AUTHORIZATION FOR DATA PROCESSING
I have been informed (a) by MariaCe Posada Gatos y Perros (Responsible for the treatment) of the following: (i) The data provided in this document will be processed for the following purposes: Send or use the information for contractual purposes, customer service , Marketing (Such as consumption analysis, brand traceability, among others), Commercial, (Such as benefits, promotions, discounts, current campaigns, promotional events, writings, images, data messages, allied brands and own brand programs or from allies, among others), update data and provide relevant information; Consultation to answer questions about products and services offered, conducting studies for statistical purposes, customer knowledge. Information, to inform the owners of the data about news, products, services and special offers, for the development of activities related to telephone service, collections or others of a similar nature. Allowing you to transfer or transmit the data or partial or total information to its subsidiaries, businesses, companies and / or affiliated entities and strategic or commercial allies that operate or not in another jurisdiction or Colombian territory. (ii) It is optional to answer questions about sensitive data or minors; (iii) As the owner of the data and/or representative of the minor, I have the rights to know, update, rectify or delete my information or revoke the authorization granted; (iv) If my request is not resolved directly, and subsidiarily, I have the right to file complaints with the Superintendence of Industry and Commerce, in accordance with Law 1581 of 2012, Decree 1377 of 2013 and other complementary regulations; (v) I can exercise my rights and obligations strictly observing the Data Treatment Policy of MariaCe Posada Gatos y Perros. Available at www.mariaceposada.com and by email email@example.com. I declare that the supply of third-party data has been done with their unequivocal and express authorization.
INTERNAL MANUAL OF POLICIES AND PROCEDURES ON THE PROTECTION OF PERSONAL DATA OF MARIACE POSADA CATS AND DOGS
This personal data protection policy is carried out by MARIACE POSADA GATOS Y PERROS to comply with article 15 of the Constitution, Law 1581 of 2012, Decree 1377 of 2013 and other provisions that regulate the duties of those Responsible and In Charge of the Processing of personal data, among which the adoption of an internal manual of policies and procedures to guarantee adequate compliance with the rights of the Holders of personal data stands out.
SECTION I. GENERAL PROVISIONS
FIRST: OBJECT. Through this manual, a series of principles, rules and procedures are established to guarantee the Right of Habeas Data of the holders of personal data for which MARIACE POSADA GATOS Y PERROS is Responsible or In Charge of Treatment.
- Authorization: Prior, express and informed consent of the Owner to carry out the Processing of personal data;
- Database: Organized set of personal data that is subject to Treatment;
- Personal data: Any information linked or that can be associated with one or several determined or determinable natural persons;
- Sensitive personal data: any information that affects the privacy of the Owner or whose improper use may generate discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership of unions, social organizations, of human rights or that promotes the interests of any political party or that guarantees the rights and guarantees of opposition political parties, as well as data related to health, sexual life and biometric data. MARIACE POSADA GATOS Y PERROS will not process sensitive data;
- Public personal data: It is the personal data classified as such by the Political Constitution or the Law, or that does not constitute private or sensitive personal data. Public personal data are those contained in registries, documents, gazettes, bulletins and databases of public access such as those referring to the civil registry, the commercial registry, the single automotive registry, judicial and disciplinary records, enforceable judicial sentences, and the data contained in judicial processes and judicial procedures on which there is no legal reserve or on which the publicity of personal data is predicated;
- Private data: It is the data that due to its intimate or reserved nature is only relevant to The Holder;
- Treatment Manager: Natural or legal person, public or private, that by itself or in association with others, performs the Processing of personal data on behalf of the Treatment Manager. MARIACE POSADA CATS AND DOGS and its employees are data processors;
- Responsible for the Treatment: Natural or legal person, public or private, that by itself or in association with others, decides on the database and/or the Treatment of the data. MARIACE POSADA GATOS Y PERROS, will be responsible for the treatment, unless it is carried out for third parties;
- Owner: Natural person whose personal data is subject to Treatment. The clients of MARIACE POSADA GATOS Y PERROS, employees, distributors, and people who participate in market studies are part of MARIACE POSADA GATOS Y PERROS;
- Treatment: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion;
- Transmission: Treatment of personal data that implies a transmission of the same within and outside of Colombia;
- Transfer: Sending personal data made by the Responsible or the Manager to a third party who will assume the role of Responsible;
- Privacy Notice: Physical, electronic or any other format document generated by the Responsible Party that is made available to the Owner for the Processing of their personal data. In the Privacy Notice, the Owner is informed of the information regarding the existence of the information Treatment policies that will be applicable to him, the way to access them and the characteristics of the Treatment that is intended to be given to personal data.
WARNING: In case of doubts about the role of MARIACE POSADA GATOS Y PERROS within the data processing, it is recommended to present a legal consultation.
THIRD: PRINCIPLES. The principles established below constitute the foundation of the personal data protection policy. In case of doubt about the interpretation of the provisions contained in this manual, the principles will be used to find the meaning of the rule to apply. These are:
- Principle of legality: Treatment is a regulated activity that must be subject to the provisions of the Law and other provisions that develop it. The personal data protection policy of MARIACE POSADA GATOS Y PERROS is governed by articles 15 and 20 of the Political Constitution, Law 1581 of 2012, Decrees 1377 of 2013 and 886 of 2014 compiled in Decree 1074 of 2015, the ruling C-748 of 2011 and the circulars issued by the Superintendence of Industry and Commerce, as well as the provisions that modify, replace or repeal them;
- Principle of purpose: The Treatment must obey a legitimate purpose in accordance with the Constitution and the Law, which must be informed to the Holder. As a general rule, the purpose of the Treatment will be the development of the corporate purpose of MARIACE POSADA GATOS Y PERROS. However, the treatment may have other purposes, as long as those are indicated to the Holder of the information.
- Principle of freedom: The Treatment can only be exercised with the prior, express and informed consent of the Holder. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that relieves consent;
- Principle of veracity or quality: The information subject to Treatment must be true, complete, exact, updated, verifiable and understandable. The Processing of partial, incomplete, fractional or misleading data is prohibited;
- Principle of transparency: In the Treatment, the right of the Holder to obtain from the Treatment Manager or the Treatment Manager, at any time and without restrictions, information about the existence of data that concerns him must be guaranteed;
- Principle of access and restricted circulation: The Treatment is subject to the limits that derive from the nature of the personal data, from the provisions contained in the Law and the Constitution. In this sense, the Treatment can only be done by the staff of MARIACE POSADA GATOS Y PERROS, or by authorized third parties;
Personal data, except for public information, may not be available on the Internet or other means of dissemination or mass communication, unless access is technically controllable to provide restricted knowledge only to the Holders or authorized third parties;
- Principle of security: The information subject to Treatment by the Responsible or Person in Charge of the same must be handled with the technical, human and administrative measures that are necessary to grant security to the records avoiding their adulteration, loss, consultation, use or unauthorized access or fraudulent;
- Principle of confidentiality: All persons involved in the Processing of personal data that are not of a public nature are obliged to guarantee the confidentiality of the information, even after the end of their relationship with any of the tasks included in the Treatment, and may only Provide or communicate personal data when it corresponds to the development of the activities authorized in this law and in its terms.
FOURTH: DATABASES. The policies and procedures contained in this manual apply to the databases managed by the company, and which will be registered in accordance with the provisions of Law 1581 of 2012, Decree 886 of 2014. The data stored by MARIACE POSADA GATOS Y DOGS must be deleted when the purposes of the Treatment are fulfilled, except that they must be kept for the fulfillment of a contractual or legal obligation.
SECTION II: RIGHTS AND DUTIES
FIFTH: RIGHT OF THE HOLDERS OF THE INFORMATION. In accordance with the provisions of article 8 of Law 1581 of 2012, the Holder of personal data has the following rights:
- Know, update and rectify your personal data against MARIACE POSADA GATOS Y PERROS. This right may be exercised, among others, against partial, inaccurate, incomplete, fractioned, misleading data, or those whose Treatment is expressly prohibited or has not been authorized;
- Request proof of the authorization granted MARIACE POSADA GATOS Y PERROS, except when expressly excepted as a requirement for Treatment, in accordance with the provisions of article 10 of Law 1581 of 2012;
- To be informed by MARIACE POSADA GATOS Y PERROS of the Treatment, upon request, regarding the use that has been given to personal data;
- Submit complaints to the Superintendence of Industry and Commerce for violations of the provisions of Law 1581 of 2012 and other regulations that modify, add or complement it;
- Revoke the authorization or request the deletion of the data when the principles or rights are not respected in the Treatment. In case of conflict between MARIACE POSADA GATOS Y PERROS and the Holder, the revocation or deletion will proceed when the Superintendency of Industry and Commerce has determined that in the Treatment MARIACE POSADA GATOS Y PERROS have incurred in conduct contrary to Law 1581 of 2012 to the Constitution;
- Free access to your personal data that have been processed.
SIXTH: DUTIES OF MARIACE POSADA CATS AND DOGS IN RELATION TO THE PROCESSING OF PERSONAL DATA.
MARIACE POSADA GATOS Y PERROS, as the Data Controller or Manager, undertakes to permanently comply with the following duties in relation to the Processing of personal data:
- Guarantee the Holder, at all times, the full and effective exercise of the right of habeas data;
- Request and keep a copy of the respective authorization granted by the Owner;
- Duly inform the Holder about the purpose of the collection and the rights that assist him by virtue of the authorization granted;
- Keep the information under the necessary security conditions to prevent its adulteration, loss, consultation, use or unauthorized or fraudulent access;
- Guarantee that the information provided to the Manager or the Treatment Manager, as the case may be, is true, complete, accurate, updated, verifiable and understandable;
- Update the information, communicating in a timely manner to the person in charge or person in charge of the treatment, as the case may be, of all the news regarding the data that he has previously provided and adopt the other necessary measures so that the information provided to him is kept updated;
- Rectify the information when it is incorrect and communicate what is pertinent to the Treatment Manager;
- Provide the Person in Charge or Responsible for Treatment, as the case may be, only data whose Treatment is previously authorized in accordance with the provisions of the Law;
- Demand from the Person in Charge or Responsible for Treatment, as the case may be, and at all times, respect for the security and privacy conditions of the Owner's information;
- Process the queries and claims formulated in the terms indicated in articles 14 and 15 of Law 1581 of 2012;
- Inform the Person in Charge or Responsible for Treatment, as the case may be, when certain information is under discussion by the Holder, once the claim has been filed and the respective procedure has not been completed;
- Inform at the request of the Owner about the use given to their data;
- Inform the data protection authority when there are violations of the security codes and there are risks in the administration of the information of the Holders;
- Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce;
- Update the information reported by the Persons Responsible or in Charge of Treatment within five (5) business days from its receipt;
- Register in the database the legend "claim in process" in the manner in which it is regulated in Law 1581 of 2013, in case of claims by the Holder;
- Allow access to information only to people who may have access to it;
- Register the databases in the National Registry of Databases.
Paragraph. In the event that the qualities of Treatment Manager and Treatment Manager concur in the same person, compliance with the duties provided for each one will be required.
SEVENTH: SPECIAL TREATMENT OF CERTAIN PERSONAL DATA. MARIACE POSADA GATOS Y PERROS will not be responsible or in charge of the Processing of data on sensitive information and minors.
SECTION III AUTHORIZATION AND PROCEDURES
EIGHTH: AUTHORIZATION. Any Processing of personal data in which MARIACE POSADA GATOS Y PERROS acts as Manager or Manager requires the free, prior, express and informed consent of the Owner thereof. MARIACE POSADA GATOS Y PERROS has provided the necessary mechanisms to obtain the authorization of the Owners, guaranteeing in any case that it is possible to verify the granting of said authorization.
In the event that MARIACE POSADA GATOS Y PERROS, as Data Processor, has contractually agreed to execute the Treatment based on the counterparty's policy, the latter must guarantee the principles contained in this manual.
NINTH: CONTENT AND FORM TO GRANT THE AUTHORIZATION. The authorization may be in a physical, electronic document or in any other format that allows for the unequivocal conclusion that the Holder has expressly given his consent. The authorization must be able to be consulted later by the Holder and must contain:
- a) The name of the Holder;
- b) The type of identification and identification number of the Holder
- c) Contact details of the Treatment Holder (Cell phone number, Address and Email);
- d) The contact details of MARIACE POSADA GATOS Y PERROS
- e) The identification of MARIACE POSADA GATOS Y PERROS as Responsible or In Charge of Treatment;
- f) The purpose of data processing;
- g) The enunciation of the data on which the Treatment will be provided;
- h) The rights that assist the Holder;
- i) The privacy notice;
- j) The mechanisms for the Owner to know and exercise their rights, as well as the Personal Data Protection Policy of MARIACE POSADA GATOS Y PERROS;
- k) A statement in which the Holder determines that he knows and understands the conditions in which the Treatment will be carried out, the rights that assist him and the mechanisms to exercise them;
- l) The signature of the Owner or any other physical or digital mechanism that allows determining that the Owner authorizes the Data Processing.
Paragraph. The authorizations must be kept in a physical or digital file or database for the term determined by the Law. If there is a change in the purpose of the Treatment, MARIACE POSADA GATOS Y PERROS must obtain a new authorization from the Holder.
TENTH: PRIVACY NOTICE. The authorization of MARIACE POSADA GATOS Y PERROS must contain the following notice:
The Processing of personal data will be carried out only for the purposes authorized by the Owner. The mechanisms that MARIACE POSADA GATOS Y PERROS uses to carry out the Processing of Personal Data are safe and confidential, since we have the appropriate technological means to ensure that they are stored in such a way that unwanted access by third parties is prevented, and in In the same order, we ensure their confidentiality based on the Personal Data Treatment Policy of MARIACE POSADA GATOS Y PERROS, which can be consulted on the page www.mariaceposada.com/datospersonales/ . In case of doubts, requests, inquiries, claims and the like, you can contact MARIACE POSADA GATOS Y PERROS by email firstname.lastname@example.org .
The authorization, in addition to the foregoing, will contain the company name MARIACE POSADA GATOS Y PERROS, the trade name MARIACE POSADA GATOS Y PERROS, the treatment to which the data will be submitted and its purpose, the rights of the Owner and the mechanisms to know the policy of MARIACE POSADA GATOS Y PERROS, as well as its updates. On the website www.mariaceposada.com/datospersonales/ , the privacy notice must be displayed together with the information mentioned in this paragraph, in accordance with the provisions of article 15 of Decree 1377 of 2013.
ELEVENTH: MEANS OF RESOLUTING QUERIES, CLAIMS AND REVOCATIONS. MARIACE POSADA GATOS Y PERROS through its website www.mariaceposada.com , will make this Personal Data Protection Policy available; the privacy notice, the forms for queries, claims and revocations; and instructions for completing them. In addition, MARIACE POSADA GATOS Y PERROS will enable the email email@example.com as a communication channel between the data holders and the company, as well as a contact form that will direct the requests completed on the website to the email contacto@mariaceposada. com .
In case of doubts in this regard, the Holder may contact the numbers 3104523659 or write to the email firstname.lastname@example.org to receive more information.
TWELFTH: CONSULTATIONS. The Holder or his successors in title may consult the Holder's personal data free of charge when MARIACE POSADA GATOS Y PERROS acts as Responsible or In Charge of Treatment. For this, the Holder or his successors in title must send a message to the email email@example.com , in which he will request his personal information. The message must contain as attachments:
- Copy of the Holder's citizenship card;
- In the case of being the successor in title, that is, his heirs, a copy of the civil registry in which the kinship or bond is proven.
The query will be answered to the email that sent the query within a maximum term of ten (10) business days from the date of receipt thereof. When it is not possible to respond to the query within said term, the interested party will be informed, stating the reasons for the delay and indicating the date on which the query will be addressed, which in no case may exceed five (5) business days following the expiration of the first term.
THIRTEENTH: CLAIMS AND DATA UPDATE. The Owner or his successors in title who consider that the information contained in a database must be corrected, updated, rectified or deleted, or when they notice the alleged breach of any of the duties contained in Law 1581 of 2012, may present a claim before the Treatment Manager, which will be processed under the following rules:
- The Holder will send a message to the email firstname.lastname@example.org , in which he will present his request for update or claim. The message must contain as attachments:
- Copy of the Holder's citizenship card
- In case of being the successor in title, copy of the civil registry in which the kinship or link is proven.
- If the claim is incomplete, the interested party will be required within five (5) days following receipt of the claim to correct the failures. After two (2) months from the date of the request, without the applicant submitting the required information, it will be understood that the claim has been withdrawn.
- In the event that MARIACE POSADA GATOS Y PERROS receives the claim without being competent to resolve it, it will notify the appropriate person within a maximum term of two (2) business days and inform the interested party of the situation, as long as they have the contact information. to whom it is directed In case of not having the information, you must inform the Holder that of that situation
- Once the complete claim is received, a legend that says "claim in process" and the reason for it will be included in the database, within a term of no more than two (2) business days. Said legend must be maintained until the claim is decided.
- The maximum term to address the claim will be fifteen (15) business days from the day following the date of receipt. When it is not possible to address the claim within said term, the interested party will be informed of the reasons for the delay and the date on which their claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the first term.
FOURTEENTH: REVOCATION OF THE AUTHORIZATION. The Holders of the personal data may totally or partially revoke the consent to the Treatment of their personal data at any time, as long as it is not prevented by a legal or contractual provision. For this, the Holder or his successors in title must send a message to the email email@example.com in which he will request the revocation of the authorization. The message must contain as attachments:
- Copy of the Holder's citizenship card
The request to revoke the authorization will be answered by email in the same response terms as the queries.
SECTION IV: INFORMATION SECURITY
FIFTEENTH: SECURITY MEASURES. In development of the security principle established in Law 1581 of 2012, MARIACE POSADA GATOS Y PERROS will adopt the technical, human and administrative measures that are necessary to grant security to the records avoiding their adulteration, loss, consultation, or unauthorized or fraudulent access. .
SIXTEENTH: IMPLEMENTATION OF SECURITY MEASURES. MARIACE POSADA GATOS Y PERROS will maintain mandatory security protocols for personnel with access to personal data and information systems. The procedure should consider at least the following aspects:
- Scope of application of the procedure with detailed specification of the protected data. Measures, norms, procedures, rules and standards aimed at guaranteeing the level of security required by Law 1581 of 2012;
- Functions and obligations of the personnel;
- Backup and recovery procedures (back up) of the data;
- Periodic controls that must be carried out to verify compliance with the provisions of the security procedure.
The personal data on which MARIACE POSADA GATOS Y PERROS performs the Treatment or is responsible rests in the Shopify application, in the database of www.mariaceposada.com contained in the server owned by MARIACE POSADA GATOS Y PERROS.
SEVENTEENTH: SECURITY OF ACCESS AND ACCOMMODATION OF INFORMATION.
- The information is found in servers or applications with exclusive destination of data;
- The servers are located in a data center that meets technical standards; required to store sensitive data;
- The access to the information is done through the applications which are hosted on independent servers;
EIGHTEENTH: LOSS OF INFORMATION. The information from the servers is supported daily automatically and incrementally and monthly in a total way, guaranteeing double backup.
NINETEENTH: ADULTERATION AND FRAUDULENT ACCESS. Access to the applications can only be done by active officials who are validated through active directory policies, that is, with user management, passwords and access to defined network segments.
SECTION: V FINAL PROVISIONS
TWENTIETH: COMPETITION. The information analysis area will be responsible for:
- The adoption and implementation of the personal data protection policy;
- Resolve the requests made by the Holders of personal data;
- Ensure compliance with security measures.
TWENTY-FIRST: CONTACT DETAILS. The holders of personal data may contact MariaCe Posada Gatos y Perros when acting as Responsible in:
Address: Calle 40 #74b-49 Laureles, Medellin.
TWENTY-SECOND: VALIDITY. This manual is effective as of February 10, 2019 and replaces previous manuals.