1. Controller and scope
Lulab Technology, RUC 8-996-763, DV 58, operating in the Republic of Panama, is the controller of personal data collected for its own inquiries, estimates, sales, billing, support and administration.
When Lulab develops, hosts, maintains or supports a platform containing data controlled by a client, Lulab may act as a custodian or processor under the client's documented instructions and the applicable agreement.
2. Data we may process
- Identity and contact data: name, company, email, phone, country and role.
- Commercial and project information: service, budget, goals, scope, schedule, content, references and approvals.
- Contractual and administrative information: proposals, payments, invoices, support, renewals, communications and acceptance evidence.
- Submitted files: logos, images, documents, catalogues, authorized datasets and other project materials.
- Technical data: hashed IP address, browser, user agent, language, session, source page, referrer, UTM, gclid, fbclid and security logs.
- Client-controlled data hosted on their behalf when a contract includes hosting, maintenance, migration, backup or technical support.
3. How data is obtained
Data may be provided directly by a person or company through forms, email, WhatsApp, meetings, proposals, contracts, files or authorized access. We may also receive technical information generated when using the site or from providers used to deliver the service.
Anyone providing third-party information represents that they have authorization or another lawful basis and must provide notice to those individuals when required.
4. Purposes and legal bases
- Respond to inquiries, qualify opportunities and prepare requested proposals.
- Perform projects, coordinate deliverables, maintain systems, provide support and manage the contractual relationship.
- Process payments, billing, renewals and accounting, tax and legal obligations.
- Protect the site, prevent fraud, spam, abuse and unauthorized access, and investigate incidents.
- Improve processes, measure inquiry sources and preserve commercial or contractual evidence.
- Send promotional communications only with authorization or another permitted basis, with an opt-out option.
5. Required data, minimization and sensitive data
Fields marked as required are necessary to process the request or provide the service. If they are not provided, the request may not be handled.
Do not submit passwords, full card numbers, medical records, identity documents, minors' data, biometric data or other sensitive information unless expressly requested. When a project requires such information, additional controls and responsibilities will be agreed before it is received.
7. Providers, processors and transfers
We may use hosting, domain, email, security, CDN, backup, messaging, client-configured analytics, payment, accounting, technical support and professional service providers. Only information reasonably necessary for the contracted function is shared.
Some providers may process data outside Panama. In those cases, we seek providers with appropriate contractual and technical measures, without limiting the client's obligations when the client selects or administers the provider.
We do not sell personal data.
8. Retention and deletion
- Unconverted inquiries and estimates: normally up to 24 months after the last interaction.
- Client, contract, payment and dispute records: during the relationship and for the period needed for legal, accounting, warranty or claims-defense obligations.
- Intake files: during the project and normally up to 180 days after completion or archival, unless otherwise agreed or justified.
- Security logs: normally up to 12 months, unless an investigation or applicable duty requires longer.
- Backups: deleted under technical rotation and may temporarily persist after operational deletion.
9. Security and confidentiality
We apply reasonable risk-based measures such as HTTPS, access controls, protected sessions, private file storage, input validation, abuse protection, backups when included in the service and restricted sensitive directories.
No system is invulnerable. Security also depends on clients and users protecting credentials, limiting access, updating devices and avoiding unnecessary data submissions.
10. Individual rights
Individuals may request access, rectification, cancellation or deletion where applicable, objection, portability and withdrawal of consent, without affecting prior lawful processing or records that must be retained.
Requests should be sent to ventas@lulabtech.com with the subject “Data rights”, stating the name, contact method, relationship with Lulab, requested right and enough information to verify identity without requesting excessive information.
As an operational reference under Panamanian rules, we seek to respond to access within 10 business days, rectification within 5, cancellation and portability within 10, and objection immediately where applicable.
11. Security incidents
If we detect an incident involving personal data, we will activate containment, evidence preservation, assessment, remediation and communications to the client, individuals or authorities when required by law or contract.
Security reports may be sent to ventas@lulabtech.com. Do not include additional personal data in the first message.
12. Minors
Lulab commercial services are not directed to minors. We do not intentionally request their data. If information is detected without valid authorization, deletion will be assessed and the responsible party contacted where needed.
13. Changes, contact and authority
This is version 2026-08-01. Material changes will be published on this page and, where appropriate, communicated through a reasonable channel.
Privacy contact: ventas@lulabtech.com. If a request is not satisfactorily resolved, the person may contact Panama's National Authority for Transparency and Access to Information (ANTAI), without limiting other rights.