PERSONAL DATA PROCESSING POLICY

This Personal Data Processing Policy (the “Policy”) regulates the collection, storage, use, circulation, transmission, transfer, updating, rectification, deletion, and, in general, the processing of personal data carried out by José Francisco Acuña Vizcaya, an individual practicing professionally under the commercial name Bufete Acuña Vizcaya (hereinafter, the “Data Controller”), in accordance with Statutory Law 1581 of 2012, Decree 1074 of 2015, and any other provisions that modify, add to, substitute, or supplement them.

1. IDENTIFICATION OF THE DATA CONTROLLER

  • Data Controller: José Francisco Acuña Vizcaya
  • Commercial Name: Bufete Acuña Vizcaya
  • Domicile: Bogotá D.C., Colombia
  • Address: Av. Calle 19 No. 3A - 37, Office 902, Tower B
  • Email: [To be defined]
  • Telephone: [To be defined]

2. PURPOSE AND SCOPE

The purpose of this Policy is to inform data subjects of the guidelines applicable to the processing of information collected by the Data Controller through any physical or digital channel, including, among others, the website, forms, email, telephone calls, instant messaging, in-person or virtual meetings, physical or digital documents, and contractual, pre-contractual, employment, professional, or institutional relationships.

This Policy applies to all databases, both physical and digital, containing personal data processed by the Data Controller, in their capacity as data controller and, when applicable, as data processor.

This Policy is directed toward clients, potential clients, suppliers, contractors, candidates, employees, former employees, partners, journalists, academic or institutional contacts, website visitors, and, in general, any data subject whose personal data is processed by the Data Controller.

3. DEFINITIONS

For the purposes of this Policy, the following terms shall be understood as:

  • Authorization: The prior, express, and informed consent of the data subject to carry out the processing of their personal data.
  • Database: An organized set of personal data subject to processing.
  • Personal Data: Any information linked to or that can be associated with one or more identified or identifiable natural persons.
  • Public Data: Data categorized as such by law or the Constitution, as well as any data that is not semi-private, private, or sensitive.
  • Sensitive Data: Data affecting the privacy of the data subject or whose misuse may generate discrimination.
  • Data Processor: A natural or legal person, public or private, that independently or jointly with others processes personal data on behalf of the Data Controller.
  • Data Controller: A natural or legal person, public or private, that independently or jointly with others decides on the database and/or the processing of data.
  • Data Subject: The natural person whose personal data is subject to processing.
  • Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation, transmission, transfer, updating, rectification, or deletion.
  • Transmission: The processing of personal data involving the communication thereof within or outside the territory of Colombia to perform processing by the Data Processor on behalf of the Data Controller.
  • Transfer: Sending personal data to a recipient who, in turn, acts as a Data Controller.

4. APPLICABLE PROCESSING PRINCIPLES

The processing of personal data by the Data Controller shall be governed by the following principles:

  • Legality: Processing is a regulated activity subject to applicable legal provisions.
  • Purpose: Processing must serve a legitimate purpose, which shall be communicated to the data subject.
  • Consent / Freedom: Processing may only take place with the prior, express, and informed consent of the data subject, except where legally exempted.
  • Truthfulness or Quality: Information subject to processing must be truthful, complete, accurate, updated, verifiable, and understandable.
  • Transparency: The data subject may obtain information regarding the existence of data concerning them at any time.
  • Restricted Access and Circulation: Processing is subject to limits derived from the nature of personal data, as well as constitutional and legal provisions.
  • Security: Information subject to processing shall be handled with reasonable technical, human, administrative, and organizational measures to prevent its alteration, loss, unauthorized or fraudulent consultation, use, or access.
  • Confidentiality: All persons participating in the processing of non-public personal data are obligated to guarantee the secrecy of the information.
  • Temporality: Personal data shall be stored only for the reasonable and necessary period to fulfill the purposes justifying its processing, as well as any additional time required by legal, contractual, accounting, tax, evidentiary, or judicial obligations.
  • Necessity and Proportionality: The personal data processed must be strictly necessary for fulfilling the intended purposes.

5. SOURCES AND CHANNELS OF COLLECTION

The Data Controller may collect personal data through:

  • Physical or digital forms;
  • Website contact forms;
  • Emails sent to official accounts of the Data Controller or Bufete Acuña Vizcaya;
  • Telephone calls;
  • In-person or virtual meetings;
  • Messages sent via WhatsApp or other messaging channels enabled by the Data Controller;
  • Physical or digital documents provided by the data subject or authorized third parties;
  • Resumes/CVs received via email, referrals, or references;
  • Contracts, quotes, proposals, invoices, payment requests, and other commercial or professional documents;
  • Publicly accessible sources or legally available public information.
When the data subject voluntarily submits personal information through any of these channels, the Data Controller may process it to handle requests, follow up on matters, manage professional or contractual relationships, and fulfill the purposes outlined in this Policy.

6. DATA SUBJECT AUTHORIZATION

Without prejudice to statutory exceptions, the processing of personal data requires the prior, express, and informed authorization of the data subject.

Authorization may be obtained through any mechanism that allows for subsequent consultation, including:

  • Signed physical documents;
  • Digital forms;
  • Checkboxes on websites;
  • Emails;
  • Data messages;
  • Call recordings;
  • Contracts;
  • Unequivocal conduct by the data subject that allows for the reasonable conclusion that authorization was granted.
Authorization shall be understood as granted, among other instances, when the data subject submits an inquiry via email, fills out a form, sends a resume, requests contact, provides information for matter review, or enters premises with duly noticed video surveillance.

The Data Controller shall retain proof of authorization granted by the data subject whenever required by law.

7. CASES WHERE AUTHORIZATION IS NOT REQUIRED

Authorization from the data subject shall not be required in cases involving:

  • Information requested by a public or administrative entity acting within its legal functions or by court order;
  • Public data;
  • Medical or health emergencies;
  • Information processing authorized by law for historical, statistical, or scientific purposes;
  • Data relating to civil registry records of individuals;
  • Other cases provided for under applicable laws.
In all events, even when authorization is not required, processing must adhere to the principles and rules set forth in current regulations.

8. DUTY TO INFORM THE DATA SUBJECT

At the time of requesting authorization, or at the latest upon collecting data when applicable, the Data Controller shall clearly and explicitly inform the data subject regarding:

  • The specific processing to which their personal data will be subjected and its underlying purpose;
  • The optional nature of answering questions concerning sensitive data or data regarding children and adolescents;
  • The rights assisting them as a data subject;
  • The identification and contact information of the Data Controller.

9. PURPOSES OF PROCESSING

Personal data collected by the Data Controller may be processed for the following purposes, based on the category of the data subject:

9.1. Clients and Potential Clients

  • Responding to inquiries, requests, requirements, and meetings.
  • Conducting preliminary legal analysis of matters submitted to the Data Controller.
  • Contacting individuals interested in legal services offered by Bufete Acuña Vizcaya.
  • Managing pre-contractual, contractual, and professional relationships.
  • Providing legal advisory, consulting, defense, representation, or support services.
  • Preparing proposals, engagement letters, contracts, quotes, invoices, payment requests, and other service-related documents.
  • Managing payments, collections, billing, tax compliance, accounting, and administration.
  • Following up on matters, proceedings, inquiries, meetings, communications, and commitments made.
  • Maintaining internal contact records and professional networks.
  • Evaluating service quality and performing statistical, administrative, and process improvement analyses.
  • Sending institutional, legal, academic, newsletter, publication, event, conference, or firm activity information when proper authorization or legal basis exists.
9.2. Customer Support via Email, Telephone, and WhatsApp

  • Receiving, processing, and responding to requests sent to official firm channels.
  • Coordinating schedules for meetings, calls, consultations, or personalized support.
  • Providing continuity to initial inquiries and, when appropriate, forwarding information to direct channels (including WhatsApp) for agile management.
  • Maintaining communication traceability for service, compliance, and evidentiary purposes.
9.3. Candidates

  • Receiving and reviewing resumes and professional profiles sent via email or other means.
  • Contacting candidates for interviews, validations, or selection stages.
  • Verifying provided information, references, experience, and educational background when legally permissible.
  • Retaining resumes for future selection processes when authorized or backed by a legal basis.
9.4. Employees and Former Employees

  • Fulfilling obligations derived from employment relationships.
  • Managing affiliations, payroll, certifications, social security, tax obligations, and other statutory duties.
  • Implementing internal policies, occupational health and safety procedures, performance evaluations, and personnel management.
  • Handling emergencies and contacting designated emergency contacts.
  • Retaining physical and digital documentation for legal, evidentiary, and administrative purposes.
9.5. Suppliers and Contractors

  • Managing onboarding, verification, contracting, monitoring, and payment processes.
  • Verifying financial, tax, banking, corporate, or compliance information.
  • Performing due diligence and screening against restrictive lists or risk prevention databases where applicable.
  • Maintaining records and documentation of commercial or contractual relationships.
9.6. Journalists, Partners, and Academic/Institutional Contacts

  • Sharing institutional, legal, or academic information regarding firm activities, publications, events, awards, or speaking engagements.
  • Sending invitations to events, academic symposia, or institutional functions.
  • Managing corporate communications and professional relationships.
9.7. Website Visitors

  • Processing forms or requests submitted through the website.
  • Managing contact resulting from website interactions.
  • Implementing security measures, fraud prevention, monitoring, and operational continuity.

10. PROCESSING OF SENSITIVE DATA

The Data Controller may process sensitive data only in cases permitted by law and when such processing is necessary, relevant, and proportionate to the purpose communicated to the data subject.

Whenever sensitive data is collected, the Data Controller shall:

  • Inform the data subject that they are not required to authorize its processing;
  • Explicitly and clearly inform them in advance about the specific sensitive data collected and its intended purpose;
  • Obtain express authorization from the data subject when legally required;
  • Limit processing strictly to what is necessary.
Sensitive data may be processed, among other circumstances, in cases involving:

  • Health information within an employment context or during emergency situations;
  • Photographs, recordings, or biometric data for security and access control;
  • Information necessary for structuring, defending, or representing legal, judicial, disciplinary, administrative, or arbitral matters, provided legal authorization exists.

11. PROCESSING OF DATA CONCERNING CHILDREN AND ADOLESCENTS

The processing of personal data belonging to children and adolescents shall take place strictly in cases authorized by law, respecting their best interests and guaranteeing full protection of their fundamental rights.

When processing such information becomes necessary, authorization shall be requested from the legal representative, taking into consideration, whenever possible, the minor’s opinion according to their level of maturity.

12. VIDEO SURVEILLANCE

The Data Controller maintains or may maintain video surveillance systems within its offices or facilities.

Images collected serve the following purposes:

  • Protecting the safety of individuals, property, documents, and facilities;
  • Controlling access to facilities;
  • Supporting internal investigations;
  • Serving as evidentiary support before competent authorities when applicable.
Images shall be retained for a maximum period of ninety (90) calendar days, unless longer retention is required as evidence in a claim, investigation, judicial, administrative, or disciplinary proceeding.

Where access control or private security services operate, third parties involved must observe this Policy and instructions issued by the Data Controller, without prejudice to statutory obligations applicable to controllers and processors.

13. TRANSFERS, TRANSMISSIONS, AND DISCLOSURE OF INFORMATION

The Data Controller may transmit or transfer personal data within or outside Colombia when necessary for:

  • Cloud storage;
  • Website hosting;
  • Corporate email services;
  • Digital messaging and support tools, including WhatsApp or equivalent platforms;
  • Document management;
  • Cybersecurity;
  • Administrative, technological, accounting, or contractual support;
  • Legitimate professional partnerships or support;
  • Compliance with legal obligations or requests from competent authorities.
When third parties act on behalf of the Data Controller as data processors, reasonable contractual, technical, and administrative measures shall be adopted to ensure data is processed in accordance with this Policy and applicable law.

Information may be provided to:

  • Data subjects, their successors, or duly accredited representatives;
  • Public or administrative entities exercising legal functions or court orders;
  • Third parties authorized by the data subject or by law;
  • Data processors formally engaged by the Data Controller.

14. RIGHTS OF DATA SUBJECTS

The data subject has the right to:

  • Access, update, and rectify their personal data;
  • Request proof of authorization granted, when applicable;
  • Be informed, upon request, regarding the usage given to their personal data;
  • File complaints with competent authorities for violations of applicable data protection laws, after having exhausted the consultation or claim process before the Data Controller;
  • Revoke authorization and/or request deletion of data when legally appropriate;
  • Access free of charge their personal data undergoing processing.

15. DUTIES OF THE DATA CONTROLLER

The Data Controller shall comply with the following duties, among others:

  • Guarantee the data subject full and effective exercise of their habeas data rights;
  • Request and retain copies of authorizations when required;
  • Properly inform the data subject of the purpose of collection and their rights;
  • Maintain information under reasonable security conditions;
  • Ensure that information provided is truthful, complete, accurate, updated, verifiable, and understandable;
  • Rectify incorrect information;
  • Process consultations and claims within statutory deadlines;
  • Adopt internal procedures to ensure proper legal compliance;
  • Inform the data subject, upon request, about the use of their data;
  • Report security code violations and data management risks to competent authorities when legally required;
  • Require data processors to respect information security and privacy standards.

16. DUTIES OF DATA PROCESSORS

Data processors—and the Data Controller when acting as a processor—shall fulfill the following duties:

  • Guarantee the data subject full and effective exercise of their habeas data rights;
  • Retain information under required security conditions;
  • Perform timely updates, rectifications, or deletions of data;
  • Process consultations and claims submitted by data subjects;
  • Allow access to information only to authorized personnel;
  • Report security code violations and data management risks to competent authorities when legally required;
  • Verify that the data controller has obtained proper authorization when mandatory.

17. PERSON OR CHANNEL RESPONSIBLE FOR HANDLING REQUESTS, CONSULTATIONS, AND CLAIMS

The Data Controller, directly or through a designated person, shall handle requests, inquiries, claims, and petitions related to personal data protection through the following channels:

  • Email: [To be defined]
  • Telephone: [To be defined]
  • Physical Address: Av. Calle 19 No. 3A - 37, Office 902, Tower B, Bogotá D.C., Colombia

18. PROCEDURE FOR CONSULTATIONS

The data subject, their successors, representative, or duly accredited attorney-in-fact may consult the personal information residing in the Data Controller's databases.

Consultations must contain at a minimum:

  • Name and identification of the data subject (and representative/successor, if applicable);
  • Clear description of the information requested;
  • Contact details to receive the response;
  • Supporting documents proving identity or legal representation.
Consultations shall be answered within a maximum period of ten (10) business days from the date of receipt. When impossible to respond within said period, the interested party shall be notified prior to expiration, stating reasons for delay and the expected response date, which may not exceed five (5) business days following the initial deadline.

19. PROCEDURE FOR CLAIMS

Data subjects, their successors, representatives, or attorneys-in-fact who consider that information held in a database should be corrected, updated, or deleted, or who note alleged non-compliance with statutory duties, may file a claim with the Data Controller.

The claim must contain at a minimum:

  • Identification of the data subject;
  • Contact details;
  • Clear description of the facts giving rise to the claim;
  • Supporting documentation, if applicable;
  • Specific request.
If the claim is incomplete, the applicant will be required within five (5) business days following receipt to cure defects. If two (2) months elapse from the request date without the applicant providing the requested information, the claim shall be deemed abandoned.

Once a complete claim is received, a tag reading “claim in progress” along with the reason shall be added to the database within two (2) business days and maintained until resolved.

The maximum period to resolve a claim is fifteen (15) business days counted from the business day following receipt. If impossible to respond within said timeframe, the interested party shall be informed of the reasons for delay and the expected resolution date, which may not exceed eight (8) business days following initial deadline expiration.

20. REVOCATION OF AUTHORIZATION AND DELETION OF DATA

Data subjects may revoke authorization and/or request deletion of their personal data when legally permissible.

Deletion shall not apply, among other cases, when:

  • The data subject has a legal or contractual duty to remain in the database;
  • Data elimination hinders judicial or administrative proceedings;
  • Data is required to fulfill legal, contractual, accounting, tax, evidentiary, or legal defense obligations;
  • Data is necessary to protect legally protected interests of the data subject or Data Controller.

21. PERSONAL DATA INCIDENT MANAGEMENT PROCEDURE

An incident is understood as any anomaly, event, or circumstance affecting or capable of affecting the security of databases or information contained therein.

Anyone becoming aware of a personal data incident must report it immediately to the Data Controller or designated officer to adopt measures necessary to contain, analyze, mitigate, and document the incident.

When an breach creates risks to data management or constitutes a material security breach, the Data Controller shall take appropriate steps and, when legally required, inform competent authorities.

Except as required by law or court order, technical, operational, or security details concerning data incidents shall not be disclosed beyond what is strictly necessary for management, mitigation, or legal compliance.

22. INFORMATION SECURITY AND CONFIDENTIALITY

The Data Controller adopts reasonable technical, human, administrative, and organizational measures to protect personal data against alteration, loss, unauthorized consultation, use, or fraudulent access.

Persons participating in processing non-public personal data remain bound to preserve confidentiality even after their relationship with the Data Controller ends, unless a legal duty requires disclosure.

23. EFFECTIVE DATE AND DATA RETENTION

This Policy becomes effective upon publication.

Personal data shall be stored for as long as necessary to fulfill communicated purposes, while the relationship with the data subject persists, and for any additional period necessary to comply with legal, contractual, accounting, tax, archival, evidentiary, or judicial defense obligations.

Any material changes to this Policy will be communicated to data subjects through the Data Controller's website or other appropriate means.

Effective Date: August 16, 2026
Last Updated: August 16, 2026

Copyright © Acuña Vizcaya 2026