This Privacy Policy explains how Digital Consulting Plus (“DCP”), through Digital Consulting Plus SAS and/or Digital Consulting Plus LLC, collects, uses, stores, shares, and protects personal information relating to: website visitors; prospective clients; commercial contacts; customers; client representatives; vendors and partners; and users of DCP services and products when DCP acts as a data controller.
Where DCP processes personal data on behalf of an enterprise client under its documented instructions, the client acts as data controller and DCP acts as data processor, governed by the applicable contract or Data Processing Agreement (DPA).
Depending on the commercial relationship, contracted solution, purchase order, invoice, and territory, personal data processing is performed by the entity acting as controller:
A. Digital Consulting Plus SAS (Colombia)
Digital Consulting Plus SAS
NIT 901146936-4
DG 48 SUR 18-47 APT 1606, Bogotá D.C., Colombia
B. Digital Consulting Plus LLC (United States)
Digital Consulting Plus LLC
EIN 32-0668302
2423 SW 147th Ave #680, Miami, FL 33185, United States
Determining the specific contracting entity and responsible controller depends on the commercial engagement, proposal or Statement of Work (SOW) executed, purchase order, contracted service, issued invoice, and applicable jurisdiction. Under no circumstances should it be construed that both companies operate as a single legal entity or that they assume indiscriminate joint and several liability.
3.1.Information provided by the individual
We may collect: first name, last name, organization, job title when provided, email address, telephone or WhatsApp number, country, preferred language, service or product of interest, message body, and information voluntarily submitted through forms, scheduled meetings, or correspondence.
3.2.Commercial and contractual information
Where an active business relationship exists, we may process: corporate and contact details; proposals and quotes; service orders; contracts; invoices; payment history; technical support tickets; project communications; and records of deliverables.
3.4.Information obtained via integrations
When an individual or client authorizes a technical integration, we may receive data from third-party platforms to the extent strictly necessary to deliver the requested service.
We may process personal data to:
- respond to inquiries and contact requests;
- contact prospects who requested information;
- assess requirements and prepare proposals;
- execute and administer contracts;
- deliver, operate, and enhance services;
- provide technical support;
- manage billing and payment processing;
- maintain commercial relationships;
- ensure security, auditing, and fraud prevention;
- resolve technical incidents;
- comply with statutory, tax, regulatory, or contractual duties;
- measure website performance and engagement;
- understand traffic acquisition and content effectiveness;
- improve digital user experience and accessibility;
- send commercial updates where a valid legal basis exists;
- maintain records of user consent and preferences;
- establish, exercise, or defend legal rights.
DCP will not use personal data for purposes materially incompatible with those disclosed without securing an appropriate legal basis or authorization when required.
Depending on jurisdiction and context, DCP may rely on one or more of the following legal bases: consent; performance of a contract or pre-contractual measures; compliance with legal obligations; legitimate interests, where applicable and not overridden by fundamental rights; or other lawful bases recognized by applicable legislation.
Where processing relies on consent, the individual may withdraw it at any time where legally recognized, without affecting the lawfulness of processing carried out prior to withdrawal.
DCP may send commercial communications to individuals who requested them, granted explicit consent where required, or maintain a customer relationship permitting such communications under applicable law.
Recipients may opt out of receiving promotional mailings via the mechanism included in each message or by contacting DCP directly. Operational, contractual, security, or support communications may continue where strictly necessary for service delivery.
DCP may share information with vendors strictly necessary to operate its business, such as: hosting and cloud infrastructure; email and messaging; CRM; workflow automation; web analytics; support platforms; storage systems; payment gateways; accounting and billing; video conferencing; authorized artificial intelligence tools; and professional legal advisors.
DCP strives to limit data access to what is strictly required for the designated purpose and enforce appropriate contractual agreements or controls. DCP does not sell personal data to advertisers.
DCP operates through corporate entities and service providers that may be located in Colombia, the United States, or other jurisdictions.
Consequently, personal data may be processed in a jurisdiction other than the individual's country of residence. Where applicable law mandates specific safeguards for international transfers, DCP strives to implement appropriate mechanisms prior to executing the transfer.
For activities subject to the European Union General Data Protection Regulation (GDPR), DCP evaluates and applies adequacy decisions, Standard Contractual Clauses (SCCs), or other legally recognized transfer mechanisms as appropriate.
Pending prior to targeted European commercial launch: formal evaluation regarding requirement of an EU representative, Data Protection Officer (DPO), and specific cross-border transfer mechanisms.
DCP retains information for the period necessary to: fulfill disclosed purposes; maintain contractual relationships; provide ongoing support; meet statutory, tax, or accounting duties; resolve disputes; and maintain reasonable records for security, consent, and audit verification.
When a valid purpose or statutory retention requirement no longer exists, data will be erased, irreversibly anonymized, or restricted as appropriate. Specific timeframes may be documented in internal retention schedules.
DCP implements reasonable administrative, technical, and organizational measures to mitigate risks of loss, alteration, unauthorized access, disclosure, or misuse. Measures include access controls, multi-factor authentication, audit logging, regular backups, environment segregation, secret management, and secure software development practices. No transmission or storage method is completely infallible.
DCP maintains established procedures to evaluate, contain, and remediate information security incidents.
Where an incident triggers statutory notification duties, DCP will provide mandatory disclosures to affected individuals, clients, or supervisory authorities within the applicable statutory timeframes.
Depending on jurisdiction, individuals may hold rights to: know or access their personal data; request correction or updating; request deletion where legally applicable; withdraw consent; object to specific processing operations; request processing restrictions; request data portability; understand how their data is used; and lodge a complaint with a supervisory authority.
Rights vary across legal jurisdictions. DCP responds to requests pursuant to applicable legislation and may request reasonable documentation to verify the identity of the applicant.
DCP does not intend to use data collected through its corporate website to make solely automated decisions that produce legal or similarly significant effects concerning an individual, absent a valid legal basis, transparent notice, and appropriate safeguards.
Where a specific client deployment or proprietary product incorporates automated decision-making logic, its data processing will be evaluated and disclosed separately.
DCP services are directed primarily to businesses and adult professionals. DCP does not intentionally collect personal data from minors through its corporate website. If processing of minors' data is required within an enterprise client engagement, specific safeguards, legal bases, and verified authorizations must be established under applicable laws.
The website may link to third-party services, widgets, or resources. Privacy practices of external websites are governed exclusively by their respective privacy statements.
DCP may amend this Policy to reflect statutory updates, architectural enhancements, or operational changes. The effective version will display its latest revision date.
Privacy requests and rights inquiries may be submitted to info@digitalconsultingplus.com with the suggested subject line: “Privacy / Personal Data”. DCP may request reasonable information to verify the identity and legal authority of the requester.
