
Finantodo, a strategic ally
PERSONAL DATA PROCESSING POLICY - FINANTODO SAS
1. GENERALITIES OF THE POLICY
OBJECTIVE
Define the guidelines for the proper management of the data of the data subjects in Finantodo SAS.
SCOPE
This Personal Data Processing Policy applies to all employees involved in the collection, storage, use, circulation, deletion of personal data and in all activities that constitute personal data processing.
DEFINITIONS
- Authorization: Prior, express and informed consent of the Data Subject to carry out the Processing of personal data;
- Database: An organized set of personal data that is subject to processing;
- Personal data: Any information linked to or that can be associated with one or more specific or identifiable natural persons;
- Public data: This is data classified as such according to the mandates of the law or the Political Constitution, and any data that is not semi-private, private, or sensitive. Public data includes, among others, data relating to a person's marital status, profession or occupation, status as a merchant or public servant, and data that can be obtained without restriction. By their nature, public data may be contained in, among other sources, public registries, public documents, official gazettes, and bulletins.
- Sensitive data: Sensitive data is understood to be data that affects the privacy of the Data Subject or whose misuse may generate discrimination, such as data that reveals racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in trade unions, social or human rights organizations or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data relating to health, sex life and biometric data;
- Data Processor: Natural or legal person, public or private, who, alone or in association with others, carries out the processing of personal data on behalf of the Data Controller;
- Minor: This category includes children and adolescents. According to the Children and Adolescents Code, a child is defined as a person between 0 and 12 years old, and an adolescent as a person between 12 and 18 years old.
- Data Controller: Natural or legal person, public or private, who alone or jointly with others, decides on the database and/or the processing of the data;
- Data Subject: Natural person whose personal data is subject to Processing.
- Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation or deletion of such data.
2. RESPONSIBLE PARTIES
| ROL | RESPONSABLE |
|---|---|
| POLITICAL LEADER | Data Protection Officer |
| POLICY IMPLEMENTERS | All employees. |
3. DESCRIPTION
- FINANTODO SAS, with registered address in the city of Bogotá at Calle 100 # 7A – 81, Floor 6, Telephone: 3908484, hereinafter referred to as the Company, and its website www.finantodo.com, hereinafter referred to as the Portal, hereby makes known the policies for the use, privacy, processing, and confidentiality of personal data. These policies apply to all users, clients, and individuals who have provided their personal data, who are the owners of personal data acquired by the Company under commercial agreements, conventions, cooperation, and/or alliances, who use the Portal in any way, and who acquire any product or service from the Company through any existing channel. These policies also outline the rights of users and/or clients to know, update, and rectify the information held about them.copIlen about them in databases or files and the right to information.
- The company and its portal may request personal data and any information linked to or that may be associated with users and/or customers from users and/or customers, always referring to it as personal data, but sensitive data is not requested, nor are records or any data of that nature kept.
- Taking into account the Privacy policies, by using, accessing, or registering in any other way and by continuing to browse the portal or by providing data and information, users and/or clients express their authorization and express consent for the company to carry out the processing of the personal data and information provided.
3.1. Principles
FINANTODO SAS, in the course of its activities, collects, uses, stores, transmits, and performs various operations on the personal data of Data Subjects. All Personal Data Processing carried out by FINANTODO SAS is governed by the following principles:
- Principle of Legality: The processing of data is a regulated activity that must comply with the provisions of the Statutory Law on Data Protection, Decree 1377 of 2013 Compiled in Chapter 25 of Decree 1074 of 2015 and other provisions that develop it.
- Principle of Freedom: All processing of personal data is carried out once the prior, express and informed authorization of the data subject has been obtained, unless the law establishes an exception to this rule.
- Principle of Purpose: All Personal Data Processing activities must adhere to the purposes stated in this Policy, in the Authorization granted by the Data Subject, or in the specific documents governing each type or process of Personal Data Processing. The specific purpose of the Processing of Personal Data must be communicated to the Data Subject at the time their Authorization is obtained. Personal Data may not be processed for purposes other than those communicated to and consented to by the Data Subjects.
- Principle of veracity or quality: Personal Data subject to Processing must be truthful, complete, accurate, up-to-date, verifiable, and understandable. When in possession of partial, incomplete, fragmented, or misleading Personal Data, FINANTODO SAS must refrain from Processing it or request the data subject to complete or correct the information.
- Principle of Transparency: When requested by the Data Subject, FINANTODO SAS must provide information about the existence of Personal Data concerning the requester.
- Principle of Restricted Access and Circulation: Personal Data may only be processed by authorized FINANTODO SAS personnel or those whose duties include carrying out such activities. Personal Data may not be disclosed to individuals who are not authorized or have not been empowered by FINANTODO SAS to process it. Personal data, except for public information, may not be available on the Internet or other means of mass dissemination or communication, unless access is technically controllable to ensure restricted access only to Data Subjects or authorized third parties in accordance with the Law.
- Principle of Confidentiality: All Personal Data that is not Public Data must be treated as confidential by the Data Controllers, even after the contractual relationship or link between the Data Subject and FINANTODO SAS has ended. Upon termination of said link, such Personal Data must continue to be processed in accordance with this Policy and the Law.
- Principle of Necessity: Personal Data may only be processed for as long as and to the extent that the purpose of its processing justifies it.
- Security Principle: Information subject to processing is handled with the necessary technical, human, and administrative measures to ensure the security of records, preventing their alteration, loss, unauthorized or fraudulent access, use, or disclosure. Therefore, the corresponding security measures are implemented and communicated to all personnel with direct or indirect access to the data. Users accessing the company's information systems must be aware of and comply with the security rules and measures applicable to their roles. These rules and security measures are outlined in FT-GA-R008 - Finantodo Information Security Policy, which is mandatory for all users and personnel of FINANTODO SAS. Any modifications to the rules and measures regarding personal data security by the company are communicated to users.
3.2. Information Processing
The purpose and use of the information and data provided are used for the provision of contracted services, as well as for offering products and services, sending promotions, information on products and services and general processing related to this and also for the following purposes:
3.2.1. Candidates, workers and former workers:
- The processing of essential personal data of candidates, employees, and former employees is governed by law and the company's status, and includes all data necessary for fulfilling its obligations as an employer. The information processed is used, among other things, for:
- To enter into the employment contract and proceed with the affiliations to the comprehensive social security and parafiscal system, as well as to the severance fund administrator.
- To comply with the legal and extra-legal labor obligations, if any, arising from the employment contract.
- Make reports to administrative, police and judicial authorities, when they require it.
- Benefits administration; payroll processing; recognition of legal obligations, audits; accounting reports; statistical analysis; interaction with entities that manage or may manage the general social security system, parafiscal collection entities, Ministry of Labor, UGPP, Superintendency of Health, operator of the Comprehensive Contribution Settlement Form, Superintendency of Industry and Commerce, Regional and National Board of Disability Rating; training and development; access to agreements with third parties; among other processes inherent to personnel administration.
- The others are related to events in which information may be shared.
The information provided by active workers, including that of their family group and beneficiaries, remains stored physically, in electronic media or other means that are available for the term indicated by labor and accounting regulations.
- The information provided by applicants or candidates to be employees of the company and that is recopThis process, carried out during the selection process, aims to verify, compare, and evaluate the job and personal skills of prospective candidates against FINANTODO SAS's selection criteria; schedule interviews and administer tests to applicants; evaluate the applicants' selection tests directly or through third parties; report the overall results of the selection process; consult and evaluate all information about the applicant stored in legitimately established judicial or security background databases, whether state or private, national or foreign; and in any case, the information is deleted from the company's information systems when such applicants or candidates are not selected by the company and/or when, for any reason, an employment contract is not signed with the company.
- Information provided by former employees of the company during the term of an employment relationship is kept by the company in accordance with applicable regulations on commercial, labor and occupational risk and occupational health and safety management and is stored physically, electronically or by other means as provided.
3.2.2. providers
The Personal Data processed by FINANTODO SAS must be used strictly and solely for the purposes indicated below. Likewise, those responsible for processing or third parties who have access to the Personal Data must limit the processing to the following purposes:
- Manage all the information necessary for compliance with tax obligations and commercial, corporate and accounting records.
- Comply with internal processes regarding the management of suppliers and contractors.
- The process of archiving, updating systems, and protecting and safeguarding information and databases.
- Processes for development or operational purposes and/or systems administration.
- Consult, compare and evaluate all information about the supplier stored in legally constituted judicial or security background databases, whether state or private, national or foreign, or any commercial or service database that allows for a comprehensive assessment of the supplier's behavior, including consultations on lists for the prevention and control of money laundering and terrorist financing.
- Analyze, process, evaluate and compare the information provided by the suppliers.
- Sending information of commercial or non-commercial interest and invitations to events scheduled by Finantodo SAS.
- To comply with Colombian or foreign law and the orders of judicial and/or administrative authorities.
- Issuance of certifications relating to the commercial relationship between the data subject and Finantodo SAS.
- Delivery of information to inspection, surveillance, control, regulatory bodies or internal or external auditors.
- Make payments for services provided or products sold by the supplier.
- Preparation of invitations to quote.
- Other purposes that may be necessary to comply with legal and regulatory obligations.
3.3 customers
The personal data processed by Finantodo SAS must be strictly and solely for the purposes indicated below:
- Establish fluid, current and repeated communication in relation to services, products, promotions, programming and everything related to the corporate purpose.
- To carry out marketing, promotional, and/or advertising activities, whether for ourselves or third parties, repeatedly; sales, invoicing, collections, payment processing, scheduling, market research, service improvement, verifications and inquiries, monitoring, behavior analysis, payment method activation, fraud prevention, and any other activities related to current and future products and services, for the fulfillment of contractual obligations and the company's purpose, which users and/or clients expressly authorize to be sent through any means of communication, including virtual platforms, social media, email, voice, SMS, and any other method developed for the mass or personalized distribution of information. This also includes scheduling payments on private calendars on mobile and electronic devices.
- Evaluate the quality of products and services and conduct studies on consumption habits, preference, purchase interest, product testing, concept, service evaluation, satisfaction and other related services and products.
- To take all necessary steps to fulfill the obligations inherent to the services and products contracted with the company.
- Report on changes to products and services related to the ordinary course of business of the company.
- The control and prevention of fraud and money laundering, including, but not limited to, consultation of restricted lists, and all the necessary information required for SAGRILAFT.
- The data provided by the owner may be processed, collected, stored, used, circulated, deleted, shared, updated, transmitted, in accordance with the terms and conditions of the Privacy Policies indicated above as applicable, mainly to make it possible to provide its services, for reports to control and surveillance authorities, and also for use for administrative, commercial and advertising purposes and contact with the owners of the same.
- On this website, as a fundamental security principle, the privacy of data and information is paramount. Therefore, this information is used solely to provide better service to our clients, tailored to their interests and needs. For this reason, physical, electronic, and administrative security measures have been designed and implemented to protect the information.copThis information is collected in accordance with the Privacy Policy. These security measures are frequently reviewed to protect against unauthorized access, viewing, or use, alteration, loss, disclosure, and misuse of your information, and to maintain the accuracy and integrity of that information.
- Payment information is used to request payment authorization from the relevant entities. Therefore, information provided on the portal by users and/or customers, such as personal data, card numbers, and expiration dates, is never stored or recorded. Any transfer of this type of information to a third party or authorized entity is subject to confidentiality agreements, and users and/or customers authorize this processing.
- Due to the security measures in place on the portal, no information related to credit and/or debit cards, or any other electronic means of payment, is ever stored or saved. Therefore, the user and/or customer is obligated to enter all the data related to the card or means of payment used each time they make a transaction on the portal.
- The information provided by the user and/or client to access and use the portal is not disclosed in any way by the portal or the company. However, the user and/or client expressly authorizes the company to carry out any legal processing, commercial use, development, communication, as well as to share, assign, and transfer the information and personal data with any third-party entity or company that is in charge of or responsible for processing data and information, extending to them the express authorization granted by the data subject to carry out the processing of personal data.
- In accordance with the foregoing and having the authorization granted by the client and/or user for the processing of data and information, this authorization empowers the company to use the information received and entered by the user and/or client for marketing, statistical, survey, and customer service purposes related to its own affiliated or linked products, in order to offer services, offers, and promotions tailored to their profile. This includes sharing the information provided to third parties, suppliers, affiliates, etc., as appropriate for registration purposes. These third parties, suppliers, affiliates, etc., are subject to confidentiality agreements that prohibit the disclosure or unauthorized use of the information provided. Notwithstanding the foregoing, the authorization granted herein by the client and/or user extends to these third parties, suppliers, affiliates, and others, and may be revoked at any time by written communication. The email addresses included in the database may be used to contact you, reference you, send you offers, advertising, surveys, and other communications related to new services, promotions, suppliers, or to send you electronic messages or communications, unless you indicate your wish not to receive them. The user and/or client consents to the portal exchanging, reproducing, obtaining, processing, transferring, and disposing of the data and information of registered users and/or clients to third parties, their establishments, companies, and/or affiliated and/or participating and/or related entities, so that these third parties may offer products and/or services to the users and/or clients.
3.4. Processing of Personal Data of Minors
- In accordance with the provisions of the law, Finantodo SAS proceeds to process the personal information of children and adolescents, respecting their best interests and ensuring, in all cases, respect for their fundamental rights and minimum guarantees.
- In all cases where it is necessary to process the personal information of minors, the company will obtain the authorization of their legal representatives, who for this purpose are the father and/or mother or guardian.
3.5. Confidentiality of Information
The data provided by the user and/or client is protected by security measures designed to guarantee the confidentiality of the information within the systems, employing the most secure technology possible. This confidentiality is maintained even after the termination of the relationship that encompasses the processing of the data.
3.6. Rights of the Holders
Law 1266 of 2008 and Law 1581 of 2012 establish that the Holders of personal data have the following rights:
- To know, update, and rectify your personal data held by data controllers or processors. This right can be exercised, among other things, with respect to data that is partial, inaccurate, incomplete, fragmented, misleading, or whose processing is expressly prohibited or has not been authorized.
- Request proof of the authorization granted to the data controller except when expressly exempted as a requirement for processing, in accordance with the provisions of Article 10 of the aforementioned law.
- To be informed by the data controller or the data processor, upon request, regarding the use that has been made of your personal data.
- To file complaints with the Superintendency of Industry and Commerce for violations of the provisions of the aforementioned law and other regulations that modify, add to or complement it.
- To revoke authorization and/or request the deletion of data when the processing does not respect constitutional and legal principles, rights, and guarantees. Revocation and/or deletion is warranted when the Superintendency of Industry and Commerce has determined that the controller or processor has engaged in conduct contrary to the law and the constitution.
- Access your personal data that has been processed, free of charge. Additionally, Regulatory Decree 1377 of 2013 stipulates that data controllers must retain proof of the authorization granted by data subjects for the processing of their personal data.
Consultation and Complaint Procedure
- Holders can exercise their rights by sending a request to the email address juridicofinantodo@gmail.com stating the right being exercised.
- Inquiries are addressed within a maximum of ten (10) business days from the date of receipt. If it is not possible to address the inquiry within this period, the Data Subject will be informed, stating the reasons for the delay. In any case, the inquiry will be answered within five (5) business days following the expiration of the initial ten (10) business day period.
- Claims for correction, updating or deletion, or for alleged breach of any of the duties contained in the law, are processed under the following rules:
- The complaint must be submitted in writing to the Data Controller or the Data Processor, including the Data Subject's identification, a description of the facts giving rise to the complaint, the address, and any supporting documents. If the complaint is incomplete, the interested party will be notified within five (5) days of receipt of the complaint to correct the deficiencies. If the applicant fails to provide the required information within two (2) months of the notification, the complaint will be considered withdrawn. If the recipient of the complaint is not authorized to resolve it, they will forward it to the appropriate party within two (2) business days and inform the interested party of the situation.
- The maximum time to address the claim is fifteen (15) business days, starting from the day after the date of receipt. If it is not possible to address the claim within this period, the interested party will be informed of the reasons for the delay, and in any case, the claim will be answered within eight (8) business days following the expiration of the initial fifteen (15) business day period.
3.7. Person Responsible for Handling Inquiries and Complaints
The Data Protection Officer is responsible for defining, implementing and monitoring the actions required to guarantee this right to the Holders of personal data held by Finantodo SAS, in accordance with current regulations.
3.8. Cookies or Web Bugs
- The Finantodo SAS website does not use cookies or web beacons to collect personal user data. Their use is limited to facilitating user access to the website. Session cookies, which are not permanently stored on the user's device and disappear when the browser is closed, are used solely to collect technical information to identify the session in order to facilitate secure and efficient access to the website and provide better service.
- If you do not wish to allow the use of cookies, you can reject or delete existing ones by configuring your browser (Internet Explorer, Firefox, Safari, Chrome, among others) and disabling the browser's Java Script code in the security settings.
- Most web browsers allow you to manage your cookie preferences; however, please note that blocking cookies may affect or prevent the website from functioning correctly. Additionally, one of the third-party services that may be used to track activity related to the service is Google Analytics. Therefore, if you do not wish for this information to be collected and used, you can install an opt-out tool in your web browser, such as: tools.google.com/dlpage/gaoptout?hl=None.
3.9. Acceptance and Application of the Privacy and Confidentiality Policies
- Any user and/or client who accesses or uses the portal's services and/or makes use of any other type of product or service offered by the portal and/or the company through any existing or different channel or mechanism, accepts and is bound by the privacy and confidentiality policies established on the portal. This constitutes a legal agreement between the client and/or user and the company, and it is understood that these terms and conditions are expressly accepted and that the user agrees to them, as their consent is express and informed. Likewise, acceptance implies that the user and/or client authorizes the company and/or the portal to process their personal data.
- This privacy and confidentiality policy for personal data came into effect on February 22, 2013 and the database of the company FINANTODO SAS has a validity of Ten (10) Years counted from February 22, 2013, a period that will be automatically renewed unless there is a request from the owner of the information to proceed with its deletion.
4. CHANGE CONTROL
| DATE (dd-mm-yy) | VERSION | DESCRIPTION | RESPONSABLE | CARGO |
|---|---|---|---|---|
| Dec 12 19 | 1 | Code assignment | Alejandra Sarmiento | Head of Processes |
| 12-jul-22 | 2 | Update in accordance with Law 1581 of 2012 | Monica Moreno | Data Protection Officer |
| 30-jul-24 | 3 | Update the customer service channel, keeping the same email address registered in the SIC's RNBD portal | Laura González | Data Protection Officer |
| 20-ago-25 | 4 | Updated new address FINANTODO SAS | Laura González | Data Protection Officer |
| PREPARED | REVIEWED | APPROVED | |
|---|---|---|---|
| Name | Laura Gonzalez | Alejandra Sarmiento | Laura Gonzalez |
| Role | Data Protection Officer | Director of Quality and Projects | Data Protection Officer |
| Date (dd-mm-yy) | 20-ago-25 | 21-ago-25 | Sep 19 25 |

























































































