Privacy Policy
Information about how personal data is processed and protected.
This English text is provided for information. The contract is governed by Argentine law and the Spanish version is the one that binds, under clause 32.1. Read the binding Spanish version
1 Controller and scope
1.1 This Privacy Policy describes how Sitios Hispanos SRL, CUIT 30-71181720-0, hereinafter “SitiosHispanos.Com”, processes personal data. It forms part of the General Terms and Conditions of Service in accordance with their section 2.
1.2 It applies to the website, the client area, the ticket system, the contracting, billing and support processes, and communications connected with the services.
1.3 It does not apply to the content the Client hosts on their own services. That processing is governed by section 4 of this Policy and by section 19 of the Terms.
1.4 Processing is governed by Personal Data Protection Law 25,326, its implementing rules and the regulations issued by the Agency for Access to Public Information.
2 Data we process
2.1 Account and identification data: name and surname or corporate name, CUIT or CUIL where applicable, address, email address, telephone number and country. This is obtained from the data subject when registering or contracting.
2.2 Contracting and billing data: contracted services, plan, period, currency, price, taxes, orders, proforma invoices, tax receipts and VAT status. Tax receipts are issued to ARCA, the Argentine revenue and customs authority, in accordance with the legislation in force.
2.3 Payment data: the payment method chosen and the status of the transaction. Full card, bank account or CBU details are entered into and processed directly by the relevant payment processor. SitiosHispanos.Com does not store card security codes under any circumstances. Where a payment method is saved for future transactions, an encrypted identifier provided by the processor is retained and, depending on the case, the last digits and the expiry date — data that identify the method but do not allow it to be reconstructed or used outside that gateway.
2.4 Technical and security data: IP address, date and time of access, session identifier, browser and operating system, authentication logs and records of actions performed within the account. These are recorded to operate the service and to evidence the traceability provided for in section 4.5 of the Terms.
2.5 Support data: the content of tickets, attachments, screenshots and any information the Client provides to diagnose an incident. The Client should avoid including passwords or unnecessary sensitive data.
2.6 Domain data: that required by the registry or registrar for a registration, renewal or transfer, including the registrant, administrative, technical and billing contacts.
2.7 Sensitive data within the meaning of Law 25,326 is not requested. If a data subject provides it spontaneously in a ticket, it will be processed solely to resolve the query and deleted once it is no longer necessary.
3 Purposes and legal bases
3.1 Performing the contract: setting up, providing, maintaining, renewing, suspending or cancelling the services, and providing support. Legal basis: the contractual relationship and the consent given on accepting the Terms.
3.2 Complying with legal obligations: issuing and retaining tax receipts, accounting records, responding to requests from a competent authority, and obligations imposed by domain name registries.
3.3 Security and fraud prevention: protecting accounts, detecting unauthorised access, investigating incidents, preserving evidence and containing risks to the platform or to third parties.
3.4 Operational communications: expiry notices, proforma invoices, maintenance, security incidents and contractual changes. These communications are inherent to the service and do not constitute advertising.
3.5 Commercial communications: sent only with prior and separate consent. Each message includes a mechanism to withdraw it, and withdrawal takes effect at no cost. Withdrawing consent does not affect the provision of the contracted services.
3.6 Data is not used for automated decisions producing legal effects on the data subject, nor to build profiles for that purpose.
4 Data hosted by the Client
4.1 With respect to personal data the Client hosts on their services — databases, mailboxes, files, applications — the Client determines the essential purposes and means and acts as controller. SitiosHispanos.Com acts as processor or infrastructure provider.
4.2 SitiosHispanos.Com accesses that content only where necessary to provide, secure, back up, restore or support the service, to comply with a valid order from a competent authority, or where the Client requests it in a ticket. Such access is logged.
4.3 The Client is responsible for having a legal basis, for informing data subjects and for applying appropriate measures to the data they host, in accordance with section 19.3 of the Terms.
4.4 Where the Client hosts personal data of their own or of third parties, the Data Processing Agreement published at https://www.sitioshispanos.com/en/legal/data-processing-agreement applies. It specifies the subject matter, nature and duration of the processing, documented instructions, staff confidentiality, security measures, location and transfers, assistance with data subject rights, incidents, return or deletion on termination, and reasonable audits. That agreement forms part of the contract and may be accepted electronically.
5 Recipients and providers
5.1 The following categories of recipient are involved in providing the services:
- payment processors, which handle the data needed to collect payment: Pagos360, MercadoPago, PayPal and dLocal Go, each under its own policy;
- banks, where payment is made by transfer;
- domain name registries and registrars, including NIC Argentina and ICANN-accredited intermediaries;
- the campaign delivery provider, solely for those who contract the email marketing service;
- ARCA, for issuing tax receipts; and
- professional advisers and competent authorities, where an obligation exists or a right is to be exercised.
5.2 Hosting is provided on infrastructure owned by SitiosHispanos.Com and under its control: the data the Client hosts is not handed to a third party to process on behalf of SitiosHispanos.Com. The recipients listed take part in specific operations — collection, domain registration, invoicing — and not in the hosting itself.
5.3 Personal data is not sold or transferred for third-party advertising purposes.
5.4 The contact details for a domain name may be published or communicated to the relevant registry under the policies governing that extension, over which SitiosHispanos.Com has no decision-making power.
6 International transfers
6.1 Some of the recipients listed in section 5 may be located outside the Argentine Republic. In that case the communication is carried out under articles 11 and 12 of Law 25,326, with the contractual clauses or safeguards that may be required.
6.2 The content the Client hosts remains on the infrastructure of SitiosHispanos.Com. Its location is disclosed before contracting and on a material change, at the Client’s request by ticket.
7 Retention periods
7.1 Account and contracting data is retained for as long as the relationship remains in force.
7.2 Tax receipts and accounting records are retained for the periods set by the applicable tax and commercial legislation.
7.3 Hosted content is governed by the retention windows in section 25 of the Terms: fifteen calendar days for web hosting and application hosting, and seven calendar days for cloud, VPS and dedicated servers, counted from suspension for expiry.
7.4 Technical, security and processing records are retained for the following periods, counted from their creation unless otherwise stated:
| Category | Retention period |
|---|---|
| Web and security logs | 12 months |
| Authentication history | 12 months |
| Administrative access logs to content | 24 months |
| Support tickets and attachments | 5 years from closure |
| Abuse reports and their handling | 5 years from resolution |
| Evidence of acceptance and contract version | 10 years from the end of the relationship |
| Tax receipts and accounting records | 10 years |
| Backups | The plan window, under section 15 of the Terms |
7.5 Once the periods have elapsed, data is deleted or retained only to the extent strictly necessary for invoicing, defence of rights, fraud prevention or legal compliance, with restricted access.
7.6 Once those periods have elapsed the records are deleted or aggregated so that they no longer identify the data subject. SitiosHispanos.Com maintains an internal retention matrix with the operational detail; it is not published at a level of granularity that could compromise security.
8 Data subject rights
8.1 Data subjects may exercise their rights of access, rectification, updating and deletion of their personal data, under Law 25,326.
8.2 Requests are submitted to privacidad@sitioshispanos.com, the dedicated data protection channel, or by ticket at https://www.sitioshispanos.com/submitticket.php. Only a reasonable and proportionate identity verification will be required, intended exclusively to prevent a third party from accessing another person’s data.
8.3 Access is free of charge at intervals of no less than six months, unless a legitimate interest is demonstrated. The information is provided within ten calendar days. Rectification, updating or deletion is resolved within five business days.
8.4 Deletion may not be complete where a legal retention obligation exists, particularly in respect of tax receipts. In that case the data retained, the grounds for retaining it and the period will be stated.
8.5 The Agency for Access to Public Information, as the enforcement authority for Law 25,326, is empowered to hear complaints and claims brought in relation to non-compliance with personal data protection rules.
9 Security
9.1 SitiosHispanos.Com applies technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure: encryption in transit, access control on least privilege, logging of administrative access, segmentation, backup and updating of the components under its responsibility.
9.2 Account passwords are stored using non-reversible derivation functions. SitiosHispanos.Com does not request the full account password by email, in accordance with section 5.3 of the Terms.
9.3 No system is invulnerable. In the event of a security incident affecting personal data, SitiosHispanos.Com will take containment measures, inform affected data subjects where appropriate, and comply with any applicable notification obligations.
9.4 Security of the layers administered by the Client — self-managed operating system, applications, CMS, plugins, own credentials — is the Client's responsibility under section 16 of the Terms.
9.5 The security and confidentiality obligations that articles 9 and 10 of Law 25,326 impose on SitiosHispanos.Com are not transferred to the Client. Section 9.4 delimits which layers each party administers, but does not release SitiosHispanos.Com from the measures incumbent on it in respect of the infrastructure and the data under its control.
10 Cookies and similar technologies
10.1 The site uses a technical session cookie, necessary to keep the session open in the client area and to retain the selected language and currency during the visit. Without it, signing in and completing a purchase are not possible.
10.2 Public forms use Google reCAPTCHA v3 to distinguish a person from an automated program. It is active on the domain checker, account registration, the contact form, ticket submission and password reset. It is not loaded on pages that do not contain those forms. That service assesses interaction with the page and processes the IP address under Google’s policies.
10.3 The site does not use analytics, advertising, cross-site tracking or profiling cookies. Should any be introduced in future, prior consent will be requested through a mechanism allowing them to be accepted or refused separately, and this Policy will be updated before they are activated.
10.4 Data subjects may delete or block cookies from their browser. Blocking technical cookies prevents signing in and completing a purchase.
11 Minors
11.1 The services are aimed at persons with the capacity to contract. They are not offered or marketed to minors and their data is not deliberately collected.
11.2 If it is found that a minor's data has been registered without proper representation, it will be deleted once the situation has been verified. This may be reported through the channels in section 8.2.
12 Term, changes and version
12.1 This Policy may be updated to reflect regulatory, technical or provider changes.
12.2 Material changes affecting purposes, recipients, retention periods or rights will be notified individually at least thirty calendar days in advance, following the procedure in section 28 of the Terms. Corrections that do not alter meaning are published with the version and date indicated.
12.3 The applicable version is the one identified at the foot of this document. SitiosHispanos.Com keeps an accessible history of versions.