Data Protection Policy

(Tour Operator, in compliance with the LODPP Ecuador – Organic Law on Personal Data Protection, 2021)

1. OBJECTIVE

To guarantee the legal, secure, and transparent processing of personal data of clients, suppliers, and collaborators, in compliance with the LODPP (2021) and its Regulations, minimizing risks of unauthorized access, loss, or misuse.

2. SCOPE OF APPLICATION

Applies to all personal data collected through:

  • Web forms, emails, WhatsApp, phone calls, or in-person interactions.
  • Reservations, payments, surveys, contracts, and partnerships with suppliers.
  • Internal systems (CRM, databases, payroll).

3. GOVERNING PRINCIPLES

  • Legality: Data is collected only with prior and informed consent.
  • Purpose: Exclusive use for contracted tourist purposes (e.g., reservations, billing, support, national park registration, transport bookings).
  • Minimization: Only strictly necessary data is collected (e.g., marital status is not requested if irrelevant).
  • Accuracy: Data must be up to date (clients may correct it).
  • Confidentiality: Restricted access to authorized personnel only.

4. TYPES OF DATA PROCESSED

Category Examples Legal Basis
Identification Names, ID/passport, birth date Consent (Art. 9 LODPP)
Contact Phone, email, address Contract execution (Art. 10.2)
Sensitive Allergies, disabilities, health* Explicit consent (Art. 11)
Financial Card details, transfers Legal obligation (billing)

*Only collected if essential (e.g., adventure tours).

5. CONSENT

  • Format:
    • Digital: Checkbox on web forms.
    • Written: Evaluation surveys.
  • Content:
    • Specific purpose (e.g., sending promotions, generating statistics).
    • Right to revoke at any time.

6. DATA SUBJECT RIGHTS

Clients may exercise their ARCO rights via written request to contacto@ecuadorverdepais.com:

  • Access: Know what data is stored.
  • Rectification: Correct inaccurate data.
  • Cancellation: Delete unnecessary data.
  • Objection: Stop use for marketing.
  • Response time: 15 business days (Art. 23 LODPP).

7. SECURITY MEASURES

  • Technical:
    • Database encryption (AES-256) and secure communications (SSL).
    • Strong passwords and multi-factor authentication.
  • Organizational:
    • Annual employee training.
    • Confidentiality agreements with suppliers (e.g., hotels, transporters).
  • Physical:
    • Physical files under lock (e.g., emergency forms on tours).

8. INTERNATIONAL TRANSFERS

External providers (e.g., Booking.com, PayPal, WeTravel) must comply with standards equivalent to the LODPP.
Clients will be informed if their data is stored outside Ecuador (e.g., on U.S. servers).

9. RETENTION AND DELETION

  • Retention Periods:
    • Financial data: 5 years (Art. 85 Tax Code).
    • Contact data: Until consent is revoked.
  • Deletion: Secure methods.

10. INCIDENTS AND NOTIFICATIONS

  • Report to the Superdatur within 72 hours if security breaches affect rights (Art. 30 LODPP).
  • Notify affected parties if risk is high (e.g., sensitive data leaks).

11. RESPONSIBLE PARTY AND CONTACT

12. PENALTIES

Non-compliance may result in:

  • Fines: Up to 1,000 SBU (≈ $4,250 in 2024).
  • Reputational and legal damages.

🔗 Annexes:

  • Consent Form
  • ARCO Rights Exercise Procedure.
  • Record of Processing Activities (Art. 18 LODPP).

“Ecuador Verde País is committed to protecting your data as part of our ethical and legal responsibility.”