In accordance with the constitutional right of all persons to know, update and rectify the information collected about them in databases or files, and the other constitutional rights, freedoms and guarantees referred to in Articles 15 and 20 of the Political Constitution, Law 1581 of 2012 and its Regulatory Decree 1377 of 2013 have been developed, establishing mechanisms that allow the full exercise of the aforementioned constitutional right.
The Personal Data Protection Act establishes a series of obligations for all individuals and legal entities that maintain files containing personal data. This law aims to guarantee and protect the processing of personal data, public freedoms, and fundamental rights of individuals, particularly with regard to their honor and personal and family privacy.
This document has been drafted to comply with the aforementioned regulations and outlines the possible and necessary technical and organizational measures to guarantee the protection, confidentiality, integrity, and availability of non-sensitive personal data of clients, users, collaborators, employees, suppliers, strategic partners, third parties, and other interested parties under the responsibility of Cipelog.
To comply with the rules of this Manual and in accordance with the provisions of Law 1581 of 2012 and Regulatory Decree 1377 of 2013, the following definitions apply:
This document will apply to databases containing personal data that are under the responsibility of Cipelog, including information systems, media and equipment used for the processing of personal data, which must be protected in accordance with current regulations on the protection of personal data.
The policies and procedures contained in this Manual apply to the databases managed by Cipelog, which will be registered in accordance with the provisions of Law 1581 of 2012 and Decree 1377 of 2013, whose validity period will be counted from the date of authorization and up to a term of 10 years.
This Manual fulfills the requirements of Article 17, paragraph k) of Law 1581 of 2012, which regulates the duties of those responsible for processing personal data. These duties include adopting an internal manual of policies and procedures to ensure proper compliance with the Law, particularly regarding the handling of inquiries and complaints from Data Subjects. It also aims to regulate the procedures for collecting, managing, and processing personal data carried out by Cipelog S.A.S. in order to guarantee and protect the fundamental right of habeas data within the framework established by law.
The principles set out below constitute the general parameters that will be respected by Cipelog in the processes of collection, use and processing of personal data:
The collection, storage, use, circulation or deletion of personal data by Cipelog requires the free, prior, informed and express consent of the Data Subject. Cipelog, in its capacity as Data Controller – Processor of personal data, has established the necessary mechanisms to obtain the authorization of the Data Subjects, guaranteeing in all cases that it is possible to verify the granting of said authorization.
The authorization may be contained in a physical or electronic document or in any other format that allows its subsequent consultation, or through a suitable technical or technological mechanism by which it can be unequivocally concluded that, had the Data Subject not taken certain actions, the data would never have been captured and stored by Cipelog.
The Data Subject’s authorization is a fundamental requirement for Cipelog to initiate any type of commercial activity with the Data Subject. Therefore, prior to using the Data Subjects’ personal data, Cipelog must obtain their respective authorizations. Paragraph: Cipelog will establish the formats and procedures to apply the guidelines of Law 1581 of 2012.
The Data Subject’s Authorization is a declaration that the Data Subject permits Cipelog to use their personal or sensitive data and must also contain:
The procedures and forms to be used in Cipelog‘s routine operations will be made available to company employees via the company intranet. Staff will receive training on these policies and procedures.
Cipelog will take the necessary measures to maintain records or suitable technical mechanisms of when and how the Data Subject’s authorization for the Processing of Data was obtained.
The Privacy Notice is the physical, electronic, or other format document made available to the Data Subject regarding the Processing of their personal data. This document informs the Data Subject of the applicable data processing policies, how to access them, and the characteristics of the intended processing of their personal data.
Cipelog will provide a Privacy Notice to all Data Subjects whose personal data is held in the company’s databases in accordance with the provisions of Law 1581 of 2012 and Decree 1377 of 2013.
The privacy notice must, at a minimum, contain the following information:
Cipelog will retain the model of the privacy notice that was transmitted to the Data Subjects while the Processing of personal data is carried out and the obligations arising from it remain in effect.
In accordance with the provisions of Article 8 of Law 1581 of 2012, the Data Subject has the following rights:
Cipelog will always bear in mind that personal data belongs to the Data Subjects and that only they can decide how it is used. Therefore, it will only use this data for the purposes for which it is duly authorized, and always respecting Law 1581 of 2012 on the protection of personal data.
Cipelog is committed to permanently complying with the following duties related to the processing of personal data:
The power of disposition or decision that the Data Subject has over their personal information necessarily entails the right to access and know whether their personal information is being processed by Cipelog, as well as the scope, conditions, and generalities of said processing. Therefore, Cipelog must guarantee the Data Subject’s right of access through:
Written requests, in the form of a formal petition, should be sent to servicioalcliente@cipelog.com, Cipelog‘s customer service email address. Consultation requests will be addressed within a maximum of fifteen (15) business days from the date of receipt. If it is not possible to address the consultation within this timeframe, the interested party will be informed before the fifteen (15) days expire, stating the reasons for the delay and indicating the date on which the consultation will be addressed, which in no case may exceed five (5) business days following the expiration of the initial period.
In accordance with the provisions of Article 15 of Law 1581 of 2012, the Data Subject or their successors who consider that the information contained in a Database should be corrected, updated or deleted, or who notice the alleged breach of any of the duties established by Law 1581 of 2012, may file a claim with Cipelog through the channel indicated in the previous section, which will be processed provided that the claim meets the following requirements:
This deletion implies the total or partial elimination of personal information in accordance with the request of the Data Subject in the records, files, databases or Processing carried out by Cipelog.
In accordance with the security principle established in Law 1581 of 2012, Cipelog will adopt the necessary technical, human and administrative measures to ensure the security of the records, preventing their alteration, loss, unauthorized or fraudulent consultation, use or access.
Cipelog will maintain mandatory security protocols for personnel with access to personal data and information systems. The procedure must consider at least the following aspects:
Cipelog designates the administrative area to be responsible, in association with the technology area, for fulfilling the function of personal data protection.
Cipelog designates the administrative area to handle requests, inquiries, corrections, updates and deletion of data by the Data Subjects.
Cipelog designates the administrative area as responsible for the adoption and implementation of the obligations provided for in Law 1581 of 2012.
This Internal Manual of Policies and Procedures for the Protection of Personal Data was communicated to our work team in its substantive aspects, as well as the mandatory compliance with each and every one of the aspects that comprise it. In accordance with the above, this manual will begin to govern within the framework established by law.