatever the channel through which it must be filed.

Colombia Annex · International Transfer

The United States and the Netherlands appear, by name, on the Superintendence of Industry and Commerce's list of countries with an adequate level of protection: item 3.2 of Chapter Three of Title V of the Single Circular, which External Circular 005 of 2017 added and External Circular 008 of 2017 replaced with the version in force. Israel is not named on that list: it enters through the clause that closes that same item, which recognizes as adequate "the countries that have been declared to have an adequate level of protection by the European Commission", among which Israel stands by Decision 2011/61/EU. Towards Israel the transfer further counts, as reinforcement, on the Standard Contractual Clauses that the provider's data processing agreement incorporates and on your express and informed consent.

In addition, since the processors the policy names act on our behalf and not as controllers, the sending towards them is a transmission of data backed by the data processing agreement each one incorporates into its terms, which is the contract of Article 25 of Decree 1377 of 2013 (Decree 1074 of 2015, Article 2.2.2.25.5.2); that is why Article 24 (2) of the same decree does not require that transmission to be reported to you or a separate consent to be asked of you. The sending of data to Google is different: it is not a transmission to a processor but a transfer between independent controllers, which Section 15 of the trunk covers. For Colombia that transfer rests on the United States being named on the adequacy list cited above, on the controller-to-controller standard contractual clauses that Google's terms incorporate, and on your express and informed consent.

Colombia Annex · Retention After Termination

When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Law 1581 of 2012 sets no retention periods for a controller such as us, only the purpose principle (Article 4 (b)), which Decree 1377 of 2013 turns into a temporal limit in its Article 11 (Decree 1074 of 2015, Article 2.2.2.25.2.8): data is kept only for the time that is reasonable and necessary for the purposes that justified collecting it, and once those purposes are fulfilled it is suppressed, unless a legal or contractual obligation requires keeping it.

After the suppression we keep the records the law requires us to keep:

  • The consent log, because Article 17 (b) obliges us to request and keep a copy of the authorization you granted, and Decree 1377 of 2013 requires us to be able to prove it in its Article 8 (Decree 1074 of 2015, Article 2.2.2.25.2.5).
  • The audit trail, because Article 17 (d) obliges us to keep the information under security conditions that prevent its adulteration, loss, consultation, unauthorized use or access, and that trail is the proof that those conditions existed.
  • Subject rights requests and their resolution, which are the proof of having met the terms of Articles 14 and 15, and on which the complaint you may later file with the Superintendence depends.
  • The billing trail, because the Commercial Code obliges the merchant to keep its books and papers for at least ten (10) years (Article 60), and the Tax Statute obliges it to keep the information and evidence of its returns (Article 632) until the income tax return supported by them becomes final, under the term set for it by Article 46 of Law 962 of 2005.

Costa Rica Annex · Applicable Law and Supervisory Authority

The processing of personal data of data subjects domiciled in Costa Rica is governed by Ley N° 8968, on the protection of the person with regard to the processing of their personal data, published in La Gaceta N° 170 of September 5, 2011, and by its Reglamento, Decreto Ejecutivo N° 37554-JP of October 30, 2012, amended by decretos ejecutivos N° 40008-JP of 2016 and N° 41582 of 2019. Both pieces are named together because the deadlines that reach you -the five business day term, the breach notice- live in the regulation, not in the law.

Your authorization. Ley N° 8968 makes consent the door to processing: its article 30, subparagraph a), makes it a serious offence to "recolectar, almacenar, transmitir o de cualquier otra forma emplear datos personales sin el consentimiento informado y expreso del titular de los datos". That is what the consent screen asks you for before you accept, and what is frozen, with its date, in the consent log. You can revoke it whenever you want, through the mechanism article 7 of the Reglamento requires us to give you: prompt, simple and free of charge.

The authority. It is the Agencia de Protección de Datos de los Habitantes (PRODHAB), a maximum deconcentration body attached to the Ministerio de Justicia y Paz which article 15 of Ley N° 8968 created. It is the authority you complain to if you are not satisfied with what we do, and you can also write to us at [email protected].

And how you complain, so that you do not have to look it up. Article 24 of Ley N° 8968 gives the complaint to anyone with a subjective right or a legitimate interest who considers that a database is acting against the rules or the principles of the law. Article 25 sets the procedure: PRODHAB gives us three business days to state whether the charges are true and to file evidence -and if we do not file that report, "se tendrán por ciertos los hechos acusados"-, it may require information from us, inspect our databases on site and order interim measures, and must issue the final decision no later than one month after the complaint; against it there is a request for reconsideration within the third day, resolved in eight days. If you are right, article 26 orders the immediate deletion, rectification, addition or clarification of the data, or bars its transfer or disclosure. Article 27 also lets it open a sanctioning procedure of its own motion. Articles 58 to 72 of the Reglamento develop that procedure with the same terms.

On the registration of databases, and why we did not do it. Article 21 of Ley N° 8968 orders the registration before PRODHAB of "toda base de datos, pública o privada, administrada con fines de distribución, difusión o comercialización". Custodio Legal does not distribute, disseminate or commercialise third party data: it processes it on behalf of a firm, which is the party that decides about it. Under that reading there is no database to register, and the annual two hundred dollar levy of article 33 does not run either, because that article imposes it on "las personas responsables de bases de datos que deban inscribirse ante la Prodhab, de conformidad con el artículo 21". This is our reading of the text, not a confirmation from PRODHAB nor the opinion of a Costa Rican lawyer. If the legal review of this annex concludes otherwise, we will register the database, pay the levy and say so here.

As of September 10, 2026 Ley N° 8968 is still in force with no amendment whatsoever: PRODHAB itself states so on its regulations page, updated on September 9, 2026. What we could not verify is whether a reform bill is before the Asamblea Legislativa -its site did not respond on the day this legislation was read- so we assert neither that there is one nor that there is not. If a reform changes what this annex promises, we will update it and tell you before the change reaches you.

Costa Rica Annex · Deadlines for Answering Your Rights (ARCO)

Ley N° 8968 sets a single deadline, for everything: its article 7 requires answering "de manera gratuita, y resolver en el sentido que corresponda en el plazo de cinco días hábiles". Article 18 of the Reglamento is the one that says from when it is counted: "cinco días hábiles, contados a partir del día siguiente en que la misma haya sido recibida". That is the one we apply, because it is the one that yields a concrete day.

  • Access: five (5) business days from the day after your request (Law, article 7.1; Reglamento, articles 18 and 21).
  • Rectification: five (5) business days, on the same terms (Law, article 7.2; Reglamento, articles 18, 23 and 24).
  • Erasure or deletion: five (5) business days (Law, article 7; Reglamento, articles 18, 25 and 26).
  • Revocation of consent: five (5) business days to execute it, and within that same term we notify anyone we had transferred your data to, who have another five to execute it on their side (Reglamento, article 8).
  • Confirmation that the processing ceased: three (3) business days, free of charge, if you ask us for it (Reglamento, article 9). It is the shortest term in the whole Costa Rican regime.

Objection and portability do not exist in Costa Rican law, and this annex does not promise them to you: neither Ley N° 8968 nor its Reglamento names them. What you can do, and what stands in for the first, is revoke your consent. And from 'My account > Your privacy' you can download a structured, machine-readable copy of your account data: we give you that copy by our own decision, not because a Costa Rican rule requires it.

Two counting rules the rule itself imposes, and we would rather you read them here than when they reach you. The first: if your request arrives incomplete or unclear, we may ask you once only, within the first five business days, for the missing details; you have five business days to answer, and if you answer a fresh five day term starts on the following day. If you do not answer, the request is treated as not filed (Reglamento, article 19). The second: between two access requests of yours there must be a minimum interval of six months, unless you set out to us, with reasons, why you believe your rights are being infringed (Reglamento, article 21).

One more limit, and it is the one that supports the retention section of this annex: article 26 of the Reglamento excludes from erasure the data "que deban ser mantenidos por disposición constitucional, legal o resolución de órgano judicial". Data a law requires us to keep is not deleted on request; what we do is tell you which law that is.

If the Costa Rican business day calendar for the year is not loaded in the platform, your request is filed all the same and we attend to it: what we do is mark the due date as estimated rather than certain, instead of giving you a date we cannot compute.

Costa Rica Annex · Security Incident Notification

Costa Rica does set a breach notice deadline, and it is not in the law but in article 38 of its Reglamento: the controller must inform the data subject "sobre cualquier irregularidad en el tratamiento o almacenamiento de sus datos, tales como pérdida, destrucción, extravío, entre otras, como consecuencia de una vulnerabilidad de la seguridad", and has five business days from the moment the vulnerability occurred to do so. Within that same term the exhaustive review opens, to measure the impact and decide the corrective measures.

Two things about that deadline, said plainly. The first: it runs from when the incident occurred, not from when we detected it, which is stricter than the "without undue delay from knowledge" the trunk's incident protocol is written to. In Costa Rica we apply the Costa Rican deadline. The second: the recipient is twofold -you and PRODHAB- and both are told the same thing, which is what article 39 of the Reglamento enumerates: the nature of the incident, the personal data compromised, the corrective actions taken immediately, and the means or the place where you can obtain further information.

Costa Rica Annex · International Transfer

Operating the Service means transmitting your data outside Costa Rican territory. Costa Rica solves that with a single door, and it is article 14 of Ley N° 8968: controllers of databases "solo podrán transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y válidamente tal transferencia", and provided the transfer does not infringe the principles and rights that same law recognises.

There are no other bases. Costa Rica publishes no list of countries with an adequate level of protection, and its law does not recognise standard contractual clauses as the basis of the transfer. What supports it is your express authorization, and that is why we ask you for it where it can genuinely be given: on the consent screen, naming the destination and the safeguard, before the data leaves.

The data of the firm's clients and opposing parties is a different matter, and it is worth being clear about whose duty it is. Over that data the controller is the firm, not Custodio Legal: it is the firm that has the relationship with the data subject and that obtains their express authorization to process and to transfer it, and that is what the firm declares when it accepts the third party data declaration, which cites Ley N° 8968 as its basis. We are its processor and act on its instructions.

To that are added the contractual guarantees each provider incorporates into its terms: confidentiality and security obligations and -for the text generation provider- the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 which that agreement incorporates for transfers outside the European Economic Area. They are not the basis of the Costa Rican transfer -that is your authorization, and it alone- they are the additional safeguard we do have and that you can verify.

The same holds for the data sent to Google, which is not a processor of ours but an independent controller, as Section 15 of the trunk explains: Ley N° 8968 does not distinguish the basis of the transfer by the role of whoever receives the data, so that sending rests on the same express authorization of article 14, and additionally on the controller-to-controller standard contractual clauses that Google's terms incorporate.

Why we take this so seriously: transferring data against the rules of chapter III of the law is a serious offence under article 30, subparagraph b), with a fine of five to twenty base salaries (article 28, subparagraph b). The consequence of getting this wrong is not an observation: it is a penalty.

Costa Rica Annex · Bar Association Check

When you open your firm —and afterwards, from Settings— you may enter your membership number of the Colegio de Abogados y Abogadas de Costa Rica. It is optional: if you do not enter it, we check nothing, and your firm works the same. If you do, we ask the public member search the bar publishes at abogados.or.cr, and what we do with the answer is show a badge on your firm's profile.

What leaves here for the bar is the number and nothing else: your name does not travel, nor your firm's, nor any of your clients'. What comes back is a page with the result, and from that page we keep exactly three things: whether the bar knows the number, the condition it records —in good standing or suspended— and the date we asked. Nothing more. The bar's search prints, next to each member, their full name, national id number, address, email and phone: none of that is stored, and the program that reads the answer discards it before it reaches the database. This is the information-quality principle of article 6 of Ley N° 8968: only the datum the purpose needs is kept, and the purpose here is showing a badge.

Asking once is the rule, and only when the number changes. If the bar does not answer, the badge says it could not be checked and that is where it stops: we do not insist.

You can withdraw the number whenever you want, by leaving the field blank in Settings. Doing so deletes the whole row —the number, the condition and the date— and the badge disappears.

The badge decides nothing. A number the bar does not know, one with a suspension recorded, and a bar that does not answer all give exactly the same access to the Service: what changes is what the profile says. We do not close the door on you because of what a third party's page says — or fails to say.

Costa Rica Annex · Retention After Termination

When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Ley N° 8968 sets no retention periods for a controller such as us. What its Reglamento sets, in article 11, is a ceiling: the retention of personal data that may affect its subject "no deberá exceder el plazo de diez años, desde la fecha de terminación del objeto de tratamiento del dato, salvo disposición normativa especial que establezca otro plazo". None of the windows in this annex exceeds it.

What outlives the suppression, and why:

  • The evidence of your authorization and of the processing -the consent log and the audit trail- because processing without informed and express consent is a serious offence (Ley N° 8968, article 30, subparagraph a) and proving that we had it requires keeping the record. Article 26, subparagraph b), of the Reglamento is what allows keeping it after suppressing the rest: data that must be kept by legal provision is not deleted.
  • The data subject requests and their resolution, which are the evidence of having met the five business days of article 7 of the Law and article 18 of the Reglamento.
  • The billing trail, for five years, and by two routes that reach the same number. The Código de Comercio requires the merchant to "conservar los libros de contabilidad desde que se inician hasta cinco años después del cierre del negocio y conservar igualmente la correspondencia, las facturas y los demás comprobantes, por un período no menor de cinco años, contado a partir de sus respectivas fechas, salvo que hubiera juicio pendiente en que esos documentos se hubieran ofrecido como prueba" (article 234, subparagraph d), and repeats the five years for a business being wound up in its article 270. The Código de Normas y Procedimientos Tributarios reaches the same term through the taxpayer's duty: "los contribuyentes o los responsables deberán conservar los duplicados de estos documentos por un plazo de cinco años" (article 109). That duty is your firm's, as a Costa Rican merchant and taxpayer; we keep the receipt so it can comply.

One clarification about the number, because it is easy to confuse: the Código de Normas y Procedimientos Tributarios sets the statute of limitations of the Tax Administration's action at four years (article 51). Four years is what it has to collect; five is what has to be kept. The window this annex promises is the retention one.

Dominican Republic Annex · Applicable Law and Supervisory Authority

The processing of personal data of subjects domiciled in the Dominican Republic is governed by Ley núm. 172-13, on the comprehensive protection of personal data held in files, public registries, databanks and other technical means of data processing, of December 13, 2013 (Gaceta Oficial núm. 10737 of December 15, 2013). Its rules are of public order and apply throughout the national territory (article 3), to personal data recorded in any databank capable of processing, in the public and in the private sphere (article 2).

Your authorization. Article 5, paragraph 4, requires that the processing and the assignment of your data have your free, express and conscious consent, which must be given in writing or by an equivalent medium and which -when given together with other declarations- must appear expressly and prominently. That consent follows the duty to inform of paragraph 3 of the same article: the purpose and the recipients, the existence of the file and the identity and address of whoever answers for it, and the possibility of exercising the rights of access, rectification and deletion. That is what the consent screen shows you before you accept, and what is frozen, with its date, in the consent log.

The authority. Ley núm. 172-13 did not create a general-purpose data protection authority. Its supervisory body, the Superintendencia de Bancos de la República Dominicana, supervises "los archivos, registros o bancos de datos, públicos o privados, destinados a proveer informes crediticios" (article 29), and the entities that must register with it are the Sociedades de Información Crediticia (article 43). Custodio Legal is not a credit information company and does not provide credit reports, so there is today no regulator in the country with which we register databases, request transfer authorization or answer for this processing. What the law does require of us, and we comply with, is having information policies that guarantee the security and control measures of article 42, and the duties of article 13: keeping information securely, updating, rectifying or deleting it in good time, handling your queries and complaints, and maintaining an internal manual of policies and procedures.

You may write to [email protected] to exercise your rights. If you are not satisfied, the law opens the judicial hábeas data action to you (articles 7, 17 and 21), which follows the amparo procedure and is heard by the judge of the defendant's domicile (article 20).

As of September 9, 2026 Ley núm. 172-13 is still the only Dominican personal data protection statute, and no later law amended or repealed it: we verified that against the complete repertoire of the Consultoría Jurídica del Poder Ejecutivo. If a reform ever creates a supervisory authority, we will update this annex and tell you before the change reaches you.

Dominican Republic Annex · Deadlines for Answering Your Rights (ARCO)

Ley núm. 172-13 does set deadlines, and they are the ones we apply:

  • Access: five (5) business days from your request. Article 10 imposes it on the user of the databank, and article 12, after setting that same term for the credit report, says expressly that "igual disposición aplica para las demás entidades que manejan bancos de datos, públicos o privados". We are one of them.
  • Rectification, updating and cancellation: ten (10) business days from our receiving your complaint or noticing the error, under article 8, and at no cost to you. If we had already communicated the datum to a third party, we notify it of the rectification or the deletion within the following five (5) business days.
  • Objection: the four rights are independent, and exercising one is not a precondition for exercising another (article 9).

If the deadline passes without our answering, article 8 entitles you to bring the hábeas data action with no further requirement.

Two limits the law itself sets, and that we would rather you read here than meet unannounced: while we verify a datum you challenged, when reporting on it we record that it is under review (articles 8 and 21); and deletion does not proceed where it could harm the rights or legitimate interests of third parties, or where a contractual or legal obligation to keep the data exists (articles 8 and 15).

Beyond those four rights, you may download from 'My account > Your privacy' a structured, machine-readable copy of your account data. Ley núm. 172-13 recognizes no right of portability: we give you that copy by our own decision.

Dominican Republic Annex · Security Incident Notification

Ley núm. 172-13 imposes the duty of security -adopting the technical, organizational and security measures that prevent alteration, loss, processing, consultation or unauthorized access: article 5, paragraph 5, and article 13, paragraph 2- but it sets no incident notification deadline and no authority to file one with for a controller such as us. By our own decision, and not because a Dominican rule imposes it, if we detect an incident that puts your personal data at risk we tell you without undue delay and, in any event, within the three (3) days following confirmation, with what we know and what we are doing.

Dominican Republic Annex · International Transfer

Operating the Service means transmitting your data outside Dominican territory, which is what article 6, paragraph 20, of Ley núm. 172-13 calls an international transfer of data. The Dominican Republic publishes no list of countries with an adequate level of protection, and the law requires no prior authorization from any authority: article 80 lists the cases in which the transfer proceeds, and ours relies on two of them.

The first is your own authorization: paragraph 1 admits the transfer where the natural person, "libre y conscientemente", decides to authorize it of their own will, and that is what you do by accepting this policy knowing the destination and the safeguard. The second is paragraph 6: the transfer necessary for the performance of the contract between the data subject and the controller, without which there is no Service to render.

To that are added the contractual guarantees each provider incorporates into its terms: confidentiality and security obligations and -for the text generation provider- the Standard Contractual Clauses of European Commission Implementing Decision (EU) 2021/914 that agreement incorporates for transfers outside the European Economic Area. They are not a Dominican requirement: they are the safeguard we do have, and that you can verify.

The same holds for the sending of data to Google, which is not a processor of ours but an independent controller, as Section 15 of the trunk explains: Ley núm. 172-13 does not make the basis of a transfer depend on the figure of whoever receives the data, so that sending rests on the same two items of Article 80, and further on the controller-to-controller standard contractual clauses that Google's terms incorporate.

Dominican Republic Annex · Retention After Termination

When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: Ley núm. 172-13 sets no retention periods for a controller such as us.

What outlives the suppression, and why:

  • The evidence of your authorization and of the processing -the consent log and the audit trail- because article 5, paragraph 4, requires consent to be given in writing or by an equivalent medium, and article 15 orders that what is cancelled be blocked and kept at the disposal of the branches of the State, for the liabilities arising from the processing, throughout their limitation period.
  • Subject rights requests and their resolution, which are the evidence of having met the deadlines of articles 8 and 12.
  • The billing trail, because the Tax Code (Ley núm. 11-92), in its article 50, subparagraph h) -as amended by article 105 of Ley núm. 155-17- requires keeping in orderly form, for a period of ten (10) years, the accounting books, the receipts or proofs of payment and any document, physical or electronic, relating to the taxpayer's operations and activities. That duty is your firm's as a Dominican taxpayer; we keep the proof so that it can meet it.

Over all of them runs the same limit of article 8: deletion does not proceed where a contractual or legal obligation to keep the data exists.

Ecuador Annex · Applicable Law and Supervisory Authority

The processing of personal data of subjects domiciled in Ecuador is governed by the Organic Law on Personal Data Protection (LOPDP) and its General Regulation (RGLOPDP), issued by Executive Decree 904.

The supervisory authority is the Personal Data Protection Superintendency (SPDP), which Article 76 of the LOPDP defines as the body that controls and oversees this matter, and with which you may file complaints.

The personal data protection delegate (Article 48 of the LOPDP) is designated: he is the natural person named in Section 1 of the trunk of the policy, reachable at [email protected]. His designation is registered with the Personal Data Protection Superintendency through the procedure the SPDP's Regulation on the personal data protection delegate sets out (Resolution SPDP-SPD-2025-0028-R, Article 5). That regulation requires a delegate from private-law legal persons that provide information technology services, including those devoted to developing or deploying artificial intelligence (Article 10, item 13); Custodio Legal is the trade name of a natural person, so that item does not impose the designation on him. We made it anyway, and that is why the delegate is named here with his name and his email address.

Ecuador Annex · Deadlines for Answering Your Rights

In Ecuador we answer within the fifteen (15) days following receipt of the request, which is the term the LOPDP gives each of the four rights: access (Article 13), rectification and updating (Article 14), erasure (Article 15) and objection (Article 16). The law calls them a plazo and does not qualify them as business days, so we count calendar days, which is the reading that favors you most.

Beyond those four, Article 17 of the LOPDP recognizes the right to portability: you may download from 'My account > Your privacy' a structured, machine-readable copy of your account data. That article sets no term of its own; we answer portability within the same fifteen days.

Ecuador Annex · Security Incident Notification

If we detect a security incident that puts your personal data at risk, we notify the Personal Data Protection Superintendency and the Telecommunications Regulation and Control Agency as soon as possible and, at the latest, within the término of five (5) days from when we become aware of it (Article 43 of the LOPDP). We notify you without delay when the incident carries a risk to your fundamental rights, within the término of three (3) days counted from when we learn of that risk (Article 46 of the LOPDP).

Ecuador Annex · International Transfer

The providers listed in Section 10 of the trunk act as processors, not as controllers. Article 23 of the Superintendency's General Rule on transfers (Resolution SPDP-SPD-2026-0004-R, of January 28, 2026) states that, under Ecuadorian law, a processing mandate is neither a transfer nor a communication of personal data; what backs those sendings, then, is the data processing agreement each processor incorporates into its terms, with confidentiality and security obligations.

The sending to Google is different, because Google is not a processor but an independent controller, as Section 15 of the trunk explains: that one is an international transfer. The Personal Data Protection Superintendency has not declared, as far as we have been able to verify by walking its list of resolutions on September 9, 2026, any country with an adequate level of protection; Articles 11 to 19 of that same general rule set the procedure for declaring one, and it has not been used yet. That transfer relies on your explicit and informed consent (Article 60, item 2, of the LOPDP), which you give by accepting this policy knowing the destination and the safeguard, and on the independent-controller terms Section 15 cites by version.

One precision about contractual clauses, so that you do not read more into them: the Standard Contractual Clauses of European Commission Implementing Decision (EU) 2021/914 that the text generation provider's agreement incorporates govern the transfers that provider makes outside the European Economic Area, and they are not the standard clauses Ecuador recognizes. Articles 20 and 22 of the Superintendency's general rule recognize as an adequate guarantee the model contractual clauses of the Ibero-American Data Protection Network, and we do not claim to have those signed.

Ecuador Annex · Artificial Intelligence and Automated Decisions

The artificial intelligence features that Section 14 of the trunk describes are an artificial intelligence system within the meaning of Resolution No. SPDP-SPD-2026-0009-R of the Personal Data Protection Superintendency, «General rule for guaranteeing the right to personal data protection in the use of artificial intelligence systems», signed in Quito on February 12, 2026. That rule applies regardless of where the system and the provider are located (Article 1), so it governs this processing even though the inference runs outside Ecuador.

Before it, Custodio Legal acts as a deployer —the one who, by using an artificial intelligence system, carries out the provision of a service (Article 2, item 2)— and as an implementer —the one who implements it in its internal processes (Article 2, item 4)—. It neither develops nor trains models, and so it is not a developer within the meaning of that rule.

None of those features takes decisions with legal effects on you, or that similarly affect you, without human intervention. Article 20 of the LOPDP grants you the right not to be subject to a decision based solely or partly on automated assessments that produces such effects, and Article 4 of the resolution requires that right to be guaranteed at all times: artificial intelligence results are supporting material that a professional verifies before using, and Section 14 of the trunk describes feature by feature what each one does, what data leaves and what runs on your click.

You may object to the artificial intelligence processing that runs without a click of yours —indexing for questions with citations, fact extraction and matter reassessment, which item (viii) of Section 14 lists— by writing to [email protected], and through whatever means the platform makes available to you for that. The features that produce a result to read run only when you execute them, so not using them amounts to not authorizing them. Objections are answered within the fifteen (15) days this annex declares above.

The inference runs on the infrastructure of the providers Section 10 of the trunk lists: text generation at Nebius B.V. (Netherlands) and the vector representations of semantic search at Voyage AI (United States). Both act as processors, and what backs those sendings is what the «International Transfer» section of this annex says above.

We keep the record of the processing activities carried out through artificial intelligence systems —with the automated decisions that may generate legal impacts or affect rights and freedoms— and the personal data protection impact assessment of these features, which Articles 5 and 7 of the resolution require. Both are at the disposal of the Personal Data Protection Superintendency.

Ecuador Annex · Retention After Termination

Data is kept for no longer than is necessary to fulfil the purpose of its processing (Article 10, letter i, of the LOPDP). When the relationship with a firm ends we warn its owner at sixty (60) days and suppress its data at ninety (90); the thirty days in between are the margin to come back. Those two windows are platform policy: the LOPDP sets the retention principle, not the periods.

After the suppression we keep three things, and we say why for each. The consent log and the audit trail, because Article 10, letter k, of the LOPDP requires us to demonstrate to you and to the Superintendency that the processing complied with the law, and that evidence is the only thing that demonstrates it. Subject rights requests and their resolution, for the same reason and with respect to the fifteen days above. And the billing trail, because of the provider's accounting and tax obligations, which are not Ecuadorian: Custodio Legal is the trade name of a natural person domiciled in Colombia, as Section 1 of the trunk declares, and it is the Colombian accounting and tax rules that set how long he must keep his own books and receipts.