Suplemen Amerika Latin

    Versi awal dalam peninjauan hukum

    Versi 0.9.0

    Dokumen ini belum diterjemahkan ke bahasa Indonesia. Dokumen ditampilkan dalam bahasa Inggris, dan teks bahasa Inggris yang mengikat sampai terjemahannya tersedia.

    Table of contents

    1. Scope and precedence
    2. Our roles in Latin America
    3. Common rules for all countries in this Supplement
    4. Peru
    5. Chile
    6. Mexico
    7. Colombia
    8. Argentina
    9. Ecuador
    10. Uruguay
    11. Venezuela
    12. Language

    1. Scope and precedence

    1.1. This Supplement applies to you if you live in, or your personal data is collected in, Peru, Chile, Mexico, Colombia, Argentina, Ecuador, Uruguay or Venezuela.

    1.2. It supplements the Privacy Policy, the Terms of Service and the other documents of the SonhoLab Legal Center. It does not repeat them.

    1.3. If this Supplement conflicts with any other SonhoLab document, this Supplement prevails for you. Nothing in any SonhoLab document excludes or limits rights that cannot be excluded or limited under the law that applies to you.

    1.4. Controller. L. M. PEREZ MONTANA, trade name SonhoLab, CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil. Email contacto@sonholab.com. Phone +55 85 99412-2292. Data protection officer: contacto@sonholab.com.

    2. Our roles in Latin America

    2.1. Controller. We are the controller (responsable) for our website, central registration, accounts, billing, support, marketing, free tools and consumer apps.

    2.2. Processor. When a business in your country (a clinic, school, store or other organization) loads personal data into a System, that business is the controller, and SonhoLab is its processor (encargado). The business must inform you, obtain your consent where its law requires it, and register its databases where required. Send requests about that data to the business. If you send them to us, we forward them and help the business answer on time.

    2.3. The Data Processing Addendum (DPA) contains the processor terms, with country annexes where local law requires specific clauses.

    3. Common rules for all countries in this Supplement

    3.1. Your rights. In every country listed you can ask us to give you access to your data, correct it, delete it and stop processing it (objection). Where your law gives you more rights, such as portability, blocking or review of automated decisions, you have them too. Country sections below list the details.

    3.2. How to ask. Write to contacto@sonholab.com, or use the tools in your account. Data export is always available in your account, on every plan. The procedure is in Your Privacy Rights and How to Exercise Them. Requests are free.

    3.3. Deadlines. We answer within the deadline of your country's law. Where your law sets no deadline, we answer within 15 days.

    3.4. Consent. Several laws in the region rely mainly on consent. Where your law requires consent for a purpose, we ask for it separately, in clear terms, and you can withdraw it at any time. Marketing and non-essential cookies are always based on your consent.

    3.5. Where your data goes.

    • Our primary hosting is Hetzner Online GmbH, in Helsinki, Finland (EU), with Hetzner's automated server backups in Finland.
    • SonhoLab is established in Brazil and accesses data from Brazil. An off-site backup copy, encrypted before it leaves the server, is stored on equipment operated by SonhoLab in Brazil.
    • Some subprocessors are in the United States (for example Stripe, Meta, Google for push notifications and analytics, and OpenAI for our own website chat and support desk). Culqi processes payments in Peru where a clinic uses it. AI providers that a business customer connects with its own key are that customer's vendors.
    • Each recipient is bound by a contract that requires protection at least equivalent to your law. The complete list is in Subprocessors and International Transfers.

    3.6. Security incidents. If an incident affects your data, we notify your authority and you within the deadlines of your law, where your law requires it. See Security and Incident Response.

    3.7. Sensitive data and children. We process sensitive data as controller only in Hades (voice), with the voice owner's express, separate consent. Hades and SonhoLab Poker are for adults (18+). See the Hades Addendum: Voice, Biometrics, Memorials and Companion AI.

    4. Peru

    4.1. Law. Ley 29733, Ley de Protección de Datos Personales, and its Reglamento approved by Decreto Supremo 016-2024-JUS, in force since 30 March 2025.

    4.2. Authority. Autoridad Nacional de Protección de Datos Personales, part of the Ministry of Justice and Human Rights (MINJUS).

    4.3. Your rights. Information, access, rectification, cancellation and objection (the "ARCO" rights), and the right not to be subject to decisions based solely on automated processing that significantly affect you, and any other right that the Reglamento (DS 016-2024-JUS) grants.

    4.4. Deadlines. We answer requests within the deadlines set by Ley 29733 and its Reglamento (DS 016-2024-JUS). If we do not answer, or you disagree, you can file a complaint (procedimiento trilateral de tutela) with the Authority.

    4.5. Databases. Where SonhoLab is the controller of a personal data bank containing data of people in Peru, SonhoLab registers it in the Registro Nacional de Protección de Datos Personales. Where a customer is the controller, the customer registers its own data banks.

    4.6. Security incidents. We notify the Authority within 48 hours of becoming aware of an incident that affects personal data, as the Reglamento requires, and inform affected people where appropriate.

    4.7. Cross-border flow. Your data flows to Finland (EU), Brazil and the United States as described in section 3.5. We inform you of this flow here, and we ensure that each recipient provides an adequate level of protection by contract. Where the Reglamento requires us to communicate a cross-border flow to the Authority, we do so.

    5. Chile

    5.1. Law today. Ley 19.628 sobre Protección de la Vida Privada.

    5.2. Law from 1 December 2026. Ley 21.719, which reforms Ley 19.628, creates the Agencia de Protección de Datos Personales and adds rights and duties similar to the GDPR. Its entry into force is set for 1 December 2026.

    5.3. Your rights today (Ley 19.628). Access (information), rectification, cancellation (deletion) and blocking. Under the current law, we must answer within 2 business days; if we do not, you can go to court (habeas data).

    5.4. Your rights from 1 December 2026 (Ley 21.719). Access, rectification, suppression, objection, portability and blocking, and the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We answer within 30 days, extendable once by up to 30 more days with reasons. If we deny your request or do not answer, you can complain to the Agencia de Protección de Datos Personales.

    5.5. Portability. From 1 December 2026, you can receive your data in a structured, commonly used, machine-readable format and have it sent to another controller where technically possible. Our in-account export already provides this.

    5.6. Authority. Until 1 December 2026, the courts. From then, the Agencia de Protección de Datos Personales.

    5.7. Security incidents. From 1 December 2026, we notify the Agencia without undue delay of incidents that create a reasonable risk to people's rights, and inform the affected people where the law requires.

    5.8. International transfers. From 1 December 2026, transfers to countries not recognized as adequate rely on contractual clauses or other safeguards provided by Ley 21.719. Our transfers rely on the contracts described in section 3.5.

    5.9. Chilean consumers. The Ley 19.496 on consumer protection also applies to you as a consumer. Nothing in our Terms of Service limits it.

    6. Mexico

    6.1. Law. The new Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), in force since 21 March 2025. The 2011 Reglamento applies where compatible until a new one is issued.

    6.2. Authority. The Secretaría Anticorrupción y Buen Gobierno, which took over the functions of the former INAI for the private sector.

    6.3. Privacy notice. This Supplement, the Privacy Policy and the Cookie Policy form our comprehensive privacy notice (aviso de privacidad integral) for people in Mexico.

    6.4. Your rights. Access, rectification, cancellation and objection (ARCO rights), and revocation of consent. For sensitive data, we ask for express written consent.

    6.5. Deadlines. We tell you our decision, and carry it out, within the deadlines set by the LFPDPPP. If we deny your request or do not answer, you can start a rights protection procedure with the authority.

    6.6. Transfers and remissions. Sending data to our processors (for example, hosting and AI providers) is a remission and does not require your consent. We do not transfer your data to third parties that would use it for their own purposes, except where the law allows it without consent.

    7. Colombia

    7.1. Law. Ley Estatutaria 1581 de 2012 and Decreto 1377 de 2013 (compiled in Decreto Único 1074 de 2015). This Supplement and the Privacy Policy form our information processing policy (política de tratamiento de la información).

    7.2. Authority. Superintendencia de Industria y Comercio (SIC), https://www.sic.gov.co.

    7.3. Authorization. Where Colombian law requires your prior, express and informed authorization, we ask for it and keep a record of it.

    7.4. Your rights. Know, update and rectify your data; request proof of your authorization; be informed of how your data is used; revoke your authorization and request deletion where there is no legal or contractual duty to keep the data; access your data free of charge; and complain to the SIC.

    7.5. Deadlines. We answer queries (consultas) within 10 business days, extendable by up to 5 more, and claims (reclamos) within 15 business days, extendable by up to 8 more, telling you the reason for any extension. You must first contact us before complaining to the SIC.

    7.6. National Database Registry (RNBD). Registration in the Registro Nacional de Bases de Datos is required only for controllers whose total assets exceed 100,000 UVT. SonhoLab will register its databases if it meets that threshold.

    7.7. International transfers. Transmissions to our processors abroad are covered by processing contracts (contratos de transmisión). Transfers to controllers abroad go only to countries with an adequate level of protection, or where another legal exception applies.

    8. Argentina

    8.1. Law. Ley 25.326 de Protección de los Datos Personales and its regulations. Argentina has ratified Convention 108+ (Ley 27.699).

    8.2. Authority. Agencia de Acceso a la Información Pública (AAIP), https://www.argentina.gob.ar/aaip.

    8.3. Your rights. Access, rectification, update, suppression and confidentiality of your data. You can exercise the right of access free of charge at intervals of at least six months, unless you show a legitimate interest to do so sooner.

    8.4. Deadlines. We answer access requests within 10 calendar days, and rectification, update or suppression requests within 5 business days. If we do not, you can take habeas data action in court and complain to the AAIP.

    8.5. Database registration. Where SonhoLab is the controller of a database of people in Argentina, it registers it with the AAIP where the law requires.

    8.6. International transfers. We transfer data to countries with an adequate level of protection or, otherwise, under contractual clauses consistent with the AAIP model clauses.

    9. Ecuador

    9.1. Law. Ley Orgánica de Protección de Datos Personales (LOPDP, 2021) and its Reglamento General (2023), together with the 2026 resolutions of the Superintendencia on large-scale processing (SPDP-SPD-2026-0005-R) and on artificial intelligence (SPDP-SPD-2026-0009-R).

    9.2. Authority. Superintendencia de Protección de Datos Personales (SPDP).

    9.3. Your rights. Information, access, rectification and update, deletion, objection, portability, suspension of processing, and the right not to be subject to decisions based solely or partly on automated assessments.

    9.4. Deadlines. We answer within the deadlines set by the Ley Orgánica de Protección de Datos Personales. If we deny your request or do not answer, you can complain to the SPDP.

    9.5. AI. Where we use AI to process your data, the AI Transparency Notice explains which features use it, the providers involved, and how to reach a human.

    9.6. Security incidents. We notify the SPDP of incidents that affect personal data within the period the law sets, and inform affected people where the law requires.

    9.7. International transfers. We transfer data to countries with an adequate level of protection or under contractual safeguards accepted by the LOPDP.

    10. Uruguay

    10.1. Law. Ley 18.331 de Protección de Datos Personales, Decreto 414/009 and Ley 19.670. The European Commission recognizes Uruguay as providing an adequate level of protection.

    10.2. Authority. Unidad Reguladora y de Control de Datos Personales (URCDP), part of AGESIC.

    10.3. Your rights. Information, access, rectification, update, inclusion and suppression.

    10.4. Deadlines. We answer access requests within 5 business days, and rectification, update, inclusion or suppression requests within 5 business days. If we do not, you can take habeas data action in court and complain to the URCDP.

    10.5. Database registration. Where SonhoLab is the controller of a database of people in Uruguay, it registers it with the URCDP where the law requires.

    10.6. Security incidents. We notify the URCDP and affected people of security incidents as the law requires.

    11. Venezuela

    11.1. Law. Venezuela has no general data protection law. Your data is protected by the Constitution: art. 28 (habeas data: the right to access your data held by others, to know its purpose, and to ask a court to update, correct or destroy data that is wrong or unlawfully affects your rights) and art. 60 (privacy). The Ley Especial contra los Delitos Informáticos also applies.

    11.2. Authority. There is no data protection authority. You can take habeas data action before the courts.

    11.3. Your rights. We give you the same rights of access, rectification, deletion and objection as described in section 3.1, within 15 days.

    12. Language

    12.1. The master text of our legal documents is in English. Where the law of your country requires information in Spanish, the Spanish version prevails for you. If a text is unclear, it is read in the way most favorable to you as a consumer.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Versi awal dalam peninjauan hukum

    Versi 0.9.0

    Sidik jari SHA-256 teks ini: e5b61395e159ac4018c1fc72c6cf73d179201cff2583d706472136f3b51a81d8

    Kembali ke Pusat Hukum