Skip to content

Privacy Policy

In effect since August 2, 2026; updated October 10, 2026.

This policy explains what personal data the CercaPros website (the “Platform”) collects and processes, for what purposes, who it's shared with, and what rights you have. It complements the Terms of Service. This policy is published in Spanish, Russian and English; if the versions differ, the Spanish version prevails.

1. Who processes your data

The data controller for the CercaPros Platform (cercapros.com) is Denis Berdyshev, an individual, at Edificio Home Villa Morra, Gómez de Castro 545, Asunción 001411, Paraguay. Their contact details, the representative for complaints about infringed rights and the consumer-protection authorities are on the “Who runs CercaPros” page (linked at the bottom of every page of the site). For any questions about personal data, write to info@cercapros.com.

2. What data we collect

At registration: name, email and/or phone number, password (stored as a hash, never in plain text).

Specialist profile data (optional): work categories, city and district, service descriptions, tags, portfolio photos, and intro video.

A Specialist's gender is optional: clients can filter specialists by it in the catalog, and “Prefer not to say” can be chosen. A license or registration is optional too and is asked only for services whose activity requires one by law: it is shown on the profile with a note that the Platform does not verify it.

A Specialist's phone number and the “Message on WhatsApp” button are shown to users logged in to the Platform, on the profile and in conversations, while “Show my number and WhatsApp” is checked in the profile settings. If the Specialist unchecks it, the number and the button are shown only to the people the Specialist has replied to in a conversation. A Specialist sees a client's number in a conversation only after the client has replied or has chosen them. Visitors without an account and search engines are not shown the number. A number you write yourself in the text of a profile, a request or a review is seen by everyone, search engines included.

An identity document — voluntarily uploaded by a Specialist to obtain the “Identity verified” badge.

The content of requests, responses, chat messages, and reviews you post on the Platform. Both sides leave reviews: the client about the Specialist's work, and the Specialist about the client; Specialists see a client's average rating next to that client's requests.

Reports: who reported, whom or what (a person, a request, a review), the reason, and the text the person reporting wrote.

Complaints about infringed rights sent through the form on the “Who runs CercaPros” page (anyone can send one, without an account): name, email, the link to the Platform page, which right is infringed, the description, and the box declaring the information true.

Technical data: cookies and entries in your browser's storage (details in the Cookie Policy), IP address, and browser data, kept in standard server logs for security purposes.

To limit attempts (logging in, registering, resetting a password, sending SMS codes, posting and other actions), the Platform keeps records of those attempts in its database. Most of them hold only the kind of action and the account's internal ID; some actions — for example, logging in, registering, resetting a password and sending an SMS code — also keep the IP address or the email or phone number entered. These records are deleted by the daily cleanup once they are older than 24 hours, so they are kept for up to 48 hours.

If a wrong two-factor code is entered many times in a row when signing in to the administration panel, the administrators get an email with the IP address of the last attempt.

Stores. If you manage a Store's page, we keep that your account manages it and since when, when you accepted the store terms (the Terms of Service, Section 8) and which version, the invitation you accepted (the email it was sent to) and changes to the Store's WhatsApp and phone: who made them, the old number and the new one. If the administrator hides the Store from the site, we keep when and for what reason; whoever manages the Store's page sees that reason. It is kept until the Store is back on the site. A Store's WhatsApp, phone and address are published on its page and anyone can see them, including people without an account and search engines: the Store provides them so people can contact it. If it is your personal number, keep that in mind before entering it.

Store statistics: how many times a day a Store's page was opened and “WhatsApp”, “Call”, “Get directions” or a product question was tapped. Only these numbers are kept, with no data on who. To avoid counting the same visit twice and to stop abuse, the IP address is used in the rate-limit records (deleted as described in Section 8).

Reports about a Store: who reported, which Store, the reason and the text they wrote. They are not shown to the Store.

The Specialist card shows on your screen your name, your photo, the “Identity verified” badge if you have it, and today's date and time. The Platform does not send this data to the Store: the cashier sees it when you show them your screen.

3. What we use the data for

To provide the core features: registration and login, searching for specialists, posting requests and responses, messaging, reviews.

To send service notifications: a new response, a new message, an urgent request in your services, a request expiring, email confirmation.

To maintain trust and safety: automated review of the content you publish by OpenAI's artificial-intelligence service — your name at registration and whenever you change it, the profile description, education, license or registration, keywords and service names, requests, reviews and replies to reviews, the profile and portfolio photos you upload, the video cover, and your Google account photo if you created your account by signing in with Google, and what a Store publishes: product names, promotions, the description, and the store and product photos uploaded by whoever manages its page (details in Section 5); manual moderation by the administrator; reviewing reports; verifying documents for the “Identity verified” badge; and preventing fraud and automated (spam) sign-ups. Chat messages are not reviewed automatically. The administrator may read the conversation between two users only while handling a report connected with it: a report by one of the two against the other (against the person, their request or their review), or a report about a review one of them left about the other. The report's card shows the last messages between them, and every opening of the whole conversation is recorded in the administrator's action log. Also, if you ask for a copy of your data, the file includes the messages you sent; if your account has no confirmed email, the administrator downloads it to hand it to you, and this is recorded.

To review complaints about infringed rights (Articles 16 and 19 of Law No. 4868/2013): a complaint from the form is seen only by the administrator, in the admin panel and, as a rule, in the email that reaches them through Resend, who replies to the email given in it. The complaint is not published and is not reviewed by OpenAI.

To show Store pages, give whoever manages a Store the statistics of its page, and review reports about Stores.

With your separate consent — to send you news and promotions by email and SMS. None are sent today (see Section 6).

4. Legal basis for processing

Data necessary for the service to function (registration, requests, messages, service notifications) is processed to perform our contract with you — that is, to provide the Platform features you use.

Data for marketing emails and SMS is processed only with your explicit consent, which you can withdraw at any time without needing to justify it.

An identity document is processed with your consent: you upload it voluntarily and, until the request is decided, you can ask us to delete it (see Section 8).

On the basis of the Platform's legitimate interest in protecting the service and other users, we process: the phone number confirmed with an SMS code, to prevent fake and duplicate accounts; security logs and the records used to limit attempts, to protect against break-ins, fraud and spam; and the content you publish in the automated review (the Platform's own list of banned words and OpenAI, see Section 5), so that unacceptable content is not published.

You can object to processing based on legitimate interest by writing to info@cercapros.com. We will review your objection and reply within 30 calendar days.

5. Who we share data with

We do not sell personal data or share it with ad networks for targeting.

To run the service we use the following processors, which handle data on our behalf:

  • Vercel — hosting for the Platform, storage for uploaded files (avatars, portfolio photos, intro video, and Store photos), and technical server logs
  • Prisma Data Platform — hosting for the database that holds all account and posting data and, until the request is decided, the document submitted for the “Identity verified” badge
  • Resend — sending email notifications
  • Twilio — sending the SMS with a confirmation code when you register with a phone number, add or confirm the number of your account, change your number, or reset your password, and, when the number changes, a short notice to the previous number (it receives the phone number and the text of the message)
  • Cloudflare — the “I'm not a robot” check on login, registration, a password reset request, sending an SMS code, reactivating an account, and sending a complaint about infringed rights (it receives your IP address and technical browser data)
  • Google — sign-in via a Google account (OAuth), if you choose that option: Google gives us your name, email address and profile photo (see the next paragraph)
  • OpenAI — automated review of the content you publish: text (name, profile description, education, license or registration, keywords, service names, requests, reviews, replies to reviews) and reduced copies of photos (avatar, portfolio, video cover, Google account photo) and, for Stores, product names, promotions, the description and the store and product photos uploaded by whoever manages the page are sent to OpenAI to assess whether the content is acceptable on the Platform. All that comes back is the decision — publish, send for manual review, or refuse — and a short explanation for the administrator. Photo metadata (EXIF, geolocation) is stripped before sending; under the OpenAI API terms, such data is not used to train its models. More in the paragraphs below.

What happens after the review. A text (the profile description, education and license or registration, keywords, “Services and prices”, a request, a review, a reply to a review) that the automated review — the Platform's own list of banned words or OpenAI — finds unacceptable is not saved: you see the refusal right away and can correct the text and send it again, and, if you think the refusal is a mistake, ask for a person to review the decision (see the Terms of Service, Section 3). A description, education, license or registration, request, review or reply the review has doubts about is published and goes to the administrator's queue, who can keep it or remove it. A keyword or a line of “Services and prices” is shown to others only if the review is sure it is suitable; otherwise it waits for the administrator's decision and is not shown until then. A name, at registration or when it is changed, is refused right away only by the Platform's own list of banned words; if OpenAI objects, the name is saved, published and goes to the administrator's queue. A name that comes from your Google account is never refused: if the review has doubts, it is published and goes to the administrator's queue. A photo you upload (avatar, portfolio) is published right away only if the review is sure it is suitable; any other is decided by a person, the administrator: until then it is not published, and if there is no decision within 30 days, the file is deleted and you are notified that the photo was not accepted.

Messages the administrator writes to you (for example, a warning or the explanation of a decision) may be translated into your language with OpenAI: only the text of the message is sent to OpenAI.

Under the OpenAI API terms, the data we send may be kept for up to 30 days to detect abuse and is not used to train models.

If you created your account by signing in with Google, we fetch your Google account photo once and review it the same way as the photos you upload (see OpenAI above). If the review is sure the photo is suitable, we store a copy (with Vercel, metadata removed) and it becomes your profile photo on the Platform until you upload another one or remove it. If the review has doubts, the photo is not stored and your profile stays without one: you can upload your own.

The mailbox info@cercapros.com is hosted by the Zoho mail service: Zoho receives and stores the emails you send to that address (including replies to our notifications). The notifications themselves are sent by the Platform through Resend.

When you message a Store on WhatsApp or call it, the Store receives your data directly and handles it under its own responsibility. The Platform does not pass any of your data to the Store.

An identity document is not published on the Platform, is not shown to other users, and is not shared with third parties beyond the processor that hosts the database (Prisma Data Platform). Only the administrator views it, for verification purposes. The file is kept in the Platform's database and has no internet address from which it could be opened: only the Platform itself shows it to the administrator, after they sign in with two-factor authentication. Metadata in photos of the document, including geolocation, is removed on upload. Once the request is decided, the file is deleted (see Section 8).

Apart from the reports of signs of exploitation of people that we make ourselves (see the Terms of Service, Section 3), we hand over data only on a written request from a judge or the Public Prosecutor's Office (Ministerio Público). The content of chat messages is handed over only on a court order.

6. Email and SMS communications

Service notifications (for example, about a new response, a new message, a specialist being chosen, a request expiring, a new review or an urgent request in your category or with your keyword) go only to your confirmed email and do not depend on marketing consent. You can turn them off at any time: in “Account settings”, under “Communications”, by unchecking “I want emails about new responses, messages and requests about to expire”, or with the “Stop receiving these notifications” link at the end of any such email. Emails about the account itself (password reset, a change of password, email or phone, account deactivation and reactivation, and the administration's decisions) also go only to a confirmed email and, as a rule, even if you turned notifications off (of the administration's decisions, a deactivated account gets only those about a block, its lifting or the account's deletion). The email with the confirmation link goes to the address being confirmed. While you have no email, or it isn't confirmed, all of this shows up on the site, under “Notifications”.

We send the password reset link only to a confirmed email. If your email isn't confirmed, you can reset your password with a code by SMS to the account's number. If an email with no account behind it is entered on the “Forgot your password?” page, that address may get an email saying there is no account with it.

The Platform does not send any marketing or promotional messages yet. Consent to them can be given at registration or later in account settings, and once such messages start, they will go only to those who gave that separate, explicit consent. In line with Articles 21⁠–⁠23 and 30 of Law No. 4868/2013 on Electronic Commerce, every such message will be clearly labeled as advertising and include a simple, free way to unsubscribe.

SMS is already used for service messages: the codes to confirm your phone number, to change it and to reset your password, and, when the number changes, a short notice to the previous number, are sent through Twilio (see Section 5). No marketing messages are sent today, by email or by SMS. Your consent covers both channels, so we won't ask again when they start — but we will update this policy and name in Section 5 the service they are sent through. Marketing SMS will be sent only Monday to Friday, from 8:00 to 18:00 Asunción time, unless you allow other hours. If you don't want to receive them, withdraw your consent by any of the means below.

You can unsubscribe at any time: via the link in the marketing message or SMS itself, on the unsubscribe page that the “Stop receiving these notifications” link in our emails opens, or in “Account settings”, under “Communications”, by unchecking “I want to receive news and promotions by email and SMS” — everybody has it, including people without an email. Re-subscribing works the same way.

7. Cookies

The Platform uses only technical cookies — to log in, to remember the language and for other service tasks — and your browser's storage for form drafts and one preference. There are no advertising or analytics cookies. The full list, how long each is kept and how to opt out are in the separate Cookie Policy.

8. How long we keep data

Account and profile data is kept until the account is deleted. If you deactivate your own account, or the administrator blocks it, the data is kept (hidden from search) since it may be part of other users' history — requests, conversations, reviews. Until the account is deleted, its requests and its conversations are kept too. Full data deletion is available on request — see “Your rights” below.

In-platform reports (about a person, a request or a review) and the cards of the administrator's review queue (the copy of the text or photo the review flagged) are deleted 2 years after they are resolved, and the administrator's action log entries 2 years after they are written. Kept longer: the entries about deleting an account or a profile (with the fingerprint explained below); the entry about a block and the report that led to it, while the block lasts; the entry about a rejected keyword, while it stays rejected; and the cards of approved content, so the same text does not go back to review. Reports and cards not yet resolved are kept until they are resolved.

When an account is deleted, all of its conversations are deleted too, for the other person as well: the conversation with the deleted account disappears from their side too. The in-platform reports that person made, or that were made against them, are deleted as well; complaints about infringed rights from the public form are not tied to an account, and how long they are kept is said below. The administrator's action log keeps the administrator's decisions, but without the deleted person's name or contact details: instead of the email (or the phone number, if there was no email) it keeps its fingerprint — the result of one-way encryption, from which the address cannot be recovered and which only lets one check whether the account of an already known address was deleted.

Deleted automatically, by a daily cleanup: the entries used to limit attempts (IP address, email, phone number), once they are older than 24 hours, so they last up to 48 hours; unused SMS codes, after they expire; reduced copies of refused or removed photos shown in your notifications, after 30 days; uploaded photos the administrator has not decided on within 30 days, with a notice to you that the photo was not accepted.

Complaints about infringed rights (the form on the “Who runs CercaPros” page) are kept for up to 2 years after they are resolved; on request we delete them sooner.

If your account is deleted, the reviews you left about other users stay on the Platform without your name or any other data, signed “Deleted user”: they are part of another person's history and rating. The text of the review stays as you wrote it, but without your full name, your email or the account's phone number, if you had written them in it: “[…]” stands in their place. On request, we can also delete your reviews.

If an administrator removes a review, the Platform keeps a record of it (who left it, about whom, and when it was removed, without the text of the review): it is there so that its author can't leave a new review of the same person right away. The record is deleted together with the account of the author or of the person reviewed.

An identity document is kept only until the verification request is decided: as soon as the administrator approves or rejects it, the file is deleted automatically. Until then you may request its deletion by writing to info@cercapros.com.

Portfolio photos and video are kept until you delete them yourself from your specialist profile settings, or until the account is deleted.

For Stores: reports are deleted 2 years after they are resolved; changes to the WhatsApp and phone, 2 years after they are made; daily statistics, after 400 days; an invitation that was not accepted, 30 days after it expired or was withdrawn; a promotion, 30 days after it ends. A promotion or a product name the administrator refused is kept longer, as the record of that decision: if it is sent again, it waits for the administrator's review; such a promotion is deleted 2 years after it ends, and a refused product name that was removed or replaced, 2 years after that. If the account of whoever manages a Store is deleted, they stop being its manager; the Store's page stays published.

9. Your rights

You have the right to: access your personal data; correct inaccurate data; delete your data or your entire account; restrict or withdraw consent to processing (for marketing messages); object to processing based on legitimate interest (see Section 4); receive a copy of your data in a machine-readable format.

To exercise any of these rights, write to info@cercapros.com. We will review your request and respond within 30 calendar days.

We send the copy of your data (a JSON file) by email, and only to your account's confirmed address. If you don't have one, we agree with you on another way in which we can check that the request is yours.

Today these rights rest on Law No. 4868/2013 on Electronic Commerce, Decree No. 1165/2014 and the constitutional habeas data guarantee (Art. 135 of Paraguay's Constitution). Law No. 7593/2025 on Personal Data Protection comes into force on November 28, 2027; we already apply its principles.

10. Security

Passwords are stored as an irreversible hash (bcrypt), the connection to the site is protected with HTTPS/TLS, and access to administrative features requires an additional check (two-factor authentication). Uploaded photos and the intro video have their metadata stripped, including capture coordinates. Identity verification documents are not published on any Platform page, are kept in the database with no public link, can be viewed only by the administrator, and are deleted as soon as review is finished.

11. International data transfers

The processors listed in Section 5 (Vercel, Prisma Data Platform, Resend, Twilio, OpenAI, Cloudflare, Google, Zoho) process data on servers outside Paraguay, in the United States and other countries. These transfers are necessary to provide you the Platform services you use. These providers' terms of service and published privacy policies apply; where a provider offers a data processing agreement for our plan, we apply it.

12. Minors

The Platform is intended for people 18 and older. We do not knowingly collect data from minors. If we learn that an account was created by someone under 18, we will delete that account and its associated data.

13. Complaints

If you believe your data-protection rights have been violated, please write to us first at info@cercapros.com — we'll try to resolve it directly. If it is not resolved, you can turn to the Ministry of Industry and Commerce, Directorate General of Digital Signature and Electronic Commerce (Ministerio de Industria y Comercio — Dirección General de Firma Digital y Comercio Electrónico, https://www.mic.gov.py); if you are a consumer, to the Secretariat for Consumer and User Protection (Secretaría de Defensa del Consumidor y el Usuario, SEDECO); and to the courts, with a habeas data action. From November 28, 2027 you will also be able to complain to the National Personal Data Protection Agency (Agencia Nacional de Protección de Datos Personales).

14. Changes to this policy

We may update this policy. For substantial changes we give at least 15 days' notice under “Notifications” and, if your active account has a confirmed email, by email too. When they take effect, we ask you to accept the new version. If you don't accept it, you can close your account: deactivate it in “Account settings” or ask us to delete it. Changes that do not affect your rights are published with the new date at the top of the document.

15. Contact

For any questions about personal data, write to info@cercapros.com.