1. Who we are
Croma operates a platform that returns official public records as structured data. For questions about this policy or the handling of your personal data, contact us at tomas@usecroma.com.
2. Information we collect
We collect the following categories of information:
- Account data: name, email, organization, and credentials you provide when you create a workspace.
- Usage data: API requests, endpoints called, timestamps, and technical logs used to operate and secure the Services.
- Billing data: plan, usage volume, and payment details processed by our payment providers.
- Public-record data: information from official public sources that you query through the Services.
3. How we use information
We use personal data to:
- Provide, maintain, and secure the Services.
- Authenticate users and manage workspaces and API keys.
- Process billing and prevent fraud or abuse.
- Respond to support requests and communicate service updates.
- Comply with legal obligations and enforce our Terms.
4. Data from official public records
The Services return information drawn from official public sources. When you query these records, you act as the data controller for that processing and are responsible for having a lawful basis and a legitimate purpose. Croma processes this data as a data processor, following your instructions and applicable law. We do not use records returned to you to build independent profiles of the individuals they concern.
5. Legal basis
We process account, usage, and billing data on the basis of performing our contract with you, our legitimate interest in operating and securing the Services, and, where required, your consent. For public-record queries, the lawful basis rests with the customer initiating the query.
7. International transfers
Some providers may process data outside the country the records come from, including outside Colombia, Peru, and Mexico. Where they do, we rely on contractual guarantees that impose at least the same protection the originating country requires, consistent with Ley 1581 de 2012, Ley N° 29733 and its Reglamento, and the Mexican federal law.
8. Data retention
We keep account and usage data for as long as your workspace is active and as needed to comply with legal, accounting, and security obligations. You may request deletion as described below.
9. Security
We apply technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and audit logging. No system is perfectly secure, but we work continuously to protect your information.
10. Your rights
You have the right to know, access, update, and rectify your personal data, to request proof of the authorization granted, to be informed about the use of your data, to revoke consent, to oppose processing, and to request deletion where processing does not comply with the law. In Peru you may also request portability, and in Mexico these are known as the ARCO rights. To exercise them, contact tomas@usecroma.com, which is also our contact point for data-protection matters in Peru.
You may also file a complaint with the supervisory authority of your country: the Superintendencia de Industria y Comercio (SIC) in Colombia, the Autoridad Nacional de Protección de Datos Personales in Peru, or the Secretaría Anticorrupción y Buen Gobierno in Mexico. Where a record you dispute is held by an official source, the correction has to be made by that source; we will correct our own copy and point you to it.
12. Children
The Services are intended for businesses and professionals and are not directed to children. We do not knowingly collect personal data from minors.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you.
14. Contact
For any question about this Privacy Policy or your personal data, write to us at tomas@usecroma.com.