Balance — Uruguay Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Uruguayan resident covered by this Annex, and the Delegado de Protección de Datos designated under Ley 19.670 Art 40 + Decreto 64/020 Art 11 read with Ley 18.331. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Ley 18.331 — Ley de Protección de Datos Personales y Acción de Habeas Data (the "LPDP"), (b) any amendment to Decreto 414/009 (the original Reglamento of the LPDP) or to Decreto 64/020 de 17 de febrero de 2020 (the Reglamento del Capítulo II de la Ley 19.670 — operationalising the GDPR-aligned overlays of Ley 19.670 Arts 37–40), (c) any amendment to Ley 19.670 de 15 de octubre de 2018 (the Ley de Rendición de Cuentas whose Arts 37–40 modified the LPDP to introduce GDPR-aligned overlays: accountability principle; breach-notification obligation; mandatory Delegado de Protección de Datos (DPO) for specified controllers; explicit extraterritorial reach) or its successor, (d) any Resolución of the Unidad Reguladora y de Control de Datos Personales (URCDP) — particularly Resolución 1/2009, Resolución 1/2011, Resolución 6/2014, Resolución 1/2018 (international transfers), Resolución 1/2020 (breach notification operational rules), Resolución 35/2020 (DPO designation operational rules), Resolución 2/2021 (children's-data Recomendaciones), and any successor Resolución — that materially alters the operational rules below, (e) any amendment to Ley 17.823 de 7 de septiembre de 2004 (Código de la Niñez y la Adolescencia — "CNA"), (f) any amendment to Ley 17.815 de 6 de septiembre de 2004 (Violencia sexual comercial o no comercial cometida contra niños, adolescentes o incapaces — the principal CSAE-criminalisation statute), (g) any amendment to Ley 19.580 de 22 de diciembre de 2017 (Violencia hacia las mujeres basada en género) or to Ley 19.747 de 19 de abril de 2019 (trafficking in persons), (h) any amendment to Ley 17.250 de 11 de agosto de 2000 (Ley de Relaciones de Consumo — the LRC) or its Reglamento (Decreto 244/000) issued by the Área de Defensa del Consumidor of the Ministerio de Economía y Finanzas (MEF), (i) any Sentencia of the Suprema Corte de Justicia or of the Tribunal de lo Contencioso Administrativo that materially changes the interpretation of Constitución de la República Arts 7, 28, 72 (the constitutional anchors for personal-data protection) or of the acción de habeas data, (j) the European Commission rescinding or modifying the Uruguay EU adequacy decision (Decision 2012/484/EU of 21 August 2012) under GDPR Art 45 (the adequacy decision is in force at the Effective date), (k) any amendment to the Convention 108+ instrument in force for Uruguay (Council of Europe ETS 108 of 28 January 1981; ratified by Uruguay on 10 April 2013; CETS 223 Protocolo Modificativo of 18 May 2018 — Convention 108+ — ratified by Uruguay on 6 April 2022 and in force for Uruguay since 1 August 2022), or (l) any change to a sub-processor's Uruguay data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Uruguay row).
- Children's Privacy Notice § 14 (Country annexes — Uruguay row).
- Child Safety Standards § 13 (Country annexes — Uruguay row).
- Terms of Service § 19 (Uruguay consumer-protection carve-out under Ley 17.250).
- Subscription Terms § 20 (Uruguay consumer-rights overlay — Art 16 derecho de revocación 5-working-day right of revocation; LRC overlays).
- Data Retention & Deletion Policy § 14 (Uruguay URCDP complaint route).
- our breach-notification runbook § 9 (Uruguay breach-notification route via URCDP under Ley 19.670 + Decreto 64/020 — 72-hour benchmark).
- our international-transfer pack § 6 (Ley 18.331 Art 23 international-transfer treatment + EU adequacy + Convention 108+ overlays).
This Annex is the canonical Uruguay-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Uruguayan resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Uruguayan resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The authoritative Spanish-language version is republished at Uruguay annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Uruguayan residents.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Oriental Republic of Uruguay ("Uruguay"), without distinction between the 19 departamentos.
We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Uruguay as the country of residence, this Annex applies, even if the other signals are non-Uruguayan. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
Ley 18.331 has extraterritorial effect under its Art 3 read with Ley 19.670 Art 38 (which expanded the territorial scope to controllers established outside Uruguay that offer goods or services to data subjects located in Uruguay, or that monitor their behaviour to the extent that the behaviour takes place in Uruguay — the GDPR-Art-3(2)-aligned extension): the LPDP applies whenever the controller is established in Uruguay, whenever the processing is carried out by means in Uruguay, or whenever the controller, even without being established in Uruguay, targets Uruguayan residents. Balance squarely targets Uruguayan residents through Google Play and through publication of this Annex at balance.babayagaprogram.com.
2. Statutory framework — what applies
The Uruguayan data-protection and online-safety regime is the most GDPR-aligned framework in Latin America. Uruguay holds an EU adequacy decision since 2012 — one of only two LatAm jurisdictions (with Argentina) to hold one as of the Effective date. The regime sits at the intersection of the Constitución de la República, Ley 18.331 and its Reglamento (Decreto 414/009), the GDPR-aligned overlays in Ley 19.670 Arts 37–40 + Decreto 64/020, a body of Resoluciones issued by the URCDP, the Código de la Niñez y la Adolescencia (Ley 17.823), the Código Penal read with Ley 17.815 (the principal CSAE-criminalisation statute) and Ley 19.580 (gender-based violence), and Ley 17.250 (consumer protection).
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitución de la República 1967 | CN, as amended (current text 2004); Art 7 (right to be protected in life, honour, liberty, security, work, and property); Art 28 (papers of private individuals, their correspondence, telegraphic and telephonic communications are inviolable); Art 72 (the enumeration of rights, duties, and guarantees made by the Constitution does not exclude others inherent to the human person or derived from a republican form of government — the constitutional gateway to the personal-data-protection right, as confirmed by the Suprema Corte de Justicia in its data-protection line of jurisprudence). | The constitutional anchor for the personal-data-protection regime. The acción de habeas data is statutory (Ley 18.331 Arts 37–45) but is constitutionally grounded via Art 72. | Applies in full as the foundational constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Ley 18.331 — Ley de Protección de Datos Personales y Acción de Habeas Data | LPDP — Ley 18.331 of 11 August 2008 | The principal data-protection regime: definitions (Arts 4–6); principles — legality, veracity, purpose, prior consent, security, reservation, responsibility (Arts 5–10); lawful bases — Art 9 (consent) + Art 9 limitations to consent; special-category data — Arts 18–22; rights of the data subject — Arts 13–19 (information, access, rectification, update, inclusion, cancellation/suppression, recurso de habeas data); international transfers — Art 23; URCDP supervisory authority — Arts 31–35; Registro de Bases de Datos — Art 30; acción de habeas data (the judicial constitutional remedy) — Arts 37–45; sanctions — Art 36. | Applies in full. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. |
| Decreto 414/009 | Reglamento de la Ley 18.331 of 31 August 2009 | The original operational rules layer. | Applies in full as the original implementing layer. |
| Ley 19.670 — Ley de Rendición de Cuentas (Arts 37–40) | Ley 19.670 of 15 October 2018 — Arts 37 to 40 of the Rendición de Cuentas statute introduced GDPR-aligned overlays to the LPDP | Introduces: Art 37 — extended extraterritorial scope (GDPR-Art-3(2)-aligned); Art 38 — accountability principle (responsabilidad proactiva) — controllers must demonstrate compliance by maintaining records of processing, conducting DPIAs for high-risk processing, implementing data-protection-by-design and data-protection-by-default, and being able to demonstrate compliance on URCDP demand; Art 39 — breach-notification obligation — controllers must notify the URCDP without undue delay (72-hour benchmark per Decreto 64/020); Art 40 — mandatory designation of a Delegado de Protección de Datos (DPO equivalent) for (i) public entities; (ii) controllers whose core activities consist of large-scale processing of sensitive data; (iii) controllers whose core activities consist of large-scale, systematic monitoring of data subjects; (iv) controllers processing personal data of children's data as a core activity. | Applies in full. Balance's processing of children's data engages the Art 40 DPO-mandate (core-activity large-scale processing of children's data). is designated as the Delegado de Protección de Datos (DPO) — see § 3.2 below. The Art 38 accountability artefacts are at our Records of Processing Activities (Article 30) (records of processing) + our Data Protection Impact Assessment (DPIA). The Art 39 breach-notification mechanics are in our breach-notification runbook § 9 + § 11 below. |
| Decreto 64/020 | Reglamento del Capítulo II de la Ley 19.670 of 17 February 2020 | Operationalises the GDPR-aligned overlays of Ley 19.670 Arts 37–40: extraterritorial-scope operational rules (Art 2); accountability artefacts (Arts 3–6); DPIA criteria (Arts 7–9); breach-notification operational rules — 72 hours to the URCDP from the controller becoming aware (Art 10) + data-subject notification "sin dilación indebida" (without undue delay); DPO designation criteria, functions, qualifications, and contact-publication (Arts 11–14). | Applies in full as the GDPR-alignment operational layer. The 72-hour benchmark + the DPO designation + the DPIA mechanics are all directly engaged by Balance's processing. |
| URCDP Resoluciones | The URCDP's binding administrative acts. Principal Resoluciones in force at the Effective date include: Resolución 1/2009 (Listado de países con nivel adecuado de protección — Uruguay's adequacy list); Resolución 1/2011 (Procedimiento para el ejercicio de derechos); Resolución 6/2014 (Procedimiento de denuncias e inicio de oficio); Resolución 1/2018 (international transfers — contractual clauses model and BCRs); Resolución 1/2020 (breach-notification operational rules); Resolución 35/2020 (DPO designation operational rules); Resolución 2/2021 (Recomendaciones para el tratamiento de datos personales de niños, niñas y adolescentes) — the URCDP's children's-data guidance. | Sets the binding interpretive layer on the LPDP, Ley 19.670, and Decreto 64/020. | Applies. Balance's processing is operationalised consistently with the URCDP's Resoluciones. The URCDP's children's-data Recomendaciones (Resolución 2/2021) is the principal substantive interpretive instrument for § 7 below. |
| Ley 17.823 — Código de la Niñez y la Adolescencia | CNA — Ley 17.823 of 7 September 2004, as amended | The principal child-protection statute. Art 1 — definitions: a niño/niña is every human being under 13 years of age; an adolescente is every person between 13 and under 18 years of age. Art 6 — best-interest principle (interés superior del niño y del adolescente). Art 8 — capacity (a child or adolescent has all the inherent rights of a human person; the exercise of those rights is graduated by maturity). Art 9 — right to be heard (the child or adolescent has the right to be heard in matters that concern them, with their opinion considered in accordance with their maturity). Art 11 — right to intimidad (the right to private life and to the protection of honour and image). Art 28 — right to information (the child or adolescent has the right to receive information appropriate to their age and maturity). Establishes the Sistema Nacional de Protección Integral a la Infancia y la Adolescencia. The Instituto del Niño y Adolescente del Uruguay (INAU) is the principal cabinet-level child-welfare authority (status: servicio descentralizado; legal anchor: Ley 15.977 de 14 de septiembre de 1988 — INAU's organic law, as amended; replacing the former INAME). | Applies in full to every Uruguayan kid covered by this Annex. Treatment in §§ 5, 7, 14 below. |
| Ley 15.977 | Instituto del Niño y Adolescente del Uruguay (INAU) organic law of 14 September 1988, as amended | Establishes INAU as the principal cabinet-level child-welfare authority. | Applies as the institutional anchor for INAU. |
| Ley 17.815 — Violencia sexual comercial o no comercial cometida contra niños, adolescentes o incapaces | Ley 17.815 of 6 September 2004 | The principal CSAE-criminalisation statute. Art 1 — Producción y comercialización de material pornográfico con menores (production and commercialisation of CSAM). Art 2 — Comercio y difusión de material pornográfico con menores (commerce and distribution of CSAM). Art 3 — Facilitamiento de la comercialización y difusión de material pornográfico (facilitating the commercialisation or distribution of CSAM). Art 4 — Retribución o promesa de retribución a personas menores de edad o incapaces para realizar actos sexuales (paid sexual exploitation of minors). Art 5 — Contribución a la explotación sexual (facilitating CSAE). | Applies. Cross-reference in Child Safety Standards § 8 (Uruguay CSAE routes — see § 14 below). |
| Ley 19.580 — Violencia hacia las mujeres basada en género | Ley 19.580 of 22 December 2017 | Comprehensive statute on gender-based violence. Includes provisions on violence against children and adolescents. Strengthens the Sistema Interinstitucional de Respuesta a la Violencia Basada en Género. | Applies. Cross-reference in Child Safety Standards § 5 + § 8. |
| Ley 19.747 | Trata de personas of 19 April 2019 | Strengthens trafficking-in-persons provisions, particularly in respect of children and adolescents. | Applies. Cross-reference in Child Safety Standards § 8. |
| Código Penal — Ley 9.155 | Código Penal of 4 December 1933, as amended | The Uruguayan criminal-law backbone. Relevant articles for personal-data protection and CSAE: Art 296 bis (illicit access to computer systems) + complementary cybercrime articles inserted by successive legislative amendments. CSAM-specific offences are in Ley 17.815 (see above). | Applies. Cross-reference in Child Safety Standards § 8. |
| Ley 17.250 — Ley de Relaciones de Consumo | LRC — Ley 17.250 of 11 August 2000, as amended | The principal consumer-protection statute. Art 13 (information); Art 16 (derecho de revocación — 5-working-day right of revocation for door-to-door and distance contracts); Art 30 (advertising); Art 41 (abusive contract terms); Art 51 (collective interests). Implementing decree: Decreto 244/000 of 23 August 2000. The Uruguayan supervisory authority is the Área de Defensa del Consumidor of the Ministerio de Economía y Finanzas (MEF). | Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below. |
| Ley 17.948 | Adecuación de la normativa al Convenio 108 del Consejo de Europa of 8 January 2006 | Adjusts Uruguayan law to the Council of Europe Convention 108 requirements. Relevant context for the LPDP's design. | Applies as context. |
| EU adequacy | Commission Implementing Decision 2012/484/EU of 21 August 2012 — Adecuada protección de datos personales por la República Oriental del Uruguay | The European Commission's adequacy decision in respect of Uruguay under GDPR Art 45 — in force at the Effective date. Uruguay is one of only two LatAm jurisdictions (with Argentina) to hold an EU adequacy decision; the decision recognises that the level of protection of personal data ensured by Uruguay is essentially equivalent to the level guaranteed within the EU under the GDPR. | Applies in full. The Uruguay EU adequacy decision allows the bidirectional flow of personal data with the EU/EEA without supplementary transfer instruments. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to Uruguay under the 2012/484/EU adequacy decision. Treatment for the UY-to-US leg in § 8 below. |
| Convention 108 + Convention 108+ | Council of Europe ETS 108 of 28 January 1981 + Protocol CETS 223 of 18 May 2018 (Convention 108+) | Uruguay acceded to Convention 108 on 10 April 2013 (in force for Uruguay from 1 August 2013) — the first LatAm country to accede. Uruguay ratified Convention 108+ on 6 April 2022 (in force for Uruguay from 1 August 2022). | Convention 108+ is in force for Uruguay at the Effective date. Treatment in § 8 below. |
| Ley 19.696 (CPP) | Código del Proceso Penal of 29 December 2014, in force from 1 November 2017 | The Uruguayan criminal-procedure code. Sets the procedural rules for criminal investigations, including intercept and search-and-seizure procedures. | Applies. Treatment in § 13 below. |
| Ley 19.293 (CPP-related) | Código General del Proceso + Ley 19.293 de 2014 | Sets general civil-procedure rules. | Applies. |
| URCDP Concepts and Guidance Notes | Principal Concepts — the URCDP's published interpretive notes on key questions of LPDP interpretation; the URCDP's Recomendaciones para el tratamiento de datos personales de niños, niñas y adolescentes (Resolución 2/2021); the Guía para el cumplimiento del principio de responsabilidad proactiva; the Guía para la realización de Evaluaciones de Impacto en la Protección de Datos. | Sets the URCDP's published interpretive practice. | Applies. |
(Any prospective Uruguayan regulation governing automated processing, algorithmic decisions, or related techniques — including any URCDP Resolución or AGESIC Recomendación in that area and any Congressional proyecto de ley on such topics — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Uruguayan regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. URCDP — Supervisory authority
3.1 The URCDP as supervisory authority
The supervisory authority for the LPDP is the Unidad Reguladora y de Control de Datos Personales ("URCDP"), established by Ley 18.331 Art 31 and operating with functional autonomy within the AGESIC (Agencia para el Desarrollo del Gobierno de Gestión Electrónica y la Sociedad de la Información y del Conocimiento) — the Uruguayan e-government and information-society agency, established by Ley 17.930 Art 72 (de 2005) and Ley 18.172 Art 54 (de 2007). The URCDP exercises regulatory, supervisory, enforcement, and sanctioning powers in respect of personal-data processing in Uruguay. The URCDP is one of the most operationally mature LatAm DPAs and is the principal driver of Uruguay's EU-adequacy posture.
| Field | Value |
|---|---|
| Name | Unidad Reguladora y de Control de Datos Personales (URCDP) — within AGESIC |
| Headquarters | Liniers 1324, piso 4, Torre Ejecutiva Sur, Edificio Libertador, CP 11.100, Montevideo, Uruguay |
| General website | https://www.gub.uy/unidad-reguladora-control-datos-personales/ |
| Complaint / claim channel (Denuncias y reclamos) | URCDP intake at https://www.gub.uy/unidad-reguladora-control-datos-personales/comunicacion/inicios-tramites |
| Incident-notification channel | URCDP online incident-notification form per Resolución 1/2020 and Decreto 64/020 Art 10 |
| Registro de Bases de Datos | URCDP online registry under Ley 18.331 Art 30 — https://www.gub.uy/unidad-reguladora-control-datos-personales/ (the Registro is mandatory for in-scope controllers; foreign controllers without local establishment fall outside the registration scope per URCDP interpretive practice) |
urcdp@datospersonales.gub.uy (general intake); legal communications at the institutional inbox published at the gub.uy page |
|
| Phone | +598 2901 2929 (URCDP / AGESIC central line) |
| Director Ejecutivo / Consejo Ejecutivo | The URCDP is governed by a Consejo Ejecutivo of 3 members (URCDP director + AGESIC director + an additional member designated by the Executive Branch — Ley 18.331 Art 32); the day-to-day direction is led by the URCDP Director Ejecutivo (currently the Ing. Federico Monteverde or successor as published at the gub.uy page). |
The URCDP is the first-line forum for any LPDP-grounded complaint. A Uruguayan resident may petition the URCDP without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the Delegado de Protección de Datos of Balance) and we will respond within the LPDP timelines (see § 6 below).
A Uruguayan resident may also pursue private remedies against Balance via the acción de habeas data (Ley 18.331 Arts 37–45 — the judicial constitutional remedy), administered by the Juzgados Letrados de Primera Instancia en lo Civil (in Montevideo, the Juzgados Letrados de lo Contencioso Administrativo) with appeal to the Tribunales de Apelaciones en lo Civil; via the ordinary civil courts; or via the Ministerio Público — Fiscalías Especializadas en Crimen Organizado, en Estupefacientes, en Delitos Sexuales, Violencia Doméstica y Violencia Basada en Género, and the División de Delitos Informáticos of the Ministerio del Interior, where criminal offences are engaged.
3.2 The Delegado de Protección de Datos (DPO)
Ley 19.670 Art 40 + Decreto 64/020 Arts 11–14 require the designation, by specified controllers, of a Delegado de Protección de Datos ("DPO"). The DPO must be designated by every controller that (a) is a public entity; (b) carries out as a core activity the large-scale processing of sensitive data; (c) carries out as a core activity the large-scale, systematic monitoring of data subjects; or (d) carries out as a core activity the processing of personal data of children and adolescents.
Balance's core activity is the processing of personal data of children and adolescents and accordingly engages the (d) trigger. The Balance DPO is:
- , Director, BabaYaga Program, TOO —
.
The DPO's functions per Decreto 64/020 Art 13 are: (a) inform and advise the controller and its personnel on LPDP, Ley 19.670, Decreto 64/020, and URCDP Resoluciones; (b) monitor compliance with the LPDP, Ley 19.670, Decreto 64/020, the controller's internal data-protection policies, and the URCDP Resoluciones; (c) advise on DPIAs per Decreto 64/020 Arts 7–9; (d) cooperate with the URCDP in any supervisory or investigation activity; (e) act as the contact point for data subjects on rights-exercise matters and for the URCDP on regulatory matters; (f) lead the children's-data treatment under the URCDP's Recomendaciones (Resolución 2/2021).
The DPO designation is published in this Annex (see top), in the global Privacy Policy (Privacy Policy § 1), and is notified to the URCDP per Decreto 64/020 Art 11.
3.3 Registro de Bases de Datos — non-registration position
Ley 18.331 Art 30 + Decreto 414/009 require certain controllers to register their personal-databanks (bases de datos personales) in the Registro de Bases de Datos maintained by the URCDP. The URCDP's published interpretive practice is that foreign controllers without a permanent establishment in Uruguay are not required to register their databanks in the Registro; the obligation applies to controllers having a permanent establishment in Uruguay (which Balance does not).
Should the URCDP's interpretive practice change, or should Balance ever establish a permanent presence in Uruguay, the registration will be filed within the statutory window prescribed by the URCDP's Registro rules.
4. Lawful bases under the LPDP
Balance processes personal data of Uruguayan residents on the following LPDP lawful bases. The mapping below is the canonical Balance-side bridge between each processing purpose and the LPDP lawful basis. The full record is in our Records of Processing Activities (Article 30).
| Processing purpose | Lawful basis (Ley 18.331 + Decreto 414/009 + Ley 19.670 + Decreto 64/020) | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | Ley 18.331 Art 9 — express, prior, free, and informed consent of the data subject (here, the parent at sign-up); supplemented by Art 9 limitations to consent — processing necessary for the performance of a contractual relationship between the data subject and the controller | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | Ley 18.331 Art 11 read with Ley 17.823 Arts 6 + 11 (CNA best-interest + intimacy) and the URCDP's Resolución 2/2021 Recomendaciones para el tratamiento de datos personales de niños, niñas y adolescentes; supplemented by Ley 18.331 Art 9 as applied to the parent under the patria potestad doctrine of the Código Civil Arts 252 et seq. | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | Ley 18.331 Art 9 — express consent + limitations to consent (contractual relationship) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | Ley 18.331 Art 10 (security principle) — the controller's duty to adopt the technical and organisational measures necessary to safeguard the security of the data; supplemented by the controller's legitimate-interest reading under Ley 19.670 Art 38 responsabilidad proactiva | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations (LPDP Arts 13–19 DSAR responses; Decreto 64/020 Art 10 breach notification; URCDP information requests; MEF Área de Defensa del Consumidor information requests; CNA cooperation duties; CSAE-report obligations under Ley 17.815 + Ley 19.580) | Ley 18.331 Art 9 limitations to consent — processing required by a legal or contractual provision | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | Ley 18.331 Art 9 + Art 11 — express, prior, free, and informed consent of the parent under the CNA Art 6 best-interest principle + the patria potestad doctrine | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | Ley 18.331 Art 9 limitations to consent — necessary for the performance of the subscription contract | H4; Ley 17.250 LRC overlay in § 16 below |
Balance does not rely on the "public-source data" carve-out (Ley 18.331 Art 9 limitations to consent — data accessible from sources of public access) as a lawful basis for any kid-side processing.
5. CNA — children's rights overlay
Ley 17.823 (the Código de la Niñez y la Adolescencia, "CNA") is the principal Uruguayan child-protection framework. The principal Balance-side handshakes are:
5.1 Definitions (CNA Art 1)
Under CNA Art 1, a child (niño/niña) is every human being under 13 years of age; an adolescent (adolescente) is every person between 13 and under 18 years of age. The constitutional anchor is CN Art 72 (read with Art 7) + the UN Convention on the Rights of the Child, internalised in domestic Uruguayan law via Ley 16.137 de 28 de septiembre de 1990.
5.2 Best-interest principle (CNA Art 6)
CNA Art 6 establishes the interés superior del niño y del adolescente as the controlling principle for any decision that concerns a child. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.
5.3 Capacity (CNA Art 8) + Right to be heard (CNA Art 9)
CNA Art 8 codifies that children and adolescents have all the inherent rights of a human person, with the exercise of those rights graduated by maturity. CNA Art 9 codifies the kid's right to be heard in any matter that concerns them, with their opinion considered in accordance with their maturity. Balance's architectural posture preserves both principles: the kid app's UI is designed for the kid; the kid sees their own limits, schedules, tasks, and earned-time ledger in their own kid-app UI; the kid can request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision.
5.4 Right to intimidad (CNA Art 11)
CNA Art 11 protects the intimidad of children and adolescents — their right to private life, family life, correspondence, communications, honour, and image. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).
5.5 Right to information (CNA Art 28)
CNA Art 28 codifies the kid's right to information appropriate to their age and maturity. Balance's age-appropriate kid-app UI satisfies the obligation.
5.6 No advertising directed at children — Ley 17.250 Art 30 + URCDP Recomendaciones
Ley 17.250 Art 30 prohibits deceptive advertising and the use of techniques that exploit the credulity of minors. The URCDP's Recomendaciones para el tratamiento de datos personales de niños, niñas y adolescentes (Resolución 2/2021) further restrict the use of children's data for advertising or commercial purposes. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.7 Cooperation routes (INAU + Sistema Nacional)
The principal Uruguayan child-protection bodies are: (i) INAU — Instituto del Niño y Adolescente del Uruguay — the principal cabinet-level child-welfare authority (Ley 15.977); (ii) INAU — Línea Azul 0800 5050 — the national 24-hour child-protection line; (iii) Sistema Integral de Protección a la Infancia y Adolescencia contra la Violencia (SIPIAV) — the cross-government child-protection-against-violence coordination system; (iv) Institución Nacional de Derechos Humanos y Defensoría del Pueblo (INDDHH) — the constitutional human-rights ombudsperson under Ley 18.446 de 24 de diciembre de 2008 — Adjuntía para los Derechos de los Niños, Niñas y Adolescentes; (v) Ministerio del Interior — Dirección General de la Lucha contra el Crimen Organizado e INTERPOL — División de Delitos Informáticos. Balance cooperates with each on incidents that involve Uruguayan kids — see § 14 below.
6. LPDP Arts 13–19 + Ley 19.670 — the rights, the timeline, and how to exercise them
6.1 The rights catalogue
A Uruguayan resident has the following rights under the LPDP. The article-list mirrors LPDP Arts 13–19 + Ley 19.670 + Decreto 64/020 as in force at the Effective date.
- Ley 18.331 Art 13 — Right to information. The right to be informed, at the time of collection, of (i) the existence of the personal-databank; (ii) the identity of the controller and the DPO; (iii) the purposes of the processing; (iv) the recipients of the data; (v) the existence of cross-border transfers; (vi) the data subject's rights and how to exercise them; (vii) the consequences of not providing the data. Satisfied by the global Privacy Policy + this Annex + the in-app consent screen.
- Ley 18.331 Art 14 — Right of access. The right to obtain confirmation that personal data are being processed and to receive the data, the purposes, the categories of data, the recipients, and the cross-border transfers. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a Spanish plain-language summary. - Ley 18.331 Art 15 — Right to rectification, update, and inclusion. The right to require the controller to correct inaccurate data, to update outdated data, or to include omitted data. Honored in-app at Settings → Account → Edit and at
. - Ley 18.331 Art 15 — Right to cancellation (supresión). The right to require the controller to delete personal data where the data are no longer necessary for the purposes for which they were collected, where the data subject withdraws consent, or where the data are processed contrary to the law. Honored at Settings → "Delete my account" / "Delete this kid"; at Delete-account page; or at
. Cascade per Data Retention & Deletion Policy § 7. - Ley 18.331 Art 17 — Right to oppose / withdraw consent. The right to withdraw consent and the right to oppose the processing where the lawful basis is something other than the data subject's express consent. Honored at the same channels.
- Ley 19.670 Art 38 (read with Decreto 64/020) — Right to portability (implicit, through accountability). The Art 14 access right is operationalised in a portable format (machine-readable JSON), satisfying the GDPR-Art-20-aligned portability expectation that flows from the EU-adequacy framework. Honored at the same channels.
- Ley 18.331 Arts 37–45 — Acción de habeas data. The judicial constitutional remedy. Where the controller fails to honor the rights at Arts 14–17 or where the data subject has not received a timely or satisfactory response, the data subject may file an acción de habeas data before the Juzgado Letrado de Primera Instancia en lo Civil with jurisdiction (in Montevideo, the Juzgado Letrado de lo Contencioso Administrativo). The procedure is summary and the court is required to act with celerity. Appeal to the Tribunal de Apelaciones en lo Civil. The acción de habeas data is the principal fast-track judicial remedy.
- URCDP complaint. The data subject may file a complaint directly with the URCDP under the Resolución 6/2014 complaint procedure. The URCDP procedure runs in parallel with (and does not displace) the acción de habeas data.
6.2 Timeline
- Information (Art 13): discharged at the time of collection.
- Access (Art 14): the controller must respond within 5 working days of the request (LPDP Art 14 + URCDP Resolución 1/2011). Where the request is for rectification or cancellation, the controller must execute the change within the same window.
- Rectification / cancellation / opposition (Arts 15 + 17): the controller must respond within 5 working days of the request (LPDP + URCDP Resolución 1/2011).
- URCDP complaint procedure: the URCDP processes complaints on its own administrative timeline per Resolución 6/2014.
- Acción de habeas data (Arts 37–45): the procedure is summary; the court is required to act with celerity. First-instance resolution typically within weeks.
Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to file a complaint with the URCDP and to seek habeas data redress.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of the Uruguayan Cédula de Identidad) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.
6.4 No cost
The exercise of the LPDP Arts 14–17 rights is free of charge for the first request in any 6-month period.
6.5 Language
A request may be submitted in Spanish (preferred for Uruguayan residents) or in English.
7. Children's data — LPDP Art 11 + CNA + URCDP Recomendaciones (Resolución 2/2021)
Ley 18.331 Art 11 does not contain a fully-developed children-specific article equivalent to GDPR Art 8. The children's-data regime is built up from (i) Ley 18.331 Art 9 consent (applied to the parent under the patria potestad doctrine of the Código Civil Arts 252 et seq.); (ii) CNA Arts 6 + 11 + 28 (best interest + intimacy + age-appropriate information); (iii) URCDP Resolución 2/2021 — the URCDP's Recomendaciones para el tratamiento de datos personales de niños, niñas y adolescentes — which provides the principal substantive interpretive instrument for processing children's data in Uruguay.
The URCDP Recomendaciones (Resolución 2/2021) establish that: - Processing of children's and adolescents' personal data must be based on the express consent of the holder of parental responsibility, except in residual scenarios authorised by law. - The processing must respect the child's interés superior, intimidad, right to be heard, and right to information appropriate to age. - The privacy notice for children's data must be drafted in age-appropriate language. - The controller must implement enhanced security and confidentiality measures for children's data. - The processing must be subject to a DPIA where it presents a high risk to the rights and freedoms of the child. - The controller must designate a DPO where children's data is a core processing activity (engaging Ley 19.670 Art 40(d)).
For Balance:
- Children (under 13) and adolescents (13–17). Processing requires the express, prior, free, and informed consent of the parent or legal guardian. Balance obtains this via the VPC mechanism in United States annex § 5 (the same VPC mechanism is engaged for Uruguayan residents): email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device, accompanied by a Spanish-language Verifiable Parental Consent screen that itemises the categories of data being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights (cross-reference: LPDP Art 13 + URCDP Resolución 2/2021).
- No kid-self-serve consent path. Balance's architectural posture is identical regardless of the kid's age — the parent always consents on behalf of the kid; there is no kid-self-serve consent path inside Balance. This is the most-protective reading of CN Art 72 + CNA Arts 6 + 8 + 9 + 11 + 28 + Ley 18.331 Arts 9 + 11 + URCDP Resolución 2/2021 + the Código Civil patria potestad doctrine.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Uruguay
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Uruguayan resident's data leaves Uruguay at the point of being uploaded to the Balance backend.
8.1 The UY-to-US transfer mechanism — Ley 18.331 Art 23
Ley 18.331 Art 23 prohibits the transfer of personal data to countries that do not provide an adequate level of protection, except where (a) the data subject has given express and unequivocal consent; (b) one of the statutory carve-outs applies (judicial cooperation; medical assistance; international cooperation; treaty obligations; performance of a contract between the data subject and the controller; etc.); (c) the destination provides an adequate level of protection per URCDP Resolución 1/2009 (adequacy list); or (d) the controller has executed appropriate safeguards (contractual clauses replicating the URCDP-published model under Resolución 1/2018; Binding Corporate Rules approved by the URCDP).
The URCDP adequacy list (Resolución 1/2009 as amended) does NOT include the United States as of the Effective date. (The URCDP adequacy list includes EU/EEA member states, the United Kingdom, Andorra, Argentina, Canada (PIPEDA scope), Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, Switzerland, and Convention 108+ ratifying states meeting the URCDP's quality criteria — but not the United States.)
Balance relies on the following stack to satisfy Art 23 for the UY → US transfer:
- Express and unequivocal consent of the parent (Ley 18.331 Art 23 first paragraph + Art 9). The parent's sign-up consent prominently discloses the international transfer (cross-reference: Privacy Policy § 12 + the in-app Spanish-language consent screen, which itemises the country of destination — the United States — and the categories of recipients).
- Contract-performance carve-out (Ley 18.331 Art 23 + Art 9 limitations to consent). The transfer is necessary for the performance of the subscription contract between the parent and Balance and for the delivery of the parental-control service the parent contracted for.
- Contractual clauses replicating the URCDP-published model (URCDP Resolución 1/2018). Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor DPA that incorporates contractual clauses replicating the URCDP-published model. The full transfer pack is in our international-transfer pack § 6. The contractual clauses are reinforced by the EU SCC substance as the substantive overlay (the EU SCCs already cover each sub-processor's EU/EEA-bound flows).
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's DPA forbids onward transfer of Uruguayan-resident data to a third country outside the Art 23 framework without the controller's prior written authorisation.
8.2 The EU-to-UY axis (incoming transfers) — EU adequacy decision
The European Commission's Implementing Decision 2012/484/EU of 21 August 2012 finds that Uruguay provides an adequate level of protection for personal data. The decision allows the bidirectional flow of personal data between the EU/EEA and Uruguay without the need for supplementary transfer instruments. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to Uruguay under the 2012/484/EU adequacy decision.
For Balance, the EU adequacy is relevant only in respect of any EU/EEA-resident data that transits through (or is processed in) Uruguay — which is not part of Balance's current data-flow architecture (Balance's backend is in the United States, not in Uruguay). The EU adequacy is therefore a context-setting fact, not a transfer mechanism for the Balance flows.
8.3 Convention 108+ overlay
Convention 108+ (Council of Europe CETS 223 + ETS 108) is in force for Uruguay since 1 August 2022. Convention 108+ Art 14 provides a transfer mechanism (transfers may be made to non-Convention-108+ jurisdictions only where the destination provides an appropriate level of protection or the controller has put in place appropriate safeguards). Balance's transfer mechanism in § 8.1 above satisfies Convention 108+ Art 14 via the contractual safeguards.
8.4 Transfer mechanism — the UY-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the URCDP adequacy list, the UY-KZ axis is covered by contractual clauses replicating the URCDP-published model (Resolución 1/2018) signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
9. Data residency for Uruguayan residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Uruguayan resident's data held in Uruguay? | No. Every Uruguayan resident's data is held in the United States. The Ley 18.331 Art 23 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via URCDP-model contractual clauses in the inverse arrangement in § 8.4. |
| Is there a Uruguayan establishment? | No. Balance has no permanent establishment in Uruguay. |
| Where is the supervisory authority? | Uruguay — Unidad Reguladora y de Control de Datos Personales (URCDP), Liniers 1324, piso 4, Torre Ejecutiva Sur, CP 11.100, Montevideo. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Uruguay does not impose a comprehensive data-localisation mandate on parental-control services as of the Effective date.
10. Sub-processors touching Uruguayan resident data
| Sub-processor | Role | Location of processing | Uruguayan transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Parent's express consent (Ley 18.331 Art 23) + contract-performance carve-out + URCDP-model contractual clauses (Resolución 1/2018) on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Parent's express consent + URCDP-model contractual clauses on file as part of the Google Cloud Data Processing Addendum; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Parent's express consent + URCDP-model contractual clauses on file as part of the Google Cloud Data Processing Addendum; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Uruguayan kid + parent devices | United States | Parent's express consent + URCDP-model contractual clauses as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Parent's express consent + URCDP-model contractual clauses as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Parent's express consent + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Uruguayan parent users | United States | Parent's express consent + URCDP-model contractual clauses on file. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + Ley 18.331 Art 10 + Decreto 64/020 security duties. The full sub-processor list, with each row's DPA status and contractual-clause execution date, is at our sub-processor register.
11. Breach notification — Ley 19.670 Art 39 + Decreto 64/020 Art 10
Ley 19.670 Art 39 + Decreto 64/020 Art 10 + URCDP Resolución 1/2020 establish a GDPR-Art-33/34-aligned breach-notification regime:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| URCDP | A security incident affecting personal data that is reasonably likely to cause damage to data subjects. | Within 72 hours of the controller becoming aware (Decreto 64/020 Art 10). Where the controller cannot provide all the elements within 72 hours, the notification is filed initially and supplemented as the forensic picture develops. | URCDP online incident-notification form per Resolución 1/2020 and the URCDP intake page; filed in Spanish by the DPO or by external Uruguayan counsel acting on the DPO's instructions. |
| Affected data subjects | A breach likely to result in a high risk to the rights and freedoms of natural persons. | "Without undue delay" (Decreto 64/020 Art 10 — sin dilación indebida). | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected). |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | Línea Azul 0800 5050 (INAU) + Ministerio del Interior División de Delitos Informáticos + Fiscalía Especializada en Crimen Organizado + INDDHH Adjuntía Niñez. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, URCDP notification within the 72-hour benchmark, affected-data-subject notification without undue delay per the Decreto 64/020 Art 10 harm-likelihood analysis.
11.1 Minimum content of the URCDP notification (Decreto 64/020 + Resolución 1/2020)
The URCDP notification states:
- the nature of the personal data affected;
- the categories and approximate number of data subjects involved;
- the technical and security measures in place at the time of the incident;
- the risks for the data subjects;
- the measures adopted or proposed to mitigate the effects of the incident;
- the DPO contact point (, named individual: ).
The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering is produced by external Uruguayan counsel on filing.
12. Cookies and electronic direct marketing
Uruguay does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) Ley 18.331 Art 9 consent as the lawful basis for any cookie that processes personal data; (ii) Ley 19.670 Art 38 responsabilidad proactiva (accountability) — the controller must demonstrate compliance with the consent principle by implementing data-protection-by-design and data-protection-by-default; (iii) the URCDP's published interpretive practice on cookies — Concepto notes and the Guía para el cumplimiento del principio de responsabilidad proactiva; (iv) Ley 17.250 (LRC) provisions on pre-contract information, deceptive advertising (Art 24), and abusive terms (Art 30); (v) Art 9 limitations to consent (anti-spam reading) — direct marketing by electronic means requires the recipient's prior consent.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent in the Spanish-language consent screen.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send electronic direct marketing to Uruguayan residents. The only email Balance sends to Uruguayan parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 18.331 Art 9 + the URCDP's published interpretive practice require pre-existing consent and a free, easy unsubscribe mechanism for any commercial electronic communication; if Balance ever introduces a marketing channel, we will comply with the URCDP's interpretive guidance + the Ley 17.250 prohibitions on misleading advertising.
13. Lawful-access requests and the encryption posture
Uruguayan authorities may serve a lawful-access request on Balance via:
- A judicial order under the Código del Proceso Penal (Ley 19.293 + Ley 19.696, in force from 1 November 2017).
- A Ministerio Público — Fiscalía General de la Nación request under the Ley Orgánica de la Fiscalía General de la Nación (Ley 19.483 of 5 January 2017).
- A judicial intercept order under the CPP and the Ley 18.494 de 5 de junio de 2009 (controlled deliveries and other special techniques) + complementary statutes.
- A juez letrado order in the acción de habeas data civil procedure (Ley 18.331 Arts 37–45).
- A judicial order in the ordinary civil procedure (Código General del Proceso — Ley 15.982 of 18 October 1988).
- A URCDP information-request under Ley 18.331 Arts 31–35 + Ley 19.670 + Decreto 64/020.
- An Área de Defensa del Consumidor information-request under Ley 17.250 + Decreto 244/000.
- A judicial order under the Convenio sobre la Ciberdelincuencia (Budapest Convention; signed by Uruguay on 20 April 2023 — ratification pending at the Effective date but the cooperation channels are operational on a best-effort basis via INTERPOL).
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Uruguayan counsel to assess the validity of the request and the appropriate response; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the Ministerio del Interior — División de Delitos Informáticos, with the Ministerio Público — Fiscalías Especializadas en Crimen Organizado, en Delitos Sexuales, Violencia Doméstica y Violencia Basada en Género, and with INAU, on any CSAE-related referral, via the routes in § 14 below.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Uruguay
A Uruguayan resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in Spanish for Uruguayan reporters. - Línea Azul 0800 5050 — INAU — the national 24-hour child-protection line. Online:
https://www.gub.uy/instituto-nino-adolescente-uruguay/. Toll-free within Uruguay: 0800 5050. - INAU — Instituto del Niño y Adolescente del Uruguay — the principal cabinet-level child-welfare authority. Online:
https://www.gub.uy/instituto-nino-adolescente-uruguay/. - SIPIAV — Sistema Integral de Protección a la Infancia y Adolescencia contra la Violencia — the cross-government child-protection-against-violence coordination system led by INAU.
- Ministerio del Interior — Dirección General de la Lucha contra el Crimen Organizado e INTERPOL — División de Delitos Informáticos — the cybercrime investigation unit. Online:
https://www.minterior.gub.uy/. Emergency: 911. - Ministerio Público — Fiscalía General de la Nación — Fiscalías Especializadas en Crimen Organizado —
https://www.fiscalia.gub.uy/. - Ministerio Público — Fiscalías Especializadas en Delitos Sexuales, Violencia Doméstica y Violencia Basada en Género —
https://www.fiscalia.gub.uy/. - Ministerio Público — Fiscalías Especializadas en Estupefacientes y Delitos Conexos — for trafficking-related CSAE cases.
- Institución Nacional de Derechos Humanos y Defensoría del Pueblo (INDDHH) — Adjuntía para los Derechos de los Niños, Niñas y Adolescentes —
https://www.gub.uy/institucion-nacional-derechos-humanos-uruguay/. - INAU — Línea Violeta 0800 4141 — for violence against children, adolescents, and women.
- ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Uruguayan coordination via INAU + Ministerio del Interior + INTERPOL Uruguay. - Te Protejo Latin America regional intake —
https://www.teprotejo.org/— for transnational CSAE reports.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Uruguayan resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Unidad Reguladora y de Control de Datos Personales (URCDP) | LPDP + Ley 19.670 + Decreto 64/020 + URCDP Resoluciones | Liniers 1324, piso 4, Torre Ejecutiva Sur, CP 11.100, Montevideo; https://www.gub.uy/unidad-reguladora-control-datos-personales/ |
| Área de Defensa del Consumidor — Ministerio de Economía y Finanzas (MEF) | Ley 17.250 Ley de Relaciones de Consumo | Colonia 1206, Montevideo; https://www.gub.uy/ministerio-economia-finanzas/areas-defensa-consumidor |
| Institución Nacional de Derechos Humanos y Defensoría del Pueblo (INDDHH) — Adjuntía para los Derechos de los Niños, Niñas y Adolescentes | Constitutional human-rights ombudsperson; child-rights complaints | https://www.gub.uy/institucion-nacional-derechos-humanos-uruguay/ |
| Ministerio Público — Fiscalía General de la Nación | Cybercrime + child-sexual-exploitation + criminal LPDP-grounded prosecutions | https://www.fiscalia.gub.uy/ |
| Poder Judicial — Juzgados Letrados de Primera Instancia en lo Civil / Juzgados Letrados de lo Contencioso Administrativo | Acción de habeas data (Ley 18.331 Arts 37–45) | Per jurisdiction (Montevideo: Juzgados Letrados de lo Contencioso Administrativo) |
| Poder Judicial — Juzgados Letrados de Familia | Family-court actions | Per jurisdiction |
A Uruguayan resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the Delegado de Protección de Datos). We will respond within the LPDP 5-working-day window. Raising the matter with us first is not a precondition to complaining to the URCDP, filing an acción de habeas data, or seeking any other constitutional, civil, or criminal remedy; the URCDP accepts complaints directly.
16. Consumer rights — the Ley 17.250 overlay
Ley 17.250 (the Ley de Relaciones de Consumo, "LRC") is the principal Uruguayan consumer-protection statute. Where the parent is acting as a consumidor within the meaning of LRC Art 2, the following overlays apply to the subscription purchase flow and to the Terms of Service.
16.1 Pre-contract information (LRC Art 13 + Decreto 244/000)
The parent is entitled to información clara, veraz y oportuna on the essential characteristics of the service. Implemented in Subscription Terms § 5.
16.2 5-working-day right of revocation — derecho de revocación (LRC Art 16)
LRC Art 16 grants the consumer a 5-working-day right of revocation for door-to-door and distance contracts, computed from the date of the contract or from the delivery of the service. This is the Uruguayan equivalent of the Argentine botón de arrepentimiento (AR Annex § 16.2), the Chilean derecho de retracto (CL Annex § 16.2), the Colombian derecho de retracto (CO Annex § 16.2), and the Peruvian derecho de retracto (PE Annex § 16.2). Balance's subscription is concluded at a distance (in-app); the 5-working-day right of revocation applies and is implemented in Subscription Terms § 20. The right of revocation is honored regardless of whether the parent has used the service in the 5-working-day window — the parent is entitled to a full refund through the Google Play Billing refund route.
16.3 Abusive contract terms (LRC Art 30 + Art 31)
LRC Arts 30 and 31 declare null any contract term that (i) limits the supplier's liability for damages contrary to public order; (ii) reverses the burden of proof to the consumer's detriment; (iii) imposes a unilateral right of termination on the supplier; (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 30/31 risk.
16.4 Forum and choice of law
LRC operates on a consumer-protective basis. The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace Uruguayan law to the prejudice of the Uruguayan consumer are presumptively null under LRC Arts 30 and 31.
16.5 MEF Área de Defensa del Consumidor procedure
LRC + Decreto 244/000 establish the MEF Área de Defensa del Consumidor administrative procedure for the resolution of consumer disputes. The consumer may file an individual claim with the Área or pursue a collective interest action under LRC Art 51.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — URCDP-model contractual clauses (Resolución 1/2018) on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA) — the EU/EEA Annex confirms the Uruguay EU adequacy decision (2012/484/EU) under GDPR Art 45.
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the LPDP (Ley 18.331) or to Ley 19.670 Arts 37–40 (the GDPR-aligned overlays) triggers an off-cycle rewrite of §§ 2, 4, 6, 7, 8, and 11.
- A material amendment to Decreto 414/009 or Decreto 64/020 triggers an off-cycle update to the affected operational sections.
- A new URCDP Resolución that materially affects Balance's posture triggers an off-cycle update to the relevant operational section.
- A material amendment to the CNA (Ley 17.823) triggers an off-cycle update to § 5 + § 7 + § 14.
- A material amendment to Ley 17.250 (LRC) or Decreto 244/000 triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to Ley 17.815 (CSAE), Ley 19.580, or Ley 19.747 triggers an off-cycle update to § 13 + § 14.
- A material Sentencia of the Suprema Corte de Justicia or of the Tribunal de lo Contencioso Administrativo that materially affects the constitutional or statutory interpretation triggers an off-cycle update to the relevant operational section.
- The European Commission rescinding or modifying Decision 2012/484/EU (the Uruguay EU adequacy decision) triggers an immediate off-cycle update to § 8 + § 9.
- Uruguay's ratification of the Budapest Convention on Cybercrime (signed 20 April 2023; ratification pending at the Effective date) triggers an off-cycle update to § 13.
- A material change to a sub-processor's Uruguayan contractual-clause status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Delegado de Protección de Datos co-signs any change to § 3 (DPO designation), § 5 (CNA), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The authoritative Spanish-language version is republished at Uruguay annex.
End of Uruguay Country Annex.