NATIVAPPS’ POLICY FOR THE PROCESSING AND PROTECTION OF PERSONAL DATA
NATIVAPPS SAS. with Tax ID: 900.545.138-1 and hereinafter referred to as NATIVAPPS, complying with the provisions of Statutory Law 1581 of 2012 and its Regulatory Decree 1377 of 2013, which establish the creation and regulation of the personal data protection regime, and in order to standardize the process, this policy is issued, containing the legal framework and the procedure to be followed based on information security standards for the proper processing of personal data within the company. This is not only a legal duty enshrined in Article 15 of the Political Constitution, in Law 1581 of 2012 and its Regulatory Decree, but also constitutes a philosophy adopted by the organization in order to be active agents in safeguarding the Habeas Data rights of the data subjects, who have entrusted their data to us for processing in the course of our commercial activity and corporate purpose. Therefore, we issue This policy is based on the following:
TITLE I
GENERAL PROVISIONS
ARTICLE 1.- PURPOSE OF THE POLICY
To provide guidelines for the protection of Personal Data at NATIVAPPS, formalizing the adoption of a philosophy of respect for the rights of data subjects, embraced by senior management for all areas of the company. This consists of adopting, as one of the fundamental standards to be considered in each of our tasks, informing data subjects of their rights and our obligations regarding the proper processing and protection of their data. We guarantee our commitment, not only in terms of regulations but also institutionally, and provide data subjects with the tools to exercise their rights of access, updating, rectification, and erasure of their data, where applicable.
ARTICLE 2.- SCOPE
The provisions of this policy for the protection and processing of Personal Data of NATIVAPPS shall apply to all administrative, organizational, and control aspects and therefore bind the following persons:
a) The company’s legal representative.
b) NATIVAPPS internal personnel, from directors to administrative employees, who process, store, or have personal data processed by them.
c) Contractors and natural or legal persons who provide services to NATIVAPPS or with whom agreements are entered into under any contractual modality through which any processing of personal data is carried out; this provision must be included in all contracts entered into.
d) Those persons with whom there is a legal relationship of a statutory, contractual, or similar nature.
e) Natural persons, legal entities, mixed-economy entities, NGOs, public entities, oversight bodies, and, in general, those who assume the status of users of personal data.
f) Other persons as established by law.
ARTICLE 3.- SCOPE OF APPLICATION
The principles and procedures established in this policy shall apply to the processing of personal data carried out by NATIVAPPS, including its offices and/or branches within Colombian territory, whether operating independently or through agreements, or when the data controller and/or processor is located outside of Colombian territory by virtue of international treaties, contractual relationships, or other means.
The principles and provisions of this policy apply to any database registration process through which data is collected in person, remotely, through a representative, virtually, or biometrically, for the acquisition of any NATIVAPPS product and/or service, or as a result thereof. This policy also applies to any database held by NATIVAPPS as the data controller and/or processor of personal data.
NATIVAPPS will directly handle the processing of personal data; however, it reserves the right to delegate this processing to a third party, provided that the processor complies with and implements the appropriate foundations and procedures for the protection of personal data, strict confidentiality, security, and compliance with these policies. This compliance extends to its employees, contractors, and others who have a relationship with them and who, in the course of their duties, have access to the data. This compliance must be guaranteed even after the termination of their employment, as stipulated in the respective contracts.
ARTICLE 4.- LEGAL FRAMEWORK:
This policy is developed based on the following regulations:
Law 1266 of 2008; “which establishes the general provisions for habeas data and regulates the handling of information contained in databases of personal data, especially financial, credit, commercial, and service data, and data originating from third countries, and other provisions are enacted.”
Law 1273 of 2009: “Which modifies the Penal Code, creates a new protected legal right—called “the protection of information and data”—and comprehensively preserves the systems that use information and communication technologies, among other provisions.”
Judgment C-748 of 2011 – “Constitutionality of the draft statutory law on the protection of Personal Data”
Law 1581 of 2012: “Which establishes general provisions for the protection of Personal Data.”
ARTICLE 5.- DEFINITIONS
a) Privacy Notice: Verbal or written communication in a physical or electronic document generated by the data controller and made available to the data subject with information regarding the existence of personal data processing policies, how to access them, and the purposes of the intended processing of personal data.
b) Personal Data Database: A set of organized personal data stored in a system for consultation.
c) Transfer of Personal Data: Data processing that involves its disclosure to a person other than the data subject or someone other than the authorized recipient.
d) Personal Data: Any information or data that identifies or allows the identification of one or more natural persons (referring to a person or individual). Data may be: numerical (addresses, telephone numbers, etc.), alphabetical (names), graphic (photographs, digitized signatures, route maps, etc.), visual (video recordings), biometric (fingerprints, personal image, voice audio), or of any other type.
e) Data Private: This is data that, due to its intimate and confidential nature, is only relevant to its owner.
f) Public Data: This refers to data that is not semi-private, private, or sensitive. Public data includes information related to a person’s marital status, profession or occupation, and their status as a merchant or public servant. By their nature, public data may be contained in public registries, public documents, gazettes, official bulletins, and duly executed court judgments that are not subject to confidentiality, and are freely accessible without restriction.
g) Sensitive Data: This is personal data that is specially protected because it relates to racial or ethnic origin, membership in unions, social or human rights organizations, political or religious beliefs, sexual life, biometric data, or health data (medical records). This data forms part of a person’s private life and may only be collected with the express and informed consent of the data subject, as provided by law.
h) Data Processor: A natural or legal person, public or private, who, alone or jointly with others, processes personal data on behalf of the data controller.
i) Data Controller: A natural or legal person, public or private, who, alone or jointly with others, decides on the database and/or the processing of the data.
j) Data Subject: A natural or legal person whose data is being processed.
k) Processing: Any operation or set of operations and technical procedures, whether automated or not, performed on personal data, which may include collection, recording, storage, retention, use, circulation, modification, blocking, cancellation, or deletion.
l) User: A natural or legal person who has an interest in the use of personal information.
m) Violation of Personal Data: This is the crime established by Law 1273 of 2009, contained in Article 269 F of the Colombian Penal Code. The criminal offense is as follows: “Anyone who, without authorization, for their own benefit or that of a third party, obtains, compiles, steals, Anyone who offers, sells, exchanges, sends, buys, intercepts, discloses, modifies, or uses personal codes or personal data contained in files, archives, databases, or similar media will be subject to imprisonment for forty-eight (48) to ninety-six (96) months and a fine of 100 to 1,000 times the current monthly minimum wage.
TITLE II
PRINCIPLES
ARTICLE 6.- PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
The protection of personal data at NATIVAPPS will be subject to the following fundamental principles or rules. Based on these, the guidelines for internal processes related to the processing of personal data will be established. These principles will be interpreted harmoniously to resolve any conflicts that may arise in this area. The principles established in international standards, Colombian laws, and the jurisprudence of the court will be applied. Constitutional framework that has developed fundamental rights related to personal data.
6.1. Legality: Since the processing of personal data is a regulated activity in Colombia, all processes related to it and the recipients of Law 1581 of 2012 must comply with it.
6.2. Purpose: The processing of personal data must have a legitimate purpose, in accordance with the Constitution and the law, which must be clearly and precisely communicated to the Data Subject beforehand so that they can give their informed consent.
6.3. Principle of Informed Consent or Principle of Freedom: To process personal data within NATIVAPPS, it may only be done with the prior, express, and informed consent of the data subjects. Personal data may not be obtained, processed, or disclosed without the data subject’s authorization, except as provided by law or a court order that supersedes the data subject’s consent.
6.4. Principle of veracity or quality: The personal data collected by NATIVAPPS must be truthful, complete, accurate, verifiable, understandable, and kept up-to-date. The processing of partial, fragmented, incomplete, or misleading data is prohibited.
6.5. Principle of transparency: In the processing of personal data, the data subject’s right to obtain and know from the controller and/or processor, at any time and without restrictions, information about the existence of data concerning them will be guaranteed.
6.6. Principle of access and restricted circulation: The personal data collected or processed by NATIVAPPS will be used only in accordance with the purpose and authorization granted by the data subject. Therefore, it may not be accessed, transferred, assigned, or communicated to third parties. Personal data held by NATIVAPPS may not be made available on the internet or through any other mass media, unless access is technically controllable and secure. This is to ensure restricted access only to the data subjects or authorized third parties, in accordance with the law and applicable principles.
6.7. Security Principle: NATIVAPPS, as the data controller and/or processor, as applicable, will implement the necessary physical, technological, and/or administrative measures to guarantee the integrity, authenticity, and reliability of personal data. Therefore, it will implement high, medium, or low level security measures, as appropriate, to prevent alteration, leakage, unauthorized or fraudulent access, use, or disclosure.
6.8. Principle of Confidentiality: NATIVAPPS, and all persons involved in the processing of personal data, are obligated to guarantee the confidentiality of the information, even after the termination of the employment and/or contractual relationship. NATIVAPPS will include data protection clauses in its contractual relationships as required to guarantee this principle.
TITLE III
RIGHTS OF PERSONAL DATA SUBJECTS
Article 7:
Rights of Data Subjects: Data subjects whose personal data is stored in NATIVAPPS’ information systems have the following rights, in compliance with constitutional guarantees and the law. The exercise of these rights will not entail any cost for users and is a personal right that belongs solely and exclusively to the data subject in the first instance, except as otherwise provided by law.
a) Right of access: This right grants all users the power to know and obtain all information regarding their personal data processed by NATIVAPPS, including the purpose of the processing, the location of the databases, and any communications and/or transfers made by them.
b) Right to update: This right grants the data subject the power to update their personal data when it has been modified.
c) Right to rectification: All data subjects whose personal data is processed by NATIVAPPS may modify any data that is inaccurate, incomplete, or nonexistent.
d) Right to cancellation or revocation of consent: The data subject, or someone authorized by law, may cancel or delete their personal data, as well as revoke the consent NATIVAPPS has for processing their personal data, when they consider it excessive, irrelevant, or when the processing is contrary to the law, except for the exceptions provided for in the legal system and when such cancellation or revocation is applicable.
e) Right to object. This right constitutes the power of the data subject to object to the processing of their personal data, except in cases where such right does not apply by law.
If the processing of personal data violates general interests that outweigh the particular interests of NATIVAPPS, NATIVAPPS, in light of the legitimate rights argued by the data subject, will make the appropriate decision.
f) Right to file complaints and claims or to take legal action. The data subject has the right to file complaints and claims with NATIVAPPS regarding the processing of their personal data, as well as with the Superintendency of Industry and Commerce, or the competent authority, and to take legal action for the protection of their data, in accordance with Law 1581 of 2012.
g) Right to authorize data processing. In accordance with the principle of informed consent, the data subject has the right to authorize NATIVAPPS to process their personal data. This consent may be given by any means that allows for its subsequent verification.
Paragraph: NATIVAPPS will exceptionally not require authorization for the processing of personal data in the following cases:
When required by a public or administrative entity in compliance with its legal functions, or by court order.
When dealing with publicly available data.
In cases of medical or health emergencies.
When processing information is authorized by law for historical, statistical, or scientific purposes.
When dealing with personal data related to civil registration.
Therefore, despite the fact that the data subject’s authorization is not required, NATIVAPPS will ensure compliance with the relevant legal principles and provisions. While the data subject’s authorization is not required, the other legal principles and provisions regarding personal data protection will apply.
TITLE IV
DUTIES OF RECIPIENTS OF THIS POLICY REGARDING PERSONAL DATA WHEN THEY ACT AS CONTROLLERS AND/OR PROCESSORS
ARTICLE 8: DUTIES OF CONTROLLERS OF PERSONAL DATA:
In the event that NATIVAPPS or any of the recipients of this policy assumes the role of controller of personal data entrusted to its custody, it shall have the legal duty, without prejudice to the provisions of the law, to comply with the following:
a) Guarantee the Data Subject, at all times, the full and effective exercise of their right to data protection (habeas data).
b) Request and retain a copy of the respective authorization granted by the Data Subject.
c) Inform the Data Subject of the purpose of the processing of their data and their rights.
d) Maintain the information under the necessary security conditions to prevent its alteration, loss, unauthorized or fraudulent access, use, or disclosure.
e) Ensure that the information provided to the data processor is truthful, complete, accurate, up-to-date, verifiable, and understandable.
f) Promptly update, rectify, or delete the data in accordance with the law and take all other necessary measures to ensure that the information provided to the processor remains up-to-date.
g) Rectify the information when it is incorrect and notify the Data Processor accordingly.
h) Provide the Data Processor, as applicable, only with data whose processing has been previously authorized in accordance with the law.
i) Require the Data Processor at all times to respect the security and privacy conditions of the Data Subject’s information.
j) Process inquiries and complaints submitted in accordance with the terms established in this policy and the law. k) Inform the data processor that certain information is under dispute by the data subject, once a complaint has been filed and the corresponding procedure has not yet been completed.
l) Inform the data subject promptly and upon request about the use given to their data.
m) Inform the data protection authority when security breaches occur and there are risks in the management of data subjects’ information.
n) Comply with the instructions and requirements issued by the Superintendency of Industry and Commerce.
ARTICLE 9: DUTIES OF THOSE IN CHARGE OF PROCESSING PERSONAL DATA.
In the event that NATIVAPPS or any of the recipients of this policy assumes the role of data processor for personal data entrusted to its custody, it shall have the legal obligation, without prejudice to the provisions of the law, to comply with the following:
a) Guarantee the Data Subject, at all times, the full and effective exercise of their right to data protection (habeas data).
b) Maintain the information under the necessary security conditions to prevent its alteration, loss, unauthorized or fraudulent access, use, or disclosure.
c) Carry out the timely updating, rectification, or deletion of the data. The terms of the law.
d) Update the information reported by the data controllers within five (5) business days of receiving it.
e) Process inquiries and complaints submitted by data subjects in accordance with the terms established in this regulation and the law.
g) Register the phrase “complaint in process” in the database, as regulated by law, for unresolved complaints or claims submitted by data subjects.
h) Insert the phrase “information under judicial review” in the database once notified by the competent authority of legal proceedings related to the accuracy of the personal data.
i) Refrain from circulating information that is being disputed by the data subject and whose blocking has been ordered by the Superintendency of Industry and Commerce.
j) Allow access to the information only to those persons authorized to access it. k) Report to the Superintendency of Industry and Commerce any violations of security codes and any risks in the management of data subjects’ information.
l) Comply with the instructions and requirements issued by the Superintendency of Industry and Commerce.
ARTICLE 10: COMMON DUTIES OF DATA CONTROLLERS AND PROCESSORS.
In addition to the duties described above, NATIVAPPS and any other person assuming the role of data controller or processor shall be responsible for the following additional duties, regardless of their status:
a) Implement security measures according to the classification of the personal data processed by NATIVAPPS.
b) Adopt incident management procedures applicable to databases containing personal data.
c) Adopt backup procedures for the databases containing personal data. d) Periodically audit compliance with the law and this policy by its recipients.
e) Securely manage databases containing personal data.
f) Apply this policy on the processing and protection of personal data in accordance with the “Information Security Policy.”
g) Maintain a central registry of databases containing personal data, including their history from creation and data processing to deletion.
h) Securely manage access to personal data databases contained in information systems where it acts as the data controller or processor.
i) Regulate access to databases containing personal data in contracts with third parties.
TITLE V
PROCESSING OF PERSONAL DATA
Activities related to the processing of personal data at NATIVAPPS will be governed by the following parameters: personal data will be collected from its users (applicants in the selection process, contractors, visitors, and others) for the performance and development of its business and/or corporate purpose, based on the following grounds:
a) Acceptance of the policy: Our users, employees, contractors, partners, and others involved unequivocally acknowledge and accept our policy for the processing and privacy of personal data and their information, in accordance with its terms, when the user, the data subject, or their legal representative (in the case of minors) provides the data through the means provided for this purpose at the service points, or through their parents, during interviews for job applications and contractual relationships.
a) Acceptance of the policy: Our users, employees, contractors, partners, and others involved unequivocally acknowledge and accept our policy for the processing and privacy of personal data and their information, in accordance with its terms, when the user, the data subject, or their legal representative (in the case of minors) provides the data through the means provided for this purpose at the service points, or through their parents, during interviews for job applications and contractual relationships.
b) Processing of sensitive data: Data subjects are under no obligation to provide or authorize the processing of sensitive data. However, if such data is required for the provision of any service, they must expressly consent to the processing of the information in accordance with this policy. In this case, data related to their medical history and biometric data may be processed, for which the highest protection and security measures will be applied.
c) Processing of data for security and legal compliance purposes: For security purposes, NATIVAPPS may collect, store, share, and compare personal information and data, including biometric data, from our users obtained through our website and image, audio, or video recording devices located at our facilities with various administrative control and oversight authorities, police authorities, and national and international judicial authorities. This information will be obtained after informing the general public through privacy notices.
d) Processing of data collected by video surveillance cameras. Surveillance cameras: The surveillance cameras installed at NATIVAPPS facilities
The cameras are monitored by NATIVAPPS and their purpose is to collect images that allow for the prevention or identification of potential criminal behavior or behavior that affects the rights of our visitors, employees, or personnel associated with NATIVAPPS. Recording is done in real time and a record is stored in the system for the first 24 hours, after which it is automatically deleted. In the event of an incident that warrants saving a copy, only the person in charge of and/or responsible for processing the recording will make a copy and store it, guaranteeing the integrity of the evidence. NATIVAPPS has posted privacy notices in the areas where the cameras are located and never records in private or intimate spaces. NATIVAPPS prohibits the delivery of copies of recordings to individuals; however, if their image is captured, the right of access to the data will be guaranteed, provided that all legal requirements are met and the confidentiality and privacy of third parties recorded in the recordings are ensured. Copies of the recordings will only be provided upon official request from the competent authority, fulfilling all legal requirements to maintain the integrity of the evidence. Given that video surveillance in public areas is solely the responsibility of the State, NATIVAPPS has cameras in external areas that only capture images of access points to our private areas, such as doors and gates. This is to ensure security at our entrances, and notices will be posted at these access points.
Paragraph: Applicants for positions offered by Human Resources, contractors, employees, suppliers, and other users and data subjects are obligated to provide us with truthful information about their personal, family, corporate, and other references. NATIVAPPS presumes the veracity of the information provided, even after verifying it with aptitude tests and/or studies, security checks, and other evidence. This presumption of veracity will be based on the good faith of the applicants, employees, users, suppliers, and others. Therefore, in the event of falsehoods and/or omissions on their part, no responsibility is assumed for the consequences arising from the lack of truthfulness, validity, sufficiency, or authenticity of the information and personal data, including damages or losses resulting from cases of homonymy or identity theft.
ARTICLE 11. PROCESSING OF PERSONAL DATA RELATED TO HUMAN RESOURCES
Express acceptance of this policy for the processing and protection of personal data, in accordance with its terms, occurs when the data subject or their representative provides their personal data through any channel or means established by NATIVAPPS for the proper execution of the various Human Resources management processes and procedures, with the express written consent, which is understood to occur in three stages: a) before, b) during, and c) after the employment and/or contractual relationship. Therefore, NATIVAPPS will inform interested parties in advance of the characteristics and conditions of the selection process, as well as the rules applicable to the processing of the personal data provided by the interested party and that collected during the selection process.
ARTICLE 12: SPECIFIC PURPOSE OF PROCESSING PERSONAL DATA RELATED TO HUMAN RESOURCES:
NATIVAPPS will use your personal data due to its relationship with the Human Resources department for the following purposes:
a. To use the information and personal data provided to send information, either by mail or email,
b. related to Human Resources processes and procedures, such as: managing available job openings within the company, sending you information related to the selection process, hiring process, collective benefits derived from an employment contract, pay stubs or payment slips, training and development courses, and/or any other type of information directly or indirectly related to fulfilling the obligations arising from an employment contract, civil or commercial contract, and with Human Resources management.
c. To provide information and personal data to national and international control and oversight, administrative, police and judicial authorities, pursuant to a legal or regulatory requirement and/or to use or disclose this information and personal data in defense of the rights and/or property of the company, its clients, our websites or its users, for the detection or prevention of fraud, apprehension or prosecution of criminal acts or when
In good faith, we consider that the delivery of personal information and data is in the best interest of preserving security.
d. To allow access to personal information and data to auditors or third parties contracted to carry out internal or external audit processes related to our business activities.
e. To consult and update personal information and data at any time in order to keep said information current.
f. To contract with third parties for the storage and/or processing of personal information and data for the proper execution of Human Resources processes and procedures, under the security and confidentiality standards to which we are bound.
g. To transfer your personal information and data in the event of a change of control to another company through a merger, acquisition, bankruptcy, spin-off, or creation, to the new entity controlling the company. If, as a result of the change of control, there is a change in the entity responsible for processing personal information and data, this situation will be reported to the data subjects so that they may exercise their rights in accordance with applicable law. The conditions under which data subjects may exercise their rights will be indicated when the change of control is reported.
h. Transfer your personal data for suitability studies, medical examinations, psychometric tests, and other relevant selection processes.
i. Send greeting cards for birthdays and/or special occasions, as well as messages of condolence in the event of tragic events.
j. Register with compensation funds, occupational risk insurance companies (ARL), health insurance providers (EPS), process disability claims, and other related entities to guarantee the rights of workers and/or associates.
k. Manage activities related to year-end events, gifts for employees’ children, subsidies, and other related matters.
ARTICLE 13: PROCESSING OF PERSONAL DATA BEFORE HIRING.
NATIVAPPS will inform you of the positive or negative result once the selection process is complete. Information obtained by NATIVAPPS regarding those who were not selected, such as results of psychometric tests, interviews, and other relevant data, will be deleted from files and information systems, thus complying with the principle of purpose limitation. Once this purpose has been fulfilled, the data will be removed from the databases. When NATIVAPPS receives personal data through transfers from third parties responsible for hiring individuals for temporary work, NATIVAPPS will regulate in the contracts the processing of personal data provided by the data subjects to the third party and received for the purpose of that contract, as well as the intended use of the personal information obtained. Personal data and information obtained during the selection process regarding personnel selected to work at NATIVAPPS will be stored in a personnel file, which may be physical or digital. High levels of security and measures will be applied to this information due to the likelihood that it contains sensitive data. The purpose of providing the data supplied by those interested in vacancies offered by NATIVAPPS, and the personal information obtained during the selection process, is limited to participation in the process and aptitude tests for the work or service to which they aspire. Therefore, its use for any other purpose is prohibited.
ARTICLE 14: PROCESSING OF PERSONAL DATA DURING HIRING:
NATIVAPPS will store the personal data and information collected during the employee selection process in the respective digital or physical file, which is identified with the data subject’s name. This data will be processed by the Human Resources department, or its equivalent, for the purpose of managing actions arising from the contractual relationship between NATIVAPPS and the employee. The use of employee information for any purpose other than that derived from the contractual relationship is prohibited.
Paragraph: NATIVAPPS does not collect sensitive data from its employees; however, if required, it will indicate the optional nature of the data subject’s data collection and may process it during the contractual relationship to fulfill the purposes of the contract and guarantee the employer’s rights, such as disability benefits, subsidies, union membership rights, etc. Therefore, when necessary, this data will be managed with due diligence and stored with high security, preventing unauthorized access and thus guaranteeing its security. Similarly, the data of our employees’ minor children will be processed with prior authorization. And their parents, and with the sole related purpose of guaranteeing the rights and/or benefits they hold due to their parents’ contractual status.
ARTICLE 15. PROCESSING OF PERSONAL DATA UPON TERMINATION OF THE CONTRACT.
Once the relationship arising from the contract has ended, for whatever reason, NATIVAPPS will store the personal data, both that obtained during the contracting process and that derived from the contractual relationship, in a central file under high security measures. The transfer of this data to third parties is prohibited, except with the written authorization of the data subjects, a legal mandate, or a request from the competent authorities.
ARTICLE 16. PROCESSING OF PARTNERS’ PERSONAL DATA.
NATIVAPPS collects data from individuals who are members of the organization. This data is considered confidential, as it is recorded in the company’s accounting records and holds the same status by legal mandate. Therefore, access to this information will be granted in accordance with applicable commercial regulations, and it will only be processed for the purposes of the existing relationship with the members.
ARTICLE 17. PROCESSING OF PERSONAL DATA OF CONTRACTORS AND/OR SUPPLIERS.
For NATIVAPPS, the processing of personal data is essential for formalizing contracts that enable the development of its business activities. Therefore, it will only collect the necessary, relevant, and non-excessive data for the following purposes:
a) Evaluating and selecting suppliers.
b) Complying with legal and tax obligations to government entities and regulatory bodies arising from the contracting process. c) Conduct qualitative and quantitative diagnostic assessments and evaluations of the service levels received from suppliers.
d) Communicate the terms and conditions regarding negotiation policies with suppliers.
e) Generate inquiries, audits, and reviews arising from the contractual relationship with the supplier.
f) Any other activity necessary for the effective performance of the contracted work.
NATIVAPPS will collect the personal data of its suppliers’ employees only when they are involved in the contract and when such data is necessary and appropriate to the contract. For security reasons, NATIVAPPS must analyze and verify this data according to the type of services contracted. The personal data of supplier employees collected by NATIVAPPS will be used solely to verify the suitability and competence of the employees. Therefore, once the purpose for which the data was collected and the contract’s objective have been fulfilled, NATIVAPPS will return the documentation to the supplier or delete the collected information from its electronic or physical files. Likewise, suppliers will be obligated to NATIVAPPS, when NATIVAPPS provides personal data of their employees, to process and protect it in accordance with this policy, ensuring that the data is relevant and not excessive in relation to the purpose of the contract, and that the documents required for such purposes are returned and the personal data deleted from their databases once the contract’s purpose has ended.
ARTICLE 18. PROTECTION OF PERSONAL DATA OF MINORS AND ADOLESCENTS.
NATIVAPPS may process personal data of children and adolescents under the age of 18, provided that such processing is duly authorized by their parents or legal guardians. In the event that the parents or legal guardians of these minors detect unauthorized data processing, they may submit their inquiries or complaints to the following email address: protecciondedatos@nativapps.com. NATIVAPPS will ensure the proper use of the personal data of children and adolescents, guaranteeing that the processing of their data respects applicable laws, their best interests, and their fundamental rights, and, where possible, taking into account their opinion as the data subjects.
ARTICLE 19. DATA RETENTION PERIOD.
The information processed by NATIVAPPS will remain in its information systems according to the purpose of the processing and the nature of the data; however, it may remain stored for up to eighty (80) years from the date of the last processing, to allow us to comply with the legal and/or contractual obligations in charge, especially in accounting, tax and fiscal matters, or for all the time necessary to comply with the provisions applicable to the matter in question, as well as the administrative, accounting, tax, legal and historical aspects of the information, or in any other way. Event foreseen by law.
ARTICLE 20. EXCEPTIONS TO AUTHORIZATION FOR THE PROCESSING OF PERSONAL DATA.
NATIVAPPS is subject to exceptions to the authorization for the processing of personal data in the following cases:
a) When the information is required by a public or administrative entity acting in the exercise of its legal functions or by court order.
b) When the data is of a public nature because it is not protected by the scope of application of the law.
c) In the case of duly verified medical or health emergencies.
d) In those cases where the information is authorized by law to fulfill historical, statistical, and scientific purposes.
e) When the data is related to the civil registry of persons because this information is not considered to be of a private nature.
ARTICLE 21. PERSONS TO WHOM DATA IS DELIVERED WITHOUT THE AUTHORIZATION OF THE DATA SUBJECT.
NATIVAPPS may disclose personal data to third parties without the data subject’s involvement in the following cases:
a) To the heirs of the data subjects or their representatives at any time and through any means when they so request and duly prove their status to NATIVAPPS.
b) To judicial or administrative entities exercising their functions when they request the information.
c) To third parties authorized by any law of the Republic of Colombia.
d) To third parties expressly authorized by the data subject to disclose the information, provided that such authorization is duly submitted to NATIVAPPS.
ARTICLE 22. DISCLOSURE OF DATA TO AUTHORITIES.
When competent authorities require NATIVAPPS to access and/or provide personal data contained in its databases, NATIVAPPS will verify the legality of the request and ensure proper documentation of the information delivery, guaranteeing its attributes such as authenticity, reliability, and integrity. NATIVAPPS will also emphasize its responsibility for confidentiality and safekeeping, as well as its duty to protect the data, both for the requesting official and the recipient, as well as for the entity for which they work. NATIVAPPS reserves the right to comply with the legal orders of competent authorities and to keep such legal requests confidential from the data subjects, respecting investigations and any order issued by the competent authority to refrain from informing the data subject about the request made by the authorities.
ARTICLE 23. DATA CONTROLLER AND PROCESSOR
NATIVAPPS is the data controller and, in some cases, the processor of personal data. This does not exclude the responsibility of all employees to adopt the guidelines and procedures for compliance with this policy, given their status and commitment as custodians of the personal information they may process in the performance of their duties and which is contained in Nativapps’ information systems. Therefore, the responsibility within the organization to ensure compliance with and safeguard these rights rests with NATIVAPPS Management, and this policy provides the following identifying information:
Company Name: NATIVAPPS SAS. Tax ID: 900.545.138-1
Main Address: Calle 94 # 51b-46, Office 607 Movich, Buró 51 Barranquilla (Atlántico)
Contact Phone: (605) 3148468
The person or department responsible for handling requests, inquiries, and complaints, as well as the area in charge of receiving and processing all requests and concerns, is the Management Department, which can be contacted via email at: protecciondedatos@nativapps.com
TITLE VI
PROCEDURES FOR INQUIRIES AND COMPLAINTS RELATED TO THE PROCESSING OF YOUR PERSONAL DATA
In order to guarantee the rights of access, updating, rectification, cancellation, and objection of the data subject, NATIVAPPS implements the following procedure for these purposes:
a) The data subject must complete the Problem Handling Form (PWF) provided for this purpose and provide a detailed explanation of the The request must include the facts, your petition, and the right you wish to exercise, which you may print and submit to Nativapps in physical or electronic form.
b) Attach a physical or digital copy of your identity document. If you are acting as an attorney-in-fact, attach the power of attorney, duly authenticated by a notary public, and copies of the identity documents of the person you represent and your own. The request to exercise any of the aforementioned rights must contain the following information:
– Provide a physical and email address for notification purposes. – Attach supporting documents for the request. If applicable.
If any of the indicated requirements are missing, NATIVAPPS will contact the applicant within five (5) days of the application’s submission so that the deficiencies can be corrected. If two (2) months pass from the date of the request without the applicant submitting the required information, it will be understood that the application has been withdrawn.
NATIVAPPS will provide physical forms and virtual means via email at protecciondedatos@nativapps.com to facilitate the exercise of these rights by the data subject or their representative. These forms will indicate whether it is an inquiry or a complaint. Within two (2) business days of receiving the complete application, NATIVAPPS will indicate in its systems or files that it is a “complaint in process.” In the respective database, a field must be included displaying the following statements: “HABEAS DATA CLAIM IN PROCESS” and “HABEAS DATA CLAIM RESOLVED.”
When NATIVAPPS is responsible for the personal data contained in its information systems, it will respond to the request within ten (10) days if it is an inquiry, and within fifteen (15) days if it is a claim. NATIVAPPS will respond within the same timeframes when it verifies that its information systems do not contain the personal data of the interested party exercising any of the aforementioned rights.
In the case of a claim, if it is not possible to respond within fifteen (15) days, the interested party will be informed of the reasons for the delay and the date on which the claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the initial fifteen (15) days.
When NATIVAPPS acts as the data processor, it will inform the data subject or interested party of the personal data and notify the data controller of the request so that they may respond or address any applicable complaint. A copy of the communication addressed to the data processor will be sent to the data subject or interested party so they are aware of the identity of the data controller and, consequently, the primary party responsible for guaranteeing the exercise of their rights.
NATIVAPPS will maintain a record of requests and complaints made by data subjects or interested parties and will archive them. This information will be processed in accordance with the organization’s internal correspondence and security regulations, and, if necessary, will be referred to the Superintendency of Industry and Commerce to protect the rights of data subjects, using the legal actions available to them.
TITLE VII
PROHIBITIONS
ARTICLE 24 PROHIBITIONS RELATED TO THE PROCESSING OF YOUR PERSONAL DATA
In order to guarantee the rights of data subjects and the security of information, NATIVAPPS establishes the following prohibitions and penalties arising from non-compliance.
a) NATIVAPPS prohibits the access, use, management, transfer, communication, storage, and any other processing of sensitive personal data without the authorization of the data subject. Any such conduct by NATIVAPPS employees will result in the corresponding penalties under the law.
b) Any violation of this prohibition by suppliers contracting with NATIVAPPS will result in the consequences provided for such violations, without prejudice to any other legal action that may be taken. c) In contracts with suppliers where the contracted object relates to personal data, a provision will be agreed upon regarding any damages that may be caused to NATIVAPPS as a result of fines, operational sanctions, or other penalties imposed by the competent authorities, and as a consequence of the supplier’s imprudent or negligent actions.
d) The transfer, communication, or circulation of personal data is prohibited without the prior, written, and express consent of the data subject or without authorization from NATIVAPPS. The transfer or communication of personal data must be recorded and documented in the database where the data subject’s information is stored and must have the authorization of the data subject, as well as that of the custodian of the NATIVAPPS database, in this case, management.
e) NATIVAPPS prohibits the access, use, transfer, communication, processing, storage, and any other processing of sensitive personal data that may be identified during an audit procedure carried out in accordance with the organization’s policy on the proper use of IT resources and/or other policies issued by NATIVAPPS for these purposes.
f) NATIVAPPS prohibits the recipients of this this policy prohibits any processing of personal data that could give rise to any of the conduct described in Law 1273 of 2009 on Computer Crimes, unless authorized by the data subject and/or NATIVAPPS, as applicable.
g) NATIVAPPS will only process personal data of children and adolescents under the age of 18 with the express, prior, and informed consent of their legal representatives and/or those holding legal representation, for the purposes required in relation to the exercise of its business activities and/or corporate purpose. In all cases, the prevailing rights recognized by the Political Constitution for these individuals must be ensured, in accordance with the Code for Children and Adolescents.
TITLE VIII
POLICY AMENDMENTS
ARTICLE 25. POLICY AMENDMENTS:
This Policy may be amended when NATIVAPPS deems it necessary. We reserve the right to update and make significant modifications to this policy, as well as to our information handling practices. Recipients and the community at large have the right to request a copy of the current Data Processing and Protection Policy at any time, and they also have the right to exercise their rights as data subjects in accordance with applicable law.
Any changes to the personal data processing policy will be communicated to data subjects and/or recipients through the website: www.nativapps.com
TITLE IX
PROCEDURE AND SANCTIONS
ARTICLE 26: PROCEDURES AND SANCTIONS
NATIVAPPS informs the recipients of this policy of the sanctions regime established by Law 1581 of 2012 in Article 23, which addresses the risks assumed by the improper processing of personal data:
“ARTICLE 23. Sanctions. The Superintendency of Industry and Commerce may impose the following sanctions on Data Controllers and Data Processors: a) Personal and institutional fines of up to the equivalent of two thousand (2,000) current legal monthly minimum wages at the time the sanction is imposed. These fines may be levied successively as long as the non-compliance that gave rise to them persists. b) Suspension of activities related to the Processing for a period of up to six (6) months. The suspension order will specify the corrective measures that must be adopted. c) Temporary closure of operations related to the Processing once the suspension period has expired without the corrective measures ordered by the Superintendency of Industry and Commerce having been adopted. d) Immediate and definitive closure of the operation involving the Processing of sensitive data.”
Notice of any investigation procedure by any authority, related to the processing of personal data, must be immediately communicated to NATIVAPPS Management, in order to take the necessary measures to defend the entity’s actions and avoid the imposition of the sanctions provided for in Colombian legislation, particularly those set forth in Title VI, Chapter 3 of Law 1581 of 2012, described above.
As a consequence of the risks assumed by NATIVAPPS, either as the controller and/or processor of personal data, non-compliance with this rule by its recipients is considered a serious offense and will result in the termination of the respective contract without prejudice to any other legally applicable actions.