POLICY AND PROCEDURES FOR THE PROTECTION OF PERSONAL DATA
NETTING SOLUTIONS COLOMBIA S.A.S , asimplified share company, incorporated in accordance with the laws of the Republic of Colombia, identified with NIT. 900.081.454-1
(hereinafter NETTING SOLUTIONS).
In accordance with the provisions of Statutory Law 1581 of 2012 “by which general provisions for the protection of personal data are detailed” and Regulatory Decree 1377 of 2013 “by which Law 1581 of 2012 is partially regulated”, has prepared and established the following internal policies aimed at the proper processing and administration of personal data that have been collected and stored in its databases.
Object
This document seeks to socialize and disseminate such policies among all officials and collaborators of the Company, including all persons involved and/or related to the operational, commercial, administrative, financial and marketing activities developed by NETTING SOLUTIONS in which there may be collection or processing of personal data.
Scope
Therefore, the policies provided herein will apply to employees, collaborators, administrators, Board of Directors, General Meeting of Shareholders, administrative bodies, contractors, subcontractors and other natural, legal or third parties who are involved or become involved in any way with NETTING SOLUTIONS and who may become involved or participate in the collection or processing of personal data.
PROCESSING OF PERSONAL DATA CAPTURED BY NETTING SOLUTIONS AS DATA CONTROLLER.
For treatment, collection, storage, use, circulation, deletion, among others, of personal data of natural persons by NETTING SOLUTIONS, prior and informed authorization must be obtained from its Owner (natural person whose personal data are subject to Processing) or who is legitimized in accordance with the provisions of Article 20 of Decree 1377 of 2013, which may be granted by written or oral means or by unequivocal conduct of the holder that allows to conclude in a reasonable way that granted authorization and that may be subsequently consulted by its Owner or who is entitled to exercise the rights of the Owner in accordance with the law.
For the purposes of this policy, the following terms shall have the following meanings, which were taken from Statutory Law 1581 of 2012 and Decree 1377 of 2013:
Authorization: Statutory Law 1581 of 2012, Article 3, literal to: Prior, express and informed consent of the Holder to carry out the processing of personal data;
Privacy Notice: verbal or written communication generated by the controller addressed to the Owner for the Processing of his personal data, by which he is 2 informed about the existence of the policies of Processing information that will be applicable to him, how to access them and the purposes of the Processing that is intended to give to personal data;
Database: Organized set of personal data subject to Processing;
Personal data: Any information linked to or that may be associated with one or more natural persons determined or determinable; Certain personal data are part of the so-called “public data”, within which are those included in the Civil Registry. NETTING SOUTIONS in order to comply with its legal and contractual obligations, requires the processing of numerous personal data, including those of its workers, to which the provisions provided for by Law 1581 of 2012, and its Regulatory Decree 1377 of 2012, and consequently this policy, apply.
Sensitive data: sensitive data means data that affect the Privacy of the Owner or whose misuse may lead to discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership of trade unions, social organizations, human rights organizations or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data relating to health, sex life and biometric data.
Processor: Natural or legal person, public or private, who by himself or in association with others, performs the Processing of personal data on assistance of the controller;
Data Controller: Natural or legal person, public or private, who alone or in partnership with others, decides on the basis of data and/or the Processing of data;
Owner: Natural person whose personal data are subject to Processing;
Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
Transfer: the transfer of data takes place, when the controller and/or Processor of personal data, located in Colombia, sends the information or personal data to a recipient, who in turn is Responsible for the Processing and is located inside or outside the country.
Transmission: Processing of personal data involving the communication of the same within or outside the territory of the Republic of Colombia when it is intended to carry out a Processing by the Processor on without the responsibility.
RIGHTS OF PERSONAL DATA OWNERS
In compliance with the terms of the applicable regulations regarding personal data, NETTING SOLUTIONS assumes the role of Data Controller and Data Controller in all or some of its cases, depending on each one, when it collects, stores, uses, circulates, deletes, transfers or transmits data of Holders in any of its activities, either by itself or through third parties.
Persons who own and/or hold the personal data to be provided to NETTING SOLUTIONS or who have been provided to us have the following rights:
Know, update and/or rectify your personal data, by means of a request sent to the controller or processor of such information. This right may be exercised, among others, against partial, inaccurate, incomplete or fractional data, which induced error or those whose processing is expressly prohibited or has not been authorized.
Note: Performance assessments, results reports, and other data used by NETTING SOLUTIONS to record the performance of officers, collaborators, or contractors may not be modified and/or altered, except in cases where the data subject finds that such information was poorly archived or processed with errors.
Request proof of the authorization granted to the controller, except in cases where such authorization is not necessary in accordance with article 10 of Law 1581 of 2012.
Be informed by the controller and/or processor, upon written request, regarding the uses that will be given or given to your personal data.
File complaints or claims with the Superintendency of Industry and Commerce for violations committed by NETTING SOLUTIONS, the provisions of Law 1581 of 2012 and other rules that modify, add or supplement it.
Revoke authorization at any time and/or request the deletion of the information contained in the NETTING SOLUTIONS database, when constitutional and legal principles, rights and guarantees are not respected. Revocation and/or deletion shall proceed where the Superintendency of Industry and Commerce has determined that, in the processing, the controller or processor has committed conduct contrary to the Law and the Constitution.
Free access to the personal data that has been processed and of which is the exclusive owner.
procedure
Collection of data and information.
NETTING SOLUTIONS in development of its social object, permanently performs the collection of personal data of those people who have some kind of link with the Company. The most significant cases and examples of this work, without limiting themselves to them, are:
The data of your customers and users of the different business segments. This data is collected for the purpose of identifying them, maintaining with them a commercial or contractual relationship. This includes users or visitors to the different NETTING SOLUTIONS locations.
The signing of the agreement or document that is signed with customers, holders, or third parties indicates acceptance of these policies, terms and conditions, and confirms your knowledge and consent to the policies set forth herein.
Data from suppliers, contractors and subcontractors providing NETTING SOLUTIONS with goods or services necessary for the development of the activities and operations of its social object.
Data from NETTING SOLUTIONS officials, employees, contractors and subcontractors is collected at the time of the selection or recruitment process and is required to create the file or folder of each of them.
The data of people who work, collaborate or provide any type of service related to the media of NETTING SOLUTIONS (Website, magazines, flyers, newsletters, events, promotional and marketing activities, fairs, business wheels, conventions, etc.).
Data from affiliates or linked to other legal entities or other companies that have agreements, contracts or a business relationship with NETTING SOLUTIONS, such as occupational risk manageries.
Data from speakers, conferences, and training activities or educational activities organized by NETTING SOLUTIONS for your employees, customers, collaborators, or officials.
Data from attendees and visitors to events, fairs, business wheels and conventions organized by NETTING SOLUTIONS or where the latter participates.
All this data is collected for the purpose of identifying and maintaining open communication with their owners, and inviting them to participate in the different commercial or marketing activities of NETTING SOLUTIONS.
Storage
As far as the holders are concerned, once the authorization process for the processing of personal data is completed, a record is created in our databases to archive the personal information of each holder.
Access to such a folder is limited to those officials, collaborators, contractors or subcontractors who participate directly in the administrative, commercial or operational activity or process of NETTING SOLUTIONS, which requires the data of the holder for the normal performance of its functions.
With regard to the data of principal and alternate members of the Board of Directors and the General Assembly of Shareholders, Employees, Suppliers and Contractors of NETTING SOLUTIONS, once the linking process is completed, electronically or physically, a special folder is created to archive all personal and/or work information of each holder.
Customer and user or visitor data from NETTING SOLUTIONS facilities, which is captured for entry to those dependencies.
Data from NETTING SOLUTIONS suppliers of goods or services, which are collected for the purpose of having the information necessary for the normal execution of existing agreements, agreements and contracts with those suppliers.
Internal use of personal data:
The different areas of NETTING SOLUTIONS may have access to the databases regarding their specialty and task within the Company and in accordance with the uses or treatments authorized by their owners.
NETTING SOLUTIONS administrative staff and employees will have the information of customers, suppliers and third parties, to manage the company’s activities and operations, conduct service or marketing campaigns, and address everything related to the obligations of their positions within the company.
Circulation of information:
NETTING SOLUTIONS will use information related to its customers, suppliers and third parties only for the purposes set out in the Law, inside and outside the Colombian territory.
In no case will the personal data contained in the NETTING SOLUTIONS databases be alienated in favour of third parties, temporarily or definitively, in whole or in part, free of charge or onerous.
NETTING SOLUTIONS ensures that the handling of information will be carried out and executed under the highest standards of security and confidentiality. In the event that judicial authorities request this information from NETTING SOLUTIONS, NETTING SOLUTIONS shall be obliged to share it in accordance with Colombian law.
Attention to Inquiries, Requests and Claims:
NETTING SOLUTIONS must allow free access by the Data Subject to its information, where required, to make inquiries, as well as guarantee the right to Holders to file claims and requests for correction, updating or deletion of personal data. NETTING SOLUTIONS may receive the above requests about Personal Data from:
Data subject
Of the successors, legal representatives or guardians of the holders.
Public or administrative entities in the exercise of their social or legal functions.
By court order and by third parties authorized by the holder or by law.
By stipulation in favor of another or for another.
Inquiries, requests and/or complaints should be addressed as follows:
To email: seguridadyprivacidad@nettingsolutions.com as long as the e-mail address from which the request is submitted is registered in the NETTING SOLUTIONS database. Otherwise you may use telephone line (571) 2562050; where you will be asked for control data to verify the identity of the holder.
They will also be received in writing to your judicial notice address at Cra 15 No. 98 42 Office 301
Inquiries about personal data will be resolved by NETTING SOLUTIONS within a maximum period of ten (10) working days from the date of receipt of the same. Where it is not possible to attend the consultation within that term, the holder or his successors will be informed, creating the reasons for the delay and indicating the date on which his consultation will be attended, which in no case may exceed five (5) working days following the expiration of the first term.
The processing of these inquiries and claims will be free of charge, except in the cases expressly indicated by law.
When the request is related to personal data belonging to our customers’ databases, the information security and privacy officer will inform the project manager so that the project manager can contact the customer’s manager and follow the procedure established by the customer and their policy and privacy of the information will be followed.
If it is a requirement related to one of the platforms on which NettingSolutions is the primary managed and has the permissions to be performed by the project manager and the account manager configure the platform so that the application is automatically and manually completed.
It must be ensured that the platform keeps the evidence that the request was made to satisfaction.
Revocation of data authorization and/or deletion:
Given the revocable nature of the authorisation, the holders of the information may, at any time, revoke the authorization granted for the processing of their personal data. This request should be addressed as well:
To email: seguridadyprivacidad@nettingsolutions.com as long as the e-mail address from which the request is submitted is registered in the NETTING SOLUTIONS database. Otherwise you can use telephone line No. (571) 2562050; where they will ask you for control data aimed at verifying the identity of the holder. It will also be received in writing to your judicial notification address at Cra 16 # 64-13.
As long as this revocation does not occur, it shall be understood that the authorization given by the owner of the information remains in force.
PURPOSES OF COLLECTING PERSONAL DATA
The information of the holders collected in our database is intended to:
Carry out the administrative, commercial, operational and financial processes established by NETTING SOLUTIONS.
Inform customers and holders in a timely manner about NETTING SOLUTIONS’ business and marketing activities, as well as the benefits, discounts and promotions they can access, through the different business activities and programs deployed by NETTING SOLUTIONS.
Inform or invite customers to events, business wheels, conventions, and marketing activities.
Advance service quality tracking and verification campaigns, satisfaction surveys, information data refresh, marketing campaigns, and special services.
Address Questions Complaints and Complaints – PQRs .
Attention to the requirements of authorities and to provide information to administrative, judicial and public entities authorized by the Law.
Collect financial information from customers, suppliers, and third parties, for cases where NETTINGSOLUTIONS grants them credits or has to make court or out-of-court charges.
Sending correspondence, emails, newsletters, telephone contact or any other method with your customers, suppliers and users of your various products, goods and services, developing advertising, promotional, marketing or market research activities focused on your activity of providing technological services or supplying goods, even if you have ended your relationship with NETTING SOLUTIONS.
For sending correspondence, emails, communications, virtual newsletters, invitations or telephone contact of your different products, services, programs, activities, and agreements.
Execution and / or performance of the contracts or agreements it has with third parties for the execution of the activities of its social object.
To share information with business or corporate partners, for the offering of services or goods related to the execution of activities within the NETTINGSOLUTIONS object.
Maintenance by itself or through a third party, databases.
Obtaining information from stakeholders for the relationship of NETTING SOLUTIONS (contact details of journalists and authorities).
Transfer and transmission of data to third parties inside and outside Colombia with whom you make agreements or alliances related to your object or activities, or with whom you hire studies or commission them to process data.
Report and consult credit risk plants legally incorporated in Colombia.
Analysis of prospects for commercial, financial or marketing purposes.
Collection or commercial management.
The data collected from employees is intended to:
Comply with the legal obligations in the development of the employment contract.
Selection of personnel, management of contracts, management of industrial relations and fulfillment of the obligations arising thereof, granting benefits to its employees by itself or through third parties, as well as allowing employees access to the computer or administrative resources of NETTING SOLUTIONS.
Properly handle sensitive information, as provided for in article 12 of Law 1581 of 2012. With respect to this information NETTING SOLUTIONS undertakes to:
Inform the owner of the information the processing to which the personal data will be subject and the purpose thereof.
The optional nature of the answer to the questions asked to you, when you are looking at sensitive data or data from children and adolescents.
The rights that are attended to him as the holder.
The identification, physical and/or electronic address and telephone number of the controller, who undertakes to keep proof of compliance and to deliver a copy to the holder when he/she needs it.
The data collected from suppliers, consultants and consultants are intended to:
Comparison of offers and market research required by NETTING SOLUTIONS for the execution of the activities of its social object.
Collect information about invoicing, dispatching and receiving goods.
Professional experience assessment, payments, financial analysis, fair trade policy review and court collections.
MODIFICATION AND/OR UPDATING OF DATA PROTECTION AND INFORMATION MANAGEMENT POLICY
Any substantial changes or modifications to internal policies for the processing of personal data, as provided for in Article 5 of Decree 1377 of 2013, will be communicated in a timely manner to the holders of the personal data in an effective manner that guarantees their knowledge and understanding, which will be done before implementing the new policies.
VALIDITY OF PERSONAL DATA PROCESSING POLICIES
These policies apply as of July 7, 2020.
Contact information of the controller of personal data:
Charge: Information Security and Privacy Officer
Address: 8400 N.W. 36th Street, Doral, FL 33166
E-mail: seguridadyprivacidad@nettingsolutions.com
In case you have any questions or concerns regarding the handling of your personal data, you can write to the email: seguridadyprivacidad@nettingsolutions.com