Phones+57(1) 4768000 - +57(1) 7450140
LocationCra 73 No. 74-54, Bogotá, COL
ScheduleMon - Fri: 07:30 - 17:00

Data Protection

Internal security regulations on staff roles and obligations regarding the protection of personal data

Data Protection

Management process

1. Introduction

In accordance with the constitutional right of all persons to know, update and rectify the information collected about them in databases or files, and the other constitutional rights, freedoms and guarantees referred to in Articles 15 and 20 of the Political Constitution, Law 1581 of 2012 and its Regulatory Decree 1377 of 2013 have been developed, establishing mechanisms that allow the full exercise of the aforementioned constitutional right.

The Personal Data Protection Act establishes a series of obligations for all individuals and legal entities that maintain files containing personal data. This law aims to guarantee and protect the processing of personal data, public freedoms, and fundamental rights of individuals, particularly with regard to their honor and personal and family privacy.

This document has been drafted to comply with the aforementioned regulations and outlines the possible and necessary technical and organizational measures to guarantee the protection, confidentiality, integrity, and availability of non-sensitive personal data of clients, users, collaborators, employees, suppliers, strategic partners, third parties, and other interested parties under the responsibility of Cipelog.

2. Definitions

To comply with the rules of this Manual and in accordance with the provisions of Law 1581 of 2012 and Regulatory Decree 1377 of 2013, the following definitions apply:

  1. Authorization: Prior, express and informed consent of the Data Subject to carry out the Processing of Personal Data.
  2. Databases: An organized set of personal data that is subject to Processing.
  3. Personal Data: Any information linked to or that can be associated with one or more specific or identifiable natural persons.
  4. Processor: Natural or legal person, public or private, who, alone or in association with others, carries out the Processing of Personal Data on behalf of the Data Controller.
  5. Data Controller: Natural or legal person, public or private, who, alone or jointly with others, decides on the database and/or the Data Processing.
  6. Data Subject: Natural person whose personal data is subject to Processing.
  7. Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation or deletion.
  8. Sensitive Data: Data that affect the privacy of the Data Subject or whose misuse may lead to discrimination, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, social or human rights organizations, or that promote the interests of any political party or guarantee the rights and guarantees of opposition political parties, as well as data relating to health, sexual life and biometric data.
  9. Private Data: Data that, due to its intimate nature, is only relevant to the Data Subject.
  10. Public Data: Data that is not semi-private, private or sensitive. Public data includes, among others, data relating to a person’s marital status, profession or occupation, and their status as a merchant or public servant. By their nature, public data may be contained, among other sources, in public registries, public documents, official gazettes and bulletins, and duly executed judicial judgments that are not subject to confidentiality.
  11. Privacy Notice: Verbal or written communication generated by Cipelog, addressed to the Data Subject for the Processing of their Personal Data, through which they are informed about the existence of the Information Processing policies that will be applicable to them, how to access them and the purposes of the intended processing of the personal data.
  12. Transfer: The transfer of data takes place when Cipelog, located in Colombia, sends the information or personal data to a recipient who in turn is responsible for the Processing and is located inside or outside the country.
  13. Transmission: Processing of personal data that involves its communication within or outside Colombian territory, when its purpose is the performance of Processing by the Processor on behalf of Cipelog.

3. Scope of application

This document will apply to databases containing personal data that are under the responsibility of Cipelog, including information systems, media and equipment used for the processing of personal data, which must be protected in accordance with current regulations on the protection of personal data.

4. Databases

The policies and procedures contained in this Manual apply to the databases managed by Cipelog, which will be registered in accordance with the provisions of Law 1581 of 2012 and Decree 1377 of 2013, whose validity period will be counted from the date of authorization and up to a term of 10 years.

5. Object

This Manual fulfills the requirements of Article 17, paragraph k) of Law 1581 of 2012, which regulates the duties of those responsible for processing personal data. These duties include adopting an internal manual of policies and procedures to ensure proper compliance with the Law, particularly regarding the handling of inquiries and complaints from Data Subjects. It also aims to regulate the procedures for collecting, managing, and processing personal data carried out by Cipelog S.A.S. in order to guarantee and protect the fundamental right of habeas data within the framework established by law.

6. Guiding principles

The principles set out below constitute the general parameters that will be respected by Cipelog in the processes of collection, use and processing of personal data:

  1. Principle of legality in matters of Data Processing: The Processing referred to in this Manual complies with the provisions of Law 1581 of 2012, Regulatory Decree 1377 of 2013, and other provisions that clarify, modify or develop these regulations.
  2. Principle of purpose: The Processing of data collected by Cipelog must be for a legitimate purpose in accordance with the Constitution and the Law, which must be communicated to the Data Subject;
  3. Principle of freedom: Processing may only be carried out with the prior, express and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that waives the requirement for consent;
  4. Principle of truthfulness or quality: The information subject to Processing must be truthful, complete, accurate, up-to-date, verifiable and understandable. The Processing of partial, incomplete, fragmented or misleading data is prohibited;
  5. Principle of transparency: In the Processing, the right of the Data Subject to obtain from the Data Controller or the Processor, at any time and without restrictions, information about the existence of data concerning them must be guaranteed;
  6. Principle of restricted access and circulation: Processing is subject to the limits derived from the nature of the personal data, the provisions of the law and the Constitution. Processing may only be carried out by persons authorized by the Data Subject and/or by the persons provided for by law. Personal data, except for public information, may not be available on the internet or other means of dissemination or mass communication, unless access is technically controllable to provide restricted access only to the Data Subjects or authorized third parties;
  7. Principle of security: Information subject to Processing by Cipelog will be handled with the technical, human and administrative measures necessary to ensure the security of the records, preventing their alteration, loss, consultation, use or unauthorized or fraudulent access;
  8. Principle of confidentiality: All persons involved in the Processing of personal data that is not of a public nature are obliged to guarantee the confidentiality of the information, even after their relationship with any of the tasks that comprise the Processing has ended, and may only supply or communicate personal data when it corresponds to the development of the activities authorized by law.

7. Authorization

The collection, storage, use, circulation or deletion of personal data by Cipelog requires the free, prior, informed and express consent of the Data Subject. Cipelog, in its capacity as Data Controller – Processor of personal data, has established the necessary mechanisms to obtain the authorization of the Data Subjects, guaranteeing in all cases that it is possible to verify the granting of said authorization.

8. Form and mechanisms for granting authorization

The authorization may be contained in a physical or electronic document or in any other format that allows its subsequent consultation, or through a suitable technical or technological mechanism by which it can be unequivocally concluded that, had the Data Subject not taken certain actions, the data would never have been captured and stored by Cipelog.

The Data Subject’s authorization is a fundamental requirement for Cipelog to initiate any type of commercial activity with the Data Subject. Therefore, prior to using the Data Subjects’ personal data, Cipelog must obtain their respective authorizations. Paragraph: Cipelog will establish the formats and procedures to apply the guidelines of Law 1581 of 2012.

9. Content of the authorization

The Data Subject’s Authorization is a declaration that the Data Subject permits Cipelog to use their personal or sensitive data and must also contain:

  1. Object of the authorization.
  2. Purpose of the Personal Data Processing.
  3. Users of the information.
  4. International transfer of information to third countries.
  5. Personal data of children and adolescents.
  6. Data controllers and processors.

The procedures and forms to be used in Cipelog‘s routine operations will be made available to company employees via the company intranet. Staff will receive training on these policies and procedures.

10. Proof of authorization

Cipelog will take the necessary measures to maintain records or suitable technical mechanisms of when and how the Data Subject’s authorization for the Processing of Data was obtained.

11. Privacy notice

The Privacy Notice is the physical, electronic, or other format document made available to the Data Subject regarding the Processing of their personal data. This document informs the Data Subject of the applicable data processing policies, how to access them, and the characteristics of the intended processing of their personal data.

Cipelog will provide a Privacy Notice to all Data Subjects whose personal data is held in the company’s databases in accordance with the provisions of Law 1581 of 2012 and Decree 1377 of 2013.

12. Minimum content of the privacy notice

The privacy notice must, at a minimum, contain the following information:

  1. The identity, address, and contact details of the Data Controller;
  2. The type of processing to which the data will be subjected and its purpose;
  3. The general mechanisms provided by the Data Controller to ensure that the Data Subject is aware of the data processing policy and any substantial changes to it;
  4. In all cases, the Data Subject must be informed of how to access or consult the data processing policy.

13. Privacy notice and information processing policies

Cipelog will retain the model of the privacy notice that was transmitted to the Data Subjects while the Processing of personal data is carried out and the obligations arising from it remain in effect.

14. Rights of data subjects

In accordance with the provisions of Article 8 of Law 1581 of 2012, the Data Subject has the following rights:

  1. To know, update, and rectify their personal data held by Cipelog.
  2. To request proof of the authorization granted to Cipelog in its capacity as Data Controller/Processor.
  3. To be informed by Cipelog about the uses or processing of the Data Subject’s personal data, upon request.
  4. To file complaints with the Superintendency of Industry and Commerce for violations of the provisions of Law 1581 of 2012 and Decree 1377 of 2013, once the consultation or claim process with Cipelog has been exhausted.
  5. To revoke authorization and/or request the deletion of data when the processing does not respect constitutional and legal principles, rights, and guarantees.
  6. To access, free of charge, their own personal data that has been processed.

15. Cipelog’s obligations regarding the processing of personal data

Cipelog will always bear in mind that personal data belongs to the Data Subjects and that only they can decide how it is used. Therefore, it will only use this data for the purposes for which it is duly authorized, and always respecting Law 1581 of 2012 on the protection of personal data.

Cipelog is committed to permanently complying with the following duties related to the processing of personal data:

  1. Guarantee to the Data Subject, at all times, the full and effective exercise of the right of habeas data;
  2. Maintain the information under the necessary security conditions to prevent its alteration, loss, consultation, use, or unauthorized or fraudulent access;
  3. Carry out the timely updating, rectification, or deletion of data, in accordance with the terms established in Articles 14 and 15 of Law 1581 of 2012;
  4. Process inquiries and complaints submitted by Data Subjects in accordance with the terms established in Article 14 of Law 1581 of 2012;
  5. Insert the legend “Information under judicial review” into the database once notified by a competent authority of legal proceedings related to the quality or details of the personal data;
  6. Refrain from circulating information that is being disputed by the Data Subject and whose blocking has been ordered by the Superintendency of Industry and Commerce;
  7. Allow access to the information only to those persons who are authorized to access it;
  8. Inform the Superintendency of Industry and Commerce when violations of security codes occur and there are risks in the management of the Data Subjects’ information;
  9. Comply with the instructions issued by the Superintendency of Industry and Commerce.

16. Procedures for consultations

The power of disposition or decision that the Data Subject has over their personal information necessarily entails the right to access and know whether their personal information is being processed by Cipelog, as well as the scope, conditions, and generalities of said processing. Therefore, Cipelog must guarantee the Data Subject’s right of access through:

Written requests, in the form of a formal petition, should be sent to servicioalcliente@cipelog.com, Cipelog‘s customer service email address. Consultation requests will be addressed within a maximum of fifteen (15) business days from the date of receipt. If it is not possible to address the consultation within this timeframe, the interested party will be informed before the fifteen (15) days expire, stating the reasons for the delay and indicating the date on which the consultation will be addressed, which in no case may exceed five (5) business days following the expiration of the initial period.

17. Claims

In accordance with the provisions of Article 15 of Law 1581 of 2012, the Data Subject or their successors who consider that the information contained in a Database should be corrected, updated or deleted, or who notice the alleged breach of any of the duties established by Law 1581 of 2012, may file a claim with Cipelog through the channel indicated in the previous section, which will be processed provided that the claim meets the following requirements:

  1. The claim may be submitted by the Data Subject, providing the following information:
    1. Data Subject’s identification number;
    2. Description of the facts that give rise to the claim;
    3. Address for reply;
    4. Documents required to support the claim.
  2. Once Cipelog receives the claim, it will require the interested party within five (5) days of receipt to correct any deficiencies, in cases where the claim does not comply with the requirements established in the previous point.
  3. If two (2) months have passed since the date of the request without the applicant submitting the required information, it will be understood that they have withdrawn their claim. If, for any reason, a claim is received that should not actually be directed against Cipelog, it will be forwarded, to the extent possible, to the appropriate party within a maximum period of two (2) business days, and the interested party will be informed of the situation.
  4. Once Cipelog receives the complete claim, it will include a note in its databases stating that the claim is “in process” and the reason for the claim, within a period not exceeding three (3) business days. This note must remain until the claim is resolved to the satisfaction of the Data Subject.
  5. The maximum time to address the claim will be fifteen (15) business days, counted from the day following the date of its receipt. If it is not possible to address it within said period, the interested party will be informed, before the expiration of the aforementioned period, of the reasons for the delay and the date on which their claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the first period.
  6. Request for Updating, Rectification, and Deletion of Data. Cipelog will rectify and update, at the request of the Data Subject, any incomplete or inaccurate information, in accordance with the procedure and terms outlined above. The Data Subject may submit their request in writing or electronically to servicioalcliente@cipelog.com, indicating the update or correction of the data and attaching the documentation that supports their request.
  7. The Data Subject has the right at any time to request Cipelog to delete their personal data when:
    1. They consider that their data is not being processed in accordance with the principles, duties, and obligations established in Law 1581 of 2012.
    2. The data is no longer necessary or relevant for the purpose for which it was collected.
    3. The period necessary for fulfilling the purposes for which the data was collected has expired.

    This deletion implies the total or partial elimination of personal information in accordance with the request of the Data Subject in the records, files, databases or Processing carried out by Cipelog.

  8. Cipelog may deny the request for deletion when the data is necessary, in consideration of the legal or contractual duty that the Data Subject has to remain in the Cipelog database. Likewise, Cipelog may deny the deletion of the data when its elimination hinders judicial or administrative actions or when the data is necessary to protect the legally protected interests of the Data Subject.
  9. Revocation of Authorization and/or Deletion of Data. Data Subjects may revoke their consent to the processing of their personal data at any time, provided that no legal or contractual provision prevents it. To do so, the Data Subject may revoke their consent in writing or electronically by email to servicioalcliente@cipelog.com.
  10. If, after the respective legal term has expired, the company has not deleted the personal data, the Data Subject shall have the right to request the Superintendency of Industry and Commerce to order the revocation of the authorization and/or the deletion of the personal data. For these purposes, the procedure described in Article 22 of Law 1581 of 2012 shall apply.
  11. In the event that an interested party other than the Data Subject requests to rectify the information and does not prove in what capacity they are submitting the request, Cipelog will consider the request not to have been submitted.
  12. The company will collect only the data that is strictly necessary to carry out the purposes pursued and will keep it only as long as needed for the purpose for which it was registered. Likewise, it will respect the Data Subject’s freedom to authorize or not the use of their personal data, and consequently, the mechanisms it uses to obtain consent will allow the Data Subject to express unequivocally that they grant such authorization.
  13. Cipelog has the obligation to rectify and update, at the request of the Data Subject, any of their information that is incomplete or inaccurate, in accordance with the procedure and terms indicated in this Manual.
  14. Data Deletion Process. Cipelog must operationally carry out the deletion of the data in such a way that the deletion does not allow the recovery of the information.

18. Information security / Security measures

In accordance with the security principle established in Law 1581 of 2012, Cipelog will adopt the necessary technical, human and administrative measures to ensure the security of the records, preventing their alteration, loss, unauthorized or fraudulent consultation, use or access.

19. Implementation of security measures

Cipelog will maintain mandatory security protocols for personnel with access to personal data and information systems. The procedure must consider at least the following aspects:

  1. Scope of the procedure with detailed specification of the protected data.
  2. Roles and responsibilities of personnel.
  3. Procedures for creating backups and recovering data.
  4. Periodic checks to be carried out to verify compliance with the security procedure.

20. Area in charge of data protection

Cipelog designates the administrative area to be responsible, in association with the technology area, for fulfilling the function of personal data protection.

21. Area in charge of requests, inquiries, correction, updating and deletion of data

Cipelog designates the administrative area to handle requests, inquiries, corrections, updates and deletion of data by the Data Subjects.

22. Adoption and implementation of the obligations of Law 1581 of 2012

Cipelog designates the administrative area as responsible for the adoption and implementation of the obligations provided for in Law 1581 of 2012.

23. Validity

This Internal Manual of Policies and Procedures for the Protection of Personal Data was communicated to our work team in its substantive aspects, as well as the mandatory compliance with each and every one of the aspects that comprise it. In accordance with the above, this manual will begin to govern within the framework established by law.