Privacy Policy
This policy explains how Congero Technology Group Inc. and its group companies (collectively, “Congero,” “we,” “us”) process the personal data we collect through the congerotechnology.com website and its subdomains (the “Site”).
Data controller for the Site:
Congero Technology Group Inc.
12110 Sunset Hills Rd, Suite 600, Reston, Virginia 20190, United States
Privacy email: webmaster@congerotechnology.com
1. Who we are
This policy covers only the personal data that we process as data controllers through the Site and our business and marketing activities.
It does not cover personal data that we process on behalf of our clients in connection with ERP, CRM, billing, automation, or managed-services implementation projects. In those cases, we act as data processors, and our obligations are governed by the data processing agreement entered into with the client, which is the data controller for that data. If you are an end customer of a company that uses systems implemented by Congero, direct your requests to that company.
This policy also does not apply to third-party websites linked from the Site.
| Country | Company / office | Location |
|---|---|---|
| United States (headquarters) | Congero Technology Group, Inc. | Reston, Virginia |
| Costa Rica | Congero Costa Rica | San José |
| Brazil | Congero Brasil | São Paulo |
| Sweden | Congero Suecia | Solna |
| Mexico | Congero México | Querétaro |
| Canada | Congero Canadá | Toronto |
| India | Congero India | Bangalore |
Group privacy officer: Privacy Officer — Congero Technology Group — webmaster@congerotechnology.com. This appointment fulfills the role of data protection officer contemplated by Article 41 of Brazil’s LGPD and serves as the single privacy point of contact for all operations.
European Union representative (Article 27 GDPR): Pending designation. We will update this policy as soon as a representative is appointed.
2. What data we collect and where it comes from
2.1 Data you provide to us
| Source | Data | Required? |
|---|---|---|
| Contact form | Name, email address, message | Yes — without them, we cannot respond |
| Contact form | Telephone number, company | No — optional |
| Demo or proposal request | The above, plus job title, country and business need | As specified in the form |
| Communications subscription | Email address and, where applicable, name and company | Yes |
| Recruitment | Application data | Depending on the vacancy |
2.2 Data collected automatically
When you visit the Site, our servers and the tools described in section 6 record: IP address (truncated where the tool allows), browser type and version, operating system, language, referring page, pages visited, time spent, date and time of access, and interaction events.
We do not collect precise geolocation data from your device. Approximate location inferred from the IP address is limited to country and, in some cases, city.
We use business-identification and data-enrichment tools that may associate a visit with the originating company and supplement professional contact details with information from public sources, professional networks and specialist B2B data providers.
2.3 Data from other sources (Article 14 GDPR)
| Source | Data that may be obtained |
|---|---|
| B2B contact-data providers, including Apollo.io | Name, job title, business email, company, industry and company size |
| Professional networks, including LinkedIn | Public professional profile and interactions with our content |
| Public registers and sources | Corporate and business contact information |
When we obtain your data from these sources, we will notify you in our first communication, indicating the source and your right to object.
2.4 Children’s data
The Site is intended solely for professionals and organizations. We do not knowingly collect data from minors. The applicable threshold varies by country (between 13 and 16 in EU Member States, 13 in the United States, and as provided by local law elsewhere). If we discover that we received data from a minor, we will delete it. Parents or guardians may contact webmaster@congerotechnology.com.
3. Why we process your data, legal basis and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Respond to inquiries | Identification, contact and message data | Pre-contractual measures; legitimate interests | 24 months from last contact |
| Business relationships and proposals | Professional contacts and interaction history | Contract or pre-contractual measures | Relationship + 10 years for accounting/tax duties |
| Marketing and newsletters | Business email and preferences | Consent; where applicable, B2B legitimate interests with right to object | Until unsubscribe + 12 months of unsubscribe records |
| B2B development using third-party data | Professional contact data | Legitimate interests with documented balancing assessment | 12 months without response |
| Site analysis | Cookie identifiers and browsing data | Consent | Section 6 |
| Advertising and remarketing | Advertising identifiers | Consent | Section 6 |
| Security and abuse prevention, including reCAPTCHA | IP address and technical data | Legitimate interests | 12 months |
| Legal, accounting and tax compliance | Necessary data | Legal obligation | Applicable statutory periods |
| Defense against claims | Necessary data | Legitimate interests | Applicable limitation period |
| Recruitment | Application data | Consent and pre-contractual measures | 12 months unless longer retention is consented to |
No data is retained for more than 10 years following the end of the relationship unless a legal obligation requires longer. On expiry, data is deleted or irreversibly anonymized. Where we rely on legitimate interests, you may request a summary of our balancing assessment.
4. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. We use automated lead scoring to prioritize sales outreach. It does not determine access, price or contractual terms, and human involvement is always present. You may request information about the logic, object or request human review by emailing us. California residents also have the rights in section 9.3.
5. Use of artificial intelligence
Pursuant to Article 50 of the EU AI Act, applicable from August 2, 2026, we inform you that the Site does not include chatbots or AI conversational assistants. If we introduce one in the future, we will clearly identify it at the start of the interaction and update this policy.
Blog and press-room content generated or assisted by AI undergoes human editorial review. We do not use your personal data to train our own or third-party AI models.
6. Cookies and tracking technologies
6.1 How consent works
On first entry, a cookie settings panel keeps non-essential cookies disabled until accepted. “Accept all” and “Reject all” are equally accessible, with category settings. You may change or withdraw consent through the “Cookie settings” link in the footer.
6.2 Cookie and technology inventory
| Category | Tool/provider | Purpose | Duration | Consent? |
|---|---|---|---|---|
| Strictly necessary | WordPress session | Basic operation and form security | Session | No |
| Strictly necessary | Cookie preference record | Remember choice | 6–12 months | No |
| Security | Google reCAPTCHA | Prevent spam and automated submissions | According to Google | No; legitimate interests |
| Analytics | Google Analytics 4 | Audience measurement and behavior | Up to 24 months | Yes |
| Advertising | Google Ads / remarketing | Targeted ads and conversion measurement | Up to 24 months | Yes |
| B2B identification | Apollo.io | Company identification and contact enrichment | According to provider | Yes |
| Social media | LinkedIn Insight Tag | Campaign and audience measurement | According to LinkedIn | Yes |
6.3 reCAPTCHA
Site forms are protected by Google reCAPTCHA and are subject to Google’s Privacy Policy and Terms of Service.
6.4 Browser signals
We honor Global Privacy Control (GPC) as a valid browser- and device-level request to opt out of sale and sharing. We do not process the older “Do Not Track” signal because it lacks a uniform standard.
7. With whom we share your data
We do not sell personal data for money. We share it only with group companies; infrastructure and hosting providers; CRM and marketing-automation providers; Google and LinkedIn for analytics/advertising; Apollo.io for B2B intelligence; professional advisers; authorities where legally required; and a purchaser in a merger, acquisition or asset sale, with prior notice and continuing protection.
Infrastructure and hosting: AWS (United States). CRM and marketing automation: Odoo (United States).
Providers act as processors under written contracts requiring confidentiality, appropriate security and processing only under our instructions.
8. International data transfers
Congero operates in the United States, Costa Rica, Brazil, Sweden, Mexico, Canada and India. Data may therefore be processed outside your country.
- EU/EEA to the United States: EU–U.S. Data Privacy Framework for certified providers, otherwise the 2021 Standard Contractual Clauses.
- Countries without an adequacy decision, including India, Costa Rica, Brazil and Mexico: 2021 Standard Contractual Clauses plus measures from transfer-impact assessments.
- Between group companies: an intra-group transfer agreement with equivalent safeguards.
You may request a copy of applicable safeguards. Under Costa Rica Law No. 8968, transfers outside the economic interest group require unequivocal, informed consent unless otherwise provided by law.
9. Your rights
9.1 General rights
Regardless of residence, we recognize rights of access, rectification, erasure, objection, restriction, portability, withdrawal of consent and non-discrimination.
9.2 How to exercise them
Email webmaster@congerotechnology.com or write to our postal address, stating the right you wish to exercise. We may request only the information necessary to verify identity. Representatives must demonstrate authority. Exercising rights is free.
| Jurisdiction | Response period |
|---|---|
| EU / United Kingdom | 1 month; up to 2 additional months for complexity |
| Costa Rica | 5 business days for rectification; otherwise as soon as possible |
| United States | 45 days; extendable by 45 days |
| Brazil | As soon as possible and free |
| Canada | 30 days |
| India | Up to 90 days for complaints |
| Mexico | Per the competent authority’s procedure |
As a general rule, we respond within 30 calendar days.
9.3 Additional rights by jurisdiction
California (CCPA/CPRA): rights to know, delete, correct, limit sensitive-data use, and opt out of sale/sharing and certain automated decision-making. Use the footer link “Do Not Sell or Share My Personal Information” or GPC. Authority: California Privacy Protection Agency.
Virginia and other U.S. states: access, correction, deletion, portability, opt-outs from targeted advertising, sale and significant-effect profiling, and appeal rights.
EU/EEA: you may complain to your local supervisory authority; in Sweden, the Integritetsskyddsmyndigheten (IMY).
Costa Rica: contact PRODHAB of the Ministry of Justice and Peace.
Brazil: Article 18 LGPD rights including confirmation, access, correction, anonymization, blocking, deletion, portability, sharing information and consent withdrawal. Authority: ANPD.
Mexico: ARCO rights and consent withdrawal under the Federal Law on Protection of Personal Data Held by Private Parties published March 20, 2025. Competent authority: Secretaría Anticorrupción y Buen Gobierno.
Canada: rights under PIPEDA and, in Quebec, Law 25. Complaints may be made to the Office of the Privacy Commissioner of Canada.
India: access, correction, erasure, nomination, easy consent withdrawal and complaint to the Data Protection Board of India.
10. Marketing communications
We send marketing only with consent or another lawful basis for professional prospecting. In Canada, we apply CASL. Marketing emails identify the sender, include our physical address and provide a free, one-step unsubscribe link operational for at least 30 days. We process opt-outs within 10 business days and in practice immediately. Opting out does not stop operational project or contract emails.
11. Information security
We use measures proportionate to risk, including TLS encryption in transit, role-based access and least privilege, enhanced authentication for critical systems, logging, staff training, confidentiality obligations and provider assessments. Internet transmission is never completely secure, but we maintain and periodically review an appropriate level of protection.
12. Personal data breaches
We maintain a documented incident-management process. Notifications are made within applicable periods: EU supervisory authorities within 72 hours where risk exists; PRODHAB and affected Costa Rican individuals within 5 business days; India’s Data Protection Board initially without delay and in full within 72 hours; affected individuals without undue delay where high risk exists; and other authorities according to local law.
13. Links to third-party sites
The Site links to resources such as LinkedIn, Facebook and technology-partner websites that we do not control. We are not responsible for their privacy practices and recommend reviewing their policies before providing data.
14. Changes to this policy
We may update this policy. We will change the “Last updated” date and, for material changes to purposes, recipients or legal bases, provide a prominent Site notice and, where possible, email notice before applying the change. Version history is available by emailing us.
| Version | Date | Main changes |
|---|---|---|
| 3.0 | August 13, 2026 | Multi-jurisdictional framework, legal bases, retention, cookie consent, AI transparency and jurisdictional rights |
| 2.0 | March 2, 2022 | Previous generic-template version |
15. Accessibility
We work to ensure the Site complies with WCAG 2.2 Level AA. Report accessibility barriers to accessibility@congerotechnology.com.
16. Contact
Privacy officer — Congero Technology Group
Email: webmaster@congerotechnology.com
Address: 12110 Sunset Hills Rd, Suite 600, Reston, Virginia 20190, United States
Costa Rica office: Oficentro Ejecutivo La Sabana, Floor 7, San José, 10108, Costa Rica
European Union representative: Pending designation
We will address inquiries or complaints as soon as possible and within applicable statutory periods. If unsatisfied, you may contact the supervisory authority identified in section 9.3.