Effective version: August 11, 2026. This policy supplements the Privacy policy.
1. Purpose and scope
This policy defines how HERING Ingeniería, S.R.L. collects, consults, organizes, stores, updates, discloses, and deletes personal data relating to contacts, prospects, clients, suppliers, representatives, and administrative users. It is binding on personnel and providers processing information for HERING.
2. Principles
Processing follows lawfulness, fairness, transparency, specified purpose, proportionality, accuracy, restricted access, security, and limited retention. Only adequate and necessary data will be collected, and inaccurate information will be corrected or deleted when appropriate.
3. Data, sources, and operations
Typical categories include identity and contact details, company and role, request content, client-project relationships, service history, and technical security data. Sources include the data subject, their organization, legitimate business interactions, and relevant public sources. HERING may record, classify, consult, update, back up, transfer under controls, and delete data for disclosed purposes.
4. Authorization and notice
Before collecting website data, HERING identifies the controller, purposes, required fields, and access to these policies. Where consent is the applicable basis, it must be prior, informed, demonstrable, and withdrawable for the future. Services will not be conditioned on unnecessary data.
5. Rights requests
Requests for access, correction, updating, objection, or deletion are received at servicios@heringsrl.com. Requests must identify the applicant, describe the data or processing, and provide a response channel. HERING will verify identity, record the case, and answer within the applicable period, explaining any lawful restriction.
6. Processors, transfers, and confidentiality
Providers accessing data must use only what is needed, follow instructions, restrict access, maintain confidentiality, report incidents, and return or delete data when services end. International transfers, including a visitor’s voluntary opening of WhatsApp, will use reasonable notices and safeguards appropriate to the service.
7. Security, incidents, and traceability
HERING applies role-based permissions, authentication, encryption in transit, file and form validation, backups, activity logs, and access reviews. Incidents will be contained, documented, assessed, and reported where a duty or relevant risk exists. Data may not be downloaded, shared, or reused beyond its authorized purpose.
8. Lifecycle and accountability
Each area must periodically review and delete or anonymize records that have met their purpose and retention period. Website requests generally follow a 24-month period after the last interaction, subject to legal or contractual exceptions in the Privacy policy. HERING management approves changes, trains personnel, and reviews this policy at least annually.
Legal reference: Dominican Law No. 172-13 and other applicable rules.