Language notice. This is an English translation provided for convenience. This Policy is issued in Spanish and English. In the event of any discrepancy, the Spanish version prevails.
1. Who we are and how to contact us
Flowing Code S.A. ("Flowing Code", “we”), a corporation organized under the laws of the Argentine Republic, with registered offices at Santiago Derqui 960, city of Santa Fe (S3000), Province of Santa Fe, Argentine Republic, Tax ID (CUIT) No. 30-71553998-1, owns the website genitrace.com and provides the GeniTrace service.
For any query, request or complaint relating to personal data:
Email: contacto@genitrace.com Suggested subject line: “Personal data — GeniTrace” Postal address: Santiago Derqui 960, Santa Fe (S3000), Santa Fe, Argentina
2. Scope of this Policy
This Policy describes how we process personal data in two distinct contexts:
(a) The Site. Browsing genitrace.com, contact forms, demonstration requests, meeting scheduling and commercial communications.
(b) The Service. The provision of GeniTrace on a dedicated instance to our customers, including the information that the customer and its users upload to and generate in their instance.
This Policy does not apply to third-party sites, applications or services accessible from the Site or the Service, which are governed by their own policies.
3. Our dual role: controller and processor
It is important to distinguish two situations, because they determine where a request should be directed:
| Context | Flowing Code’s role | Who decides on the processing |
|---|---|---|
| Site visitors, commercial contacts, customer relationship administration, invoicing, support | Data controller | Flowing Code |
| Data contained in a customer’s GeniTrace instance | Data processor | The customer (controller) |
When we act as a processor, we process data solely on the customer’s documented instructions and do not determine its purposes. If you are a data subject whose data is hosted in a customer’s instance (for example, because you are an employee, supplier, student, recipient or user of an organization that uses GeniTrace), you must direct your request to that organization. If you send it to us, we will forward it to that organization without undue delay and inform you accordingly, to the extent legally possible.
The conditions applicable to our role as processor are set out in Annex I to this Policy.
4. Data we process as controller
4.1. Site browsing
We use cookieless analytics. We record, in aggregated and non-identifiable form: pages visited, approximate country, device type, browser type, language and referring site. We do not store persistent identifiers on your device for analytics or advertising purposes and we do not build profiles.
Our servers and our infrastructure provider record, as is technically unavoidable and necessary for security, technical logs (IP address, date and time, resource requested, response code, user agent). These logs are retained for a short period, as set out in section 12.
4.2. User preferences
The visual theme (light or dark) and the selected language are stored locally in your browser and are not transmitted to our servers.
4.3. Contact forms and demonstration requests
We process the data you voluntarily provide: name and surname, email, telephone, organization, job title, country and the content of your message. These forms are processed through a forms tool provided by a corporate productivity provider, within Flowing Code’s corporate account.
4.4. Meeting scheduling
If you schedule a meeting, we process your name, email, time slot and the data you include in the invitation, through a corporate calendar tool.
4.5. Contact data of customers and administrator users
To administer the contractual relationship we process: name and surname, job title, corporate email, contact telephone and access logs of the individuals designated by the customer as administrators, signatories or technical or commercial contacts.
4.6. Support
When a support case is opened we process the identification and contact data of the requesting individual, the content of the query and the technical information needed to diagnose and resolve it. We expressly ask that no third-party personal data and no sensitive data be included in case descriptions.
4.7. Invoicing and compliance
We process the tax, billing and payment data necessary to issue invoices and to comply with our accounting, tax and anti-money laundering obligations.
4.8. Commercial communications
If you request it, or where a prior commercial relationship exists, we may send you communications about our products and news. Every communication includes a simple, free mechanism to opt out, and you may object at any time by writing to us.
5. Data we process on behalf of the customer
GeniTrace primarily processes organizational information, but management system records necessarily contain personal data. The customer’s instance hosts, on its instruction and under its responsibility:
- User and manager data: name and surname, email, job title, area, role within the management system, processes owned and permissions.
- Personnel competency and training data: required job profile, accredited training, completed courses and competency evaluations.
- Auditor data, internal and external: identification, qualifications and audit assignments.
- Supplier contact data and their performance evaluation results.
- Management system record content: documents and their versions, minutes, findings, non-conformities, corrective actions, root cause analyses, risks, indicators and calibration records, which may mention or identify individuals in their capacity as responsible, involved or audited parties.
- Traceability: records of who created, modified, reviewed, approved or accepted each item, with date and time.
- Artificial intelligence interactions: context submitted, proposals generated and the record of their acceptance or rejection.
Warning regarding records involving individuals. Non-conformities, audit findings and competency evaluations may contain assessments of the performance of identifiable individuals. The customer, as controller, must inform the affected personnel, restrict access to that information through permission configuration and refrain from using it for disciplinary or employment purposes without the safeguards required by its applicable law.
Flowing Code does not decide what data is uploaded, for what purpose or how long it is retained: those decisions rest with the customer.
6. Purposes and lawful bases
| Purpose | Lawful basis (Law No. 25,326 and related rules) |
|---|---|
| Responding to queries and demonstration requests | Data subject’s consent upon submitting the form (sec. 5) |
| Scheduling commercial meetings | Data subject’s consent |
| Preparing and sending commercial proposals | Pre-contractual measures at the data subject’s request (sec. 5(2)(a)) |
| Performing the agreement, providing and administering the Service | Contractual relationship (sec. 5(2)(a)) |
| Providing technical support | Contractual relationship |
| Invoicing and complying with accounting and tax obligations | Legal obligation (sec. 5(2)(b)) |
| Preserving the security of the Service, preventing fraud and abuse, and keeping technical logs | Controller’s legitimate interest and security duty (sec. 9) |
| Sending commercial communications | Consent or pre-existing commercial relationship |
| Processing data in the customer’s instance | Documented instruction of the customer as controller (sec. 25) |
7. Data we do not want to receive
Unless expressly provided for in the order form and subject to agreed additional security measures, the following must not be uploaded to GeniTrace: sensitive data within the meaning of section 2 of Law No. 25,326 (racial or ethnic origin, political opinions, religious, philosophical or moral beliefs, trade union membership, information concerning health or sexual life), genetic or biometric data, data relating to minors, criminal record information, or full payment card numbers.
If we detect such data being uploaded, we may require the customer to delete it and, where there is a serious risk, take containment measures.
8. Cookies and similar technologies
The Site does not use analytics, advertising, remarketing or third-party tracking cookies. It may use only local browser storage to remember your language and theme preferences, and strictly necessary cookies for security and for the operation of forms and sessions.
Within the Service, strictly necessary cookies are used to maintain the user’s authenticated session and to protect against cross-site request forgery. These cookies are not used for advertising or profiling purposes.
9. Artificial intelligence and data processing
Queries submitted to the artificial intelligence features, together with the context needed to answer them, are transmitted in encrypted form to a language model provider engaged as a sub-processor, which processes them and returns a response.
Our commitments:
- No training. Neither we nor our providers use the content of queries or responses to train, fine-tune or improve models.
- Minimization. We send only the context needed to resolve the query, not the customer’s entire database.
- Isolation. One customer’s context is never mixed with another’s and is never used to answer another customer.
- No automated decisions. AI features propose; the decision and its validation always rest with a person.
- Provider retention. We engage our model providers on terms of zero retention or retention limited to the minimum period needed for service delivery and abuse prevention.
Generated responses may contain errors. They must be reviewed by a person before being used.
GeniTrace specifics. The artificial intelligence features operate under the rule “AI proposes, people decide”: every output is generated as a proposal and is not incorporated into the management system until an authorized person accepts it, with acceptance recorded with user identification, date and time. Accordingly, GeniTrace makes no automated decision whatsoever with effects on individuals.
The context sent to the model provider may include fragments of management system records that mention individuals. We recommend that the customer apply minimization criteria when drafting non-conformities, findings and evaluations, avoiding the inclusion of personal data not necessary for the purpose of the record.
10. Recipients and sub-processors
We do not sell or transfer personal data. We share personal data only with:
(a) Providers acting as sub-processors, engaged to provide necessary components of the Site and the Service, contractually bound to confidentiality, to process data only on our instructions and to apply appropriate security measures. The current categories are listed in Annex II.
(b) Professional advisors (accountants, lawyers, auditors) bound by professional secrecy, where necessary.
(c) Public authorities, where required by a mandatory rule of law, a court order or a request from a competent authority. In that case, unless legally prohibited, we will inform the customer before responding so that it may exercise its defenses, and we will limit disclosure to the minimum required.
(d) Acquirers or successors, in the context of a corporate reorganization, merger, spin-off or transfer of business, with prior notice to the customer and maintaining the conditions of this Policy.
We maintain an up-to-date list of sub-processors identifying the provider, the service supplied and the hosting country, available upon the customer’s written request. We undertake to notify the addition or replacement of a sub-processor no less than thirty (30) calendar days in advance, within which the customer may object on reasonable and substantiated data protection grounds.
11. International transfers
Data processed in connection with the Service is hosted in data centers of infrastructure providers that may be located outside the customer’s or data subject’s country of residence. We may also access it from the Argentine Republic in order to operate and support the Service.
All international transfers are carried out applying, as applicable:
- the European Union adequacy decision in respect of the Argentine Republic (Decision 2003/490/EC, revalidated by the European Commission), which allows data flows from the European Economic Area without additional safeguards;
- the model contractual clauses approved by DNPDP Provision No. 60-E/2016 and the Model Contractual Clauses of the Ibero-American Data Protection Network adopted by AAIP Resolution No. 198/2023;
- the standard contractual clauses required by the law of the customer’s country where applicable (for example, the standard clauses approved by Resolution CD/ANPD No. 19/2024 of Brazil);
- the data subject’s informed consent or any other applicable statutory exception.
At the customer’s request we will execute the transfer instrument required by its local law.
12. Retention periods
| Category | Period |
|---|---|
| Server and security technical logs | Up to twelve (12) months, unless longer retention is needed to investigate an incident |
| Aggregated Site analytics | Indefinite, in aggregated and non-identifiable form |
| Contact form and demonstration request data | For the duration of the pre-contractual or commercial relationship and up to two (2) years from the last contact |
| Contact data of customer administrators and representatives | For the term of the agreement and two (2) years thereafter |
| Support cases | For the term of the agreement and three (3) years thereafter |
| Accounting, tax and invoicing records | Ten (10) years, in accordance with section 328 of the Argentine Civil and Commercial Code and tax regulations |
| Data in the customer’s instance | In accordance with the retention policy configured by the customer and with section 18 of the Terms of Service |
| Records of acceptance of terms and of consents | For as long as needed as evidence and until expiry of applicable limitation periods |
GeniTrace specifics. Quality management system records must be retained throughout the entire certification cycle, which typically spans three (3) years, and in many cases for longer periods where required by sector standards, the certification body or the customer’s own clients. For that reason, GeniTrace applies no automatic retention trimming to management system records: periods are defined by the customer, which is responsible for ensuring they are compatible with the requirements of its certification and its sector regulations. Deleting records that must be retained may compromise the outcome of an audit, and is a decision exclusively for the customer.
Upon expiry of these periods, data is deleted or irreversibly anonymized. Where a mandatory rule of law requires retention, data is kept blocked, with restricted access and without further processing, until expiry of the legal period.
13. Security measures
We apply technical and organizational measures appropriate to the risk, aligned with the Recommended Security Measures for the Processing and Retention of Personal Data approved by AAIP Resolution No. 47/2018 and with the practices of our quality management system certified under ISO 9001:2015. In particular:
- Isolation: each customer operates on a dedicated instance, with its own database and storage, with no commingling of data between customers.
- Encryption: encryption in transit via TLS and encryption at rest of databases and file storage.
- Access control: individual authentication, role-based profiles and permissions, least-privilege principle and periodic access reviews. Flowing Code personnel access to customer data is restricted to the technical staff strictly necessary, is named and is logged.
- Traceability: audit logs of access and of relevant operations.
- Backup and recovery: periodic, encrypted backups with restoration testing.
- Vulnerability and change management: dependency updates, security patching, code review and separation of development, testing and production environments.
- Personnel confidentiality: all personnel and external contractors are bound by confidentiality agreements.
- Secure destruction of media and information at the end of its lifecycle.
No system is absolutely secure. We undertake a qualified best-efforts obligation, not a guarantee of inviolability.
14. Security incidents
We maintain a procedure for the detection, assessment, containment, eradication, recovery and post-incident analysis of security incidents.
In the event of a security incident affecting personal data hosted in a customer’s instance, we will notify the customer without undue delay and in any case within forty-eight (48) hours of becoming actually aware of it, reporting the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken and recommended.
It is for the customer, as controller, to assess and carry out the notifications to the supervisory authority and to data subjects required by its applicable law. We will provide the reasonable assistance it needs to do so, bearing in mind that several jurisdictions impose short deadlines (for example, 72 hours in the European Union, 3 business days before Brazil’s ANPD and 48 hours before Peru’s ANPD).
15. Data subject rights and how to exercise them
Data subjects have the right to access their data, to rectify, update and delete it, to request its blocking where applicable, to object to certain processing and to withdraw consent, without retroactive effect.
How to exercise them before Flowing Code (where we act as controller): write to contacto@genitrace.com with reasonable proof of identity. We will respond within ten (10) calendar days for access requests and within five (5) business days for rectification, update or deletion requests, in accordance with sections 14 and 16 of Law No. 25,326.
Where we act as processor, the request must be directed to the organization that owns the instance. If we receive it, we will forward it without undue delay and inform the requester.
Data subjects have the right to exercise their right of access free of charge at intervals of no less than six months, unless a legitimate interest is demonstrated in accordance with section 14(3) of Law No. 25,326.
The Agency for Access to Public Information, as supervisory authority under Law No. 25,326, has the power to handle complaints and claims filed in connection with non-compliance with personal data protection rules.
Data subjects resident in other countries may additionally turn to their local supervisory authority, as indicated in section 17.
16. Minors
Neither the Site nor the Service is directed to minors, and we do not knowingly collect their data through the Site.
GeniTrace is not intended for processing data relating to minors and does not contemplate their registration.
If we become aware that we have received a minor’s data without the corresponding authorization, we will take reasonable steps to delete it or to require the responsible customer to delete it.
17. Legal framework and regional specifics
This Policy is governed by Argentine Law No. 25,326 on the Protection of Personal Data, its Implementing Decree No. 1558/2001 and the resolutions of the Agency for Access to Public Information (AAIP) of the Argentine Republic, the competent supervisory authority.
Where the customer or data subjects are located in other Latin American countries, we recognize and assist the customer in complying with the applicable local regulations:
| Country | Regulation | Supervisory authority |
|---|---|---|
| Argentina | Law No. 25,326 and Decree No. 1558/2001 | AAIP |
| Brazil | Law No. 13,709/2018 (LGPD) | ANPD |
| Chile | Law No. 19,628 and, once in force, Law No. 21,719 | Personal Data Protection Agency |
| Colombia | Statutory Law No. 1581/2012 and Decree No. 1074/2015 | Superintendence of Industry and Commerce |
| Ecuador | Organic Law on Personal Data Protection and its Regulations | Superintendence of Personal Data Protection |
| Mexico | Federal Law on Protection of Personal Data Held by Private Parties | Ministry of Anti-Corruption and Good Governance |
| Peru | Law No. 29,733 and Supreme Decree No. 016-2024-JUS | National Authority for Personal Data Protection |
| Uruguay | Law No. 18,331, Law No. 19,670 and Decree No. 64/020 | URCDP |
Several of these regimes impose additional obligations (registration, appointment of a local officer or attorney-in-fact, breach notification within short deadlines, data portability rights). Where applicable to a particular engagement, the parties will address them in the particular agreement. This Policy does not limit any rights granted to data subjects by their local law.
18. Changes to this Policy
We may update this Policy to reflect changes in the Service, in our providers or in applicable law. Material changes will be communicated to customers by email and published on the Site no less than thirty (30) calendar days prior to their effective date. The header always indicates the version and effective date; prior versions are available upon request.
Annex I — Conditions for processing personal data on behalf of the customer
This Annex governs the processing that Flowing Code carries out as a processor, on behalf of and on the instructions of the customer, in respect of personal data contained in its GeniTrace instance. It forms part of the Terms of Service and of the service agreement. In the event of conflict with the main body of this Policy regarding processing on behalf of the customer, this Annex prevails.
I.1. Subject matter, nature, purpose and duration
Subject matter and nature: hosting, storage, organization, consultation, processing, backup, transmission and deletion of personal data, by automated means, in connection with the provision of GeniTrace.
Purpose: to provide, maintain, secure, back up and support the Service, in accordance with the Documentation published at docs.genitrace.com and the customer’s instructions.
Duration: for the term of the service agreement, plus the retrieval and deletion periods set out in section I.9.
I.2. Categories of data subjects and of data
Categories of data subjects: the customer’s employees and contractors participating in the management system; process owners; internal and external auditors; individuals mentioned in non-conformities, findings and corrective actions; contacts of evaluated suppliers.
Categories of data: identification and contact data; employment and job data; training, competency and performance evaluation data as regards competency for the role; management system record content identifying or mentioning individuals; traceability, approval and acceptance records; context submitted to the artificial intelligence features.
Sensitive data: not contemplated. The customer undertakes not to upload it unless expressly agreed in the order form. Particular caution is noted regarding records relating to occupational health and safety, accidents or medical fitness, which may contain health information and must not be uploaded to the Service without prior agreement.
I.3. Customer instructions
Flowing Code processes personal data solely on the customer’s documented instructions, as contained in the agreement, the Documentation, the configuration the customer applies in the application and any additional written instructions.
Flowing Code will inform the customer if, in its reasonable opinion, an instruction breaches applicable law, and may suspend its execution until the customer confirms or amends it. If a mandatory rule of law requires Flowing Code to carry out different processing, it will inform the customer before doing so, unless that same rule prohibits it.
Flowing Code will not use the customer’s personal data for its own purposes, nor for profiling, nor for advertising, nor to train artificial intelligence models.
I.4. Flowing Code’s obligations
Flowing Code undertakes to: (a) implement and maintain the technical and organizational measures described in section 13 of this Policy; (b) ensure that persons authorized to process the data are bound by a duty of confidentiality; (c) assist the customer in complying with its obligations regarding security, incident notification, impact assessments and prior consultation with the supervisory authority, to a reasonable extent and in light of the information available to it; (d) make available to the customer the information necessary to demonstrate compliance with these obligations; and (e) not transfer or disclose the data to third parties outside the cases set out in section 10.
I.5. Personnel confidentiality
All Flowing Code personnel and external contractors with potential access to customer data are bound by confidentiality agreements of indefinite duration as regards trade secrets and of at least five (5) years as regards other confidential information, and receive instruction on the appropriate handling of personal data.
I.6. Sub-processors
The customer grants general authorization for Flowing Code to engage sub-processors, subject to the conditions in section 10 of this Policy: contractual obligations equivalent to those assumed herein, thirty (30) calendar days prior notice of any addition or replacement, and the customer’s right to object on substantiated grounds.
If the customer objects on substantiated grounds and the parties do not reach a reasonable solution within thirty (30) days, the customer may terminate without penalty the affected portion of the agreement, with a pro-rata refund of prepaid, unearned amounts.
Flowing Code remains liable to the customer for its sub-processors’ performance of these obligations to the same extent as for its own.
I.7. Assistance with data subject rights
Flowing Code will make available to the customer the application features that allow it to handle access, rectification, update, deletion, blocking, objection and portability requests itself.
Where these are insufficient, Flowing Code will provide reasonable assistance within timeframes that allow the customer to meet the deadlines imposed by its applicable law. Assistance exceeding reasonable effort may be invoiced at the then-current professional services rate, subject to an accepted quotation.
I.8. Security incidents
Section 14 of this Policy applies. Notification to the customer does not constitute an admission of fault or of any liability by Flowing Code.
I.9. Return and deletion
Upon termination of the service, Flowing Code will proceed in accordance with section 18 of the Terms of Service: thirty (30) calendar day self-service export window; deletion from production environments within the following thirty (30) calendar days; purging of backup copies within the normal rotation cycle, not exceeding a further ninety (90) calendar days; deletion certificate upon written request; and blocked retention only where required by a mandatory rule of law.
I.10. Audit
Upon the customer’s written request, with no less than thirty (30) calendar days notice and no more than once (1) per calendar year — unless there is a confirmed security incident or a request from a competent authority — Flowing Code will make available documentation of its security measures, its applicable policies and, where available, current audit reports or certifications.
If the customer requires an on-site audit or a specific assessment, it will be carried out during business hours, without disrupting operations, subject to prior agreement on scope, methodology and confidentiality, by an independent auditor that is not a competitor of Flowing Code, and at the customer’s cost.
I.11. International transfers
Section 11 of this Policy applies. At the customer’s request, Flowing Code will execute the model or standard contractual clauses required by applicable law.
I.12. Liability
Liability arising from this Annex is governed by section 23 of the Terms of Service, including the enhanced cap for unauthorized disclosure of personal data and the exceptions for willful misconduct and gross negligence.
Annex II — Categories of sub-processors
Flowing Code engages providers in the following categories. The specific identity of each provider, the service it supplies and the hosting country are set out in the current sub-processor list, available upon written request to contacto@genitrace.com.
| Category | Function | Personal data processing |
|---|---|---|
| Cloud and data center infrastructure | Hosting of dedicated instances, compute and database | Hosting of customer data |
| Object storage | Storage of attachments, documents and evidence | Hosting of customer data |
| Backups | Encrypted backup and disaster recovery | Hosting of customer data |
| Transactional email | Sending of notifications, alerts and password recovery | Email address and notification content |
| Monitoring, observability and error logging | Availability monitoring and fault diagnosis | Technical logs, with personal data minimization |
| Language model and artificial intelligence providers | Processing of queries from AI features | Query and context content submitted, with no use for training |
| Corporate productivity and forms | Management of commercial contacts, forms and scheduling | Commercial contact data |
| Invoicing, collections and accounting | Issuance of invoices and collections management | Tax and billing data |
| Document generation and electronic signature | Production of exportable documents, minutes and reports | Identification data of signatories and approvers |
19. Contact and complaints
Flowing Code S.A. Santiago Derqui 960, Santa Fe (S3000), Province of Santa Fe, Argentine Republic Email: contacto@genitrace.com Site: genitrace.com Documentation: docs.genitrace.com
If you believe we have not handled your request appropriately, you may file a complaint with the Agency for Access to Public Information of the Argentine Republic or with the supervisory authority of your country of residence.
Document version 1.0, effective as of September 20, 2026. Prior versions and their periods of effect are available upon request.