Last updated: September 13, 2026
Hereinafter, "Daguito", "we" or "the Controller".
Daguito is an entity organized in the United States that provides services to clients in Latin America. Therefore, the processing of personal data may be subject simultaneously to the law of the country where the data subject resides and the law of the country where the processing physically takes place.
As an operating standard, for all data subjects and regardless of their country, we apply the most demanding level of protection among the rules applicable to us:
| Country | Main regulation | Supervisory authority |
|---|---|---|
| Colombia | Statutory Law 1581 of 2012, Decree 1377 of 2013 and Decree 1074 of 2015 | Superintendencia de Industria y Comercio (SIC) |
| Brazil | Law 13.709/2018 (LGPD) | Autoridade Nacional de Proteção de Dados (ANPD) |
| Chile | Law 19.628 and, from December 1, 2026, Law 21.719 | Personal Data Protection Agency |
| Peru | Law 29733 and its regulation | National Authority for Personal Data Protection |
| Argentina | Law 25.326 | Agency for Access to Public Information |
| United States | Applicable federal and state regulations | FTC and state authorities |
The particularities of each jurisdiction are set out in Annex A.
This policy applies to all personal data recorded in Daguito’s databases, including data collected through:
Daguito applies the eight principles of Law 1581 of 2012: legality, purpose, freedom, truthfulness or quality, transparency, restricted access and circulation, security and confidentiality.
6.1 Website visitors. Data: IP address, device and browser type, pages visited, traffic source, cookie identifiers. Purposes: to operate and secure the site, measure usage and performance, improve content, and —where the data subject authorizes it— serve and measure advertising.
6.2 Prospects and commercial contacts (leads). Data: name, email, phone, company, role, country/city, stated need, history of conversations and meetings. Purposes: to respond to requests, schedule demos and assessments, prepare quotes, follow up commercially, and —with prior authorization— send marketing communications, newsletters and content.
6.3 Platform users. Data: name, corporate email, access credentials (passwords stored encrypted), role and permissions, company, activity logs, agent and automation configuration, and integrations the user connects. Purposes: to create and manage accounts, provide the contracted service, support and debug issues, control access and security, measure product usage, bill and notify relevant service changes.
6.4 Clients and billing. Data: contact and tax identification details of the client and its representatives, billing details and contracted plan. Purposes: to perform the contract, bill and collect, and comply with accounting, tax and record-retention obligations. Note: card and payment method data are processed directly by our payment gateway (Stripe); Daguito does not store full card numbers.
6.5 Candidates, staff and suppliers. Data: résumé, contact and identification details, education, experience and references; and, for staff and suppliers, the data required by the employment or contractual relationship. Purposes: to manage selection processes, perform the employment or contractual relationship and comply with legal obligations.
6.6 Sensitive data and minors. Daguito does not routinely collect sensitive data. If it ever becomes necessary, express authorization will be requested, the sensitive nature and purpose will be disclosed, and the data subject will be advised that they are not obliged to authorize such processing. Our services are aimed at businesses and adults. We do not knowingly collect data from children or adolescents. If we detect that we have received such data without a legal basis, we will delete it.
When a client uses Daguito’s products or services and uploads, connects or provides access to databases containing personal data of its own clients, prospects, employees or other third parties, the client acts as the Data Controller and Daguito acts as the Data Processor, under the applicable data protection rules. With respect to this data:
Specific conditions on security, sub-processors, international transfers, incidents, retention, return and deletion may be set out in the corresponding Data Processing Agreement (DPA) between Daguito and the client.
Daguito’s products and services may incorporate automation and artificial intelligence tools, including lead classification, content generation, commercial follow-up, opportunity recovery, assistants and conversational agents. To provide these services:
These automations are not intended to produce legal effects on data subjects by themselves, nor to replace human decisions that may produce significant effects. Where applicable, the data subject may request information about how an automated decision works and request human intervention through the channels set out in this policy.
We use cookies and similar technologies to:
| Type | Purpose | Basis |
|---|---|---|
| Necessary | Session, security, load balancing, basic preferences | No consent required |
| Analytics | Understand how the site and product are used | Consent |
| Marketing | Measure campaigns and show relevant advertising | Consent |
You can accept, reject or configure non-necessary cookies in the site banner, and delete or block them from your browser. Disabling necessary cookies may affect how the site works. Tools used: Google Analytics and Meta Pixel. More details in our Cookie Policy.
To provide the service we rely on providers that may access personal data, including:
| Provider | Service | Location |
|---|---|---|
| AWS | Infrastructure and storage | USA |
| Stripe | Payment processing | USA / Ireland |
| Google Workspace | Email delivery | USA |
| OpenRouter | Language processing | USA |
| Google Analytics | Usage metrics | USA |
With all of them we sign agreements requiring them to process data only under our instructions and to maintain adequate security measures. Because Daguito is organized in the United States and its infrastructure is hosted outside the countries of residence of most of its data subjects, processing by default involves an international data transfer. In this regard:
In all cases we require contractual commitments of confidentiality, security and processing limited to our instructions. We may also disclose personal data when required by a competent judicial or administrative authority, or when necessary to protect the rights of third parties or the security of the service. Daguito does not sell personal data.
The data subject’s authorization is obtained before or at the time of collection, through mechanisms such as: checking boxes on forms, accepting terms when creating an account, an express reply by email or WhatsApp, or signing physical or electronic documents. We keep evidence of the authorization granted.
Authorization is not required when the information is requested by a public or administrative entity exercising its legal functions or by court order, when the data is public in nature, in cases of medical or health emergency, for historical, statistical or scientific purposes that are duly anonymized, or with respect to data related to the civil registry of persons.
As a data subject you have the right to:
The area in charge of handling requests, queries and claims is the Data Protection team, reachable at:
Email is the primary channel and is available to data subjects in any country.
13.1 Queries. The request must include the data subject’s name, a description of what is requested, a contact channel and a document proving identity (or the capacity of representative or successor). We will respond within a maximum of ten (10) business days. If not possible, we will state the reasons and the response date, which will not exceed the five (5) business days following the expiry of the first term.
13.2 Claims. Applies when the data subject considers that their data should be corrected, updated or deleted, or notes an alleged breach. If the claim is incomplete, we will ask the interested party within five (5) days to complete it; if they do not respond within two (2) months, it will be deemed withdrawn. Within two (2) business days of receipt we will add the note "claim in process" and the reason to the database until the claim is decided. The claim will be resolved within a maximum of fifteen (15) business days, extendable by a further eight (8) business days, with prior notice of the reasons for the extension.
13.3 Admissibility requirement. The data subject may only file a complaint with the SIC once they have exhausted the query or claim procedure with Daguito.
We apply reasonable technical, human and administrative measures to protect data against loss, unauthorized access, misuse or alteration, including: encryption in transit and at rest, role-based and least-privilege access control, strong authentication for staff, audit logs, periodic backups, confidentiality agreements with staff and provider assessments.
No system is completely infallible; in the event of a security incident affecting personal data, we will notify the competent supervisory authority and the affected data subjects or clients in accordance with applicable law and without undue delay.
We keep personal data only for as long as necessary to fulfill the purposes described in this policy, provide the contracted services, comply with legal or contractual obligations, resolve disputes and exercise or defend rights. In particular:
Once the purpose is fulfilled or the applicable retention period expires, the data will be deleted, anonymized or subjected to mechanisms that prevent its use for the original purposes, unless there is a legal retention obligation.
This policy is effective as of July 1, 2026. Daguito’s databases will remain in force for as long as necessary to fulfill the purposes described or while legal or contractual obligations subsist.
We may modify this policy. When the change is material, we will communicate it through the website and, where appropriate, by email, at least ten (10) days before it takes effect.
In addition to the body of this policy, if you reside in one of the following countries these rules apply to you.
| Country | Response time to requests | Points to note |
|---|---|---|
| Colombia | 10 business days (queries) / 15 business days (claims) | See sections 12 and 13. Exhausting the procedure with Daguito before turning to the SIC is required. |
| Mexico | 20 business days, plus 15 to make it effective | ARCO rights. A privacy notice with the minimum legal content and express consent for sensitive and financial data are required. |
| Brazil | 15 days | Extended rights, including portability. The LGPD requires appointing an encarregado (DPO) and, for foreign controllers offering services in Brazil, a local representative. |
| Chile | Per regulation | Until November 30, 2026 Law 19.628 applies. From December 1, 2026 Law 21.719 applies, adding ARCO rights plus portability, breach notification to the Agency and affected parties, records of processing activities and impact assessments. |
| Peru | 20 business days (access) / 10 business days (rectification, cancellation, objection) | Registration of databases with the National Authority may be required. |
| Argentina | 10 calendar days (access) / 5 business days (rectification and deletion) | Registration of databases with the AAIP may be required. |
United States: state consumer privacy laws (such as the CCPA/CPRA in California) apply only to businesses exceeding certain revenue or data-volume thresholds. If Daguito exceeds them in the future, the corresponding annex will be added with opt-out rights, disclosure of data categories and the "Do Not Sell or Share My Personal Information" link.