Cookies
Cookie Policy and Notice
Applicable to the institutional website and portals.
Leer este documento en español
This is a courtesy translation. The Spanish version is the binding text and prevails in the event of any discrepancy.
Unidad Educativa Particular Iberoamericano, AMIE code 23H00332, whose legal entity of reference is CORPORACION EDUCATIVA IBEROAMERICANO STO DGO CIA.LTDA. (RUC 2390630665001), legally represented by Lic. Isidro Ipólito Borja Fiallos, with registered address at Urbanización Hermanos Guerrero, calle Teniente Ruilova s/n y Río Sucúa, esquina, Santo Domingo de los Tsáchilas, Ecuador.
1. Purpose
This Policy explains what cookies and similar technologies are, what they may be used for on the institution's sites and portals, which categories exist, when consent is required and how users can manage their preferences.
2. What cookies are
Cookies are small files or identifiers that a website may store on, or read from, the user's device. Similar technologies, such as local storage, pixels, tags or session identifiers, may perform equivalent functions. Their use may involve the processing of personal data where they allow a person or device to be identified directly or indirectly.
3. Principles of use
The institution shall apply the principles of transparency, purpose limitation, data minimisation and security. Strictly necessary cookies may be enabled so that the site functions, maintains a session, remembers essential preferences or protects forms and accounts. Non-essential cookies requiring consent must not be loaded before a valid affirmative action.
Closing the banner, continuing to browse the page or remaining silent shall not, in themselves, be regarded as consent to non-essential cookies. Users shall be able to accept, reject or configure categories with a comparable degree of ease.
4. Categories of cookies
- Necessary or technical: they enable indispensable functions such as authentication, security, load balancing, fraud prevention, session persistence and essential preferences.
- Preferences or functionality: they remember non-essential options that improve the user experience.
- Analytics or measurement: they help to understand site usage, performance, pages visited or errors. Where they involve processing that requires consent, they shall be enabled only after such consent has been obtained.
- Advertising or personalisation: they allow profiles to be built, campaigns to be measured or personalised promotional content to be displayed. They must not be enabled without a valid legal basis and, where required, consent.
- Third-party: cookies placed or read by services other than the institution, for example embedded content, maps, video, analytics or authentication. They shall be identified in the preference centre whenever they are enabled.
5. First-party and third-party cookies
First-party cookies are managed from domains controlled by the institution. Third-party cookies belong to external suppliers. The institution shall maintain an up-to-date technical inventory recording the name, domain, supplier, purpose, category, duration and legal basis of each cookie or similar technology in use.
6. Operational inventory
Before this Policy is published, the IT area and the Data Protection Officer must carry out an actual inventory of the site. Until such an inventory and an operational consent mechanism exist, the institutional recommendation is not to enable non-essential cookies that require consent.
7. Consent management
Where consent must be requested, the banner or preference centre shall display sufficient information before the corresponding cookies are installed. Consent shall be recorded in a demonstrable manner and may be modified or withdrawn at any time through the “Configure cookies” link or an equivalent mechanism permanently available.
Withdrawal shall not affect the lawfulness of processing carried out before it. Refusing non-essential cookies must not prevent access to content or services that do not technically depend on them.
8. Browser settings
Users may also delete or block cookies through their browser settings. If strictly necessary cookies are blocked, certain authentication, form or preference functions may cease to operate correctly. The institution must not rely on this technical possibility as a substitute for the consent mechanism where the law requires prior consent.
9. Data relating to children and adolescents
Portals directed at, or accessible to, students who are minors must avoid unnecessary tracking mechanisms, behavioural advertising and non-essential profiling. Where processing by means of cookies requires consent and affects minors' data, the reinforced rules of the LOPDP shall apply and information shall be provided in clear, age-appropriate terms.
10. Third-party content
Videos, maps, forms, social buttons or external resources may generate requests to third parties and activate their own technologies. Where third-party content involves non-essential cookies, the institution shall endeavour to block it until the user expresses the corresponding preference, or shall provide an equivalent mechanism preventing it from loading in advance.
11. Changes to this Policy
The institution shall update this Policy whenever the technologies used, the suppliers, the purposes or the applicable regulations change. The date and version shall remain visible. Changes requiring fresh consent shall apply only once such consent has been obtained.
12. Recommended banner wording
“We use cookies that are necessary for the operation and security of the site. With your permission, we may also use preference, analytics or other non-essential categories described in our Cookie Policy. You can accept, reject or configure your preferences and change them later.”
Recommended buttons: “Accept non-essential”, “Reject non-essential” and “Configure”. None should be deliberately designed to make refusal harder or to induce unintended acceptance.
13. Contact
Queries about cookies and the processing of personal data shall be directed to the Data Protection Officer's channel: [COMPLETAR].
References
Asamblea Nacional del Ecuador. (2008). Constitución de la República del Ecuador. Registro Oficial No. 449, 20 de octubre de 2008, and amendments in force.
Asamblea Nacional del Ecuador. (2021). Ley Orgánica de Protección de Datos Personales. Quinto Suplemento del Registro Oficial No. 459, 26 de mayo de 2021. https://www.registroficial.gob.ec/
Presidencia de la República del Ecuador. (2023). Decreto Ejecutivo No. 904: Reglamento General de la Ley Orgánica de Protección de Datos Personales. Tercer Suplemento del Registro Oficial No. 435, 13 de noviembre de 2023. https://www.registroficial.gob.ec/
Superintendencia de Protección de Datos Personales. (2025). Resolución No. SPDP-SPD-2025-0028-R: Reglamento del Delegado de Protección de Datos Personales. https://spdp.gob.ec/
Superintendencia de Protección de Datos Personales. (2025). Resolución No. SPDP-SPD-2025-0024-R: Normativa general sobre transferencias o comunicaciones nacionales e internacionales de datos personales. https://spdp.gob.ec/
Asamblea Nacional del Ecuador. (2002). Ley de Comercio Electrónico, Firmas y Mensajes de Datos, and amendments in force.
Superintendencia de Protección de Datos Personales. (2025). Resolución No. SPDP-SPD-2025-0028-R: Reglamento del Delegado de Protección de Datos Personales. https://spdp.gob.ec/
