Privacy Terms
Data Treatment and Privacy Policy
Last Updated:
Your trust is our top priority, and we are committed to protecting the privacy and security of your personal data, as well as the data of third parties that may be shared with us. We have a dedicated privacy team committed to safeguarding all personal data we collect and ensuring it is properly managed in every country where we operate. Please read our Data Treatment and Privacy Policy (hereinafter referred to as the “Privacy Policy”) carefully. To use our website and receive the services we provide, you must read and accept this Privacy Policy, as well as our Terms and Conditions, which are available.
1. Introduction and Objectives
This Privacy Policy is the document that governs the management of all Databases and/or files of Domu that contain Personal Data from clients, contractors, suppliers, and other third parties that are subject to processing by Domu, in cases where it is considered the “Controller” and/or “Processor” of such Personal Data, in accordance with the provisions of Statutory Law 1581 of 2012, Decree 1377 of 2013, External Circular No. 02 of November 3, 2015, and other rules that may amend and/or supplement them in the future. Furthermore, its objective is to establish the policies and procedures for information management and protection for Domu, aligned with the Information Security Policy implemented by the company, with the aim of preserving security during the exchange, transfer, or destruction of information.
This Privacy Policy applies globally, including to personal data transferred from the European Union, the United Kingdom, and Switzerland to Domu Technology Inc. in the United States.
2. Definitions
Authorization: Refers to the prior, express, and informed consent of the Data Subject for the processing of personal data.
Privacy Notice: Refers to the verbal or written communication directed to the Data Subjects whose personal data is being processed by Domu, informing them about the existence of the personal data processing policies that will be applied, how to access them, and the purposes for which their personal data will be used.
Database: Refers to the organized collection of Personal Data that is subject to Processing.
Biometric Data: Refers to data such as fingerprints, facial recognition, iris recognition, handwritten signature recognition, and voice recognition.
Deleted Data: Refers to data for which express authorization for processing could not be obtained from the Data Subject, or data that the Data Subject has requested to be deleted, or that Domu decides to delete from its Databases.
Personal Data: Refers to any information linked or associable to one or several determined or determinable natural persons; or information provided by any natural or legal person registering on our website and/or mobile applications.
Public Data: Refers to data classified as such under the law and not considered semi-private, private, or sensitive. Public data includes, among others, information related to individuals’ marital status, profession or trade, their status as a merchant or public servant, and data obtainable without restrictions. Public data may be found in public records, official documents, gazettes, and bulletins.
Private Data: Refers to data that, due to its intimate or reserved nature, is only relevant to the Data Subject.
Sensitive Data: Refers to data that affects the Data Subject’s privacy or whose misuse could lead to discrimination. Such data includes those revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, union membership, participation in social or human rights organizations, or political affiliation. It also includes health data, sexual life information, and biometric data.
Processor: A natural or legal person, public or private, that processes Personal Data on behalf of the Controller.
Controller: A natural or legal person, public or private, that, alone or in association with others, decides about the Database and/or the Processing of data.
Processing: Any operation or set of operations performed on Personal Data, such as collection, storage, use, circulation, or deletion.
Data Subject: Refers to the owner of the information, who can be a natural or legal person whose Personal Data is subject to Processing.
Data Transfer: Data transfer occurs when the Controller and/or Processor of personal data, located in Colombia, sends the data to a recipient who, in turn, is a Data Controller and is located within or outside the country.
Domu: Refers to Domu Technology Inc., identified with EIN 37-2102218, a company incorporated in Delaware, United States.
●Affiliates and/or Related Parties: Refers to our parent company, subsidiaries, affiliates, allies, and subordinates.
3. Processing and Scope of Personal Data
Domu, in the course of its corporate purpose and economic activities, acts as the Controller and/or Processor of personal data provided by clients, employees, contractors, and/or suppliers, which are stored in its databases and in the databases of those who, under this policy, may access such data.
Consequently, Domu collects, stores, uses, transmits, transfers, deletes, and generally processes Personal Data provided by natural and legal persons with whom it has or has had any type of relationship, regardless of its nature (civil, commercial, and/or labor), including but not limited to clients, users of cloud-based software, allies, suppliers, contractors, employees, creditors, debtors, and shareholders.
This document covers the processing of information managed by Domu. It includes all delivery, transfer, or transmission of medium- or high-confidentiality information both within the organization and in interactions with clients, suppliers, external databases, social networks, and the general public.
Information exchanges may occur through various types of communication, such as verbal communication, in-person or telephone conversations, visual methods such as videos, or written communication on paper or digital media. This involves the collection, transfer, processing, storage, and deletion of information provided by clients.
4. Guiding Principles
We are committed to ensuring that any Processing of Personal Data respects the rights enshrined in our Constitution and laws. Therefore, the following principles guide our actions:
Principle of Quality: Domu ensures that Personal Data under Processing is accurate, complete, relevant, correct, and up-to-date to fulfill the necessary purposes indicated in the comprehensive privacy notice.
Principle of Confidentiality: All individuals involved in the Processing of Personal Data are obligated to ensure the confidentiality of the information, even after their relationship with the tasks involving such processing has ended.
Principle of Consent: Domu obtains consent for the Processing of Personal Data in a free, specific, and informed manner, except when not required under Article 10 of the Federal Law for the Protection of Personal Data (LFPD).
Principle of Information: Domu provides complete information about the Personal Data being processed and other requirements established by the LFPD, enabling individuals to exercise their rights to informational self-determination, privacy, and data protection.
Principle of Purpose: The Processing of Personal Data must serve a legitimate purpose that will be communicated to the Data Subject.
Principle of Freedom: The Processing of Personal Data can only be carried out with the prior, express, and informed consent of the Data Subject.
Principle of Lawfulness: Domu collects data in compliance with applicable legislation in Mexico and internationally.
Principle of Loyalty: Domu does not use deceptive or fraudulent means to collect Personal Data and processes it in good faith and with the utmost diligence, respecting the reasonable expectations of privacy of the Data Subjects. Processing is carried out in accordance with what was agreed upon.
Principle of Proportionality: Domu only processes Personal Data that is necessary, adequate, and relevant to the necessary purposes outlined in our comprehensive privacy notice.
Principle of Responsibility: Domu has established mandatory policies and procedures for managing Personal Data within its organization. These are aligned with international best practices to ensure responsible Processing of Personal Data. Additionally, Domu provides training, updates, and awareness programs for staff regarding applicable provisions and obligations for Personal Data protection. Internal supervision and monitoring systems are in place to ensure compliance with these policies, which are reviewed periodically to determine if modifications are necessary.
Principle of Security: Information subject to Processing must be handled with commercially reasonable technical, human, and administrative measures to provide security to records, preventing their alteration, loss, unauthorized consultation, use, or fraudulent access.
Principle of Truthfulness: Information subject to Processing must be truthful, complete, accurate, updated, verifiable, and understandable. The Processing of partial, incomplete, fragmented, or misleading Personal Data is prohibited.
5. Use of the Privacy Policy and Information Protection
All Processing of Personal Data will be subject to this Privacy Policy. Therefore, if a Data Subject disagrees with this Privacy Policy, they must refrain from providing any information to be recorded in one of Domu’s Databases.
Domu is committed to the security of the Data provided and is obligated to use it appropriately and maintain its required confidentiality as established in this Privacy Policy and the applicable legislation. In accordance with this document, when Data Subjects provide their Personal Data to be collected in Domu’s Databases, it is understood that they accept and acknowledge that the Processing of such Personal Data will be governed by this Privacy Policy.
Personal Data may be transferred to Domu’s shareholders, Affiliates, and/or Related Parties, as well as to third parties and judicial or administrative authorities, whether they are natural or legal persons, Colombian or foreign, in cases where the transfer or transmission of data is necessary to carry out the uses and activities authorized by the Data Subjects in line with Domu’s corporate purpose. In all cases, the exchange of such information must comply with the requirements set out in Section 6 of this Policy. Additionally, the information must be kept strictly confidential and will undergo rigorous Processing, respecting the rights and guarantees of the Data Subjects.
Domu may use service providers and data processors acting on its behalf. These services may include system hosting and maintenance, encryption, analytics, email messaging, call center services, delivery services, payment transaction management, credit checks, and address validation, among others. Consequently, Data Subjects understand that by providing information to Domu, they automatically grant these third parties authorization to access their Personal Data.
Domu is committed to taking all necessary actions to ensure that service providers, processors working on its behalf, and other authorized third parties under this Privacy Policy protect the confidentiality of the Personal Data entrusted to them in all circumstances.
Domu may collect information available in the public domain to supplement its Databases. Such information will be treated in the same manner as outlined in this Privacy Policy.
6. Limitation of Liability
Domu makes its best efforts to comply with current regulations and safeguard the information provided by the Data Subjects or transmitted by clients. However, there is a possibility that an unforeseen external attack could breach the security of the databases protecting the information, leading to the loss or leakage of information.
In light of this, the Data Subjects acknowledge the inherent risk of disclosing, sharing, or granting access to information through electronic means and therefore release Domu from any liability in cases where unforeseen situations compromise the rights of the Data Subjects.
7. Effects of Authorization
The Authorization granted by the Data Subjects is considered an express and informed consent given to Domu, its Affiliates, Related Parties, and third parties designated by Domu in the course of its corporate purpose, for the Processing of their Personal Data. This consent is valid regardless of the means by which the data was provided (written, verbal, or through unequivocal actions). Additionally, it implies the Data Subject’s full understanding and acceptance of all the content in this Privacy Notice.
In the event of a sale, merger, consolidation, change in corporate control, asset transfer, reorganization, or liquidation of Domu and/or its Affiliates or Related Parties, Domu may transfer the Personal Data of the Data Subjects to the involved parties. By accepting this document, it is understood that Domu is authorized to carry out such transfers.
8. Personal Data Subject to Processing
Domu collects or receives information and Personal Data that fall under the following general categories:
Full Name
Email Address
Unique Population Registry Code or Country of Residence and/or Origin
Date and Place of Birth
Official Identification
Biometric Data
Gender
Bank Account Information
Data of Minors
Domu’s websites and applications are not directed at individuals under the age of 18. Domu does not knowingly collect any personal information directly from minors under the age of 18. If you believe that we may have processed personal information related to a minor inappropriately, we urge you to contact Domu using the information provided in the “Contact Us” section below.
Data from Publicly Accessible Sources
Domu obtains data through remote or local means of electronic, optical, and other communication technologies from publicly accessible sources. These are sources available to anyone and include phone directories, newspapers, gazettes, official bulletins, and social media, all in compliance with applicable regulations. Therefore, Domu does not require your consent to obtain personal data from publicly accessible sources.
9. Purposes and Uses of Information
The personal data provided to Domu will be processed for the following purposes, depending on their applicability to each Data Subject:
a. Proper execution of the contract formalized between the Data Subject and Domu.
b. Creation of an account to access Domu’s platform.
c. Identity verification using any valid official document that serves as proof of identity.
d. Facilitation of contact between Domu and the Data Subject.
e. Improvement of Domu’s commercial and promotional initiatives, as well as analysis of visited pages and searches performed, to enhance the content and articles offered by Domu and to personalize their presentation and services.
f. Conduct studies measuring the participation of various population sectors in Domu.
g. Sending information or text messages to the provided mobile phone or email regarding new services, changes to services and fees, payment reminders, promotions, events, and general information of interest to Data Subjects.
h. Billing and other tax-related purposes, in which case the data will be shared with government entities responsible for such tasks.
i. Analysis of Personal Information by Domu, its shareholders, Affiliates, Related Parties, and third parties contracted for the development and promotion of its services.
j. Completion of profile information on Domu’s platform.
k. Payment processing for acquired services.
l. Identity validation.
m. Collection of information on the services used by Data Subjects and how they are utilized.
n. Gathering information from other sources and combining it with the data Domu collects through its platform.
o. Background checks, including police, criminal, or sexual offender registry checks.
p. Fraud detection and security-related reviews.
q. Receiving results of criminal background checks or fraud alerts from identity verification services for Domu’s fraud prevention and risk assessment efforts.
r. Receiving information about the Data Subject, their activities inside and outside Domu’s platform through its partners, or information about experiences and interactions that the Data Subject has had through Domu’s network from associated advertisers.
s. Other communications and activities related to Domu’s corporate purpose.
10. Duties and Rights of Data Subjects
Rights of Data Subjects
Data Subjects whose Personal Data is provided to Domu have the following rights:
a. The right to access, update, and rectify their Personal Information free of charge.
b. The right to request proof of the existence of the authorization granted to Domu, except in cases where authorization is expressly not required by law for Processing.
c. The right to be informed, upon request, about the use that has been made of their Personal Information.
d. The right to file complaints with the Superintendence of Industry and Commerce or the competent authority for violations of the provisions of the current law and other regulations that amend, supplement, or enhance it.
e. The right to revoke the authorization and request the deletion of data when its use does not comply with the authorized purposes and uses. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce or the competent authority determines that Domu’s Processing has involved behavior contrary to the law.
f. The right to submit inquiries and claims regarding their Personal Data.
Duties of Data Subjects
Data Subjects providing their Personal Information to Domu are required to:
Provide truthful information, which may be verified by Domu for control and validation purposes. Domu reserves the right to deny requests if the information provided by the Data Subject is found to be false or inconsistent.
Keep their contact information updated to ensure efficient and timely service delivery and to maintain a direct communication and information channel between Domu and the Data Subject.
11. Confidentiality of Personal Data
The Personal Data provided by Data Subjects will be used solely by Domu, its shareholders, Affiliates, Related Parties, and authorized third parties for the purposes established in this Privacy Policy. The Data will not, under any circumstances, be used for purposes other than those for which it was provided.
Domu is committed to protecting the privacy of Personal Information and will make its best efforts to maintain it under the necessary security conditions to prevent its alteration, loss, unauthorized or fraudulent consultation, use, or access, while respecting the rights of the Data Subjects.
If, under any circumstances, a competent authority requests the disclosure of Personal Information held by Domu, and it becomes Domu’s legal obligation to provide such information, Domu will comply. In such cases, the Data Subjects accept and authorize Domu to disclose their information for this purpose. However, Domu will inform the Data Subject of the situation.
12. Information Security
In compliance with the provisions of the Federal Law on the Protection of Personal Data Held by Private Parties (Mexico), Statutory Law 1581 of 2012 (Colombia), Lei Geral de Proteção de Dados Pessoais (Brazil), Law 19.628 (Chile), the General Data Protection Regulation (GDPR), and other applicable legislations, international treaties, decrees, circulars, manuals, recommendations, and regulations on the Protection and Privacy of Personal Data, Domu has implemented administrative security measures to establish organizational management, support, and review of Personal Data security.
These measures include:
Identification and classification of information.
Awareness, training, and education of staff regarding Personal Data protection.
Domu has also established physical security measures using advanced technology to prevent unauthorized access, damage, or interference with physical facilities, critical areas, equipment, and information. This includes protecting mobile computing devices from unauthorized access.
Additionally, Domu has implemented technical security measures ensuring that access to its databases is restricted to authorized users only. In the event of a Personal Data breach, Domu will analyze the causes of the breach and implement corrective, preventive, and improvement actions to adjust security measures and reduce the risk of recurrence.
Notwithstanding these efforts, and given that Domu’s services are delivered via the internet, where personal information is also collected, there is a possibility of illegal interceptions or breaches of systems and databases by unscrupulous or unauthorized individuals. In such cases, Domu is not liable for the misuse of information obtained through these means.
12.1. Information Retention
Files under Domu’s responsibility must comply with the protocols and procedures established by the information security policy, specifically in asset management and information classification. These include:
a. Separate storage: Data belonging to the owner of the information will be stored in separate instances with access controls for reading.
b. Access restriction: Unauthorized personnel must be prevented from accessing the information.
c. Encryption: All files are encrypted upon being stored in the designated repository.
d. Secure transfer: Transfers of sensitive or restricted files must be carried out through reliable messaging systems, preferably with encryption.
13. Handling of Media
Domu will implement procedures for managing removable media in accordance with its adopted classification scheme. These procedures will adhere to the following obligations:
Media Destruction: Domu will destroy media containing confidential information when it is no longer necessary for business purposes, ensuring that the information is irrecoverable.
Protection Controls: Controls will be defined and implemented to protect media containing information that needs to be transported.
Strict Distribution Control: A strict control will be maintained for both internal and external distribution of all types of media storing confidential information.
Media Classification: Media will be classified to determine the confidentiality level of the Data.
Approved Transfers: All transfers of media must be approved before they are moved from a secure area, including when distributed to individuals.
Inventory Management: A detailed inventory of all media will be maintained.
Mobile Device Use: The use of mobile devices must be explicitly authorized and must comply with all policies, rules, and security standards defined by Domu to avoid introducing risks into the corporate network.
14. Transfers and Referrals
Domu Technology Inc. performs national and international transfers and referrals of Personal Data in accordance with its comprehensive privacy notice and in compliance with applicable legal provisions.
Communications or referrals made between Domu and data processors do not require consent (Article 2, Section IX of the LFPD Regulation), and some transfers carried out under Article 37 of the LFPD are also exempt from requiring consent.
When a transfer does require consent, this will be clearly indicated in our comprehensive privacy notice. We encourage you to review it via the link provided at the end of our Privacy Policy.
14.1. Exchange of Personal Data
When formal agreements are made for the exchange of information with third parties, procedures and/or protocols for the transfer of Personal Data must be established. At a minimum, these protocols should include the following security conditions:
Responsibility Assignment: Define responsibilities for control, dispatch, and receipt of the data.
Tracking Mechanisms: Implement mechanisms to ensure traceability and non-repudiation of the data exchange.
Incident Management: Define responsibilities and obligations in the event of information security incidents, such as data loss.
Contractual Safeguards: Include contractual safeguards regarding data ownership, personal data protection, respect for copyright, software licenses, and other similar legal considerations.
Confidentiality Agreements: Formalize confidentiality agreements with recipients of the information.
14.2. Collection of Information in Exchanges
All information managed or processed by Domu that is classified as high or medium confidentiality (or equivalent) must be received in a predefined format for such exchanges between Domu and its clients and/or suppliers, using secure and encrypted channels. The following considerations apply:
Encrypted and Authenticated Medium: The exchange medium must be encrypted, include an authentication system, and maintain an access log.
Encrypted Transmission Protocol: The information must be transmitted using a protocol that ensures data encryption during transmission.
IP-Restricted Access Control: The exchange medium must restrict access based on IP addresses, allowing only the IPs previously communicated in writing by the information owner.
Limited Storage Period: Information deposited in the exchange medium must remain stored for a maximum of 24 hours. All data on exchange mediums must be deleted at least once daily.
Provision of Exchange Medium: If the information owner cannot provide an exchange medium with the specified characteristics, Domu may provide one, adhering to all described parameters.
Evaluation of Client/Provider Protocols: Domu may evaluate and adopt the client or provider’s protocol if it maintains a high level of security.
Virus and Malware Prevention: Domu will implement controls to prevent the introduction of viruses or malware into its data network when receiving information.
Email and Messaging Guidelines: Information exchanges via email or instant messaging must comply with the guidelines and parameters outlined in this policy.
Confidentiality in Calls and Meetings: When sharing confidential information through phone calls or video meetings, employees must take special precautions regarding when, where, and how information is shared to prevent unauthorized persons or the general public from overhearing. Private settings should be sought to prevent unintended disclosure.
Physical Transport and Storage: If physical information transport or storage is necessary, the packaging or storage medium must be strong enough to protect the contents from potential damage (e.g., heat or humidity) and ensure physical security through locks and best practices.
14.3. Information Loading
Information received through exchanges is processed using extraction, transformation, and loading (ETL) processes, adhering to the following specifications:
Encryption of Sensitive Data: Sensitive Data must be encrypted prior to being loaded into Domu’s databases.
Separate Client Databases: Client data must be stored in separate databases.
Encrypted Databases: All databases are encrypted at rest.
Segregated ETL Processes: Extraction, transformation, and loading processes must be executed in separate instances.
Data Integrity Validation: Validation checks are performed on loaded data, ensuring alignment with the original data source.
15. EU–U.S. Data Privacy Framework (DPF) Compliance Notice
Domu Technology Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce.
Domu Technology Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.
If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the UK Extension to the EU-U.S. DPF, the Principles shall govern.
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/
15.1 Types of Personal Data Covered
This certification applies to personal data transferred from the EU and UK, to Domu in the United States in connection with:
AI-powered outbound and inbound communications;
Processing of call recordings, communication logs, and message outputs;
Compliance and operational metadata provided by clients;
Client-managed datasets required for Domu to perform contracted services.
Domu processes such data solely on behalf of and under the instructions of its Clients, who act as the Data Controllers.
15.2 DPF Principles
Domu adheres to the following DPF Principles:
Notice
Choice
Accountability for Onward Transfer
Security
Data Integrity & Purpose Limitation
Access
Recourse, Enforcement & Liability
15.3 Disclosures to Third Parties and Subprocessors
In accordance with the DPF Principles, Domu Technology discloses personal information to the following types of third parties and for the following purposes:
Cloud Infrastructure Providers: We use third-party hosting services (such as AWS or Google Cloud) to securely store and process call recordings, communication logs, and client datasets.
AI and Communications Subprocessors: We engage specialized service providers to facilitate AI-powered outbound and inbound communications and to perform transcription or analysis of communication data.
Customer Support & CRM Tools: We may share contact information with our internal support tool providers to manage client-managed datasets and respond to service inquiries.
15.4 Recourse, Enforcement & Dispute Resolution
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Domu Technology Inc. commits to resolve DPF Principles-related complaints about your privacy and our collection or use of your personal information. EU and UK individuals with inquiries or complaintsregarding our handling of personal data in reliance on the DPF should first contact us at domu@domu.ai.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Domu AI commits commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF to BBB NATIONAL PROGRAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your complaint to your satisfaction, please visit www.bbbprograms.org/dpf-complaints for more information or to file a complaint. The services of BBB NATIONAL PROGRAMS are provided at no cost to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction for more information on this process.
15.5 U.S. Regulatory Oversight
Domu Technology Inc. is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC)
15.6 Onward Transfers to Third Parties
Domu remains responsible for the processing of personal data it receives under the DPF and subsequently transfers to a third party acting as an agent on its behalf.
Domu complies with the DPF “Accountability for Onward Transfer” Principles, including:
ensuring all third parties provide at least the same level of protection as required by the DPF Principles;
maintaining written contracts with all subprocessors;
verifying their compliance with appropriate safeguards.
If an agent processes personal data inconsistently with the DPF Principles, Domu remains liable unless Domu proves it is not responsible for the event giving rise to the damage.
15.7 Individual Rights under the DPF
Domu Technology Inc. acknowledges that EU and UK individuals have the right to access the personal information that we maintain about them. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct their query to support@domu.ai. If requested to remove data, we will respond within a reasonable timeframe.
Additionally, if personal information covered by this policy is to be used for a new purpose that is materially different from that for which the personal information was originally collected or subsequently authorized, or is to be disclosed to a non-agent third party in a manner not specified in this policy, we will provide you with an opportunity to choose whether to have your personal information so used or disclosed. Requests to opt out of such uses or disclosures of personal information should be sent to domu@domu.ai. Certain personal information, such as information about medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, is considered “sensitive information.” We will not use sensitive information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual unless we have received your affirmative and explicit consent (opt-in).
Domu processes personal data only under client instructions, so EU and UK individuals should direct requests to access their personal information or to limit the use and disclosure of their personal information to the relevant Controller. Domu will support Clients in fulfilling these rights.
15.8 Required Disclosures
Domu may be required to disclose personal data in response to:
lawful requests by public authorities;
national security requirements;
law enforcement requirements.
Domu will notify Clients unless legally prohibited.
15.9 Data Retention under the DPF
Domu retains personal data only for the duration instructed by the Client. Once processing is complete, Domu deletes personal data using secure AWS-native purge mechanisms unless the Client instructs otherwise.
16. Cookies and Other Technological Tools
Domu uses cookies and similar technologies to personalize and enhance customer experiences, as well as to display relevant online advertisements.
Cookies are small text files containing a unique identifier that is stored on the computer or mobile device through which you access the website and/or mobile applications. These allow Domu to recognize you each time you use the website and/or applications.
The Data Subject can choose to disable some or all of the cookies we use at any time. However, this may restrict their use of the site and limit their experience.
The use of cookies does not involve or affect Personal Data and does not pose a risk of viruses.
17. Procedure for Queries, Rectifications, and Complaints
Domu has specific manuals designed for the procedures related to queries, complaints, and claims, as well as for the processing of Personal Data, which are available here.
Notwithstanding the above, a brief summary of the procedures is provided below.
17.1 Enquiries
Enquiries and requests from Data Subjects will be addressed within a maximum term of ten (10) business days from the date of receipt.
If it is not possible to resolve the query within this period, the Data Subject will be informed of the situation at the notification address provided in the query, and the response term may be extended by an additional five (5) business days.
Responses to queries or complaints submitted by Data Subjects may be delivered via any physical or electronic means.
17.2 Rectifications and Complaints
If a Data Subject believes their information needs to be corrected, updated, or deleted, or if they observe a potential non-compliance by Domu with its obligations regarding Personal Data Protection under applicable legislation or this Privacy Policy, they may submit a complaint as follows:
1. Submission of a Written Request: The request must specify the requirement in detail.
2. Incomplete Complaints: If the complaint is incomplete, Domu will request the missing information within five (5) business days of receiving the initial submission.
If the Data Subject does not provide the required information within two (2) months of the request, the claim will be considered withdrawn.
If the recipient of the complaint is not competent to address it, they will transfer it to the appropriate authority within two (2) business days and inform the claimant.
3. Acknowledgment of the Complaint: Once the complaint is complete or completed, a “CLAIM IN PROCESS” notation will be included in the database within two (2) business days.
4. Resolution Timeline: Domu will resolve the complaint within a maximum of fifteen (15) business days from the day after receiving the complete submission.
If the resolution cannot be provided within this term, the Data Subject will be informed of the delay, reasons, and an expected response date at the notification address provided in the complaint.
The extended term will not exceed an additional eight (8) business days.
Responses to complaints from Data Subjects may be delivered via any physical or electronic means.
18. Data Protection Contact
Domu has established a dedicated area for handling Personal Data, named Privacy Domu, as the entity responsible for the protection of your data.
If you have any questions or concerns about this Privacy Policy or the Processing and use of Personal Information, you may direct your inquiries, requests, complaints, or claims to:
Email: domu@domu.ai
Address: 2261 Market Street STE 86157, San Francisco, CA 94114
Phone: +1 850 364 4843
19. Information Deletion
Any information storage device deemed obsolete or decommissioned by the Data Subject must be securely eliminated according to the terms set out in the Manual of Procedures for Collection, Storage, Use, and Suppression of Information, and the following guidelines:
19.1 Deletion Procedure
Retention Period: Files will be retained for as long as requested by the Data Subject, with prior written communication sent to the Information Security Committee.
Extraordinary Deletion Requests: Partial or complete deletion of the Data Subject’s information may be requested, affecting both the received files and all data subsequently generated from Domu’s management and Processing activities.
A written request must be sent to the Privacy Domu area, which will assess whether any legislation prohibits deletion or requires conservation for a specific period.
If deletion is permissible, Privacy Domu will request Domu’s OSI (Operational Security Infrastructure) to remove the data from Domu’s databases.
Record of Deletion: When information is deleted or destroyed, a deletion record must be created, signed by all involved areas, detailing the fields destroyed.
Domu will retain public Personal Data for traceability purposes.
Destruction of Electronic Media: Magnetic (electronic) media must be destroyed before disposal to ensure it cannot be accessed by third parties.
Decommissioned Computers: The hard drives of decommissioned computers must be formatted or physically destroyed to erase stored information and installed software completely.
Document Destruction: Paper documents scheduled for destruction must be shredded using appropriate shredders located within Domu’s offices in designated secure locations.
19.2 Destruction of Storage Media
Physical Media: Physical media are tangible representations of data, often associated with paper copies (handwritten or printed), payment card plastics, fax materials, photographs, tapes, drums, plates, and printing plates, as well as any other physical device used to store logical data.
Examples include:
Magnetic Media: Diskettes, hard drives, magnetic tapes, etc.
Optical Media: CDs, DVDs, etc.
Magneto-Optical Media: Zip disks, Jaz disks, SuperDisk, etc.
Electronic Media: Flash drives, ROM and RAM memory, solid-state drives (SSD), etc.
Logical Media: Logical media store data representations in the form of bits and bytes and their corresponding structures (files, filesystems, drives, etc.).
19.3 Data Deletion from Logical Media
Redacting: This technique involves removing specific parts of a digital document to prevent the viewing of confidential data during declassification. It includes metadata deletion and truncation or removal of images and text.
Deleting: This technique performs a basic deletion by removing file references at the operating system level (de-indexing), but the data remains on the storage medium and can be recovered using forensic computing techniques.
Clearing: This method uses logical (software-based) procedures to securely delete data in storage locations, preventing recovery through forensic techniques. Secure deletion procedures are typically applied using standard read/write commands to overwrite data with new values in multiple passes or resetting the device to factory defaults (if overwriting is not supported). A secure deletion tool implementing at least one pass of overwriting is recommended.
Purging: This method uses physical or logical techniques to prevent data recovery from the storage device through laboratory techniques (e.g., recovery via magnetic remanence), especially when the device is to be reused, recycled, or disposed of. It is recommended to use at least one degaussing or purging device.
20. Modifications to the Privacy Policy
Domu reserves the right to modify this Privacy Policy at any time.
Any changes will be published on our website and/or mobile applications.
The provision of Authorization, regardless of the means, will be considered an express acceptance of this Privacy Policy.
It is the responsibility of the Data Subject to frequently review these Privacy and Personal Data Protection Policies.
21. Validity
This Privacy Policy has been effective since Jan 4th, 2026, and will be reviewed periodically during the second week of March each year.
22. Authority for Issuance, Review, and Publication
This Privacy Policy has been developed by Domu’s Privacy Area, which is exclusively responsible for protecting Personal Data and ensuring the exercise of the rights of Data Subjects.
The Privacy Policy was approved by Nicolas Diaz – CTO.
Last Update – Jan 8th, 2026