Approval date: September 14, 2026

Data Controller: ORG Auditores Independientes, S.A.

1. PURPOSE

The purpose of this Privacy and Personal Data Protection Policy is to establish the principles, criteria, and procedures governing the processing of personal data that ORG Auditores Independientes, S.A. (hereinafter "ORG" or the "Firm") collects, uses, stores, retains, accesses, modifies, discloses, and, where applicable, deletes in the course of its professional and administrative activities.

ORG recognizes the importance of protecting the privacy and personal data of its clients, personnel, service providers, representatives, business contacts, and all other individuals whose data is processed by the Firm.

This Policy is adopted in accordance with the laws of the Republic of Panama governing personal data protection, particularly Law No. 81 of March 26, 2019 on Personal Data Protection and its implementing regulations under Executive Decree No. 285 of May 28, 2021, as well as all other applicable provisions, criteria, and guidelines.

2. SCOPE

This Policy applies to personal data processed by ORG in the course of its activities, regardless of the medium used to collect or store it, including physical and electronic records, accounting and administrative systems, corporate email, technology platforms, forms, contracts, documents provided by clients, the website, and professional or social networks managed by ORG.

This Policy covers, among others, clients and prospective clients; their representatives, shareholders, beneficial owners, and contact persons; personnel and job applicants; suppliers and contractors; business partners; professional contacts; visitors to and users of ORG's digital channels; and any other individual whose personal data is lawfully processed by the Firm.

3. LEGAL AND REGULATORY FRAMEWORK

ORG's processing of personal data will be governed, as applicable, by:

  • Law No. 81 of March 26, 2019 on Personal Data Protection.

  • Executive Decree No. 285 of May 28, 2021, which implements Law No. 81 of 2019.

  • Provisions and criteria issued by the National Authority for Transparency and Access to Information (ANTAI) concerning personal data protection.

  • Other legal and regulatory provisions applicable to ORG's professional activities, including those relating to accounting, tax, employment, commercial, crime-prevention, and other legal obligations.

4. PRINCIPLES GOVERNING THE PROCESSING OF PERSONAL DATA

ORG will process personal data in accordance with the principles established by Panamanian law, including:

  • Fairness: processing must be lawful, transparent, and consistent with the stated purposes.

  • Purpose limitation: data must be collected for specified, explicit, and legitimate purposes.

  • Proportionality: processing must be limited to data that is adequate, relevant, and necessary.

  • Accuracy: data must be accurate, complete, and kept up to date where necessary.

  • Security: reasonable technical, administrative, and organizational safeguards must be implemented.

  • Transparency: clear and accessible information about processing must be provided.

  • Confidentiality: anyone with access to personal data must maintain its confidentiality.

5. PERSONAL DATA ORG MAY COLLECT

Depending on the nature of the relationship and the services engaged, ORG may process identification data; contact information; professional and employment information; financial, accounting, and tax information; contractual and business information; employment information relating to personnel; and data contained in documents provided by clients.

When providing audit, accounting, tax advisory, and legal services, ORG may have access to personal data contained in documents, records, systems, and files provided by its clients. In such cases, ORG will process the data solely within the scope of the contracted services and in accordance with the applicable instructions, legal obligations, and responsibilities.

6. PURPOSES OF PROCESSING

ORG may process personal data to provide audit, accounting, tax advisory, and legal services; manage contractual relationships with clients and suppliers; prepare and submit documents, filings, reports, and applications to authorities; comply with legal, regulatory, tax, employment, and professional obligations; manage billing and collections; manage suppliers and personnel; respond to inquiries; maintain professional communications; manage files and records; protect information security; prevent unauthorized access; manage risks and internal controls; and fulfill other purposes directly related to contracted services or ORG's legitimate activities.

ORG will not use personal data for purposes incompatible with those for which it was collected.

7. LEGAL BASES FOR PROCESSING

Personal data may be processed, as applicable, on the basis of:

  • The data subject's consent.

  • A request made directly by the data subject.

  • The performance or fulfillment of a contractual or business relationship.

  • Compliance with legal or regulatory obligations applicable to ORG Auditores.

  • A legitimate interest permitted by applicable law, provided that the data subject's rights and freedoms do not take precedence.

For newsletters and other promotional communications, information will be used for that purpose only when the individual has requested or authorized receipt of those communications.

8. WEBSITE AND DIGITAL CHANNELS

When ORG collects personal data through its website, electronic forms, social networks, or other digital channels, it will inform the data subject of the purpose and conditions of processing. ORG will also request confirmation that the data subject has read and understood the Privacy Notice and, where applicable, will obtain the data subject's freely given, prior, informed, and express consent to the processing of their personal data.

When an individual uses the forms available at https://orgauditores.com.pa, the data provided is used to receive, respond to, and follow up on the relevant inquiry or request.

Information received through these forms is currently stored using technology infrastructure provided by Hostinger.

Users should avoid including sensitive information or third-party personal information that is not necessary for ORG to respond to their request.

9. NEWSLETTERS AND COMMUNICATIONS

When an individual voluntarily subscribes to ORG's newsletter, their contact information may be processed using EnvialoSimple, the platform used to manage and send those communications.

The individual may stop receiving these communications by using the available unsubscribe options or by directly requesting deletion of their data at: info@orgauditores.com.pa

Unsubscribing will not affect other processing that ORG may be required to continue for contractual or legal reasons, as applicable.

10. WEB ANALYTICS AND COOKIES

ORG uses web analytics tools to gain a general understanding of how its website is used and how it performs.

These tools include Matomo, which is configured to operate without tracking cookies. This information is used to generate statistical metrics such as visits, pages viewed, general traffic sources, and technical browsing characteristics.

ORG does not use these analytics for behavioral advertising or to create commercial profiles of website visitors.

The website's current analytics configuration does not use tracking cookies to identify visitors on a persistent basis.

If technologies requiring non-essential cookies or additional consent mechanisms are introduced in the future, this Policy and the relevant notices will be updated as necessary.

11. TECHNOLOGY SERVICE PROVIDERS AND THIRD PARTIES

ORG may use technology service providers only to the extent necessary to operate its services and fulfill the purposes described in this Policy.

Technology providers currently involved in website-related activities include:

  • Hostinger, for website hosting, storage related to forms, and associated technical services.

  • EnvialoSimple, for managing and sending requested newsletters and communications.

  • Matomo, for statistical measurement and analysis of website use.

The use of these providers does not involve the sale or other commercial exploitation of personal data databases.

ORG will seek to ensure that providers with access to personal data, or that process such data, do so only for the applicable purposes and subject to reasonable confidentiality and security measures.

Some technology providers may operate infrastructure located outside the Republic of Panama. Where personal data is processed or transferred internationally, ORG will seek to ensure that such processing or transfer complies with the requirements and levels of protection established by applicable law.

12. INFORMATION PROVIDED TO DATA SUBJECTS

When ORG collects personal data directly from an individual, it will seek to inform the individual, as applicable, of the identity of the data controller; the data to be collected; the purpose and legal basis for processing; how the data will be used; the data subject's rights and how to exercise them; and any applicable transfers or disclosures.

This information may be provided through contracts, forms, privacy notices, electronic communications, this Policy, or other appropriate means.

13. CONFIDENTIALITY

ORG recognizes that, due to the nature of its professional services, it may have access to confidential information belonging to clients and third parties. Personal data and other confidential information will be processed only by individuals who require access to perform their duties.

Personnel, partners, professionals, contractors, and third parties with access to personal information must comply with the applicable confidentiality obligations.

14. SECURITY MEASURES

ORG will implement reasonable and appropriate administrative, technical, and organizational measures to protect the personal data under its responsibility. These measures may include access controls for systems and records; individual credentials; role-based and need-to-know access restrictions; protection of equipment, systems, and physical documents; backups where appropriate; permission management; controls over the sending and receiving of information; personnel training; and procedures for managing security incidents.

These measures may be updated to address evolving risks, technological changes, and the Firm's needs.

15. EMPLOYEE ACCESS TO INFORMATION

Access to personal data within ORG will be granted on a need-to-know basis. Employees may access only the information necessary to perform their assigned duties.

Personal information may not be used, copied, disclosed, or transferred for purposes other than those authorized by ORG or required by applicable law.

16. RETENTION OF PERSONAL DATA

ORG will retain personal data for as long as necessary to fulfill the purposes for which it was collected and to meet applicable contractual and legal obligations.

The retention period may be extended where necessary to comply with legal or regulatory obligations, respond to requests from authorities, retain evidence of professional services, resolve disputes or claims, exercise or defend legal rights, or comply with document-retention obligations.

At the end of the applicable retention period, ORG will seek to securely delete, anonymize, or otherwise dispose of the data, as appropriate.

17. THIRD PARTIES AND DATA PROCESSORS

ORG may engage service providers or use third-party services that, in certain circumstances, have access to personal information necessary to provide technology, administrative, professional, or other services.

Where applicable, ORG will seek to establish appropriate data-processing, confidentiality, and security obligations by contract. Third parties with access to personal data must use that information only for authorized purposes and in accordance with applicable obligations.

18. DATA TRANSFERS AND DISCLOSURES

ORG may disclose or transfer personal data where necessary to comply with legal obligations, respond to requests from competent authorities, perform contracted services, fulfill contractual obligations, engage service providers or data processors, protect rights or legitimate interests, or fulfill other purposes permitted by applicable law.

Where a transfer or disclosure is subject to specific legal requirements, ORG will seek to satisfy those requirements before carrying it out.

19. DATA SUBJECT RIGHTS

Under applicable Panamanian law, data subjects may exercise the rights recognized by Law No. 81 of 2019 and its implementing regulations, including, as applicable, the rights of access, rectification, cancellation, and objection.

The exercise of these rights is subject to the conditions, exceptions, and procedures established by applicable law.

20. PROCEDURE FOR EXERCISING DATA SUBJECT RIGHTS

Data subjects may submit requests concerning their personal data through ORG's designated contact channels.

A request must contain sufficient information to identify the data subject and enable ORG to reasonably determine the information or processing to which it relates. ORG may request additional information where necessary to verify the requester's identity or properly process the request.

Requests will be handled within the time limits and subject to the conditions established by applicable law.

Contact channel for personal data matters:

Data Controller: ORG Auditores Independientes, S.A.

Email: info@orgauditores.com.pa

Physical address: Avenida Balboa, Bayfront Tower, 1st Floor, Panama City, Panama.

21. SECURITY INCIDENTS

ORG will maintain internal mechanisms to identify, assess, and manage incidents that may compromise the security of personal data.

Where applicable, ORG will take the measures necessary to contain, investigate, and remediate the incident and will provide any notifications to data subjects or competent authorities required by applicable law.

Personnel must promptly report any known loss, unauthorized access, disclosure, alteration, or misuse of personal information.

22. PERSONAL DATA RECEIVED FROM CLIENTS

When providing professional services, ORG may receive personal information from clients contained in accounting, financial, tax, employment, legal, administrative, and commercial documents.

Where ORG processes such data on behalf of a client, the Firm will comply with the applicable instructions and responsibilities under the relevant agreement and applicable law.

Clients should ensure that personal information provided to ORG has been obtained and supplied lawfully and in compliance with their applicable obligations.

23. EMAIL AND DIGITAL MEDIA

ORG may use email, digital platforms, and other technologies to receive, store, and transmit information related to the provision of its services.

Personnel must use ORG-authorized channels and tools and take appropriate measures to prevent unauthorized access to or disclosure of personal information.

24. EMPLOYEE RESPONSIBILITIES

Every ORG employee with access to personal data must:

  • Use information only for authorized purposes.

  • Maintain the confidentiality of information.

  • Refrain from sharing access credentials.

  • Protect physical and electronic documents.

  • Report incidents or suspected unauthorized access.

  • Comply with internal security policies and procedures.

  • Refrain from copying, downloading, transferring, or storing personal information on unauthorized media.

  • Return or delete information, as appropriate, in accordance with internal instructions and procedures.

25. TRAINING AND AWARENESS

ORG will seek to provide its personnel with information and training on personal data protection, confidentiality, information security, proper use of systems and devices, incident prevention, and procedures for handling personal information.

26. POLICY UPDATES

ORG may amend or update this Policy as necessary to reflect legislative changes, new regulatory guidance, changes in the Firm's services or processes, technological developments, emerging risks, or improvements to internal controls.

The current version will be the version approved and published by ORG.

27. ACCEPTANCE AND COMPLIANCE

Personnel and all other individuals subject to this Policy must understand and comply with the provisions applicable to them.

This Policy forms part of ORG's internal information-protection framework and must be interpreted together with the applicable agreements, procedures, information-security policies, and other internal documents.

28. EFFECTIVE DATE

This Policy will take effect on the date of its approval and will remain in force until amended or replaced by a new version.

29. CONTACT INFORMATION

Data Controller: ORG Auditores Independientes, S.A.

Address: Avenida Balboa, Bayfront Tower, 1st Floor, Panama City, Panama.

Telephone: 392-3850

Website: https://orgauditores.com.pa/

Contact channel for personal data requests: info@orgauditores.com.pa

30. APPROVAL

Approved by: ORG Auditores Independientes, S.A.

PRIVACY AND PERSONAL DATA PROTECTION POLICY

Services and Industries

Allinial Global

About us

Contact us

Audit | Accounting | Fiscal | Legal | Taxes | Advisory | BPO

We are part of this prestigious multinational organization.

Organized • Responsible • Managers
-Comprehensive Solutions -

Our advisors are ready to review your case.