Data protection

Privacy policy

What data we process, why, for how long, and how you can exercise your rights at any time, whichever country you write to us from.

Last updated: 11 August 2026

1. Data controller

  • Registered name: DEV-21 S.R.L.
  • Trading name: CENCO Consultoría
  • Tax identification: TODO: RUT
  • Registered address: Dr. Luis Bonavita 1294, Piso 4, Oficina 402, WTC Free Zone, TODO: código postal Montevideo, Uruguay
  • Registry details: Registered with the Uruguayan National Trade Registry under no. 12453, on 5 October 2020
  • Email: info@cencoconsultoria.com
  • Phone: TODO: teléfono de contacto
  • Database register entry (URCDP): TODO: URCDP register entry number, or "not applicable"

The Uruguayan company named above is the sole owner of this website and the sole controller of the data collected through it. CENCO Consultoría is the trading name it operates under.

1.1. A distributed team, a single controller

Our team works remotely across locations: some of us are based in Uruguay and some in Spain, and we serve organisations in a range of countries. Team members may access messages received here from whichever country they are in, always on behalf of and under the instructions of the controller named above, and bound by confidentiality. This creates no additional controllers: responsibility for your data remains, in every case, with the Uruguayan company. Section 7 sets out what this means in terms of international transfers.

We have no company, branch or registered establishment in the European Union. Nor have we appointed a representative in the Union under article 27 GDPR: the processing carried out through this site is occasional, limited to professional contact details, does not include special categories of data or data relating to criminal convictions and offences on a large scale, and is unlikely to result in a risk to the rights and freedoms of individuals — so the exemption in article 27(2)(a) GDPR applies. Should that change, we would appoint a representative and state so here.

Appointing a data protection officer is likewise not mandatory: processing sensitive data is not our core business and we do not handle large volumes of personal data (article 40 of Law 19.670 and article 10 of Decree 64/020), and our activity involves no regular and systematic monitoring of data subjects on a large scale (article 37 GDPR). Any privacy-related question can be addressed to the email address above.

2. Applicable law

As a Uruguayan company working with clients in several countries, two legal frameworks apply to this processing at the same time:

  • Uruguay — Law No. 18.331 on the protection of personal data and the habeas data action, its implementing Decree 414/009, and the accountability provisions of Law No. 19.670 and Decree 64/020. This is the primary framework, as it governs the controller.
  • European Economic Area — Regulation (EU) 2016/679 (GDPR), which applies to us under its article 3(2)(a) because we offer services to people located in the European Union, not because we have an establishment there. For users in Spain, Organic Law 3/2018 (LOPDGDD) is also taken into account.

Where the two frameworks address the same matter with a different scope, we apply whichever standard is more protective of the data subject. If you reside in a third country, we process your data with the safeguards of Law 18.331 as a minimum, without prejudice to any mandatory local rules that may apply.

3. What data we process and why

3.1. Contact form

When you submit the form, we process the data you enter into it:

  • Required: name, email address and message.
  • Optional: company, phone or WhatsApp number, and service of interest.

Purpose: to handle your enquiry, reply to you and, where applicable, maintain the communication needed to assess a possible engagement. We do not use that data for any other purpose, in line with the purpose limitation principle in article 8 of Law 18.331.

The message field is free text. We recommend not including data that is not necessary for your enquiry, in particular health data, racial or ethnic origin, political opinions, religious beliefs, sex life or trade union membership — sensitive data under article 18 of Law 18.331 and special categories under article 9 GDPR — nor personal data of third parties without having informed them beforehand.

The message is sent by email to our contact mailbox. It is not stored in any website database.

3.2. IP address and abuse prevention

When the form is submitted we temporarily record your IP address in the server's memory, along with the submission timestamp, in order to limit the number of requests per address and prevent automated or abusive use of the contact channel.

This information is not linked to the content of your message, is not written to disk and is lost when the service restarts. The control window is 15 minutes.

3.3. Server logs

The server may log technical incidents for diagnosis, as well as submission attempts detected as automated. These logs are limited to the information needed to keep the service secure and operational.

3.4. Browsing

Simply browsing the site requires no personal data and involves no profiling. This site uses no analytics, advertising or third-party tracking tools (see section 8).

4. Legal basis

  • Contact form: your prior, informed and express consent, given by ticking the acceptance box before submitting the form (articles 9 and 13 of Law 18.331; article 6(1)(a) GDPR). Where the enquiry relates to engaging or evaluating our services, processing is additionally based on steps taken at the request of the data subject prior to entering into a contract (article 9(D) of Law 18.331 and article 6(1)(b) GDPR).
  • IP address and technical logs: our legitimate interest in ensuring the security and availability of the site and preventing fraudulent use of the form, in compliance with the security duty in article 10 of Law 18.331 and under article 6(1)(f) GDPR.

You may withdraw your consent at any time by writing to info@cencoconsultoria.com. Withdrawal does not affect the lawfulness of processing carried out beforehand.

5. Retention period

Messages received through the form are kept in our mailbox for TODO: retention period (suggested: 12 months from last contact), unless you request their deletion earlier or the enquiry leads to a contractual relationship, in which case they will be kept for the duration of that relationship and any applicable statutory limitation periods, including the commercial and tax record-keeping periods required under Uruguayan law.

The abuse-control data described in section 3.2 is held transiently in memory and does not survive a service restart.

6. Recipients

We do not disclose your data to third parties, nor do we use it for profiling or automated decision-making. No analytics, CRM or marketing platforms are connected to this site.

Our infrastructure and email providers do access the data as processors, strictly as needed to provide their service: TODO: proveedor de hosting y correo (dominio cencoapps.com). We hold contracts with them imposing the security and confidentiality duties of articles 10 and 11 of Law 18.331 and meeting the requirements of article 28 GDPR.

We may disclose data to courts or competent public authorities where we are under a legal obligation to do so, and to the Personal Data Regulatory and Control Unit in the exercise of its supervisory powers.

7. Where data is held and international transfers

This site's server and the mailbox that receives your messages are hosted in TODO: country where the server and mailbox are hosted.

For people located in the European Economic Area: access to your data from Uruguay constitutes an international transfer. Uruguay is recognised by the European Commission as providing an adequate level of data protection (Implementing Decision 2012/484/EU of 21 August 2012), so the transfer requires no additional safeguards under article 45 GDPR.

From Uruguay to other countries: where data is accessed from a different country — for instance by team members resident in Spain — or where a provider is established outside Uruguay, the transfer is governed by article 23 of Law 18.331. European Economic Area countries are among those the Personal Data Regulatory and Control Unit deems adequate. For the rest, transfers rely on contractual clauses offering equivalent safeguards or, failing that, on the unambiguous consent of the data subject.

Whichever country your data is accessed from, the level of protection applied is the same: the standards in this policy apply uniformly across the whole team.

8. Cookies and local storage

This site does not use cookies, neither first-party nor third-party. There are no analytics, advertising or personalisation cookies, which is why you will not see a consent banner.

The site stores a single value in your browser's local storage (localStorage), under the key theme, to remember whether you prefer light or dark mode. It is a technical preference, it cannot identify you, and it is never transmitted to our servers or to third parties. It is exempt from the prior consent requirement as strictly necessary to provide the service you requested — an exemption set out in article 5(3) of Directive 2002/58/EC and, for users in Spain, in article 22(2) of the LSSI. You can remove it at any time by clearing your browsing data.

Fonts and all other site assets are served from our own domain: browsing generates no requests to third-party servers that could record your IP address.

9. Your rights

You may exercise the following rights at any time, free of charge:

  • Access: find out what data of yours we process (article 14 of Law 18.331; article 15 GDPR).
  • Rectification, updating or inclusion: correct or complete inaccurate or incomplete data (article 15 of Law 18.331; article 16 GDPR).
  • Erasure: ask us to delete your data (article 15 of Law 18.331; article 17 GDPR).
  • Objection: object to processing based on legitimate interest (article 21 GDPR).
  • Restriction: ask us to suspend processing while a claim is verified (article 18 GDPR).
  • Portability: receive your data in a structured, commonly used format (article 20 GDPR).
  • Withdrawal of consent, with effect for the future.

To exercise them, write to info@cencoconsultoria.com stating which right you wish to exercise. We may ask you to prove your identity where there is reasonable doubt as to who is making the request.

Response times: we handle access requests within five working days, and requests for rectification, updating, inclusion or erasure also within five working days, under articles 14 and 15 of Law 18.331. Where the GDPR applies, the maximum period is one month in any event. We always apply whichever of the two is shorter.

If you believe your rights have not been properly addressed, you may lodge a complaint with the Personal Data Regulatory and Control Unit (URCDP), the supervisory authority competent for the controller, or bring a habeas data action before the competent Uruguayan courts (articles 37 et seq. of Law 18.331). If you are in the European Economic Area, you may also complain to the supervisory authority of your country of residence; in Spain, the Spanish Data Protection Agency (AEPD).

10. Security and breach notification

We apply technical and organisational measures proportionate to the risk of the processing: HTTPS traffic encryption, validation and size limits on submissions, request origin restrictions, anti-automation measures on the form, and no database storage, which reduces the exposed surface.

No system is completely infallible. Should a security breach occur that could significantly affect your rights, we would notify the Personal Data Regulatory and Control Unit within 72 hours of becoming aware of it and inform you, as required by article 39 of Law 19.670 and Decree 64/020, as well as the relevant European supervisory authority under articles 33 and 34 GDPR.

11. Minors

This site is aimed at professionals and organisations. It is not intended for minors and we do not knowingly collect their data. For users in Spain, consent under article 8 GDPR requires being at least fourteen years old (article 7 LOPDGDD). If we find that we have received data from a minor without the consent of their legal guardian, we will delete it.

12. Changes to this policy

We may update this policy to reflect regulatory changes or changes in how the site works. The version in force is always the one published on this page, bearing the update date shown above. We recommend reviewing it periodically.

You may also consult the legal notice for the owner's identifying details and the terms of use of this site.