Privacy Policy
Nobiglobal Servicios Financieros S.A.S. (hereinafter "Nobiglobal", "we") operates the website nobiglobal.com. This Privacy Policy describes how we collect, use and protect your personal data under Ecuador's Organic Law for the Protection of Personal Data (LOPDP), published in Official Registry Supplement 459 on 26 May 2021.
1. Data controller
Nobiglobal Servicios Financieros S.A.S., Tax ID 1793209876001, with registered office at Av. República del Salvador N36-84, Mansión Blanca Building, 8th floor, Cumbayá, Quito, Ecuador. Data Protection Officer: privacidad@nobiglobal.com.
2. Data we collect
We collect identification data (name, national ID or passport), contact data (email, phone), economic data for the KYC process (proof of income, source of funds) and navigation data (IP address, device type, pages visited).
3. Purpose and legal basis
We use your data to manage your registration as a lender, comply with legal obligations (KYC, anti-money laundering under the UAFE), send you communications about new operations if you have opted in, and improve our services. The legal basis is consent (art. 7 LOPDP), contract performance and compliance with a legal obligation.
4. Retention
We keep your data while there is a contractual relationship and, after termination, for 10 years as required by the General Regulation to the Anti-Money Laundering Law.
5. Recipients
We may share your data with Fiducia S.A. (trust vehicle), Security Data (electronic signature), the Superintendency of Companies, the Internal Revenue Service, the UAFE, and cloud infrastructure providers located in the European Union with adequate international transfer safeguards.
6. Your rights
You may exercise ARCO rights (access, rectification, cancellation, opposition), portability, restriction of processing and the right not to be subject to automated decisions by writing to privacidad@nobiglobal.com. You may also file a claim with Ecuador's Superintendency for the Protection of Personal Data.
7. Security
We apply TLS 1.3 encryption in transit, AES-256 encryption at rest, mandatory two-factor authentication and annual security audits under the ISO/IEC 27001 standard.
8. Changes
We will publish any changes on this page. If a change is material, we will notify you by email at least 30 days before it takes effect.