Privacy and Data Processing Policy
Last updated: October 5, 2026
This policy explains what information we collect, what we use it for, who we share it with, and what you can require from us. It follows Costa Rica's Law 8968 on the Protection of Individuals with regard to the Processing of their Personal Data.
1. Who is responsible
Almendro Factura Electrónica is responsible for processing the data collected through this site and the platform. For any question about this policy, or to exercise your rights, write to support@almendro.cr.
2. What data we collect and why
We collect only what is needed to provide the service:
- Account and billing. Legal name, tax ID, address, email and phone of the taxpayer and its users. Used to operate the platform, issue documents before the Ministry of Finance, and bill the service.
- Electronic documents. The documents you issue, including your own customers' data. They are processed to meet your tax obligations and remain available in your account.
- Signing credentials. Your digital certificate, its password and your Ministry of Finance PIN. Used solely to sign your documents.
- Contact and support form. Name, email, phone and the message you write, in order to handle your request.
- Newsletter. Your email, if you choose to subscribe. You can unsubscribe from any message.
- Site usage. Visit statistics. Our own measurement does not store your IP address: it turns it into an irreversible code that only serves to count unique visitors per day.
Account data and signing credentials are mandatory: without them the platform cannot issue documents on your behalf. The newsletter and the contact form are voluntary.
3. Who we share it with
- Ministry of Finance. Electronic documents are transmitted to the Dirección General de Tributación, as required by law. That is the very purpose of the service.
- Infrastructure providers. Servers and backup storage, acting on our behalf and under confidentiality obligations.
- Analytics services. When enabled, the public site uses Google Analytics, Google Tag Manager and the Meta pixel, with the IP address anonymised. These services set cookies in your browser and you can block them from your browser settings.
We do not sell, rent or transfer personal data to third parties for commercial purposes.
4. International transfer
Database backups are stored on servers located in the United States. They leave our server encrypted with a key the storage provider does not hold, so it cannot read them. By using the platform you consent to this transfer.
5. How long we keep it
Your account data is kept while the service is active. The XML file of each document is kept for three months, or up to five years with extended retention; we email you before the deadline. The document data itself, such as totals, recipient and line items, remains available in your account.
Important. The legal obligation to keep electronic documents for five years belongs to the taxpayer, not to the software provider. If your plan has three-month retention, download and store your documents.
6. How we protect your information
- Your digital certificate, its password and your Ministry of Finance PIN are stored encrypted with AES-256 and are never displayed, not even to you.
- Each taxpayer's data is isolated: no user from another company can reach it, and our admin panel has no way to open your documents. What we see are account operation figures.
- If you work with an integrator, they only see the documents they issue on your behalf.
- If you work with an accountant, they cannot see or issue anything of yours without your permission, and there are two separate permissions: view, to see your issued and received documents and your reports, and issue, to invoice on your behalf. The accountant requests them and you decide which ones to grant; you can revoke either one at any time from the portal. If your accountant registered your account, it starts with the view permission, and with the issue permission too if they uploaded your certificate themselves. When they invoice for you, the signature uses your certificate, which the accountant cannot download.
- Backups run daily and travel encrypted.
No system is infallible. Technical staff with access to our servers have material access to the database, as on any cloud platform; that possibility is limited by confidentiality agreements and by the logging of administrative actions. If your company needs the full technical detail for an audit, we provide it on request.
7. Your rights
At any time you may:
- Know what data of yours we hold and obtain a copy.
- Correct data that is wrong or incomplete.
- Request that we delete your personal data.
- Withdraw your consent for non-mandatory uses, such as the newsletter.
Most of these you can do yourself from the portal: download your documents in XML and PDF, correct your account data, and unsubscribe from the newsletter. For anything else, write to support@almendro.cr and we will reply within the timeframes set by law.
Deletion has one limit that is not up to us: electronic documents already issued are not erased, because tax regulations require keeping them.
If you believe we did not handle your request properly, you may turn to the Agencia de Protección de Datos de los Habitantes (PRODHAB).
8. Changes to this policy
If we change this policy we update the date in the header and, when the change is significant, we notify you by email.