Privacy Policy
Last updated: 1 October 2026
1. Controller
The controller of personal data collected through basecoresales.com is Mariano Sandonato, an individual, CUIT 20-35996407-3, with address at La Pampa 3000, 6th floor, Unit C, CABA (C1428), Argentina. Privacy and data protection enquiries may be sent to [email protected].
2. Applicable framework
This policy is primarily governed by Argentina's Personal Data Protection Law No. 25,326, Regulatory Decree 1558/2001 and applicable rules and resolutions issued by the Agencia de Acceso a la Información Pública (AAIP).
The EU General Data Protection Regulation (GDPR) applies only where its territorial scope requirements are met. The mere fact that the website is available in English or can be accessed from Europe does not, by itself, determine that the GDPR applies. Where the GDPR applies to a specific processing activity, the provisions described in section 8 also apply.
3. Data and purposes
We collect information voluntarily provided through our website forms when a person requests information, a diagnostic, a meeting or a downloadable resource. We do not buy third-party databases for these purposes.
3.1. Contact form
Data: first name, last name (if provided), company, service of interest, WhatsApp number, email address (if provided) and message.
Purposes: to respond to the enquiry, manage the requested contact, prepare a commercial proposal where appropriate and arrange a call or meeting requested by the person.
Legal basis: consent given by voluntarily submitting the form and, where there is a pre-contractual or contractual relationship, the processing of the data necessary to handle it.
3.2. E-book download form
Data: first name, last name (if provided), company, WhatsApp number (if provided) and email address.
Purposes: to deliver the requested content and, where appropriate, handle the commercial enquiry initiated by the person. Recurring newsletters or marketing communications require additional consent through the dedicated marketing checkbox.
3.3. CRM — HubSpot
Information submitted through our forms may be stored in our CRM, currently HubSpot, to manage the specific enquiry or request, record its source and carry out the requested commercial follow-up.
This may include first name, last name, company, email address, WhatsApp number, service of interest, source form, message and UTM parameters present in the originating URL. UTM parameters are used to identify the source of a conversion and are not used by themselves to track a person across pages.
Being added to the CRM does not, by itself, authorise us to send newsletters or recurring marketing communications. That requires the separate consent described in section 3.4.
3.4. Marketing communications and newsletter
Recurring commercial communications, updates or newsletters are only sent to people who have voluntarily selected the dedicated marketing checkbox. The checkbox is unchecked by default and is not required to submit the form or to receive the requested response or content.
Consent is recorded together with the date and, where appropriate, the information needed to show how it was obtained. It can be withdrawn at any time, for example through the unsubscribe link included in our communications or by writing to [email protected].
3.5. Analytics — Google Analytics 4 and Cloudflare Web Analytics
When a person gives consent through the cookie banner, we use Google Analytics 4 to obtain statistics about website use, such as pages viewed, approximate traffic source, device/browser information and interaction events. To do so, Google Analytics uses technical identifiers (cookies) that distinguish visits and sessions.
Our configuration prevents personal data entered in the forms from being sent to Google Analytics. Analytics is used to measure and improve the website, not to send newsletters. If the person does not give consent, Google Analytics is not loaded.
In addition, to understand visit volume and the technical performance of the website, we use Cloudflare Web Analytics, which loads on every page. This tool does not set cookies or use local storage on the device, and it does not identify or track the person across sessions or across websites. It processes technical data about each visit, such as the page viewed, the referring site, the browser and device type, the approximate country and page load times, and presents them in aggregate. It does not receive the data entered in the forms. The basis for this processing is our legitimate interest in measuring how the website works in a minimally intrusive way.
3.6. WhatsApp
The website offers contact through WhatsApp. If a person chooses this channel, or provides their number in a form, we may use it to respond to their request and manage the conversation they initiated. Use of WhatsApp also involves processing by Meta/WhatsApp under its own terms and privacy policies.
3.7. Meeting booking — HubSpot Meetings
When a person books a meeting through HubSpot Meetings, the information entered into that service is processed to arrange the booking, send meeting-related communications and organise the requested service. This is in addition to any information the person may have previously provided on the website.
4. Providers, processors and international transfers
We use technology providers to operate the website and provide our services. They may process data on our behalf or receive data as part of the technical operation of the site. We do not sell personal data to third parties for their own commercial purposes.
Where a provider processes data from a country that does not provide an adequate level of protection recognised by Argentine law, the international transfer relies on a valid mechanism under Law 25,326, its regulatory decree and applicable AAIP rules. Available contractual mechanisms include the models approved by Disposition 60/2016 and those approved by AAIP Resolution 198/2023. Clauses or mechanisms required by other jurisdictions, such as the GDPR, are not automatically treated as sufficient for Argentine-law purposes.
| Provider | Function | Data / category | Main location |
|---|---|---|---|
| Resend | Sending the emails generated by the website forms | Data needed for the email and the form content | United States |
| HubSpot | CRM, contact management and meeting booking | Identification and contact data, company, request and related activity | European Union (Germany) |
| Google (Gmail) | Receiving and managing email sent to [email protected] | Content of emails received and contact data | United States |
| Google (Analytics 4) | Website analytics, only with consent | Analytics data, technical identifiers and events | United States |
| Vercel | Website hosting and technical delivery | Technical data needed to serve the website | United States |
| Cloudflare | Anti-bot security (Turnstile), delivery network, forwarding of email sent to [email protected] and aggregate visit and performance measurement (Web Analytics, cookieless) | Technical signals to prevent automated submissions; emails in transit; technical visit data | United States |
This list will be updated if we add providers or processing activities involving personal data.
5. Retention
- Enquiries and contacts without an ongoing commercial relationship: for the time necessary to handle the request and, as a general rule, up to 12 months after the last contact, unless there is a legitimate reason to keep them for a different period or the person requests erasure where applicable.
- Clients and contractual relationships: during the relationship and afterwards for the periods necessary to comply with legal obligations and to exercise or defend legal rights, applying the legal period relevant to each case.
- Accounting and tax records and receipts: for the periods required by applicable tax and accounting rules.
- Marketing consent: for as long as necessary to demonstrate consent and manage withdrawal. Where a person opts out of communications, we may retain a minimum suppression record to avoid contacting them again by mistake.
- Cookies and similar technologies: as described in the Cookie Policy.
Personal data is not kept for longer than necessary for the stated purposes, unless required by law or needed to exercise or defend legal rights.
6. Data subject rights
- Access to personal data and to the information required by Law 25,326.
- Rectification and updating of inaccurate or outdated data.
- Erasure where applicable and where no legal obligation or legitimate reason requires retention.
- Information about processing purposes and recipients.
- Withdrawal of consent for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, write to [email protected] stating the right you wish to exercise and providing reasonable information to verify your identity. The response periods set by Law 25,326 and its regulations apply.
7. Database registration
Base Core will comply, where applicable according to the nature and purpose of its databases, with registration obligations before the AAIP's National Register of Personal Databases. Argentine law provides for the registration of personal databases covered by the registration regime; registration, modification and deregistration of private databases are processed through TAD or GDE and are free of charge. The database to be registered is determined under the regime in force and the actual structure of the data processed.
8. GDPR / European Economic Area users
The GDPR applies only where its territorial-scope criteria are met, for example where goods or services are offered to people in the EEA or their behaviour is monitored within the scope of the GDPR. The mere international accessibility of the website does not, by itself, determine that it applies.
Where the GDPR applies, individuals may exercise, as applicable, the rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and the other rights recognised by the GDPR.
Where applicable, they may also lodge a complaint with the data protection authority of their place of residence or with the competent authority in Spain.
9. Security
We apply reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, destruction or improper disclosure. These include HTTPS connections, access controls on the tools we use, credential management and the use of providers that maintain their own security measures.
No system connected to the Internet can be guaranteed to be completely invulnerable. In the event of a relevant incident, we will take the appropriate containment, investigation and communication measures.
10. Children
Base Core's services are primarily aimed at businesses and professionals. The website is not designed to knowingly collect personal data from minors. If someone believes that a minor's data has been collected improperly, they can contact [email protected].
11. Changes
We may update this policy when our tools, processing activities, services or legal requirements change. The date at the top indicates the current version.

