Skip to content
Ditap®
Back to Home

Corporate Governance & Code of Conduct

Last updated: August 2026

1. How we govern ourselves today

DITAP is a private company, founded and led by Jhonatan Matias, operating in Argentina, Chile, and Italy. Our corporate governance rests on a real code of conduct, applied on every project across all three regions, and on unified technical and business leadership.

This document describes the principles that govern how we work, how we handle client data, how we govern the use of artificial intelligence in our operations — DITAP is an AI-native company, with AI agents in every area under human supervision — and what to do if someone spots conduct that departs from these principles. This code is reviewed periodically and updated as the company's structure evolves.

2. Integrity and anti-corruption

DITAP does not offer, solicit, or accept improper payments, commissions, or benefits to obtain or retain business, or to influence the decision of a client, supplier, or public official. This applies in each of the three countries where we operate, even where local practice is looser.

Concrete principles:

  • No payments, gifts, or courtesies that could be read as an attempt to improperly influence a business decision are made or accepted.
  • Every quote, invoice, and contract reflects work actually performed — no overbilling, no fictitious line items.
  • Tender and supplier-selection processes are decided on technical and economic merit, not on undisclosed personal relationships.
  • Any informal payment request from a third party (including public officials) is refused and documented internally.
  • 3. Conflicts of interest

    A conflict of interest exists when a personal, financial, or relational interest could influence — or appear to influence — a professional decision within DITAP.

    How we handle it:

  • Before accepting a project, we assess whether any personal or financial relationship exists with the client, supplier, or competitor involved that could compromise our objectivity.
  • If a real or potential conflict exists, it's declared explicitly, and we decide case by case whether DITAP can continue the work, under what safeguards, or whether to decline the project.
  • No vendor, technology, or subcontractor is recommended over another for undisclosed personal benefit — the technical recommendations on our integrations and comparison pages reflect real implementation experience, not hidden commercial deals.
  • No DITAP employee or collaborator may use a client's internal information for personal gain or on behalf of a third party.
  • 4. Client data confidentiality

    In the normal course of its work, DITAP has access to infrastructure, credentials, operational data, and in some cases personal data belonging to the clients it serves. That trust is the foundation of the business, and we treat it that way.

    Concrete commitments:

  • Access to client systems (networks, servers, cameras, cloud platforms) is used exclusively for the contracted work — never for purposes unrelated to the project.
  • A client's information — its infrastructure, business data, vulnerabilities found during an audit — is not shared with third parties or used as a public reference without explicit authorization.
  • When we publish case studies on the site, we present them anonymized by sector and size (for example, "40-room boutique hotel"), without identifying the client unless express authorization exists.
  • Access credentials (Wi-Fi, VPN, admin panels) are handled with the same standard of care we would demand for our own, and are revoked once a project ends unless an active support contract is in place.
  • Our Privacy Policy and our DPA expand on the technical and legal detail of this commitment — both are available in our Legal Center (link at the bottom of this page).
  • 5. Compliance posture and certifications

    DITAP aligns its internal practices and the projects it delivers with recognized frameworks, such as ISO 27001 for information security management and GDPR for data protection. That means we design processes, controls, and documentation following those frameworks.

    We're honest about where we stand on that path: we do not currently hold a formal ISO 27001 certification issued by an accredited body. We do not display any certification seal or badge we have not obtained. When a certification is formally obtained, it will be announced explicitly, naming the certifying body and the date.

    6. Whistleblowing channel

    Anyone — employee, client, supplier, or third party — who detects conduct that departs from this code can report it through our whistleblowing channel, without retaliation for reporting in good faith.

    The channel, its scope, and its confidentiality guarantees are described in detail on the Whistleblowing Channel page (link at the bottom of this page). For corporate governance inquiries that don't require the formal channel, you can also write directly to [email protected].

    7. Scope and validity

    This code of conduct applies to DITAP, to the people working under its brand, and to subcontractors operating on DITAP's behalf in front of a client. It is reviewed periodically and updated whenever the company's structure or the applicable regulation in Argentina, Chile, or Italy changes.