Data protection
Personal Data Privacy and Protection Policy
Applicable to students, guardians, applicants, teachers, staff, visitors and users.
Leer este documento en español
This is a courtesy translation. The Spanish version is the binding text and prevails in the event of any discrepancy.
Unidad Educativa Particular Iberoamericano, AMIE code 23H00332, whose legal entity of reference is CORPORACION EDUCATIVA IBEROAMERICANO STO DGO CIA.LTDA. (RUC 2390630665001), legally represented by Lic. Isidro Ipólito Borja Fiallos, with registered address at Urbanización Hermanos Guerrero, calle Teniente Ruilova s/n y Río Sucúa, esquina, Santo Domingo de los Tsáchilas, Ecuador.
1. Purpose and scope
This Policy explains clearly, sufficiently and accessibly how personal data connected with the educational, administrative, financial, employment, technological and security activities of Unidad Educativa Particular Iberoamericano is collected, used, consulted, organised, stored, updated, disclosed, transferred, blocked, erased and otherwise processed.
It applies to processing carried out on physical and digital media, including admission and enrolment processes, academic records, assistance to guardians, educational platforms, the website, institutional email, academic systems, video conferencing tools, messaging channels, payments, technical support, information security, access control and any other officially enabled services.
2. Data controller
The institutional controller of reference is CORPORACION EDUCATIVA IBEROAMERICANO STO DGO CIA.LTDA., RUC 2390630665001, associated with the operation of Unidad Educativa Particular Iberoamericano, AMIE code 23H00332, with registered address at Urbanización Hermanos Guerrero, calle Teniente Ruilova s/n y Río Sucúa, esquina, Santo Domingo de los Tsáchilas, Ecuador. The definitive identification of the controller must match the contracts, educational permits, tax records and other instruments in force.
Data Protection Officer (DPO): [COMPLETAR NOMBRE DEL DPD REGISTRADO]. DPO email: [COMPLETAR]. Institutional telephone or channel: [COMPLETAR]. Channel for exercising rights: [COMPLETAR].
3. Applicable principles
Processing shall observe the principles of lawfulness, fairness, transparency, purpose limitation, relevance and minimisation, proportionality, confidentiality, accuracy, storage limitation, security, proactive accountability and reinforced protection of children and adolescents. The institution shall avoid collecting information that is not necessary for specified, legitimate purposes.
4. Data subjects covered
- Applicants and persons interested in the educational offering.
- Enrolled students, graduates and former students.
- Mothers, fathers, legal guardians, tutors, persons financially responsible and emergency contacts.
- Teachers, administrative staff, management, employees, job applicants and former employees.
- Suppliers, contractors, visitors and third parties interacting with the institution.
- Users of the website, platforms, networks, forms and official channels.
5. Categories of personal data
Depending on the relationship with the data subject, and only where relevant, the institution may process the following categories:
- Identification and contact details: given names, surnames, identity document, date of birth, nationality, address, email, telephone numbers, signature and details of the guardian.
- Academic data: enrolment, level, year, class group, modality, records, grades, attendance, conduct, pedagogical adaptations, assessments, projects, certificates, degrees and platform logs.
- Family and socio-economic data necessary for scholarships, discounts, follow-up, invoicing, legal representation or compliance with legal obligations.
- Financial and transactional data: person responsible for payment, invoices, receipts, account statements, transaction references and reconciliations. The institution neither requires nor should store banking passwords or secret card codes.
- Technological data: IP address, date and time of access, session identifiers, device, browser, authentication logs, audit trails, incidents and activity necessary for security and continuity.
- Audiovisual data: image, voice, photographs, recordings of classes or events and video conferences, where a valid legal basis exists and the purpose has been disclosed.
- Special categories where strictly necessary: data relating to children and adolescents; health data; disability data; and, if authorised mechanisms are implemented, biometric data for identification or attendance control.
- Employment data of staff in accordance with labour, social security and institutional management legislation.
6. Sources of collection
Data may be obtained directly from the data subject or their guardian; from paper or electronic forms; from documents submitted in academic or administrative processes; from institutional systems; from teachers and authorised staff; from public bodies where legally permitted; from contracted technology suppliers; and from publicly accessible sources only where the new processing is compatible with the purpose of publication and has a legitimising basis.
7. Purposes of processing
- To manage information, guidance, pre-registration, admission, enrolment, re-entry, transfers, promotion, graduation and certifications.
- To deliver, organise and assess the educational service in authorised modalities, including tutorials, virtual classes, assessments, attendance control, feedback and pedagogical support.
- To create and administer institutional accounts, email, digital identity, access profiles and authentication mechanisms.
- To maintain academic and administrative records, report information to the National Education Authority and comply with regulatory obligations.
- To manage invoicing, payments, scholarships, discounts, reconciliations, lawful debt collection and tax obligations.
- To handle requests, complaints, support, incidents, emergencies and official communications.
- To protect physical and digital security and to prevent fraud, impersonation, unauthorised access and system abuse.
- To manage employment relationships, recruitment, payroll, social security, training and staff attendance control.
- To comply with legal obligations, orders from authorities and judicial or administrative proceedings.
- To carry out promotional communications only where a valid legal basis and a mechanism for objection or withdrawal exist, without making the educational service conditional on unnecessary consents.
8. Legal bases
Each purpose must be associated with a specific legal basis. Depending on the case, the institution may base processing on: valid consent; the performance of pre-contractual or contractual measures; compliance with legal obligations; protection of vital interests; a public mission or public interest where legally applicable; or legitimate interest, subject to prior assessment and provided the rights and freedoms of the data subject do not override it.
Consent shall not be used as a blanket formula to legitimise processing that rests on another legal basis. Where consent is required, it shall be sought freely, specifically, on an informed basis and unambiguously; evidence of its granting shall be retained; and it shall be capable of withdrawal through a straightforward mechanism.
9. Processing of children's and adolescents' data
Data relating to children and adolescents is a special category and shall receive reinforced protection. The institution shall apply the principle of the best interests of the child, minimise the exposure of information and adapt privacy notices to language appropriate for the data subject's age.
Where the legal basis is consent, the special rules of the LOPDP and its Regulations shall be observed. Adolescents aged fifteen and over may give explicit consent in the cases permitted by law, provided the purposes are clearly explained. In all other cases requiring representation, the institution shall verify the legal guardian's authorisation.
Enrolment or continued attendance shall not be made conditional on authorisations for image use, marketing, publications or purposes that are not necessary for the provision of the educational service. Such purposes must have a separate mechanism where they depend on consent.
10. Sensitive data, health, disability and biometrics
Sensitive data shall be processed only where a valid legal authorisation exists and with reinforced measures. Health or disability information shall be limited to what is necessary for care, safety, reasonable accommodations, inclusion, emergencies, employment obligations or purposes permitted by law.
If the institution uses biometrics for access or attendance control, it must first document their necessity and proportionality, analyse less intrusive alternatives, carry out the corresponding risk or impact assessment, restrict access, define erasure periods and specifically disclose the processing. The mere existence of a biometric device does not in itself make the processing lawful.
11. Platforms, email and technology services
The institution may use its own infrastructure and third-party services for email, storage, academic management, virtual learning, video conferencing, authentication, support, backup and security. Where a third party processes data on the institution's behalf, it must act as a processor in accordance with documented instructions, security measures, confidentiality, purpose limitations, controlled sub-processing and rules on return or erasure at the end of the service.
Users must keep their credentials confidential and report incidents. Activity logs may be used for security, auditing, continuity, incident resolution and the investigation of improper access, respecting the principles of proportionality and minimisation.
12. Disclosures and transfers
Data may be disclosed to educational, tax, judicial, supervisory or social security authorities where a legal obligation or authorisation exists; to contracted technology suppliers and professionals where necessary; to financial institutions or payment gateways in order to process transactions; and to other expressly disclosed recipients.
International transfers or disclosures, including those arising from cloud, email or platform services with infrastructure outside Ecuador, must comply with the LOPDP, its Regulations and the SPDP rules on national and international transfers. The institution shall document recipients, countries or categories of countries, purposes and applicable safeguards in its Record of Processing Activities and in its contracts with processors.
13. Retention and erasure
Data shall be retained for as long as necessary for the purpose that justified its processing and thereafter for the archiving, limitation, control or retention periods required by educational, tax, employment, corporate or rights-protection regulations. Academic records that must be preserved by legal provision may be kept for the corresponding period.
Where no retention obligation exists and the purpose has been fulfilled, data shall be erased, anonymised or blocked as appropriate. Backups shall be purged in accordance with reasonable technical cycles. Data associated with incidents, complaints or proceedings may be retained for as long as necessary for the establishment, exercise or defence of rights.
14. Information and personal data security
The institution shall apply technical, organisational and legal measures appropriate to the risk, including access and privilege control, authentication, event logging, network segmentation, backups, encryption where appropriate, vulnerability management, updates, anti-malware protection, continuity, recovery, incident management, training and confidentiality agreements. These measures shall be reviewed in line with the state of the art and the risks of the processing.
No measure eliminates risk entirely. The institution's obligation is to apply appropriate safeguards, to detect and respond to incidents in good time and to comply with the notification and documentation obligations established by the regulations.
15. Video surveillance, photographs and recordings
Where security cameras exist, their use shall be limited to legitimate purposes of security and the protection of people and property. Visible signage shall be installed, access to recordings shall be restricted and a proportionate retention period shall be defined, unless a sequence must be preserved on account of an incident, investigation or request from an authority.
Photographs, videos or recordings for pedagogical purposes shall be distinguished from advertising or promotional uses. The promotional use of students' images shall require the corresponding legal basis and, where it depends on consent, a separate, specific and revocable authorisation.
16. Automated decisions and artificial intelligence
The institution shall not take decisions producing legal effects or significantly affecting students based solely on automated processing where the law prohibits this. Artificial intelligence tools used for academic or administrative purposes must be subject to human oversight, data minimisation and controls proportionate to the risk.
Where analytics systems or support models are used to identify academic needs, drop-out risk, arrears or other indicators, their outputs shall be of an auxiliary nature and shall not replace human assessment where the decision may affect relevant rights or interests.
17. Rights of data subjects
Data subjects may exercise the rights recognised by the LOPDP, including access, information, rectification and updating, erasure, objection, suspension of processing, portability where applicable, and the right not to be subject to decisions based solely on automated assessments in the cases provided for by law.
Requests must be addressed to the institutional data protection channel: [COMPLETAR]. The institution may request reasonable information in order to verify identity and legal representation. The exercise of rights shall be free of charge, save for the exceptions provided by law, and shall be handled within the applicable time limits.
If a data subject considers that their rights have not been upheld, they may apply to the Superintendencia de Protección de Datos Personales or to the competent authorities, without prejudice to other remedies.
18. Accuracy and updating
Data subjects or their guardians must endeavour to ensure that the information provided is accurate and kept up to date. The institution shall establish mechanisms to correct errors and to prevent inaccurate information from producing undue effects. Keeping contact details up to date is particularly important for academic, administrative and emergency communications.
19. Cookies and similar technologies
The website and institutional portals may use cookies or similar technologies. Strictly necessary cookies may be used for security, session management or operation. Non-essential cookies requiring consent must not be enabled before a valid affirmative action. The details are governed by the Cookie Policy and by the site's preference centre.
20. Changes to this Policy
The institution may update this Policy in response to regulatory, technological or organisational changes or changes to the processing carried out. Substantial amendments shall be communicated by reasonable means and, where a new purpose requires consent, fresh authorisation shall be sought before the corresponding processing begins.
References
Asamblea Nacional del Ecuador. (2008). Constitución de la República del Ecuador. Registro Oficial No. 449, 20 de octubre de 2008, and amendments in force.
Asamblea Nacional del Ecuador. (2021). Ley Orgánica de Protección de Datos Personales. Quinto Suplemento del Registro Oficial No. 459, 26 de mayo de 2021. https://www.registroficial.gob.ec/
Presidencia de la República del Ecuador. (2023). Decreto Ejecutivo No. 904: Reglamento General de la Ley Orgánica de Protección de Datos Personales. Tercer Suplemento del Registro Oficial No. 435, 13 de noviembre de 2023. https://www.registroficial.gob.ec/
Superintendencia de Protección de Datos Personales. (2025). Resolución No. SPDP-SPD-2025-0028-R: Reglamento del Delegado de Protección de Datos Personales. https://spdp.gob.ec/
Superintendencia de Protección de Datos Personales. (2025). Resolución No. SPDP-SPD-2025-0024-R: Normativa general sobre transferencias o comunicaciones nacionales e internacionales de datos personales. https://spdp.gob.ec/
Asamblea Nacional del Ecuador. (2002). Ley de Comercio Electrónico, Firmas y Mensajes de Datos, and amendments in force.
Ministerio de Educación. (2024). Resolución No. MINEDUC-CZ4-2024-00244-R, de 28 de marzo de 2024.
Ministerio de Educación. (2025). Acuerdo No. MINEDUC-MINEDUC-2025-00030-A: Reglamento para la regulación de pensiones y matrículas en las instituciones educativas particulares y fiscomisionales del Sistema Nacional de Educación.
Ministerio de Educación. (2025). Reglamento General a la Ley Orgánica de Educación Intercultural, and amendments in force.
Ministerio de Educación. (n.d.). Ley Orgánica de Educación Intercultural, codification and amendments in force. https://educacion.gob.ec/
Servicio de Rentas Internas. (2026). Taxpayer registration certificate (RUC) of CORPORACION EDUCATIVA IBEROAMERICANO STO DGO CIA.LTDA., issued on 11 August 2026.
