Data protection policy
0. Internal Data Management Policy of OL Software S.A.S.
This document contains the internal policies established by OLSOFTWARE S.A.S. to comply with Law 1266 of 2008, Law 1581 of 2012, and all other regulatory provisions governing Habeas Data and personal data protection.
Furthermore, these policies promote the values of respect, legal compliance, privacy, confidentiality, availability, and the proper handling of the personal information utilized by the company to achieve its corporate and business objectives.
These policies aim to guarantee that the natural and legal persons interacting with OLSOFTWARE S.A.S. are aware of the purposes, conditions of use, and processing applied to their personal data during the execution of our corporate purpose. Additionally, they ensure that these individuals are informed about who the Data Controllers and Processors are, and that they have access to the necessary mechanisms to exercise their right to decide and control how their personal information is used and directed.
Additionally, these policies encompass fundamental regulatory aspects, appendices outlining the specific purposes for which personal information is collected by the company, procedural guidelines to obtain authorization from the Data Subject, and the guarantees and mechanisms required to secure the fundamental rights protected by the aforementioned provisions.
1. Identification of the Data Controller
OLSOFTWARE S.A.S., a simplified joint-stock company (Sociedad por Acciones Simplificada), bearing Tax ID (NIT) 900.420.501-5, legally incorporated via private document on March 11, 2011, and registered with the Cali Chamber of Commerce on March 14, 2011, under No. 2930 of Book IX, as evidenced in the Certificate of Existence and Legal Representation issued by the Cali Chamber of Commerce.
Corporate Domicile: Cali, Colombia
Email Address: habeasdata@olsoftware.com
Phone Numbers: +57 (602) 308-7748 / +57 (602) 373-8333
2. Mission
To develop high-impact digital solutions that improve people’s lives and drive progress for our stakeholders.
3. Vision and Higher Purpose
Vision: By 2026, to increase sales to $15 billion COP (approx. $15,000,000 million COP) with an EBITDA margin of 25%, consolidating our position as a medium-sized enterprise.
Higher Purpose: “To drive progress and improve people’s lives through high-impact digital experiences.”
4. Quality Policy
At OLSOFTWARE S.A.S., we are committed to providing our clients with high-impact digital solutions, driven by sustainability criteria and high levels of timeliness, quality, and reliability. We aim to satisfy established requirements and continually improve process performance and our quality management system.
5. Information Security Policy
OLSOFTWARE S.A.S is committed to:
Preserving the confidentiality, integrity, availability, and privacy of the information assets belonging to both our organization and our clients.
Continually improving service delivery efficiency and adhering to organizational guidelines for high-quality service management.
Defining risk acceptance criteria and acceptable risk levels.
Maintaining continuous improvement and target performance across all organizational processes.
6. Definitions
For the purposes of this policy, the following definitions established by current regulations shall apply:
Authorization (Consent): The prior, express, and informed consent of the Data Subject to carry out the processing of personal data.
Database: Any organized set of personal data subject to processing.
Personal Data: Any information linked to or that can be associated with one or more specific or determinable natural persons.
Data Processor: The natural or legal person, public or private, who, individually or jointly with others, processes personal data on behalf of the Data Controller.
Data Controller: The natural or legal person, public or private, who, individually or jointly with others, decides upon the database and/or the processing of the data.
Data Subject: The natural person whose personal data is subject to processing.
Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation, or erasure.
Privacy Notice: Verbal, written, or digital communication generated by OLSOFTWARE S.A.S., addressed to the Data Subject, informing them of the existence of the applicable data processing policies, how to access them, and the intended purposes of the personal data processing.
Public Data: Data relating to civil status, profession or trade, and status as a merchant or public servant; essentially, data that by its nature is not subject to restricted protection.
Sensitive Data: Data that affects the Data Subject’s privacy or whose misuse may lead to discrimination. This includes data revealing racial or ethnic origin, political alignment, religious or philosophical beliefs, trade union membership, social or human rights organization membership, or data promoting political party interests, as well as health, sex life, and biometric data.
Transfer: Data transfer occurs when OLSOFTWARE S.A.S. (located in Cali, Colombia) sends information or personal data to a recipient who acts as a Data Controller and is located inside or outside the country.
Transmission: Data transmission occurs when OLSOFTWARE S.A.S., acting as the Data Controller, communicates the data inside or outside the territory of Colombia to a Data Processor acting on behalf of OLSOFTWARE S.A.S. to carry out specific processing activities.
7. Guiding Principles
For the collection, handling, and erasure of personal data, OLSOFTWARE S.A.S. shall act in accordance with the principles established by law:
Legality: In the processing of personal data, OLSOFTWARE S.A.S. shall strictly adhere to the provisions set forth by law and other regulatory guidelines.
Purpose: OLSOFTWARE S.A.S. shall inform the Data Subject of the purpose of the personal data processing, which must be legitimate under the constitution and the law.
Consent (Freedom): OLSOFTWARE S.A.S. shall only process personal data with the prior, express, and informed consent of the Data Subject, or by legal or judicial mandate.
Accuracy or Quality: Personal data subject to processing must be truthful, complete, accurate, updated, verifiable, and understandable. The processing of partial, incomplete, fractioned, or misleading data is strictly prohibited.
Transparency: OLSOFTWARE S.A.S. guarantees the Data Subject’s right to obtain, at any time and without restriction, information regarding the existence of their data.
Restricted Access and Circulation: The processing of personal data by OLSOFTWARE S.A.S. shall be subject to the limits established by law and the Constitution. Personal data may not be made available on the Internet or other mass media or public communication channels, unless it is public in nature or access to it is technically controllable to restrict viewing to the Data Subject or authorized third parties.
Security: Information processed by OLSOFTWARE S.A.S. shall be protected through necessary technical, human, and administrative measures to secure records and prevent their alteration, loss, unauthorized or fraudulent consultation, use, or access.
Confidentiality: All persons involved in the processing of non-public personal data are obligated to guarantee the confidentiality of the provided information, even after their relationship with any of the processing tasks has ended. OLSOFTWARE S.A.S. shall guarantee the necessary means to maintain this confidentiality.
8. Purposes of Data Processing
This policy is applicable to all processes and procedures carried out within the scope of OLSOFTWARE S.A.S.‘s corporate purpose. The company collects, stores, uses, manages, transfers, transmits, and erases personal data for the following purposes:
8.1. In Relation to the Corporate Nature and Business Management of OLSOFTWARE S.A.S.
Personal data processing is carried out to execute its primary corporate purpose, which consists of: providing, creating, and commercializing all types of technological mechanisms; developing technology-related projects; developing and commercializing software across any known or future platforms and devices; rendering professional services derived from its corporate purpose; providing enterprise computer system maintenance services; conducting training courses and seminars on IT systems and tools; developing electronic devices or hardware; providing technical consulting and advisory services in all IT-related fields; performing research and development on known or future IT platforms; designing, planning, and developing internet, extranet, and intranet projects; executing local and remote communication network interconnection projects; marketing the company’s products and services nationally and internationally; exploiting the company’s intellectual property; and engaging in any other lawful IT-related economic activity both in Colombia and abroad.
8.2. In Relation to the Operations of OLSOFTWARE S.A.S.
8.2.1. Human Talent Management
The processing of personal data of employees/collaborators is carried out under their authorization for onboarding, performance management, communications, offboarding, or termination of contractual relations, and for purposes related to its corporate purpose, specifically for the described legal and contractual ends, as follows:
a) Fulfilling the existing contractual relationship between the Data Subject and OLSOFTWARE S.A.S., including compliance with labor or credit obligations, as well as contractual relationships with third parties.
b) Conducting internal demographic, statistical, and consumer habit studies.
c) Maintaining the security of the people, assets, and facilities of OLSOFTWARE S.A.S., especially regarding data collected through security cameras or documents provided by data subjects to security personnel.
d) Executing the core functions of OLSOFTWARE S.A.S. according to its corporate purpose, fulfilling obligations derived from civil and labor contracts, particularly:
Processing salary payments through banking institutions.
Reporting and paying social security contributions.
Organizing, systematizing, and delivering information requested by state and regulatory entities (such as Ministries, Superintendencies, DIAN, judicial courts, and any others that legally require information about the company, its clients, or its workers).
e) Registering and monitoring activities performed by employees, as well as verifying compliance with regulations, employment contracts, company policies, and Occupational Health and Safety (OHS) guidelines, or similar frameworks.
f) Providing evidence for the defense of the company’s interests before administrative entities and courts where the company or one of its clients is a party.
g) Transferring and/or transmitting employment contracts, résumés, and any information collected during the employment relationship to the company’s legal and judicial representatives so it can be evaluated in its entirety and/or submitted as evidence in any judicial, extrajudicial, or administrative proceeding where deemed necessary by the designated counsel.
h) Analyzing and studying employment contracts, résumés, and related personal data to continually improve the company’s labor policies and employee well-being, including transferring this data to third parties with whom relevant agreements have been signed.
i) Communicating with the Data Subject/employee through communication technologies, computers, mobile phones, emails, or any other media.
j) Executing any other aspect the company deems appropriate or required to fulfill its corporate purpose.
k) Complying with civil, commercial, labor, tax, accounting, contractual, and any other type of legal obligations.
l) Performing breathalyzer tests and/or screenings for psychoactive substances and narcotics at any point during the employment relationship, on days and times unilaterally decided by the company, and using the resulting data to ensure compliance with the employment contract, Internal Work Regulations, Industrial Hygiene and Safety Regulations, OHS systems, and all internal company policies.
m) Collecting biometric data via security recordings, fingerprint readers, and other devices designed for such purposes to enforce internal company policies.
Additionally, personal data may be used to initiate and conduct disciplinary proceedings where applicable, in accordance with the regulations and procedures established by the company. The information collected to process our employees’ personal data has been provided voluntarily and under the declaration of being truthful. Employees acknowledge that their rights as Data Subjects are those set forth in the Political Constitution and the law—specifically the right to access, update, rectify, and erase their personal information, as well as the right to revoke consent given for personal data processing—and that they can exercise these rights through the channels provided by OLSOFTWARE S.A.S. in accordance with this personal data processing policy.
8.2.2. Occupational Health and Safety (OHS) Management
Personal data processing is carried out to implement regulatory requirements and execute Occupational Health and Safety Management programs.
Employee Database: Processing employee personal data is conducted not only for recruitment, affiliation, and onboarding processes, but also to develop training and education programs that enhance workplace performance, prevention, and occupational health. Furthermore, personal data may be used to initiate and carry out disciplinary proceedings according to established company regulations.
8.2.3. Finance & Administration Management
Personal data processing is performed for all activities that define guidelines and policies ensuring the efficient management of the company’s activities and financial, administrative, and labor resources to enable sustainable corporate growth.
8.2.4. Physical & Technological Infrastructure Management
Personal data processing is performed within software development management, which aims to design and develop effective technological solutions tailored to client needs based on industry standards and best practices in software project development.
8.2.5. Commercial Sales & Billing Management
Personal data processing is performed to execute the company’s commercial strategy, which consists of establishing methodologies and conditions to identify market needs, market products and services, maintain the sales revenue levels required for operations and growth, measure client satisfaction, and gather feedback for improvement from the client’s perspective. Personal data of various types is collected during site visits to validate client needs, present the corporate portfolio, or deliver commercial proposals. Additionally, personal data is processed during the formalization of contracts, purchases, client registration in internal company systems, billing, and shipping procedures.
8.2.6. Relationship Management – Commercial – Customer Service & Support
Personal data concerning customer relationships is processed to enable long-term relationships by rendering services with agreed quality and timelines. As a monitoring tool, the company employs specialized personnel in project management and software quality assurance. Additionally, the company conducts customer surveys to identify improvement opportunities and increase satisfaction levels. In addressing customer petitions, complaints, or claims (PQRs), personal data is processed in compliance with the law and the Constitution.
8.2.7. Quality & Process Management
Data processed under this category aims to establish guidelines and activities to document, plan, implement, and guarantee the correct functioning of the Quality Management System and continually improve its effectiveness.
8.2.8. Supplier Relationship Management
Personal data of suppliers and strategic allies is processed to foster mutually beneficial relationships. The company strengthens relationships with suppliers, recognizing their importance to operations, based on respect, transparency, confidentiality, quality, and mutual growth.
8.2.9. Security at OLSoftware S.A.S. Facilities
Processing is carried out for the surveillance and safety of individuals, assets, and facilities of OLSOFTWARE S.A.S.
Video Surveillance: OLSOFTWARE S.A.S. utilizes various video surveillance systems—such as video cameras and alarm systems with remote monitoring provided by the security company Proviser—installed in multiple indoor and outdoor locations at its offices. Data Subjects and third parties are informed of these mechanisms through visible signs displaying video surveillance alerts. No video surveillance device is placed in locations that could compromise the privacy of Data Subjects. Information collected through these means is used for security, asset traceability, and the safety of facilities and individuals present on-site, or as evidence in any internal, judicial, or administrative proceeding, strictly adhering to legal regulations.
8.3. Specific Purposes
For the execution of the procedures supporting the aforementioned processes, OLSOFTWARE S.A.S. establishes specific purposes for personal data processing, which are integrated into this policy document. OLSOFTWARE S.A.S. commits to not processing personal data for purposes other than those described in this policy without obtaining the express and unequivocal authorization of the Data Subject.
9. Data Subject
For the purposes of this policy, Data Subjects are understood to be all individuals registered in OLSOFTWARE S.A.S.’s databases, such as:
SIIGO Accounting System: I) Shareholders; II) Employees/Collaborators; III) Suppliers; IV) Clients; V) Allies.
HubSpot Customer Platform: I) Clients; II) Allies.
GIOBS Personnel Administration Platform: II) Employees/Collaborators.
In the case of minors (children and adolescents), their legal representatives have the power to authorize or deny the processing of their personal data. The processing of such data shall guarantee respect for the prevailing rights of minors, such as privacy and personal information protection.
10. Processing of Personal Data
OLSOFTWARE S.A.S. establishes the following procedures and instruments for the collection, storage, use, circulation, and erasure of information:
10.1. Collection of Personal Data
Without prejudice to the exceptions provided by Law, OLSOFTWARE S.A.S. shall collect personal data only after obtaining authorization from its Data Subject, limiting collection to data that is relevant and adequate for the purpose for which it is gathered or required under current regulations. OLSOFTWARE S.A.S. shall not use deceptive or fraudulent means to collect and process personal data.
The collection process is performed by filling out database opt-in requests, surveys, or forms via telephone, electronic or digital means, in person, or through any other suitable medium, without prejudice to the specific conditions applying to each purpose for which the personal data is collected. From the moment the Data Subject authorizes OLSOFTWARE S.A.S. to collect and process their personal data, it may be used in the execution of all its commercial and labor activities.
10.2. Authorization (Consent)
Without prejudice to the exceptions provided by law, OLSOFTWARE S.A.S. shall process personal data only with the prior, informed, and express authorization of the Data Subject. This authorization shall be written in clear and simple language and must be obtained through any written, physical, digital, or electronic means that can be consulted afterward, at the latest prior to its collection.
When requesting authorization, OLSOFTWARE S.A.S. must clearly and expressly inform the Data Subject of the personal data to be collected, the specific purposes of the processing, their rights as a Data Subject, and the means through which they can exercise them.
The Data Subject has the right to choose not to provide any sensitive personal data requested by OLSOFTWARE S.A.S. concerning, among others, racial or ethnic origin, membership in trade unions, social or human rights organizations, political or religious beliefs, sex life, biometrics, or health data.
OLSOFTWARE S.A.S. shall publish this data policy through digital media and organizational documentation, understanding that all recipient Data Subjects are deemed notified and have granted authorization.
OLSOFTWARE S.A.S. may provide the Data Subject’s personal data to their successors, legal representatives, general attorneys-in-fact, third parties authorized by them or by law, and public or administrative entities executing legal functions or by judicial order.
In all cases, depending on the activity, OLSOFTWARE S.A.S. shall clearly communicate to the Data Subject the mechanisms placed at their disposal to access, update, modify, and erase their data, as well as to revoke the granted authorization.
OLSOFTWARE S.A.S. may continue processing the data contained in its databases for the purposes indicated in this policy, without prejudice to the Data Subject’s right to exercise their right to request the erasure of their data at any time.
10.3. Cases Where Authorization is Not Required
The authorization of the Data Subject is not required for:
(i) Data or databases of a public nature.
(ii) Information required by public administrative authorities in exercise of their legal functions or by court order.
(iii) Cases of medical or sanitary emergency.
(iv) Processing of information authorized by law for historical, statistical, or scientific purposes, among other public-interest purposes.
10.4. Retention and Erasure of Personal Data
OLSOFTWARE S.A.S. shall retain personal data in its physical and digital repositories. Considering the level of risk, it will implement necessary technical, human, and administrative measures to guarantee the privacy, confidentiality, and security of the provided data, preventing its alteration, loss, unauthorized or fraudulent consultation, use, or access by third parties.
In applying the principle of autonomy, OLSOFTWARE S.A.S. reserves the right to maintain and classify the information residing in its databases as confidential.
Furthermore, OLSOFTWARE S.A.S. declares that some of its portals may contain links to third-party websites over which it has no management or control. Therefore, it is not responsible for the content, privacy policies, security, or personal data management established on those sites. It is the responsibility of the Data Subject to review the data protection and processing policies on those respective portals. The OLSOFTWARE S.A.S. website will provide instructions for users or Data Subjects to interact with their data and submit requests for correction, modification, and erasure in accordance with this policy.
10.5. Processing of Personal Data of Children and Adolescents
Data processing shall guarantee respect for the prevailing rights of children and adolescents. The processing of personal data of children and adolescents is prohibited, except for data that is of a public nature.
10.6. Data Collected Prior to the Adoption of This Policy
OLSOFTWARE S.A.S. shall comply with the authorization request notice required by current data protection regulations to continue processing databases created before the entry into force of Law 1581 of 2012, utilizing the channels established under this policy.
11. Rights of the Data Subject
The Data Subject of the personal data, or of the contractual or credit obligation acquired with OLSOFTWARE S.A.S., shall have the right to:
Access, update, and rectify their personal data with OLSOFTWARE S.A.S. through the channels established in these policies. This right may be exercised, among others, against partial, inaccurate, incomplete, fractioned, or misleading data, or data whose processing is expressly prohibited or has not been authorized.
Request proof of the authorization granted to OLSOFTWARE S.A.S. for the processing of their personal data, except for those cases exempted by law.
Be informed by OLSOFTWARE S.A.S., upon request submitted through the channels provided in these policies, regarding the use given to their personal data.
Submit inquiries to OLSOFTWARE S.A.S. and file complaints with the competent authority in charge of personal data protection.
Request the revocation of authorization and/or the erasure of their personal data when OLSOFTWARE S.A.S. engages in conduct contrary to the law and the Constitution.
Access free of charge and without restriction, through the channels provided in these policies, their personal data that is subject to processing.
12. Duties and Obligations
The Data Subject is responsible for keeping their information updated and guaranteeing its accuracy to OLSOFTWARE S.A.S. at all times. OLSOFTWARE S.A.S. shall not, under any circumstances, assume liability of any kind arising from inaccuracies in the information provided by the Data Subject.
13. Data Controller and Data Processor Roles
13.1. Duties of the Data Controller
OLSOFTWARE S.A.S. shall act as the Data Controller of the personal data and, in such capacity, assumes the following obligations:
Guarantee the Data Subject, at all times, the full and effective exercise of the right to habeas data.
Request and retain, under the conditions provided by law, a copy of the respective authorization granted by the Data Subject.
Duly inform the Data Subject about the purpose of data collection and the rights they hold by virtue of the granted authorization.
Store and maintain the information under the security conditions necessary to prevent its alteration, loss, unauthorized or fraudulent consultation, use, or access.
Ensure that the information provided to the Data Processor is truthful, complete, accurate, updated, verifiable, and understandable.
Update the information by communicating in a timely manner to the Data Processor all updates or modifications regarding the data previously provided, and adopt any other necessary measures to ensure the information provided to the processor is kept up to date.
Rectify information when it is incorrect and communicate the relevant corrections to the Data Processor.
Provide the Data Processor, as applicable, only with data whose processing has been previously authorized in accordance with the provisions of the law.
Require the Data Processor, at all times, to respect the security and privacy conditions of the Data Subject’s information.
Process inquiries and claims filed within the terms set forth by law.
Adopt policies and procedures to ensure proper compliance with the law, particularly for addressing inquiries and claims.
Inform the Data Processor when specific information is being contested by the Data Subject, once a claim has been filed and the respective process has not yet been finalized.
Inform the Data Subject, upon request, about the use given to their data.
Comply with the instructions and requirements issued by the Superintendency of Industry and Commerce (SIC).
Inform the data protection authority of any security code breaches or risks regarding the administration of the Data Subjects’ information.
13.2. Data Processor
The Administration Department—specifically the individuals holding the roles of Accounting Administrative Assistant and Process Leader, in coordination with the customer service areas—shall be the department in charge of processing personal data on behalf of OLSOFTWARE S.A.S. This department will be supplied with the personal information of the Data Subjects residing in the databases. Additionally, it shall monitor and update the purposes of personal data processing within the company.
The officer in charge of said department shall maintain a registry of the databases and shall perform the following functions:
Understand this policy and apply it within their scope of responsibility to guarantee the Data Subject the full and effective exercise of their rights.
Inform the Data Subject about the purpose of data collection and guarantee the exercise of their rights under the granted authorization.
Use only personal data obtained via authorization, unless such authorization is not legally required.
Retain a copy or backup of the respective authorization granted by the Data Subject.
Ensure that the processed information is truthful, complete, accurate, updated, verifiable, and understandable.
Adhere to the security and privacy conditions of the Data Subject’s information to prevent its alteration, loss, unauthorized or fraudulent consultation, use, or access.
Perform the update, rectification, or erasure of personal data within five (5) business days from its receipt.
Process inquiries and claims filed by Data Subjects in a timely manner.
Apply the procedures required by law in the event of claims or administrative or judicial proceedings related to the processing of personal data, as well as when security code breaches occur and pose a risk to the administration of Data Subjects’ information.
Restrict access to information solely to authorized personnel.
Establish the internal measures to be adopted within OLSOFTWARE S.A.S. across all processes and procedures involving the processing of Data Subjects’ personal data.
Execute confidentiality agreements with any personnel handling information related to the processing of personal data.
Comply with the instructions and requirements issued by the competent administrative authority.
Perform any other duties established by law.
14. Procedure for the Exercise of Data Subject Rights
14.1. Communication Channels
Personal data processing activities may be conducted by OLSOFTWARE S.A.S. via physical mail, email, landline, website, mobile phone, text message, social media, surveys, or any other widely known medium of communication, in compliance with current regulations.
OLSOFTWARE S.A.S. establishes the following communication channels for Data Subjects:
Website: www.olsoftware.com
Email: habeasdata@olsoftware.com
Phone Numbers: +57 (602) 308-7748 / +57 (602) 373-8333
14.2. Inquiries, Requests, and Claims
OLSOFTWARE S.A.S. will receive inquiries, requests, and claims in writing at its physical address: Calle 44 Norte 5N-27 – Cali, verbally via telephone at +57 (602) 308-7748 / +57 (602) 373-8333, or in writing through its website www.olsoftware.com or email habeasdata@olsoftware.com addressed to the Administrative Areas.
Inquiries made by the Data Subject or their successors will be addressed by OLSOFTWARE S.A.S. within a maximum term of ten (10) business days from the date of receipt of the request. This term may be extended for a maximum of five (5) business days, provided that OLSOFTWARE S.A.S. informs the applicant of the extension beforehand.
Data Subjects or their successors who believe that the information contained in OLSOFTWARE S.A.S.‘s databases should be corrected, updated, or erased, or who notice an alleged breach of any of the duties set forth in the law or these policies, may submit a claim to the Accounting Administrative Assistant and Process Leader and the customer service areas. This claim will be processed under the following rules:
The claim must be submitted via a request addressed to the Accounting Administrative Assistant and Process Leader through the communication channels provided in this policy, including the identification of the Data Subject, a description of the facts giving rise to the claim, the contact address, and any required supporting documents.
The maximum term to address the claim shall be fifteen (15) business days starting from the business day following its receipt. If it is not possible to resolve the claim within this period, the term may be extended for a maximum of eight (8) business days, and the administrative area must inform the applicant of the reasons for the delay.
If the claim is incomplete, the applicant will be required within five (5) business days following receipt of the claim to remedy the deficiencies. If two (2) months elapse from the date of the request without the applicant presenting the required information, it will be understood that the claim has been abandoned.
If the recipient of the claim is not competent to resolve it, they shall forward it to the Accounting Administrative Assistant and Process Leader within a maximum of two (2) business days and inform the applicant of the situation.
Prior to filing a complaint with the authority in charge of monitoring compliance with data protection regulations, the Data Subject must first process their claim directly with OLSOFTWARE S.A.S. through the means and channels provided for such purpose.
15. Scope of Application
These policies shall apply to all databases under the administration of OLSOFTWARE S.A.S. by virtue of its corporate purpose and the commercial relationships it establishes.
Depending on the obligations acquired under these relationships, OLSOFTWARE S.A.S. shall act as either Data Controller or Data Processor, depending on whether it receives the data from a third party or collects the data itself.
Furthermore, this policy shall apply when data processing is carried out within Colombian territory. These policies shall also apply when the Data Controller or Data Processor does not reside in Colombia but is subject to Colombian legislation by virtue of international standards or treaties.
16. Right to Habeas Data (Right to Access and Rectify Data)
These policies adopt the definition set forth in Article 15 of the Political Constitution of Colombia, which establishes Habeas Data as the fundamental right of all individuals to access, update, and rectify information collected about them in databases or files managed by both public and private entities. Furthermore, and in accordance with Judgment C-748 of 2011 issued by the Constitutional Court, this right encompasses additional powers, such as authorizing data processing, adding new data, and excluding or erasing data from a database or file.
The scope of Habeas Data within these policies also includes what is referred to as “financial habeas data,” understood as the right of every individual to access, update, and rectify their personal, commercial, credit, and financial information stored in public or private credit bureaus and information registries whose function is to collect, process, and circulate such data to assess the financial risk profile of the Data Subject.
Finally, for the purposes of these policies, the right to Habeas Data extends beyond a strictly financial and credit-focused perspective to encompass the broader authority of the Data Subject to control any information collected about themselves in any database or archive administered by public or private entities.
17. National Registry of Policies and Databases
This registry serves as the public directory of databases subject to processing that operate within the country, and it is open to free consultation by citizens. OLSOFTWARE S.A.S. shall register its policies and databases with the competent administrative authority within the timeframe and at the location designated by said authority.
19. Authorized Databases
OLSOFTWARE S.A.S. has identified the following databases:
Database Containing Public Information: The data contained in public registries is derived from the fulfillment of legally regulated duties, and its forms and procedures serve a purpose of public disclosure and enforceability against third parties. This data is public by statutory provision and does not require the prior authorization of the Data Subject for its processing. Similarly, any registries subsequently delegated to OLSOFTWARE S.A.S. shall be understood to hold the same status of public data.
Shareholders’ Database: Structured manual or automated databases containing public and private personal data of natural persons associated with the company in their capacity as shareholders/partners. The private data registered in this database requires the authorization of the Data Subject. These databases may contain sensitive information; therefore, they shall be used solely for the specific purposes for which they were entrusted.
Employees’ and Workers’ Database: Structured manual or automated databases containing public and private personal data of natural persons legally employed by OLSOFTWARE S.A.S.
Allies’ and Contractors’ Database: Data processing is performed for purposes related to the contract management process for products and services required by OLSOFTWARE S.A.S. for its operations in accordance with current regulations. Data processing is carried out for contract execution, payments, collections, credit management, and portfolio management, among other activities necessary for the company’s operations. The private data registered in this database requires the authorization of the Data Subject. These databases may contain sensitive information; therefore, they shall be used solely for the specific purposes for which they were entrusted.
Suppliers’ Database: Manual or automated databases containing data of natural or legal persons who maintain a contractual and commercial relationship with the company. The purpose of this processing is to comply with the contractual provisions established by OLSOFTWARE S.A.S. for acquiring the services and goods required to develop the company’s corporate purpose and economic activity. This database contains public, private, and sensitive personal data processed for the development of contractual relationships. Processing this data for purposes other than maintaining the contractual relationship or complying with statutory duties requires the prior authorization of the Data Subject or their legal representative, as applicable, which shall be incorporated into the clauses established for such purpose in onboarding, service, or agreement documents.
Customers’ Database: Structured manual or automated databases containing public and private personal data of natural or legal persons in their capacity as customers. At OLSOFTWARE S.A.S., this capacity is attributed to any natural or legal person formally onboarded by the company during the commercial management process. The private data registered in this database requires the authorization of the Data Subject. These databases may contain sensitive information; therefore, they shall be used solely for the specific purposes for which they were entrusted.
19. Bases de datos autorizadas
Sensitive personal data will be available for review and/or modification within the authorized databases through:
Website: www.olsoftware.com
The aforementioned databases are protected by the necessary security mechanisms required to safeguard data, which include:
Regular data backups (copias de seguridad)
A centralized management system
Contingency and disaster recovery plans
Role-based access control (control de acceso por perfiles)
20. Privacy Notices and Security Measures Applied to Processing
In cases where it is not possible to make these policies directly available to the Data Subject, OLSOFTWARE S.A.S. shall inform the Data Subject of their existence and how to access them through a Privacy Notice. This notice shall be prepared and communicated in compliance with data protection regulations, and a copy of such publication shall be retained as evidence in the archives of OLSOFTWARE S.A.S.
OLSOFTWARE S.A.S. maintains dedicated “Information Security Policies” to ensure compliance with all security requirements governing the processing of personal data. These security policies are deemed fully incorporated into this document and outline the controls implemented by OLSOFTWARE S.A.S. to guarantee personal data security. These controls entail the adoption of physical, administrative, and legal procedures and measures to guarantee access control, data processing, incident management, and information security audits of personal data.
21. Transfers and Transmissions of Personal Data
In the execution of its corporate purpose, OLSOFTWARE S.A.S. establishes partnerships and alliances with other legal entities that act as Joint Data Controllers (corresponsables) of personal data. In such cases, OLSOFTWARE S.A.S. shall extend the obligations established in these policies for Data Controllers and Processors to these relationships.
Furthermore, the company shall execute the respective data transmission agreements to process personal data on behalf of the Data Controller, in compliance with the guiding principles that protect them, safeguarding the security of the databases containing personal data, and maintaining strict confidentiality regarding their processing.
22. Applicable Legislation
Political Constitution of Colombia: Articles 15 (Right to Privacy and Habeas Data) and 20 (Freedom of Expression and Information).
Law 527 of 1999: (Electronic Commerce, Digital Signatures, and Data Messages Law).
Law 1266 of 2008: (Financial Habeas Data Law).
Law 1273 of 2009: (Cybercrime and Information Protection Law).
Statutory Law 1581 of October 17, 2012: (General Personal Data Protection Regime).
Regulatory Decree 1727 of 2009: (Regulating Law 1266 of 2008 regarding credit reporting and information bureaus).
Regulatory Decree 2952 of 2010: (Regulating partially Law 1266 of 2008).
Regulatory Decree 1377 of 2013: (Regulating partially Statutory Law 1581 of 2012 regarding consent, policies, and international transfers).
Regulatory Decree 886 of May 13, 2014: (Regulating the National Registry of Databases).
Constitutional Court Judgment C-748 of 2011: (Constitutional review and enforceability of Statutory Law 1581 of 2012).
23. Entry into Force, Term of Validity, and Amendments
This policy shall enter into force on December 22, 2023, and shall remain valid for as long as OLSOFTWARE S.A.S. executes its corporate purpose in Colombia, or until otherwise or differently provided by law.
This policy may be modified at any time and unilaterally by OLSOFTWARE S.A.S., with the obligation to notify the Data Subjects of any such modifications in a timely manner.
These policies shall be published in accordance with the instructions and guidelines issued by the Superintendency of Industry and Commerce (SIC).
(Signed by the General Manager)