Privacy Policy

Preamble

Compliance with the company's internal and external policies is one of our most important objectives, which is why we have been in charge of preparing manuals that allow us to create a system of procedures. In this case, we refer herein to the Data Protection Law. This manual aims to create an organizational system for the management of all types of information that has been collected in databases obtained by our company.

INVERSIONES NATALIA DUQUE E HIJOS S.A.S, adheres to the general provisions contained in Law 1581 of 2012 and Decree 1377 of 2013, and other regulations that modify the matter, and therefore makes this manual for the protection and use of personal data available to all people who work for it or those who have some type of commercial relationship such as suppliers, shareholders, creditors, debtors, among others.

General Data of Láu De Lá as Data Controller

NIT: 900658294-8

Address: Calle 14 sur #43A - 21 IN 102, Medellín, (Ant), Colombia

Switchboard: 57 3522311

Website: www.laudela.com.co

Objective

The Personal Data Processing and Protection Policy presented below shall apply to all Databases and/or Files containing personal data that are processed by LÁU DE LÁ, considered as the data controller and/or data processor.

These policies apply to all LÁU DE LÁ employees, as well as to all clients, external advisors, temporary staff and guests, who make use of the resources and services provided by LÁU DE LÁ.

Habeas Data

Law 1266 of 2008, known as “HABEAS DATA LAW”, has been established by the national government with the purpose of developing the constitutional right that all people have to know, update and rectify the information collected about them in Databases, and the other constitutional rights, freedoms and guarantees related to the collection, processing and circulation of personal data referred to in article 15 of the Political Constitution, particularly in relation to financial, credit, commercial, services information and that from third countries.

It is applicable to all personal information data registered in databases that are managed by public and private entities.

It is not applicable to data maintained in an exclusively personal or domestic scope and those that circulate internally.

Definitions and Concepts

Personal Data: This is information that can be used for the identification, location, or contact with a specific and natural person. Personal data may consist of identification numbers, fingerprints, and other data that can lead to someone's identification. It is important to note that some of this data is public, either because it is part of the public information of each natural person, or by the person's own decision.

Some personal data must be given the category of special, as the information they contain can be negative if published.

Database: A set, compilation, or collection of data from one or more persons related by subject matter or a common context.

Data Subject: This is the person whose personal data has been analyzed, requested, or collected. The data subject is the one who, legally, by constitutional directive, has the right to modify, update, and know what information is held about them.

Data Processing: This refers to any type of process, operation, or action carried out on the data provided. This processing does not have any special handling with regard to the methods by which the data is acquired. (RELATED TO DATA CONTROLLER: natural or legal person responsible for executing the operations that fall on the data).

Public Data: Any data that is not private or sensitive is considered public data. Decree 1377 of 2013 indicates that it will be any data found in a public document, official gazettes and bulletins, and duly executed judicial sentences that are not subject to reservation.

Privacy Notice: Verbal or written communication generated by the Controller, addressed to the Data Subject for the processing of their personal data, through which they are informed about the existence of the applicable Information Processing Policies, how to access them, and the purposes of the intended processing of personal data.

Sensitive Data: Information that affects the privacy of individuals or whose improper use may generate discrimination (Racial or ethnic origin, political orientation, philosophical or religious convictions, membership in unions or social or human rights organizations, health data, sexual life, and biometric data)

Data Controller: Natural or legal person, public or private, who, alone or in conjunction with others, decides on the database and/or the processing of the data.

Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.

Transfer: Data transfer occurs when the Data Controller and/or Data Processor of personal data, located in Colombia, sends the information or personal data to a recipient, who in turn is a Data Controller and is located inside or outside the country.

Transmission:Processing of personal data that involves the communication of said data within or outside the territory of the Republic of Colombia when its purpose is to carry out processing by the Processor on behalf of the Controller.

Guiding Principles 

Principle of Legality: Data and its processing must comply with legal provisions and regulations.

Principle of Purpose: The management of data must have a specific purpose, in accordance with legal principles and following data processing policies, which must be informed to the data subject.

Principle of Freedom: Actions may only be taken with the express and tacit permission of the data subject, having informed them of the policies and actions to be carried out with the data in question.

Principle of Veracity: Law 1521 of 2012 states the following: “The information subject to Processing must be truthful, complete, accurate, updated, verifiable and understandable. The Processing of partial, incomplete, fragmented or misleading data is prohibited.”

Principle of Restricted Access and Circulation: Only persons in charge of data processing or authorized by the data subject may have access to the data.

Personal data that is not public may not be published on the Internet or other dissemination media unless this is done for the use of the data processor or with the authorization of the data subject.

Principle of Security: The processing of data must be carried out in a technical, human, and under the correct measures to provide security to the author or the person in charge of processing this data.

Data Categories

Sensitive Data: These are "those that affect the privacy of the data subject or whose improper use may lead to discrimination, such as those revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership in unions, social organizations, human rights organizations or those that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data related to health, sexual life and biometric data." (Art. 5 Law 1581/12)

Article six of the same Law points out some exceptions to the rule:

  1. The Data Subject has given explicit authorization for said Processing, except in cases where such authorization is not required by law.
  2. The Processing is necessary to safeguard the vital interest of the Data Subject, and the Data Subject is physically or legally incapacitated. In these events, legal representatives must provide their authorization.
  3. The Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association, or any other non-profit organization, whose purpose is political, philosophical, religious, or union-related, provided that it refers exclusively to its members or to persons who maintain regular contact due to its purpose. In these events, the data may not be provided to third parties without the authorization of the Data Subject.
  4. The Processing refers to data that is necessary for the recognition, exercise, or defense of a right in a judicial process.
  5. The Processing has a historical, statistical, or scientific purpose. In this event, measures must be adopted to suppress the identity of the Data Subjects. Likewise, the person responsible for data processing must inform the data subject of the following:

    Inform the Data Subject that, being sensitive data, they are not obliged to authorize its Processing.

    Inform the Data Subject explicitly and prior to the processing, in addition to the general requirements for authorization for the collection of any type of personal data, which of the data to be processed are sensitive and the purpose of the Processing, as well as obtain their express consent.

    No activity may be conditioned on the Data Subject providing sensitive personal data.

Public Data: When we talk about public data, we refer to any data that is available in banks, databases, or other forms of public data collection; meaning that anyone can access them without any special requirement. Likewise, personal data found in these types of sources will be considered public by nature, respecting the parameters imposed by legislation and what has been stipulated above.

Authorization and Data Collection

AUTHORIZATION for data collection must be carried out by the data subject, who must express their verbal or written consent for the use and collection of said data; the data controller has the duty to inform the data subject of the usage policies, that is, the purpose for which the requested information will be needed. This must be done at the time of data collection. AUTHORIZATION FROM THE DATA SUBJECT WILL BE UNDERSTOOD AS GRANTED WHEN IT IS DONE: in writing, verbally, or through unequivocal actions of the Data Subject that allow for the reasonable conclusion that authorization was granted. In no case may silence be assimilated to an unequivocal action.

Authorization will NOT be needed in the following cases:

  1. Information required by a public or administrative entity in the exercise of its legal functions or by judicial order;
  2. Data of a public nature;
  3. Medical or sanitary emergency cases;
  4. Processing of information authorized by law for historical, statistical or scientific purposes;
  5. Data related to the Civil Registry of Persons.

PROOF OF HOW DATA HANDLING WAS AUTHORIZED MUST ALWAYS BE KEPT.

Collection of personal data: Based on the principles established in this manual, the data collected with prior authorization must be limited to those personal data that are relevant and adequate for the purpose for which they are collected or required in accordance with current regulations.

Personal data found in publicly accessible sources, regardless of the medium through which they are accessed, meaning data or databases available to the public, may be processed by anyone as long as, by their nature, they are public data.

Change of data processing policies: When the data processor, for any justified reason, changes the policies, they must inform the data subject of the changes that have been made, and must do so at the time of implementing the new provisions.

“…At the request of the Superintendence of Industry and Commerce, Controllers must provide a description of the procedures used for the collection, storage, use, circulation and deletion of information, as well as a description of the purposes for which the information is collected and an explanation of the need to collect the data in each case…”

Revocation of authorization: Data Subjects may at any time request the data controller or processor to delete their personal data and/or revoke the authorization granted for the processing of said data, by submitting a claim or request.

Rights of the data subject:

Article 8 of Law 1581 of 2012 sets forth the following Rights of Data Subjects.

  1. To know, update and rectify their personal data before the Data Controllers or Data Processors. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented, misleading data, or data whose processing is expressly prohibited or has not been authorized.
  2. To request proof of the authorization granted to the Data Controller, except when expressly exempted as a requirement for processing, in accordance with the provisions of Article 10 of this Law;
  3. To be informed by the Data Controller or Data Processor, upon request, regarding the use given to their personal data.
  4. To file complaints with the Superintendence of Industry and Commerce for infringements of the provisions of this law and other regulations that modify, add to or complement it.
  5. To revoke the authorization and/or request the deletion of the data when the processing does not respect constitutional and legal principles, rights and guarantees. Revocation and/or deletion shall proceed when the Superintendence of Industry and Commerce has determined that the Controller or Processor has engaged in conduct contrary to this law and the Constitution during processing.
  6. To access their personal data that has been processed free of charge.

These rights may also be exercised by:

  1. The Data Subject, who must sufficiently prove their identity through the different means made available by the controller.
  2. Their successors, who must prove such status.
  3. The representative and/or attorney-in-fact of the Data Subject, after proving representation or power of attorney.
  4. By stipulation for the benefit of another or for another.

Duties of Data Controllers

  • Guarantee the Data Subject, at all times, the full and effective exercise of the right to habeas data.
  • Request and keep, under the conditions provided in this law, a copy of the respective authorization granted by the Data Subject.
  • Duly inform the Data Subject about the purpose of the collection and the rights they have by virtue of the authorization granted.
  • Keep the information under the necessary security conditions to prevent its alteration, loss, consultation, unauthorized or fraudulent use or access.
  • Guarantee that the information provided to the Data Processor is truthful, complete, accurate, updated, verifiable and understandable;
  • Update the information, communicating in a timely manner to the Data Processor, all changes regarding the data previously provided to them and adopt other necessary measures to keep the information provided to them updated.
  • Rectify the information when it is incorrect and communicate what is pertinent to the Data Processor.
  • Provide the Data Processor, as the case may be, only data whose Processing is previously authorized in accordance with the provisions of this law.
  • Demand from the Data Processor at all times, respect for the security and privacy conditions of the Data Subject's information.
  • Process inquiries and claims formulated in the terms indicated in this law.
  • Adopt an internal manual of policies and procedures to ensure proper compliance with this law and, in particular, for handling inquiries and claims.
  • Inform the Data Processor when certain information is under discussion by the Data Subject, once the claim has been filed and the respective procedure has not ended.
  • Inform, at the Data Subject's request, about the use given to their data.
  • Inform the data protection authority when security code violations occur and there are risks in the administration of Data Subjects' information.

Temporary Limitations on the Processing of Personal Data

Those responsible for data handling and processing may only collect, request, use, and otherwise dispose of personal data in accordance with the purpose and objective initially set out in the usage policies, for a period that must be reasonable and appropriate. Once the purpose or purposes of the Processing have been met and without prejudice to legal norms that provide otherwise, the Data Controller and the Data Processor must proceed to delete the personal data in their possession. Notwithstanding the foregoing, personal data must be kept when required for the fulfillment of a legal or contractual obligation.

Processing Policies

The Processing policies are an integral part of this manual. These processing policies must be maintained throughout the entire data processing process. Any change or modification made to the processing policies must be immediately communicated to the data subject, so that they can authorize the continuation of such processing or withdraw from it.

In certain cases where the data subject cannot be informed about the data processing policies, a privacy notice must be provided to the data subject about the existence of such policies and how to access them in a timely manner and, in any case, no later than at the time of collecting the personal data.

Data Access

Data subjects will always have access to their data and it will be available to them, as data processors must implement simple and agile mechanisms for data access. The Data Subject may consult their personal data free of charge: at least once every calendar month, and whenever there are substantial modifications to the Information Processing Policies that motivate new consultations.

Steps to follow with previously collected data

• Data controllers must inform the data subjects of already collected data about the policies for their use, and inquire about their continued use and management, as mentioned in this manual.

• If it is difficult for the data controller to locate and inform each data subject about the processes that will be carried out with their data, they may implement other alternative mechanisms, such as widely circulated national newspapers, local newspapers or magazines, the controller's website, informational posters, among others, and inform the Superintendence of Industry and Commerce within five (5) days following their implementation. The same would happen if it were impossible for the data controller to locate the data subject due to omitted location data or changes in it without proper updating.

• If, within thirty (30) business days after interposing any of the aforementioned mechanisms, the data subject has not communicated with the Controller or Processor, they may continue to process the data contained in their databases for the purpose or purposes indicated in the information processing policy, made known to the Data Subjects through such mechanisms, without prejudice to the Data Subject's right to exercise their right at any time and request the deletion of the data.

• In any case, the Controller and the Processor must comply with all applicable provisions of Law 1581 of 2012 and this Decree. Likewise, it will be necessary for the current purpose or purposes of the Processing to be equal, analogous or compatible with the purpose or purposes for which the personal data was initially collected.

Security Measures 

INVERSIONES NATALIA DUQUE E HIJOS S.A.S. has sufficient security measures to protect all our employees, clients, and associates; as a main example, this data protection manual, governed by national legal regulations, where we try to cover all necessary aspects to provide protection guarantees.

In addition to the above, we propose as a foundation the use of personalized authorizations for each of our workers, clients, and other people who may at some point be linked with us, and we also propose, through our internal network, mass communications to administrative staff and all area managers.

Technology and Communications - Access Code and Password

The confidentiality and integrity of the data stored in LÁU DE LÁ systems are protected by access codes and passwords that ensure that only authorized employees have access.

IT Responsibilities

Information Technology is responsible for managing access controls to all the company's Information systems, as well as to the different services offered such as Internet, Intranet, VPN, shared folders, etc.

IT will disable user codes for people who are on vacation, incapacitated and/or on paid or unpaid leave, as recorded in the Payroll Information System, and will enable them in the same way. User codes for employees who are removed from the payroll will also be deleted.

Procedures to guarantee the exercise of data subject rights

Data subjects may at any time file and follow one of the following procedures to defend their rights, including the updating, changing, or modifying of generated data.

  • Inquiries: data subjects may consult the basic information of the databases in our company; this request can be submitted in writing, or verbally, but always identifying themselves properly.
  • Claims: the data subject who believes that the generated information is not correct, or is not being well managed, or is not being used properly, may generate the respective claim in writing or verbally in our company or with the person in charge, regarding the generated claim, a response will be given as soon as possible and the necessary changes will be made.
  • Requests: for making changes, modifications, or updates to the data contained, a request must be made in writing or verbally.

To be taken into account

  • Article 19 of Law 1581 of 2012 states that the COMPETENT AUTHORITY for Data Protection is The Superintendence of Industry and Commerce, through a Delegation for the Protection of Personal Data, which will oversee ensuring that the principles, rights, guarantees, and procedures are respected in the processing of personal data.
  • Article 26 of Law 1581 of 2012 PROHIBITS THE TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES that do not provide adequate levels of data protection. A country is understood to offer an adequate level of data protection when it complies with the standards set by the Superintendence of Industry and Commerce on the matter.

Sanctions

The Data Protection Law has established in its Article 23 the sanctions for non-compliance with any of the foreseen obligations, as follows: Article 23. Sanctions. The Superintendence of Industry and Commerce may impose the following sanctions on Data Controllers and Data Processors:

  1. Fines of a personal and institutional nature up to the equivalent of two thousand (2,000) monthly legal minimum wages at the time the sanction is imposed. Fines may be successive as long as the non-compliance that originated them persists.
  2. Suspension of activities related to Processing for a term of up to six (6) months. The act of suspension shall indicate the corrective measures to be adopted.
  3. Temporary closure of operations related to Processing once the suspension period has expired without the corrective measures ordered by the Superintendence of Industry and Commerce having been adopted.
  4. Immediate and definitive closure of the operation involving the Processing of sensitive data.

Paragraph. The sanctions indicated in this article only apply to private entities. In the event that the Superintendence of Industry and Commerce observes an alleged non-compliance by a public authority with the provisions of this law, it will refer the action to the Attorney General's Office to carry out the respective investigation.

Both this manual and the data processing policy will come into effect from their publication date on the company's website and internal media.