Platform privacy policy
This policy describes how Pablo Galmés, trading under the commercial name «traza» (hereinafter, «traza»), processes personal data related to the use of the traza console, available at consola.trazaai.app. It was drafted using the General Data Protection Regulation of the European Union (GDPR) as its framework, whose standard also covers the requirements of Argentina's Personal Data Protection Act 25.326, Brazil's LGPD and equivalent regulations.
This policy is separate from the privacy policy of trazaai.app, which covers the institutional website and the Discovery Agent. If you arrived here as a visitor to the website or as a user of the Discovery Agent, that is the policy that applies to you.
For any question about this policy or about your data: privacy@trazaai.app.
01Who is responsible, and in what capacity
Pablo Galmés, domiciled in the Autonomous City of Buenos Aires, Argentina, operates the console.
On this platform traza holds two distinct roles. They are worth distinguishing because retention periods, legal bases and the allocation of each right depend on them:
Controller with respect to the data of the people who use the console: who accesses it, with which role and what actions they perform. traza determines the purposes and means for that data.
Processor with respect to the data the console processes on behalf of each client: the documents the client sends and the information extracted from them. The controller of that data is the client. traza processes it following the client's instructions and the contract between them.
02What the console is and who can access it
The console is the working platform where traza operates each client's automated processes. It is not an open sign-up service: access is granted exclusively by invitation from the administration. Public registration is disabled. An email address without an invitation cannot create an account. Neither can an uninvited Google sign-in.
The invitation creates the account with a random password that nobody knows and nobody can recover. The invited person activates it by their own means. No password is ever sent by email.
03Who this policy covers
Client users. People who access the console on behalf of a client company, with the roles provided by the platform.
The traza team. People at traza with an operational role on the platform.
Third parties named in documents and in received emails. When a client sends receipts to its intake address, the email usually comes from a person working at one of that client's suppliers. The documents, in turn, contain third party data. Those people did not choose any relationship with traza: their data arrives as part of the client's operation and is processed on the client's behalf, with the safeguards described in this policy.
04What data we process about users
Membership. The email address, which is the account identifier, the assigned role, the client the person belongs to and the date they were added. The console does not store users' name, job title or phone number in its membership records.
Account. In addition to the email address, the account creation date and the date of last sign-in.
Google sign-in. Anyone choosing to sign in with Google links their already invited account through the verified email address returned by that provider. On that path the account also retains the person's name as it appears in Google, together with the person's identifier at that provider, the issuer, the sign-in method identifier and the verification status of the email address and the phone number. No profile picture or phone number is retained.
Activity. Every action performed on data leaves an entry in an audit log, recording who performed it, what they did, when, and the detail of the change. That log is insert only: it cannot be modified or deleted, by design and through a technical constraint in the database.
IP addresses. The console does not record them. The infrastructure providers that support it keep their own technical connection logs, over which traza has neither control nor visibility.
05What data we process on behalf of each client
The documents the client sends, along with the information extracted from them: issuer, tax identifier, amounts, taxes and dates. Original files are kept in a private repository, with one folder per client and read access restricted to those who belong to that client.
The arrival of every email received at the intake address is also recorded, with its sender, subject and file name, even when the document cannot be processed. That record exists so that no submission is lost silently. It is a technical custody record and is not part of the client's business information.
06What we use the data for, and on what legal basis
a. Providing access to the platform and operating it. Membership and account data are used to identify whoever signs in, apply the permissions that correspond to them and maintain the session. Legal basis: performance of the contract between traza and the client, under which the person is granted access.
b. Recording what happens. The audit log exists so that it is possible to answer, at any later point, what was done with each document and who did it. Legal basis: the legitimate interest of traza and its clients in traceability, security and evidence of proper custody of information, together with compliance with the obligations arising from the contract.
c. Processing the client's documents. The data described in section 5 is processed following the instructions of the client, who is its controller. Legal basis: the contractual relationship between traza and the client.
The console performs no usage measurement or behavioural analytics whatsoever. There are no statistics, advertising or tracking tools of any kind.
07How long we keep the data
During the relationship with the client, with no term of our own. Original documents, extracted data and the intake record are kept for as long as the relationship lasts. traza does not set a term of its own over that information because it is not ours: it is processed on behalf of the client. The obligation to keep receipts for the applicable legal periods rests with the client. Setting our own expiry would amount to deleting information the client may need.
After termination, ninety days. Once the sequence described in section 8 is complete, the client's operational data is purged ninety days after archiving. The period is deliberately short: by then the client has already received the complete portability package, so longer retention would not protect the client and would only keep someone else's data stored.
Exception: the audit log is kept permanently. Including after the purge. This is a deliberate decision, guaranteed by a technical constraint in the database: if someone asks in the future what was done with a given document, the answer must exist. For that reason this policy does not promise complete erasure: the trace of actions remains, without the content of the documents.
| Type of data | Term |
|---|---|
| Client's original documents | For the duration of the relationship, then ninety days from archiving |
| Data extracted from documents | For the duration of the relationship, then ninety days from archiving |
| Email intake record | For the duration of the relationship, then ninety days from archiving |
| Membership and account | For as long as the person retains access, then as described in section 9 |
| Audit log | Kept permanently |
08What happens when a client relationship ends
A client is archived, not deleted. The sequence is as follows:
- Operations are frozen: the intake address stops receiving documents.
- The portability package is delivered through a signed link, containing the documents and the extraction of each one, the original files with their index, the client's master records, the configuration of its processes and a copy of its audit log, all in open formats.
- Access is revoked for all of that client's users.
- The client is archived: no longer visible, receiving and processing nothing, with its data frozen.
- After ninety days the operational data is purged.
Up to step 4 the sequence is reversible: a client resuming the relationship within that window recovers its information in full. Step 5 is the only action with no way back. That is why it is deferred and explicit.
The email intake record described in section 5 follows the fate of the operational data and is purged with it. It is not part of the portability package, because it is a technical custody record rather than the client's business information.
09User accounts
When a person no longer needs access, the console allows it to be revoked: from that moment they cannot sign in or see any information. Definitive deletion of the account is carried out on request, by writing to privacy@trazaai.app. This policy states the platform's actual situation: today revocation is performed from the console and definitive deletion is handled through that channel.
10Your rights
Users may, at any time and free of charge, access their data, rectify it, request its deletion, object to processing based on legitimate interest and request the portability of their data, by writing to privacy@trazaai.app.
With respect to data that traza processes on behalf of a client, including data of third parties named in documents or in received emails, the controller is the client. Such requests must be addressed to the client. traza provides the reasonable assistance the client needs in order to handle them. If a person writes to us directly about that data, we will indicate who the controller is, unless doing so proves impossible or would involve disproportionate effort.
If you consider that the processing of your data does not comply with applicable regulations, you may lodge a complaint with the Agency for Access to Public Information of Argentina (argentina.gob.ar/aaip) or with the supervisory authority of your jurisdiction.
12Security
We apply appropriate technical and organisational measures: encryption in transit and at rest; access exclusively by invitation, with public registration disabled; random initial passwords that nobody knows; two factor authentication available to anyone who wishes to enable it; isolation of each client's data, so that people from one client cannot access another client's information; database access solely through controlled functions that record every operation; signed download links with short validity, with an entry recorded for each opening; and an unalterable audit log.
13Minors
The platform is intended exclusively for people over 18 years of age acting on behalf of a company. We do not knowingly process data of minors.
14Changes to this policy
We may update this policy. The version in force will always be published with its date of last update. If a change substantially affects the processing of data, we will communicate it by a reasonable means. This policy is drafted in Spanish. Versions in other languages are provided for convenience only: in the event of any difference in interpretation, the Spanish version prevails.
Contact
For any matter related to this policy or to your personal data: privacy@trazaai.app. For other inquiries: hello@trazaai.app.
Book a conversationYou are in Platform Privacy Policy · Keep exploring
⌂ Volver al inicio