Privacy Policy
Contents
- 1. Who is responsible for your data
- 2. Data we process as controller
- 3. What we use it for and on what legal basis
- 4. Information your company stores (3R SOFT as custodian)
- 5. Who we share data with
- 6. Transfers outside Panama
- 7. Security and encryption
- 8. Automatic content review
- 9. How long we keep data
- 10. Your rights
- 11. Cookies
- 12. Phone and tablet apps
- 13. Minors
- 14. Changes to this policy
- 15. Contact
This policy explains what personal data 3R SOFT processes in the 3R PROJECTS cloud service (the "Service"), what it is used for, who it is shared with and how you can exercise your rights. It is based on Panama's Law 81 of 2019 on Personal Data Protection and its regulation, Executive Decree 285 of 2021. It forms part of the Terms of Service.
1. Who is responsible for your data
The Service is provided by 3R SOFT ("3R SOFT" or "we"). There are two kinds of data in the Service, and each has a different controller:
| Data | Data controller | Role of 3R SOFT |
|---|---|---|
| Account and Service data: name, email, sign-ins, devices, billing, support and content review (sections 2 and 8) | 3R SOFT | Controller |
| Information each company stores in the system: its customers, employees, projects, documents, files, photos, signatures and locations (section 4) | The company using the Service | Custodian ("custodio"): processes it on the company's behalf and on its instructions |
If you are a customer or employee of a company that uses 3R PROJECTS and want to see or correct your data, contact that company first. If you write to us, we will pass your request on to the company and let you know.
For any privacy matter, write to us through the Service's support channels.
2. Data we process as controller
| Type | What it includes |
|---|---|
| Account | Name, email, phone (if you give it), language, password (stored only in a hashed form that cannot be read), two-step verification settings (authenticator app, backup codes and email codes) and the companies you belong to. |
| Company and Service billing | Company name and line of business, contact email and phone, plan, add-ons, payments (amount, date, method and reference) and referral code. We do not store card numbers: the payment gateway handles them. |
| Security and logs | IP address, date and time of sign-ins and failed attempts, and company events (for example, plan changes, support entries and uses of the key's backup copy). |
| Devices | When you register the iPhone, iPad or Android app: a device identifier, the platform, and the device type and model. |
| Support | Support tickets, their messages and anything you send us so that we can help you. |
| Content review | When something saved matches a sign of illegal activity: category, rule, short excerpt, user, date and time, IP and screen or field; and what the company writes in an appeal (section 8). |
| Sign-up | If Cloudflare Turnstile verification is turned on, Cloudflare processes technical browser data to check that the person signing up is not a robot. |
3. What we use it for and on what legal basis
- Providing the Service and managing your account (creating the company, letting you sign in, applying plan limits): under the contract you accept when you sign up.
- Charging for the Service and meeting tax and accounting obligations: under the contract and legal obligations.
- Protecting the Service (preventing unauthorised access, bots and abuse, and keeping security logs): under the contractual relationship and our legitimate interest in keeping the Service secure.
- Preventing illegal use of the Service (automatic content review, section 8): under the contractual relationship, since the Terms forbid it; our legitimate interest in the Service not being used for crimes; and, where applicable, legal obligations.
- Giving you support when you ask for it.
- Sending you Service emails: sign-ins, verification codes, password resets, billing notices and notices of changes.
When you sign up you accept this policy, and we record the version you accepted. Where processing is based on your consent, you can withdraw it at any time, without retroactive effect; please note that without certain data we cannot provide the Service.
We do not sell personal data or use it for advertising. Apart from the automatic content review (section 8), we do not make automated decisions that have legal effects on you.
4. Information your company stores (3R SOFT as custodian)
What a company uploads to the Service may include third parties' personal data: its customers, contacts, employees and technicians. It also includes what is captured in the field: photos, customer signatures and the location at the moment of checking in or out, taking photos or collecting a signature (the app does not track location continuously). For this data, the company is the data controller and 3R SOFT is the custodian. Therefore:
- We only process it to provide the Service, on the company's instructions: these terms, its settings and what its users do in the system. We do not use it for our own purposes, except for the automatic content review (section 8).
- Our staff and providers with access are bound to keep it confidential.
- We apply the security measures in section 7.
- If a security incident affects that data, we inform the company immediately so that it can notify ANTAI and the people affected as the law requires.
- We help the company handle requests from people about their data.
- The company authorises us to use the providers listed in section 5. If we change providers, we update this policy and give notice in advance; if the company does not agree, it may cancel.
- When the Service ends, the company may ask for its information, and we then delete it as described in section 9.
- Electronic invoices are sent to the PAC the company hired, when the company instructs us to.
As controller, the company must have a legal basis to process that data, inform the people concerned (for example, its technicians about location and its customers about photos and signatures) and respect their rights. If it stores data about minors, it needs authorisation from their parents or guardians.
5. Who we share data with
We only share data with those who need it to provide the Service, and only what is necessary:
- Servers and database: cloud hosting providers.
- Files: S3-compatible object storage providers (files are stored encrypted).
- Email: an email delivery provider (SMTP), which receives the address and content of each Service email.
- Bot protection: Cloudflare Turnstile, if it is turned on for sign-up.
- Payments: payment gateways, Yappy and banks, with the data needed for each payment.
- PAC: the electronic invoicing provider your company chose, with the invoice data your company instructs us to send.
- Authorities: when a law or an order from a competent authority requires it. We will hand over only what is required.
You can ask us for the current list of providers.
6. Transfers outside Panama
The servers and some providers may be located outside Panama, so your data may be stored or processed in other countries. We only do this:
- with providers that offer a level of protection equal to or higher than Panamanian law requires, or that are bound by contract to protect the data (Law 81 of 2019, article 33; Executive Decree 285 of 2021, articles 51 to 53); and
- to the extent necessary to provide the Service you contracted.
By accepting this policy, you consent to these transfers. For the information your company stores, the company authorises them as controller and must tell the people whose data it stores.
7. Security and encryption
- Encrypted connections (HTTPS), passwords stored in a form that cannot be read, optional two-step verification and logging of sign-ins.
- Each company's information is kept in a separate area of the database (PostgreSQL) and encrypted with the company's own keys. Files are also stored encrypted.
- Standard mode (the default): we keep a backup copy of the company's key to recover access (for example, if a password is forgotten) and to give support. In this mode, therefore, 3R SOFT can technically access the information. We only use that copy to recover access when the company asks, for support the company requests or authorises, or to comply with an order from a competent authority. Each use is logged and the company can see it.
- Private mode (optional): only the company holds the keys. 3R SOFT cannot read or recover the information already saved (the automatic content review in section 8 still happens when saving, before encryption). If the passwords and the recovery key are lost, nobody can recover it.
- Support access: support staff can enter a company to help it with the "Enter (support)" option, which asks for confirmation and is recorded in the company's events. If the company's information is encrypted, this is only possible while the company has a temporary access open in Settings → Data privacy.
- Some technical data is not encrypted with the company's key because the Service needs it to work: identifiers, statuses, creation dates, document codes, sign-in data and the Service's billing data. Support tickets and their messages are stored in the central system and are seen by support staff. Content review records (section 8) are also stored in the central system and are seen by 3R SOFT staff.
- Incidents: if a security breach affects data for which we are the controller, we will notify ANTAI and the people affected within 72 hours of becoming aware of it (Executive Decree 285 of 2021, article 37), in clear language and with what they can do to protect themselves. If it affects a company's information, we inform the company immediately.
8. Automatic content review
To prevent the Service from being used for illegal purposes, the system automatically reviews what is saved. Suspension and appeals are explained in section 5 of the Terms of Service.
- What is reviewed: the text users save from the web, the app or the API, the names of uploaded files and the text inside documents (txt, csv, docx, xlsx and pdf). Images and photos are not analysed.
- How: the text is compared against a list of signs of illegal activity under Panamanian law, such as drug trafficking, weapons or explosives, child sexual abuse material, human trafficking, money laundering, forgery of documents or money, and terrorism.
- When: on the server, at the moment of saving and before encryption. It therefore also applies in private mode: that mode prevents 3R SOFT from reading information already saved, but does not prevent this review.
- What is recorded when there is a match: the category, the rule matched, a short excerpt (up to about 200 characters around the match), the user, the date and time, the IP address and the screen or field. These records are stored in the central system, are not encrypted with the company's key and are seen by 3R SOFT staff. 3R SOFT is the controller of these records.
- What happens next: with a clear sign, the content is not saved, the company's account is suspended immediately with no access at all, and the company's main contact is notified by email with a link to appeal. With a less clear sign, a person at 3R SOFT reviews it and may suspend the account in the same way.
- Review by a person: Law 81 of 2019 (article 19) recognises the right not to be subject to a decision based solely on automated processing that produces negative legal effects. To respect it, each suspension can be appealed once, and the appeal is reviewed by a person, not by an automated system, normally within 5 business days. The appeal asks for the company's real business activity, a description of the business and an explanation of the content; the RUC or aviso de operación (operating notice) and a contact phone may be added.
- Retention: these records and appeals are kept for up to 5 years after the case is closed.
- Authorities: we may keep this information and hand it over when Panamanian law or a competent authority requires it.
9. How long we keep data
- Company information: while the company's account is active. After cancellation, the company has 30 days to ask us for a copy; we then delete it from the systems in use, and backup copies are erased as they rotate, within 90 days at most.
- User account: while it belongs to at least one company. If it no longer belongs to any, you can ask us to delete it.
- Service billing: for as long as tax and commercial laws require.
- Content review and appeals: up to 5 years after the case is closed, or longer if a competent authority requires it.
- Security logs and support tickets: for as long as needed for the security of the Service and to handle claims; those of a cancelled company follow the same periods as its information.
10. Your rights
You have the right to access your data, rectify it, ask for its cancellation (deletion), object to its processing and receive it in a structured, commonly used format to take it to another service (portability) (Law 81 of 2019, article 15). These rights cannot be waived and exercising them is free of charge.
- You can change much of your account data yourself under "My account".
- For anything else, write to us through the Service's support channels from your account's email address or with what is needed to verify your identity, and say what you are asking for.
- We answer access requests within 10 business days at most, and rectification or cancellation requests within 5 business days at most (Law 81 of 2019, articles 16 and 17). Other requests, within 10 business days at most.
- We may be unable to delete data that the law requires us to keep (for example, billing records); in that case we will explain why.
- If your data is part of a company's information (section 4), the request is handled by that company; we help it.
If you are not satisfied with our answer, or do not receive it in time, you may file a complaint with the National Authority for Transparency and Access to Information (ANTAI), Personal Data Protection Directorate: www.antai.gob.pa, email [email protected].
11. Cookies
We only use the cookies needed for the Service to work: the session cookie (to keep you signed in and protect forms) and the language cookie. We do not use advertising cookies or third-party analytics tools. If sign-up uses Cloudflare Turnstile, Cloudflare may process technical browser data for verification only.
12. Phone and tablet apps
- The app registers the device (identifier, platform and model) to let you sign in and to apply your account's device limit.
- It asks the phone's system for permission to use the camera (photos) and location (when checking in and out, taking photos or collecting a signature). You may refuse; some features will then not be available.
- It keeps a working copy on the device so that it can work offline, and syncs it with the Service when there is a connection.
13. Minors
The Service is for businesses and its users must be adults. We do not knowingly collect data about minors as controller. If a company stores data about minors in its information, it must have authorisation from their parents or guardians.
14. Changes to this policy
If we make important changes, we will announce them to each company's contact email and inside the Service at least 30 days before they take effect. The date of the last update is shown at the top.