This is an informative translation. The governing text is the Spanish version.
1. Purpose
To establish the guidelines under which Confía Digital S.A.S. carries out the collection, storage, use, circulation, transfer and deletion of personal data, in order to guarantee respect for the rights of data subjects, in compliance with Law 1581 of 2012, Decree 1377 of 2013 and other applicable regulations in Colombia.
2. Scope
It applies to all databases and information systems containing personal data collected, stored and processed by Confía Digital S.A.S., including clients, employees and contractors, suppliers and partners, and visitors to its digital channels.
Compliance is mandatory for all employees, contractors and third parties acting on behalf of the organization.
3. Glossary
| Term | Definition |
|---|---|
| Personal data | Information that makes it possible to identify a natural person |
| Sensitive data | Information that may affect privacy or give rise to discrimination |
| Data subject | Natural person whose data is processed |
| Processing | Operations such as collection, storage, use, circulation or deletion |
| Data controller | Natural or legal person who decides on the processing |
| Data processor | Person who carries out the processing on behalf of the controller |
| Authorization | Prior, express and informed consent of the data subject |
| Transmission | Sending of data to a processor for its processing |
| Transfer | Sending of data to another controller, within or outside the country |
4. Guiding principles
| Principle | What it means |
|---|---|
| Legality | Compliance with current data protection legislation |
| Purpose | Processing is carried out for legitimate, informed and specific purposes |
| Freedom | Data is only processed with the express and informed authorization of the data subject |
| Truthfulness and quality | Information must be truthful, accurate, up to date and verifiable |
| Restricted access and circulation | Only authorized persons may have access |
| Security | Measures to prevent tampering, loss, unauthorized consultation or improper access |
| Confidentiality | Confidentiality and appropriate use of the data |
General purpose. Data is processed for purposes related to the corporate purpose: provision of technology services, fulfillment of contractual and legal obligations, administrative, commercial and employment management, continuous improvement of the client experience, information security and regulatory compliance.
5. Processing and purpose by type of data subject
| Data subject | Purposes |
|---|---|
| Clients | Provision of technology services. Invoicing and payment management. Sending information about products and services. Consumption analysis and market research. Service quality evaluations. Fulfillment of contractual and legal obligations |
| Employees and contractors | Administration of the employment and contractual relationship. Payroll and benefits. Social security enrollment. Performance evaluations. Access control to tools. Occupational health and safety |
| Suppliers and partners | Evaluation and selection. Contractual compliance and payment management. Audits and verifications. Legal and tax compliance |
| Visitors | Security of digital channels. On the website: responding to contact form requests and recording them as prospects in the commercial system; measuring visits in aggregate, without cookies; handling ethics line reports. Only with a separate, optional authorization: contacting the sender for commercial purposes and measuring the results of advertising campaigns, including conversion reporting to Google Ads |
6. Specific policies
6.1 Confidentiality and access
Access is restricted to authorized persons who need the information to perform their duties. Controls are established through authentication, encryption and security policies. Anyone who handles personal data must sign a confidentiality agreement.
6.2 Security and protection
Technical and administrative measures to prevent unauthorized access, loss or alteration. Secure password policy and encryption protocols. Periodic audits and reviews.
6.3 Retention and deletion
Data is retained only for the time necessary to fulfill the purpose or legal requirements. When it is no longer required, it is securely deleted.
6.4 Transfer and transmission
It is only carried out when the data subject authorizes it, there is a legal or contractual mandate, and it is verified that the receiving country offers adequate levels of protection, or the data transmission agreement required by law is signed.
To operate the website and handle the requests received through it, Confía Digital S.A.S. transmits personal data to the following data processors, located in the United States:
| Processor | Service provided | Country |
|---|---|---|
| Google LLC | Cloud infrastructure for the website and its forms (Google Cloud and Firebase) | United States |
| Resend, transactional email provider | Email delivery of contact form requests and ethics line reports to the company mailboxes, and of the confirmation to the sender | United States |
| Web analytics provider, as data processor | Aggregate visit analytics, without cookies, hosted on Google Cloud | United States |
| Commercial system (ERP) | Recording of the prospects received through the website, hosted on Google Cloud | United States |
| Google LLC (Google Ads) | Receipt of the conversion of those who optionally authorized the measurement of advertising campaigns | United States |
| Microsoft Corporation (Microsoft 365 and Microsoft Bookings) | Corporate email, meeting scheduling and recording of the appointments requested from the website | United States |
| Meta Platforms, Inc. (WhatsApp) | Handling of those who write to us on WhatsApp | United States |
These processors handle the data on behalf of Confía Digital S.A.S. and only for the purposes described in this policy.
6.5 Handling of data subjects' rights
| Data controller | Detail |
|---|---|
| Company name | Confía Digital S.A.S. |
| NIT | 901.890.580-6 |
| Registered office | Cartagena, Colombia |
| Contact channel, sole channel for exercising rights | Email legal@confiadigital.com.co |
| Type of request | Response time |
|---|---|
| Inquiries | Maximum 10 business days from the date of receipt. If it is not possible to respond within that period, the requester is informed of the reason and of the response date, which will not exceed 5 business days after the first period expires |
| Complaints | Maximum 15 business days from the day after the date of receipt. If it is not possible to respond within that period, the requester is informed of the reason and of the response date, which will not exceed 8 business days after the first period expires |
Inquiry procedure (article 14 of Law 1581 of 2012). Data subjects or their successors may consult the personal information held in the databases of Confía Digital S.A.S. by writing to legal@confiadigital.com.co. The company will provide all the information contained in the individual record or linked to the identification of the data subject.
Complaint procedure (article 15 of Law 1581 of 2012). When data subjects or their successors consider that information should be corrected, updated or deleted, or notice an alleged breach of a legal duty, they may file a complaint at legal@confiadigital.com.co including the identification of the data subject, a description of the facts giving rise to the complaint, the address or means for receiving a response, and any documents they wish to submit. If the complaint is incomplete, the requester will be asked within 5 days of its receipt to correct the deficiencies. If 2 months pass from that request without the requested information being submitted, the complaint will be deemed withdrawn. Once the complete complaint is received, the legend "complaint in process" and its reason will be added to the database within no more than 2 business days, and will remain until the complaint is decided.
Prerequisite for filing with the authority. Data subjects or their successors may only file a complaint with the Superintendencia de Industria y Comercio (Superintendence of Industry and Commerce) after exhausting the inquiry or complaint procedure with Confía Digital S.A.S. (article 16 of Law 1581 of 2012).
Responsible area: Legal and Compliance, at legal@confiadigital.com.co
7. Rights of data subjects
- Access their personal information processed by the company.
- Know, update and rectify their data when it is inaccurate or incomplete.
- Request proof of the authorization for the processing.
- Be informed about the use that has been made of their data.
- File complaints or claims with the data protection authority.
- Request deletion when there is no legal duty to retain the data.
- Revoke the authorization at any time.
8. Duties of Confía Digital as data controller
- Guarantee the right of habeas data.
- Request and retain authorizations.
- Inform the purpose and use of the data.
- Protect the information with adequate security measures.
- Respond in a timely manner to inquiries and complaints.
9. Authorization
Processing requires the prior, express and informed authorization of the data subject, which may be obtained through physical or digital forms, acceptance of terms and conditions, employment or commercial contracts, and recordings of calls or emails.
On the website, the contact form has two checkboxes: a required one, to answer the request and record it in the commercial system, and an optional one, for commercial contact and campaign measurement. Without the optional checkbox, no campaign data is sent. The version of the accepted text and the time are recorded as proof of the authorization.
9.1 Sensitive data
Only with express, prior and informed authorization. The data subject will be informed that they are not obliged to provide that information, and of which data is sensitive and for what purpose. No activity, service or benefit will be conditional on the provision of sensitive data.
9.2 Minors
Avoided as far as possible. If required, only in exceptional cases that respond to the best interests of the minor, with the prior and express authorization of their legal representative.
10. Security and compliance procedures
- Access control: only authorized personnel handle databases containing personal information.
- Internal training: periodic awareness sessions.
- Compliance audits: internal reviews to assess compliance with the policy.
11. Amendments and validity
It enters into force upon its publication and remains in force for as long as the processing of personal data continues. Any amendment is communicated to data subjects. Databases are retained for as long as the purpose subsists or there is a legal or contractual duty.