Zymplo operates in 13 countries and complies with the data protection · invoicing · e-commerce and consumer regulations applicable in each jurisdiction.
1. Corporate structure
- Zymplo Inc. · Delaware USA · EIN 30-1486305 · DUNS 145007664
- Zymplo Brasil LTDA · CNPJ 66.667.634/0001-00 · Fortaleza CE · Brazil operating subsidiary
- Primary banking: Mercury Bank (USA)
- Payment processing: Stripe Atlas (USA) · Stripe Brasil (BR) · Mercado Pago (LATAM)
2. Compliance by country
| Country | Privacy | Tax / invoicing | Status |
| 🇧🇷 Brazil | LGPD (Lei 13.709/2018) · ANPD | Municipal NFS-e · MEI · DAS · CPF/CNPJ | OK |
| 🇲🇽 Mexico | LFPDPPP · INAI | RESICO · CFDI · RFC/CURP | OK |
| 🇺🇸 USA | CCPA (California) · COPPA · various state laws | EIN · Sole Prop · LLC · Sched-C | OK |
| 🇨🇴 Colombia | Law 1581 / 2012 · SIC | Régimen Simple (RST) · NIT/Cédula/RUT | OK |
| 🇪🇸 Spain | GDPR (EU) · LOPDGDD · AEPD | Autónomos (RETA) · NIF/NIE/DNI | OK |
| 🇦🇷 Argentina | Law 25.326 · AAIP | Monotributo (A-K) · DNI/CUIT | OK |
| 🇵🇾 Paraguay | Law 1682/01 · Law 6534/20 · MITIC | RIRE · RUC/Cédula · SET | OK |
| 🇵🇪 Peru | Law 29733 · ANPD-Peru | RUS / Nuevo RUS / MYPE · RUC/DNI · SUNAT | OK |
| 🇪🇨 Ecuador | Organic Law on Data Protection · SPDP | RIMPE Emprendedor · RUC/Cédula · SRI | OK |
| 🇨🇱 Chile | Law 19.628 · CPLT | Pro PyME / 14 ter · Chilean RUT · SII | OK |
| 🇺🇾 Uruguay | Law 18.331 · URCDP | Monotributo Social MIDES · RUT/Cédula · DGI | OK |
| 🇧🇴 Bolivia | Law 1928 · ATT | RTS Simplificado · NIT/Cédula · SIN | OK |
| 🇨🇷 Costa Rica | Law 8968 · PRODHAB | Simplified Taxation · Cédula Jurídica · MH | OK |
3. Subcontracted processors
We share data only with processors that have a signed DPA (Data Processing Agreement):
- Meta (WhatsApp Business API): messaging infrastructure · signed DPA.
- Anthropic / OpenAI / xAI: AI processing · signed DPAs · NO training on user data.
- Stripe / Mercado Pago: payment processors · PCI-DSS Level 1 compliant.
- Cloudflare · Oracle Cloud Infrastructure: hosting and CDN · ISO 27001 · SOC 2 Type II.
- Resend: transactional emails · GDPR-compliant.
4. International transfers
When data crosses borders (e.g. BR user → processor in the USA) we use:
- Standard Contractual Clauses (SCC) EU 2021/914 for European users.
- Equivalent model clauses for LATAM users.
- TLS 1.3 encryption in transit · AES-256 at rest.
5. Technical certifications
- Oracle Cloud Infrastructure hosting · ISO 27001 · SOC 2 Type II · PCI-DSS
- Cloudflare CDN · ISO 27001 · ISO 27018 · SOC 2 Type II
- Stripe payments · PCI-DSS Level 1
- SOC 2 Type II Zymplo · in progress (Q4 2026 target)
- ISO 27001 Zymplo · in progress (Q1 2027 target)
6. Data subject rights
In every country where we operate · users can:
- Access their data · request a copy
- Correct inaccurate data
- Delete their account and associated data (/en/legal/delete-account/)
- Portability · export in JSON
- Object to non-essential uses
- Withdraw consent without affecting prior processing
Exercise your rights: privacy@zymplo.com · we respond within the legal timeframes (15 days LGPD · 30 days GDPR).
7. Breach notification
In the event of a security incident affecting personal data:
- We notify the regulatory authority within the legal timeframe (72h LGPD/GDPR · 30 days depending on the country).
- We notify affected users via WhatsApp and email where applicable.
- We publish details at /security/ (when relevant).
8. Auditing and publications
- LGPD-compliant audit logs (R7 · R55) · minimum 5-year retention.
- Annual transparency report · published every March 31.
- Report on responses to authorities · published every June 30.
9. DPO and regulatory contact
- DPO contact: privacy@zymplo.com
- Legal counsel: legal@zymplo.com
- ANPD Brazil registration · UY URCDP · ES AEPD · etc · pending / complete depending on the country (inquire about specific cases)