Privacy
Policy
Last updated: August 29, 2026
This notice is issued under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). Other mandatory laws may apply depending on the people, organizations, processing, and locations involved, including the GDPR or Brazil's LGPD. This notice does not claim that one legal basis or procedure is sufficient in every jurisdiction, and it is not by itself a Data Processing Agreement.
Flouvia and CORD are trade names used by Andre Valle Ortega, the operator identified in this notice. This document describes the processing evidenced in the current Cord code and configuration; it does not turn an optional or unconfigured integration into an active data flow.
01 Identity of the Controller
For legal and operational purposes, it is important to distinguish how we interact with data:
- As Data Controller: We act as controllers over the data of you and your team (our direct clients) when creating an account or subscribing.
- As Data Processor: We act as processors over the data of your own clients. We only process this information following your instructions on the platform.
Open compliance item: the controller’s verified service address has not yet been published. This omission does not restrict any privacy right or request channel.
02 Personal Data Collected
We collect information through three main channels:
- Identity Data: Name, email address, and passwords (managed securely via encrypted hashes).
- Tax Data (CFDI 4.0): RFC, Legal Name, Tax Regime, Zip Code, and Digital Seal Certificates (CSD).
- Tax Data (Verifactu, Spain): NIF/CIF, legal name, tax address, and, if the business configures the feature, an electronic certificate (.p12/.pfx). The certificate and password are stored encrypted. Real AEAT submission has an additional environment gate that is disabled by default; without the verified system identity and an enabled submission path, Cord produces a commercial document and must not claim remittance.
- Financial and Asset Data: Bank name, account holder, CLABE, payment movements, refunds, disputes, and negative balances. CORD stores the CLABE encrypted and keeps its last four digits for display. CORD does not store card numbers or security codes; Stripe tokenizes them directly.
- Identity Verification Data: Information on the legal representative, directors and beneficial owners (25% or more), and images of official identification and, where required, proof of address. Document images are transmitted directly to Stripe and are not persistently stored by CORD. Before transmitting them, CORD strips the file's metadata, including any GPS location the capturing device may have embedded. CORD retains a compliance record of each submission — which part of the document was sent, when, from which IP address, the technical form of the file and the verification system's reply — for five (5) years, as required by anti-money-laundering regulation. That record never includes the image, a thumbnail, the document number, the date of birth or the personal address.
- Business Data: Product catalog, price lists, and data of the companies you quote to.
- Buyer and Dispute Evidence: Buyer name, email, purchase IP address, commercial communications, receipts, delivery documents, service dates, and other evidence that the Client decides to save or send to contest a payment dispute.
Because payment onboarding may involve financial, asset, or identity-verification data, we request the data subject's express electronic consent before completing it. Consent may be revoked through the procedure in section 13, without retroactive effect; however, revocation or failure to provide required data may prevent CORD and Stripe from enabling or maintaining payment services.
03 Purposes
The collected data is used exclusively for the following essential purposes:
- Generate, store, and send quotes, and process the stamping of electronic invoices.
- Manage the billing of your monthly subscription and calculate excess usage.
- Payment Processing (Stripe Connect Custom): Connect the Client's payment account, receive and reconcile payments, calculate and collect Cord transaction fees, schedule payouts, process refunds, manage chargebacks and negative balances, and comply with financial verification requirements. Banking data is encrypted in CORD and transmitted to Stripe by API. Document images are transmitted to Stripe without persistent storage in CORD, with their metadata stripped beforehand.
- Artificial Intelligence: Process the text required by the AI feature the user invokes. Cord uses Anthropic's commercial API; the provider's current published policy states that commercial inputs and outputs are not used for model training unless the commercial customer opts in. Cord does not present that provider policy as a guarantee that AI processing is risk-free.
- Autonomous AI Collections (optional): If the account Administrator enables it, Cord processes receivables data (client name, email, amount owed, due date, and the conversation context selected by the workflow) to draft or send reminders on the creditor's behalf. It is disabled by default.
- Send transactional emails and notifications.
04 Anonymized and Aggregated Data
We may create aggregated or de-identified statistics to analyze trends and improve Cord. Removing direct identifiers alone does not make data anonymous: if a dataset can reasonably be linked back to a person, we continue treating it as personal data. We do not promise that every de-identification technique makes re-identification impossible.
05 Cookie Policy
CORD uses cookies and tracking technologies in a minimalist and non-invasive manner. We do not sell your browsing data to third-party advertising networks.
- Strictly Necessary Cookies: Used to keep your session active, authenticate your identity, and prevent Cross-Site Request Forgery (CSRF) attacks. Without these cookies, the application cannot function securely. These are always on and cannot be disabled from the cookie banner.
- Browser Product Analytics (PostHog): Measures page views and feature adoption after you accept analytics in the banner. Signed-in browser events may be linked to the user and organization. Separately, if PostHog is configured, Cord's server may record organization-level business events with person-profile creation disabled; those events do not depend on a browser cookie.
- Cookieless Web Analytics (Vercel): Records aggregated page-view dimensions without third-party cookies. Cord removes query strings and replaces customer, document, dispute, SSO, invitation, public-link, and identity-capture identifiers before transmission. Vercel still processes the technical request needed to provide its service, so this is described precisely rather than as “identifies nobody.”
You can change your analytics cookie preference at any time.
06 Processing roles and third parties
This privacy notice does not make a complete Article 28 DPA effective merely through use of Cord. A standalone DPA is still a controlled draft and must be completed with verified party details, processing schedules, transfer mechanism, and execution evidence before a customer relies on it. The inventory below states each third party's actual role; not every recipient is a sub-processor.
| Third party | Role | Purpose and activation |
|---|---|---|
| Neon | Sub-processor | Hosting of the PostgreSQL database containing account, operational, and customer data. Core infrastructure. |
| Vercel | Sub-processor | Hosting, request execution, technical logs, and aggregated web analytics. Core infrastructure; paths containing identifiers are redacted before Web Analytics. |
| Anthropic | Sub-processor | Text processing for AI features, including quotes and collections when used. Only when an AI feature is invoked. |
| Resend | Sub-processor | Delivery of transactional email and management of the double-opt-in newsletter. When Cord sends email or a user confirms an editorial subscription. |
| PostHog | Sub-processor | Product analytics. Browser capture starts after consent; the server may emit organization-level business telemetry without creating a person profile. Only when PostHog is configured; browser capture requires analytics consent. |
| Upstash | Sub-processor | Distributed rate limiting and ephemeral technical sessions. Only when Upstash environment variables are configured; PostgreSQL is the fallback. |
| Slack (alertas de Cord) | Sub-processor | Receipt of minimized operational alerts through a Cord-controlled webhook. Only when the internal webhook is configured. |
| Facturapi | Sub-processor | Preparation, stamping, and retrieval of CFDI, including the CSD configured by the business. Only for Mexican CFDI when the provider is configured. |
| Stripe | Provider with its own legal duties | Subscriptions, payments, refunds, disputes, payouts, and financial/identity verification. Its role depends on the product and may include independent regulatory duties. When billing or Cord Payments is used. |
| Provider with its own legal duties | User-selected OAuth authentication; Cord receives the authorized identifier, name, and email. Only when Google sign-in is selected. | |
| Apple | Provider with its own legal duties | User-selected authentication; Cord receives the identifier and data authorized by Apple. Only when Apple sign-in is selected. |
| SAT, PAC y AEAT | Authority or legally required recipient | Recipients of tax data when an applicable tax obligation or feature is actually enabled. SAT/PAC when stamping CFDI. AEAT only when Verifactu and submission are configured; submission is disabled by default today. |
| SAML, MCP, Slack y webhooks del Cliente | Customer-directed integration | Data exchange with the identity provider, MCP server, Slack workspace, or endpoint configured by the Customer. Only under the Customer’s instruction and configuration. |
07 International Data Transfers
Some providers may process data outside the country where the user or Customer is located. A provider's public DPA or sub-processor list is evidence of its published terms, but it does not prove Cord's account-specific region, configuration, or executed transfer mechanism. Those records remain part of the release checklist. Where Chapter V GDPR applies, an adequacy decision, the applicable 2021 Standard Contractual Clauses, or another valid mechanism must be identified for the particular transfer; consent to this notice is not used as a blanket substitute.
08 Business Transfers (M&A)
Information relevant to the Services may form part of a merger, acquisition, financing, restructuring, insolvency, or sale of assets, subject to confidentiality, purpose limitation, and notice duties that apply to the transaction. This does not authorize an unrelated buyer to disregard this notice or applicable law.
09 Retention and Security
Cord uses TLS in transit and field-level encryption for stored CLABEs and configured secrets. Stamped CFDI and identity-submission compliance records are currently configured around five-year retention. When Verifactu mode is actually enabled, the database stores an append-only sequence whose records reference the previous hash; this technical property is not described as proof that every Spanish retention obligation is already operational. Payment, dispute, provider, backup, and legal-acceptance retention still requires a documented record-by-record schedule. Identity-document images sent to Stripe are not persistently stored by Cord.
10 Security Breach Protocol
If Cord becomes aware of a personal-data breach affecting Customer Data for which it acts as processor, Cord will inform the applicable Customer without undue delay and provide information reasonably available for that Customer's assessment and notifications. When Cord acts as controller, it will assess notice to authorities and affected people under the law that applies to the incident. The GDPR's 72-hour supervisory-authority period is not described as a 72-business-hour processor-to-customer deadline.
11 Data Portability and Deletion
Account settings provide JSON export of organization data and CSV exports of products and clients. Deleting an organization removes its primary Cord database row and dependent operational rows. It does not by itself erase records that a provider keeps under its own legal duties, data already delivered under a Customer instruction, backups still within their rotation period, or the pseudonymous legal-acceptance evidence Cord retains to establish the contract. Requests concerning those records are assessed separately under the applicable law.
12 Minors Privacy
CORD is a SaaS platform designed exclusively for businesses and professionals. We do not knowingly collect or solicit Personal Information from anyone under the age of 18. If we learn that we have collected information from a minor without proper verifiable corporate consent, we will delete that information from our servers as quickly as possible.
13 Privacy Rights
The name and legal basis of each right depends on the applicable law. Mexico provides Access, Rectification, Cancellation, and Objection (ARCO); GDPR regimes include access, rectification, erasure, restriction, portability, and objection; Brazil's LGPD provides its own statutory rights. Settings currently supports organization export, selected CSV exports, correction of account data, and organization deletion. Other requests require individual assessment and are not described as automated merely because a Settings page exists.
Requests that cannot be completed in Settings may be sent to legal@flouvia.com. Describe the right and the account or relationship involved. Do not attach an identity document unless Cord asks for a proportionate verification method after reviewing the request; requesting a full ID by default would collect more data than necessary.
14 Changes to the Policy
Each published notice has a version and a content hash. Material changes that require a new acknowledgement are presented through Cord's legal re-acknowledgement screen and recorded against the exact version shown. Continued use is not described as “explicit acceptance.” A change to a sub-processor or transfer also follows the notice and objection procedure in the applicable executed DPA, if one exists.