← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Argentina Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Argentine resident covered by this Annex. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Ley 25.326 (the Ley de Protección de los Datos Personales, "PDPL"), (b) ratification of the pending Anteproyecto de Ley de Protección de los Datos Personales (the draft GDPR-aligned successor to Ley 25.326 that has been before the National Congress since 2022/2023; if ratified it will supersede Ley 25.326 and this Annex's § 2, § 6, and § 8 must be rewritten), (c) any Disposición of the Agencia de Acceso a la Información Pública ("AAIP") that materially alters the operational rules below, (d) any amendment to Ley 26.061 (Ley de Protección Integral de los Derechos de las Niñas, Niños y Adolescentes), (e) any amendment to Ley 26.388 (the Ley de Delitos Informáticos, which amended the Código Penal), (f) any amendment to Ley 24.240 (Ley de Defensa del Consumidor) or its implementing Resoluciones, (g) any decision of the Corte Suprema de Justicia de la Nación ("CSJN") that materially changes the PDPL's interpretation, (h) any change to the EU's adequacy finding in respect of Argentina (Commission Decision 2003/490/EC of 30 June 2003), or (i) any change to a sub-processor's Argentina data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Argentina-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Argentine resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Argentine resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The authoritative Spanish-language version is republished at Argentina annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Argentine residents.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Argentine Republic ("Argentina"), without distinction between the 23 provinces and the Ciudad Autónoma de Buenos Aires (CABA).

We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Argentina as the country of residence, this Annex applies, even if the other signals are non-Argentine. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

Ley 25.326 has extraterritorial effect under its Art 1 ("the present law has as its object the integral protection of personal data registered in archives, registers, databanks, or other technical means of data treatment, whether public or private destined to give reports, in order to guarantee the right to honour and to privacy of persons, as well as the access to information that may be recorded about them, in accordance with the provisions of Article 43, third paragraph, of the National Constitution"). The AAIP's interpretive practice is that the PDPL applies whenever the controller targets Argentine residents — Balance squarely targets Argentine residents through Google Play and through publication of this Annex at balance.babayagaprogram.com.


2. Statutory framework — what applies

The Argentine data-protection and online-safety regime sits at the intersection of one constitutional provision, one personal-data-protection statute (Ley 25.326), one child-protection statute (Ley 26.061), one consumer-protection statute (Ley 24.240), the Código Penal (as amended by the cybercrime Ley 26.388), and a series of AAIP Disposiciones (the binding administrative acts of the supervisory authority).

Instrument Short cite What it does Balance's posture
Constitución Nacional Argentina CN 1853-1994, Art 43 third paragraph (acción de habeas data) + Art 75-22 (constitutional rank of human-rights treaties, including the American Convention on Human Rights and the UN Convention on the Rights of the Child) The constitutional anchor for the personal-data-protection regime. Art 43 grants every person a constitutional action of habeas data to know any data about themselves recorded in public registers or in private databanks intended to supply reports, and, where appropriate, to demand the suppression, rectification, confidentiality, or updating of those data. Applies in full as the foundational constitutional layer. Treatment in §§ 3, 6, 7 below.
Ley 25.326 — Ley de Protección de los Datos Personales PDPL — Ley 25.326 of 4 October 2000, as amended; implemented by Decreto 1558/2001 The principal data-protection regime: definitions (Art 2); lawful bases for processing — consent + statutory exceptions (Arts 4 + 5); special-category data (Art 7); rights of access, rectification, suppression, and confidentiality (Arts 14–16); international transfers (Art 12); supervisory authority (Arts 29–30, as amended by Ley 27.275 Art 19); sanctions (Art 31); habeas data civil procedure (Arts 33–46). Applies in full. Treatment in §§ 3, 6, 7, 8, 9, 11, 13 below.
Decreto 1558/2001 PDPL implementing decree Operational rules for the PDPL, including the security measures, the registration of databanks, and the transfer-mechanism rules. Applies as the implementing rules layer on top of Ley 25.326.
Pending — Anteproyecto de Ley de Protección de los Datos Personales The GDPR-aligned PDPL successor — Mensaje del Poder Ejecutivo of 30 June 2022 + AAIP public-consultation rounds 2022–2024 + the parliamentary text under consideration at the National Congress as of the Effective date A comprehensive rewrite of Ley 25.326 with GDPR-aligned definitions (controller / processor / data subject), a fuller rights catalogue (rectification, deletion, restriction, portability, objection, automated-decision review), a DPIA obligation, a DPO obligation for high-risk controllers, and an updated transfer regime. NOT in force as of the Effective date. If and when the bill is enacted, this Annex's § 2 + § 6 + § 8 will be rewritten and the rewrite will trigger an off-cycle update. Balance is already operationally GDPR-aligned (cross-reference: EU / EEA annex § 6 + § 8), so the substantive posture below already anticipates the successor regime; the regulatory cite is the only thing that will change.
Disposición AAIP 47/2018 AAIP security-measures resolution Sets the Medidas de Seguridad Recomendadas para el Tratamiento y Conservación de los Datos Personales en Medios Informatizados, with three security levels (básico, medio, crítico) depending on the category of data processed. Applies to all controllers and processors under Ley 25.326. Balance processes children's data, which raises the security level to crítico under Disposición 47/2018 § 3. The technical-and-organisational measures table at our Records of Processing Activities (Article 30) § 7 satisfies the crítico standard.
Disposición AAIP 4/2019 AAIP children's-data resolution Sets the AAIP's interpretive criteria for the processing of children's and adolescents' personal data under Ley 25.326, read with Ley 26.061 and the constitutional best-interest principle. Implemented by Balance's Verifiable Parental Consent (VPC) mechanism in United States annex § 5 (the same VPC mechanism is engaged for Argentine residents — see § 7 below).
Disposición AAIP 60-E/2016 AAIP international-transfer resolution Sets the AAIP-approved Cláusulas Contractuales Tipo (Argentine SCCs) for international transfers to controllers / processors outside Argentina under Ley 25.326 Art 12, supplementing the EU-adequacy and other adequacy-finding paths. The AAIP SCCs are signed with each US sub-processor in respect of Argentine-resident data — see our international-transfer pack § 6.
Disposición AAIP 161/2023 AAIP incident-reporting guidance Sets the AAIP's published guidance on the notification of security incidents affecting personal data, including the form, content, and reasonable timeframe of notification. Implemented by the breach runbook in our breach-notification runbook § 9.
Ley 26.061 — Ley de Protección Integral de los Derechos de las Niñas, Niños y Adolescentes Lei 26.061 of 28 September 2005 The principal child-protection statute. Art 22 protects the dignity of children and adolescents in any kind of communication or public expression. Establishes the Sistema de Protección Integral de los Derechos de Niñas, Niños y Adolescentes. Creates the Defensor de los Derechos de las Niñas, Niños y Adolescentes and the Secretaría Nacional de Niñez, Adolescencia y Familia (SENAF). Applies in full to every Argentine kid covered by this Annex. Treatment in §§ 5, 7, 14 below.
Ley 26.388 — Ley de Delitos Informáticos Cybercrime statute — Ley 26.388 of 4 June 2008, amending the Código Penal Inserts Art 128 Código Penal (CSAM and child-grooming offences), Art 131 (online grooming — grooming — added by Ley 26.904 of 2013), Art 153 (correspondence violation), Art 153-bis (illicit access to data systems), Art 157-bis (unlawful disclosure of personal data registered in databanks). Applies. Cross-reference in Child Safety Standards § 8 (Argentina CSAE routes — to be added; see § 14 below).
Ley 26.904 Grooming statute — 13 November 2013 Inserted Art 131 Código Penal (online grooming of a minor with sexual intent). Applies. The protocol for cooperating with Argentine prosecutors on grooming matters is in § 14 below.
Ley 24.240 — Ley de Defensa del Consumidor Consumer protection — Ley 24.240 of 22 September 1993, as amended (notably by Ley 26.361 of 2008) The principal consumer-protection statute. Art 4 — information duty; Art 7 — offer; Art 8-bis — dignified treatment; Art 10-ter (added by Ley 26.361) — botón de arrepentimiento for distance contracts; Art 34 — revocación de la aceptación; Art 37 — abusive contract terms. Implementing instrument: Resolución SCT 424/2020 (the Reglamentación del Botón de Arrepentimiento y de Baja). Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below.
Resolución SCT 424/2020 Botón de Arrepentimiento y de BajaSecretaría de Comercio Interior (now within the Secretaría de Comercio) Mandatory implementation of the botón de arrepentimiento (10-day right-of-regret button) and the botón de baja (subscription-cancellation button) in every e-commerce site / digital service offered to Argentine consumers. Implemented by the in-app and Play Store subscription-cancellation flow per Subscription Terms § 20.
Ley 25.690 ISP content-filtering law — 2002 Requires Argentine ISPs to offer content-filtering products to subscribers to support parental controls. Not directly applicable to Balance, but underscores the Argentine legislator's policy commitment to parental-control architectures.
Ley 27.275 — Ley de Derecho de Acceso a la Información Pública Right-to-Information statute — 14 September 2016 Creates the AAIP (Art 19) as the single agency competent for both access-to-public-information matters and personal-data-protection matters. The PDPL's Dirección Nacional de Protección de Datos Personales (DNPDP) was absorbed into the AAIP. The AAIP is the supervisory authority for Ley 25.326. See § 3 below.
Convention 108 + Convention 108+ Convenio para la Protección de las Personas con respecto al Tratamiento Automatizado de Datos de Carácter Personal (Council of Europe ETS 108 of 28 January 1981) and its Protocolo Modificativo (CETS 223 of 18 May 2018). Argentina is a party to Convention 108 (ratified 2019) and has signed the modernised Convention 108+ (pending ratification). Argentina's accession to Convention 108 is one of the factors underpinning the EU's adequacy finding (Commission Decision 2003/490/EC). Treatment in § 8 below.
EU adequacy Commission Decision 2003/490/EC of 30 June 2003 on the adequate protection of personal data in Argentina The European Commission's adequacy decision in respect of Argentina, recognising Argentina as a destination that provides adequate protection within the meaning of GDPR Art 45. Relevant to the EU-AR leg of any user whose data crosses both jurisdictions, but does not by itself solve the AR-to-US leg, which is the principal transfer Balance has to address. Treatment in § 8 below.
AAIP Guías y Recomendaciones AAIP orientative guidance: Guía Orientativa para el Tratamiento de Datos Personales de Niñas, Niños y Adolescentes (current edition in force at the Effective date); Guía para Notificar Incidentes de Seguridad; Guía de Buenas Prácticas en Privacidad para el Desarrollo de Aplicaciones. AAIP Guías are non-binding but are followed by the AAIP in its supervisory and enforcement activity. Balance follows the AAIP Guías as a matter of policy.

(Any prospective Argentine Ley de Inteligencia Artificial and any AAIP Disposición directed at automated-processing or algorithmic-decision rules are intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Argentine regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. AAIP — supervisory authority

3.1 The AAIP as supervisory authority

The supervisory authority for Ley 25.326 is the Agencia de Acceso a la Información Pública ("AAIP"), an autonomous decentralised body within the Jefatura de Gabinete de Ministros, created by Ley 27.275 Art 19. The AAIP absorbed the former Dirección Nacional de Protección de Datos Personales (DNPDP) in 2017 and is now the single competent authority for both right-to-information and personal-data-protection matters.

Field Value
Name Agencia de Acceso a la Información Pública (AAIP)
Headquarters Av. Pte. Gral. Julio A. Roca 710, piso 3°, C1067 CABA, Argentina
General website https://www.argentina.gob.ar/aaip
Personal-data section https://www.argentina.gob.ar/aaip/datospersonales
Complaint / claim channel (Reclamos y Denuncias) https://www.argentina.gob.ar/aaip/datospersonales/reclama
Incident-notification channel Per Disposición AAIP 161/2023https://www.argentina.gob.ar/aaip/datospersonales/notificacion-incidentes
Email datospersonales@aaip.gob.ar (general); reclamos@aaip.gob.ar (complaints)
Phone +54 11 4811-9046
Director The Director of the AAIP is the head of the Agency, appointed under Ley 27.275 Arts 21–22, with a 5-year term, removable only on cause set out in Art 24.

The AAIP is the first-line forum for any PDPL-grounded complaint. An Argentine resident may petition the AAIP without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: ) and we will respond within the PDPL Arts 14–16 timelines (see § 6 below).

An Argentine resident may also pursue private remedies against Balance via the acción de habeas data (the constitutional action under CN Art 43 third paragraph, with the procedural rules in Ley 25.326 Arts 33–46), in the justicia federal (the federal courts) under the fuero contencioso-administrativo federal or the fuero civil federal as appropriate, or via the Ministerio Público Fiscal (Public Prosecutor's Office) where collective interests are engaged.

3.2 No mandatory DPO designation in Argentina at the Effective date

Ley 25.326, as in force at the Effective date, does not mandate the appointment of a Data Protection Officer (Delegado de Protección de Datos) for foreign controllers offering services to Argentine residents. The pending GDPR-aligned Anteproyecto introduces a DPO obligation for high-risk controllers; if and when the Anteproyecto is enacted, Balance will designate an Argentine DPO and re-publish this Annex.

In the interim, the single point of contact for Argentine residents is (named individual: ), with the AAIP as the supervisory authority and the justicia federal as the judicial forum.

3.3 Database registration

Ley 25.326 Art 21 requires the registration of personal-databanks in the Registro Nacional de Bases de Datos maintained by the AAIP. Disposición AAIP 6/2018 sets the operational rules for the registration. The AAIP's published practice is that foreign controllers without a permanent establishment in Argentina are not required to register their databases in the Registro Nacional; the obligation applies to controllers having a permanent establishment in Argentina (which Balance does not).

Should the AAIP's interpretive practice change, or should Balance ever establish a permanent presence in Argentina, the registration will be filed within the statutory window.


4. Lawful bases under Ley 25.326

Balance processes personal data of Argentine residents on the following Ley 25.326 lawful bases. The mapping below is the canonical Balance-side bridge between each processing purpose and the PDPL lawful basis. The full record is in our Records of Processing Activities (Article 30).

Processing purpose Lawful basis (Ley 25.326) Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) Art 5(2)(d) — data necessary to perform a juridical or contractual relationship in which the data subject is a party; supported by Art 5(1) — express and informed consent of the parent at sign-up H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data Art 5(1) — express and informed consent of the parent or legal guardian (under the parental-responsibility doctrine of Ley 26.061 + the constitutional best-interest principle); supported by Art 5(2)(c) — public-interest lawful processing where the controller is performing a duty by law (under Ley 26.061's prevention duty) § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts Art 5(2)(d) — contractual relationship; supported by Art 5(2)(a) — express renunciation of consent where the data are obtained from sources of unrestricted public access (not directly applicable but illustrative); the parent's consent at sign-up covers operational alerts H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access Art 5(2)(c) — performance of legitimate functions of the public administration / private entity under law (read with Disposición AAIP 47/2018 security obligations) H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations (PDPL Art 14–16 DSAR responses; Disposición AAIP 161/2023 breach notification; AAIP information requests; Ley 24.240 consumer-rights requests; Ley 26.061 cooperation duties; CSAE-report obligations) Art 5(2)(b) — the data are collected for the exercise of functions appropriate to the powers of the State; supported by Disposición-AAIP rules § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data Art 5(1) — express and informed consent of the parent § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data Art 5(2)(d) — contractual relationship for the subscription H4; Ley 24.240 overlay in § 16 below

Balance does not rely on Art 5(2)(a) (data from sources of unrestricted public access) as a lawful basis for any kid-side processing.


5. Ley 26.061 — children's rights overlay

Ley 26.061 is the principal Argentine child-protection statute. The principal Balance-side handshakes are:

5.1 Best-interest-of-the-child principle

Ley 26.061 Art 3 establishes the interés superior de la niña, niño y adolescente as the controlling principle for any action that concerns a child. The constitutional anchor is the American Convention on Human Rights Art 19 and the UN Convention on the Rights of the Child Art 3, both of which have constitutional rank under CN Art 75-22. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.

5.2 Dignity in communications (Art 22)

Ley 26.061 Art 22 protects the dignity of children and adolescents in any kind of communication or public expression. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).

5.3 No advertising directed at children — Ley 26.061 + AAIP Guía

Ley 26.061 does not contain an explicit federal prohibition of advertising directed at children, but the AAIP's Guía Orientativa para el Tratamiento de Datos Personales de Niñas, Niños y Adolescentes identifies advertising directed at children as a high-risk processing that requires a higher consent standard. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.4 Cooperation routes (federal + provincial)

Ley 26.061 establishes the Sistema de Protección Integral de los Derechos de Niñas, Niños y Adolescentes with three levels: federal (Secretaría Nacional de Niñez, Adolescencia y Familia — SENAF), provincial (each province's child-protection authority), and local. Balance cooperates with each level on incidents that involve Argentine kids — see § 14 below.


6. Ley 25.326 Articles 14–16 rights — the rights, the timeline, and how to exercise them

6.1 The rights catalogue

An Argentine resident has the following rights under Ley 25.326. The article-list mirrors Ley 25.326 as in force at the Effective date above.

Additional rights derived from PDPL reading + AAIP Guías + the pending Anteproyecto (the controller honors these on a voluntary best-effort basis pending statutory enactment): - Right to data portability — the Art 14 JSON export is portable to any other service that accepts JSON. - Right to object to processing for purposes outside the original purposes — honored at . - Right to withdraw consent — honored at the same channel. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. - Right to information about the recipients — honored; the canonical share-list is the sub-processor list at our sub-processor register + § 10 of this Annex. - Right to review automated decisions — Balance does not engage in solely automated decision-making affecting the data subject's interests. The earned-time ledger is deterministic and is reviewable by the parent at any time. - Right to file a complaint with the AAIP (PDPL Arts 14–16 + Ley 27.275 + AAIP procedural rules). - Right to compensation for damage — under the general Argentine tort regime (Código Civil y Comercial, Arts 1716 et seq.) read with Ley 25.326 Art 31.

6.2 Timeline

Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to file a complaint with the AAIP and to seek judicial habeas data redress.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (Decreto 1558/2001 Art 14). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of an Argentine DNI) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 No cost

The exercise of the Art 14 + Art 16 rights is free of charge (PDPL Art 19; Decreto 1558/2001 Art 19). A fee may only be charged where the data subject submits more than one request within a 6-month period without proving a legitimate interest in repeating the request.

6.5 Language

A request may be submitted in Spanish (preferred for Argentine residents) or in English.


7. Children's data — Ley 25.326 + Ley 26.061 + AAIP Disposición 4/2019

Ley 25.326 does not contain an explicit children-specific article equivalent to GDPR Art 8. The treatment of children's data is governed by:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Argentina

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Argentine resident's data leaves Argentina at the point of being uploaded to the Balance backend.

8.1 Transfer mechanism — Ley 25.326 Article 12

Ley 25.326 Art 12 prohibits the international transfer of personal data to countries that do not provide adequate protection, except where (i) the data subject has expressly consented to the transfer; or (ii) one of the carve-outs in Art 12(2) applies (medical assistance; bank or stock-exchange transfers; treaty obligations; international cooperation between intelligence services in the fight against terrorism or organised crime). Decreto 1558/2001 Art 12 + Disposición AAIP 60-E/2016 set the operational rules.

Balance relies on the following stack to satisfy Art 12:

8.2 EU adequacy is not the transfer tool for AR-to-US

Commission Decision 2003/490/EC declares Argentina an adequacy destination from the EU side. This decision governs the EU → AR leg, not the AR → US leg. For Argentine residents whose data is transferred to the US, the relevant tools are the Argentine SCCs and the supplementary measures in § 8.1 above; the EU adequacy decision is not relied upon for the AR → US leg.

8.3 Transfer mechanism — the AR-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan does not have an Argentine adequacy finding, the AR-KZ axis is covered by Argentine SCCs (Disposición 60-E/2016) signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.4 Article 12(2) carve-outs — not relied upon

Balance does not rely on the Art 12(2) carve-outs (medical assistance; bank/stock-exchange transfers; treaty obligations; international cooperation) as the basis for routine transfers — those carve-outs are reserved for case-by-case scenarios, not for routine flows.


9. Data residency for Argentine residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Argentine resident's data held in Argentina? No. Every Argentine resident's data is held in the United States. The Ley 25.326 Art 12 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via Argentine SCCs in the inverse arrangement in § 8.3.
Is there an Argentine establishment? No. Balance has no permanent establishment in Argentina.
Where is the supervisory authority? Argentina — Agencia de Acceso a la Información Pública (AAIP), Av. Pte. Gral. Julio A. Roca 710, piso 3°, C1067 CABA.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Argentina does not impose a comprehensive data-localisation mandate on parental-control services as of the Effective date.


10. Sub-processors touching Argentine resident data

Sub-processor Role Location of processing Argentine transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States Argentine SCCs (Disposición 60-E/2016) on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Argentine SCCs on file as part of the Google Cloud Data Processing Addendum; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Argentine SCCs on file as part of the Google Cloud Data Processing Addendum; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Argentine kid + parent devices United States Argentine SCCs as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Argentine SCCs as above.
Google LLC — Google Play Billing Processes subscription purchases United States Argentine SCCs as above; Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Argentine parent users United States Argentine SCCs on file.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + Disposición AAIP 47/2018 crítico security level. The full sub-processor list, with each row's DPA status and Argentine SCC execution date, is at our sub-processor register.


11. Breach notification — Disposición AAIP 161/2023

Ley 25.326 does not contain an explicit breach-notification article (the gap is one of the principal motivators for the pending Anteproyecto). The AAIP has filled the gap through Disposición AAIP 161/2023, which sets the published guidance on the notification of security incidents affecting personal data.

Audience Trigger Deadline Channel
AAIP A security incident affecting personal data that is reasonably likely to cause damage to data subjects. Without undue delay — Disposición 161/2023 § 5 anchors a 72-hour benchmark from the controller becoming aware, modelled on GDPR Art 33. The AAIP incident-notification portal at https://www.argentina.gob.ar/aaip/datospersonales/notificacion-incidentes, filed in Spanish by the Privacy Officer or by external Argentine counsel acting on the Privacy Officer's instructions.
Affected data subjects A breach likely to cause significant harm to data subjects (the AAIP's "high-risk" overlay analogue). "Without undue delay" — the AAIP's published guidance is in line with the 72-hour benchmark, with the controller's reasoned judgment as to the appropriate moment for the data-subject notification (which may legitimately be later than the AAIP notification where the data-subject notification depends on the fuller forensic picture). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected).
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). Línea 137 + Fiscalía Especializada en Cibercrimen + Ministerio Público Fiscal + (where applicable) ICMEC/INHOPE.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, AAIP notification within the 72-hour benchmark, affected-data-subject notification per the Disposición 161/2023 analysis.

11.1 Minimum content of the AAIP notification (Disposición 161/2023)

The AAIP notification states: - the nature of the personal data affected; - the categories and approximate number of data subjects involved; - the technical and security measures in place at the time of the incident; - the risks for the data subjects; - the measures adopted or proposed to mitigate the effects of the incident; - a Privacy Officer contact point (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering is produced by external Argentine counsel on filing.


12. Cookies and electronic direct marketing

Argentina does not have a specific ePrivacy / cookies statute. The AAIP's published guidance is that cookies are personal data within the meaning of PDPL Art 2 to the extent they identify an individual or render an individual identifiable; the lawful basis for setting cookies is the data subject's consent (PDPL Art 5(1)).

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent in the Spanish-language consent screen.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send electronic direct marketing to Argentine residents. The only email Balance sends to Argentine parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 24.240 + Resolución SCT 424/2020 require pre-existing consent and a one-click unsubscribe for any commercial communication; if Balance ever introduces a marketing channel, we will comply with both rules.


13. Lawful-access requests and the encryption posture

Argentine authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Argentina

An Argentine resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

An Argentine resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Agencia de Acceso a la Información Pública (AAIP) Ley 25.326 + AAIP Disposiciones Av. Pte. Gral. Julio A. Roca 710, piso 3°, C1067 CABA; https://www.argentina.gob.ar/aaip/datospersonales/reclama
Defensa del Consumidor — Secretaría de Comercio Interior / *Subsecretaría de Defensa del Consumidor Ley 24.240 consumer-protection https://www.argentina.gob.ar/produccion/defensadelconsumidor
Provincial / municipal Oficinas Municipales de Información al Consumidor (OMIC) Ley 24.240 — first-line forum for individual consumer complaints Per province / municipality.
Ministerio Público Fiscal (MPF) — UFECI + PROTEX Cybercrime + child-trafficking-and-exploitation + collective DP-grounded prosecutions https://www.mpf.gob.ar/
Defensor del Pueblo de la Nación Constitutional human-rights ombudsperson https://www.dpn.gob.ar/
Defensor de los Derechos de las Niñas, Niños y Adolescentes Child-rights complaints (Ley 26.061) https://www.defensorianna.gob.ar/
Justicia Federal / Provincial Acción de habeas data (PDPL Arts 33–46) + Ley 24.240 actions + ordinary civil and criminal Per jurisdiction

An Argentine resident may always first raise the matter with us at (DSAR; named individual: ). We will respond within the PDPL Art 14 ten-corrido-day window (for access requests) or the Art 16 five-hábil-day window (for rectification, updating, suppression, or confidentiality). Raising the matter with us first is not a precondition to complaining to the AAIP or to any other authority; the AAIP accepts complaints directly.


16. Consumer rights — the Ley 24.240 overlay

Ley 24.240 is the principal Argentine consumer-protection statute. Where the parent is acting as a consumidor within the meaning of Ley 24.240 Art 1, the following overlays apply to the subscription purchase flow and to the Terms of Service.

16.1 Pre-contract information (Ley 24.240 Art 4)

The parent is entitled to información cierta, clara y detallada on the essential characteristics of the service. Implemented in Subscription Terms § 5.

16.2 10-day right of regret — botón de arrepentimiento (Ley 24.240 Art 34 + Resolución SCT 424/2020)

Ley 24.240 Art 34 grants the consumer a 10-day right of regret for distance contracts, computed from the date of the contract or from the delivery of the product / first delivery of the service, whichever is later. Resolución SCT 424/2020 implements the botón de arrepentimiento as a mandatory user-interface element — a prominent button labelled "BOTÓN DE ARREPENTIMIENTO" that allows the consumer to exercise the right with a single click. Balance's subscription is concluded at a distance (in-app); the 10-day right of regret applies and is implemented in Subscription Terms § 20. The right of regret is honored regardless of whether the parent has used the service in the 10-day window — the parent is entitled to a full refund through the Google Play Billing refund route.

16.3 Botón de baja (Resolución SCT 424/2020)

Resolución SCT 424/2020 also mandates a botón de baja — a prominent button that allows the consumer to cancel a subscription with a single click, without the need for telephone calls or follow-up steps. Balance's subscription-cancellation flow is implemented via the Google Play subscriptions screen + the in-app "Cancel subscription" action (under the subscription settings); both routes satisfy the botón de baja requirement.

16.4 Abusive contract terms (Ley 24.240 Art 37)

Ley 24.240 Art 37 declares null any contract term that (i) deprives the consumer of rights, (ii) limits the supplier's liability for damages, (iii) imposes a reversal of the burden of proof to the consumer's detriment, or (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 37 risk.

16.5 Trato digno y equitativo (Ley 24.240 Art 8-bis)

Ley 24.240 Art 8-bis (added by Ley 26.361) requires suppliers to provide dignified and equitable treatment to consumers. Implemented in Balance's customer-support and DSAR-handling protocols.

16.6 Forum and choice of law

Ley 24.240 Art 36 grants the consumer the forum of the consumer's domicile in financial-credit cases; the general consumer-forum rule under the Código Procesal Civil y Comercial de la Nación operates on a similar consumer-protective basis. The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace Argentine law to the prejudice of the Argentine consumer are presumptively null under Ley 24.240 Art 37.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Argentina Country Annex.

← Back to Privacy Policy · Children's Privacy Notice