Personal Data Processing Policy

OBJECTIVE

This policy aims to establish the guidelines for handling personal data of stakeholders with the intention of complying with Colombian legislation and safeguarding the good name of the Firm and its associates.

SCOPE

This policy applies to all stakeholders of Kreston RM S.A. (employees, managers, partners, competitors, suppliers, contractors, allies, state entities, clients, visitors, the general community, others).

DEFINITIONS

Authorization: Prior, express, and informed consent of the Data Subject to carry out the Processing of personal data.

Data Subject’s Authorization: For the purposes mentioned above, Kreston Colombia requires free, prior, express, and duly informed authorization from the data subjects. To this end, it has established suitable mechanisms, ensuring in each case that the granting of such authorization can be verified. This authorization may be in any medium, whether a physical document, electronic, or any format that guarantees its subsequent consultation through technical, technological tools and public information security developments on our website https://kreston.com.co/contacto.php

Privacy Notice: Verbal or written communication generated by the controller, addressed to the Data Subject for the Processing of their personal data, through which they are informed about the existence of the information Processing policies that will apply to them, how to access them, and the purposes of the intended Processing of personal data.

Database: Organized set of personal data that is subject to Processing;

National Assignment or Transfer of the Database: Information related to the national assignment or transfer of data includes the identification of the assignee, who will be considered responsible for the processing of the assigned database from the moment the assignment is perfected. It is not mandatory for the assignor to register the assignment of the database. However, the assignee, as the data controller, must comply with the registration of the database that has been assigned to them.

Personal Data: Any information linked or that can be associated with one or more individuals.

Public Data: Data that is not semi-private, private, or sensitive. Public data includes, among others, data related to the civil status of individuals, their profession or trade, and their status as a merchant or public servant. By their nature, public data may be contained, among others, in public records, public documents, official gazettes and bulletins, and duly executed judicial sentences that are not subject to confidentiality.

Sensitive Data: Those that affect the Data Subject’s privacy or whose improper use may lead to discrimination, such as those revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions, social organizations, human rights organizations, or those promoting the interests of any political party or guaranteeing the rights and guarantees of opposition political parties, as well as data related to health, sexual life, and biometric data.

Data of Minors: The provision of personal data of minors is optional and must be done with the authorization of the parents or legal representatives of the minor.

Data Processor: Natural or legal person, public or private, who by themselves or in association with others, performs the Processing of personal data on behalf of the Data Controller.

Information stored in the database: This refers to the classification of personal data stored in each database, grouped by categories and subcategories, according to their nature.

Information Security Measures: Corresponds to the controls implemented by the data controller to guarantee the security of the databases being registered, taking into account the questions provided for this purpose in the RNBD.

Origin of Personal Data: The origin of the data refers to whether it is collected from the data subject or provided by third parties, and whether there is authorization for processing or if there is a cause for exemption, in accordance with Article 10 of Law 1581 of 2012.

Data Controller: Natural or legal person, public or private, who by themselves or in association with others, decides on the database and/or the Processing of data.

Data Subject: Natural person whose personal data is subject to Processing.

Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.

Transfer: Data transfer occurs when the Data Controller and/or Data Processor of personal data, located in Colombia, sends the information or personal data to a recipient, who in turn is a Data Controller and is located inside or outside the country.

Transmission: Processing of personal data that implies the communication of such data within or outside the territory of the Republic of Colombia when its purpose is to carry out Processing by the Processor on behalf of the controller.

International Transfer of Personal Data: Includes the identification of the recipient as the data controller, the country where it is located, and whether the operation is covered by a declaration of conformity issued by the Delegation for the Protection of Personal Data of the SIC or by an exception clause in the terms indicated in Article 26 of Law 1581 of 2012.

International Transmission of Personal Data: Includes the identification of the recipient as the Data Processor, the country where it is located, whether there is a data transmission contract in the terms indicated in Article 2.2.2.25.5.2 of Section 5 of Chapter 25 of Unique Decree 1074 of 2015, or if the operation is covered by a declaration of conformity issued by the Delegation for the Protection of Personal Data of the SIC.

POLICY DESCRIPTION

In compliance with Law 1581 of 2012, its Decrees 1377 of 2013, Decree 1074 of 2015, and Decree 1759 of 2016, and the circulars issued by the Superintendence of Industry and Commerce, Kreston RM SA. (Kreston Colombia) adopts the personal data processing policy for the collection, storage, use, circulation, and deletion of personal data. This policy will be informed to all data subjects whose data has been collected or will be obtained in the course of Kreston Colombia’s activities.

The main purpose of this Policy is to inform Data Subjects of their rights, the procedures and mechanisms defined by Kreston Colombia to enforce those rights, and to make them aware of the scope and purpose of the Processing to which Personal Data will be subjected if the Data Subject grants their express and prior authorization. It also seeks to ensure that personal data is not disclosed and used by third parties without the prior, express, and free authorization of the data subject.

REGULATORY FRAMEWORK OF THE POLICY

DATA HANDLING IDENTIFICATION

NAME OR COMPANY NAME: KRESTON RM SA.
ADDRESS: CALLE 72 # 10-07 LIBERTY SEGUROS BUILDING OFFICE 1103
DOMICILE: KRESTON COLOMBIA is domiciled in the city of Bogotá.
PHONE: (57-1) 7443680
EMAIL: financialcontroller@krestoncolombia.co

IDENTIFICATION OF KRESTONCOLOMBIA'S DATABASE PROCESSOR

Database Processors

Name or Company Name: Luis David Orjuela Becerra
C.C: 1003619649
ADDRESS: Cra 87 F bis 38-13
Domicile: Domiciled in the city of Bogotá
PHONE: (57) 3204509804
Email: soporte@krestoncolombia.co

Database Controller

Name or Company Name: KRESTON RM SA.
NIT: 800.059.311-2
ADDRESS: CALLE 72 # 10-07 LIBERTY SEGUROS BUILDING OFFICE 1103
Domicile: Bogotá
PHONE: 57(1)7443680
Email: financialcontroller@krestoncolombia.co

Without prejudice to the exceptions provided by law, Processing requires the prior, express, and informed authorization of the Data Subject, which must be obtained by any means that can be consulted and verified later.

The Data Subject’s authorization will not be necessary in the case of:

  • Information required by the Financial Superintendence of Colombia in the exercise of its legal functions or by judicial order. Public data.
  • Cases of medical or health emergency.
  • Processing of information authorized by law for historical, statistical, or scientific purposes.
  • Data related to the Civil Registry of Persons.

PROCESSING AND PURPOSES

The Processing carried out by KRESTON COLOMBIA will involve collecting, storing, processing, using, and deleting personal data, strictly adhering to the duties of security and confidentiality mandated by Law 1581 of 2012 and Decrees 1377 of 2013 and 1759 of 2016. The Personal Data processed by KRESTON COLOMBIA must be subjected to the following purposes:

  • Development of the Company’s corporate purpose.
  • Manage all necessary information for the fulfillment of KRESTON COLOMBIA’s tax and accounting obligations.
  • Develop activities inherent to human resources management within KRESTON COLOMBIA, such as résumés, payroll, affiliations to general social security system entities, social benefits, welfare and training activities, management system, occupational health and safety, and process professional service contracts for the normal operation of the entity and those derived from Projects, both public and private.
  • The process of archiving, updating systems, protecting and safeguarding information and databases.
  • Respond to inquiries, petitions, complaints, and claims made by data subjects.

  • Other purposes determined by the controllers in processes of obtaining Personal Data for its Processing, in order to comply with legal and regulatory obligations, as well as the Firm’s policies.

The personal data contained in KRESTON COLOMBIA’s database will be processed automatically or manually. Manual databases are files whose information is organized and stored digitally by means of databases that are stored and managed with the help of computer tools.

Processing of sensitive data: The Processing of sensitive data is prohibited, except when:

a) The Data Subject has given their explicit authorization for such Processing, except in cases where such authorization is not required by law;

b) The Processing is necessary to safeguard the vital interest of the Data Subject and they are physically or legally incapacitated. In these events, legal representatives must grant their authorization;

c) The Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association, or any other non-profit organization, whose purpose is political, philosophical, religious, or trade union-related, provided that it refers exclusively to its members or to persons who maintain regular contact due to its purpose. In these events, the data may not be supplied to third parties without the Data Subject’s authorization;

d) The Processing refers to data that is necessary for the recognition, exercise, or defense of a right in a judicial process;

e) The Processing has a historical, statistical, or scientific purpose. In this event, measures conducive to the suppression of the Data Subjects’ identity must be adopted.

Processing of sensitive data: The Processing of sensitive data is prohibited, except when:

a) The Data Subject has given their explicit authorization for such Processing, except in cases where such authorization is not required by law;

b) The Processing is necessary to safeguard the vital interest of the Data Subject and they are physically or legally incapacitated. In these events, legal representatives must grant their authorization;

c) The Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association, or any other non-profit organization, whose purpose is political, philosophical, religious, or trade union-related, provided that it refers exclusively to its members or to persons who maintain regular contact due to its purpose. In these events, the data may not be supplied to third parties without the Data Subject’s authorization;

d) The Processing refers to data that is necessary for the recognition, exercise, or defense of a right in a judicial process;

e) The Processing has a historical, statistical, or scientific purpose. In this event, measures conducive to the suppression of the Data Subjects’ identity must be adopted.

Special requirements for the processing of personal data of children and adolescents.

By means of which the Unique Regulatory Decree of the Industry and Tourism Sector. “The processing of personal data of children and adolescents is prohibited, except when it concerns public data, in accordance with Article 7 of Law 1581 of 2012, and when such Processing complies with the following parameters and requirements: 1. That it responds to and respects the best interests of children and adolescents. 2. That it ensures respect for their fundamental rights. Once the above requirements are met, the legal representative of the child or adolescent will provide authorization after the minor exercises their right to be heard, an opinion that will be valued taking into account their maturity, autonomy, and capacity to understand the matter.

Every controller and processor involved in the processing of personal data of children and adolescents must ensure the proper use of such data. To this end, the principles and obligations established in Law 1581 of 2012 and this chapter must be applied. The family and society must ensure that controllers and processors of minors’ personal data comply with the obligations established in Law 1581 of 2012 and this chapter.

RIGHTS OF THE PERSONAL DATA SUBJECT

In accordance with the Law, Personal Data Subjects have the following rights:

a) To know, update, and rectify their Personal Data before the Firm or the Data Processors. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented, misleading data, or data whose Processing is expressly prohibited or has not been authorized.

b) Request proof of the Authorization granted to the Firm, unless the Law indicates that such Authorization is not necessary.

c) Submit requests to the Firm or the Data Processor regarding the use made of their Personal Data, and to have such information provided to them.

d) File complaints with the Superintendence of Industry and Commerce for infringements of the Law.

e) Revoke their Authorization and/or request the deletion of their Personal Data from the Firm’s databases, when the Superintendence of Industry and Commerce has determined by a definitive administrative act that the Firm or the Data Processor has engaged in conduct contrary to the Law or when there is no legal or contractual obligation to keep the Personal Data in the controller’s database.

f) Request and access their Personal Data free of charge that has been subject to Processing in accordance with Article 21 of Decree 1377 of 2013.

g) Be aware of modifications to the terms of this Policy prior to and effectively before the implementation of new modifications or, failing that, of the new information processing policy.

h) Have easy access to the text of this Policy and its modifications.

i) Easily and simply access the Personal Data under the control of the Firm to effectively exercise the rights granted to Data Subjects by Law.

j) Know the department or person authorized by the Firm to whom complaints, inquiries, claims, and any other request regarding their Personal Data may be submitted.

Data Subjects may exercise their legal rights and carry out the procedures established in this Policy by presenting their citizenship card or original identification document. Minors may exercise their rights personally, or through their parents or adults who hold parental authority, who must prove this with relevant documentation. Likewise, the Data Subject’s rights may be exercised by successors who prove such status, the Data Subject’s representative and/or attorney with the corresponding accreditation, and those who have made a stipulation in favor of another or for another.

PRINCIPLES

Principle of legality in data Processing: The Processing referred to in this law is a regulated activity that must comply with its provisions and other developing regulations.

Principle of purpose: Processing must obey a legitimate purpose in accordance with the Constitution and the Law, which must be informed to the Data Subject.

Principle of freedom: Processing can only be carried out with the prior, express, and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that waives consent.

Principle of veracity or quality: Information subject to Processing must be truthful, complete, accurate, updated, verifiable, and understandable. The Processing of partial, incomplete, fragmented, or misleading data is prohibited.

Principle of transparency: Processing must guarantee the Data Subject’s right to obtain from the Data Controller or Data Processor, at any time and without restrictions, information about the existence of data concerning them.

Principle of restricted access and circulation: Processing is subject to the limits derived from the nature of personal data, the provisions of this law, and the Constitution. In this sense, Processing may only be carried out by persons authorized by the Data Subject and/or by persons provided for in this law.

Personal data, except public information, may not be available on the Internet or other means of mass dissemination or communication, unless access is technically controllable to provide restricted knowledge only to Data Subjects or authorized third parties in accordance with this law.

Principle of security: Information subject to Processing by the Data Controller or Data Processor referred to in this law must be handled with the technical, human, and administrative measures necessary to ensure the security of records, preventing their alteration, loss, consultation, unauthorized or fraudulent use or access.

Principle of confidentiality: All persons involved in the Processing of personal data that is not public in nature are obliged to guarantee the confidentiality of the information, even after their relationship with any of the tasks comprising the Processing has ended, being able to only provide or communicate personal data when it corresponds to the development of the activities authorized in this law and in its terms.

INFORMATION SECURITY POLICIES

  • Users must avoid using corporate devices in places that do not offer the necessary physical security guarantees to prevent their loss or theft. Users must not modify the security settings of corporate devices under their responsibility, nor uninstall the software provided with them upon delivery.
  • Users must avoid installing programs from unknown sources; applications should only be installed from official repositories.
  • Users are obligated to accept and apply the new version every time their corporate equipment system notifies them of an available update. Users must not use public wireless networks with devices assigned by the company.
  • Users must avoid connecting corporate removable storage media to any public computer, hotel, or internet café, among others.
  • Users must not store videos, photographs, or personal information on assigned corporate devices.
  • Users must not use websites unauthorized by the company on corporate devices.
  • Do not upload private documents to unauthorized online sites.

Information security measures

Information Controls

It is established that the registered database information is located on a secure server or information equipment, as well as data protection for internal and external personnel through supervision by the data controller for each database registered with the SIC.

An internal data network system is in place to prevent infiltrated connections or networks under the internet and local network. This network also provides connections with internet access and shared resources.

The databases, purposes, and use in guaranteeing information are solely and exclusively used by the data controller for commercial, administrative, legal, human resources, financial, and/or accounting purposes on proprietary servers and secure equipment under the licensing of contracted software for specific purposes.

Physical Systems and Safeguarding

  • Server equipment for information backups and database security.
  • Structured cabling in RACK server, firewall, and router provisioned to prevent external connections to the local data network.
  • Regulated electrical systems backed up by uninterruptible power supplies (UPS).

INQUIRIES, COMPLAINTS, AND/OR CLAIMS ATTENTION

CLAIMS Data Protection Officer

The customer service representative is responsible for receiving and addressing petitions, complaints, claims, suggestions, and inquiries related to Personal Data. The customer service representative will direct requests to the data protection officer in accordance with Law 1582 of 2012 and the provisions of this policy, where they must:

a) Receive requests from Personal Data Subjects, process and respond to those that are based on the Law or these Policies, such as: requests for updating Personal Data; requests to know Personal Data; requests for deletion and/or rectification of Personal Data when the Data Subject presents a copy of the Superintendence of Industry and Commerce’s decision in accordance with the Law, requests for information on the use given to their Personal Data, requests for updating Personal Data, requests to revoke the Authorization granted, when applicable according to the Law.

b) Respond to Personal Data Subjects regarding requests that are not applicable according to the Law.

Customer Service contact details are:

Name: Hernán Juan Carlos Mora Suarez
Physical Address: Calle 72 #10-07 Office 1103
Email Address: gerencia.g@krestoncolombia.com
Phone: (601) 7443680

Procedures for exercising the rights of Personal Data Subjects

Inquiries

Data Subjects or their successors may consult the Data Subject’s personal information held in any database, whether public or private. The Data Controller or Data Processor must provide them with all information contained in the individual record or linked to the Data Subject’s identification.

The inquiry will be submitted through the means enabled by the Data Controller or Data Processor, provided that proof of it can be maintained.

The inquiry will be answered within a maximum period of ten (10) business days from the date of receipt. If it is not possible to answer the inquiry within this period, the interested party will be informed, stating the reasons for the delay and indicating the date on which it will be answered.

their inquiry, which in no case may exceed five (5) business days following the expiration of the initial period.

PARAGRAPH. The provisions contained in special laws or regulations issued by the National Government may establish shorter terms, depending on the nature of the personal data.

These mechanisms may be physical, such as a registration process at Kreston Colombia, or electronic, through the email pqrs@kreston.co, responsible for receiving petitions, complaints, and claims.

Whatever the means, proof of the inquiry and its response will be kept.

Claims

The Data Subject or their successors who consider that the information contained in a database should be corrected, updated, or deleted, or who notice an alleged breach of any of the duties contained in this law, may file a claim with the Data Controller or Data Processor, which will be processed under the following rules:

a) The claim will be submitted by means of a request addressed to the Data Controller or Data Processor, with the identification of the Data Subject, a description of the facts giving rise to the claim, the address, and accompanied by the documents to be relied upon. If the claim is incomplete, the interested party will be required within five (5) days following receipt of the claim to correct the deficiencies. If the applicant does not submit the required information within two (2) months from the date of the request, it will be understood that they have withdrawn the claim.

In the event that the recipient of the claim is not competent to resolve it, they will transfer it to the appropriate party within a maximum period of two (2) business days and inform the interested party of the situation.

b) Once the complete claim is received, a legend stating “claim in process” and the reason for it will be included in the database within a maximum of two (2) business days. This legend must be maintained until the claim is resolved.

c) The maximum period to address the claim will be fifteen (15) business days from the day following its receipt. If it is not possible to address the claim within this period, the interested party will be informed of the reasons for the delay and the date on which their claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the initial period.

The claim must be submitted by the Data Subject, their successors, or representatives or accredited persons in accordance with Law 1581 and Decree 1377, as follows:

  • It must be addressed to KRESTON COLOMBIA electronically at the email address pqrs@kreston.co. It must include the Data Subject’s name and identification document.
  • A description of the facts giving rise to the claim and the objective pursued (update, correction, or deletion, or compliance with duties).
  • It must indicate the claimant’s address and contact details and identification.
  • It must be accompanied by all documentation that the claimant wishes to rely upon.
  • Security measures and/or controls implemented in the database to minimize the risks of improper use of the personal data processed.

Validity

This Policy is effective from January 1, 2018. Personal Data that is stored, used, or transmitted will remain in our Database, based on the criteria of temporality and necessity, for the time necessary for the purposes mentioned in this Policy, for which it was collected.

1.PRIVACY NOTICE

In consideration of Statutory Law 1581 of 2012 and Regulatory Decree 1377 of 2013, which dictate provisions for the protection of personal data, and taking into account that KRESTON COLOMBIA currently has databases containing personal data that have been or will be collected in the development of its corporate purpose, and which were provided by the data subjects, it will maintain total confidentiality of such data in accordance with the policies defined in the document found at https://krestoncolombia.com/contacto.php If you do not wish to receive more information from KRESTON COLOMBIA, please request it via email to pqrs@kreston.co with your personal data.

At any time, the data subject may revoke their consent and exercise their right to the deletion of personal data enshrined in Law 1581 of 2012.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.