Information Privacy Policy
This document is part of Valtriom's terms of service. If you have questions about its scope, write to us at legal@valtriom.com.
Reference regulatory framework
This policy is part of Valtriom's Quality Management System and is governed by Panamanian personal data protection law.
1. Purpose and Scope
The purpose of this Privacy Policy is to set out the terms and conditions under which Valtriom, in its capacity as Personal Data Controller, collects, processes, stores, transfers and protects the personal information of its clients, providers, strategic partners, website visitors and users of its digital platforms. This document applies to every operation involving the handling of personal data within the territory of the Republic of Panama, as well as to international transfers that, even when carried out outside the country, involve data subjects residing in Panama.
The scope of this policy covers all data processing carried out by electronic, automated or physical means, including, but not limited to, information entered in web forms, electronic communications, service contracts, technical support records and authorized marketing activities. All data processing is guaranteed to be carried out under the principles of loyalty, purpose, proportionality, accuracy, security, transparency, confidentiality, lawfulness and portability, as required by Law 81 of 2019 and its regulations.
2. Data Controller and Contact Details
Valtriom acts as the Controller of personal data, which means it determines the purposes and means of its processing. Our legal address and official contact channels are clearly published on this website and in the contractual documents signed with our clients. All data processing is carried out by duly authorized personnel, under confidentiality agreements and documented security protocols.
The Data Controller has the legal and contractual obligation to implement technical, organizational and administrative measures that ensure a level of security appropriate to the risks of processing. Any inquiry, exercise of rights or complaint related to personal data may be submitted through the channels indicated in the section “Procedure for Exercising ARCO Rights”, ensuring traceability and a response within the established legal deadlines.
3. Free, Express and Informed Consent
Personal data will be collected and processed only when the data subject has given free, prior, express and informed consent, unless the law provides otherwise. This consent will be obtained in a verifiable manner and through mechanisms that make it possible to prove that the data subject understood the purpose and scope of the processing, avoiding ambiguity or tacit consent.
When consent is given together with other terms or conditions, it will be presented prominently and separately, in clear and accessible language, so that the data subject can accept or reject it without undue conditions. Refusing to give consent may limit the provision of certain services that require data processing, but will not affect access to content or features that do not depend on such processing.
4. Specific Purpose of Processing
The personal data collected will be processed exclusively for the specific, explicit and legitimate purposes communicated to the data subject at the time of collection. These purposes include: contract management, the provision of consulting and technical support services, invoicing and collections, handling requests, sending service-related communications, and compliance with legal or regulatory obligations.
Under no circumstances will the data be used for purposes incompatible with or different from those initially communicated, unless new consent is obtained or there is a legal basis for doing so. Any change of purpose will be communicated to the data subject in a timely manner, stating the reason, scope and possible consequences of that change, so they can make an informed decision about whether processing should continue.
5. Principle of Proportionality and Data Minimization
Valtriom guarantees that it will collect only the personal data that is strictly necessary and relevant to the purposes for which it was obtained. Excessive, irrelevant or disproportionate collection will be expressly avoided, as will the processing of sensitive data when it is not essential to provide the service or when the data subject has not expressly authorized it.
To ensure compliance with this principle, internal mechanisms for periodic review of forms, databases and information capture processes will be implemented, removing any fields or records unrelated to the stated purpose. Likewise, anonymization and pseudonymization policies will be established when data is used for statistical, analytical or research purposes, minimizing as much as possible the identification of data subjects.
6. Accuracy and Updating of Data
Valtriom is committed to keeping personal data accurate and truthful, so that it is adequate, relevant and up to date in line with the purposes for which it was collected. The data subject has the right to request the correction, updating or deletion of inaccurate, incomplete or outdated data, and Valtriom will take the necessary measures to handle these requests within the deadlines set by Law 81 of 2019.
Databases will be reviewed periodically to ensure their quality and accuracy, preventing the retention of information that is no longer current or that could be misleading. In all cases, any substantial modification made by the data subject will be documented to preserve the traceability of the processing.
7. Information Security and Confidentiality
The security of personal data is a strategic priority for Valtriom. Appropriate technical, administrative and organizational measures will be applied to prevent the loss, unauthorized access, alteration, destruction or improper disclosure of information. These measures include role-based access controls, encryption of data in transit and at rest, encrypted backups, periodic audits and incident response protocols.
All Valtriom personnel, as well as third parties involved in any phase of data processing, will be subject to contractual confidentiality obligations, the breach of which may result in disciplinary sanctions, civil liability and even criminal liability, under current Panamanian law.
8. Transparency in Processing
Valtriom guarantees that data subjects will receive clear, truthful, complete and easily accessible information about the purposes of processing, the categories of data collected, retention periods, the security measures implemented and the rights to which they are entitled. This information will be made available through this policy, service contracts and specific notices at the time of collection.
In the event of substantial changes to the policy or to the scope of processing, Valtriom will notify data subjects in a timely manner, indicating the changes made and requesting, when necessary, the corresponding consent to continue processing.
9. ARCO and Portability Rights
Data subjects may exercise their rights of Access, Rectification, Cancellation and Objection (ARCO), as well as the right to data portability, at any time and free of charge. These rights will be exercised following the procedure described in this policy, which guarantees traceability, handling within legal deadlines and a formal response to the data subject.
Portability means that, at the data subject's request, Valtriom will deliver their data in a structured, commonly used and machine-readable format, as long as it is technically possible and does not affect the rights of third parties. This process will be carried out with security measures to prevent leaks or alterations during the transfer.
10. Procedure for Exercising Rights
Valtriom provides formal channels for data subjects to submit requests related to their rights: a designated email address, a secure web form or written communication to the company's physical address. Requests must include the identification of the data subject, a clear description of the data covered by the request and the action requested (access, rectification, cancellation, objection or portability).
Once the request is received, Valtriom will acknowledge receipt and begin the process of verifying the requester's identity, and may request additional documentation. A response will be issued within a maximum of 10 business days, as required by regulations, and if the request is denied, the reasons will be duly stated, informing the data subject of the available remedies, including the option of going to the National Authority for Transparency and Access to Information (ANTAI).
11. Right to Be Forgotten and Habeas Data
Valtriom recognizes the right of data subjects to request the deletion or permanent removal of their personal data when it is no longer necessary for the purpose for which it was collected, has expired, or when the data subject withdraws their consent and there is no other legal basis for keeping it. This right will be exercised without prejudice to legal retention obligations that may apply in tax, contractual or regulatory matters.
The procedure for exercising the right to be forgotten will involve verifying the requester's identity and a technical and legal evaluation of the request. Valtriom will delete the data from its systems and, where applicable, notify third parties with whom the data has been shared so that they carry out the corresponding deletion. The exercise of this right is also framed within habeas data as recognized by the Constitution and Panamanian law.
12. Retention Time Limits
Personal data will be kept only for the time strictly necessary to fulfill the purposes for which it was collected. Once those purposes have been fulfilled, Valtriom will securely delete it or irreversibly anonymize it, unless a legal obligation requires it to be kept for an additional period, as in the case of tax rules or industry regulations.
In all cases, Valtriom will set maximum retention periods that do not exceed 7 years, in line with industry best practices and unless the law provides otherwise. Once that period has elapsed, the data will be permanently deleted using technical methods that ensure it cannot be recovered, and this process will be documented in a data destruction log.
13. International Data Transfers
Valtriom may transfer personal data to third parties located in other countries only when they guarantee a level of protection equivalent to or higher than that provided by Law 81 of 2019. Such a transfer may be made on the basis of: (a) the data subject's express consent; (b) the performance of a contract to which the data subject is a party; (c) a legal obligation; or (d) the adoption of standard contractual clauses or binding corporate rules approved by the competent authorities.
Every international transfer will be documented in advance, indicating the destination country, the type of data transferred, the purpose of the processing and the security measures adopted. When using cloud service providers, Valtriom will require them to comply with international standards such as ISO/IEC 27001 and ISO/IEC 27701, as well as audits by independent third parties.
14. Processing without Prior Consent
Law 81 of 2019 establishes that certain data processing may be carried out without the data subject's prior consent, as long as there is a legitimate legal basis, such as the fulfillment of contractual obligations, compliance with a law, the protection of the vital interests of the data subject or another person, or a clearly justified public interest.
Valtriom will apply this exception only in strictly necessary cases and always under criteria of proportionality and minimization. In these cases, the legal justification, the categories of data processed and the measures adopted to protect the information will be documented. In addition, whenever possible and without compromising the purpose of the processing, the data subject will be informed of the existence and scope of such processing.
15. Processing of Data of Minors and Incapacitated Persons
Personal data of minors or legally incapacitated persons will be processed only with the prior and express consent of their legal representatives, except in cases where there is a legal obligation or the processing is necessary to protect a vital interest of the minor or of the incapacitated person.
Valtriom will adopt special measures to ensure that the information of minors and incapacitated persons is collected and processed with an enhanced level of security, including the use of minimization techniques, encryption and stricter access controls. In addition, the use of this data for direct marketing or any other purpose that could harm the rights of the data subject is expressly prohibited.
16. Notification of Security Breaches
Valtriom will implement a formal protocol for managing and reporting security incidents that compromise personal data. If a security breach involving unauthorized access, disclosure, loss, alteration or destruction of data is detected, the incident response plan will be activated immediately, which includes identifying the scope, containing the damage, mitigating risks and keeping a detailed record of the event.
If the breach poses a high risk to the rights and freedoms of data subjects, Valtriom will notify the National Authority for Transparency and Access to Information (ANTAI) within no more than 72 hours, and the affected data subjects within a reasonable time, providing information about the nature of the incident, its possible consequences and the measures adopted to remedy it.
17. Data Protection Officer (DPO)
Valtriom may voluntarily appoint a Data Protection Officer (DPO), responsible for overseeing regulatory compliance in data protection matters, advising on the implementation of technical and organizational measures, and serving as the point of contact between the company, data subjects and ANTAI.
If the law or the nature of operations requires it, appointing a DPO will be mandatory, especially for high-risk processing activities, systematic monitoring of individuals or large-scale processing of sensitive data. The DPO will have functional independence, direct access to senior management and sufficient resources to perform their duties.
18. Record of Processing Activities
Valtriom will keep an up-to-date record of all personal data processing activities under its responsibility. This record will include, at a minimum: (a) the identity and contact details of the controller; (b) the purposes of the processing; (c) a description of the categories of data and data subjects; (d) the domestic and international transfers carried out; (e) retention periods; and (f) the security measures implemented.
This record will be kept available to ANTAI for inspection and audit purposes, and will be reviewed periodically to ensure it accurately reflects the reality of internal data processing. Keeping it will be mandatory for both automated processing and physical records.
19. Compliance Audits and Assessments
To ensure ongoing compliance with this policy and with current law, Valtriom will carry out internal audits and, where applicable, external audits performed by independent consultants. These assessments will review the effectiveness of security measures, the adequacy of procedures, staff training and compliance with deadlines and data subjects' rights.
In addition, when high-risk processing is planned, data protection impact assessments (DPIA – Data Protection Impact Assessment) will be carried out, identifying potential risks and proposing measures to mitigate them before processing begins.
20. Privacy by Design and by Default
Valtriom will adopt the principle of Privacy by Design, ensuring that data protection is built in from the initial conception phase of any system, process or service that involves processing personal data. This includes integrating security measures, anonymization, access control and data minimization from the technical and organizational design stage.
Likewise, the principle of Privacy by Default will be applied, configuring all systems so that, by default, they collect only the data necessary for the specific purpose, without requiring additional actions from the data subject to protect their information. This reduces unnecessary exposure and the risk of misuse.
21. Transfers to Third Parties
Valtriom may share personal data with third parties only when strictly necessary to fulfill the purposes communicated to the data subject and under a protection framework equivalent to that established in Law 81 of 2019. Before any transfer, it will be verified that the third party has adequate technical, legal and organizational measures to guarantee the security and confidentiality of the data.
Every transfer will be documented through a data processing agreement or specific data protection clauses, which will establish, among other things, the prohibition of any use other than the one agreed, the obligation to return or destroy the data at the end of the service, and the duty to report security incidents. Valtriom reserves the right to audit or request documentary evidence of compliance with these obligations.
22. Internal Training and Awareness
Valtriom recognizes that the effective protection of personal data depends largely on the conduct of the people who handle it. Therefore, all employees, contractors and authorized third parties with access to personal data will receive periodic training on applicable regulations, internal policies and best practices in information security and privacy.
These training programs will include practical cases, incident response procedures, guidelines for the secure handling of information and regulatory updates. Attendance and completion of this training will be mandatory and will be documented as part of the compliance evidence in the event of an audit.
23. Measures for Violations and Nonconformities
If a breach of this policy or of applicable law is detected, Valtriom will take immediate corrective measures to contain the risk, investigate the root cause and prevent the incident from recurring. Depending on the severity, these measures may range from retraining the staff involved to terminating contracts or imposing disciplinary sanctions.
When the violation comes from a third-party processor, Valtriom will require corrective actions to be carried out and, if necessary, will terminate the contract and notify the competent authorities. Every incident and its resolution will be documented in an internal control log.
24. Complementary Legal Framework
In addition to Law 81 of 2019 and its Executive Decree 285 of 2021, Valtriom will comply with all legal and regulatory provisions applicable to the industry and the nature of the services provided. This includes, among others, the regulations of the Superintendency of Banks of Panama, tax and commercial laws, as well as international information security standards such as ISO/IEC 27001 and ISO/IEC 27701.
In the event of a conflict between this policy and a mandatory legal provision, the legal provision will prevail, without this implying a waiver of the privacy guarantees and commitments assumed by Valtriom.
25. Legal Penalties for Non-Compliance
Failure to comply with the obligations set out in Law 81 of 2019 may result in penalties imposed by ANTAI ranging from fines to orders suspending data processing, without prejudice to any other civil or criminal liability that may arise.
Valtriom warns that any person or third party who handles personal data on its behalf and fails to comply with these provisions will be accountable for their actions before the authorities and the data subjects, and Valtriom may seek recovery from them for any damage or fine imposed on it as a result of that non-compliance.
26. Policy Update Mechanisms
Valtriom will review and update this Privacy Policy periodically or when significant changes occur in the law, in internal data processing procedures, or in the technologies used that could affect the protection of information. Updates will take effect upon publication on the website or direct communication to the data subject, as applicable.
If the modification involves a substantial change in the purposes of processing or in the conditions originally accepted by the data subject, their consent will be requested again, unless there is another legal basis that allows processing under the new conditions. Previous versions of this policy will be kept on file for traceability and audit purposes.
27. Contact Channels for Exercising Rights
For inquiries, complaints or requests related to the processing of personal data, the data subject may contact Valtriom through the following official channels:
- Email address designated exclusively for data protection.
- Secure web form available on our official website.
- Written communication addressed to Valtriom's legal address.
Every communication received through these channels will be logged, assigned to an internal owner and handled within the deadlines established by law. The traceability of each case will be guaranteed until its final resolution.
28. Links and Regulatory References
To ensure transparency and make information easier to access, Valtriom makes the following regulatory references available to data subjects:
- Law 81 of March 26, 2019 on Personal Data Protection.
- Executive Decree 285 of May 28, 2021, which regulates it.
- Guidelines and criteria issued by the National Authority for Transparency and Access to Information (ANTAI).
These documents can be consulted online through the official websites of the National Assembly and ANTAI, or requested directly from Valtriom in digital format.
29. Final Provisions
This policy is an integral part of the general terms and conditions of use of Valtriom's services. Its interpretation and application will be governed by the laws of the Republic of Panama, and any dispute arising in connection with it will be submitted to the jurisdiction of the country's competent courts.
If any provision of this policy is declared invalid or unenforceable by a competent authority, the remaining clauses will remain in full force and effect, and will be interpreted in a way that respects the purpose of personal data protection that inspires it.
30. Acceptance by the User
Use of this website, as well as contracting any service offered by Valtriom, implies full and unreserved acceptance of this Privacy Policy in the version published and in force at the time of such use or contracting.
The data subject declares that they have read, understood and accepted the terms set out here, acknowledging that the consent given was free, express and informed, and that they are aware of their rights and obligations under Law 81 of 2019 and other applicable regulations.