Skip to content

INSTITUTIONAL POLICIES

Privacy, Security and Payment Policies

A single policy for the digital services of the Ibero-American Institute of Technology, the 2026 Symposium, its registration process and ITECH Editorial.

Version 1.1 Last updated: September 9, 2026

Responsible entity: FUNDACIÓN INSTITUTO IBEROAMERICANO DE TECNOLOGÍA (ITECH) CUIT: 30-71894409-7 Address: Bernardo de Irigoyen 546, Floor 9, Office “A”, Autonomous City of Buenos Aires, Argentina General and privacy contact: info@institutotech.com

1. Purpose, scope and covered sites

These Privacy, Security and Payment Policies provide a unified framework for the processing of personal data, the general security measures that apply, and the payment conditions of the digital services managed by ITECH.

This page applies, as relevant to each service, to:

  • https://institutotech.com/
  • https://institutotech.com/simposio-2026/
  • https://institutotech.com/inscripcion-simposio-2026/
  • https://institutotech.com/editorial/

It may also apply to forms, platforms, accreditation systems, communications and future digital features managed by ITECH, provided that they expressly refer to this policy.

The payment rules apply only when a website, activity, publication, product or service has an enabled contracting or payment mechanism. At present, they apply especially to registration for the ITECH 2026 Symposium.

When an activity or service establishes specific conditions, those conditions will supplement this policy and will be disclosed to the user before contracting or making payment. No specific condition may be interpreted as a waiver of non-waivable rights recognized by applicable law.


PART I — PRIVACY POLICY

2. Data controller

The entity responsible for the personal files, records and databases covered by this policy is:

FUNDACIÓN INSTITUTO IBEROAMERICANO DE TECNOLOGÍA CUIT 30-71894409-7 Bernardo de Irigoyen 546, Floor 9, Office “A” Autonomous City of Buenos Aires, Argentina Email: info@institutotech.com

3. Personal data ITECH may collect

Depending on the service used, ITECH may collect the following categories of information:

3.1. Identification and contact data

First name, last name, type and number of identification document, date of birth, age, email address, telephone number, country, province or state, and other data necessary to identify or contact the user.

3.2. Professional and academic data

Institution, company, university, position or activity, educational institution, degree program or course of study, and other information related to institutional, professional, academic or student participation.

3.3. Symposium registration data

Registration category and format, group members, person responsible for the registration, registration status, data required to validate special categories, order identifiers, payment status, invoicing status, credentials, and data required to generate communications and individual QR codes.

When a student category is selected, ITECH may request information or documentation reasonably necessary to verify the declared status. Validation may be performed manually before payment of the applicable fee is enabled.

3.4. Invoicing data

When the user requests an invoice or receipt with customized tax information, ITECH may collect name or business name, country, CUIT, CUIL, Tax ID or other tax identification, tax status, tax address, town or city, province or state, postal code, and billing email address.

The information requested from the user does not by itself determine the tax classification of the document. Issuance and classification will be carried out in accordance with ITECH’s administrative and accounting procedures and applicable law.

3.5. Payment data

ITECH may retain data related to a transaction, such as order number or reference, amount, currency, payment method, exchange rate applied when relevant, transaction status, identifiers provided by the payment processor, and records required for reconciliation, control and auditing.

ITECH does not store complete credit or debit card numbers or CVV/CVC security codes. When payment is processed by an external provider, certain data will be processed directly by that provider under its own terms and policies.

For bank transfers, ITECH may retain the order reference, amount, currency, verification status and the proof of transfer submitted by the user. Uploading proof of transfer does not by itself constitute confirmation that funds have been credited.

3.6. Accessibility data

ITECH may optionally request limited information regarding accessibility arrangements or support required to participate in an activity or service.

Participants will not be asked to disclose diagnoses, illnesses, medical records or other medical information when such information is not necessary. When a free-text accessibility field is available, only the requested accommodation or support should be provided.

If a person voluntarily includes health-related information, ITECH will process it with restricted access and solely to manage the stated need, for the period reasonably necessary for that purpose, unless a different legal obligation applies.

3.7. Editorial data

ITECH Editorial may receive author data, institutional affiliations, contact information, manuscripts, editorial proposals, background information and other documentation voluntarily submitted as part of its editorial processes.

3.8. Technical and security information

Systems may record IP address, date and time, technical identifiers, audit events, error information, access attempts and other records required for operation, security, fraud prevention and diagnostics.

4. Purposes of processing

ITECH may use personal data to:

  • respond to inquiries and manage institutional relationships;
  • administer individual and group registrations;
  • verify registration categories when applicable;
  • calculate fees and generate orders;
  • manage payments, transfers and reconciliations;
  • manage invoicing requests and invoicing data;
  • issue or manage tax documents through the applicable administrative processes;
  • organize in-person or virtual participation;
  • generate participant credentials and QR codes;
  • provide the minimum information required by external accreditation systems;
  • distribute access to videoconferencing platforms when applicable;
  • administer editorial processes and publication proposals;
  • send operational communications required to provide the service;
  • prevent fraud, unauthorized access, abuse and other incidents;
  • maintain audit and security records;
  • comply with legal, tax, accounting and contractual obligations; and
  • improve the operation, security and user experience of digital services.

5. Mandatory and optional data

Each form will identify mandatory and optional fields. Refusal to provide mandatory data may prevent registration, validation, contracting, payment, accreditation, invoicing, publication or another procedure when that data is required to carry out the request.

Optional data may be omitted without preventing access to the service, unless it later becomes necessary to address a specific request from the user.

6. Consent and other grounds for processing

Where applicable, ITECH will request prior, informed and specific consent. Certain processing activities may also be necessary to perform a contractual, professional or institutional relationship, respond to a request from the data subject, comply with legal obligations or protect system security.

Authorization to receive promotional communications will be separate from the acceptance required to manage a registration or service. Refusing promotional communications will not prevent completion of a registration or receipt of essential operational messages.

7. Symposium accreditation and QR codes

In-person accreditation may be managed through an external application or service. ITECH will share only the information necessary for that purpose.

The planned accreditation architecture provides that the individual QR code and/or integration interface may include: first name, last name, email address, institution, position or activity, educational institution, and registration category.

Information intended for accreditation must not include, unless legally required or subject to a previously disclosed change, DNI or passport number, telephone number, date of birth, accessibility data, tax data, banking information, card numbers or private system credentials.

Technical access to accreditation data must be limited to authorized systems and persons.

8. Providers and third parties

ITECH may use technology and professional service providers to the extent necessary to provide its services, including hosting and infrastructure, email, payment processing, banking services, videoconferencing, technical support, invoicing, accreditation and other specialized services.

For the 2026 Symposium, the use of Mercado Pago for certain payments, Banco Galicia for certain transfers in U.S. dollars, and Zoom for virtual activities is contemplated, among others. The providers actually used may vary and will be disclosed, where appropriate, within the relevant service flow.

Third parties receiving personal data must process it within the applicable purpose and in accordance with applicable law and the relevant contractual obligations.

9. International transfers

Some technology providers may provide services using infrastructure located outside the Argentine Republic. When a transaction involves an international transfer of personal data, ITECH will seek to use providers, jurisdictions, contractual clauses or other mechanisms permitted by applicable Argentine law.

10. Data retention

ITECH will retain data for as long as necessary for the purpose for which it was collected and for any additional periods arising from legal, tax, accounting, contractual, security or legal-defense obligations.

When information is no longer necessary and there is no obligation or legitimate interest justifying its retention, it may be deleted, anonymized or subject to another mechanism compatible with applicable law.

Documentation used solely to validate a registration category will be retained for the period reasonably necessary to resolve and audit that validation, unless a different obligation applies.

11. Communications

ITECH may send operational communications related to inquiries, registrations, payments, validations, invoicing, accreditation, virtual access, status changes, activities and editorial processes.

Promotional or institutional communications that are not essential to providing a service will, where applicable, include consent and unsubscribe mechanisms. Acceptance of commercial communications will not be a condition for completing a registration when they are not necessary to provide the requested service.

12. Cookies and similar technologies

ITECH websites may use cookies or other technologies that are strictly necessary for security, authentication, operation and preservation of preferences.

If ITECH implements analytics, advertising or third-party technologies requiring additional information or consent, it will disclose their use and enable the appropriate preference-management mechanisms in accordance with applicable law.


PART II — SECURITY POLICY

13. General security principles

ITECH will implement reasonable technical and organizational measures proportionate to the nature of the information and the risks of each system, with the aim of reducing risks of unauthorized access, modification, loss, disclosure, destruction or processing.

Depending on the service, these measures may include:

  • access controls and separation of privileges;
  • authentication and authorization of administrative users;
  • encryption of selected data and protection of credentials;
  • server-side validations;
  • private storage of sensitive files;
  • event logging and auditing;
  • fraud and abuse controls;
  • backups and recovery procedures;
  • component updating and maintenance;
  • review of permissions and access rights; and
  • incident management procedures.

ITECH avoids publishing operational details, secrets, keys, internal configurations or information that could reduce the effectiveness of its security controls.

14. Payment security

ITECH will not store full card numbers or CVV/CVC codes. Private credentials used for payment integrations must not be exposed in public forms or in the user’s browser.

Payment confirmations received from external providers will be verified through server-side mechanisms before a transaction is considered definitively approved. ITECH may apply validations, reconciliations, audit logs and anti-fraud controls before confirming a registration.

Proofs of bank transfer uploaded to the platform must be stored in protected locations with access restricted to personnel authorized to verify the transaction.

15. Accreditation and virtual-access security

Integrations with external accreditation applications must use authentication or authorization mechanisms and provide only the minimum data intended for that function.

Access to virtual sessions may be personal. When ITECH so indicates, it must not be shared with third parties. ITECH may revoke or replace credentials when it detects exposure, misuse or a security risk.

16. Responsibility and limitations

No Internet-connected system can guarantee absolute security. ITECH will apply reasonable measures to prevent and manage incidents, but it cannot guarantee the complete absence of risks arising from technical failures, third-party attacks, unknown vulnerabilities or events outside its reasonable control.

Users must provide accurate information, protect personal access credentials or links they receive, and avoid sharing credentials or codes intended for individual use.


PART III — PERSONAL DATA RIGHTS

17. Rights of the data subject

The data subject may request information about their personal data and, where applicable, exercise the rights of access, rectification, updating, deletion or confidentiality recognized by Law No. 25,326 and supplementary regulations.

Requests may be sent to info@institutotech.com. ITECH may apply reasonable mechanisms to verify the identity of the requesting person before disclosing, modifying or deleting information.

In accordance with Law No. 25,326, access requests must be answered within ten (10) calendar days, and requests for rectification, updating or deletion within five (5) business days, where applicable.

Deletion may not apply where there is a legal obligation to retain the information or where deletion could affect the rights or legitimate interests of third parties, without prejudice to the rights of the data subject.

18. Supervisory authority

The Agencia de Acceso a la Información Pública (AAIP) is the enforcement and supervisory authority for Law No. 25,326 and receives complaints and claims related to personal data protection.

ITECH will evaluate, process and keep up to date any registrations of personal databases that are legally required before the competent authority.


PART IV — PAYMENT POLICY

19. Scope of the payment policy

This policy governs payments made to ITECH through its websites, platforms and digital services when a contracting or payment mechanism is enabled.

At present, it applies especially to the registration and payment system for the ITECH 2026 Symposium. The institutional and editorial sites are covered by this part only if they enable paid products or services in the future.

20. Pre-contract information

Before a transaction is confirmed, ITECH will seek to clearly display the category or service purchased, number of participants where applicable, fee, reference currency, payment method, final amount and other relevant conditions.

The user must review the information before confirming the transaction. Where applicable, the platform will record the version of the policies and conditions accepted at the time of contracting.

21. Symposium fees and orders

Symposium fees are originally expressed in U.S. dollars and may vary according to participation format, category, number of participants and registration period.

The applicable fees will be those published by ITECH and recorded on the platform when the order is generated. A later change to the fee schedule will not retroactively alter a valid order within its validity period.

22. Payment through Mercado Pago

For certain local payments, ITECH may enable Mercado Pago or another provider disclosed to the user.

When a fee is expressed in USD and payment is made in Argentine pesos, the platform may use an administrative USD/ARS exchange rate defined by ITECH. Before proceeding to the provider, the user must be shown the base fee, the applied exchange rate and the final amount payable in ARS.

The exchange rate used will remain associated with the order. Subsequent changes will not recalculate a valid order that has already been generated within its validity period.

A success page or browser return does not by itself constitute definitive payment confirmation. ITECH will consider the transaction approved when it receives and validates the corresponding confirmation from the provider or verifies its status through appropriate server-side technical mechanisms.

23. Bank transfers in USD

ITECH may enable payment by bank transfer in U.S. dollars. When this method is available, the platform will provide the information required to complete the transaction, including the amount and corresponding reference.

The user must transfer the exact amount of the order and may be required to upload proof of transfer. Uploading or sending such proof does not constitute confirmation that payment has been credited.

The registration will remain pending until ITECH administratively verifies that the funds have actually been credited to the corresponding account.

24. Payment statuses

Depending on the method used, a transaction may have statuses such as pending, pending verification, approved, rejected, cancelled or refunded.

Registration will be considered definitively confirmed when the payment status and applicable validations allow accreditation in accordance with the procedure established by ITECH.

25. Group payments

When a group fee is contracted, payment will correspond to the entire contracted group. The person responsible for the registration must complete the information for the exact number of participants included in the selected option.

Each member may subsequently receive their own communications, credentials, QR code or individual access credentials.

26. Errors, duplicate payments and refunds

If ITECH identifies a duplicate payment, an incorrect amount or a credit that cannot be properly associated with an order, it may contact the user to verify the transaction.

Where a refund is appropriate, ITECH will seek to use the same payment method originally used when technically possible and appropriate. Refund crediting times may depend on financial institutions, payment providers and banking processes outside ITECH’s control.

27. Right of withdrawal and service cancellation

When the Argentine consumer protection regime applies to a distance contract, the consumer may exercise the non-waivable right to withdraw their acceptance within the applicable legal period, in accordance with Law No. 24,240, the Civil and Commercial Code of the Nation and the regulations in force.

For covered contracts, ITECH must maintain visible and direct mechanisms in the corresponding digital channels named “BOTÓN DE ARREPENTIMIENTO” and, where applicable, “BOTÓN DE BAJA DE SERVICIO”, without requiring prior registration to initiate the request.

ITECH may apply only reasonable and customary mechanisms intended to verify the identity and security of the user submitting the request.

Within twenty-four (24) hours after receiving a request covered by the regulations in force, ITECH will provide the identification or registration code of the request through the same medium used and will take the necessary measures to process it.

Any exceptions and special arrangements established by the regulations in force will apply where appropriate according to the specific nature of the contract.

28. Cancellations outside the statutory right of withdrawal

Once any applicable statutory withdrawal period has expired, voluntary cancellation requests will be governed by the specific conditions disclosed for each activity or service.

Where no specific condition has been published, submitting a cancellation request does not automatically create a right to a refund. ITECH will assess the case taking into account the nature of the service, proximity of the activity, services already performed, costs already committed and other relevant circumstances, without affecting non-waivable consumer rights.

29. Cancellation or rescheduling by ITECH

If ITECH permanently cancels a paid activity and does not offer a substitute service accepted by the participant, it will process the refund of the amounts due in accordance with applicable law and the specific conditions disclosed.

In the event of a significant change to the date, format or essential conditions, ITECH will inform participants of the available mechanisms and applicable rights.

Minor changes to the agenda, speakers, internal schedules or organization that do not substantially alter the service may be communicated without necessarily constituting cancellation of the service, without prejudice to the rights legally recognized to the user.

30. Invoicing

Tax documents will be issued in accordance with applicable law and the relevant tax status.

On the Symposium platform, the participant may indicate whether they require a tax document with customized tax information. Indicating that they do not require customized tax information does not eliminate ITECH’s tax obligations or determine the type of document by itself.

Documents will be issued through the corresponding administrative and accounting process, currently manually through ARCA systems, and may subsequently be sent in digital format.

The participant will not directly select invoice type A, B, C, E or another tax classification; that determination belongs to ITECH’s administrative and accounting process.

31. Confirmation, accreditation and virtual participants

When payment and the applicable validations are approved, ITECH may send an email confirmation and generate the credentials required for participation.

Each Symposium participant may receive an individual QR code for accreditation. Processing of the data included in that QR code is governed by section 7 of this policy.

Virtual participants with confirmed registration may receive, shortly before the activity, instructions and connection links for the videoconferencing platform used by ITECH. Those access credentials may be personal and must not be shared when so indicated.


PART V — CONTACT, CLAIMS AND UPDATES

32. Contact channels

Privacy, personal data and institutional inquiries: info@institutotech.com

Symposium registration, payments and operations: simposiotech@institutotech.com

General Symposium inquiries: simposio@institutotech.com

Editorial and communications: comunicacion@institutotech.com

ITECH may request information reasonably necessary to identify a transaction, request or data subject and to prevent unauthorized access or changes.

33. Consumer support

When an activity or service is subject to consumer protection regulations, ITECH will provide on the relevant website the support channels and conditions required by the regulations in force for inquiries, claims, withdrawal and service cancellation.

34. Amendments and effective version

ITECH may update these Policies to reflect changes to its services, payment methods, internal processes, providers, security measures or applicable regulations.

The current version will indicate its version number and update date. When a form or contract requires acceptance, the system may record the version accepted and the corresponding date.

The version published at the institutional URL defined by ITECH will be the current version and must be used as the common reference for the websites and services covered by section 1.


Main legal references

This policy is interpreted in accordance with applicable Argentine law, including, as relevant, Personal Data Protection Law No. 25,326, Consumer Protection Law No. 24,240, the Civil and Commercial Code of the Nation, Disposición 954/2025 and Disposición 3/2026, together with their regulatory, supplementary and amending provisions.