Privacy Policy
Last updated: September 2, 2026
1. Data controller
Controller: Luis Zárate, a natural person carrying out business activity in Colombia, operating under the trade names Ascensa Global and Ascensa Labs (together, "Ascensa," "we," "us").
[PENDING: Ascensa is in the process of incorporating as a company in a free zone in Dubai, United Arab Emirates. Once that incorporation is finalized, this section will be updated with the legal entity name, trade license number, and registered address in Dubai. Until then, the controller of the personal data collected through this site is Luis Zárate, a natural person domiciled in Colombia.]
Address: Calle 144 # 12-31, Bogotá D.C., Colombia
Contact email for privacy matters: management@ascensaglobal.com
This policy applies to ascensaglobal.com (ascensaacademy.com automatically redirects to this domain) and to the forms, products and services offered on it.
2. Applicable legal frameworks
Ascensa serves people in different countries, so this policy is written to the highest standard among the three frameworks that apply to us, detailing the specifics of each where relevant:
- The EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and, for Spain, Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD): apply if you are located in the European Union or Spain, or if we process data of people located there.
- Colombian Law 1581 of 2012 and its implementing Decree 1377 of 2013, which govern the right of habeas data: apply because Ascensa currently operates from Colombia and processes data of people located in Colombia.
- The UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, PDPL): applies to the data of people located in the United Arab Emirates, the market Ascensa is expanding its operations toward.
If you are unsure which framework applies to you, write to us at management@ascensaglobal.com and we will clarify.
3. What data we collect
We collect data depending on the form or channel you use:
- Account Radar (audit request form): name, WhatsApp number, email address, the advertising platform you invest on, your monthly investment range, who manages your campaigns, whether you know your key metrics (CPA, average ticket), and, if you choose to share it, an open-ended note about why you're reaching out.
- Dubai Ad Account Scorecard (free lead magnet): email address and, if provided, your company name, your niche, and how you found us.
- Waitlist / newsletter (site pop-up): email address and, if provided, your name.
- Browsing data: IP address, browser and device type, pages visited, time on site, and traffic source, collected through cookies and similar technologies described in our Cookie Policy.
- Ad account access data: if you purchase the Account Radar or a media management service, we access your Meta Ads, Google Ads or other authorized advertising account in read-only mode, along with the metrics visible there. We do not access your payment methods or administrator credentials.
- Billing data: if you purchase a paid product, your payment method details are handled directly by PayPal, our payment gateway; we do not store your full card or PayPal account details.
- Direct communications: if you email or message us on WhatsApp, we keep that conversation so we can follow up.
We do not request or intend to collect special categories of data (health, ethnic origin, political affiliation, or similar). If you share this kind of information voluntarily in a free-text field, we process it only for the purpose of the contact that generated it.
4. What we use your data for
- Responding to your Account Radar, Scorecard, or other product or service request.
- Delivering the services you purchase (audit, media management, media direction, training).
- Sending you your diagnostic results and coordinating the included session.
- Sending you marketing communications about our products and services, if you consented to it, or if you are a customer and applicable law allows this contact under legitimate interest (always with an opt-out).
- Measuring the performance of our own advertising campaigns on Meta and Google, and improving the site's content and functioning.
- Complying with legal, tax, and accounting obligations applicable to our business.
5. Legal basis for processing
Under the GDPR (European Union/Spain):
- Art. 6(1)(a) Consent, for sending marketing emails and using non-essential cookies.
- Art. 6(1)(b) Performance of a contract or pre-contractual measures, to handle your Account Radar request, deliver purchased services, and respond to your inquiries.
- Art. 6(1)(f) Legitimate interest, for measuring our own advertising campaigns and improving the site, always weighed against your rights and reasonable privacy expectations.
Under Colombian Law 1581 of 2012 and Decree 1377 of 2013:
Processing is based on the prior, express and informed authorization you grant by submitting your data through our forms, in accordance with Article 9 of Law 1581 of 2012. We inform you of the purpose of the processing on the form itself or at the point of collection, as required by Decree 1377 of 2013.
Under the UAE PDPL (Federal Decree-Law No. 45 of 2021):
Processing is based on your consent (Art. 6) for the purposes described in this policy, and, where applicable, on the necessity of processing your data to provide the service you request.
6. Who we share your data with
We do not sell your personal data. We share it only with the providers we need to run the site and deliver our services, each acting as a data processor or, in the case of payment gateways and advertising networks, sometimes as an independent controller of the data they process for their own purposes (for example, PayPal for payment processing, or Meta and Google for advertising measurement).
| Provider | What we use it for | Data processed | Location / international transfer |
|---|---|---|---|
| Supabase | Database where your requests (leads) and generated audits are stored | Name, email, WhatsApp, form responses | United States (us-east-1 region); transfer covered by the EU Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Brevo (Sendinblue SAS) | Sending confirmation emails, delivering the Scorecard, and marketing communications | Email, name, WhatsApp, form responses, open and click history | Company headquartered in France (European Union); in principle does not involve a transfer outside the European Economic Area |
| Hostinger Reach | Adding contacts from the site's newsletter pop-up and its welcome automation | Email, name | Hostinger International Ltd. (company headquartered in the European Union); any international transfer is governed by the mechanisms described in its privacy policy |
| Meta Platforms, Inc. (Meta Pixel and Conversions API) | Measuring the effectiveness of our advertising and optimizing campaigns | Cookies (_fbp, _fbc), IP address, browser type, and a hashed (SHA-256) version of your email, phone and name when you fill out a form | United States; transfer covered by the European Union's Standard Contractual Clauses and/or the EU-US Data Privacy Framework, to the extent Meta is certified under it |
| Google LLC / Google Ireland Limited (Google Analytics 4, Google Tag Manager) | Website usage analytics | Cookies, IP address, pages visited, traffic source | United States; transfer covered by the EU-US Data Privacy Framework and/or Standard Contractual Clauses |
| PayPal (PayPal, Inc. / PayPal (Europe) S.à r.l. et Cie, S.C.A.) | Payment processing | Payment and billing data you manage directly with PayPal | United States and other jurisdictions, depending on PayPal's operations; PayPal acts as an independent controller under its own privacy policy |
| Vercel Inc. | Website hosting | Technical connection data (IP address, HTTP headers) | United States; transfer covered by the mechanisms Vercel describes in its own privacy policy |
| WhatsApp (Meta Platforms, Inc. / WhatsApp Ireland Ltd.) | Direct coordination when you message us or we message you on WhatsApp | Your phone number and the content of the conversation | Depends on WhatsApp's infrastructure; subject to WhatsApp's privacy policy |
We may also share data when a competent authority legally requires it, or as part of a potential sale or restructuring of the business, always in a manner consistent with this policy or with prior notice of any material change.
7. International data transfers
Several of the providers listed above are located outside your country of residence, including the United States. When we transfer personal data of EU residents to a provider outside the European Economic Area, we rely on the mechanisms recognized as valid under the GDPR: the provider's certification under the EU-US Data Privacy Framework, where applicable, or the Standard Contractual Clauses approved by the European Commission.
For residents of Colombia, these transfers are carried out in accordance with the exceptions and conditions set out in Law 1581 of 2012 and Decree 1377 of 2013, including the authorization you grant when submitting your data.
For residents of the United Arab Emirates, these transfers are carried out in accordance with the international transfer mechanisms recognized under the PDPL (Federal Decree-Law No. 45 of 2021).
8. How long we keep your data
- Leads and contacts without a purchase (Radar, Scorecard, newsletter, outreach requests): we keep your data until you withdraw your consent or request its deletion, and for a maximum of 24 months from the last contact.
- Customers (Account Radar, media management, training): for the duration of the contractual relationship and, afterward, for the retention period required by applicable commercial and tax law. In Colombia, under Article 60 of the Commercial Code, a merchant's books and records, including commercial and billing documents related to your purchase, must be kept for 10 years. [PENDING: once the entity in Dubai is incorporated, the applicable retention period under its commercial and tax rules will be added here.]
- Technical and cookie data: as set out in our Cookie Policy.
You may request early deletion of your data at any time, subject to the rights described in the next section, unless we have a legal obligation to keep it.
9. Your rights
If you are located in the European Union or Spain (GDPR): you have the right to access your data, rectify it, request its deletion, restrict or object to its processing, request data portability, and not be subject to decisions based solely on automated processing. You also have the right to file a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es, or with the data protection authority of your EU country of residence.
If you are located in Colombia (habeas data, Law 1581 of 2012): you have the right to know, update and rectify your data; to request proof of the authorization granted; to be informed about how we have used it; to file complaints with the Superintendencia de Industria y Comercio (SIC) for violations of the law; to revoke your authorization and/or request deletion of your data when there is no legal or contractual duty requiring us to keep it; and to access your data free of charge.
If you are located in the United Arab Emirates (PDPL, Federal Decree-Law No. 45 of 2021): you have the right to be informed about the processing of your data, to access it, to request its correction or deletion, to restrict or object to its processing, to data portability, and to file a complaint with the UAE Data Office.
10. How to exercise your rights
Write to us at management@ascensaglobal.com, telling us which right you want to exercise and providing the information needed to identify you. We respond within a maximum of 30 calendar days as a general rule, in line with the GDPR. If you are located in Colombia, we apply the deadlines under Law 1581 of 2012: 10 business days for inquiries and 15 business days for complaints, both counted from receipt of your complete request.
11. Data security
We apply reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS), access controls on our internal tools, and the use of providers that maintain their own security measures. No system is entirely fail-safe; if we detect a security incident affecting your data, we will notify you as required by applicable law.
12. Minors
Our products and services are intended for people over 18 years old. We do not knowingly collect data from minors. If you become aware that a minor has provided us with personal data, please contact us so we can delete it.
13. Cookies
The use of cookies and similar technologies on our site is described in detail in our Cookie Policy, which forms part of this Privacy Policy.
14. Changes to this policy
We may update this policy to reflect changes in our practices, the providers we use, or applicable law. We will publish the current version on this page, with its last-updated date.
15. Contact
For any questions about this policy or about how we process your data: management@ascensaglobal.com