Privacy Policy
OnTech DGI Reports · Effective date: October 10, 2026
This policy explains how OnTech Solutions Corp. (“OnTech”, “we”), a company of the Republic of Panama, handles personal data in the application available at contab.ontech.la (the “Application”), including the data obtained from QuickBooks Online. It complements the End-User License Agreement.
1. Roles
The companies that contract the Application (the “Customers”) decide what data they record in QuickBooks and what the Application is used for: regarding their vendors’ data they act as data controllers, and OnTech processes those data on their behalf and following their instructions. OnTech is responsible for the data of the Application’s user accounts.
2. Data we process
- Users of the Application: name, job title, e-mail address, role, companies they can access, password (stored only as a secure hash) and sign-in information such as failed attempts and lockouts.
- Data from QuickBooks Online, for each connected company: vendors (name or legal name, person type, RUC and DV, tax concept and source, withholding agent indicator and up to three e-mail addresses), chart of accounts, and bills, purchases (expenses) and vendor credits with their dates, numbers, lines, amounts and taxes.
- Documents generated by the Application: ITBMS withholding certificates (number, vendor, period, rate, public code, whether they were sent and how many times they were downloaded from the public link).
- Company configuration: legal data and logo, withholding parameters, and e-mail sending settings, including the SMTP password, which is stored encrypted.
- QuickBooks connection: the company identifier (realm ID) and the access and refresh tokens issued by Intuit, stored encrypted. We never receive the Customer’s Intuit password.
- Technical records: date, requested page, result and duration of each request, and the history of synchronizations and e-mail sendings, for security, support and troubleshooting.
3. Purposes
We use the data only to provide the service: authenticate users and control their access; synchronize data from QuickBooks Online; generate Annexes 72, 73 and 94, Form 43, the withholding report and its DGI file, and the withholding certificates; send the certificates by e-mail to the vendors when a user requests it; update a vendor in QuickBooks when an authorized user saves changes to it; and keep the Application secure and working. We do not use the data for advertising, we do not sell it, and we do not use it to profile individuals.
4. QuickBooks Online data
The Application accesses QuickBooks Online only after an administrator of the Customer authorizes it in Intuit, only for the company chosen at that moment, and only with the accounting permission (com.intuit.quickbooks.accounting). It reads the data listed above and writes to QuickBooks only when a user updates a vendor. The Customer can revoke access at any time from the Application or from its Intuit account. Use of QuickBooks is also subject to Intuit’s own privacy policy.
5. Who we share data with
- Intuit Inc., to read and update data in QuickBooks Online on behalf of the Customer.
- The e-mail provider configured by the Customer (for example Google Workspace), which sends the certificates to the vendors’ addresses.
- Infrastructure providers that host the servers of the Application, under confidentiality obligations.
- Authorities, when required by law or a court order.
We do not share data with any other third party. The reports and files that the Customer downloads and files with the DGI are filed by the Customer.
6. Security
Connections use HTTPS. Passwords are stored as hashes; QuickBooks tokens and the SMTP password are encrypted. Each company’s data is separated and users only see the companies assigned to them. The database is not exposed to the Internet and is backed up daily. Generated PDF, Excel and TXT files are created on request and sent to the browser or by e-mail; they are not stored on our servers.
7. Retention
We keep the data while the Customer uses the service, so that reports for previous periods can be regenerated. When the Customer ends the service or requests it, we delete its data and its connection to QuickBooks. Backups are kept for up to fourteen (14) days and are then deleted automatically. Technical records are kept for a limited time, only for security and support.
8. Cookies
The Application only uses cookies that are necessary for it to work: the signed-in session, protection against cross-site request forgery, the company selected by the user, and a temporary cookie during the connection to QuickBooks. It does not use advertising or third-party analytics cookies.
9. Your rights
In accordance with Law 81 of 2019 on the protection of personal data of the Republic of Panama and its regulations, data subjects can request access to, rectification, cancellation and portability of their data, and object to their processing. Vendors whose data come from a Customer’s QuickBooks should preferably address the Customer, who controls that data; OnTech will assist the Customer in responding. Requests can be sent to info@ontech.la and will be answered within the time limits set by law.
10. Minors
The Application is intended for companies and their staff. It is not directed at minors.
11. Changes
We may update this policy. The current version, with its effective date, is always published at this address, and significant changes will be notified in advance to the Customers’ administrators.
12. Contact
OnTech Solutions Corp. · Republic of Panama · info@ontech.la
A Spanish version of this policy is available at /legal/privacidad. In case of discrepancy, the Spanish version prevails.
