Privacy Policy & Personal Data Processing Terms
In compliance with Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013, and related provisions of the Republic of Colombia.
Document Outline
Data Protection Officer
For inquiries regarding your personal data or to exercise your habeas data rights, contact our official channel:
info@reto.com.co1. Identification of the Data Controller
The firm +RETO Strategic Consulting (hereinafter "+RETO"), a commercial entity duly incorporated under the laws of the Republic of Colombia, with registered domicile in Bogotá D.C., official contact email: info@reto.com.co, acts as Data Controller for personal data collected through its web portal and corporate channels.
2. Legal Framework & Scope of Application
This Data Processing Policy is adopted pursuant to Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013, Single Regulatory Decree 1074 of 2015, and related legal frameworks. It applies to all personal data registered in +RETO databases, collected in the course of its strategic advisory, auditing, IT governance, risk management, and corporate consulting operations.
3. Purposes of Personal Data Processing
Personal data collected by +RETO through digital forms, electronic communications, and business relationships is processed for the following purposes:
- Prompt management and response to inquiries, technical consulting requests, and corporate communications.
- Structuring, presentation, and follow-up of technical and commercial proposals for strategic consulting services.
- Execution and fulfillment of contractual engagements, Non-Disclosure Agreements (NDAs), and advisory agreements.
- Distribution of relevant institutional updates, technical whitepapers on IT governance, AML/CFT compliance, and regulatory trends.
- Compliance with statutory, tax, and reporting obligations before regulatory and supervisory authorities.
4. Data Subject Rights (ARCO Rights)
Pursuant to Article 8 of Statutory Law 1581 of 2012, data subjects are entitled to:
5. Information Security Measures
+RETO enforces strict technical, physical, and administrative security controls to safeguard the confidentiality, integrity, and availability of personal data, preventing alteration, loss, unauthorized access, or misuse. All communications through this portal utilize high-grade SSL/TLS encryption protocols.
6. Procedure for Exercising Data Subject Rights (PQRS)
The data subject or their legal successors may submit inquiries or claims by sending an email to: info@reto.com.co specifying their full name, identification number, clear description of the request, and contact address.
• Inquiries: Maximum term of ten (10) business days from the date of receipt.
• Claims: Maximum term of fifteen (15) business days from the day following receipt.
7. Validity of the Policy and Databases
This policy takes effect upon institutional publication. Databases containing personal data shall remain valid for the period necessary to fulfill the purposes for which they were collected, or as required by statutory or contractual mandates.