Last updated: January 12, 2026
Privacy Policy
At Ecavista Crowdlending Inmobiliario S.A.S. ("Ecavista") we respect your privacy and comply with Ecuador's Organic Law on Personal Data Protection (LOPDP, Official Registry Supplement 459) and its General Regulation. This document explains what data we collect, for what purposes and what your rights are.
1. Data controller
Ecavista Crowdlending Inmobiliario S.A.S., tax ID 1793204856001, with registered address at Av. República de El Salvador N36-140 and Naciones Unidas, Mansión Blanca Building, Suite 802, Quito, Ecuador. Data Protection Officer: dpo@ecavista.com.
2. Data we collect
Identification data (name, ID or passport), contact data (email, phone), financial and suitability data (source of funds, investor profile), browsing data (IP address, cookie identifiers) and contractual data (investment operations).
3. Purposes and legal basis
We process your data to: (i) fulfil the investment contract and provide our services; (ii) comply with legal obligations on anti-money-laundering and tax reporting; (iii) send you commercial communications with your consent; (iv) prevent fraud and protect our legitimate interest.
4. Recipients
We share data with the trustee that administers the autonomous estate, intermediary financial institutions, the Superintendence of Companies, the SRI tax authority, the Financial and Economic Analysis Unit (UAFE) and technology providers under confidentiality agreements.
5. International transfers
We may transfer data to providers in countries with adequate protection levels or via standard contractual clauses, exclusively for cloud hosting and analytics tools.
6. Retention period
We keep your data throughout the contractual relationship and for at least 10 years afterwards, pursuant to anti-money-laundering and tax regulations.
7. Your rights
You may exercise your rights of access, rectification, deletion, opposition, portability and not to be subject to automated decisions by writing to dpo@ecavista.com. You may also file a claim with Ecuador's Personal Data Protection Authority.
8. Security
We apply TLS 1.3 encryption, role-based access controls, two-factor authentication and annual security audits. Our servers are hosted in ISO 27001 certified data centres.
9. Changes to this policy
We may update this policy to reflect legal or service changes. We will notify any material change at least 15 days in advance via your registered email.