Privacy Notice

Version 1.1 · Effective 2026-05-08 · Last updated 2026-08-24

Executive summary (the essentials in 30 seconds)

1. Identity of the data controller

2. Lawful bases (Art. 7 LOPDP — Ecuadorian Personal Data Protection Law)

Being a pure client-side tool, we process no identifying data of yours and no content of yours on our servers. The only server-side processing is the aggregate counters described in section 4; the anti-abuse caps operate on an internal address of our network, not on yours. The applicable lawful bases are:

ProcessingLawful basis
CDN access logs (truncated IP, aggregated user-agent)Legitimate interest (operational security)
GitHub issues and advisories you submit voluntarilySender’s consent
Aggregate usage counters, without identifiers (section 4)Legitimate interest (knowing whether the project is used, and publishing it)
Technical caps against abuse of those counters, computed without your IP (section 4)Legitimate interest (integrity of the published figures)

3. Categories of data we do NOT process

To avoid any doubt, firmar.ec explicitly declares it does not collect, transmit, store or process:

4. Data we DO process (and why)

5. Sub-processors

Sub-processorRoleDataContractual location
CloudflareCDN + WAF + TunnelCDN logs ≤14 daysGlobal edge
Let’s EncryptTLS certificate issuancePublic CSR (no personal data)EU (ISRG)
GitHubPublic repositoriesCode + commitsUS

Two further services only come into play if you turn on the matching option (both ship disabled):

ServiceWhenWhat it receives
Time-stamping authority (freetsa.org)Only if you enable time-stampingThe hash of your document, never the document
Revocation responders of the accredited certification authoritiesOnly if you enable long-term validationThe serial number of the certificate being checked

In both cases the request goes out through a proxy of ours that strips origin and referrer, so the third party sees our server’s IP, not yours.

Any unavoidable international transfer is covered under standard contractual clauses and Ecuadorian data protection legislation. There is no international transfer of data identifying you: the only thing leaving our infrastructure is what this table describes, and only if you enable it.

6. Your ARCO+ rights (Art. 12 LOPDP)

You have the right of Access, Rectification, Cancellation, Objection, portability, erasure, and to object to automated decisions. Since we do not store identifiable personal data, in practice only the following apply:

Response deadline: 15 business days from receipt.

7. Breach notification

Should a personal data breach be detected, we will notify the Superintendencia de Protección de Datos Personales (SPDP) within 5 business days (Art. 46 LOPDP) and affected data subjects if there is significant risk. Given the pure client-side model, a personal data breach in our systems is practically impossible.

8. Auditability

The client source code is entirely public at github.com/idkmanager/firmar-ec under the AGPL-3.0 license. Any external auditor can verify:

9. Changes to this notice

We version this policy. The current version is always at /en/privacy. Previous versions are preserved in the repository git history. Any substantive change is announced 30 days in advance.

v1.1 (2026-08-24). This version does two distinct things, and they should not be conflated:

  1. It corrects an omission. Earlier versions did not declare the aggregate usage counters in section 4, which were already running. Waiting 30 days is not an option here: continuing to process without declaring would be worse than declaring today.
  2. It adds a new counter, for app installs, which starts running with this same version. That is new processing, and we say so plainly. It goes live without the 30-day notice because it is of the same nature as the other three — a global integer, no identifier, nothing of yours — and because its impact on you is nil: there is nothing to consent to and nothing to opt out of. If you disagree with that judgement, write to us through the channels in section 10.

The code that emits these pings is public and auditable (section 8): the four literal values in section 4 can be searched for in the repository.

10. Contact