Este documento está disponível em espanhol (versão que prevalece) e em inglês.
Privacy policy
What personal data we process, why, who we share it with, how long we keep it and how to exercise your rights.
1. Controller
The controller of the data described in this policy is Dona IA, with its address at the Autonomous City of Buenos Aires, Argentina ("Dona"). Privacy contact: privacidad@joindona.com.
This policy covers the data of: (a) visitors of joindona.com and people who contact us; (b) Dona customers and their users of the CRM and apps. We process the data of our Customers' customers (people who message or call a business served by Dona) on behalf of that business, under the Data processing agreement: to exercise your rights over that data, contact the business; you may also write to us.
2. Data we process
Contact data: name, email, phone, company, industry and what you write in the form or through other channels.
Account data: name, email, password (stored only as an irreversible hash), language and security settings of panel, CRM and app users.
Billing data: legal name, tax details, payment history. Card data is processed by Mercado Pago or Stripe; Dona never receives it.
Usage and security data: sign-in records, IP address, sensitive actions performed (audit log) and technical data needed to operate and protect the Service.
Content the Customer uploads: business information, catalog, files, photos and videos.
We do not use third-party advertising or analytics tools on the website or the panel.
3. Purposes and legal bases
Provide the Service and support (performance of the contract).
Answer sales inquiries and follow up as you requested (your consent and our legitimate interest in replying).
Invoice, collect payments and comply with legal, accounting and tax obligations (legal obligation).
Protect the security of the Service and prevent fraud and unauthorized access (legitimate interest and the security duty of sec. 9 of Law 25,326).
Send you Service updates. You can unsubscribe at any time.
We do not sell personal data or use it to train AI models.
4. Who we share data with
We share data only with providers we need to deliver the Service (processors or sub-processors), under contract and with confidentiality and security obligations: infrastructure and hosting (DigitalOcean), AI models (Anthropic; OpenAI to transcribe audio), messaging (Meta / WhatsApp Business; Twilio for telephony), payments (Mercado Pago, Stripe) and email delivery (Resend). The complete, up-to-date list is in the Data processing agreement.
We may also share data when required by a competent authority under the law, or in the event of a merger or sale of the company, keeping the protections of this policy.
5. International transfers
Some providers process data outside Argentina, mainly in the United States. We carry out those transfers with the safeguards required by law (contractual clauses under AAIP Disposition 60-E/2016, EU Standard Contractual Clauses where applicable, or equivalent mechanisms) and require adequate security from every provider.
6. Retention
Account and Service data: while the relationship lasts and up to 30 days after it ends (to allow export), unless you ask us to delete it sooner.
Backups: rotated and deleted within 30 days at most.
Audit log: 1 year.
Billing data: as long as accounting and tax rules require (generally 10 years).
Inquiries that do not become customers: up to 2 years after the last contact.
7. Security
We apply appropriate technical and organizational measures: encryption in transit (HTTPS), encryption of third-party credentials, hashed passwords, two-step verification for Dona staff, audit logging, least-privilege access, encrypted backups and monitoring. More in our Security policy.
If an incident affects your data we will notify you without undue delay, and the authorities where required.
8. Your rights
You may request access to your data, its correction, update or deletion, object to certain processing, withdraw consent and request portability by writing to privacidad@joindona.com. We respond within the legal deadlines.
The Argentine Agency for Access to Public Information (AAIP), as the enforcement authority of Law 25,326, handles complaints from anyone whose data protection rights have been affected.
If you are in the European Union or the United Kingdom you also have the rights of the GDPR, including lodging a complaint with your local authority. If you reside in California you have the rights of the CCPA/CPRA; Dona does not sell or share personal data for advertising.
9. Minors
The Service is intended for businesses and not for people under 18. We do not knowingly collect data from minors for our own purposes.
10. Changes
If we materially change this policy we will announce it on the website and email Customers in advance. The date of the last update appears at the bottom.
Última atualização: 2026-09-28