Personal data processing policy
Version 1.3 — Effective date: September 8, 2026. Last updated: September 8, 2026. It replaces version 1.2 of September 4, 2026; the version history is at the end of this policy.
Our databases remain in force for as long as Custodio Legal provides the service and for as long as the legal and contractual obligations that justify keeping them subsist.
Custodio Legal is the platform your law firm uses to manage its judicial and extrajudicial matters. This policy explains, in plain language, what personal data we process, what we use it for, who we share it with, how long we keep it and how you can exercise your rights over it.
The Ley Estatutaria 1581 de 2012 and Decreto 1377 de 2013 (Colombia) apply, as do the Ley Orgánica de Protección de Datos Personales (LOPDP) and its Decreto Ejecutivo 904 (Ecuador) and Ley núm. 172-13 on the comprehensive protection of personal data (Dominican Republic). For Costa Rica the regime is Ley N° 8968 on the protection of the person with regard to the processing of their personal data and its Reglamento, Decreto Ejecutivo N° 37554-JP: the Service has been offered there since September 10, 2026. For Uruguay the regime is Ley N° 18.331 on the protection of personal data and the habeas data action with its amending statute Ley N° 19.670 and Decretos N° 414/009 and N° 64/020: the country is registered in the platform and the Service is not offered there yet, so what follows describes what will govern the day it is.
This policy reaches you whether you use the platform as a professional at a firm, or your personal data appears in a matter a firm manages through Custodio Legal — as a client, opposing party or interested party in a proceeding, for instance.
Who is responsible for your data
Custodio Legal is the trade name under which Nicolás Rodríguez Lasso, identified with NIT 1057602936, domiciled in Sogamoso, Boyacá, Colombia, provides the service and is the controller of your personal data when you act as a user of the platform.
- Address: Carrera 17 #2-81, Sogamoso, Boyacá, Colombia
- Email: support@custodio.legal
- Phone: +57 333 431 8597
- Area responsible for handling queries and claims: Personal Data Protection Area, at the email address given above.
- Personal data protection officer (Ecuador, Article 48 of the LOPDP): the natural person responsible named above, reachable at the same email address; the officer is designated.
When your data appears in a matter a firm manages, the controller is that firm, not us: we act on its behalf, under the service contract and its instructions, as a processor. That has a practical consequence worth knowing: if you write to us to exercise a right over data held in a matter, we cannot decide on it on our own. We forward your request to the responsible firm within the following two business days, tell you we did, and give you its contact details so you can approach it directly.
What data we collect
- Identification and contact data of the people who use the platform: name, email address, phone, address and document number.
- Matter data your firm manages: its description, its objective, follow-up notes, and the details of those who appear as a party to the matter (name, document number), as recorded in the case file or in the judicial proceeding.
- The text of the documents uploaded to a matter. We do not keep the original file you uploaded: it is processed automatically to extract its content and then deleted; what we store is the extracted text, so the matter can be searched and consulted.
- The content of your conversations with the artificial intelligence assistant, when your firm’s plan includes that feature.
- Access and activity records: date, IP address, browser agent and what was done, so that use of the platform can be audited and improper access detected.
Sensitive data and data of minors
A judicial case file may contain sensitive data: information about your health, your sex life, your ethnic origin, your religious or political convictions, or your trade union membership. It may also contain data of children and adolescents.
Custodio Legal neither asks you for that data nor collects it on its own: it arrives at the platform inside the case file the firm manages, and it is the firm — as controller — that must have obtained the authorization the law requires to process it.
Over that data the law gives you two protections we want you to know about:
- You are not obliged to authorize the processing of sensitive data. No one may condition a service on your doing so, and no question about such data requires an answer.
- Data of minors may only be processed respecting their best interests and their fundamental rights, and it is their legal representative who exercises their rights.
We process it with the same security measures described below, without using it for any purpose other than managing the matter it appears in.
What we use it for
- Managing your firm’s judicial and extrajudicial matters.
- Watching judicial proceedings and notifying you of news and filings.
- Generating summaries, analyses and drafts with artificial intelligence, and answering your questions about a matter’s documents, when your firm’s plan includes those features.
- Sending you notifications and alerts related to the service.
- Meeting our legal obligations of security, auditing and attention to your rights as a data subject.
On what basis
We process your data with your prior, express and informed authorization: before using the platform you are asked to accept this policy, and that acceptance is recorded with its date. When you act on behalf of a firm, we also process your data within the contractual relationship between the firm and us, and the legal obligations that relationship brings with it — information security and traceability, for instance.
How long we keep it
We keep your data for as long as a relationship exists with the firm that provides you the service. We do not delete data automatically with the passage of time — it is deleted or anonymized when appropriate, for example on approving a cancellation request of yours. When your firm’s account ends, we delete or anonymize the data the platform holds for that firm within the 90 days following termination, unless a legal retention obligation applies.
There is one deliberate exception: the records of your authorization, of auditing and of your own ARCO requests are never deleted, not even after the rest of your data is anonymized. They are the proof that we comply with this policy, and their value depends on their not being alterable or erasable.
Who we share it with
To provide the service, we share some of your data with providers who act on our behalf — never for their own purposes —, under the data processing agreement each one incorporates into its terms and that we accept when contracting it:
| Provider | Country | What it receives | What for |
|---|---|---|---|
| Railway | United States | All the data the platform stores: it hosts the servers, the database and their backups | Hosting the platform |
| Nebius B.V. (Nebius Token Factory service) | The Netherlands; it declares that it runs inference in the European Union, Israel or the United States depending on the model | Matter description, its filings and fragments of your documents | Generating summaries, analyses, drafts and answers, only if your plan includes AI features |
| Voyage AI | United States | Fragments of the text of your documents | Finding the relevant part of a document when you ask the assistant a question |
| Resend | United States | Your email address and the content of the notices | Sending you notifications and alerts |
| Polar.sh | United States | Contact email and firm name | Managing your firm’s plan and payment |
| Sentry | United States | Error details, the route where it occurred and your internal user identifier; before sending them we strip your email, your name and your IP address | Detecting and correcting platform failures |
| United States | Your email and your name, only if you choose to sign in with your Google account. On the public site, the Google Ads tag loads with ads consent denied until you accept all cookies | Signing in with Google; measuring the public site’s ads | |
| Cloudflare | United States | The IP address and the metadata of each connection, because all traffic between your browser and us goes through its network | Delivering and protecting the site and the application |
Text recognition of your documents happens in a service of our own, inside our own infrastructure — it does not go out to any external provider.
The alternate text generation providers the platform keeps configured — Anthropic (United States) and z.ai (Singapore) — receive none of your data today. Activating one would change the processor and the destination, and we would not do it without telling you and asking you for a new authorization.
These providers are located in the United States and the Netherlands, and the artificial intelligence provider may run inference in Israel.
- For Colombia, the Superintendence of Industry and Commerce names the United States and the Netherlands on its list of countries with an adequate level of protection: item 3.2, which Circular Externa 008 de 2017 replaced and which is the version in force. Israel is not named on it: it enters through the clause that closes that item, which refers to the countries the European Commission declares adequate (Decision 2011/61/EU). And, since those providers act as processors and not as controllers, the sending is a transmission of data backed by the data processing agreement each one incorporates into its terms, not an international transfer requiring your separate declaration of conformity.
- For Ecuador, a processing mandate is neither a transfer nor a communication of personal data: Article 23 of the Personal Data Protection Superintendency’s General Rule on transfers (Resolution SPDP-SPD-2026-0004-R) says so. What backs those sendings is each provider’s data processing agreement, with confidentiality and security obligations, and — for the artificial intelligence provider — the European Union’s standard contractual clauses that agreement incorporates. The sending to Google is an international transfer, because Google is an independent controller, and it relies on your explicit and informed consent (Article 60, item 2, of the LOPDP), which you give by accepting the policy knowing the destination.
The artificial intelligence features depend on your firm’s plan: if your firm does not have them active, none of your data reaches Nebius or Voyage AI.
How we protect your data
We use encryption to protect the most sensitive data we store — document number, address and phone —, we never store passwords in plain text, and we restrict access according to each person’s role within your firm. We record the relevant actions over your data — and those records are never deleted —, and we watch for improper access patterns, such as bursts of failed sign-in attempts or unusual downloads of information.
If we detect a security incident that puts your personal data at risk, we notify you without undue delay and inform the supervisory authority. In Colombia, informing the Superintendence of Industry and Commerce is the duty of Article 17 (n) of Law 1581 of 2012, which carries no term in the law: the 15 business days are the ones External Circular 002 of 2015 gives for reporting the incident in the National Registry of Databases -and which binds those who must register in it-, and we adopt them by our own decision. In Ecuador, the Personal Data Protection Superintendency within 5 days and you within the following 3 days (Articles 43 and 46 of the LOPDP). In the Dominican Republic, Ley núm. 172-13 imposes the duty of security (article 5, paragraph 5, and article 13, paragraph 2) but sets no incident notification deadline and no authority to file one with for a controller such as us: we notify you, without undue delay and in any event within the 3 days following confirmation of the incident, by our own commitment. In Costa Rica the deadline is written down, and it is stricter: 5 business days counted from when the vulnerability occurred -not from when we detected it- to you and to PRODHAB, with the nature of the incident, the data compromised, the immediate corrective actions and where you can obtain further information (articles 38 and 39 of the Reglamento to Ley N° 8968).
In Uruguay there is not one deadline but three, and only two are ours. We have 24 hours from confirming the incident to start the measures that minimise its impact (article 3 of Decreto N° 64/020); when the data belongs to a firm and we are its processor, we tell it immediately (article 4, paragraph 3, of the same decree), with the time the incident happened and not only the time we learned of it. The third clock belongs to the controller — the firm, or us when it is the data of its account —: 72 hours to communicate the breach to the URCDP, with the date, the nature, the data affected and the possible impacts, and a plain-language notice to the data subjects significantly affected (article 4 of Decreto N° 64/020 and article 38 of Ley N° 19.670). Once the breach is resolved, a detailed report goes to the URCDP, which coordinates the course of action with CERTuy.
Your rights as a data subject
You have the right to know, update, rectify and delete your personal data, and to withdraw at any time the authorization you gave us. These are your ARCO rights:
- Access — knowing what data we hold about you.
- Rectification — correcting incomplete, inaccurate or out-of-date data.
- Cancellation — asking us to stop processing your data and to delete it. On approval, we anonymize the information that identifies you; we keep only the evidence that the request was made and resolved, as the law requires.
- Opposition — objecting to our continuing to process your data for a specific purpose.
- Portability — receiving a copy of your own data.
About artificial intelligence and automated decisions
The platform uses artificial intelligence to summarize matters, analyze documents, draft documents and answer questions about a case file. None of those outputs decides anything about you. They are inputs the firm’s lawyer reads, evaluates and uses under their own professional judgement: there is no process on the platform that on its own produces a decision with legal effects on a person, or that affects them similarly.
If we were to incorporate processing of that kind in the future, we would tell you beforehand and you could object, request human intervention and ask for an explanation of the logic applied.
You can also withdraw your authorization at any time with a dedicated button on that same screen. On confirming it, we close your session immediately; the next time you sign in we ask you to authorize again before continuing, without your losing any of your firm’s data.
Who can exercise them
Besides you as the data subject, these rights may be exercised by your successors in title — on proving that status —, your legal representative or attorney-in-fact, and the persons the law empowers to act on your behalf. In all those cases we ask for the document proving the representation, because handing your data to someone who is not entitled to it would itself be a violation of your rights.
How to exercise them, step by step
- If you already use the platform, go to your profile, Privacy tab. There you can download your data, withdraw your authorization with a button, or choose the type of ARCO request with a brief justification. Every request is recorded with the date and the IP address you made it from.
- If you don’t have an account, or your request concerns data appearing in a matter managed by a firm that is a client of ours, file it at custodio.legal/derechos: you state your name, your document number, which right you are exercising, what you are asking for and — if you know it — the firm. We send a link to the address you gave to confirm it is yours; until you open it we hand your request to nobody. You can also write to us at support@custodio.legal with the same details.
- We identify the responsible firm and hand them your request. An administrator of that firm — or, when we are the controller, our team — reviews and resolves it within the legal deadline, and their answer reaches the address you gave.
From your profile you can also download a copy of your own account data at any time: your personal information, the history of your authorizations and the record of your own actions on the platform. The copy may take a few moments to become ready; once ready, its link can be used once and expires after 24 hours. The temporary file remains encrypted while it awaits download. It does not today include the matters or documents your firm manages about you; to access that specific information, make an access request through the same channels, and we will deliver it within the deadline given below.
How long we take to reply
Colombian law distinguishes two procedures, with different deadlines:
- Query — when you only want to know what data we hold about you. We answer it within the 10 business days following its receipt. If that is not enough for us, we explain why and give you the date on which we will answer, which will not exceed 5 business days more.
- Claim — when you ask us to correct, update or delete, or you object to a processing operation. We resolve it within the 15 business days following its receipt, extendable by 8 business days more, telling you the reason and the new date.
While we handle a claim, the corresponding record is flagged as “claim in process” within the following two business days, so that no one treats it as if it were unchallenged.
If your claim is incomplete, we tell you within the following 5 business days so you can complete it. If two months pass without your replying, we understand that you withdrew it, and you may file it again whenever you like.
In Ecuador we answer all four rights within the 15 days following receipt of the request.
In Costa Rica there is a single deadline for everything: 5 business days counted from the day after your request, for access, rectification and erasure (article 7 of Ley N° 8968 and article 18 of its Reglamento, Decreto Ejecutivo N° 37554-JP, which is the one that pins down when they start). If your request is missing information, we may ask you for it once only within those five days; you have five business days to answer, and if you do, a fresh five-day term starts (article 19 of the Reglamento). If you do not answer, the request is treated as never filed and you may make it again whenever you like. If you ask us to confirm that processing ceased after a revocation, the deadline is shorter: 3 business days (article 9 of the Reglamento). And access carries an interval: you may consult us again after six months, unless you explain to us why you believe your rights are being infringed (article 21 of the Reglamento).
The rights of objection and portability do not exist in Costa Rican law or in its Reglamento, so we promise you no deadline for them: if you ask us for either, your request is filed all the same and we answer it, but without a date the rule does not set. The closest thing to objection in Costa Rica is revoking your consent, which you may do at any time.
In Uruguay the deadline is 5 business days and it is the same for everything: access (article 14, paragraph 3, of Ley N° 18.331) and rectification, updating, inclusion and erasure (article 15, paragraph 2). They are counted from the same day as your request and not from the next one, because the articles say «from having been requested» and «from receipt of the request», without the word «following» that other regulations do have. They are free of charge. If we had already communicated or transferred the datum, we tell whoever received it of the rectification, inclusion or erasure within the fifth business day (article 15, paragraph 6). Free access is exercised at six-month intervals, unless a legitimate interest arises anew (article 14). Objection and portability do not exist in the Uruguayan regime — they appear neither in the statute nor in Decreto N° 414/009 — so we promise you no deadline for them: your request is filed all the same and we answer it.
In the Dominican Republic the deadlines are set by Ley núm. 172-13 itself: 5 business days for access (articles 10 and 12) and 10 business days for rectification, updating and cancellation (article 8), at no cost to you. If we had already communicated the datum to a third party, we tell it of the rectification or the deletion within the following 5 business days. If the deadline passes without our answering, that same article 8 entitles you to bring the hábeas data action with no further requirement.
Who to complain to
If you consider that we did not attend to your request properly or within the deadline, you may lodge a complaint with your country’s data protection authority.
In Colombia, the law requires that you first have filed your query or claim with us and that the procedure has been exhausted: the Superintendence only admits the complaint after that. It is not an obstacle we put in place, it is a requirement of article 16 of Ley 1581, and that is why it is worth keeping the record of your request and of our reply.
Colombia — Superintendencia de Industria y Comercio, Delegatura para la Protección de Datos Personales · habeasdata@sic.gov.co · www.sic.gov.co
Ecuador — Superintendencia de Protección de Datos Personales · https://spdp.gob.ec/
Costa Rica — Agencia de Protección de Datos de los Habitantes (PRODHAB) · https://www.prodhab.go.cr/
Uruguay — Unidad Reguladora y de Control de Datos Personales (URCDP), a decentralised body of AGESIC · https://www.gub.uy/unidad-reguladora-control-datos-personales/ · complaining to it does not take away the habeas data action before the Uruguayan courts, nor the other way round.
Dominican Republic — there is no authority to complain to, and saying so is the honest answer. Ley núm. 172-13 created no general-purpose data protection authority: its supervisory body, the Superintendencia de Bancos, supervises only databanks meant to provide credit reports (article 29), and Custodio Legal is not one. What the law does give you is the judicial hábeas data action (articles 7, 17 and 21), which follows the amparo procedure before the judge of the defendant’s domicile (article 20). A bill amending the law is before the Senate; if it creates an authority, we will update this policy.
Changes to this policy
We may update this policy to reflect changes in the service or in the applicable regulations. If the change is material, we will notify you by email or with a prominent notice on the platform before it takes effect.
Version history
- Version 1.5 — September 11, 2026. Adds Uruguay, registered and not yet offered: Ley N° 18.331, its amending statute Ley N° 19.670 and Decretos N° 414/009 and N° 64/020 as the applicable rule; the single ARCO deadline of 5 business days counted from the same day, with propagation on the fifth business day and with no objection or portability; the three breach clocks — 24 hours to mitigate, immediately to the controller, 72 hours to the URCDP —; and the URCDP as the authority to complain to.
- Version 1.4 — September 10, 2026. Adds Costa Rica, registered and not yet offered: Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP, as the applicable rule; the single ARCO deadline of 5 business days from the day after, and the 3 to confirm the cessation; the breach notice of 5 business days from when it occurred, to you and to PRODHAB; and PRODHAB as the authority to complain to.
- Version 1.3 — September 8, 2026. Adds the Dominican Republic: Ley núm. 172-13 as the applicable rule, its ARCO deadlines of 5 and 10 business days, the absence of a legal incident notification deadline and the absence of a general-purpose supervisory authority, with the hábeas data action as the route for complaints.
- Version 1.2 — September 4, 2026. Opens the custodio.legal/derechos channel for titulares without an account, with email confirmation before the request is handed to anybody, and describes how we identify the responsible firm and how their answer reaches you.
- Version 1.1 — September 4, 2026. Names each provider with its country and what it receives, corrects the incident notice deadlines and the safeguards for each destination, declares the deletion period after the firm’s account ends and identifies the data protection officer for Ecuador.
- Version 1.0 — August 12, 2026. First published version.
Language of this policy
This policy is drafted in Spanish. We also publish an English translation so you can read it in that language; in case of any discrepancy between the two versions, the Spanish version prevails, as it is the one Ley 1581 de 2012 and the LOPDP operate on.