Timbro policies
Privacy Policy
What information we use, why we need it, who we share it with, and how long we keep it.
Who is responsible
INDEXA SRL, RNC 1-31-79391-6, located at Ave. Tiradentes, esq. Presidente González, Edificio La Isla, Piso 1, Ens. Naco, Santo Domingo, República Dominicana, is responsible for data Timbro collects to operate its site, accounts, and own services. Contact: hola@timbro.do.
What information we receive
When you request a demo, create an account, use Timbro, or contact us, we may receive contact details, business information, payment and invoice data, and technical records about usage, security, and performance.
How we use it
We use information to answer requests, administer accounts and services, coordinate payments, issue and deliver invoices, meet tax and accounting obligations, prevent fraud and abuse, resolve incidents, maintain security, measure the service, and improve its features.
Following up on your experience
We may send an email asking for feedback on your use of Timbro under the Terms of Use. Our email providers receive only the contact and minimal information needed to arrange and deliver that message. You can decline it on the receipt or unsubscribe in the email. These follow-up records are retained for no more than 12 months; this does not change the retention periods for payments and invoices.
Businesses and their customers
When a business submits customer or invoice data, it must provide the applicable notices and permissions. Timbro processes that information to provide, protect, and improve the platform as permitted by law.
Information in Timbro Local
When Local processes information in the business's infrastructure, the proposal and its data terms identify what information Timbro receives to activate, update, or support the service. The business remains responsible for the data it administers in that environment.
Analytics and de-identified information
We may use usage and operational information to produce statistics, trends, and indicators that help maintain and improve Timbro. Results are aggregated or disassociated to prevent the reasonable identification of people, businesses, and transactions. We do not sell personal data or identifiable business information.
Certificates and credentials
Digital certificates and their credentials are treated as confidential information with restricted access and are used only for authorized signing operations. Never send them through unauthorized channels.
Who we share it with
We may share necessary information with providers that host, protect, or support the service under contractual and confidentiality duties; with DGII and other recipients needed to complete the requested operation; or with authorities when required by law. Some providers may process information outside the Dominican Republic. You can request information about relevant recipient categories, locations, and safeguards. We do not authorize those providers to use personal data for their own commercial purposes.
Retention
Form requests are kept for up to 12 months after receipt, unless a legal obligation or claim requires longer retention. Payments, invoices, and tax records may be kept as long as needed for legal, accounting, and tax obligations. Aggregated or disassociated statistics that no longer reasonably identify a person, business, or transaction may be kept for longer.
Your requests
You can email hola@timbro.do to request access, correction, updating, deletion, objection, or information about how your data is used, where applicable. A business may also request that we stop using its identifiable data for optional service-improvement analytics. This does not affect uses necessary to provide, secure, and comply with the services, or records we must retain by law or for a claim. Never send full card details, passwords, or tokens.