INICIATIVA LEGAL S.A.S

1. PURPOSE

INICIATIVA LEGAL S.A.S — hereinafter the COMPANY — pursuant to the provisions of the regulations currently in force on the protection of personal data, particularly Article 15 of the Colombian Political Constitution (right to personal privacy and good name), Statutory Law 1581 of 2012, its implementing decrees, and all rules that repeal, amend, or supplement the foregoing approach, hereby makes known to the public interest, and to its clients or users, its Personal Data Protection and Processing Policy — hereinafter the POLICY.

A client or user who does not agree with the terms and conditions set out in this document must refrain from using the COMPANY's web platform, because once clients, users, or collaborators visit or use our website — regardless of whether the services offered by it are acquired or not — they accept and authorize the processing and the purposes contemplated in this Policy.

In light of the foregoing, the COMPANY, with respect to the personal data under its custody in its capacity as data controller and/or data processor, seeks in particular to ensure that the personal data provided to it is handled in accordance with the constitutional guidelines regarding the right to privacy and the principles of legality, freedom, veracity, transparency, security, and confidentiality, among others.

2. IDENTIFICATION OF THE DATA CONTROLLER AND DATA PROCESSOR

COMPANY NAME (RAZÓN SOCIAL): Iniciativa Legal S.A.S
NIT: 901.661.657-2
DOMICILE: Medellín
ADDRESS: Carrera 43a #1 Sur – 100. Edificio Torre Sudameris, Oficina 1304
TELEPHONE: 3187448297
EMAIL: info.iniciativalegal@gmail.com
WEBSITE: https://iniciativalegal.com

3. DEFINITIONS AND CONCEPTS

a. Authorization: Prior, express, and informed consent given by the data subject of the information and personal data, which may be granted to the COMPANY so that it may carry out the purposes established in its Policy. This authorization is implicit for clients or users who use the COMPANY's web platform.
b. Database: An organized set of personal data that will be subject to processing by the COMPANY in accordance with the provisions of the Policy.
c. Sensitive data: Data that affects the privacy of data subjects or whose misuse may give rise to their discrimination, such as data revealing racial or ethnic origin, political affiliation, religious or philosophical beliefs, membership in trade unions or social or human-rights organizations, or data that promotes the interests of any political party or that guarantees the rights and guarantees of opposition political parties, as well as data concerning health, sexual and reproductive life, and biometric data.
d. Cookies: Small data stored in text files or in a device of general use that are stored on the computer or other device when websites are loaded in a browser. These ensure a consistent and efficient experience for website visitors, and perform essential functions, such as allowing users to register and remain logged in and facilitating the loading of information. Cookies typically store information of a technical nature, personal preferences, content personalization, usage statistics, among others.
e. Personal data: Any information linked to, or that may be associated with, one or more identified or identifiable natural persons.
f. Public data: Data that is neither semi-private, private, nor sensitive. Public data is considered to include, among others, data relating to a person's marital status, profession or occupation, and status as a merchant or public servant. By their nature, public data may be contained in, among others, public records, public documents, official gazettes and bulletins, and final, duly executed court judgments that are not subject to restricted access.
g. Data processor: A natural or legal person, whether public or private, that, by itself or jointly with others, processes personal data on behalf of the COMPANY, which is the data controller.
h. Habeas data: A fundamental right that grants the data subject the power to require personal data administrators to provide access to, inclusion, exclusion, correction, addition, updating, and certification of data, as well as limitations on the possibilities of disclosure, publication, or transfer thereof, in accordance with the principles governing the process of administering personal data databases.
i. Data controller: A natural or legal person, whether public or private, that, by itself or jointly with others, decides on the databases and/or the processing of the data. Under this Policy, the data controller is the COMPANY.
j. Data subject: A natural person whose personal data is processed in the databases handled and administered by the COMPANY.
k. Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation, or deletion, carried out by the COMPANY always in light of this Policy.
l. Transfer: The relationship between the data controller and/or data processor of personal data, located in Colombia, and a recipient that is in turn responsible for processing different from that of the COMPANY and that is located within or outside the country.
m. Transmission: A form of processing of information and personal data that involves the communication thereof, internally within the COMPANY or with external third parties, within or outside the territory of the Republic of Colombia, when its purpose is the carrying out of processing by the processor in the name and on behalf of the controller, in order to fulfill the latter's purposes; however, every transmission must be carried out with the authorization of the controller.

4. GOVERNING PRINCIPLES

The protection of personal data shall be governed by the following fundamental principles or rules, set forth in Law 1581 of 2012:

a. Principle of legality: This is a regulated activity that must be subject to the provisions set forth therein, in Decree 1074 of 2016, and the other rules mentioned in the legal framework, as well as those that subsequently develop, amend, or supplement them.
b. Principle of purpose: Processing must respond to one or more legitimate purposes in accordance with the Constitution, the Law, and case law, which must be communicated to the data subject.
c. Principle of freedom: Processing may only be carried out with the prior, express, and informed consent of the data subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate dispensing with express consent.
d. Principle of veracity or quality: Information subject to processing must be truthful, complete, accurate, up to date, verifiable, and comprehensible. The processing of partial, incomplete, fragmented, or misleading data is prohibited.
e. Principle of transparency: In the processing of personal data, the COMPANY must guarantee the data subject's right to obtain, at any time and without restrictions, information regarding the existence of data belonging to or identifying them.
f. Principle of restricted access and circulation: Processing is subject to the limits arising from the nature of personal data and from the provisions of the Law, case law, and the Constitution. Accordingly, processing may only be carried out by persons authorized by the data subject and/or by persons provided for in the Law. Personal data, other than public data, may not be made available on the Internet or other means of mass disclosure or communication, unless access is technically controllable so as to provide restricted knowledge only to data subjects or third parties authorized in accordance with the law, case law, or the Constitution, or that fall within the scope of the consent granted by the data subject.
g. Principle of security: Information subject to processing by the COMPANY must be handled with the technical, human, and administrative measures necessary to provide security for the records, preventing their adulteration, loss, unauthorized or fraudulent consultation, use, or access.
h. Principle of confidentiality: All persons involved in the processing of personal data that is not public in nature are required to guarantee the confidentiality of the information, even after their relationship with any of the tasks comprised within the processing has ended, and may only supply or communicate personal data when this corresponds to the performance of activities authorized under the Law and on the terms thereof.

5. SCOPE OF APPLICATION OF THE POLICY WITH RESPECT TO THE COMPANY

This Policy shall apply to the processing that all officers, collaborators, employees, and partners of the COMPANY must give to the information and personal data administered by it. However, branches, subsidiaries, and third parties who, by virtue of the purposes of the databases, are given access to them, must also proceed in accordance with the parameters established in this Policy.

All of the foregoing is without prejudice to the legal and regulatory provisions that generally govern these procedures in Colombia.

6. PURPOSES OF THE PROCESSING OF INFORMATION AND PERSONAL DATA

This Policy shall apply to the processing that all users, collaborators, clients, suppliers, employees, service providers, persons with whom commercial contracts other than the provision of services are entered into, and others who become associated with and authorize the processing of personal data by the COMPANY, through the storage, collection, use, exchange, updating, and processing of information and personal data supplied, in accordance with Colombian legal guidelines and with the corporate purpose of the COMPANY, for the following purposes:

a. To identify the preferences of the client, user, or supplier regarding the products and/or services offered by the COMPANY, in order to identify preference patterns and manage commercial information.
b. To manage the collection of financial obligations acquired by the client with the COMPANY.
c. To design and offer personalized loyalty programs with legal support for the COMPANY's clients.
d. To register as a client of the COMPANY and update their data in the COMPANY's information systems.
e. To conduct research on the data subject in the various national and international lists and databases.
f. To manage the collection of financial obligations acquired by the client with the COMPANY.
g. Compliance with and monitoring of contractual and/or legal obligations related to the corporate purpose of the COMPANY.
h. To transfer data subjects' personal data to funds and similar entities, and to employees who engage or provide services to the COMPANY's employees.
i. To store and process all information provided by data subjects in one or more databases, in the format it deems most convenient.
j. To collect data for the fulfillment of the duties that correspond to the COMPANY as data controller of the information and personal data.
k. To consult, at any time, in databases managed by credit bureaus or other operators, all information relevant to ascertaining the data subject's performance as a debtor, their payment capacity, the feasibility of entering into or maintaining a contractual relationship, or any other purpose derived from knowledge of such information.
l. And all such activities as the COMPANY deems convenient for the development of its corporate purpose.

If necessary, the COMPANY will request personal data for purposes outside those described, provided that prior authorization is obtained from clients, users, and collaborators.

The foregoing list is presented for illustrative purposes only, since, if necessary, the COMPANY may operate with different databases.

The data subject will be asked to provide their full name or corporate name, as applicable, identification, address, contact telephone number, email address, and address.

7. RIGHTS OF DATA SUBJECTS

7.1. Individual rights of data subjects

In accordance with Colombian legislation, particularly the guarantees enshrined in the Political Constitution, data subjects may exercise the following rights:

a. To know, update, and rectify their personal data before data controllers or data processors. This right may be exercised, among other cases, with respect to partial, inaccurate, incomplete, fragmented, or misleading data, or data whose processing is expressly prohibited or has not been authorized.
b. To request proof of the authorization granted to the data controller, except where it is expressly exempted as a requirement for processing, in accordance with the provisions of Article 10 of Law 1581 of 2012.
c. To be informed by the data controller or the data processor, upon request, of the use that has been given to their personal data.
d. To file complaints with the Superintendence of Industry and Commerce for infringements of the provisions of Law 1581 of 2012 and the other rules that amend, add to, or complement it.
e. To revoke the authorization and/or request the deletion of the data when, in the processing, the constitutional and legal principles, rights, and guarantees are not respected. Revocation and/or deletion shall proceed when the Superintendence of Industry and Commerce has determined that, in the processing, the controller or processor has engaged in conduct contrary to this law and to the Constitution.
f. To access, free of charge, their personal data that has been processed.

7.2. Power to exercise the rights of data subjects

The rights of data subjects with respect to personal data and information may be exercised by the following persons:

By the data subject concerned, who must sufficiently prove their identity through the various means made available by the controller.
By their successors in interest, who must prove such status.
By the data subject's legal representative and/or attorney-in-fact, upon prior proof of the representation or power of attorney.
By stipulation in favor of, or on behalf of, another.

7.3. Where the data subject is a minor

If the data subject is a minor, their rights may be exercised only by the persons who, in accordance with the law, are authorized to represent them.

8. DUTIES OF THE DATA CONTROLLER

The COMPANY, in its capacity as data controller of personal data, shall comply with the following:

a. To guarantee the data subject, at all times, the full and effective exercise of the right of habeas data.
b. To request and retain, under the conditions provided for in this law, a copy of the respective authorization granted by the data subject.
c. To duly inform the data subject of the purpose of the collection and of the rights afforded to them by virtue of the authorization granted.
d. To retain the information under the security conditions necessary to prevent its adulteration, loss, unauthorized or fraudulent consultation, use, or access.
e. To ensure that the information supplied to the data processor is truthful, complete, accurate, up to date, verifiable, and comprehensible.
f. To update the information, promptly notifying the data processor of any changes to the data previously supplied to it, and to adopt such other measures as necessary to keep the information supplied to it up to date.
g. To rectify the information when it is incorrect and communicate the relevant matters to the data processor.
h. To supply the data processor, as applicable, only with data whose processing has been previously authorized in accordance with the provisions of this law.
i. To require the data processor, at all times, to respect the security and privacy conditions of the data subject's information.
j. To process the inquiries and claims made under the terms set forth in this law.
k. To adopt an internal manual of policies and procedures to ensure proper compliance with this law and, in particular, to handle inquiries and claims.
l. To inform the data processor when certain information is under dispute by the data subject, once the claim has been filed and the corresponding proceeding has not yet concluded.
m. To inform, at the data subject's request, of the use given to their data.
n. To inform the data protection authority when breaches of security codes occur and there are risks in the administration of data subjects' information.
o. To comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.

9. AUTHORIZATION, PROCESSING, AND STORAGE OF PERSONAL DATA

The COMPANY states that all collection, retention, use, handling, updating, correction, deletion, and, in general, any activity through which it is intended to obtain and/or process personal data and information belonging to third parties, must be carried out with the prior, express, and free authorization of the respective data subjects, which shall be collected by any electronic, physical, or verbal means.

In general, the COMPANY will collect, store, use, circulate, transmit, and transfer the personal data it processes. This information may be used solely by the COMPANY, its employees, consultants, advisors, affiliates of the corporate group, and commercial and strategic partners expressly authorized by the COMPANY that require access to this information. In any case, the COMPANY, upon the data subject's request, will provide them with complete information on the authorized persons and/or third parties that carry out the processing of their personal data.

Likewise, by means of the authorization for the retention, administration, collection, and processing of the information and personal data, the data subject declares that such data and information are truthful, complete, accurate, up to date, verifiable, comprehensible, and correspond to the facts in effect at the time they are provided.

10. PROCESSING OF SENSITIVE DATA

The COMPANY will request express, written authorization from the data subject of the sensitive data so that they may authorize its processing, following verifiable communication of the following determinations:

That they are not obliged to authorize the processing of the sensitive data, provided it is not their wish to do so.
That responding to any question or inquiry that the COMPANY raises in relation to their sensitive personal data is optional.
Which of their sensitive data will be processed by the COMPANY and for what purpose.
That all information relating to sensitive data provided to collaborators and staff will be protected under the professional secrecy that companies must observe under the terms of the law, and that adequate and suitable measures will be used for its protection.

11. PROCEDURE FOR RESOLVING INQUIRIES AND CLAIMS

11.1. Content of inquiries and claims

All inquiries, requests, or claims must contain, at a minimum, the following information: the full name of the data subject and their identification number; the full name of the requester, their identification number, and the capacity in which they are acting; a clear and concise statement of the request to know and access the information subject to processing; and, finally, contact details for notification purposes (address, telephone, mobile phone, and email address).

11.2. Channels for submitting inquiries and claims

In accordance with national regulations, the channels enabled for submitting inquiries and claims to the COMPANY are the following digital channels: www.iniciativalegal.com and info.iniciativalegal@gmail.com, as well as by physical correspondence at Carrera 43a #1 Sur – 100, Edificio Torre Sudameris, Oficina 1304, Medellín.

11.3. Inquiries

The COMPANY shall have a maximum term of 10 business days, counted from the day following its filing, to respond to inquiries submitted by data subjects or their successors in interest through the digital or physical means indicated above.

The content of the inquiry shall concern obtaining knowledge of the personal information that is subject to processing by the COMPANY.

When it is not possible to respond within that term, the interested party will be informed of the reasons for the delay and a date will be set for an effective response, which shall not exceed a term of 5 business days following the expiration of the first term.

11.4. Claims

The COMPANY shall have a term of 15 business days, counted from the day following its filing, to respond to all requests relating to a claim for correction, updating, or deletion, or when the alleged breach of any of the duties set out in this Policy or in national regulations relating to data processing is noted. This claim may be filed by the data subject or their successor in interest.

However, if it is not possible to address the claim or request within the stated term, the COMPANY will communicate the reasons why it is not possible to address it and, accordingly, will respond within an additional term of 8 business days following the expiration of the first term.

When the claim filed is incomplete, the interested party will be required, within the 5 business days following its receipt, to remedy the deficiencies. If 2 months elapse from the date of the request without the requester providing the required information, it will be understood that they have withdrawn the claim.

If the party receiving the claim is not the competent authority to resolve it, it will refer the matter to the appropriate party within a maximum term of 2 business days and will inform the interested party of the situation.

11.5. Requirement of procedural prerequisite

The data subject or successor in interest may only file a complaint with the Superintendence of Industry and Commerce once they have exhausted the inquiry or claim procedure before the COMPANY, in accordance with the foregoing.

11.6. Deletion of information

The data subject's right to file claims does not automatically entail receiving a response in accordance with what was requested, since the COMPANY may deny what is requested in the claim, particularly with respect to deletion requests, when:

The data subject has a legal or contractual duty to remain in the Database.
The contract governing the data subject's relationship with the COMPANY is in force.
The deletion of data would hinder judicial or administrative proceedings, the investigation and prosecution of crimes, or the enforcement of administrative sanctions.
The data are necessary to protect the data subject's legally protected interests.
The purpose is to carry out an action in the public interest, or to fulfill an obligation legally acquired by the data subject.

12. TRANSFER AND TRANSMISSION

The COMPANY transfers data of its clients, users, and collaborators to its various national and international partners, in the course of its business operations, legal advisory services, and the purposes described in Section Six of this Policy.

13. COOKIES

13.1. Content from other websites

Articles on this site may include embedded content, such as videos, images, articles, and the like, from other websites, which behaves in exactly the same way as if the visitor had visited the other website.

13.2. Disabling cookies

The user may disable cookies in their browser's preferences section and change the cookie settings on their computer.

In order to obtain general information on how to manage cookies and how to disable them, the user may visit www.allaboutcookies.org.

14. TERM OF VALIDITY

This Policy is effective as of its publication and for an indefinite period.

The COMPANY reserves the right to make modifications, adjustments, and/or updates to the content of its Policy in any of its sections, including the purposes or terms of the processing of the data covered by this policy. However, such modifications will be notified to all data subjects whose data is being processed at that time.

Call Now Button