Data controller
COLOCA GROUP S.A.S., NIT 901.820.031-5, acts as the Data Controller for the Personal Data of Data Subjects, in compliance with Law 1581 of 2012, Decree 1377 of 2013, and other applicable regulations in Colombia.
We value your privacy and work to ensure that the trust placed in us translates into security when operating within our ecosystem.
For inquiries: legal@colocapayments.com
Scope
This Policy applies to all natural and legal persons whose personal data is processed by Coloca, including customers, employees, suppliers, shareholders, and other third parties with a contractual relationship or legitimate connection.
It covers data collected directly by Coloca and data obtained by third parties on behalf of the company.
Definitions
- Authorization: Prior, express, and informed consent of the Data Subject.
- Data Subject: Natural person whose Personal Data is subject to Processing.
- Personal data: Information concerning identified or identifiable natural persons.
- Sensitive data: Intimate information whose improper use could lead to discrimination (health, sexual orientation, political opinions, beliefs).
- Controller: Person who decides on the collection and use of data.
- Processor: Person who processes data on behalf of the Controller.
- Transfer: Sending data to a recipient who becomes a new controller.
- Transmission: Communication of data where the purpose is Processing by the Processor on behalf of the Controller.
Purposes of processing
Customers
- Notify about new products or changes to contracted ones
- Personalize the experience
- Direct marketing (promotions, surveys, events)
- Historical record of transactions
Employees and collaborators
- Manage payroll, benefits, and entitlements
- Training and Occupational Health and Safety (OHS) prevention programs
- Performance evaluations
- Access controls
General purposes
- Provide the requested services and products
- Comply with legal regulations (LA/FT/FPADM)
- Identity validation through KYC/KYB
- Manage the contractual relationship
- Statistical analysis and market research
- Protect against fraud and cyberattacks
- Comply with SAGRILAFT policies
Rights of the Data Subject
- Access: Know and consult your personal data free of charge.
- Update and rectification: Request the correction of partial, inaccurate, or incomplete data.
- Proof of authorization: Request proof of the consent granted.
- Information on use: Be informed about the use given to your data.
- Revocation and deletion: Revoke the authorization or request deletion (except where there is a legal/contractual duty to retain it).
- Filing complaints: Submit complaints to the Superintendencia de Industria y Comercio (SIC) (Colombian Superintendency of Industry and Commerce).
To exercise these rights: legal@colocapayments.com
Obligations of the Data Subject
- Provide truthful, complete, and updated information
- Notify changes to their personal data
- Refrain from providing third-party data without authorization
- Use the communication channels appropriately and respectfully
Data of minors
Coloca will only collect data of minors when there is explicit authorization from the legal guardian, the processing has the purpose of protecting the best interests of the minor, and respect for their fundamental rights is guaranteed.
The data of minors will NOT be used for commercial purposes, except where there is a legitimate interest related to the guardian's contractual relationship.
Procedures for inquiries and complaints
Deadlines
- Inquiries: Maximum of 10 business days (extension of 5 additional days).
- Incomplete complaints: To be corrected within 5 business days.
- "Complaint in process": Insertion in the database within 2 business days.
- Resolution of complaint: Maximum of 15 business days (extension of 8 additional days).
Service channel: legal@colocapayments.com
Security measures
Coloca adopts measures to protect personal data based on confidentiality, integrity, traceability, authenticity, and availability.
Technical measures
- Documentation of policies and procedures
- Encryption on portable devices
- Controls over USB usage
- Robust antivirus updated annually
- Periodic backups
- File protection with passwords and encryption
Incident management
In the event of a breach: internal notification within 24 hours, investigation, notification to Data Subjects and the SIC within legal deadlines, and implementation of corrective measures.
International data transfer
Coloca may transfer personal data outside Colombia provided that the recipient country offers equivalent levels of protection or when a legal exception applies (express authorization of the Data Subject, performance of contracts, international treaties).
Coloca will not be liable for improper use by allied third parties that have contractual security guarantees in place.
Cookies and links
When you visit the site, we may collect information through cookies to ensure proper functioning, personalize the experience, and identify areas for improvement.
You can reject or delete cookies from your browser. Some functionalities may be affected if you disable them.
Our site may contain links to third parties. Coloca is not responsible for the privacy policies of external sites.
Term and modifications
This Policy is effective as of its publication. Data will remain in the databases only for as long as necessary to fulfill the purposes and applicable legal duties.
In the event of substantial changes, Coloca will provide notice by email, notifications on the website, or notices published through authorized channels.
