Data governance as an operating discipline.
Given the nature of its enterprise technology architecture services, Digital Reset treats data protection as a technical, ethical, and legal obligation.
1. Institutional commitment
DIGITAL RESET, a Reset Corp vertical (the "Firm"), recognizes the protection of personal data as a fundamental right of individuals and as a non-delegable professional obligation. This Policy establishes the institutional framework under which the Firm designs, implements, and oversees the processing of the personal data it receives in the course of its activity.
Given the nature of the enterprise technology architecture services the Firm provides, its professionals routinely access client information systems that contain personal data. The Firm treats this access as a technical and ethical responsibility to be exercised with discipline, traceability, and absolute respect for applicable law.
2. Applicable legal framework
This Policy is aligned with the following regulatory framework of the Republic of Panama:
- Law 81 of March 26, 2019, on the Protection of Personal Data.
- Executive Decree 285 of May 28, 2021, implementing Law 81 of 2019.
- Resolutions and guidance issued by the National Authority for Transparency and Access to Information (ANTAI).
- Sector-specific provisions applicable to the Firm's clients that operate in supervised sectors.
When the Firm provides services to clients in jurisdictions other than the Republic of Panama, it also considers the legal framework applicable in those jurisdictions, including the GDPR when relevant.
3. Governing principles
The processing of personal data at the Firm is governed by the following principles:
- Lawfulness, fairness, and transparency: all processing has an explicit legal basis, is carried out fairly toward the data subject, and is documented transparently.
- Purpose limitation: data is processed only for the specific, explicit, and legitimate purposes declared at the time of collection.
- Minimization: the Firm collects and processes only data that is adequate, relevant, and limited to what is strictly necessary.
- Accuracy: the Firm takes reasonable measures to keep data accurate and up to date.
- Storage limitation: data is retained only for as long as necessary and is deleted or anonymized once the defined periods expire.
- Integrity and confidentiality: the Firm protects data through technical and organizational measures that are reasonable and proportionate to the risk.
- Proactive accountability: the Firm takes responsibility for complying with the above principles and for being able to demonstrate that compliance.
4. Organizational structure for data protection
4.1 Data Protection Officer
The Firm appoints a Data Protection Officer (DPO) whose role is to oversee compliance with this Policy, handle data subject requests, coordinate with the supervisory authority when necessary, and keep the processing inventory up to date. The DPO reports directly to the Partner responsible for the Commercial and Administrative area.
4.2 Technical team
The technical team that carries out client projects receives periodic training on data protection best practices, handling of sensitive information, and incident procedures. Every team member commits to confidentiality as a condition of their engagement with the Firm.
4.3 Data processors
The Firm uses technology providers that act as data processors under written contracts establishing the purposes of processing, the required security measures, and the duty of confidentiality.
5. Categories of data processed
The Firm processes the following categories of personal data:
- Identification and professional contact data of website visitors, sales prospects, and client representatives.
- Data of the Firm's professional team members, in the context of the employment or service relationship.
- Data contained in client information systems that the Firm accesses in the course of contracted projects, subject to the specific clauses of the professional contract.
- Data of the Firm's suppliers and business partners.
The Firm avoids, whenever technically possible, accessing special categories of personal data. When such access is unavoidable, reinforced access control, activity logging, and confidentiality measures are applied.
6. Technical and organizational measures
6.1 Technical measures
- Individual user access control to the Firm's internal systems.
- Multi-factor authentication for systems that process sensitive information.
- Encryption of communications (HTTPS/TLS) and of credentials at rest.
- Periodic backups and verification of their recoverability.
- Activity monitoring and audit logging on critical systems.
- Regular security updates to operating systems and applications.
- Segregation of development, testing, and production environments.
6.2 Organizational measures
- An access policy for classified information based on need to know.
- Confidentiality agreements with all personnel and all providers.
- Periodic team training on data protection and information security.
- An up-to-date inventory of the personal data processing operations the Firm carries out.
- Documented procedures for handling data subject requests.
7. Security incident procedure
The Firm has a documented procedure for responding to incidents affecting the confidentiality, integrity, or availability of personal data:
- Detection and initial logging of the incident.
- Immediate containment to limit its scope.
- Root-cause analysis and risk assessment for data subjects.
- Notification to ANTAI, when the incident poses a significant risk, within the timeframes established by law.
- Notification to affected data subjects, when applicable.
- Implementation of corrective measures to prevent recurrence.
- Internal documentation of the incident and the measures taken.
8. Data subject rights
Anyone whose personal data is processed by the Firm may exercise the rights provided under Law 81 of 2019: access, rectification, cancellation, objection, and portability. Data subjects also have the right not to be subject to automated decisions with significant legal effects without human intervention.
Details of the procedure for exercising these rights are available in the Firm's Privacy Notice.
9. Audit and review
This Policy is reviewed at least once a year, or sooner when relevant regulatory changes occur, when the Firm's services change substantially, or when incidents warrant an earlier review. Reviews are documented, and the Policy is updated with a new version number and effective date.
The Firm may commission external audits of its data protection system when it considers it appropriate or when a client requires it contractually.
10. Effective date and contact
This Data Protection Policy takes effect on the date indicated on the document's cover. Its application is mandatory for all partners, professional team members, and providers of the Firm.
For inquiries or requests related to this Policy: legal@digitalreset.io · C.C. Plaza Paitilla, P.B. Office 25. Panama City, Republic of Panama.