Privacy and Data Processing Policy
How EXABYTE COMPANY S.A.S collects, stores, uses, transfers and protects the personal data of BrainBox users, under Colombian Law 1581 of 2012.
This English version is a translation provided for convenience. The Spanish version is the legally binding text, and it prevails if the two differ. Leer en español
Pursuant to the personal data protection legislation in force, Law 1581 of 2012 and any other regulations that supplement or implement it, EXABYTE COMPANY S.A.S, a commercial company identified with Tax ID (NIT) 901529728-3, duly incorporated and domiciled in Bogotá D.C., Republic of Colombia (hereinafter EXABYTE), uses this Privacy and Personal Data Processing Policy (hereinafter the “Policy”) to govern the processing of the personal data of the users of the BrainBox Software, its suppliers, partners, employees, contractors and related third parties whose data it processes.
This Data Processing Policy explains how EXABYTE collects, stores, uses, transfers and discloses your information.
Personal data is processed mainly to carry out the corporate purpose of EXABYTE COMPANY S.A.S as operator of the BrainBox software and the activities related to it. By providing any kind of personal information, its owner agrees that it will be processed in accordance with this Policy. Personal data will never be used for purposes other than those set out here. If that personal information is to be used for other purposes, the use must fall within the exceptions provided by the regulations in force, or must have the express authorization of its owner, as applicable.
EXABYTE may review and modify this Policy at any time. If it does, we will let you know through our website or through our other communication channels, such as the email address you provided. Changes to this Policy take effect from the moment they are published.
01Purpose
EXABYTE COMPANY S.A.S is a Colombian commercial company, identified with Tax ID (NIT) 901529728-3, domiciled in Bogotá D.C., Republic of Colombia, engaged in activities related to software systems development, IT consulting, data processing and hosting, among other related activities, and is the operator and administrator of the BrainBox software.
BrainBox (hereinafter, the “Software”) is a cloud-based software as a service through which the Customer can upload documents and information and then, based on their content, interact with the uploaded information using artificial intelligence: asking questions about the uploaded content, requesting summaries of the information, and other interactions.
02Scope
Under Law 1581 of 2012 and any other regulations that supplement or implement it, this Policy applies to the personal data of natural persons stored and recorded in the databases managed by EXABYTE as Controller and/or Processor. Accordingly, every area of EXABYTE that involves the processing of personal data is subject to this Policy.
2.1. Who this Policy applies to
This Policy applies to everyone who, directly or indirectly, has any kind of relationship with EXABYTE, including, among others:
- Users of the BrainBox software
- Suppliers
- Partners
- Employees
- Contractors
- Related third parties
2.2. Data controller
The legal entity that decides on the database and/or the processing of the data is:
- Company name
- EXABYTE COMPANY S.A.S
- Tax ID (NIT)
- 901529728-3
- Address
- Calle 152 B #55-45, Bogotá D.C., Colombia
- brainbox.support@exabyte.company
- Phone
- +57 300 695 84 35
- Website
- www.brainbox.com.co
03Definitions
For the purposes of interpreting this Policy, and in accordance with Law 1581 of 2012, the following definitions apply:
- Data Subject
- The natural person whose personal data is processed (hereinafter, the “Data Subject”).
- Personal data
- Any information linked to, or that can be associated with, one or more identified or identifiable natural persons.
- Processing
- Any operation or set of operations performed on personal data, such as collection, storage, use, circulation or deletion (hereinafter, the “Processing”).
- Authorization
- The prior, express and informed consent of the Data Subject to the Processing of their personal data.
- Database
- An organized set of personal data that is subject to Processing.
- Data Controller
- A natural or legal person, public or private, that on its own or together with others decides on the database and/or the Processing of personal data.
- Data Processor
- A natural or legal person, public or private, that on its own or together with others processes personal data on behalf of the Data Controller.
- Public data
- Data that circulates freely to make it easier to identify and contact people. Its use does not require prior authorization.
- Private data
- Data that, because of its intimate or confidential nature, is relevant only to the Data Subject. For example: income, financial data, borrowing capacity, gross assets, dependants, family composition, hobbies or interests, property owned, employment information, social media preferences, driving habits, consumption habits, and contact details such as a personal address, phone number and email address.
- Sensitive data
- Data that affects the Data Subject’s privacy or whose misuse could lead to discrimination. For example, biometric data, their voice, or health-related data.
- User
- Anyone who accesses BrainBox, whether registered or not, in order to use the services or view the published content (hereinafter, the “User”). Depending on context, it may also refer to a user of Personal Data.
- Superintendence of Industry and Commerce
- Colombia’s national personal data protection authority (Superintendencia de Industria y Comercio, SIC).
04Rights of data subjects
Data Subjects have the following rights:
- To know, update and correct their personal data held by Data Controllers or Data Processors. This right may be exercised, among other cases, in relation to partial, inaccurate, incomplete, fragmented or misleading data, or data whose Processing is expressly prohibited or has not been authorized.
- To request proof of the authorization granted to the Data Controller, except where the law expressly exempts authorization as a requirement for Processing.
- To be informed by the Data Controller or Data Processor, upon request, of how their personal data has been used.
- To file complaints with the Superintendence of Industry and Commerce for breaches of the law and any regulations that amend, supplement or complement it.
- To revoke the authorization and/or request deletion of the data when the Processing does not respect constitutional and legal principles, rights and guarantees. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that the Controller or Processor has acted contrary to the law and the Constitution.
- To access, free of charge, their personal data that has been processed.
- To decline to answer questions about sensitive data (unless fully justified under the law). Answering questions about sensitive data or about the data of children and adolescents is optional.
05Access to the data subject’s information
When required, EXABYTE will provide information about the Data Subject’s data to the following persons:
- Data Subjects, their successors or their legal representatives.
- Public entities exercising their legal functions, or by court order.
- Third parties authorized by the Data Subject or by law.
06Area responsible for requests, complaints, suggestions, inquiries and claims
Every user of Personal Data has the right to submit inquiries and requests to EXABYTE, free of charge, to know, access, update, correct or delete information, request data portability and revoke authorization, or to file petitions, complaints and claims about how EXABYTE processes the information.
Inquiries must be addressed to EXABYTE and include the following information:
- If submitted by the User: a valid identity document.
- Contact details (physical and/or email address and phone numbers).
- If submitted by a successor: a valid identity document, the User’s death certificate, a document proving the capacity in which they act, and the User’s identity document number.
- If submitted by a legal representative and/or attorney: a valid identity document, a document proving their status as the User’s legal representative and/or attorney, and the User’s identity document number.
- How they wish to receive a response to the request.
- The reason(s) or fact(s) giving rise to the claim, with a brief description of the right they wish to exercise (to know, update, correct, request proof of the authorization granted, revoke, delete, or access the information).
- Signature (if applicable) and identification number.
If the inquiry is incomplete, EXABYTE will ask the requester to correct it within five (5) days of receiving the claim. If two (2) months pass from the date of that request without the requester providing the information required, the claim or petition will be considered withdrawn.
Inquiries must be submitted through any of the following channels:
- Address
- Calle 152 B #55-45, Bogotá D.C., Colombia
- brainbox.support@exabyte.company
- Website
- www.brainbox.com.co
6.1. Response times
The maximum term established by law to resolve a claim is fifteen (15) business days, counted from the day after it is received. When the claim cannot be handled within that term, EXABYTE will inform the requester of the reasons for the delay and the date on which the claim will be handled, which may in no case exceed eight (8) business days after the first term expires. Once the terms set out in Law 1581 of 2012 have elapsed, a Data Subject who has been fully or partially denied the exercise of the rights of access, update, correction, deletion and revocation may bring the matter to the attention of the Superintendence of Industry and Commerce, Office for the Protection of Personal Data.
07Data processing and purposes
EXABYTE will process the personal information it collects as follows: collection, storage, use, circulation and deletion of information for the purposes set out below.
7.1. Purposes related to the use of the BrainBox application
- To share non-sensitive information with strategic partners for contracting products and services, risk management, handling claims and commercial management, complying with every legal requirement for that purpose.
- To transmit and/or transfer personal data in order to attract, assess, retain, acquire and/or study market behaviour and User service, as well as to perform the contracts needed to support the operation of BrainBox, all in accordance with the regulations in force.
- To carry out analyses to improve the User experience within the platform.
- To control access within the application.
- To carry out statistical analyses and identify topics of interest that may benefit the User community. The information may also be used to train models and to analyse it for product development.
- To process data to handle any claim about the contracted product or to provide proactive support for it, and to collect payment for services or products provided.
- To defend EXABYTE in legal proceedings.
7.2. Purposes related to EXABYTE’s corporate operations
- To process the data of employees, contractors and candidates according to the purpose of the relationship, the performance of their duties, the provision of their services and the termination of their contractual relationship with EXABYTE. This includes, among other things: recruitment and onboarding, development plans, recognition and payment of statutory and non-statutory benefits, internal and external communications, and processing of information in various technology applications installed on the company’s servers or in the cloud.
- To make payments and enrolments in the Comprehensive Social Security System for employees.
- To have EXABYTE’s human resources area process health-related data of employees, including monitoring activities of the Occupational Health and Safety Management System.
- To process data for the surveillance and security of people, property and facilities of EXABYTE through images captured by video surveillance systems, and to use that information in administrative and legal proceedings.
- To defend EXABYTE in legal proceedings.
08Sensitive personal data
Sensitive personal data is data that affects the Data Subject’s privacy and could lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, or membership of trade unions, social organizations or human rights organizations, as well as data relating to their voice, health, sex life, and biometric data.
EXABYTE collects sensitive personal data in the form of images of users of the BrainBox software. These images are treated as sensitive biometric data, since they make it possible to identify a natural person through a non-transferable physical characteristic and to distinguish one human being from another. They are collected so that the User can be identified when registering and signing in to the application.
Under the law, processing sensitive data is prohibited unless the Data Subject has given explicit authorization, except in cases where the law does not require such authorization and other legal exceptions.
Accordingly, EXABYTE informs its Users, suppliers, partners, employees, contractors and related third parties that:
- Data collected for this purpose may only be used for the purpose previously established, in this case identifying the User. If the purpose changes, or must be supplemented or removed, the Data Subjects’ authorization must be requested to continue processing their personal data. If that is not possible, the Processing cannot continue.
- Access to and disclosure of this sensitive data is restricted to the people who need to know it because of their role, following a careful analysis of the need and risks at the time the information is collected.
- Express authorization must be obtained from the Data Subject, stating that the data is sensitive and the purpose of the processing.
- According to the Superintendence of Industry and Commerce, the Processing of Sensitive Data must be handled with special care and diligence in its collection, use, security and any other activity performed with it. For this reason, the Sensitive Data collected will be subject to stronger security measures, confidentiality, restricted circulation and limited use.
Data transmitted and/or transferred to third parties will be sent through secure mechanisms that protect the information from unauthorized use and errors. In every case, EXABYTE will tell the recipient of the data the permitted purposes, require adequate confidentiality and security measures, and comply with the legislation in force on the matter.
09Principles for processing personal data
EXABYTE will apply the following principles in its operations:
- Legality
- No personal information of customers will be processed without observing the rules established in the regulations in force.
- Purpose
- Adding data to EXABYTE’s physical or digital databases must serve a legitimate purpose, which will be communicated to the Data Subject in due time in the processing authorization clause and in the privacy policy.
- Freedom
- EXABYTE will process Data Subjects’ personal data when it has their authorization to do so or when a regulation grants that power, under Law 1581 of 2012 and other applicable regulations.
- Accuracy and quality
- EXABYTE will strive to keep Data Subjects’ information truthful and up to date, providing efficient means to update and correct personal data.
- Transparency
- The mechanisms established for Data Subjects to exercise their rights will guarantee the Data Subject, their successors and third parties they authorize access to information about the personal data that concerns them.
- Restricted access and circulation
- EXABYTE undertakes to ensure that only authorized people can access personal information. Its circulation will also be limited to the purposes authorized by the User or by the regulations in force. EXABYTE will put contractual means in place to guarantee the confidentiality and restricted circulation of the information.
- Security
- EXABYTE will take every technical, administrative and human measure within its reach to ensure that the personal information of Data Subjects stored in physical or digital databases does not circulate improperly and is not accessed by unauthorized people.
- Confidentiality
- Everyone involved in processing personal data that is not public in nature must keep the information confidential, even after their involvement in the processing ends, and may only provide or communicate personal data when doing so is part of the activities authorized by law and on the terms it sets.
10Databases
EXABYTE acts as controller and processor of the following databases:
- The database of BrainBox Users.
- The database of its suppliers, partners, employees, contractors and related third parties.
Each database collects and stores the corresponding personal information, with prior authorization and for the purposes set out in this Policy.
11How information is collected
EXABYTE collects information in two (2) ways:
- When the User signs in to the BrainBox application.
- In the course of EXABYTE’s own corporate activities.
12Transfer of data to third parties
As a general rule, data will not be transmitted to third parties, except where EXABYTE is legally authorized to do so, where the transfer is necessary to establish the contractual relationship, or where you have given us your explicit prior consent to transmit the data.
For internal handling, data may be accessed by authorized EXABYTE personnel, who must know the security and data collection procedures.
13Duties of controllers and processors
As controller and/or processor, as applicable, of the personal data in its custody, EXABYTE must fulfil the following duties, without prejudice to other provisions of the law and any other rules governing its activity:
- Guarantee the Data Subject or User, at all times, the full and effective exercise of the right of Habeas Data.
- Request and keep, under the conditions set out in this Policy, a copy of the authorization granted by the Data Subject.
- Properly inform the Data Subject of the purpose of the collection and of the rights granted by the authorization.
- Keep the information under the security conditions needed to prevent its alteration, loss, consultation, use, or unauthorized or fraudulent access.
- Ensure that the information provided to the Processor is truthful, complete, accurate, up to date, verifiable and understandable.
- Update, correct or delete data in a timely manner under the law, promptly informing the Processor of any changes to data previously provided.
- Correct information when it is wrong and notify the Processor accordingly.
- Provide the Processor, as applicable, only with data whose processing has been previously authorized under the law.
- Require the Processor at all times to respect the security and privacy conditions of the Data Subject’s information.
- Handle inquiries and claims on the terms set out in this policy and in the law.
14Data retention
How long EXABYTE keeps personal data in its information systems will be determined by the purpose of the Processing.
Consequently, once the purpose for which the data was collected has been fulfilled, EXABYTE will destroy or return it, as applicable, or keep it as required by law, adopting technical measures that prevent improper processing.
15Security measures
In processing the personal data covered by this Policy, EXABYTE will adopt the following security measures:
- Encryption
- We use end-to-end encryption to protect data both in transit and at rest.
- Authentication and authorization
- We use multi-factor authentication (MFA) and role-based authorization so that only authorized people can access sensitive data.
- Auditing and monitoring
- We run audits and continuously monitor access and activity on the platform to detect and respond quickly to any suspicious activity.
- Backups
- We make periodic backups of all stored data so it can be recovered in case of data loss.
- Password policies
- We require strong passwords and rotate them periodically to minimize the risk of unauthorized access.
EXABYTE anticipates, looks after and takes the measures needed to keep Users’ information secure, and seeks to prevent its loss, alteration, access or consultation by third parties through industry-standard technologies and internal procedures, including encryption mechanisms. However, EXABYTE does not guarantee that unauthorized access to the information cannot occur. We also guarantee that:
- EXABYTE has security and access protocols for its information, storage and processing systems, including physical security risk controls. The system is continuously monitored through vulnerability analysis.
- EXABYTE must notify Users of any information security breach within seventy-two (72) hours of it occurring.
- Access to the different databases is restricted, even for employees and collaborators.
- All employees and third parties have signed confidentiality clauses in their contracts and are committed to handling the databases properly, following the information processing guidelines established by law.
- Users are responsible for having all security controls in place on their own devices or private networks when browsing to our portals.
16Cookies and local storage
EXABYTE may use technologies such as “cookies” or similar technologies, which store information on computers (hereinafter, “Local Storage”) and enable certain features and functions automatically, improving the User’s browsing experience.
Cookies do not include any information about the User, except their password when signing in to the website is required, which is deleted when the session ends (usually after twenty-four (24) hours). Most browsers let you delete cookies from your hard drive, block cookies, or receive a warning before they are stored. To delete or disable Local Storage, Users should use their settings according to the instructions provided by their technology provider. However, if the User blocks or deletes cookies, their online browsing experience may be limited.
17Effective date
This Data Processing Policy takes effect on June 12, 2024. The Databases containing Users’ information will remain in force for ten (10) years, renewable for equal periods.
EXABYTE will notify its Users of any material change to this document through the contact channels they have previously authorized.
18Governing law and jurisdiction
This Policy is governed by and interpreted in accordance with the laws of the Republic of Colombia. In the event of a dispute between the User and EXABYTE regarding this document, the parties may bring the matter before the Superintendence of Industry and Commerce, Office for the Protection of Personal Data, and/or resolve it before the ordinary courts.
19Notices
EXABYTE COMPANY S.A.S is located at the following address, and its contact details for service of any judicial or other notice are:
- Physical address
- Calle 152 B #55-45, Bogotá D.C., Colombia
- Phone
- +57 300 695 84 35
- brainbox.support@exabyte.company
- Website
- www.brainbox.com.co
20Publication
This Policy will be made available to all stakeholders through the communication channels defined by EXABYTE, especially the website www.brainbox.com.co.
EXABYTE’s data officer, or whoever performs that role, is responsible for administering this Policy and will work with the Company’s internal areas on its publication, compliance and updates.