---
title: "Privacy Policy · Croma"
description: "How Croma collects, uses, stores and protects personal data across its API, MCP server and dashboard: what is collected, why, retention and your rights."
canonical: https://usecroma.com/en/privacy
lang: en-US
last-updated: 2026-08-17
---
# Privacy Policy

Last updated: August 17, 2026

This Privacy Policy explains how Croma processes personal data when you use our website, API, MCP server, and dashboard (the “Services”). Croma acts as the data controller for account and usage data, and processes information from official public records on behalf of its customers. We protect personal data in accordance with the law of each country whose records we cover: Colombia's Ley 1581 de 2012 and Decreto 1377 de 2013, Peru's Ley N° 29733 and its Reglamento (Decreto Supremo N° 016-2024-JUS), and Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares.

## 1. Who we are

Croma operates a platform that returns official public records as structured data. For questions about this policy or the handling of your personal data, contact us at tomas@usecroma.com.

## 2. Information we collect

We collect the following categories of information:

- Account data: name, email, organization, and credentials you provide when you create a workspace.
- Usage data: API requests, endpoints called, timestamps, and technical logs used to operate and secure the Services.
- Billing data: plan, usage volume, and payment details processed by our payment providers.
- Public-record data: information from official public sources that you query through the Services.

## 3. How we use information

We use personal data to:

- Provide, maintain, and secure the Services.
- Authenticate users and manage workspaces and API keys.
- Process billing and prevent fraud or abuse.
- Respond to support requests and communicate service updates.
- Comply with legal obligations and enforce our Terms.

## 4. Data from official public records

The Services return information drawn from official public sources. When you query these records, you act as the data controller for that processing and are responsible for having a lawful basis and a legitimate purpose. Croma processes this data as a data processor, following your instructions and applicable law. We do not use records returned to you to build independent profiles of the individuals they concern.

## 5. Legal basis

We process account, usage, and billing data on the basis of performing our contract with you, our legitimate interest in operating and securing the Services, and, where required, your consent. For public-record queries, the lawful basis rests with the customer initiating the query.

## 6. How we share information

We do not sell personal data. We share information only with service providers who help us operate the Services (such as hosting, analytics, and payment processors), bound by confidentiality and data-protection obligations, and where required by law or valid legal process.

## 7. International transfers

Some providers may process data outside the country the records come from, including outside Colombia, Peru, and Mexico. Where they do, we rely on contractual guarantees that impose at least the same protection the originating country requires, consistent with Ley 1581 de 2012, Ley N° 29733 and its Reglamento, and the Mexican federal law.

## 8. Data retention

We keep account and usage data for as long as your workspace is active and as needed to comply with legal, accounting, and security obligations. You may request deletion as described below.

## 9. Security

We apply technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and audit logging. No system is perfectly secure, but we work continuously to protect your information.

## 10. Your rights

You have the right to know, access, update, and rectify your personal data, to request proof of the authorization granted, to be informed about the use of your data, to revoke consent, to oppose processing, and to request deletion where processing does not comply with the law. In Peru you may also request portability, and in Mexico these are known as the ARCO rights. To exercise them, contact tomas@usecroma.com, which is also our contact point for data-protection matters in Peru.

You may also file a complaint with the supervisory authority of your country: the Superintendencia de Industria y Comercio (SIC) in Colombia, the Autoridad Nacional de Protección de Datos Personales in Peru, or the Secretaría Anticorrupción y Buen Gobierno in Mexico. Where a record you dispute is held by an official source, the correction has to be made by that source; we will correct our own copy and point you to it.

## 11. Cookies and analytics

Our website uses essential cookies and privacy-conscious analytics to understand aggregate usage and improve the Services. You can control cookies through your browser settings.

## 12. Children

The Services are intended for businesses and professionals and are not directed to children. We do not knowingly collect personal data from minors.

## 13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you.

## 14. Contact

For any question about this Privacy Policy or your personal data, write to us at tomas@usecroma.com.

[es](https://usecroma.com/es/privacy.md) · [pt](https://usecroma.com/pt/privacy.md)
