Home / Legal Framework

Privacy Policy & Personal Data Processing Terms

In compliance with Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013, and related provisions of the Republic of Colombia.

Last updated: September 2026

1. Identification of the Data Controller

The firm +RETO Strategic Consulting (hereinafter "+RETO"), a commercial entity duly incorporated under the laws of the Republic of Colombia, with registered domicile in Bogotá D.C., official contact email: info@reto.com.co, acts as Data Controller for personal data collected through its web portal and corporate channels.

3. Purposes of Personal Data Processing

Personal data collected by +RETO through digital forms, electronic communications, and business relationships is processed for the following purposes:

  • Prompt management and response to inquiries, technical consulting requests, and corporate communications.
  • Structuring, presentation, and follow-up of technical and commercial proposals for strategic consulting services.
  • Execution and fulfillment of contractual engagements, Non-Disclosure Agreements (NDAs), and advisory agreements.
  • Distribution of relevant institutional updates, technical whitepapers on IT governance, AML/CFT compliance, and regulatory trends.
  • Compliance with statutory, tax, and reporting obligations before regulatory and supervisory authorities.

4. Data Subject Rights (ARCO Rights)

Pursuant to Article 8 of Statutory Law 1581 of 2012, data subjects are entitled to:

Know and Access Access your personal data that has undergone processing free of charge.
Update and Rectify Request the correction of inaccurate, incomplete, fragmented, or misleading personal data.
Delete and Revoke Request data deletion or revoke authorization when no statutory or contractual obligation prevents it.
File Claims Submit formal claims before the Superintendence of Industry and Commerce (SIC) upon exhausting direct procedures with +RETO.

5. Information Security Measures

+RETO enforces strict technical, physical, and administrative security controls to safeguard the confidentiality, integrity, and availability of personal data, preventing alteration, loss, unauthorized access, or misuse. All communications through this portal utilize high-grade SSL/TLS encryption protocols.

6. Procedure for Exercising Data Subject Rights (PQRS)

The data subject or their legal successors may submit inquiries or claims by sending an email to: info@reto.com.co specifying their full name, identification number, clear description of the request, and contact address.

Statutory Response Times:

• Inquiries: Maximum term of ten (10) business days from the date of receipt.

• Claims: Maximum term of fifteen (15) business days from the day following receipt.

7. Validity of the Policy and Databases

This policy takes effect upon institutional publication. Databases containing personal data shall remain valid for the period necessary to fulfill the purposes for which they were collected, or as required by statutory or contractual mandates.