English
Here you’ll find all the legal information about our company, including our services, terms and conditions of use, and our privacy and personal data processing policy.
PRIVACY AND PERSONAL DATA PROCESSING POLICY
V.2.0. - USERS - LZ GLOBAL HOLDINGS INC
PRIVACY STATEMENT: This policy expresses the commitment of LZ GLOBAL HOLDINGS INC, to the protection of data subjects' information, recognizing privacy as a fundamental right, and thus assuming responsibility for processing personal information and data in an ethical, secure, transparent manner and in accordance with applicable legal provisions.
Through this policy, we inform you of the purposes, principles, rights, duties, and procedures associated with the processing of personal information and data, and we inform you that such processing will be carried out in accordance with criteria of good faith, legality, security, confidentiality, and other criteria that may apply; this policy being applicable to any activity of collection, use, storage, transfer, transmission, and/or deletion of personal information and data carried out within the framework of the provision of the services of LZ GLOBAL HOLDINGS INC.
Therefore, the data that may be recorded in our database may include, among others, names, email addresses, identification numbers, telephone numbers, and dates of birth; the data subject may revoke their consent and exercise their right to deletion or cancellation in accordance with the provisions of this policy.
Likewise, if as a data subject you wish to submit inquiries, requests, petitions, complaints, or claims related to your personal information and data, you may do so through the channels made available by LZ GLOBAL HOLDINGS INC through the website WWW.LAZZAGLOBAL.COM and/or the email address [email protected].
INTRODUCTION: LZ GLOBAL HOLDINGS INC, hereinafter identified as LAZZA GLOBAL, through this document, communicates, informs, publishes, and issues to all interested parties the privacy and personal data processing policy for users, which may be consulted through the website WWW.LAZZAGLOBAL.COM.
Therefore, you are informed that the purpose of this policy is to describe in detail the way the personal information and data of data subjects who, as USERS, make use of our services, is collected, used, stored, shared, and/or protected.
Based on the foregoing, it is relevant to highlight that this policy applies in accordance with and as a complement to the provisions set forth in the general terms and conditions of use, and other applicable provisions, including agreements that may be directly arranged with you as a data subject and, consequently, as a USER.
OBJECTIVE: To clearly, transparently, and thoroughly inform data subjects, of the manner in which LAZZA GLOBAL, in its capacity as data controller, collects, stores, uses, protects, and/or shares the personal information and data obtained in providing the service, thereby seeking to ensure compliance with applicable regulations and to promote trust, security, and responsibility in the handling of personal information and data within the services provided.
MAIN DEFINITIONS: Below are the following concepts and definitions that may appear throughout this policy for the data subject's knowledge:
• Personal data. Any type of information that allows identification of, or that can be linked to, the data subject.
• Sensitive data. Refers to those data that, due to their nature, may affect the privacy of the data subject, or whose improper use may cause harm to their rights or discrimination.
• Public data. Public data are considered to be those that are not private or semi-private and that are determined as such by Law.
• Database. An organized set of personal data of different data subjects that are subject to processing by the data controller.
• Privacy notice. That written, digital, or verbal communication issued by the data controller to the data subject, through which the existence of privacy and/or personal data processing policies that will apply to them, the manner of access and consultation, and the purposes that may correspond, are reported.
• Authorization. Prior, express, and informed consent given by the data subject to carry out the processing of personal data.
• Data subject. A natural person whose personal data is subject to processing, and legal entities, when they hold the status of users.
• Data controller. A natural or legal person who decides on the processing of data, it being understood that for purposes of this policy this is LAZZA GLOBAL.
• Data processor. A natural or legal person who carries out the processing of data on behalf of the data controller.
• Processing. Any type of operation performed on data, such as collection, storage, use, circulation, deletion, and any other operation that may apply.
• Transfer. Transfer occurs when the controller and/or processor of the data sends information or personal data to a recipient, who in turn is the controller of the processing and may be located within the State where the data were collected or outside of it.
• Transmission. Processing of personal data that involves the communication of such data within or outside the territory where it was collected, when the purpose is the carrying out of processing by the processor on behalf of a single data controller.
• Third party. A natural or legal person, authority, service, or body other than the data subject, the data controller, the data processor, and the persons authorized to process personal data under the direct authority of the controller or the processor.
• Cross-border processing. Processing of data that involves the communication of such data outside the territory of the State where it was collected, when the purpose is the carrying out of processing by another data controller or by a processor on behalf of a controller established in another State.
• Recipient. A natural or legal person, authority, service, or other body to which personal data is communicated, whether or not it is a third party.
• Supervisory authority. An independent authority established by a State, in accordance with applicable local regulations, empowered to exercise oversight, control, inspection, sanctioning, or other functions related to the processing of personal data by natural and/or legal persons, of a public and/or private nature.
GUIDING PRINCIPLES: The principles that will guide this policy, without limitation, are:
• Legality. This policy will be applied in accordance with current and applicable legislation.
• Purpose. Processing shall be carried out for a legitimate purpose, which must be communicated to the data subject.
• Accuracy or quality. Information must be truthful, complete, up to date, and/or understandable; the processing of incomplete, partial, outdated, incomprehensible, or misleading information or data is not permitted.
• Restricted access and circulation. Personal data may not be accessible via the internet or through other means of mass disclosure or communication, except where such access can be controlled to provide knowledge to data subjects or authorized third parties.
• Freedom. Processing shall be carried out and/or performed with the prior, express, and informed consent of the data subject.
• Transparency. This implies that, during processing, the data subject's right to obtain from the controller or processor information about the existence of data concerning them must be guaranteed.
• Security. Information must be handled with the means and tools necessary to ensure the security of records, preventing their alteration, loss, unauthorized consultation, or fraudulent use.
• Confidentiality. All natural or legal persons involved in the administration of personal data are required to maintain the confidentiality of the information and personal data, even when this corresponds to a period after the relationship through which such information or personal data was obtained has ended and may thus supply or communicate information or personal data when this corresponds to the development of activities authorized by applicable legislation.
PURPOSES AND PROCESSING: The main objective of processing the data subject's personal data is the proper provision of our services, in a secure, effective, and efficient manner; therefore, LAZZA GLOBAL collects and processes information within the applicable legal framework and as necessary to fulfill the following purposes, among others:
• The information collected will be used to provide our services in general, as well as platform-related services, profile management, processing of operations, risk analysis, personalization of experience, functionalities, among others.
• Verifying identity for compliance with legal, tax, and financial requirements, technical suitability, and commercial reputation.
• Identity verification, with the purpose of confirming that it is indeed the data subject and not an unauthorized third party who is making use of the services provided, submitting petitions, complaints, claims, or inquiries about information that may concern them, and other applicable matters, thereby preventing the information from coming to the knowledge of an unauthorized third party and mitigating the risk of identity theft.
• Identity validation as a complementary measure for matters of collection management, guarantee payments, compliance with legal, contractual, and other applicable obligations.
• Managing schedules, compliance with commitments, contractual clauses, and other related matters.
• Usage data will be analyzed to understand interaction with our services and thereby achieve continuous improvement, conducting audience segmentation, preference analysis, and content personalization, based on prior interests or behaviors, in order to provide an optimal service experience.
• Information will be used to send relevant communications about our services, updates, promotions, policy changes, or to manage communication of other types of announcements related to the provision of the service.
• When the data subject chooses to receive them, the information may be used to send marketing and advertising communications related to the services provided, as well as special offers that may be tailored to the data subject's profile.
• Complying with national or international legal provisions.
• When it is necessary to disclose information to duly empowered competent authorities, by means of an administrative or judicial order.
• If applicable, and in relation to the nature of the service provided, submitting reports to oversight and control authorities.
• Using the information for internal purposes of LAZZA GLOBAL, such as audits, reports, analysis or data mining, research to improve services and communications, performance metrics, process evaluation, market studies, impact analysis, or measurement of key indicators.
• Verifying compliance with internal policies, quality management processes, good commercial and corporate practices, and national or international standards.
• Including periodic reviews, evaluations, risk management, and continuous improvement plans.
• Making backup copies of databases, in order to protect them and ensure the continuity of our business operations.
• Resolving disputes.
• Contacting the data subject.
• Informing about system failures and updates to the services of LAZZA GLOBAL.
• Providing support, assistance, and troubleshooting services to data subjects through channels such as call centers, emails, web forms, social media, and other applicable channels.
• Recording interactions, monitoring quality of service, issuing automatic or personalized responses, and conducting subsequent follow-ups.
• Preventing the platform of LAZZA GLOBAL from being used to carry out unlawful or illegal activities, in order to comply with the provisions, set forth in our general terms and conditions of use, and other policies, contracts, and documents that may be related, applicable, or relevant to the service provided.
• When applicable, conducting validations of the risk profile associated with the data subject.
• Maintaining, suspending, or terminating contractual relationships.
• Designating one or more data processors.
• When applicable, controlling access to physical facilities through video surveillance, biometric records, credential scanning, or identity validation.
• Protecting technological assets, computer networks, and systems against unauthorized access, cyberattacks, information leaks or breaches, and other related matters.
• Attending to and managing requests for access, correction, cancellation, opposition, portability, deletion, and limitation of data processing made by the data subject or competent authority.
• Respecting the consent, opposition, or withdrawal of authorization mechanisms of data subjects.
• Ensuring the effective exercise of rights by the data subject, through accessible channels and formal procedures.
• Sharing, transferring, or transmitting data with affiliates, parent companies, partners, cloud service providers, consultants, or external entities, whether national or international, for legitimate purposes and in compliance with the legal guarantees applicable to this matter.
• Detecting suspicious behavior by the data subject, preventing computer or financial crimes, conducting background checks, and monitoring transactions.
• Including the use of automatic detection technologies, predictive models, and databases shared with partner entities or competent authorities.
• Measuring satisfaction through surveys, tests, usability testing, browsing analysis, cookies, and other similar mechanisms to improve the data subject's experience on the platforms of LAZZA GLOBAL.
• Collecting feedback and adjusting services based on the needs of data subjects.
• Ensuring that the data provided by the data subject is accurate, and when applicable, PEP information.
• Managing procedures aimed at the prevention, detection, control, and reporting of operations or processes that may be related to money laundering or terrorist financing (AML/CFT) or the proliferation of weapons of mass destruction, in accordance with applicable regulations.
• Carrying out, directly or through national or international third parties, due diligence processes, transactional monitoring, analysis of restrictive lists, identification of beneficial owners, verification of sources of funds, and reports to the financial intelligence unit, among others that may apply.
• Carrying out, directly or through national or international third parties, web hosting, data analysis, processing of operations, advertising, marketing, technical support, advisory services, and other related processes.
• Transfer, transmission, or relocation of the data subject's information or data to servers located in different countries, ensuring that measures are adopted to guarantee that these processes are carried out in compliance with applicable and current regulations on this matter.
• Recording, verifying, updating, and managing the information of persons designated as beneficiaries in the event of death, based on what has been established by the data subject.
• Including the processing of data in the event of beneficiaries upon the death of the data subject, such as identification, contact information, kinship, financial or legal status, management of supporting documentation, verification of legitimacy, handling of post-mortem requests, delivery of benefits, compliance with contractual provisions, resolution of conflicts among claimants, compliance with associated legal and tax obligations, communication with heirs, legal representatives, or judicial or administrative entities, and other related matters.
• Analyzing and collecting technical information derived from the use of our services, such as IP addresses, browsers, operating systems, languages, time zones, device identifiers, sites visited, and time spent, in order to ensure security processes, fraud prevention, error diagnosis, performance improvement, personalization of the user experience, and other related matters.
• To promote the security, protection, and integrity of the services provided by LAZZA GLOBAL and its platform.
• Other purposes of a commercial, administrative, and/or contact nature.
CATEGORIES OF PERSONAL DATA PROCESSED: To ensure transparency in the processing of information and personal data, the data subject will be informed about the categories of personal data that may be collected and processed, depending on the nature of the service, relationship, and purposes; it being noted that these categories may include, among others:
• Personal identification data, such as first and last names, type and number of identification document, nationality, dates of birth, gender, handwritten or digital signature, image or photograph, among other related data.
• Contact data, such as telephone numbers, physical or mailing address, email address, among other related data.
• Financial and transactional data, such as statements regarding the source of funds, operational activity related to the services provided, financial capacity, tax information, among other related data.
• Browsing and technological data, such as IP address, location data, dates and times of access, types of browser and devices, operating systems, cookies, activity within the platform, among other related data.
• Sensitive data, only when applicable and with express authorization, such as information related to criminal records, biometric data, and any other data that, due to its nature, may affect the privacy of the data subject or whose improper use may give rise to discrimination.
• Data of referenced third parties, in the case of the designation of beneficiaries, including among such data, contact persons, personal references, kinship, and other related matters, it being understood that such data will be processed under principles of security and limited purposes.
The collection of each type or category of data will be carried out in accordance with the purposes described in this policy and in relation to the services provided, noting that the data subject may always inquire as to what type of information is being processed and the specific purposes thereof.
PROCESSING OF SENSITIVE DATA: Sensitive personal data may affect the privacy and rights of the data subject, and its improper use may give rise to discrimination; this includes, but is not limited to, data that reveal racial or ethnic origin, political affiliation, religious or philosophical beliefs, data related to physical or mental health, genetic or biometric information, among others.
Therefore, the processing of this type of data will be carried out only when strictly necessary, in accordance with the purpose pursued and always under standards of security and confidentiality, carrying out such processing when:
• The data subject has given their prior, express, free, and informed consent in writing or verbally, or through a valid digital mechanism.
• It is essential to protect the life, health, or integrity of the data subject or another person, when the data subject is physically or legally incapacitated to give their consent, in which case authorization will be requested from their legal representatives.
• Processing is necessary for reasons of relevant public interest, based on applicable law and subject to proportional safeguards.
• It arises from a legal or contractual obligation in which the handling of such data is unavoidable.
• It is used for purposes of public health, medical care, diagnosis, provision of health services, or management of health systems, always under the duty of professional secrecy and within enabling legal frameworks.
Additionally, with respect to the processing of sensitive data, the following actions will be ensured:
• Informing the data subject that, since it concerns sensitive data, they are not obligated to authorize its processing.
• Informing the data subject which data subject to processing are considered sensitive and the purpose of the processing.
• Obtaining prior, express, and informed consent for the processing of sensitive data.
• Finally, no activity may be made conditional upon the data subject providing sensitive personal data.
PROCESSING OF DATA OF GIRLS, BOYS, AND ADOLESCENTS: The processing of personal information and data of girls, boys, and adolescents will be carried out in observance of the best interests of the minor, ensuring their enhanced protection, privacy, and fundamental rights. The express, free, and informed authorization of their legal representatives will be required, without prejudice to the minor's right to be heard according to their capacity; and such processing will only be appropriate when there is a legitimate purpose.
If applicable, only the data strictly necessary will be collected, with enhanced security measures and restricted access. Sensitive data of minors will not be processed, except in those cases where it is legally permitted.
Both minors and their representatives may fully exercise the rights associated with the processing of their personal data.
RIGHTS AND DUTIES OF DATA SUBJECTS: The data subject may exercise the rights regarding their information and personal data that concern them, having as such the following, without limitation thereto, always in accordance with applicable regulations:
• Right of access. Through which they may confirm whether their information or personal data is being processed by LAZZA GLOBAL, and, if applicable, access information such as purposes of processing, retention period, category of personal data, among others.
• Right of rectification and updating. They may request the correction or updating of inaccurate, incomplete, outdated, and/or erroneous data, it being noted that both the data subject and the controller or processor must act in good faith throughout this process.
• Right of consultation and information. They may consult their information or data free of charge at least once per calendar month, and whenever there may be modifications to this policy, as well as consult the use that has been made of their information and personal data, upon prior request.
• Right to request proof of authorization. They may request proof of the authorization granted to LAZZA GLOBAL, in its capacity as data controller, except when this is expressly exempted as a requirement for processing, in accordance with applicable legal exceptions.
• Right of deletion or cancellation. The data subject may request the deletion, cancellation, or elimination of their personal data when they consider that the processing does not respect the principles, rights, and legal guarantees applicable to the matter, it being noted that this right may be limited when there is a legal duty of retention, or if the data is necessary for the formulation, defense, or exercise of claims or contractual compliance.
• Right to revoke consent. The data subject may, at any time, withdraw the consent given for processing, without this having retroactive effects; this revocation will not apply when there is a legal or contractual relationship that prevents such deletion.
• Right of opposition. They may object to the processing of their personal data for well-founded reasons related to their particular situation, unless there are legitimate reasons that may prevail over their interests or rights.
• Right to file complaints before competent authorities. If you consider that the processing of your data infringes current regulations, you may file a complaint before the supervisory and oversight authority that is competent for such purposes.
• Right to challenge a decision based on automated processing. If they wish, they may request that decisions be reviewed if such decisions are made solely by automated means, given that LAZZA GLOBAL may use automated tools for selection and admission processes, it being noted that, if these tools produce an unfavorable result for you as a data subject and potential user, you may request reconsideration of such result.
• Right of portability. The data subject has the right to request the portability of their personal information and data from the data controller, and to receive it in a structured, commonly used, and machine-readable format, as well as to transmit it to another data controller without the current one preventing it, when the processing is based on their consent or on a contractual relationship and is carried out by automated means.
Linked to the stipulation of the rights attributable to the data subject is the standing to exercise such rights, with respect to which the exercise or implementation of these rights may be carried out by:
• The data subject directly, with respect to which an identity validation process will be carried out by reasonable means for such purpose.
• If applicable, by the legal representative of the data subject, with respect to which an identity validation process will be carried out by reasonable means to verify such capacity.
• An authorized third party, with respect to which they must present written authorization signed by the data subject, accompanied by their identification credentials.
• Heirs or successors, in the event of the death of the data subject, with respect to which an identity validation and relationship verification process will be carried out by reasonable means for such purpose.
In any of these cases, LAZZA GLOBAL, may request the information and documentation necessary to verify the identity, capacity, and standing of anyone submitting requests, complaints, claims, or seeking to exercise any of the rights previously referenced and identified.
On the other hand, the data subject also has a series of essential duties related to their personal information and data, including:
• The data subject must provide truthful, complete, up-to-date, understandable, accurate, authentic, and/or verifiable information, and must therefore refrain from providing false information or information belonging to third parties without authorization, this being unrelated to the responsibility of LAZZA GLOBAL, since this matter will be handled in accordance with the principle of good faith.
• It will be the duty of the data subject to carry out updating or correction processes when relevant and pertinent, it being their responsibility to inform LAZZA GLOBAL of any modification to their information or personal data, in order to keep their information current.
• As a data subject, you must exercise your rights in a responsible and well-founded manner, in accordance with the procedures established for such purpose.
• It is prohibited to exercise rights over the information or personal data of third parties without express authorization, or without being duly empowered and entitled to do so.
• By accepting this policy and other related provisions that may apply, the data subject clearly and unequivocally undertakes to review and understand the scope of what is established herein and not to violate the rights of third parties through the improper use of their information.
• Conducting periodic reviews of updates or modifications to this policy that may be published by LAZZA GLOBAL on its website.
• Other duties that may apply.
DUTIES OF LAZZA GLOBAL: The following will be considered duties of LAZZA GLOBAL:
• Guaranteeing the right of habeas data.
• Requesting authorization from the data subject for processing.
• Retaining proof of consent given by the data subject.
• Informing about substantial changes that may be made to this policy.
• Seeking to establish security measures for the protection of personal information and data.
• Informing the data subject of the purposes for the collection and processing of personal information and data.
• Allowing access to information exclusively to those who are fully entitled to such access for that purpose.
• Submitting reports to oversight and control authorities when applicable.
• Informing the data subject, when requested, of the use given to their information and personal data and handling their inquiries and requests.
• Requesting corrections or updates from the data subject regarding their information and personal data when applicable.
• Complying with the legal provisions applicable to this matter.
• Other duties that may apply.
TRANSFER AND TRANSMISSION OF INFORMATION AND PERSONAL DATA: When information and personal data are shared, transferred, or transmitted to third parties within national territory or abroad by LAZZA GLOBAL:
• Compliance with protection standards equivalent to those of the originating jurisdiction will be ensured.
• Transfer and transmission protocols will be established to ensure confidentiality, security, and purpose.
Only when required by law will prior, express, and informed consent be requested from the data subject for national or international transfer or transmission.
On the other hand, valid purposes for carrying out national or international transfers or transmissions include, without limitation:
• Management or processing of cloud services.
• Centralization of databases.
• Customer service from international centers.
• Provision of services in various jurisdictions.
• Compliance with contractual, legal, and/or commercial obligations.
• Validation and due diligence processes.
• Management of business relationships.
• Others that may apply.
PROCESSING BY INDEPENDENT THIRD-PARTY CONTROLLERS: Given the nature of the services provided by LAZZA GLOBAL, access to, or the transfer or transmission of, information or personal data may be facilitated to third parties acting as independent controllers, it being understood that such parties autonomously determine the purposes and means of processing the information and data they receive.
These third parties may include, without limitation: public blockchain networks, regulatory compliance agencies, risk analysis firms, identity verification platforms, competent authorities, among others.
Now then, under this scenario, the processing carried out by them will be subject to their own applicable policies and regulatory frameworks; therefore, LAZZA GLOBAL, will not be responsible for the use that such third parties make of the information when they act as autonomous data controllers, it being noted that efforts will be made to ensure that, to the extent possible, they maintain adequate standards of information and data protection and respect for the rights of data subjects.
These third parties may process the personal information and data of the data subject as independent data controllers for their own purposes, which may include, among others:
• Compliance with legal provisions.
• Prevention of unlawful activities.
• Improvement in the quality of services provided.
• Onboarding of users as their own customers or as customers of third parties.
• Pursuing legal claims, as well as taking any actions that may apply.
• Others that may apply.
In light of the foregoing, where applicable, users are advised to review the privacy and personal data processing policies established by these third parties before accepting or continuing to use services linked to, integrated with, or interoperable with LAZZA GLOBAL.
SECURITY MEASURES: By LAZZA GLOBAL administrative and technical security measures that are functional to protect the data subject's personal information and data will be applied and implemented, with the purpose of preventing unauthorized access, loss, alteration, destruction, among other related events.
It is noted that LAZZA GLOBAL, will act in accordance with the principles of good faith, due diligence, and proportionality; therefore, it will not be liable for damages or losses arising from events that exceed its reasonable control, including, but not limited to:
• Unauthorized access caused by the data subject's negligence.
• Failures attributable to third parties not affiliated with LAZZA GLOBAL.
• Cyberattacks or cybersecurity incidents that are not easily preventable.
• Cases of force majeure or fortuitous events determined as such by law and judicial precedent.
• Improper use of the information and personal data by the data subject.
• Lack of due diligence and care on the part of the data subject.
• Others that may apply.
These measures and processes, implemented with respect to security, will be based on, without limitation, the following principles:
• Confidentiality: Whereby efforts will be made to ensure that information and personal data are accessible only by authorized persons and on a need-to-know basis.
• Availability: It being understood that efforts will be made to ensure that information and services are available when needed.
• Integrity: Efforts will be made to protect the consistency of information and personal data against unauthorized modifications.
• Continuous risk management: Work will be carried out on the continuous identification, assessment, and mitigation of risks.
On the other hand, with respect to controls, the implementation of the following will be considered and pursued, without this constituting an exhaustive list.
• Encryption and authentication: Where, in cases where applicable, efforts will be made to protect information and personal data through encryption and strong authentication mechanisms.
• Access controls: Efforts are made to limit access to information and personal data, both to authorized third parties and to personnel associated with LAZZA GLOBAL, applying the principle of least privilege.
PRIVACY NOTICE: The privacy notice shall be understood as that physical, digital, verbal, or electronic instrument through which the data controller informs the data subject, in advance and in an express and informed manner, of the existence of the privacy and personal data processing policy, the conditions for processing their information and personal data, as well as the rights and duties applicable to them under the relevant legal framework.
Now then, this privacy notice has as its main objectives:
• Ensuring that the data subject is aware of the contact details of the controller and, where applicable, the processor.
• Identifying the categories of data collected.
• Determining the purposes of collection and processing.
• Establishing the rights and duties applicable to the data subject.
• Informing of the optional or mandatory nature of the provision of information and personal data.
• Communicating the location of and access to the complete policy for periodic review and consultation.
This policy, its privacy notice, and the request for authorization may be communicated to the data subject using the following means:
• In person, by means of physical forms, which will include a box or space for express acceptance.
• Email, sending the data subject the relevant information and creating a mechanism for response, confirmation, or acceptance.
• Website or mobile applications, through pop-up windows, banners, forms, or links containing visible, understandable text that generates a mechanism for response, confirmation, or acceptance.
• Instant messaging or SMS, when applicable to processing in mobile or agile environments.
• Phone recordings or automated flows, which may be used when the interaction takes place by voice or through a call center.
• Interactive chats on the website (chatbots or online assistance), a mechanism whereby, before the start of the conversation or during it, a message may be displayed or sent seeking to inform the data subject about the privacy and personal data processing policy and what this entails, clearly, expressly, and in an informed manner requesting and verifying that the data subject confirms and accepts it.
In these cases, continuing the interaction with the system may be considered an unequivocal action, if permitted by applicable regulations.
Unequivocal actions, when the data subject continues to use a service, fills out a form, registers, browses through digital channels, or performs any action that implies voluntary acceptance.
Unless there is a legal provision to the contrary, the processing of personal data requires the prior, express, and informed consent of the data subject, which authorization may be given through channels such as:
• Handwritten or digital signatures.
• Electronic acceptance through checkboxes, websites, or mobile applications.
• Affirmative responses sent through electronic channels, text messages, chats, or other similar means.
• Voice recordings.
• Express consent in contracts, terms and conditions, policies, or other equivalent documents.
• Unequivocal actions when the data subject continues to use a service, fills out a form, registers, browses through digital channels, or performs any action that implies voluntary acceptance.
• Others that may apply and that allow for proof of due authorization by the data subject.
• Based on the foregoing, the data controller must retain sufficient proof of the granting of authorization, and of the conditions or means by which it was obtained.
• When applicable and involving sensitive data or minors, the authorization must be even more specific and explicit.
Finally, the authorization of the data subject regarding personal information and data will not be necessary in the following scenarios:
• When it concerns data of a public nature.
• When the information is required by a public or administrative entity in the exercise of its legal functions.
• When the information is required by judicial order.
• In cases of health or medical emergency.
• When the processing of information is authorized by law for historical, scientific, statistical, and other applicable purposes.
• Data related to the civil registry or birth registration of persons.
• Others that may apply by regulatory provision.
PROCEDURE FOR THE SUBMISSION OF REQUESTS AND EXERCISE OF RIGHTS: Data subjects may submit petitions, requests, claims, and generally exercise their rights, by means of a written request through the official contact channels made available by LAZZA GLOBAL on its website WWW.LAZZAGLOBAL.COM and/or the email address [email protected], to which an identification number will be assigned and which will be addressed within the time periods established by law for such purposes.
These requests must mandatorily contain the following information:
• Full names and identification of the data subject.
• Clear description of the request, petition, complaint, or claim.
• Notification and contact information.
• If applicable, documentary support for the request.
When these requirements are not met, the request will be returned for correction, and from the time of its new submission the response period established by law shall run.
MODIFICATIONS: This policy may be adjusted at any time for the purpose of making modifications, adaptations, updates, or legal, technological, or corporate changes; therefore, LAZZA GLOBAL may personally notify data subjects of such changes, although it will not be obligated to do so, indicating that updates and/or modifications will be uploaded directly to the website of LAZZA GLOBAL, and it will be the duty of data subjects to periodically review this policy in order to keep informed of any such modifications or adjustments that may materialize.
When such modifications are made, the date of this policy will be updated and it will become effective as of its update date.
RETENTION: Information and personal data will be retained to allow continued use of the services of LAZZA GLOBAL, for as long as necessary to fulfill the previously communicated purposes of processing; therefore, it may be retained indefinitely while there is a commercial, contractual, legal, or service relationship with the data subject, or for as long as necessary to fulfill possible responsibilities arising from the processing or to comply with regulatory obligations as applicable, including without limitation, requirements of competent authorities, AML/CFT regulations, dispute resolution, or legal claims.
Even after the relationship with the data subject has ended, the information may be retained in whole or in part in the controller's records and databases, when its deletion is not required by a legal provision or when there is an interest that justifies it, all under technical and security measures to protect the information and personal data.
Likewise, when the information or personal data of data subjects is no longer necessary to fulfill the purposes previously referred to, it may be deleted or, in addition to the foregoing, kept anonymously in a secure manner.
ACCEPTANCE: The data subject understands that they accept this policy and related documents by giving their consent or authorization expressly, through means such as physical, electronic, digital, or verbal channels enabled for this purpose, completion of forms, checking of boxes (checkbox), handwritten or digital signatures, or any other means that may serve as a reasonable means enabled for such purpose by LAZZA GLOBAL.
It is stated that, without prejudice to the foregoing, it will also be understood that there is tacit and unequivocal acceptance when the data subject, upon becoming aware of the existence of this policy, continues to use the services, browses the website, applications, or platforms, registers, accesses their profile, carries out operations, issues instructions, provides personal information, or participates in the services and activities promoted by LAZZA GLOBAL, without expressing any type of opposition to the processing of their personal information and data.
It being understood that these unequivocal actions demonstrate a clear intention on the part of the data subject to continue the relationship with LAZZA GLOBAL, under the conditions established in its corporate guidelines, including this policy, and therefore, they will be understood as a valid expression of consent and authorization, in accordance with applicable regulations.
LANGUAGES: This privacy policy may be published in different languages, indicating that, in the event of any difference or disagreement, the English version shall prevail, followed by the Spanish version, and then any others that may arise.
DIRECT CONTACT INFORMATION: You may contact the privacy and personal data protection department through the email address [email protected], where efforts will be made to resolve any concern or request directly related to the processing of information and personal data, in compliance with the legal terms established for such purpose.
EFFECTIVE DATE: This policy supersedes and amends the prior one, entering into force as of July 1, 2026.
Both the policy and the databases containing the information and personal data provided by the data subject may remain in effect indefinitely and for up to the term of duration of the company LAZZA GLOBAL.














































