The data, with the rules of the registro
Recipient in plain sight, purpose declared and nothing published that should not be. This policy states what is collected, for what purpose, how long it is kept and how rights are exercised, in the same language as the rest of the site.
- LEGAL ENTITY
- INTERNATIONAL ACCREDITATION CENTER LATAM S.A.
- CUIT (Argentine Tax ID)
- 30-71770883-7
- TAX ADDRESS
- Lanús, Province of Buenos Aires, Argentina
- FORUM
- Ordinary Courts of Lomas de Zamora, Province of Buenos Aires, Argentina
- ARGENTINA
- Law 25,326 on Personal Data Protection
- ARGENTINA
- Applicable resolutions of the AAIP
- EUROPEAN UNION
- EU General Data Protection Regulation 2016/679 (GDPR)
- BRAZIL
- Lei Geral de Proteção de Dados 13,709/2018 (LGPD)
- MEXICO
- Federal Law on Protection of Personal Data Held by Private Parties
- OTHER COUNTRIES
- Equivalent regulations where G-CERTI provides services
This translation is for informational purposes only. The Spanish version prevails.
Quién sostiene el service
Each row lists the processor, the service it provides and the country from which it provides it. International transfers are made to countries with an adequate level of protection or under Standard Contractual Clauses.
- Ferozo
- Server hosting
Argentina
- Cloudflare
- CDN / DNS / WAF
USA (international transfer)
- Stripe
- International payment processing
EE.UU. / UE
- Mercado Pago
- LATAM payment processing
Argentina + LATAM
- Microsoft 365
- Email and internal collaboration
EE.UU.
- Anthropic / OpenAI
- Digital assistant backend (AI)
EE.UU.
The clauses, in order
Data controller
INTERNATIONAL ACCREDITATION CENTER LATAM S.A. (hereinafter, G-CERTI or the Body) is the controller responsible for the personal data collected through the gcerti.org website, the client portal, G-CERTI Formación and all the services provided, in accordance with the applicable legislation:
- Law 25,326 (Argentina) — Personal Data Protection
- Applicable resolutions of the Agency for Access to Public Information (AAIP) — Argentina
- EU General Data Protection Regulation 2016/679 (GDPR), when data of European Union residents is processed
- General Data Protection Law 13,709/2018 (LGPD) — Brazil
- Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) — Mexico
- Equivalent regulations in other countries where G-CERTI provides services
Data we process
G-CERTI processes different categories of personal data depending on the role of the data subject:
- Website visitors: browsing data (IP, browser, operating system, pages visited), cookies (see separate policy), information from contact forms
- People in the inquiry or enrollment process: full name, email, phone, company or institution, position, standard of interest
- Clients in a contractual relationship: company name, tax ID, address, legal representatives' data, key personnel, information on the audited management system
- G-CERTI Formación students: identification, contact, academic and payment data, evaluation results
- Auditors: professional and academic data, qualification and evaluation documentation
- Internal personnel: labor data in accordance with applicable labor legislation
Purposes of processing
G-CERTI processes data for the following specific and limited purposes:
- Provision of the certification service (audits, decisions, issuance of certificates, surveillance)
- Academic training (Diploma programs, courses, workshops)
- Communication with clients and prospects about G-CERTI's services (with explicit consent for non-transactional campaigns)
- Compliance with legal obligations (tax, accounting, regulatory)
- Communication with IAS and competent authorities within the accreditation framework
- Internal management of auditors and personnel
- Anonymized statistics for service improvement
Legal basis for processing
Depending on the purpose, G-CERTI applies one of the following legal bases:
- Performance of a contract: clients in process or certified, students
- Compliance with legal obligations: tax records, ISO/IEC 17021-1 requirements
- Legitimate interest of the Body, balanced with the data subject's rights: anonymized statistics, security
- Explicit consent of the data subject: newsletters, non-transactional campaigns, optional cookies
Disclosure to third parties
G-CERTI shares personal data only in the following limited situations and always under confidentiality agreements:
- To IAS and accreditation authorities, within the framework of G-CERTI's accreditation process
- To vendors that provide services to G-CERTI (hosting, email, payments), under a confidentiality agreement and limited to the purpose of the service
- To competent authorities when required by law
- Inclusion in the public directory of certified clients: with the client's explicit consent
Retention period
G-CERTI retains personal data for the time strictly necessary for the stated purposes:
- Certified clients' data: for the duration of the relationship + 6 years from closure (decision and audit records)
- Students' data: for the duration of the relationship + 10 years (academic obligations)
- Auditors' data: for the duration of the relationship + 5 years
- Prospects' and visitors' data: until consent is withdrawn or 24 months from the last contact
- Accounting and tax data: in accordance with applicable tax legislation
Rights of the data subject
The data subject can exercise the following rights over their personal data at any time:
- Access to their personal data processed by G-CERTI
- Rectification of inaccurate or outdated data
- Erasure (right to be forgotten), with applicable legal limitations
- Objection to processing when there is a legitimate reason
- Restriction of processing
- Portability of their data in a structured format (when technically applicable)
- Withdrawal of consent given for specific purposes, without retroactive effects
Security measures
G-CERTI applies appropriate technical and organizational measures to guarantee the security of the personal data processed:
- Encryption in transit (HTTPS, TLS 1.3) and at rest (database and backups)
- Role-based access control with the principle of least privilege
- Auditing of access to sensitive information
- Encrypted backups with geographic replication
- Confidentiality agreements with all personnel and vendors
- Documented security incident response plan
- Security management system aligned with ISO/IEC 27001
Data breaches
In the event of a security incident affecting personal data, G-CERTI proceeds according to a documented protocol:
- Notification to AAIP within 72 hours when applicable (Law 25,326 / GDPR as applicable)
- Notification to affected data subjects when the risk to their rights and freedoms is high
- Documented internal investigation with root cause analysis
- Implementation of corrective and preventive measures
Record of academic credentials and professional profiles
G-CERTI Formación maintains an institutional record of the academic credentials it issues, designed under information security management and personal data protection principles, taking ISO/IEC 27001 and ISO/IEC 27701 as reference. The record and the publication of profiles are separate spaces:
- Institutional record (authenticity verification): processes the minimum data necessary to verify a credential — holder, program, standard, date, code, status, issuing entity and history of modifications. Legal basis: performance of the academic relationship. Being included in the record does not publish personal data.
- Public professional profile: it is voluntary and requires express, informed and field-by-field specific consent from the holder (photograph, location, specializations, languages, experience, sectors, availability, contact). Consent is revocable at any time, affecting what has been published.
- Public verification confirms the authenticity, scope, date and status of the document. It does not communicate current professional competence or professional categories.
- If the holder does not grant publication authorization, no data from their profile is made public.
Formularios de solicitud de información
Los formularios del sitio —solicitud de información de una diplomatura, contacto, pedido de propuesta, orientación y actualización de registro— tratan únicamente los datos que la persona escribe y los mínimos de ruteo y seguridad necesarios para responder:
- Datos que se piden: nombre, correo electrónico, teléfono cuando la consulta lo requiere, país u organización cuando corresponde, la norma o el programa de interés y el comentario que la persona escribe. Ningún formulario pide datos sensibles ni documentación de identidad.
- Datos técnicos de ruteo: la página de origen, el identificador del formulario, la validación antiabuso de Cloudflare y un número de ticket generado en el envío. El ticket es el que se cita en toda la conversación posterior.
- Finalidad: responder la consulta, orientar sobre el servicio o programa y dejar registro de la solicitud. No se usan para publicidad ni se ceden a terceros con fines comerciales.
- Base legal: consentimiento de la persona al enviar el formulario y, cuando ya existe relación, ejecución de esa relación. El consentimiento se retira escribiendo a info@gcerti.org.
- Dónde quedan: en la infraestructura de G-CERTI, cifrados en tránsito, accesibles sólo para el personal autorizado que atiende consultas mediante un panel interno con acceso nominado. Se conserva el historial de las respuestas enviadas.
- Plazo de conservación: hasta 24 meses desde el último contacto, o el plazo contractual aplicable si la consulta deriva en una relación de servicio.
Changes to this policy
G-CERTI periodically updates this policy to reflect changes in legislation, in the services offered or in processing practices. Previous versions remain archived and available upon request. Substantive changes are notified to data subjects 30 days in advance when possible. Continued use of the services after the publication of changes constitutes acceptance of the updated policy.
Exercise a right
Access, rectification, erasure, objection, restriction, portability and withdrawal of consent are requested in writing to the controller, with a copy of identification.
G-CERTI responds within 10 business days of receipt of the request. If the response is not satisfactory, the complaint proceeds before the AAIP in Argentina or before the supervisory authority of the data subject's country of residence.