← Back

Privacy policy

Last updated: September 17, 2026

Article 1 — Data controller and scope

LAB 9 S.A.S., CUIT 30-71742170-8, a company incorporated in the Republic of Argentina, with registered address at Juan B. Terán 201, San Miguel de Tucumán, Tucumán, owner and developer of the Quoryks AI platform, is the data controller for the personal data described in this Policy, within the meaning of Law No. 25.326 and Regulatory Decree No. 1558/2001. Contact for personal data matters: privacidad@quoryks.com.

Scope. This Policy applies to: (1) Users who create or use an account on the platform; (2) Clients (natural or legal persons) who contract the service; (3) visitors to the quoryks.com website and its official channels; and (4) third-party data subjects whose documents are uploaded, sent by email, or submitted via API to the platform.

When Quoryks AI processes personal data contained in or extracted from documents that a Client uploads—names, CUIT, addresses, amounts, or other data relating to suppliers, employees, or third parties—LAB 9 S.A.S. acts as Data Processor (Art. 25, Law 25.326) and the Client is the Data Controller, and must have obtained the necessary legal bases or consents.

Database registration. LAB 9 S.A.S. is in the process of registering its databases with the National Database Registry of the Agency of Access to Public Information (AAIP), in accordance with Art. 21 of Law 25.326.

Article 2 — Categories of personal data processed

a) User account data: first name, last name, email address, profile picture (optional), password (stored using the scrypt key derivation function, with no access to plain text), role within the Organization, and, where third-party authentication is used (Google Sign-In), the identifier of the linked account.

b) Connection and technical usage data: IP address, browser or device identifier (user agent), access logs, date, time and duration of sessions, activity logs on the platform and API, and API keys generated by the Organization.

c) Billing and contracting data: legal name, CUIT or tax identification, tax address, VAT status, contracted Plan and Add-ons, invoices issued and payment status. Quoryks AI does not store or process credit or debit card data; these are handled by the payment gateways indicated in Article 5.

d) Data contained in documents uploaded by the Client: legal name, CUIT, address, contact details, commercial terms, amounts, line-item detail, and any other personal data present in invoices, delivery notes, or other documents uploaded via web, email, or API. With respect to this data, LAB 9 acts strictly as Data Processor.

e) Received email data: sender address and name, subject, message body, and attachments when the Client uses the document reception address assigned to its Organization. These are processed on behalf of and on the instructions of the Client as Data Processor.

f) Commercial contact data (leads): name, email address, company, phone, and comments voluntarily provided by interested parties through website forms or WhatsApp.

g) Review audit data: a record of edits made by Users to processing results (field modified, previous and new value, author and date). These are kept as an audit trail for the Client and are used, in aggregated and dissociated form, to calibrate confidence levels and improve service accuracy. Quoryks AI does not record attention, focus, or review-time metrics for Users.

h) Website navigation data: pages visited, visit source, device, approximate location (country/city level), navigation and sign-up events (including the Plan selected), collected through Google Analytics in accordance with Article 12. They are not used for advertising and are not cross-matched with data under subsections d), e), and g).

i) Communications management data: destination address, subject, content and delivery status of transactional emails, and suppression list (unsubscribes and permanent bounces).

Sensitive data. Quoryks AI does not collect or require sensitive data within the meaning of Art. 7 of Law 25.326. If documents uploaded by the Client exceptionally contain sensitive data, the Client assumes sole responsibility for having the legal basis required for their processing.

Minors. The service is intended exclusively for persons over 18 years of age. Quoryks AI does not knowingly collect data from minors; if detected, it will delete them.

Article 3 — Roles: Data Controller and Data Processor

LAB 9 S.A.S. acts as Data Controller with respect to data under subsections a), b), c), f), h), and i) of Article 2.

LAB 9 S.A.S. acts as Data Processor with respect to data under subsections d), e), and g) of Article 2. In that capacity, and in accordance with Art. 25 of Law 25.326, it undertakes to:

Process such data only in accordance with the Client's instructions and for the sole purpose of providing the contracted service.

Not use the Client's data or documents for its own purposes or for training general-purpose or third-party artificial intelligence models, except with the Client's express authorization. LAB 9 may use correction records under subsection g), solely in aggregated, anonymous, and dissociated form (Art. 2, Law 25.326), to calibrate confidence levels and optimize extraction algorithms, without such information allowing documents to be reconstructed or individuals to be identified.

Not assign, transfer, or disclose such data to third parties, except to authorized subprocessors under Article 5.

Apply the security measures in Article 8.

Maintain professional secrecy and confidentiality (Art. 10, Law 25.326), an obligation that survives termination of the contractual relationship and extends to all its personnel.

Not access the content of the Client's documents except upon the Client's express request for support tasks, limiting access to the specific case and keeping a record thereof.

Notify the Client without undue delay of any security incident affecting data processed on its behalf.

Upon termination of the contractual relationship, retain or delete data in accordance with Article 7 and Annex I.

These obligations are incorporated automatically through Annex I and may also be formalized in a Data Processing Agreement (DPA) signed in a separate instrument, upon the Client's request.

Article 4 — Purposes and legal bases

Account data: to create, activate, and manage the account, verify identity, manage roles and permissions, ensure access security, and send operational notifications. Legal basis: performance of the contract (Art. 5(2)(d), Law 25.326).

Connection and technical usage data: to ensure platform security and integrity, prevent abuse and cyberattacks, diagnose errors, and measure Sheet and User consumption against the contracted Plan. Legal basis: performance of the contract and legitimate interest in security.

Billing data: issuing invoices, collection, administrative management, and compliance with tax obligations. Legal basis: performance of the contract and legal obligation.

Documents and received emails: provision of the contracted SaaS service (reading, extraction, structuring, validation, storage, and export). Legal basis: the Client's instructions in its capacity as Data Controller.

Commercial contact data: responding to inquiries, sending requested information, and coordinating demonstrations. Legal basis: the data subject's consent.

Review audit data: traceability for the Client and improvement of service accuracy in aggregated form. Legal basis: performance of the contract.

Web navigation data: visit statistics, measurement of site performance and the commercial funnel through sign-up. Legal basis: consent given through the site's cookie notice.

Communications management: ensuring delivery of transactional communications and maintaining unsubscribe lists. Legal basis: legal obligation and performance of the contract.

Mandatory or optional nature. Provision of account and billing data is mandatory; omission or inaccuracy prevents account creation or provision of the service. Phone number on contact forms and profile picture are optional.

Automated decisions. The platform uses artificial intelligence to extract data from documents and suggest values with a confidence score. Such processing does not produce legal effects or constitute final automated decisions concerning individuals: the Client and its Users retain human oversight and the ability to review, edit, or discard any data before use.

Article 5 — Subprocessors and service providers

To provide Quoryks AI services, LAB 9 S.A.S. uses technological infrastructure and services from external providers (subprocessors) involved in receiving, processing, extracting, and/or storing information, in the following categories:

Cloud infrastructure and storage providers: hosting of servers, databases, and uploaded documentation files.

Reading, data extraction, and Artificial Intelligence providers: external OCR and Artificial Intelligence services to which images or fragments of documents are transmitted solely to perform automated reading, structuring, and field extraction.

Transactional communications providers: management of sending and receiving informational or operational emails.

Authentication and identity service providers: validation of access through third-party accounts.

Conditions. Subprocessors and providers render their services under their enterprise contractual terms. LAB 9 selects providers that offer adequate security standards and, for OCR and AI providers, verifies that their terms exclude use of the Client's documents to train their models. The Client understands that use of automated extraction necessarily involves technical transmission of documents, or fragments thereof, to such providers.

General authorization and updates. The Client grants LAB 9 general authorization to engage or replace subprocessors necessary for the service. LAB 9 publishes the updated list in this Policy and at quoryks.com/seguridad, and will notify Clients by email at least fifteen (15) days in advance of the addition of a new subprocessor that accesses the Client's documents. A Client with reasonable objections may cancel the service in accordance with the Terms and Conditions.

Article 6 — International data transfers

Personal data and documents processed through Quoryks AI are stored and processed on servers located outside the Republic of Argentina. Such transfers are carried out in accordance with Art. 12 of Law 25.326 and DNPDP Disposition No. 60-E/2016, under the following conditions:

a) European Union (primary hosting, file storage, and OCR and language-model engines). The application, database, uploaded files, and data extraction engines operate in data centers in European Union Member States. EU Member States are included in the list of countries with adequate protection (Disposition 60-E/2016); therefore these transfers are authorized by law without additional safeguards or specific consent from the data subject.

b) United States (web analytics). The web analytics service may process data in the United States, a country not recognized by the AAIP as having adequate protection. These transfers are made: (i) under contractual clauses incorporating the safeguards set out in the contract model approved under Disposition 60-E/2016 or equivalent mechanisms offered by the provider; (ii) transmitting only the information strictly necessary for extraction, without retention by the provider or use for training; and (iii) with respect to account and navigation data, with the User's express consent given by accepting this Policy (Art. 12(2), Law 25.326).

The Client, as Data Controller of the data in its documents, expressly authorizes the transfers described by accepting Annex I. LAB 9 applies the security measures in Article 8 in all cases.

Article 7 — Retention periods

Account data: for the life of the account and up to twenty-four (24) months after closure, unless earlier deletion is requested.

Connection and technical usage data: up to twenty-four (24) months from generation, for security and audit purposes.

Billing data: for the duration of the subscription and for tax and accounting limitation periods required by applicable law.

Documents, received emails, and processing results (on the Client's behalf): for the term of the contract. When a User deletes a document, it immediately becomes inaccessible (logical deletion) and is permanently deleted from systems, including backup copies, within a maximum period of sixty (60) days. Upon contract termination, data are kept under secure conditions for a maximum period of twenty-four (24) months (Art. 25(2), Law 25.326) to allow export or further instructions from the Client, and are then permanently deleted. The Client may request early deletion at any time in accordance with Annex I.

Commercial contact data: up to twenty-four (24) months from the last effective contact, or until the data subject requests removal.

Review audit data: for the term of the contract; aggregated and dissociated metrics may be retained longer as they do not constitute personal data.

Web navigation data (Google Analytics): fourteen (14) months.

Sent communications: twenty-four (24) months. Suppression-list addresses are retained while the reason persists.

Article 8 — Technical and organizational security measures

Quoryks AI implements measures in accordance with Art. 9 of Law 25.326 and AAIP Resolution No. 47/2018, including:

Encryption in transit via TLS on all communications with Users and subprocessors, and forced redirection to HTTPS.

Encryption at rest of uploaded files.

Encryption of credentials and secrets for integrated services using authenticated AES-256-GCM encryption; passwords stored using the scrypt key derivation function.

Secure authentication with expiring sessions and support for sign-in via Google.

Role-based access control and isolation by Organization: each item of data is linked to a single Organization and access is restricted to Users with the corresponding Role. LAB 9 personnel do not access documents except upon the Client's support request.

Traceability: every edit to a processing result is logged with author, date, and previous and new values.

System logging and monitoring, with automatic redaction of sensitive fields in application logs.

Periodic encrypted backups stored in the European Union.

Incident response procedure, with notification to the affected Client without undue delay and to the AAIP in accordance with AAIP Resolutions No. 47/2018 and No. 332/2020.

Article 9 — Data subject rights

Data subjects have the right to access their data (free of charge at intervals of not less than six months, unless legitimate interest is demonstrated, Art. 14, Law 25.326), request rectification, updating, or deletion, request confidentiality or blocking in cases provided by law, and withdraw consent at any time without affecting the lawfulness of prior processing.

Timeframes. Quoryks AI responds to access requests within ten (10) calendar days and resolves rectification, updating, or deletion requests within five (5) business days (Arts. 14 and 16, Law 25.326).

How to exercise them. By writing to privacidad@quoryks.com, stating the right to be exercised and providing documentation to verify the requester's identity. Users may also edit their account data and delete documents or their Organization directly from the platform.

Requests concerning Client documents. When a request relates to data contained in documents or emails processed on behalf of a Client (Art. 2, subsections d, e, and g), Quoryks AI will refer it to the relevant Client within the stated timeframes and assist in responding.

Commercial communications. Any data subject may request removal or blocking of their data from the commercial contact database (Art. 27, Law 25.326). Every commercial communication includes an unsubscribe mechanism.

Supervisory authority. The Agency of Access to Public Information, supervisory body under Law 25.326, is empowered to handle complaints and claims regarding breach of personal data protection rules (Av. Pte. Julio A. Roca 710, 3rd floor, CABA; www.argentina.gob.ar/aaip).

Article 10 — Data Processor agreement

By contracting the service, creating an Organization, or using the platform, the Client, as Data Controller, accepts and automatically incorporates the Data Processing Agreement terms in Annex I, in compliance with Art. 25 of Law 25.326. Clients requiring a DPA signed in a separate instrument may request it at privacidad@quoryks.com.

Article 11 — Cookies, analytics, and local storage

11.1. In the application (app.quoryks.com). Only technical cookies and local storage are used: the session cookie, which keeps the User authenticated and expires on sign-out or inactivity, and interface preferences (sidebar, light/dark theme, panel layout), persisted in the browser. No advertising, profiling, or third-party analytics cookies are used within the application. As they are strictly necessary, they do not require prior consent; the User may delete them from the browser, with the sole consequence of needing to authenticate again.

11.2. On the website (quoryks.com). Google Analytics 4 is used, implemented via Google Tag Manager, solely to obtain visit and usage statistics for the site, its main pages and blog, and to measure the commercial funnel through sign-up and the Plan selected. Google Analytics places its own cookies (_ga and related) with a maximum duration of 13 months and transmits navigation data to Google LLC (United States) in accordance with Article 6(b). Data retention in Google Analytics is fourteen (14) months.

11.3. Management. Site visitors may reject analytics cookies through the site's cookie notice, configure their browser to block them, or use the Google Analytics opt-out add-on. Rejection does not affect use of the site or the application.

Article 12 — Effective date and amendments

This Policy is effective from September 17, 2026 and replaces all prior versions.

Quoryks AI may amend it to reflect changes in the service, its providers, or applicable law. Any amendment will be published at quoryks.com/privacy with the date of last update. When an amendment materially changes purposes, data categories, or subprocessors with access to documents, Users and Clients will be notified by email at least fifteen (15) days in advance.

Continued use of the platform after an amendment takes effect implies acknowledgment of the updated Policy, without prejudice to the data subject's right to withdraw consent under Article 9.

ANNEX I — Data Processing Agreement

By contracting the service, creating an Organization, or using the Quoryks AI platform, the Client, as Data Controller, fully adheres to these terms granted by LAB 9 S.A.S. as Data Processor, which form an integral part of the Privacy Policy and the Terms and Conditions.

Clause 1 — Purpose

To govern confidentiality, security, and processing of personal data contained in documents (invoices, vouchers, delivery notes, emails, and accounting documentation) that the Client uploads, sends by email, or submits via API to the platform for automated reading, extraction, and structuring, in compliance with Law No. 25.326 and Regulatory Decree No. 1558/2001.

Clause 2 — Obligations of LAB 9 S.A.S.

Process data and documents only in accordance with the Client's instructions derived from operation of the service and to provide the contracted SaaS function.

Not use the content of documents or the Client's personal data to train general-purpose or third-party artificial intelligence models. LAB 9 is authorized to use correction records solely in aggregated, anonymous, and dissociated form (Art. 2, Law 25.326) to calibrate confidence levels and optimize extraction algorithms, ensuring they cannot be used to reconstruct documents or identify individuals.

Maintain professional secrecy and confidentiality, an obligation that survives termination of the contractual relationship and extends to all its personnel and collaborators.

Not access document content except upon the Client's express request for support, limiting access to the specific case.

Not assign, transfer, or disclose data to third parties, except to authorized subprocessors in accordance with Clause 4.

Assist the Client, to a reasonable extent, in handling data subject requests and supervisory authority requirements relating to documents processed on its behalf.

Clause 3 — Security and incidents

LAB 9 will apply the measures described in Article 8 of the Privacy Policy. If a security incident affecting the confidentiality, integrity, or availability of the Client's data or documents is confirmed, LAB 9 will notify the Client without undue delay from detection within seventy-two (72) hours, providing reasonably available information (nature of the incident, affected data, measures taken) so the Client can assess and, where appropriate, report the matter to the AAIP.

Clause 4 — Subprocessors and international transfer

The Client grants LAB 9 general authorization to engage and replace subprocessors necessary for the service (hosting, storage, OCR and artificial intelligence, authentication, transactional email, and payments), whose updated list appears in Article 5 of the Privacy Policy. LAB 9 will notify the addition of new subprocessors with access to documents at least fifteen (15) days in advance.

The Client acknowledges and expressly authorizes international transfer of personal data and document images to servers located in the European Union and, where strictly necessary for field interpretation through language models, to providers located in the United States, under the conditions in Article 6 of the Privacy Policy. LAB 9 contracts its providers under enterprise terms that incorporate safeguards for international transfer (standard contractual clauses or other equivalent mechanisms) and that exclude retention and use of documents for training.

Clause 5 — Fate of data upon contract termination

Upon termination of the contractual relationship, documents, emails, and extracted data are retained under secure conditions for a maximum period of twenty-four (24) months (Art. 25(2), Law 25.326), solely to allow export by the Client or further instructions. After that period, they are permanently and irreversibly deleted, including backup copies.

The Client may request in writing, at any time, return (via export) or early destruction of all its data and files, in which case LAB 9 will act within no more than thirty (30) calendar days and, upon the Client's request, will certify deletion in writing.

Deletion of the Organization from the platform by the Owner constitutes a request for early destruction under the preceding paragraph.

Lab9 Agency

© 2026 LAB9 S.A.S. All rights reserved.

Document OCR Solutions

Automate your document management