Switch Language

1. General Provisions

1.1. Objective

1.1. Objective

The company Brigard & Urrutia Abogados S.A.S. domiciled in Bogotá, with physical address at Calle 70 BIS # 4-41, email address protecciondedatos@bu.com.co and telephone (+57-601) 346 2011 (hereinafter the "Firm") hereby informs the Holders of Personal Data (as such terms are defined below) that their Personal Data will be treated in any manner by the Firm, in accordance with this information treatment policy (the "Policy"), in compliance with Law 1581 of 2012, Decree 1377 of 2013 and any regulation that replaces or modifies them. The main purpose of this Policy is to inform the Holders of Personal Data of the rights that assist them, the channels, procedures and mechanisms provided by the Firm to exercise them; to inform who are the authorized persons within the Firm to handle inquiries, questions, claims and complaints, and to make known the scope and purpose of the Treatment (as such term is defined below) to which the Personal Data will be subjected in the event that the Holder grants their express, prior and informed authorization.

1.2. Scope

This Policy applies to all Holders of Personal Data that are treated in any manner by the Firm.

1.3. Definitions

The capitalized expressions used in this Policy shall have the meaning assigned to them herein, or the meaning that the Law or applicable case law assigns to them, according to said Law or case law as amended from time to time. Any difference that may exist between the terms defined herein and those established in the Law, those set forth in the Law shall prevail.

  • Authorization: It is the prior, express and informed consent of the Holder to carry out the Treatment of their Personal Data.
  • Database: It is the organized set of Personal Data that are subject to Treatment, whether electronic or not, regardless of the modality of their creation, storage, organization and access.
  • Financial Data: It is any Personal Data related to the creation, execution and termination of monetary obligations, regardless of the nature of the contract that gives rise to them, whose Treatment is governed by Law 1266 of 2008 or the regulations that complement, modify or add to it.
  • Personal Data: It is any information, linked or that may be associated with one or more determined or determinable natural or legal persons.
  • Public Data: It is the Personal Data classified as such according to the mandates of the Law or the Political Constitution and, consequently, is that which is not semi-private, private or sensitive. Public data includes, among others, data related to people's civil status, their profession or trade, their capacity as a merchant or public servant and those that can be obtained without any reservation. By their nature, public data may be contained, among others, in public registries, public documents, gazettes and official bulletins, duly executed judicial decisions that are not subject to reservation.
  • Sensitive Data: It is Personal Data that affects the privacy of the Holder or whose improper use may generate discrimination, such as those that reveal union affiliations, racial or ethnic origin, political orientation, religious, moral or philosophical convictions, membership in unions, social organizations, human rights organizations or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data related to health, sexual life, and biometric data.
  • Data Processor: It is the natural or legal person, public or private, that by itself or in association with others, carries out the Treatment of Personal Data on behalf of the Data Controller.
  • Data Controller: It is the natural or legal person, public or private, that by itself or in association with others, decides on the Database and/or the Treatment of Personal Data.
  • Holder: It is the natural person whose Personal Data is subject to Treatment, as a consequence of the relationship that the Holder has with the Firm.
  • Transfer: It takes place when the Data Controller and/or the Data Processor of Personal Data, located in Colombia, sends the personal data information to a recipient, who in turn is responsible for the treatment, and is located within or outside the country.
  • Transmission: Treatment of Personal Data that implies the communication to a third party of the same within or outside the territory of the Republic of Colombia, when said communication has as its purpose the performance of a Treatment by the Processor on behalf and on account of the Controller, in order to fulfill the purposes of the latter.
  • Treatment: It is any systematic operation and procedure, electronic or not, that allows the collection, conservation, organization, storage, modification, linking, use, circulation, evaluation, blocking, destruction and in general, the processing of Personal Data, as well as their Transfer and/or Transmission to third parties through communications, inquiries,  interconnections, assignments, data messages.

2. Policies

2.1. Principles

The Firm, in the course of its commercial activities, will collect, use, store, transmit, transfer and in general Treat the Personal Data of the Holders, in accordance with the purposes established in this Policy. In all Treatment of Personal Data carried out by the Firm, the Controllers, Processors and/or third parties to whom Personal Data is transferred, must comply with the principles and rules established in the Law and in this Policy, in order to guarantee the right to habeas data of the Holders and comply with the obligations of Law and the internal guidelines of the Firm. These principles are:

  • Prior authorization: All Treatment of Personal Data shall be carried out once the prior, express and informed Authorization of the Holder has been obtained, unless the Law establishes an exception to this rule. In the event that Personal Data was obtained prior to the issuance of Decree 1377 of 2013, the Firm will seek ordinary and alternative means to summon the Holders and obtain their retroactive authorization, following the guidelines established in said Decree and the concordant regulations. 
  • Authorized purpose: All Personal Data Treatment activity must comply with the purposes mentioned in this Policy or those mentioned in the Authorization granted by the Holder of Personal Data, or in the specific documents where each type or process of Personal Data Treatment is regulated. The purpose of the particular Treatment of a Personal Data must be informed to the Holder of the Personal Data at the time of obtaining their Authorization. Personal Data may not be treated beyond the purposes informed to and consented by the Data Holders. 
  • Quality of the Personal Data: The Personal Data submitted for Treatment must be truthful, complete, accurate, updated, verifiable and comprehensible. When in possession of partial, incomplete, fractionated Personal Data or that leads to error, the Firm must refrain from Treating them, or request from the holder the completeness or correction of the information. 
  • Delivery of information to the Holder: When the Holder requests it, the Firm must deliver the information about the existence of Personal Data that concerns the applicant. This delivery of information will be carried out by the department of the Firm in charge of the protection of personal data (see section 2.6 of this Policy). 
  • Restricted circulation: Personal Data may only be Treated by personnel of the Firm that have authorization for this purpose, or those whose functions include carrying out such activities. Personal Data may not be delivered to those who do not have Authorization or have not been authorized by the Firm to carry out the Treatment. 
  • Temporality: The Firm will not use the information of the holder beyond the reasonable period required by the purpose that was informed to the Holder of Personal Data.
  • Restricted access / Security: Unless the Personal Data is expressly authorized, the Firm may not make Personal Data available for access through the internet or other mass media of communication, unless technical and security measures are established that allow access to be controlled and restricted only to Authorized persons.
  • Confidentiality: The Firm must always carry out the Treatment by providing the necessary technical, human and administrative measures to maintain the confidentiality of the Personal Data and to prevent it from being adulterated, consulted, used, accessed, deleted, modified, or known by unauthorized persons, or that the Personal Data is lost. Any new project that involves the Treatment of Personal Data by the Firm must refer to this Treatment Policy to ensure compliance with this rule.
  • Confidentiality and subsequent Treatment: Any Personal Data that is not Public Data must be treated by the Controllers as confidential, even when the contractual relationship or the link between the Holder of the Personal Data and the Firm has ended. Upon termination of said link, such Personal Data must continue to be Treated in accordance with this Policy and with the Law.
  • Individuality: The Firm shall maintain separately the Databases in which it has the capacity of Processor from the Databases in which it is the Controller.
  • Necessity: Personal Data may only be Treated over time and to the extent that the purpose of their Treatment justifies it. The Firm will seek to collect only and exclusively the data necessary to fully comply with the regulation and the established purposes. 

2.2. Treatment of Personal Data of Girls, Boys and/or Adolescents 

Personal Data is collected, stored, organized, used, circulated, transmitted, transferred, updated, rectified, suppressed, deleted and managed in accordance with the purpose or purposes that each type of Treatment has. 

2.2.1. Processing of Personal Data of children and/or teenagers

The Firm will Treat the Personal Data of minors under 18 years of age, provided that there is prior and express consent from parents or legal guardians. In these cases, parents or legal guardians may change or revoke the Authorization as described in this Policy.

Additionally, the Treatment of Personal Data of girls, boys and adolescents will comply with the following parameters and requirements: 

  • The Treatment shall respond to and respect the best interests of children and adolescents.
  • At all times, respect for their fundamental rights shall be ensured.
  • The child or adolescent shall be heard, and their opinion shall be valued taking into account their maturity, autonomy and capacity to understand the matter. 

2.2.2. Treatment of Sensitive Data

The Firm may request Sensitive Data that will be expressly mentioned in each Authorization.

In any case, the Firm will strictly observe the legal limitations on the Treatment of Sensitive Data, subjecting to Treatment Sensitive Data only when the Holder has granted their Authorization, except in cases where the law does not require such Authorization. When the Firm requests Sensitive Data, it will inform what type of Personal Data belongs to this category and will not condition, in any case, any activity on the delivery of Sensitive Data.

Sensitive Data shall be treated with the greatest possible diligence and with the highest security and privacy standards. Limited access to Sensitive Data shall be a governing principle to safeguard the privacy of such Personal Data and, therefore, only authorized personnel may have access to this type of information. 

2.2.3.Obligations of the Firm as Data Controllers 

When the Firm acts as a Data Controller, it shall have the following obligations and/or commitments: 

  • Have a prior authorization when so required by applicable regulations.
  • Classify the data requested.
  • File and manage the authorization given by the holder.
  • Comply with the principles related to this Policy.
  • Address the inquiries, complaints or claims submitted by the holder.
  • Ensure the data provided through procedures related to security and privacy of information. 

Likewise, when acting as Processors or third parties and having access to Personal Data, they will maintain the Treatment within the following purposes contemplated for the collection of said data. 

2.3. Purposes of the Treatment 

The Firm will carry out the Treatment of Personal Data for the purposes informed at the time the Personal Data is collected and that are expressly consented. 

Likewise, the Processors or third parties that have access to Personal Data by virtue of Law or contract, will maintain the Treatment within the following purposes provided herein or those informed at the time of data collection. 

  • Manage all information necessary for compliance with the tax, commercial, corporate and accounting obligations and records of the Firm.
  • Comply with the internal processes of the Firm regarding the administration of suppliers and contractors.
  • Provide their services according to the particular needs of the Firm's clients, in order to fulfill the service contracts entered into, including but not limited to the verification of affiliations and rights of the individuals to whom the Firm's clients will provide their services, use Personal Data for marketing and/or commercialization of new services or products.
  • The control and prevention of fraud, money laundering, financing of terrorism and financing of the proliferation of weapons of mass destruction, including but not limited to, consultation of binding lists, and all information necessary to comply with the regulation on prevention of fraud, money laundering, financing of terrorism, financing of the proliferation of weapons of mass destruction, among them the following activities: 
    • Provide personal data to control and surveillance authorities, whether administrative, police, judicial, national or international. The foregoing, by virtue of a legal or regulatory requirement.
    • Use and/or disclose information and personal data, in order to defend the rights and/or property of the Firm, its clients, website or its users for the detection and prevention of fraud and for the detection, apprehension or prosecution of criminal acts.
    • Carry out the control and prevention of illegal activities such as fraud, corruption, money laundering and/or financing of terrorism, including but not limited to the consultation of binding, restrictive lists or public databases.
    • Allow access to personal data to auditors or contracted third parties to execute and carry out internal or external audit processes, pertinent to the commercial activity carried out by the Firm. 
  • The filing process, system updating, information protection and custody of the Firm's Databases.
  • Internal processes of the Firm, for development or operational purposes and/or systems administration. 
  • The transmission and transfer of data to third parties with whom contracts have been entered into for this purpose, for commercial, administrative, marketing and/or operational purposes, including but not limited to the issuance of identification cards, personalized certificates and certifications to third parties, in accordance with current legal provisions. In any case, third parties shall be bound by the terms of this Policy.
  • Maintain and process by computer or other means, any type of information related to the client's business in order to provide the relevant services and products.
  • Any other purposes determined by the Controllers in processes of obtaining Personal Data for their Treatment, in order to comply with legal and regulatory obligations, as well as the internal policies of the Firm. 

2.4. Rights of the Personal Data Holder 

In accordance with the Law, the Holders of Personal Data have the following rights: 

  • Right to update: To know, update and rectify their Personal Data before the Firm or the Data Processors thereof. This right may be exercised with respect to partial, inaccurate, incomplete Personal Data, those that lead to error, or those whose Treatment is expressly prohibited or has not been authorized.
  • Right to proof: To request proof of the Authorization granted to the Firm, except when it is expressly exempted as a requirement for the Treatment, in accordance with the provisions of article 10 of Law 1581 of 2012 (or in the regulations that regulate, add, complement, modify or repeal it), or when continuity of the Treatment has been presented as provided in numeral 4 of article 10 of Decree 1377 of 2013.
  • Right to information: To file requests before the Firm or the Data Processor regarding the use that has been given to their Personal Data, and to have such information delivered to them.
  • Right to complaints and claims: To file complaints before the Superintendence of Industry and Commerce for violations of the Law, once the inquiry or claim process before the Firm has been exhausted in accordance with the provisions of article 16 of Law 1581 of 2012.
  • Right to revocation: To revoke their Authorization and/or request the suppression of their Personal Data from the Firm's databases, when the Superintendence of Industry and Commerce has determined through a definitive administrative act that in the Treatment the Firm or the Data Processor has engaged in conduct contrary to the Law or when there is no legal or contractual obligation to maintain the Personal Data in the Controller's Database. 
  • Right of access: To request access to and access free of charge their Personal Data that have been subject to Treatment in accordance with article 21 of Decree 1377 of 2013.
  • Right to knowledge: To know the modifications to the terms of this Policy in a timely and efficient manner prior to the implementation of the new modifications or, failing that, of the new information treatment policy. As well as to know the department or person authorized by the Firm before whom they may file complaints, inquiries, claims and any other request regarding their Personal Data.
  • Right to suppression: To request the suppression of their Personal Data from the Databases whenever and when there is no legal duty or a contractual obligation by virtue of which such suppression is not possible. 

The Holders may exercise their rights under the Law and carry out the procedures established in this Policy, by presenting their identification document or a copy thereof. Minors may exercise their rights personally, or through their parents or the adults who hold parental authority, who must demonstrate it by means of the relevant documentation. Likewise, the rights of the Holder may be exercised by the successors in interest who prove such capacity, the representative and/or attorney-in-fact of the holder with the corresponding accreditation and those who have made a stipulation in favor of another or for another. 

2.5. Area responsible for handling petitions, inquiries and claims 

The Firm has designated the Customer Service management as the area in charge of the reception and handling of petitions, complaints, claims and inquiries of all types related to Personal Data. The person designated from Customer Service will process the inquiries and claims regarding Personal Data in accordance with the Law and this Policy. 

Some of the particular functions of this area in relation to Personal Data are: 

  • Receive the requests of the Holders of Personal Data, process and respond to those that are based on the Law or this Policy, such as: requests for updating Personal Data; requests to know the Personal Data; requests for suppression of Personal Data; requests for information about the use given to their Personal Data; requests for updating Personal Data; requests for proof of the Authorization granted, when it has proceeded according to the Law, among others.
  • Respond to Holders of Personal Data regarding those requests that do not proceed in accordance with the Law. 
  • The contact details of Customer Service are: 
    Physical address: Calle 70 Bis No. 4 - 41
    Email address: protecciondedatos@bu.com.co
    Telephone: (+57-601) 3462011
    Contact person title: Customer Service Analyst 

2.6. Procedures to exercise the rights of Personal Data Holders 

2.6.1. Inquiries 

The Firm will provide mechanisms for the Holder, their successors in interest, their representatives and/or attorneys-in-fact, those to whom it has been stipulated in favor of another or for another, and/or the representatives of minors who are Holders, to make inquiries regarding which Personal Data of the Holder is held in the Firm's Databases.

These mechanisms may be physical such as in-person processing, electronic through the Customer Service email protecciondedatos@bu.com.co or by telephone on the service line (+57-601) 346 2011, in charge of receiving petitions, complaints and claims by telephone.

Regardless of the medium, the Firm will keep proof of the inquiry and its response. Consequently, the following are the steps to follow for the submission of inquiries: 

  • Requests must be made in writing.
  • The request will be analyzed to verify the identification of the Holder. If the request is made by a person other than the Holder and it is not demonstrated that they act in representation of the Holder in accordance with current laws, the request will be rejected. For this purpose, the Firm may request the Holder's identification document or a copy thereof, and the special, general powers of attorney or documents required as the case may be.
  • If the applicant has the capacity to make the inquiry, in accordance with the accreditation criteria established in Law 1581 of 2012 and Decree 1377 of 2013, the Firm will collect all information about the Holder that is contained in the individual record of that person or that is linked to the identification of the Holder within the Firm's Databases.
  • The person assigned to handle the inquiry will respond within ten (10) business days counted from the date on which the request was received by the Firm.
  • In any case, the final response to all requests shall not exceed fifteen (15) business days from the date on which the initial request was received by the Firm. 

2.6.2. Claims

The Firm provides mechanisms for the Holder, their successors in interest, representative and/or attorneys-in-fact, those who stipulated for another or for another, and/or the representatives of minors who are Holders, to file claims regarding: (i) Personal Data Treated by the Firm that must be subject to correction, update, suppression or revocation of the Authorization or (ii) the alleged non-compliance with the legal duties of the Firm. 

These mechanisms may be physical such as in-person processing, electronic through the Customer Service email protecciondedatos@bu.com.co for matters related to this Policy or by telephone on the service line (+57-601) 346 2011, in charge of receiving petitions, complaints and claims by telephone. 

Regardless of the medium, the Firm will keep proof of the claim and its response. Consequently, the following are the steps to follow for the submission of claims: 

  • The claim shall be made by means of a written request.
  • The request will be analyzed to verify the identification of the Holder. If the request is made by a person other than the Holder and it is not demonstrated that they act in representation of the Holder in accordance with current laws, the request will be rejected. For this purpose, the Firm may request the citizenship card or original identification document of the Holder, and the special, general powers of attorney or documents required as the case may be.
  • The claim must contain the following information: (i) Name and identification document number of the Holder. (ii) Contact details (physical and/or electronic address and telephone numbers). (iii) Documents that prove the identity of the Holder, or the representation of their representative. (iv) A clear and precise description of the Personal Data with respect to which the Holder seeks to exercise any of the rights. (v) A description of the facts giving rise to the claim and the objective pursued (update, correction, revocation, suppression, or compliance with duties). (vi) Documents that the claimant wishes to assert. (vii) Signature, email, name and identification number of the claimant of the claim.
  • If the claim or additional documentation is incomplete, the Firm will request the claimant only once within five (5) days following the receipt of the claim to remedy the deficiencies. If the claimant does not present the required documentation and information within two (2) months following the date of the initial claim, without the applicant presenting the required information, it shall be understood that the claim has been abandoned.
  • If for any reason the person who receives the claim within the Firm is not competent to resolve it, they will forward it to the Customer Service Analyst within two (2) business days following receipt of the claim, and will inform the claimant of said referral.
  • Once the claim is received with complete documentation, a legend stating 'claim in process' and the reason for it shall be included in the Database of the Firm where the Holder's Data subject to the claim resides, within a period not exceeding two (2) business days. This legend must be maintained until the claim is decided. 
  • The maximum term to address the claim shall be fifteen (15) business days counted from the business day following the date of its receipt. When it is not possible to address the claim within said term, the interested party shall be informed of the reasons for the delay and the date on which the claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the first term. 

2.6.3. Revocation

The Holder may revoke the Authorization for the Treatment of their Personal Data at any time, provided that a legal provision or a legal or contractual obligation does not prevent it. 

2.7. Security and Privacy of Information 

In furtherance of the principle of security and privacy, the Firm has adopted reasonable technical, administrative and human measures to protect the Personal Data of the Holders and prevent adulteration, loss, consultation, use or unauthorized or fraudulent access. Access to personal data is restricted to its Holders and to the persons authorized by the Firm in accordance with this Policy. The Firm will not allow access to this information by third parties under conditions different from those announced, except at the express request of the Holder or of persons legitimized in accordance with national regulations.

It is important to bear in mind that the internet is a global communication network that implies the transmission of information on a worldwide network. In this regard, despite the fact that the Firm has the necessary measures for the protection of Personal Data, it is possible that they may be affected by failures inherent to the internet. 

2.8. Transfer and Transmission of Personal Data 

The Firm, when it carries out or executes transfers or transmissions of personal data of the holders, will guarantee strict and effective compliance, in accordance with literal a) of article 26 of Law 1581 of 2012. 

2.9. Video Surveillance 

The Firm, through magnetic and/or technological media installed in the interior and exterior of its facilities, records daily videos or images of persons who enter or have access to the building where the services contemplated in the corporate purpose of the Firm are provided. Therefore, Brigard Urrutia will inform about the existence of these security and privacy mechanisms, through notices or signs, which will be located in different spaces of the building so that they are visually accessible to the holders. The notice will state that the purpose of the collection will be to provide security and privacy spaces to our holders and to protect the assets of the Firm. Likewise, the information collected may be used as evidence before any authority, in accordance with applicable regulations. 

Additionally, surveillance videos will guarantee the right to personal privacy. 

2.10. Effectiveness 

This Policy is effective as of March 1, 2022. Personal Data that is stored, used or transmitted will remain in our Database, based on the criteria of temporality and necessity, for the time necessary for the purposes mentioned in this Policy and the respective Authorization, for which they were collected. 

2.11. Modifications 

This Policy may be modified by the Firm when so required without prior notification, provided that the modifications are not substantial. Otherwise, they will be previously communicated to the Holders. 

2.12. Annexes 

Annex A: Specific purposes. 

3. References

  • Article 15 of the Political Constitution of Colombia. Right to personal and family privacy and to one's good name.
  • Single Circular of the Superintendence of Industry and Commerce.
  • Law 1581 of 2012. By which general provisions are issued for the protection of personal data.
  • Decree 1074 of 2015. By which Law 1581 of 2012 is partially regulated.
  • Circular 886 of 2014. By which article 25 of Law 1581 of 2012, related to the National Database Registry, is regulated.
  • External Circular 02 of 2015. By which the Superintendence of Industry and Commerce issued instructions to those responsible for the treatment of personal data, private legal entities registered in the chambers of commerce and mixed economy companies, for purposes of registering their databases in the national database registry as of November 9, 2015.
  • Decree 1074 of 2015. By means of which the Single Regulatory Decree of the Commerce, Industry and Tourism Sector is issued. 
  • Standard ISO/IEC 27701: Extension of Standard ISO/IEC 27001 and ISO/IEC 27002, Requirements for the implementation of an Information Privacy Management System. 

ANNEXE A

Specific purposes
Brigard & Urrutia Abogados S.A.S., (hereinafter "The Firm") carries out the treatment of Personal Data, taking into account the following specific purposes: 

1. CLIENTS AND POTENTIAL CLIENTS: 

  • Comply with legal and contractual obligations.
  • Duly execute the contracted services, as well as their invoicing and collection.
  • Promote all services offered by the Firm.
  • Comply with Colombian tax regulations.
  • Send information related to advisory and products and services.
  • Validate legal and commercial capacity.
  • Control statistical purposes.
  • Comply with the requirements of administrative or judicial authorities.
  • Carry out validations to comply with the regulation on prevention of money laundering, financing of terrorism and financing of the proliferation of weapons of mass destruction, as well as the regulation on prevention of corruption. 

2. SHAREHOLDERS:

  • Comply with legal and contractual obligations.
  • Execute procedures related to the sale, assignment or transfer of shares.
  • Make registrations before the commercial registry of the Chamber of Commerce.
  • Carry out activities related to the payment of dividends. 

3. SUPPLIERS AND POTENTIAL SUPPLIERS:

  • Comply with Colombian tax regulations.
  • Undergo the counterparty validation process. 
  • Comply with legal and contractual obligations.
  • Report to authorities.
  • Make payments to suppliers.
  • Carry out validations to comply with the regulation on prevention of money laundering, financing of terrorism and financing of the proliferation of weapons of mass destruction, as well as the regulation on prevention of corruption. 

4. EMPLOYEES AND CANDIDATES:

  • Comply with legal and contractual obligations.
  • Carry out wellness activities.
  • Develop and manage recruitment, selection and hiring processes.
  • Evaluate the performance of employees, as well as promotion processes.
  • Manage attendance control, compliance with working hours, physical and logistical access to facilities and assets of the company.
  • Assess risks.
  • Conduct Organizational Climate surveys.
  • Train our employees.
  • Develop internal campaigns. 

4. Change Log 

Version 

Change Description 

Approved by 

Date 

0 

Creation 

Natalia Muriel – General Secretary and Compliance Officer 

25/07/2018 

1 

Review and update of the policy content. 

Board of Directors 

1/07/2020 

2 

Review and update of the policy content. 

Board of Directors 

15/02/2022 

3 

Review and update of the policy content. 

Board of Directors 

25/02/2025