Privacy Policy
Rivas & Bejarano Consulting (d/b/a CX Now)
Last Updated: November 2025
Rivas & Bejarano Consulting, San José, Costa Rica
1. Introduction and Scope
This Privacy Policy ("Policy") explains how Rivas & Bejarano Consulting (doing business as "CX Now," "we," "us," "our," or "Company") collect, use, disclose, and otherwise process personal data and information when you interact with our AI-powered survey and form platform, including our websites, applications, software, and services (collectively, the "Services").
This Privacy Policy applies to all individuals who use, visit, or interact with our Services, including survey creators, respondents, and website visitors. We refer to these categories collectively as "users."
This Privacy Policy does not apply to:
- Personal information collected from job applicants or employees in their professional capacity (governed by separate Employee Privacy Notices)
- Aggregate or de-identified data that cannot reasonably identify an individual
2. Types of Personal Data We Collect
2.1 Data You Provide Directly
(a) Account and Registration Information
When you create a CX Now account, we collect:
- Name and email address
- Password (encrypted and stored securely)
- Billing information (name, address, payment method details)
- Company or organizational name (if applicable)
- Phone number (optional)
- Profile information and preferences
- Any information you submit in account settings or profile updates
(b) Survey and Form Content
We collect and store:
- All surveys and forms you create
- Survey and form questions you design
- Instructions and descriptions you provide
- Customized designs, themes, and branding you apply
- Response data and answers collected from respondents
- Analytics and insights you generate
(c) Communication and Support Information
When you contact us, we collect:
- Your name, email address, and contact information
- The content of your messages, inquiries, or complaints
- Records of customer support interactions and calls
- Feedback, suggestions, and feature requests you submit
(d) Contact and Address Book Data
If you choose to import contact information:
- Email addresses from your address book or contact list
- Names and other identifiers of people you invite to participate in surveys
- We use this data solely as you direct and do not use it for our own marketing purposes
2.2 Data Collected Automatically
(a) Device and Browser Information
When you access our Services, we automatically collect:
- Internet Protocol (IP) address
- Device type, model, and unique identifiers (MAC address, device ID)
- Operating system and version
- Browser type and version
- Mobile device UUID
- Device performance and system information
- Inferred geographic location based on IP address
(b) Usage and Interaction Data
We track:
- Which pages or features you access
- How often and when you use the Services
- Time spent on specific pages or features
- Clicks, buttons, and links you interact with
- Forms you submit or complete
- Searches you perform
- Your language preferences
- Purchases, subscriptions, and billing information
(c) Cookies and Similar Tracking Technologies
We use:
- First-party and third-party cookies
- Web beacons (pixel tags)
- Local storage and similar technologies
- Session tracking and analytics tools
These technologies collect usage statistics, user preferences, and behavioral information. See our separate Cookies Policy for more details.
(d) Event and Log File Data
Our servers automatically record:
- Log file entries for each access to our systems
- Timestamps of your interactions
- Nature and type of each access
- File requests and responses
- Error messages and system events
- Security and access attempt information
(e) Integration Data
If you connect third-party services to your CX Now account:
- Data from integrations with email, CRM, or analytics platforms
- Authentication tokens and credentials (handled securely)
- Synchronized data and activity logs
- Performance metrics from integrated services
2.3 Data from Third Parties
(a) Respondent Data
When individuals complete your surveys or forms:
- All responses and answers they provide
- Email addresses used for survey invitations
- Identifying information they choose to include
- Interaction data and timestamps
- Survey completion status and progress
(b) Third-Party Information Sources
We may collect information about you from:
- Data brokers and public records providers
- LinkedIn and similar professional networks
- Social media platforms (when you authorize integrations)
- Marketing and analytics platforms
- Referral partners and affiliates
(c) Enterprise and Team Information
If you're part of a team or enterprise account:
- Information shared by your organization's administrators
- Directory or organizational hierarchy data
- Shared surveys and collective analytics
3. How We Use Personal Data
3.1 Providing and Operating Services
We use personal data to:
- Create and maintain your account
- Process your payments and subscriptions
- Deliver the Services and features you request
- Store and process your survey content and responses
- Provide analytics and insights for your data
- Generate reports and export data as you request
- Enable integrations with third-party services
3.2 Improving and Developing Services
We use personal data to:
- Enhance existing features and functionality
- Develop new features and AI capabilities
- Conduct testing and quality assurance
- Troubleshoot and resolve technical issues
- Analyze usage patterns and user behavior
- Create aggregate and de-identified insights
- Train and improve our AI algorithms
- Optimize platform performance
3.3 Communication
We use personal data to:
- Send transactional emails (confirmations, receipts, passwords)
- Provide customer support and respond to inquiries
- Notify you of changes to our Services or policies
- Send billing and subscription information
- Provide security updates and alerts
- Request feedback and conduct surveys about our Services
3.4 Marketing and Promotional Activities
We use personal data to:
- Send marketing communications about our Services (with your consent)
- Deliver personalized and targeted advertising
- Conduct promotional campaigns and offers
- Show targeted content based on your interests
- Analyze marketing effectiveness
- Update our marketing records and preferences
You can opt out of marketing communications at any time by unsubscribing from emails or adjusting your account preferences.
3.5 Legal and Compliance
We use personal data to:
- Comply with applicable laws and regulations
- Respond to legal requests, subpoenas, and court orders
- Enforce our Terms of Service and other agreements
- Protect against fraud, security threats, and abuse
- Verify your identity and prevent unauthorized access
- Maintain records for regulatory and tax purposes
- Protect our legal rights and the rights of others
3.6 Security and Fraud Prevention
We use personal data to:
- Detect and prevent fraudulent activities
- Monitor for security vulnerabilities and breaches
- Investigate suspicious or unauthorized activities
- Protect against malware and cyber attacks
- Verify user identity and prevent account takeover
- Maintain audit logs and access controls
4. Legal Bases for Processing (Costa Rican Law, GDPR, and Similar Laws)
We process personal data in compliance with Costa Rica's Law for the Protection of Individuals Regarding the Processing of Their Personal Data (Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales, Ley N° 8968) and its regulations, as well as applicable international frameworks. We process personal data based on the following legal grounds:
4.1 Consent
We rely on your consent to process:
- Marketing and promotional communications
- Non-essential cookies and tracking technologies
- Optional contact information for specific purposes
You can withdraw consent at any time through your account settings or by contacting us.
4.2 Contract
We process personal data as necessary to:
- Fulfill our agreement with you
- Provide the Services you requested
- Perform payment processing and billing
- Deliver customer support and technical assistance
4.3 Legitimate Interests
We process personal data for legitimate business interests, including:
- Maintaining and improving the Services
- Preventing fraud and protecting security
- Analyzing usage patterns and optimizing performance
- Conducting marketing and sales activities
- Protecting our legal rights and business interests
In each case, we balance our interests against your rights and have implemented limitations to protect your privacy.
4.4 Legal Obligation
We process personal data when required by:
- Applicable laws and regulations
- Court orders and legal demands
- Government agencies and regulatory authorities
- Tax and financial reporting requirements
5. Data Sharing and Disclosure
5.1 Data We Do Not Share
CX Now does not:
- Sell your personal data to third parties for marketing purposes
- Use your form responses or surveys to compete with you
- Contact your survey respondents for our own purposes
- Share your Content for profit or unauthorized purposes
- Disclose your survey data without your explicit permission
5.2 Data We Share
We may share personal data with:
(a) Team and Enterprise Administrators
If you're part of a team or enterprise account:
- Your organization's primary administrators can access your account data
- Administrators may view your surveys, responses, and analytics
- Administrators may transfer, modify, or delete your data
- Team members may collaborate on shared surveys
(b) Service Providers and Processors
We engage trusted partners to:
- Process payments and handle billing
- Send emails and manage communications
- Provide cloud hosting and data storage
- Analyze data and generate insights
- Provide customer support and chat services
- Conduct security assessments and monitoring
These processors are bound by strict Data Processing Agreements and use your data only as instructed.
(c) Third-Party Integrations
If you enable integrations with:
- Email marketing platforms
- CRM systems
- Analytics services
- Payment processors
- Cloud storage providers
We share only the data necessary for the integration to function. Each provider's privacy policy governs their use of that data.
(d) Legal and Law Enforcement
We may disclose personal data when:
- Required by law, court order, or government request
- Necessary to protect the rights, safety, or property of CX Now or others
- Required to detect, prevent, or address fraud or security issues
- Requested in connection with litigation or legal proceedings
We will, where legally permitted, notify you of legal requests and provide an opportunity to challenge them.
(e) Business Transfers
If CX Now is acquired, merges with another company, or undergoes asset sale:
- Your personal data may be transferred as part of the transaction
- We will notify you of any material changes to this Privacy Policy
- You will have the opportunity to opt out if permitted by law
5.3 Respondent Data
As a respondent to someone else's survey:
- The survey creator (not CX Now) controls your response data
- CX Now is a data processor for that information
- You should contact the survey creator directly regarding your responses
- The creator's privacy policy governs how they use your data
6. Data Retention
6.1 Creator Data Retention
We retain your account information and survey content as long as:
- Your account is active and in good standing
- You have not requested deletion
- Required by law or business operations
You are responsible for determining how long to retain your data. You can:
- Delete individual surveys or responses anytime
- Export your data before account closure
- Request complete data deletion when closing your account
6.2 Respondent Data Retention
Respondent data (survey responses) is retained according to:
- The survey creator's preferences and settings
- Your own data retention policies
- Applicable legal and regulatory requirements
- Our standard retention schedule
Upon account closure, response data is deleted in accordance with our Data Retention Policy and applicable law.
6.3 Backup and Residual Data
For business continuity and disaster recovery:
- We maintain backup copies of data for limited periods
- Deleted data may persist in backups for up to 90 days
- Aggregate and de-identified data may be retained indefinitely
- Backup data is securely stored and eventually destroyed
6.4 Legal Holds
If subject to legal proceedings or investigations:
- We may retain data longer than normally required
- Data held under legal process will be deleted when no longer required
- We will notify you if your data is subject to a legal hold
7. Data Security
7.1 Security Measures
We maintain robust security measures to protect personal data:
- Encryption in transit (TLS/SSL protocols)
- Encryption at rest for sensitive data
- Secure authentication and access controls
- Regular security assessments and penetration testing
- Multi-factor authentication (MFA) for accounts
- Firewalls and intrusion detection systems
- Role-based access controls and audit logs
- Secure data centers with physical access controls
7.2 Data Breach Notification
If CX Now becomes aware of unauthorized access to or acquisition, alteration, disclosure, or destruction of personal data:
- We will notify affected users without undue delay
- We will provide information about the breach and steps being taken
- We will comply with applicable notification laws and requirements
- Such notification does not constitute an admission of fault or liability
Unsuccessful access attempts, network attacks on firewalls, or non-intrusive security testing do not constitute a breach requiring notification.
7.3 Your Responsibility
You are responsible for:
- Maintaining confidentiality of your passwords and credentials
- Protecting your account from unauthorized access
- Notifying us immediately of any unauthorized access
- Keeping your contact information current and accurate
- Backing up critical data stored in your account
While we implement strong security, no system is completely immune to attacks or breaches.
8. Your Privacy Rights and Choices
8.1 Access and Portability
You have the right to:
- Request a copy of all personal data we hold about you
- Receive data in a portable, machine-readable format
- Request transfer of your data to another service
- Access your data through your account anytime you're logged in
To request a copy of your data, contact us at cxnow@lambdahq.com.
8.2 Correction and Updates
You can:
- Update your account information anytime through your account settings
- Correct inaccurate or incomplete data
- Request corrections to data we've obtained from third parties
- Request verification of information in our systems
8.3 Deletion and Right to Be Forgotten
You have the right to:
- Delete your account and associated data
- Request erasure of your personal data (subject to legal exceptions)
- Export your surveys and responses before deletion
- Request deletion of specific data elements
We will delete your data within 30 days of account closure, except where retention is required by law or for legitimate business purposes.
8.4 Restrict Processing
You can request that we:
- Limit how we use your personal data
- Restrict data processing to storage only
- Suspend marketing and promotional activities
- Restrict data sharing with third parties
8.5 Object to Processing
You may object to:
- Marketing communications (unsubscribe anytime)
- Targeted advertising and personalized content
- Profiling and automated decision-making
- Processing for legitimate interests (in certain circumstances)
8.6 Withdraw Consent
You can withdraw consent previously given for:
- Marketing and promotional communications
- Non-essential cookies and tracking
- Optional data collection activities
Withdrawing consent does not affect the lawfulness of processing before withdrawal.
8.7 Marketing Preferences
You can manage marketing preferences by:
- Clicking "Unsubscribe" in marketing emails
- Adjusting notification settings in your account
- Contacting us to opt out of all marketing communications
- Disabling cookies through your browser settings
8.8 Cookies and Tracking
You can:
- Clear cookies through your browser settings
- Opt out of non-essential cookies using our preference tool
- Use "Do Not Track" browser settings (if supported)
- Disable JavaScript or third-party tracking in browser settings
9. Children and Minors
The Services are not intended for and may not be used by individuals under 16 years of age (or older if required in your jurisdiction). We do not knowingly collect personal data from minors.
If we become aware that we have collected data from a minor:
- We will delete such information immediately
- We may terminate the account without notice
- We will comply with applicable child protection laws
If you believe we have collected data from a minor, contact us immediately at cxnow@lambdahq.com.
10. International Data Transfers
10.1 Data Processing Locations
Your personal data may be processed and stored in:
- Costa Rica (primary location)
- Countries where CX Now or our affiliates operate
- Locations where our service providers maintain infrastructure
- Other jurisdictions as needed to operate the Services
10.2 EU and International Compliance
For individuals in the European Union, United Kingdom, or Switzerland:
CX Now relies on appropriate transfer mechanisms, including:
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
- Other mechanisms approved by relevant data protection authorities
EU-U.S. Data Privacy Framework (DPF)
CX Now Inc. has self-certified compliance with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF Principles. We are committed to processing personal data from the EU, UK, and Switzerland in accordance with these frameworks.
For more information about the DPF, visit https://www.dataprivacyframework.gov/.
10.3 Data Transfer Concerns
If you have concerns about international data transfers:
- Review our EU Data Transfer Statement for details
- Contact our Data Protection Officer
- Submit requests to our dispute resolution process
11. Your Rights Under Different Regulations
11.1 Costa Rica (Ley N° 8968)
If you are in Costa Rica, under the Law for the Protection of Individuals Regarding the Processing of Their Personal Data (Ley N° 8968), you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure or deletion
- Right to restrict processing
- Right to object to processing
- Right to withdraw consent
- Right to lodge complaints with PRODHAB (Agencia de Protección de Datos de los Habitantes)
PRODHAB Contact: www.prodhab.go.cr
11.2 European Union (GDPR)
If you are in the EU, you have additional rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure (right to be forgotten)
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge complaints with your data protection authority
To exercise these rights, contact us at cxnow@lambdahq.com or through your account settings.
11.3 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information is collected, used, and shared
- Delete personal information (with limited exceptions)
- Opt-out of sale or sharing of personal information
- Non-discrimination for exercising your rights
See our California Privacy Notice for additional details.
11.4 Other U.S. State Laws
Other states provide similar privacy rights. Refer to our Region-Specific Privacy Notice for your state's specific rights and protections.
11.5 Canada (PIPEDA)
If you are in Canada, you have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your data
- Know how and why your data is being used
12. Data Controller and Data Processor Roles
12.1 For Creators
When you create surveys and forms using CX Now:
- You are the Data Controller for survey content and responses
- CX Now is the Data Processor for data you collect
- You are responsible for compliance with data protection laws in your jurisdiction
- You must provide privacy notices to respondents and obtain necessary consent
12.2 For Respondents
When you respond to a survey created by someone else:
- The survey creator is the Data Controller for your responses
- CX Now is the Data Processor on their behalf
- Contact the survey creator directly regarding your response data
- Refer to their privacy policy for information about data handling
12.3 Data Processing Agreements
CX Now enters into Data Processing Agreements (DPAs) with:
- Enterprise customers and organizations
- Customers subject to data protection regulations
- Customers with specific compliance requirements
DPAs are available upon request.
13. Third-Party Links and Services
Our Services may contain links to:
- Third-party websites and applications
- Third-party integrations and services
- Social media platforms
- External resources and tools
We are not responsible for:
- Third parties' privacy practices
- Content or accuracy of third-party sites
- Security or data handling by third parties
- Changes to third-party privacy policies
When you access third-party sites or services, their privacy policies govern your data. We recommend reviewing their policies before providing personal information.
14. Cookies and Similar Technologies
14.1 What We Use Cookies For
We use cookies and similar technologies to:
- Remember your preferences and login information
- Maintain your session while using the Services
- Track usage patterns and analytics
- Deliver personalized and targeted content
- Conduct A/B testing and feature improvements
- Measure advertising effectiveness
- Prevent fraud and enhance security
14.2 Types of Cookies
We use:
- Essential cookies (required for basic functionality, cannot be disabled)
- Performance cookies (analytics and optimization)
- Functional cookies (preferences and customization)
- Targeting cookies (personalized advertising)
- Tracking pixels and web beacons (activity monitoring)
14.3 Managing Cookies
You can:
- Clear cookies through browser settings
- Disable non-essential cookies using our preference tool
- Opt out of specific cookie categories
- Enable "Do Not Track" in your browser
- Use privacy browser extensions to block trackers
For more information, see our separate Cookies Policy.
15. Contact Information and Data Requests
15.1 Privacy Questions and Requests
For questions about this Privacy Policy or to exercise your privacy rights:
Email: cxnow@lambdahq.com
Mailing Address: CX Now San José, Costa Rica
Privacy Portal: www.cxnow.com/privacy-requests
We will respond to privacy requests within 30 days of receipt. We may request additional information to verify your identity and ensure the authenticity of your request.
15.2 Data Protection Officer
CX Now's Data Protection Officer can be reached at: cxnow@lambdahq.com
15.3 Costa Rican Data Protection Authority
If you are in Costa Rica and have concerns about our privacy practices, you may lodge a complaint with:
PRODHAB (Agencia de Protección de Datos de los Habitantes) Website: www.prodhab.go.cr
15.4 European Supervisory Authority
If you are in the European Union and have concerns about our privacy practices, you may lodge a complaint with your local data protection authority.
16. Changes to This Privacy Policy
16.1 Updates and Modifications
We may update this Privacy Policy periodically to:
- Reflect changes in our data practices
- Comply with new legal requirements
- Improve clarity and transparency
- Address emerging privacy issues
- Update contact information
16.2 Notice of Changes
For material changes, we will:
- Notify you via email at least 30 days in advance
- Post prominent notices on our website
- Require renewed consent if necessary
- Provide an opportunity to review changes before they take effect
16.3 Acceptance of Changes
Your continued use of the Services after updates take effect constitutes your acceptance of the modified Privacy Policy. If you do not agree to changes, you may stop using the Services and close your account.
17. Additional Information
17.1 Service-Specific Notices
Some CX Now services may have supplementary privacy notices addressing specific features:
- AI-powered analysis and insights
- Integration data handling
- Enterprise team features
- Research and analytics tools
These supplementary notices are incorporated into this Privacy Policy.
17.2 Related Documents
This Privacy Policy should be read in conjunction with:
- Terms of Service
- Cookies Policy
- Data Processing Agreement
- Acceptable Use Policy
In case of conflicts, the Privacy Policy and Data Processing Agreements prevail regarding personal data handling.
Last Updated: November 2025