Personal data processing policy
Effective from its publication on this site.
In accordance with Colombian Law 1581 of 2012, Regulatory Decree 1377 of 2013, and any later amendments, Alejandro Gómez Orozco, hereinafter zaz, adopts this policy for the processing of Personal Data, covering collection, use, and transfer.
Law 1581 of 2012 aims to: “[…] develop the constitutional right of every person to know, update, and rectify information collected about them in databases or files, and the other constitutional rights, freedoms, and guarantees referred to in article 15 of the Political Constitution […]”.
1. Definitions for this processing policy
For the purposes of this Policy, the definitions set out in Law 1581 of 2012 apply:
- Data Subject (Titular): Natural or legal person whose Personal Data is subject to Processing.
- Controller (Responsable del Tratamiento): Natural or legal person, public or private, that, alone or jointly, decides on the database and/or the Processing of the data. In this case, zaz is the Controller.
- Processor (Encargado del Tratamiento): Natural or legal person, public or private, that, alone or jointly, processes personal data on behalf of the Controller.
- Personal data: Any information linked or that may be associated with one or more identified or identifiable natural persons.
- Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.
- Personal Data Processing Policies: this document.
- Sensitive data: Data that affect the Data Subject’s privacy or whose misuse may lead to discrimination.
2. Principles for the processing of personal data
The principles that govern the Processing of Personal Data (article 4 of Law 1581 of 2012) are:
- Principle of legality in data processing
- Principle of purpose
- Principle of freedom
- Principle of accuracy or quality
- Principle of transparency
- Principle of restricted access and circulation
- Principle of security
- Principle of confidentiality
3. Authorization for the processing of personal data
When collecting Personal Data, zaz will request authorization from the Data Subject and inform the specific purposes of the Processing. On this site, that authorization is given when you check the consent box and send a message or a meeting request.
4. Purposes of Personal Data Processing
zaz collects Personal Data in the course of its work, for the following purposes:
- Administrative management and the commercial relationship.
- Contacting you and responding to meeting or contact requests.
- Offering and providing software design and development services.
- Sending information related to the service, when relevant.
- Invoicing and a record of the commercial relationship.
- Any other purpose that arises from the contract or commercial relationship between zaz and the Data Subject.
Use and retention
Information provided by the Data Subject will only be used for the purposes stated here. When Processing is no longer needed, the data may be deleted from zaz’s databases or archived securely, to be disclosed only when the law requires it.
5. Types of Personal Data included in the databases
Data collected by zaz through this site are mainly: name, email, phone, and the content of the message or meeting request. In the course of a commercial relationship, other data needed to provide the service may be included, such as occupation, company, or billing information.
This site uses Google reCAPTCHA v3 to tell human submissions from automated traffic on the forms. Google may collect technical data about the device and browser, and that information is sent to Google LLC (United States) for analysis. Use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.
6. Procedures for processing personal data
Personal Data in zaz’s databases come from information gathered through commercial, contractual, or other relationships with users, clients, suppliers, and the public.
On this site, collection happens through the contact and meeting-request forms. The Data Subject gives prior, express, and informed authorization by checking the consent box on those forms.
6.1 Procedure to know, update, rectify, or delete information
To protect and keep Personal Data confidential, the Data Subject may submit a request through this site’s contact form or by writing to the email indicated below.
6.2 Procedure to delete information and revoke authorization
Data Subjects may, at any time, ask zaz to delete their data and/or revoke authorization by filing a claim in accordance with article 15 of Law 1581 of 2012.
6.3 Contact information
Controller: Alejandro Gómez Orozco (zaz).
To exercise your rights, use this site’s contact form or request a meeting. zaz will handle queries and claims within the timeframes set by law.
7. Rights of the personal data subject
The Data Subject of the personal data provided has the following rights:
- To know, update, and rectify their personal data vis-à-vis the controllers or processors.
- To request proof of the authorization granted to the controller, except for the exceptions provided in Law 1581 of 2012.
- To be informed by the controller or the processor, upon request, of the use given to their personal data.
- To file complaints with the Superintendence of Industry and Commerce for violations of the Law.
- To revoke the authorization granted to the controller and/or request deletion of the data when processing does not respect constitutional and legal principles, rights, and guarantees. Such revocation or deletion shall proceed when the Superintendence of Industry and Commerce has determined that the controller or processor has engaged in conduct contrary to Law 1581 of 2012 or the Constitution.
8. Duties of the controller
As controller, zaz undertakes to:
- Guarantee the Data Subject, at all times, the full and effective exercise of the right of habeas data.
- Request and keep, under the conditions provided by law, a copy of the authorization granted by the Data Subject.
- Duly inform the Data Subject of the purpose of collection and the rights that arise from the authorization granted.
- Keep the information under the security conditions necessary to prevent alteration, loss, consultation, use, or unauthorized or fraudulent access.
- Ensure that information supplied to a Processor is truthful, complete, accurate, up to date, verifiable, and understandable.
- Update the information, promptly informing the Processor of all changes regarding data previously supplied, and adopt the other measures needed to keep that information current.
- Rectify the information when it is incorrect and communicate that to the Processor.
- Handle queries and claims in the terms set by law.
- Adopt an internal manual of policies and procedures to ensure proper compliance with the law and, in particular, to handle queries and claims.
- Inform, at the Data Subject’s request, of the use given to their data.
- Inform the data-protection authority when security codes are breached and there are risks in the administration of Data Subjects’ information.
- Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.
9. Term of the policy
This Personal Data Processing Policy is effective from its publication. zaz may amend it at any time to adapt it to legislative or case-law developments, as well as to better practices on the subject, in which case Data Subjects will be informed in due course.
Any amendment or update will be published on this page, with the effective date of the corresponding change.
Use of this site or of the services offered by zaz, or remaining linked to them after the new Policy is published, constitutes acceptance of it.
Personal Data or databases subject to Processing will remain in effect for the term of the relationship with the Data Subject, plus any additional term required by law.