Privacy policy
This policy describes how Pablo Galmés, doing business under the trade name «traza» (hereinafter, «traza»), processes the personal data of those who use the Discovery Agent and the other services available at trazaai.app. It was drafted taking as its framework the European Union's General Data Protection Regulation (GDPR), whose standard also covers the requirements of Argentina's Personal Data Protection Law 25.326, Brazil's LGPD and equivalent regulations. For any questions about this policy or about your data: privacy@trazaai.app.
01Who is responsible
Pablo Galmés, domiciled in the Autonomous City of Buenos Aires, Argentina, is the controller of the data described in this policy.
02What the Discovery Agent is
The Discovery Agent is a free conversational tool, intended for companies, that helps map an organization's financial processes and identify where manual work concentrates. The conversation is held with an artificial intelligence system. At the end, the tool produces a map of the operation covered, which is delivered to the user on screen, by email or both.
03What data we process
Identification data: name, email address, company, role, country. They are requested within the conversation itself. Conversation data: everything the person writes during the assessment, including the description of processes, systems, teams and operational difficulties of their organization, as well as the documents they choose to upload voluntarily. If you send voice notes in the conversation, they are automatically transcribed to text: the audio file is deleted as soon as it is transcribed and the transcription remains as part of the conversation, with the same treatment and retention periods as the rest of what was discussed. Audio files uploaded as material are transcribed and deleted in the same way; of them, only a reading of the process is kept, with no personal data. Data generated by the service: the map produced as output, the session state and the personal access link (magic link). Technical data: minimal operational logs necessary for security and operation; our logs avoid storing identifiable personal data. We do not request or need sensitive data in the legal sense of the term (health, beliefs, ethnic origin or others of that nature). We ask you not to include it in the conversation.
04What we use the data for and on what legal basis
a. Providing the service. We use the identification and conversation data to produce the map, allow you to pause and resume the session, and deliver the output to you. Legal basis: the performance of the service you request, with the consent you give at the start of the conversation.
b. Contacting you with related follow-up. We may contact you by email with information about traza's own services directly related to what your assessment revealed. Legal basis: traza's legitimate interest in the context of a business-to-business relationship. This contact is limited: it does not include general newsletters or unrelated promotional campaigns. You may object at any time, free of charge, through the unsubscribe link in each email or by writing to privacy@trazaai.app.
c. Improving the system with aggregated, anonymous patterns. We may extract aggregated statistical patterns from the assessments, in a way that does not allow any person or company to be identified. Our operating principle is «patterns yes, verbatim quotes no»: we do not keep identifiable fragments of conversations. Legal basis: consent, with the possibility of opting out. You may opt out by saying so in the conversation («do not use my information for improvements») or by writing to privacy@trazaai.app.
05Confidentiality
The information from your individual assessment is not shared with third parties under any circumstances. It is not used to contact other companies, not even in the same sector. No aspect of your case is published without your subsequent, explicit, written consent. Internal access is limited to the people at traza with an operational role that requires it.
06How long we keep the data
| Type of data | Period |
|---|---|
| User identification | 18 months from the last significant interaction |
| Full conversation | 18 months from the last significant interaction |
| Assessment output | 18 months from its generation |
| Personal access link (magic link) | 6 months from its generation |
| Abandoned, uncompleted assessments | 3 months without activity |
| Operational technical logs | 6 months |
| Aggregated anonymous patterns | No time limit (they do not constitute personal data) |
Each significant interaction (resuming the conversation, opening the output, downloading it) renews the period. Upon expiry, the data is permanently deleted through an automatic process.
07Your rights
You may, at any time and free of charge: access your data, rectify it, request its deletion, object to processing based on legitimate interest, withdraw the consents given and request the portability of your data. Immediate deletion from the conversation: you may request the deletion of all your data by writing «delete my data» in the chat itself; the system will ask for confirmation before executing; the deletion is immediate, permanent and includes your identification, the conversation, the generated outputs and the invalidation of the access link. By email: if you no longer have access to the chat, write to privacy@trazaai.app; we execute deletion requests received through this channel within 72 hours. Aggregated anonymous patterns are not deleted by default because they do not allow you to be identified; if you expressly request it, we delete them anyway. If you consider that the processing of your data does not comply with the regulations, you may file a complaint with Argentina's Agency for Access to Public Information (argentina.gob.ar/aaip) or with the supervisory authority of your jurisdiction.
09Security
We apply appropriate technical and organizational measures, described here in the detail a security team needs in order to assess them.
Encryption. All connections travel encrypted over TLS, with HTTPS enforced throughout the service. Data at rest is encrypted using AES-256, covering database files, their indexes, write ahead logs and backups. Encryption at rest is always on and cannot be disabled.
Data residency. Information is hosted in the European Union, in the Frankfurt region.
Data minimization. We store the minimum the service needs in order to work. The session identifier is kept in hashed form only. The network address is kept salted and hashed, never in clear text. It is deleted once the retention period described in section 6 is reached.
Access to data. The browser never accesses the database directly: every operation goes through governed server side functions, which enforce the controls and record what happens. Internal access requires reinforced authentication. Each assessment session is isolated from every other.
Audit log. Operations are recorded in an append only log: what has been recorded is neither rewritten nor deleted.
Retention and deletion. The retention periods described in section 6 are enforced automatically, by a daily process running inside the database itself: eighteen months for completed assessments and a rolling three month window for abandoned ones. Deletion on request is available at any time, from the conversation itself with a two step confirmation, or by writing to privacy@trazaai.app. It is a permanent deletion: there is no recycle bin and no subsequent recovery.
Usage limits. The service applies declared caps per network address and per day, per session caps and a global consumption ceiling, in order to contain abusive use.
Language models. Conversations are not used to train any language model: the provider's commercial terms establish that content submitted through its programming interface may not be used for that purpose. From each assessment we do retain aggregated structural patterns, without identifying data and without the content of the conversation, as described in section 4 and disclosed at the start. You may request to be excluded from that retention by writing to privacy@trazaai.app.
What we do not have. We prefer to state this rather than leave it open to interpretation: we hold no SOC 2 or ISO 27001 certification, we have not undergone third party penetration testing, nor do we apply field level encryption. Encryption at rest protects against the physical loss of a device or a backup copy, not against the misuse of a valid credential.
The personal access link. The personal link (magic link) is a private link: anyone who has it can see the output of your assessment. We recommend not forwarding it. The link expires automatically according to the periods in section 6.
10Minors
The service is intended exclusively for persons over 18 years of age acting on behalf of a company. By using it, you declare that you meet that condition. We do not knowingly process data of minors; if we detect data of a minor, we delete it.
11Website browsing data
In addition to the Discovery Agent, the trazaai.app site processes technical data of its visitors:
Usage metrics. We use Google Analytics to understand, in aggregate, how the site is used (pages visited, visit duration, traffic source). These metrics are not cross-referenced with the identity of any user of the Discovery Agent. Legal basis: our legitimate interest in understanding and improving the site.
Bot protection. We use Cloudflare Turnstile to verify that whoever starts a conversation is a person and not an automated program. Turnstile processes technical signals from the browser for that sole purpose. Legal basis: our legitimate interest in the security of the service.
Hosting. The site is served from Netlify, whose operation records technical connection data (such as the IP address) in short-lived server logs. Legal basis: our legitimate interest in operating the site.
12Early access list
If you sign up for the early access list, we keep your email address for a single purpose: notifying you of the launch and of traza's news. Legal basis: your consent. You may unsubscribe at any time through the link included in each email or by writing to privacy@trazaai.app. Upon unsubscribing, your address is permanently removed from the list.
13Changes to this policy
We may update this policy. The current version will always be published at trazaai.app/privacidad with its last update date. If a change substantially affects the processing of your data, we will inform you through a reasonable means. Each consent given is recorded together with the version of the text in force at that time. This policy is drafted in Spanish. Versions in other languages are provided for convenience only; in the event of any difference in interpretation, the Spanish version prevails.
Contact
For any matter related to this policy or to your personal data: privacy@trazaai.app. For other inquiries: hello@trazaai.app.
Book a conversationYou are in Privacy Policy · Keep exploring
⌂ Volver al inicio