Skip to main content

Compliance

This page describes how Percus addresses regulatory requirements relevant to its clients and the current status of each compliance initiative.


Regulatory applicability​

GDPR (European Union)​

In progress

Applicability analysis and gap assessment currently in progress with external legal counsel. Percus's client base is primarily LATAM-based, but GDPR may apply depending on the data subjects involved. This section will be updated once the assessment is complete.

Ley 19.628 and Ley 21.719 (Chile)​

In progress

Percus SpA is a Chilean company and processes personal data under Ley 19.628. Ley 21.719, which replaces most of that framework, takes effect in December 2026. Percus is reviewing its obligations under the new law; its processor commitments to clients are set out in the Data Protection Addendum.

Ley 8968 (Costa Rica)​

In progress

Ley 8968 applies where Percus processes personal data of Costa Rican data subjects on behalf of clients. Its applicability to each engagement is reviewed at contracting, and Percus's commitments are set out in the Data Protection Addendum.

LGPD (Brazil)​

In progress

Applicability to Brazilian clients and data subjects is under review. This section will be updated once the assessment is complete.

ISO/IEC 27001​

In progress

Percus is actively working toward ISO/IEC 27001 certification, together with a specialist partner. Work is under way on the information security management system: scope definition, risk assessment, and the control set required for certification.

This is the certification Percus is pursuing first, and the only one currently in active work.

Other certifications​

Additional certifications — including SOC 2 Type II — will be considered in future, once ISO/IEC 27001 is in place. They are not currently in progress, and Percus does not hold them today.


Architecture decisions that support compliance​

Regardless of the specific regulatory framework, several architectural decisions already align with common compliance requirements:

PrincipleHow Percus addresses it
Data minimizationTwo personalization models are offered. Client-side personalization keeps values in the host page and out of Percus entirely. Hosted render data is stored by Percus, keyed by a client-chosen token that is opaque to Percus, and is removed when its project is archived. See Data Handling.
Access controlRole-based access with organization-level isolation. Users can only access data belonging to their organization.
EncryptionAll data encrypted in transit (TLS 1.2+). At rest, template assets in S3 use server-side encryption and hosted render data is encrypted with keys managed in AWS KMS. Encryption at rest of the relational database is being enabled.
Audit trailOperations on hosted render data are recorded in an append-only log. An audit trail covering all administrative actions (sign-ins, role changes, publishing) is being implemented.
Secrets managementNo credentials hardcoded — all secrets stored in AWS Secrets Manager.
Consent managementThe embed SDK gates tracking behind explicit viewer consent: the tracking module loads only after the host page calls acceptConsent(), the decision is kept in memory only, and the ingest service drops the viewer identifier from any event sent without consent.