1. Purpose of This Policy
This Privacy, Confidentiality & Digital Security Policy describes the general principles used by prograph.com to receive, process, store, transmit, and protect information through www.prograph.com.
Its purpose is to explain, in clear terms, what information may be received, why it may be needed, how it may be used, which general safeguards may apply, and what users should do to protect accounts, communications, and documents associated with this site.
2. Information That May Be Received
Depending on the functions available on this website, information voluntarily provided by a user may include:
- Name and contact information.
- Email address.
- Telephone number or another contact method.
- Messages, questions, requests, or instructions.
- Information entered into forms.
- Documents or files voluntarily uploaded or transmitted.
- Information related to a requested service or business relationship.
- Technical information reasonably required for operation, security, diagnostics, or fraud prevention.
The fact that a form can accept certain information does not mean that a user should provide information that is unnecessary for the purpose of the communication. Users should limit submissions to information reasonably needed for the intended transaction or request.
3. Use of Information
Information received through this website may be used for legitimate purposes connected with site operation and requested services, including:
- Responding to communications.
- Processing requests or transactions.
- Providing services.
- Receiving or delivering documents.
- Managing relationships with clients, users, or authorized contacts.
- Maintaining necessary administrative records.
- Preventing fraud, misuse, or unauthorized activity.
- Investigating technical or security issues.
- Protecting the integrity and availability of the website.
- Complying with applicable legal obligations.
Information should not be deliberately used for purposes materially incompatible with the reason it was provided, except where authorized or legally required.
4. Confidentiality
prograph.com seeks to limit access to confidential information to people who reasonably need it for an authorized purpose.
Users, administrators, contractors, collaborators, and other authorized persons who obtain access to information through www.prograph.com should handle it responsibly and avoid unnecessary disclosure. Authorized access does not, by itself, authorize copying, redistribution, disclosure, or use for an unrelated purpose.
5. Security of Communications
When properly configured by the hosting environment, www.prograph.com may use HTTPS/TLS encryption to help protect information while it travels between a user's device and the web server.
Encryption in transit is an important safeguard, but no Internet-connected technology can guarantee absolute security. Accordingly, prograph.com follows a layered-risk approach rather than representing that any digital system is completely immune to software vulnerabilities, human error, malicious attacks, infrastructure failures, compromised devices, or circumstances outside reasonable control.
6. Forms and Information Transmission
Forms on www.prograph.com should be used only for their intended purposes.
Before submitting information, users should verify:
- That they are on the correct domain.
- That the browser indicates a secure HTTPS connection when appropriate.
- That the information entered is accurate.
- That selected files are the files they actually intend to transmit.
- That they are authorized to share the information being submitted.
No form on this site may be used to intentionally transmit unlawful, malicious, fraudulent, abusive, or security-compromising content.
7. Documents and Files
When this site permits documents to be sent, received, stored, or retrieved, additional safeguards may apply. Depending on the service, these safeguards can include:
- User authentication.
- Private access links.
- Unique identifiers or security tokens.
- Link expiration.
- Access restrictions.
- Activity logs.
- Download controls.
- Additional identity or authorization checks.
- Logical separation between accounts, users, or workspaces.
The existence of a link to a document does not necessarily create permanent authorization to access it. Access may be limited, revoked, or allowed to expire according to the service configuration.
8. User Accounts and Credentials
When www.prograph.com provides private accounts, access credentials are intended for the authorized user.
Do not share passwords, login credentials, recovery codes, or private access credentials with unauthorized people.
If several people legitimately require access to a system, separate credentials should be used whenever the platform permits them. Shared accounts reduce accountability and make it more difficult to determine who performed a particular action.
9. Password Protection
Users should choose reasonably strong passwords and avoid reusing passwords from other important services.
Avoid easily guessed passwords such as names, common dates, predictable sequences, or previously compromised credentials. If a user suspects that credentials have been exposed, the password should be changed and the appropriate site administrator should be notified as soon as reasonably possible.
10. Shared Computers and Public Devices
Accessing confidential information from public computers or devices outside the user's control is discouraged.
When use of a shared device cannot be avoided:
- Do not allow the browser to save the password.
- Sign out completely when finished.
- Avoid unnecessary local downloads of confidential files.
- Remove local copies when appropriate and authorized.
- Confirm that another person cannot resume the authenticated session.
Closing a browser window is not always the same as securely signing out.
11. Social Engineering and Fraudulent Communications
Digital security depends on both technology and human judgment. Users should be cautious of messages that attempt to obtain passwords, verification codes, credentials, confidential documents, financial information, or administrative access.
prograph.com recommends independently verifying unusual or unexpected requests before providing sensitive information. A message displaying an organization's name, logo, or apparent email address is not, by itself, proof that the communication is authentic.
12. Private Access Links
Private, personalized, or tokenized links should be treated as confidential information. They should not be published, posted publicly, forwarded unnecessarily, or shared with unauthorized persons.
Where technically supported, private links may be revoked, restricted, limited to particular sessions, or configured to expire.
13. Technical and Security Logs
To protect the operation of www.prograph.com, the system may generate technical records concerning access, errors, security events, requests, or attempted activity.
Such records can include date and time, IP address, browser information, device characteristics, operation performed, request outcome, and other technical data reasonably necessary for security, auditing, diagnostics, troubleshooting, or abuse prevention.
These records should not be deliberately used for purposes incompatible with legitimate site operation, administration, or security.
14. Administrative Access
Administrative privileges for www.prograph.com should be used only when necessary for authorized duties.
Where practical, the principle of least privilege should be followed so that each user receives only the permissions reasonably required for that user's function. Administrative access should not be casually shared among multiple people.
15. Backups
Backups may be created to support continuity, recovery, restoration, and resilience of site information and systems.
The existence of a backup does not necessarily imply permanent retention. Backup schedules, rotation periods, encryption, storage locations, and deletion practices may depend on technical, operational, contractual, and legal requirements.
16. Retention of Information
Information may be retained for as long as reasonably necessary to provide services, maintain operational records, resolve disputes, support contractual obligations, protect legitimate interests, comply with legal requirements, or maintain system integrity and security.
When information is no longer reasonably necessary, it may be deleted, anonymized, archived, or otherwise handled in accordance with applicable operational and legal requirements.
17. Third-Party Technology Services
The operation of www.prograph.com may depend on third-party providers for hosting, infrastructure, email delivery, security, backup, domain administration, analytics, anti-spam services, content delivery, or other technical functions.
Where third parties are used, reasonable efforts should be made to select services appropriate for the function they perform. Each provider nevertheless maintains its own infrastructure, policies, controls, and operational responsibilities.
18. Cookies and Technical Technologies
This site may use cookies or similar technologies that are necessary to maintain sessions, remember settings, protect forms, prevent abuse, provide requested functionality, or support technical operation.
If additional technologies are used in a manner that requires notice or consent under applicable law, separate notices or consent mechanisms may be provided.
19. Information Concerning Minors
This website should not be used to intentionally solicit personal information from minors when such collection is inappropriate for the purpose of the service.
Where an activity is legitimately directed to minors, applicable consent, notice, and protection requirements should be observed.
20. User Responsibility
Digital security is a shared responsibility. Technical infrastructure can provide safeguards, but users must also protect their credentials, devices, email accounts, private links, files, and the information they choose to share.
A well-designed system can still be compromised if a password is voluntarily disclosed, a device is left unlocked, a private link is forwarded without authorization, or a user's email account is compromised.
21. Security Incidents or Suspicious Activity
If unusual behavior is observed in connection with www.prograph.com—including unknown access, unexpected password requests, suspicious messages, unusual downloads, or possible security failures—the affected activity should be suspended when appropriate and reported to the responsible administrator.
Depending on the circumstances, responsive measures may include revoking access, invalidating links, changing credentials, terminating sessions, reviewing logs, restoring information, or implementing additional controls.
22. No System Is Absolutely Secure
prograph.com uses or supports safeguards designed to reduce reasonably foreseeable risk; however, no website, server, storage system, email service, telecommunications network, or data-transmission mechanism can guarantee absolute protection.
This policy describes security practices and principles. It is not a representation that a security incident can never occur.
23. Links to External Websites
www.prograph.com may contain links to resources controlled by third parties. Once a user leaves this domain, the privacy and security practices of the external site are governed by that third party's policies and controls.
The presence of an external link should not automatically be interpreted as a guarantee of the external site's security, privacy practices, availability, or content.
24. Changes to This Policy
The substantive content of this policy may be reviewed when site functions, services, data-handling practices, technologies, security controls, or applicable legal requirements materially change.
When a substantive revision is adopted, the policy version and review date should be updated.
- Policy version
- 1.0
- Last reviewed
- agosto 5, 2026
25. Dynamic Informational Elements
Certain headings, introductory statements, general security reminders, or courtesy messages displayed around this policy may vary automatically to keep the presentation current and contextually appropriate for visitors to prograph.com.
Those dynamic elements are informational only. They do not amend, replace, summarize, or override the substantive provisions of this Privacy, Confidentiality & Digital Security Policy.
If a dynamic message appears inconsistent with this policy, the fixed policy text controls.
26. Contact
Questions concerning privacy, confidentiality, security, or information handling on www.prograph.com may be directed through the official contact methods provided by this website.
Gerardo Torres-Martell
gtorres@prograph.com
A Final Security Reminder
The strongest safeguard is a combination of sound technology and careful decisions. While interacting with prograph.com, confirm recipients, protect private links, and avoid sharing credentials with people who do not require access. Careful actions reinforce every technical safeguard described above.
prograph.com
www.prograph.com