Personal Data Processing Policy
1. Legal framework
This Personal Data Processing Policy of ALDEAMO, which includes the legal entities AXESNET S.A.S., identified with NIT 830.015.727-2, domiciled in Bogotá, Colombia, and Estrategias Móviles Ecuador Estramovec S.A., identified with RUC 1792318440001, domiciled in Guayaquil, Ecuador, is prepared in accordance with the legal provisions applicable in each country.
In Colombia, it is based on the Political Constitution, Law 1581 of 2012, its implementing decrees and other complementary rules that regulate the appropriate processing of personal data. In Ecuador, it is governed by the Constitution of the Republic, the Organic Law on Personal Data Protection (LOPDP) and its Regulation.
This Policy establishes the guidelines and procedures for the collection, storage, use, circulation, rectification, deletion and other activities related to the processing of personal data under the highest standards of security and confidentiality, in compliance with the regulations in force in both countries, guaranteeing the protection of data subjects' rights.
2. Purpose
The purpose of this Personal Data Processing Policy is to unify ALDEAMO's commitments, including the legal entities AXESNET S.A.S. and Estrategias Móviles Ecuador Estramovec S.A., regarding the protection and security of personal data, acting as a statement of intent that sets out the general lines of prevention and control necessary to ensure compliance with the regulations applicable in Colombia and Ecuador. This Policy captures the control objectives to be achieved generically and is implemented through internal rules and procedures designed to ensure the confidentiality, integrity and availability of personal data, reaffirming ALDEAMO's commitment to respecting and protecting the rights of the subjects of that data.
3. Scope
This Policy applies to all activities related to the processing of personal data carried out by ALDEAMO, including its legal entities AXESNET S.A.S. in Colombia and Estrategias Móviles Ecuador Estramovec S.A. in Ecuador, as well as all their branches, subsidiaries and related companies that exist or may come to exist in both countries. This Policy applies specifically to:
- Related entities and personnel: all natural or legal persons who provide services directly or indirectly for ALDEAMO, regardless of the nature of the legal relationship, and who are involved in any operation related to the processing of personal data, whether by automated or manual means. This includes anyone who, by virtue of their functions, has or may have access to facilities, departments, information systems, databases or devices where personal data is processed or stored.
- Information systems and resources: all information systems and technological resources used to access, process, store or transmit personal data, ensuring that the security measures established in this Policy are applied.
- Training and information commitment: ALDEAMO undertakes to train and inform all persons within its scope of application about the provisions of this Policy, ensuring their compliance and promoting good practices.
This scope covers all processes and activities involving the collection, storage, use, circulation, rectification, deletion or any other type of processing of personal data, under the responsibility and custody of ALDEAMO, guaranteeing the protection of data subjects' rights in accordance with the laws applicable in each jurisdiction.
4. Definitions
- Authorization: prior, express and informed consent of the data subject to carry out the processing of their personal data, granted under the terms established by Law 1581 of 2012 in Colombia and the LOPDP in Ecuador.
- Privacy notice: a physical, electronic or any-other-format document, generated by the controller, made available to the data subject to inform them of the existence of this policy, the purpose of the processing and the rights available to them.
- Database: an organized set of personal data, administered or controlled by the controller or processor, capable of being processed in accordance with the regulations in force in Colombia and Ecuador.
- Legal bases: the conditions that make a personal-data processing activity legitimate and lawful, under Law 1581 of 2012 and the LOPDP, including the data subject's authorization or compliance with a legal obligation.
- Personal data: any information that identifies or makes a natural person identifiable. This includes, by way of example but not limitation, financial, credit, commercial, sensitive, technical, administrative, private, semi-private or public data, stored on physical, digital or electronic media, such as documents, photos, recordings, biometric data or videos.
- Public data: information classified as public by law, the Constitution or its nature (marital status, profession, occupation, status as a merchant or public servant, and that available without restriction in registers, documents, gazettes or official bulletins). This distinction applies only to processing carried out in compliance with Colombian regulations.
- Private data: data that, by its intimate or reserved nature, is only relevant to the data subject. This distinction applies only to Colombian regulations.
- Semi-private data: data that is not of an intimate, reserved or public nature, and whose knowledge or disclosure may be of interest not only to its subject but also to a certain sector or group of people. This distinction applies only to Colombian regulations.
- Sensitive data: data that affects the data subject's privacy or whose improper use may lead to discrimination: racial or ethnic origin, political orientation, religious or philosophical convictions, membership of unions or social or human-rights organizations, and data relating to health, sex life and/or biometric data.
- Data processor: a natural or legal person, public or private, public authority or other body that, by itself or in association with others, processes personal data on behalf of the controller.
- Personal data security incident: any event aimed at breaching security codes, or the alteration, loss, consultation, use, or unauthorized or fraudulent access to personal data.
- Information Security Committee: made up of the CEO, the Engineering Manager and the IMS Coordinator, to establish, coordinate and control the security measures to be applied in relation to personal data.
- Controller: a natural or legal person, public or private, public authority or other body that, by itself or in association with others, decides on the purpose and processing of the data.
- Data subject: the natural person whose personal data is processed.
- Processing: any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
- Transfer: the operation of sending the information to another recipient, who in turn becomes the controller of that data.
- Transmission: processing that involves the communication of personal data to a third party, within or outside the national territory, under the direction and supervision of the controller. Applicable to activities carried out by AXESNET S.A.S. under Colombian regulations.
- User: any person linked to AXESNET S.A.S. or Estrategias Móviles Ecuador Estramovec S.A., including employees, directors, representatives or advisors, who in the exercise of their functions participate in activities related to the processing of personal data.
5. Principles applicable to the processing of personal data
The processing of personal data carried out by ALDEAMO, including AXESNET S.A.S. in Colombia and Estrategias Móviles Ecuador Estramovec S.A. in Ecuador, will be governed by the following principles:
- Legality: the processing of personal data is a regulated activity that must comply with the provisions of the Constitution and the applicable laws of Colombia (Law 1581 of 2012) and Ecuador (LOPDP).
- Juridicity: all processing must be carried out in compliance with the principles, rights and obligations enshrined in the respective constitutions, local laws, regulations and applicable international rules.
- Fairness: collection and processing are carried out lawfully, respecting the data subject's rights and complying with the specific purposes informed beforehand.
- Purpose: processing must serve a legitimate purpose, informed to the data subject and in line with the regulatory frameworks of Colombia and Ecuador.
- Freedom: processing may only be carried out with the prior, express and informed consent of the data subject, except in cases where the law waives such consent.
- Relevance and minimization: only the personal data necessary and relevant to the informed purposes is collected and processed, avoiding excessive collection.
- Proportionality: personal data must not be available in mass-dissemination media, unless access is technically controlled and limited to the data subjects or authorized third parties.
- Accuracy or quality: the information must be truthful, complete, accurate, up to date and understandable. Processing of partial, incomplete or misleading data is prohibited.
- Transparency: the data subject's right to obtain information about the existence of their data and about the processing carried out by ALDEAMO at any time is guaranteed.
- Restricted access and circulation: personal data may only be accessible to authorized persons or data subjects.
- Security: data is protected through the technical, human and administrative measures necessary to prevent its alteration, loss, consultation, use, or unauthorized or fraudulent access.
- Confidentiality: everyone involved in the processing has the obligation to guarantee the confidentiality of the information, even after their relationship with ALDEAMO ends.
- Retention: personal data will be kept only for the time necessary to fulfill the purposes for which it was collected.
- Quality and accuracy: ALDEAMO guarantees that the data processed is complete, accurate and up to date.
- Proactive and demonstrated accountability: ALDEAMO has verification mechanisms to demonstrate the appropriate management of personal data processing.
6. Processing of personal data and purposes at Aldeamo
ALDEAMO carries out the processing of personal data in fulfillment of its corporate purpose, its commercial activities and the obligations established by the regulations applicable in both countries. Processing includes the activities of collection, storage, use, circulation, deletion and other necessary operations, carried out with personal information voluntarily provided by data subjects, aimed at fulfilling purposes for the client, prospective client, employee and human-resources, and supplier databases — the same ones described in the Privacy Notice.
In relation to its clients, Aldeamo also holds the status of data processor: for the execution of the services derived from the service, the client (controller) may make available to Aldeamo identification, personal, academic, professional, economic-financial, commercial and IP-address data of its own end users.
7. Rights of the data subjects whose data is processed by Aldeamo
ALDEAMO guarantees the data subjects whose personal data is stored in its databases the exercise of the following rights, in compliance with Law 1581 of 2012 in Colombia, the LOPDP in Ecuador and other applicable regulations:
- Right of access: access, free of charge, their personal data to know its existence in the databases, the purposes of the processing, the activities carried out and with whom it is shared. The controller must resolve the request within fifteen (15) days.
- Right to update, rectify and delete: modify data to keep it up to date, correct inaccurate data, or delete it when it is not necessary, its purpose has been fulfilled, the retention period has expired, consent has been revoked, or it affects fundamental rights.
- Right to erasure: when processing is unlawful, the data is no longer necessary, consent is revoked, there is a legal obligation, or the legal retention periods have expired.
- Right to object: when the processing is not necessary or affects fundamental rights, consent is not necessary due to a legitimate interest, it is not related to public information, or it is related to direct marketing under Ecuadorian regulations.
- Right to portability: receive their personal data in a compatible, structured, updated, common, interoperable and machine-readable format, or request its transfer to another controller.
- Right to suspension of processing: when the accuracy of the data is contested, the processing is unlawful, the data is no longer necessary for ALDEAMO but is for the data subject, or there is an objection while the legitimacy of the grounds is verified.
- Right not to be subject to automated decisions: including profiling — to request explanations, submit observations, challenge the decision and request human review, except when the decision is necessary for a contract, is authorized by regulation or court order, is based on explicit consent, or does not entail serious impacts.
- Right to request proof of the authorization granted for the processing of their data, except when the law exempts such authorization.
- Right to file complaints or claims: in Colombia with the Superintendence of Industry and Commerce, and in Ecuador with the Superintendence for the Protection of Personal Data.
- Right to require compliance with the orders of the competent authority.
- Rights of minors: exercised by those legally empowered to represent them (parents, guardians or curators), with special and priority treatment always considering the best interests of the minor.
12. Exceptions to the exercise of data subjects' rights
The exercise of the rights of rectification, update, deletion, objection, suspension and portability is subject to exceptions. A request will not be processed when: the applicant is not the data subject or their representative is not duly accredited; the data is necessary to comply with a legal or contractual obligation or a court order; it is necessary for the formulation, exercise or defense of claims; it may cause harm to the rights of third parties; it may hinder ongoing judicial or administrative proceedings; it is necessary to exercise freedom of expression and opinion; it is necessary to protect the vital interest of the data subject or another person; there is a public interest; or it is necessary for the archiving of information that constitutes State assets or scientific, historical or statistical research.
13. Aldeamo's obligations and duties regarding data protection
ALDEAMO will comply with the registration and update of its databases with the National Database Registry administered by the Superintendence of Industry and Commerce, in accordance with Decree 090 of 2018, updating it when substantial changes occur in the purposes, in the handling of claims or in the structure of the databases.
13.1. Obligations as data controller
ALDEAMO acknowledges that personal data is the property of the persons to whom it refers, and only they can decide about it. Consequently, it undertakes to:
- Guarantee the data subject, at all times, the full and effective exercise of the right to personal data protection.
- Request and keep a copy of the respective authorization granted by the data subject where applicable.
- Duly inform the data subject about the purpose of the collection and the rights available to them.
- Keep the information under the security conditions necessary to prevent its alteration, loss, consultation, use, or unauthorized or fraudulent access.
- Ensure that the information provided to the processor is truthful, complete, accurate, up to date, verifiable and understandable.
- Update and rectify the information when it is incorrect, communicating what is relevant to the processor.
- Provide the processor only with data whose processing is previously legitimized.
- Require the processor to respect the security and privacy conditions of the data subject's information.
- Process inquiries and claims under the terms indicated in the applicable regulations.
- Adopt policies and procedures to ensure appropriate compliance with the regulations.
- Inform the processor when certain information is being disputed by the data subject.
- Inform the competent authority about security breaches or risks in the administration of personal data.
- Comply with the instructions and requirements issued by the data protection authorities in both countries.
13.2. Obligations as data processor
In accordance with Article 18 of Law 1581 of 2012 in Colombia and the LOPDP in Ecuador, processors must: guarantee the data subject the full exercise of their rights; keep the information under adequate security conditions; carry out the update, rectification or deletion of the data in a timely manner; update the information reported by controllers within the five (5) business days following its receipt; process the inquiries and claims made by data subjects; adopt compliance policies and procedures; record in the database the legend "claim pending" or "information in judicial dispute" where applicable; refrain from circulating disputed information whose blocking has been ordered by the competent authority; allow access to the information only to authorized persons; inform the controller about security breaches; and comply with the instructions of the data protection authorities.
14. Legal bases
The processing of personal data by ALDEAMO will be carried out exclusively when it is supported by one of the following bases: the data subject's consent; compliance with a legal obligation; a court order; the execution of pre-contractual measures or the performance of contractual obligations; the protection of vital interests; the processing of publicly accessible personal data; or the satisfaction of a legitimate interest of ALDEAMO or of a third party, provided it does not override the fundamental rights and freedoms of the data subject.
14.1. Requesting authorization from the data subject
The processing of personal data in Colombia requires the free, prior, express and informed consent of the data subject. Authorization may be granted in writing, orally, through automated or digital technical means, or through unequivocal conduct of the data subject. In no case will silence be interpreted as unequivocal authorizing conduct. ALDEAMO will keep records that make it possible to demonstrate when and how the authorization was obtained. The data subject may revoke their consent at any time by sending a request to pqrs@aldeamo.com, without this affecting the lawfulness of the processing carried out prior to the revocation. In Ecuador, ALDEAMO may legitimize processing on the basis of consent under the same procedure.
15. Aldeamo Privacy Notice
The Privacy Notice is available on ALDEAMO's website for consultation by data subjects and competent authorities. ALDEAMO undertakes to keep it up to date and to notify any substantial change that may affect data subjects' rights.
16. Retention of personal data
ALDEAMO may only collect, store, use or circulate personal data for the reasonable time necessary to fulfill the purposes that justified its processing, taking into account administrative, accounting, tax, legal and historical aspects. Once the purpose has been fulfilled, and unless otherwise provided by law, ALDEAMO will proceed to delete it securely, unless it is necessary to comply with a legal obligation in force or with contractual obligations between ALDEAMO and the data subject.
17. Responsible area and procedure for exercising data subjects' rights
ALDEAMO has defined an Information Security Committee as the body responsible for ensuring compliance with personal data protection policies, in charge of the control, monitoring and coordination of the security measures adopted. Its functions include coordinating technical, administrative and organizational security measures; handling or delegating the handling of petitions, complaints and claims (via pqr@aldeamo.com); monitoring and assessing processing risks; updating policies in line with regulatory or technological changes; carrying out periodic reviews; and reporting any security incident to the competent authorities.
Users who have access to personal data must ensure its appropriate and secure use, strictly comply with internal rules, report any incident or suspected breach to the Information Security Committee, and maintain confidentiality even after their relationship with ALDEAMO ends. Non-compliance will give rise to disciplinary sanctions — from a verbal or written warning to dismissal of the worker — without prejudice to the civil and/or criminal actions that ALDEAMO may take.
To file a request, ALDEAMO asks for: full name and identification number; contact details; means to receive a reply; and the reasons giving rise to the claim, with a brief description of the right to be exercised. If the request is incomplete, the data subject will be required within the following five (5) days to correct it, having ten (10) days to respond; after two (2) months (Colombia) or ten (10) days (Ecuador) with no response, it will be deemed withdrawn. The maximum term to address a request will be fifteen (15) business days.
18. Security measures
ALDEAMO will adopt the technical, human and administrative measures necessary to secure records, data messages, electronic documents and other containers of personal information, preventing their alteration, loss, consultation, use, or unauthorized or fraudulent access. In the event of incidents that compromise the security or confidentiality of the data, ALDEAMO will notify the Superintendence of Industry and Commerce within the fifteen (15) business days following its detection, including a description of the incident, the type of data compromised, the measures adopted and possible impacts, and will inform the affected data subject when the incident may affect the exercise of their rights.
19. Principle of demonstrated accountability
ALDEAMO ensures that all persons involved in the processing of personal data work under common data-protection objectives, through the maintenance of up-to-date and verifiable records, periodic compliance controls and audits, and a continuous training and awareness plan aimed at employees, contractors and other interested parties.
20. International data transfers
International transfers carried out by ALDEAMO involve the flow of personal data from Colombian or Ecuadorian territory to other countries. ALDEAMO will endeavor to carry out these transfers to countries that guarantee an adequate level of personal data protection, and failing that, will guarantee the implementation of security measures equivalent to or higher than those required by the applicable local regulations.
21. Recipients declared to have an adequate level of protection by the Superintendence of Industry and Commerce
Data recipients located in a country declared to have an "adequate level of protection" by the Superintendence of Industry and Commerce do not require specific authorization. As of this date, the countries and territories declared adequate include: Germany, Austria, Belgium, Bulgaria, Cyprus, Costa Rica, Croatia, Denmark, Slovakia, Slovenia, Estonia, Spain, United States of America, Finland, France, Greece, Hungary, Ireland, Iceland, Italy, Latvia, Lithuania, Luxembourg, Malta, Mexico, Norway, the Netherlands, Peru, Poland, Portugal, the United Kingdom, the Czech Republic, the Republic of Korea, Romania, Serbia, Sweden, and the countries declared to have an adequate level of protection by the European Commission. The Superintendence exercises its regulatory power at any time to review this list.
22. Monitoring and auditing
ALDEAMO implements a comprehensive monitoring and auditing program to ensure compliance with the measures, rules and procedures of its internal personal data protection policies, with the aim of detecting and correcting any anomaly that may compromise the legality, purpose, freedom, accuracy, transparency, security and confidentiality of the data. The annual program includes the setting of objectives, planning and execution, periodic controls, and a corrective action plan based on the findings.
23. Refusal to provide personal data
Should the data subject refuse to provide their personal data, ALDEAMO will not be able to fulfill the processing purposes previously indicated. This refusal may limit or make it impossible to provide services, comply with contractual obligations, or carry out legal or administrative actions that depend on such information. ALDEAMO will ensure that the data subject is informed of the consequences of their refusal before requesting the personal data.
24. Erroneous or inaccurate data
It is the data subject's sole responsibility to provide complete, accurate, truthful and up-to-date personal data. ALDEAMO will not be responsible for the consequences arising from the provision of incorrect or outdated information, but will ensure that the data subject has the necessary means to rectify, update or complete their data at any time.
25. Effective date
This Personal Data Policy of ALDEAMO was created on February 25, 2022, reviewed and updated in May 2025, and takes effect as of June 10, 2025. Any change will be communicated in a timely manner by ALDEAMO through email, the official website, the mobile app, and other computer means implemented by the organization.