Back to home

Legal

Privacy Policy

Last updated August 30, 2026
Effective from September 29, 2026
01

1. Introduction and Roles

At Proxima AI LLC ("Proxima", "we", "our", "us"), we operate Sello Sign and respect your privacy. This policy describes how we collect, use, and protect information when you use our electronic signing platform for tax documents in Costa Rica, the Dominican Republic, El Salvador, Guatemala, and Panama.

This policy applies exclusively to the cloud service hosted by Proxima (sign.sello.page). If you use Sello Sign self-hosted, you are the data controller and this policy does not apply to you.

Data processing roles. Sello Sign serves electronic invoicing providers who in turn serve their own taxpayer clients. That chain determines who answers for each piece of data: Proxima acts as data controller for your users' account data (name, email, credentials, access records, and billing), which we process to provide and charge for the Service.

For the data you upload about your issuers (taxpayers) — tax data, signing certificates, and the documents being signed — Proxima acts as data processor, on your behalf and under your instructions. You are the controller toward those issuers: it is your responsibility to have a legal basis to process their data, to inform them, and to handle their rights requests. We process that data only to provide the Service to you, never for our own purposes.

Additional jurisdictions: we may progressively enable the Service in other countries, including Ecuador, Bolivia, Peru, Colombia, Uruguay and Brazil. This policy applies equally to data processed in those jurisdictions, under the same roles described above.

02

2. Information We Collect

Account information

  • 01 Name, email, and password (stored hashed) when you create your account
  • 02 Authentication information, including the 2FA secret and backup codes if you enable it
  • 03 Sign-in data from OAuth providers (Google or GitHub) if you choose that method

Issuer information

  • 01 Issuer tax data per jurisdiction: name, cédula jurídica (Costa Rica), RNC/ID (Dominican Republic), NIT/NRC (El Salvador), NIT (Guatemala), RUC (Panama), economic activity, and technical contact
  • 02 Digital signing certificates, stored encrypted at rest
  • 03 Signing records with metadata for each operation and, if you enable signature storage, the resulting signature

Usage information

  • 01 Access and administrative activity records, including IP address and browser
  • 02 API usage: endpoints accessed, request volume, and source IP address
  • 03 Session information (device, browser, IP) used for security and so you can revoke sessions
03

3. How We Use Your Information

  • 01 Provide and maintain the electronic signing service
  • 02 Authenticate your identity and protect your account
  • 03 Process the signing of electronic tax documents (DTE, FE, e-CF depending on jurisdiction)
  • 04 Manage subscriptions, billing, and collection, including metering usage beyond your plan
  • 05 Send notifications related to the service, security, and your account
  • 06 Improve platform security and functionality, and detect abuse
04

4. Certificates and Signing Data

Signing certificates are especially sensitive data. We apply specific measures:

  • 01 Private keys are stored encrypted at rest with XChaCha20-Poly1305 (256-bit authenticated encryption) and are only decrypted in memory for the instant of signing
  • 02 Private keys are never transmitted in plaintext nor exposed through the API; they can only leave the platform through an export you explicitly request and confirm with your password
  • 03 Signing records contain operation metadata. If you enable signature storage in your workspace settings, the record also includes the generated signature, which in some formats embeds the signed document; that storage is optional and you define its retention period
  • 04 The public signature verification tool processes certificates exclusively in the browser via the Web Crypto API: they are never transmitted to or stored on our servers
  • 05 In Guatemala (FEL regime) we apply only the taxpayer's emission signature: you transmit the signed document to the SAT-authorised Certificador of your choice. Sello Sign is not a Certificador and sends neither your data nor your issuers' data to that third party
05

5. Data Sharing and Subprocessors

We do not sell your personal information nor share it with third parties for advertising purposes. We share it only with the infrastructure providers needed to operate the Service, when required by law, or when you explicitly consent.

The following subprocessors process data on our behalf:

International transfers: our infrastructure and that of our subprocessors is hosted primarily in the United States and on global distribution networks. When you use the Service from your country, your data and your issuers' data is transferred and processed outside your jurisdiction. We require contractual confidentiality and security commitments from each subprocessor.

  • 01 Cloudflare — application hosting, distribution network, and edge protection (United States and global network)
  • 02 Neon — managed PostgreSQL database holding accounts, issuers, encrypted certificates, and records (United States)
  • 03 Polar — payment processing and subscription billing; receives name, email, and transaction data (United States)
  • 04 Resend — transactional email delivery: verification, password recovery, invitations, and alerts (United States)
  • 05 Google and GitHub — only if you choose to sign in with those providers
  • 06 Tax and judicial authorities — only where a legal obligation or valid request exists
06

6. Data Retention and Deletion

We retain your information while your account is active and for the periods described below. Sello Sign is a signing tool: the obligation to retain tax documents and their receipts for statutory periods belongs to the issuer and to you as the provider, not to Proxima. We do not retain records beyond what is needed to provide the Service.

If you request deletion of your workspace, a staged process applies: a 30-day grace period during which the service stays operational and you can reverse the request, followed by 90 days of retention during which you can still export your data or request restoration. After 120 days from the request, deletion is permanent and irreversible.

Retention by data type:

  • 01 Account data (name, email, credentials): while the account is active. When you delete your user account, it is removed immediately
  • 02 Issuer data, certificates, and API keys: while the workspace is active; after a deletion request, until permanent removal at 120 days
  • 03 Signing records: while the workspace is active. If you enable signature storage, the stored signature is automatically deleted once the retention period you configure elapses (between 1 and 365 days depending on your plan), keeping only the operation metadata
  • 04 Audit and access records: 24 months, to allow investigation of security incidents
  • 05 Data exports generated on request: the file stays available for 7 days and is then automatically deleted
  • 06 Invoices and payment records: retained in accordance with the accounting and tax obligations applicable to Proxima, independently of workspace deletion
07

7. Security

We implement technical and organizational measures to protect your information:

No system is completely secure. We recommend enabling two-factor authentication, rotating your API keys periodically, and revoking any session you do not recognize.

Incident notification: if we detect a security breach affecting your personal data or your issuers' data, we will notify you without undue delay and, in any case, within 72 hours of becoming aware of it, describing the nature of the incident, the data affected, and the measures taken.

  • 01 Encryption in transit (TLS/HTTPS) and authenticated encryption at rest for private keys
  • 02 Two-factor authentication (2FA) available for all accounts, with backup codes
  • 03 Role-based access control within workspaces (owner, admin, member)
  • 04 Audit trail of access and administrative operations: sign-ins, credential changes, exports, and deletions
  • 05 Detailed record of every signing operation, with issuer, API key, environment, outcome, and IP address
08

8. Your Rights

You have the right to:

Access, rectification, and export can be exercised directly from the platform: your account settings let you edit your data, and workspace settings let you generate a complete JSON export, with the option to include your certificates' private keys after confirming your password.

For any other request, write to the address at the end of this policy. We will respond within 30 calendar days. If you are a taxpayer whose data was uploaded by an invoicing provider, please contact that provider: they are the data controller and we act only on their behalf.

  • 01 Access your personal data and obtain a copy
  • 02 Correct inaccurate information in your account
  • 03 Request deletion of your account and your workspace
  • 04 Export your data and certificates in a standard, machine-readable format
  • 05 Object to a specific processing activity or withdraw your consent where that is the legal basis
09

9. Cookies and Local Storage

Sello Sign does not use advertising, profiling, or third-party analytics cookies. We do not embed Google Analytics, tracking pixels, or equivalent tools.

We use only cookies strictly necessary for the Service to work:

Additionally, your theme preference (light or dark) is saved in your browser's local storage and is never sent to our servers. You can clear these cookies from your browser, but your session will end and some preferences will be lost.

  • 01 Session cookie: keeps you securely signed in
  • 02 Active workspace cookie: remembers which workspace you are working in
  • 03 Language cookie: preserves the interface language you selected
  • 04 Temporary cookies for the registration and two-factor verification flows
10

10. Changes to This Policy

We may update this Privacy Policy. Material changes — new processing purposes, new subprocessors, or modified retention periods — will be notified by email at least 30 days before they take effect, in line with the notice period set out in our Terms of Service.

Non-material changes, such as wording clarifications, take effect upon posting on this page. Continued use of the Service after the effective date constitutes your acceptance.

11

11. Contact

For privacy inquiries or to exercise your rights, you can contact us at

privacy@proxima.la