Privacy Policy
Your privacy is part of our professional responsibility. We explain clearly what data we collect, what we use it for and how we protect it.
Last updated: January 2026
Data controller
TacticRisk is the controller of the personal data collected through this website and its professional corporate risk-management services.
Definitions
For the purposes of this Policy, the following terms mean:
Data subject
A natural person whose personal data is subject to processing.
Data controller
The person or entity that decides on the database and the processing. In this case: TacticRisk.
Data processor
The person or entity that processes data on behalf of the Controller.
Database
An organized set of personal data subject to processing.
Processing
Any operation on personal data: collection, storage, use, circulation or deletion.
Authorization
The data subject's prior, express and informed consent to the processing of their data.
Sensitive data
Data that affects privacy or whose misuse may lead to discrimination: health, ethnic origin, political orientation, biometrics, among others.
International transfer
Sending personal data to a recipient located outside the Controller's country of origin.
Using TacticRisk's platforms or submitting the contact form constitutes unequivocal acceptance of this Privacy Policy, in accordance with Article 5 of Law 25,326.
Processing principles
TacticRisk commits to complying with the following principles recognized in international data-protection regulations:
Legality
Processing is carried out in accordance with the law and regulations applicable in each jurisdiction.
Purpose
Data is collected only for legitimate, specific and explicit purposes.
Consent
Processing requires the data subject's authorization, except for legally provided exceptions.
Minimization
Only strictly necessary data is collected. We do not store excess information.
Transparency
Data subjects have clear access to how their data is collected, used and shared.
Security
Appropriate technical and organizational measures protect data against unauthorized access or loss.
Accuracy
Data is truthful, complete and up to date; it is corrected when necessary.
Accountability
TacticRisk actively demonstrates compliance and adopts effective protection measures.
Data we collect
We collect only the data necessary to provide you with our services. We do not collect sensitive data through this site.
| Category | Specific data | Source |
|---|---|---|
| Identification | First and last name, company or organization | Contact form |
| Contact | Work email, phone/WhatsApp (optional) | Form, WhatsApp |
| Inquiry | Service of interest, description of needs | Contact form |
| Browsing | Anonymized IP, pages visited, device and browser | Cookies, Google Analytics |
| Platform | Risk and asset data entered by the client in Relvik or Foresight | Software use |
Purposes of processing
We process your data for the following purposes and legal bases:
- Respond to inquiries and demo requests: pre-contractual measures at the data subject's request.
- Provide contracted services: performance of the professional services contract.
- Commercial management and billing: compliance with contractual and legal obligations.
- Marketing communications about our services: TacticRisk's legitimate interest, with the option to object at any time.
- Statistical analysis of platform use: anonymized and irreversibly de-identified data, to improve the service.
- Website improvement (Google Analytics): consent given through cookie preferences.
- Post-service follow-up and client satisfaction: TacticRisk's legitimate interest.
- Compliance with legal obligations: tax, accounting and regulatory rules applicable in Argentina.
- Identity verification and fraud prevention: compliance with applicable security regulations.
- Training and sending valuable content: only with express consent and with an immediate opt-out option.
TacticRisk does not use its clients' risk data for comparative analyses between organizations, nor does it share it with third parties without express authorization. Data entered into the platform is the exclusive property of the client.
Retention periods
- Contact data with no contractual relationship: up to 2 years from the last communication.
- Data linked to contracts: during the term and for up to 10 years afterward (Argentine accounting and tax rules).
- Platform data: during the term of the subscription plus an additional 90 days for recovery, then secure deletion.
- Browsing data (Analytics): up to 14 months according to the Google Analytics configuration.
Recipients and transfers
We do not sell or assign data to third parties. We only share it in the following cases:
- Technology providers: Google LLC (Analytics, Workspace), Web3Forms (contact form) and hosting providers, under contracts that guarantee confidentiality. Google operates under the GDPR.
- Competent authorities: when required by Argentine law or a final court order.
- Professional advisors: lawyers and accountants under a legal duty of professional secrecy.
International transfers to Google LLC are covered by the appropriate GDPR safeguards and Google's privacy policy (policies.google.com/privacy).
Your rights
Under Law 25,326, the GDPR and the CCPA (California), you have the following rights:
- Access: know what data we hold, how we obtained it and what we use it for.
- Rectification: request the correction of inaccurate or incomplete data.
- Erasure: request deletion when the data is no longer necessary or you withdraw your consent (right to be forgotten).
- Confidentiality: object to uses not expressly authorized.
- Portability (GDPR/CCPA): receive your data in a structured, machine-readable format (CSV, JSON or Excel), at any time during the term of the contract. We deliver the data within a maximum of 30 days of the formal request.
- Opt out of marketing: unsubscribe from commercial communications at any time with a single click.
- Withdrawal of consent: withdraw it without affecting the lawfulness of prior processing.
- Non-discrimination (CCPA): TacticRisk does not discriminate against data subjects who exercise privacy rights.
Procedure to exercise rights (GDPR Art. 12): send an email to direccion@tacticrisk.com with your name, ID type and number, specifying the right to exercise and a clear description of your request. We respond within a maximum of 10 business days. For complex requests, we may extend the deadline by up to 60 additional days, notifying you in writing with justification.
If you believe the processing is not adequate, you may file a complaint with the Agency for Access to Public Information (AAIP), the supervisory authority in Argentina. Users in the EU may complain to the data-protection authority of their country.
Data anonymization
TacticRisk may process anonymized and irreversibly de-identified data to improve the platform and develop new features. Data is considered anonymized when it meets:
- K-anonymity: the record is indistinguishable from at least 4 other records in the set (k≥5).
- Irreversibility: it is impossible to re-identify the data subject even by cross-referencing other public or private data sources.
- Documented process: documentation of the anonymization algorithms and techniques is maintained.
- Exclusion of sensitive data: sensitive data (health, ethnic origin, political orientation) is not processed for comparative analyses without express consent.
Anonymized data may be used by TacticRisk without additional restrictions. The client retains the right to request the technical criteria used in the anonymization.
Data security
We implement the following technical and organizational measures:
- Encrypted transmission via HTTPS/TLS 1.3 in all communications.
- Encrypted storage via AES-256 for data at rest.
- Access restricted to authorized personnel only, under a documented confidentiality agreement.
- Annual security audits by independent third parties, aligned with ISO 27001.
- A documented security-incident response procedure.
- Storage on servers with physical and logical access controls.
- A strong-password policy (minimum 12 characters) and multi-factor authentication for administrative access.
Incident procedure: in the event of a security breach with a significant risk to data subjects' rights, TacticRisk will notify without undue delay and within a maximum of 72 hours (GDPR Art. 33). The notification will include: the nature of the breach, affected data, likely consequences and mitigation measures implemented.
Data on the platform
When clients use Relvik or Strategic Foresight, they enter their own organization's data (assets, risks, strategic variables). We apply specific safeguards to this data:
- Exclusive property of the client: the data entered is their exclusive property. TacticRisk acts as Data Processor, not as Controller.
- No comparative use between clients: we do not use one client's data for analyses involving others, or for benchmarking without express authorization.
- Service-improvement analysis: we may use anonymized and irreversibly de-identified data to improve the software. This use does not allow any client or data subject to be identified.
- Deletion at the end of the contract: data is securely deleted via multiple overwriting (3+ passes) within 90 days, unless there is a legal obligation to retain it.
- Data portability: the client may download their data in CSV, JSON or Excel at any time during the subscription, free of charge. We deliver the data within a maximum of 30 days.
Minors
TacticRisk's services are aimed exclusively at people over 18 and at legal representatives of legal entities. We do not knowingly collect data from minors. If we detect a minor's data without parental consent, we will delete it immediately.
Changes to this policy
We may update this Policy to reflect changes in our practices, services or applicable regulations. Significant changes are communicated by updating the date at the top of the document. Continued use of the site or services implies acceptance of the updated policy.
Contact
For inquiries, requests to exercise rights, complaints or security-incident reports related to privacy:
Privacy and security channel
Email: direccion@tacticrisk.com
Hours: Monday to Friday, 9:00 to 18:00 (Argentina time)
Response time: maximum 10 business days (GDPR Art. 12). Urgent security reports: maximum 24 hours.