1. OBJECTIVE
In order to comply with current data protection legislation, specifically Law 1581 of 2012 and Decree 1377 of 2013 (and any other regulations that modify, add to, supplement, or elaborate on them), we hereby inform you of the relevant aspects regarding the collection, use, and transfer of personal data by CONSTRUCTORA CARPOL S.A.S. (hereinafter “CARPOL”), identified by Tax ID No. 800.040.872-9, as the Data Controller, regarding the processing of your personal data.
In this policy, you will find the corporate and legal guidelines under which CARPOL processes your personal data, the purpose of such processing, your rights as a data subject, as well as the internal and external procedures in place for exercising those rights with the company, among other things.
2. INFORMATION ABOUT THE DATA CONTROLLER
| Data Controller | CONSTRUCTORA CARPOL S.A.S. |
|---|---|
| Tax ID Number | 800.040.872-9 |
| Address | 4th Street, No. 7-32, Office 301, Popayán, Cauca, Colombia |
| Privacy Notice | info@constructoracarpol.com |
| Website | www.constructoracarpol.com |
| Date Updated | June 9, 2026 |
| Validity | Indefinite, subject to update in accordance with the law |
3. SCOPE
This Policy governs all of CARPOL’s organizational processes involving the processing of personal data and provides general information to all individuals who submit their personal data to the company regarding the Policy, which applies to all databases and the personal data they contain.
4. APPLICABLE LAW
This policy was developed in accordance with current legislation on the protection of personal data, specifically Statutory Law 1581 of October 17, 2012, Decree 1377 of 2013 “Partially Regulating Law 1581 of 2012,” and Article 2.2.2.25.1.1, Section 1, Chapter 25 of Decree 1074 of 2015 (and any other regulations that modify, add to, supplement, or further develop them).
5. DATABASES
CARPOL stores the personal data it collects for the purposes set forth in this Policy and in the respective authorizations in physical and/or digital databases, which are identified in an internal inventory created in compliance with the Principle of Demonstrable Accountability.
The databases, as well as the information they contain, will be made available in accordance with the activities for which they were collected and in accordance with the processing and storage guidelines set forth in this privacy policy.
6. DEFINITIONS
For the purposes of this Policy, the terms listed below shall have the following meanings:
- Authorization: Prior, express, and informed consent from the Data Subject to process personal data.
- Privacy Notice: A verbal or written communication issued by CARPOL and addressed to the Data Subject, informing the Data Subject of the existence of this Policy for the handling and processing of personal data, how to access it, and the purposes for which the company intends to process the personal data. The privacy notice is used only in the event that CARPOL is unable to make this Policy available to the public;
- Database: An organized collection of personal data that is subject to processing. Manual databases are those in which the information is organized and stored physically. Automated databases are those that are stored and managed using computer tools.
- Question: Request by the data subject or by persons authorized by the data subject or by law to access information stored in any CARPOL database, whether contained in an individual record or linked to the data subject’s identification.
- Personal information: Any information that is linked to or may be associated with one or more specific or identifiable individuals.
- Public personal information: Data that is neither semi-private, private, nor sensitive, and that, by its nature, may be contained in public records, public documents, official gazettes, official bulletins, and/or duly enforceable court rulings that are not subject to confidentiality. Data considered public includes, among other things, data relating to individuals’ civil registration, their profession or trade, and/or their status as a businessperson or public servant.
- Private personal information: This is data that, due to its intimate or confidential nature, is relevant only to the data subject.
- Semi-private personal data: Information whose knowledge or disclosure may be of interest to the data subject and to a certain sector or group of people.
- Sensitive personal information: Data that affects the Data Subject’s privacy or whose misuse may lead to discrimination against the Data Subject, such as data revealing racial or ethnic origin; political orientation; religious or philosophical beliefs; membership in labor unions, social organizations, human rights organizations, or organizations that promote the interests of any political party or that safeguard the rights and guarantees of opposition political parties; data relating to health or sex life; and biometric data.
- Data Controller: A natural or legal person, whether public or private, who, either alone or in association with others, processes personal data on behalf of the Data Controller.
- Security Incident: Unauthorized access, attempted access, use, disclosure, modification, or destruction of information, and, in general, a violation of the Information Security Policy
- Data Protection Officer: The department or individual within the organization responsible for personal data protection.
- Claim: Request by the data subject or persons authorized by the data subject or by law to correct, update, or delete their personal data, or to revoke consent in the cases provided for by law.
- Data Controller: A natural or legal person, whether public or private, who, either alone or in association with others, makes decisions regarding data and/or data processing.
- News headline: A natural person whose personal data is subject to processing.
- Treatment: Any operation or set of operations performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Transfer: This occurs when the data controller, located in Colombia, sends personal information to a third-party recipient—whether located within or outside the country—who is, in turn, the data controller for that information;
- Broadcast: This occurs when the Data Controller, located within or outside the country, shares personal information for processing by the Data Processor located within or outside the country.
7. GUIDING PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
In all activities related to the processing of personal data contained in CARPOL’s databases, the principles recognized by law and the case law of the Colombian Constitutional Court must be fully applied; these principles are as follows:
7.1. Principle of Purpose
The processing of personal data must serve a legitimate purpose in accordance with the Constitution and the law, and the data subject must be informed of that purpose.
The purpose of CARPOL's databases is established by current regulations and/or the company's operational needs.
The data collected will not be used for purposes other than those set forth in the authorization granted by the Data Subject and/or those that are legally and contractually authorized.
7.2. Principle of Necessity and Proportionality
The personal data contained in CARPOL’s databases must be strictly limited to what is necessary to fulfill the purposes of the processing. In this regard, the data must be adequate, relevant, and consistent with the purposes for which it was collected.
7.3. Principle of Temporality
The retention period for personal data stored in CARPOL’s databases must be limited to the time necessary to fulfill the purpose for which it was collected.
7.4. Principle of Freedom
Personal data may only be processed with the prior, express, and informed consent of the data subject. Therefore, personal data may not be collected or disclosed without prior authorization, or in the absence of a legal or judicial order.
Whenever data is collected by CARPOL, the data subject must be provided with clear, sufficient, and prior information regarding the purpose of processing the information provided; therefore, data may not be collected without a clear specification of the purpose of such processing.
7.5. Principle of Truthfulness or Quality
The information subject to processing must be true, complete, accurate, up-to-date, verifiable, and understandable. The processing of data that is partial, incomplete, fragmented, or misleading is prohibited.
Reasonable measures must be taken to ensure that the data collected is accurate and sufficient and, when requested by the Data Subject or when determined by CARPOL, is updated, corrected, or deleted, the latter if applicable.
7.6. Principle of Transparency
In the processing of personal data, CARPOL must guarantee the data subject’s right to obtain, at any time and without restrictions, information regarding the existence of data concerning him or her.
7.7. Principle of Restricted Access and Movement
Personal data, with the exception of public information, may not be made available on the Internet or through other means of mass dissemination or communication, unless access is technically controllable so as to provide restricted access to the data to the data subjects or authorized third parties.
7.8. Safety Principle
Any information processed by CARPOL must be protected by implementing the necessary technical, human, and administrative measures to ensure the security of the records and, to the extent possible, prevent their tampering, loss, unauthorized or fraudulent access, use, or disclosure.
7.9. Confidentiality Principle
All employees involved in the processing of personal data—other than information that is in the public domain—are required to ensure the confidentiality of such information, even after the processing has ended and/or their involvement in any of the related tasks has concluded.
8. PROCESSING AND PURPOSE OF PERSONAL DATA COLLECTION
CARPOL will process Personal Data; that is, it will carry out activities such as the collection, storage, use, dissemination, transmission, or deletion of such data in order to fulfill the normal course of our company’s corporate purpose and our relationship with the data subjects.
8.1. Processing of Customers' Personal Data
The Personal Data processed by CARPOL must be used strictly and solely for the purposes set forth below, which must also be observed by data processors or third parties who have access to the Personal Data by virtue of law or contract:
- Carry out activities arising from the pre-contractual relationship (requests to set aside or reserve properties, verification of the property’s availability, and registration of the potential buyer’s interest, prior to the execution of any preliminary sales agreement or sales contract, among others), as well as contractual and post-contractual activities, including the collection, validation, storage, updating, and management of the information necessary for the provision of services, real estate marketing, document receipt, financial management, and the transfer of funds.
- To comply with legal, regulatory, contractual, and corporate obligations related to the conduct of activities that fall within CARPOL’s corporate purpose.
- Manage processes related to deed execution, registration, legalization, and property handover, as well as procedures involving notaries, public registry offices, trust companies, financial institutions, family compensation funds, subsidy-granting entities, and other third parties involved in real estate development projects.
- To contact the Data Subject via email, regular mail, phone calls, text messages (SMS/MMS), instant messaging apps such as WhatsApp, or other authorized channels, for operational, administrative, contractual, informational, commercial, and customer service purposes, sending commercial, promotional, and institutional information, and for collection purposes, in accordance with Law 2300 of 2023 and any regulations that amend or replace it.
- Assess, manage, and monitor credit, financial, and commercial risk; consult, report, update, store, and process information with credit and risk bureaus; and conduct collection activities directly or through authorized third parties.
- Verify information against national and international sanctions lists, public or private databases, and other validation mechanisms to prevent fraud, money laundering, terrorist financing, corruption, and other illicit activities.
- To respond to requests, inquiries, petitions, complaints, claims, judicial or administrative demands, and requests made by competent authorities.
- To conduct business development, marketing, advertising, customer profiling, segmentation, market research, preference analysis, satisfaction surveys, surveys, sales campaigns, promotion of products and services, distribution of commercial information, events, product launches, and offers related to goods; market research and distribution of information related to real estate projects, promotions, events, product launches, sales campaigns, and other activities related to CARPOL’s corporate purpose, as well as its own services or those of strategic partners.
- To share, disclose, or transfer personal data to strategic partners, suppliers, financial institutions, affiliated companies, parent companies, subsidiaries, or domestic or international third parties with whom we have a commercial, contractual, or collaborative relationship, for the purposes authorized by the Data Subject and in accordance with applicable regulations.
- Handle the procedures related to the transfer and legalization of real estate, including providing information to utility companies and other entities necessary for the proper transfer of subscriber or user status.
- To retain the information for historical, statistical, accounting, legal, evidentiary, and auditing purposes.
- Report changes to personal data processing policies, conduct campaigns to update information, and keep data subjects' records up to date.
- Conduct community outreach and engagement activities related to real estate projects and disseminate information about these activities through websites, social media, corporate publications, or informational materials.
- Implement control, monitoring, and security measures for CARPOL's facilities, property, and assets.
- To capture, store, and use images, voice recordings, and videos obtained through video surveillance or monitoring systems installed by THE CONSTRUCTION COMPANY, to support security activities, access control, and risk prevention, and as evidence in judicial, administrative, and extrajudicial proceedings or internal investigations.
- Contact the Data Subject to identify their needs, preferences, and interests, as well as to provide information about projects, products, and services offered by CARPOL.
- Manage referral and commercial recommendation programs, ensuring the proper handling of third-party information and the deletion of data when there is no legitimate interest or authorization to continue processing it.
- Document and manage the stages preceding, concurrent with, and following the real estate sales process, including reservations, preliminary sales agreements, sales agreements, closing, financing procedures, legalization, property handover, warranties, and after-sales service, as well as the handling, processing, and follow-up of claims related to construction defects, structural defects, non-compliance with technical specifications, latent defects, and other situations arising from the contractual relationship or covered by applicable legal warranties, including coordination with contractors, insurers, and other third parties involved in addressing and resolving such issues.
- To capture and use photographs, images, and videos taken during events, trade shows, product launches, and commercial or promotional activities for informational, advertising, commercial, and institutional outreach purposes through the physical or digital media that CARPOL deems appropriate.
- To manage the collection, storage, and processing of personal data obtained through websites, digital forms, landing pages, social media, messaging apps, online chats, and other digital channels used by CARPOL, in order to respond to inquiries, manage business processes, and maintain the pre-contractual or contractual relationship.
- Issue certifications, statements, clearance certificates, and other documents related to the holder’s employment status, real estate acquisitions, financial obligations, or contractual status, when appropriate or upon request by the holder or authorized third parties.
In addition, CARPOL collects and stores personal data from individuals interested in purchasing a property within its projects, as well as from those who have already purchased one. This information is provided directly by the data subjects or their representatives and is processed in accordance with the provisions of this Policy and within the framework of Law 1581 of 2012 and its implementing regulations, in accordance with the purposes authorized by the data subjects.
When the data pertains to legal entities—which are not considered personal data under national law—CARPOL will likewise ensure that such data is processed in accordance with strict security and confidentiality measures.
By authorizing the use of their information by any means, customers agree that CARPOL may: store the information in physical and/or digital databases; conduct marketing research and profile analysis; carry out administrative tasks; maintain a registry of customers who have purchased real estate; offer goods and services; retain the information for statistical and historical purposes or to comply with legal archiving obligations; address requests, complaints, and claims; respond to requests from competent authorities; and send communications and advertising regarding projects and activities related to the company’s corporate purpose, via digital or physical means or data messages.
In accordance with Article 52 of Law 675 of 2001, CARPOL may act as the provisional administrator of the projects it develops, an activity that involves collecting and processing personal data from residents, visitors, and domestic staff, in order to provide a service tailored to the needs of the condominium whose administration has been entrusted to it. This processing will always be carried out in accordance with the principles and purposes established in Law 1581 of 2012 and its regulatory decrees, and will cease once its term as provisional administrator ends.
The data may be shared, transmitted, provided, transferred, or disclosed for the purposes mentioned above to: i) legal entities that are affiliates, subsidiaries, related entities, or the parent company of CARPOL; ii) third parties necessary for the fulfillment of rights and obligations arising from the contracts entered into, such as call centers, external attorneys, and network service providers, among others; iii) partner companies that require the information for verification and risk prevention, fraud prevention, and anti-money laundering assessments, in order to offer their own products and services, without the need for additional procedures with said companies.
8.1.1. Validity of Customer Data
Customers’ personal data will be retained for a maximum of twenty (20) years from the termination of the contractual relationship or the last activity, a period that will be automatically renewed for equal periods, unless the data subject requests the deletion of the data or revokes consent, provided there is no legal or contractual obligation to retain it. This period is established without prejudice to (i) a specific legal requirement to store the data for a specified period, or (ii) the need to store the data for a longer period to defend any rights and interests in judicial or administrative proceedings, up to one (1) year after the corresponding judgment becomes final.
8.2. Processing of Personal Data of Candidates, Employees, and Former Employees
The processing of essential personal data of applicants, employees, and former employees will be conducted in accordance with the law and in accordance with CARPOL’s status, and will be limited to what is necessary to fulfill its obligations as an employer.
8.2.1. Specific Objectives for Candidates
- Verification, comparison, and evaluation of the job-related and personal competencies of candidates against CARPOL’s selection criteria.
- Conducting recruitment processes, scheduling interviews, and administering tests to applicants.
- Evaluate candidates' selection tests either directly or through third parties.
- Conducting knowledge, psychological, and/or technical tests on the subjects of the personal data.
- Report the overall results of the selection process.
- Review and evaluate all information regarding the candidate for the position that is stored in lawfully established criminal or security databases, whether government or private, domestic or foreign.
8.2.2. Specific Purposes for Employees and Former Employees
The information being processed will be used, among other things, to:
- Manage the employee’s employment relationship, including the execution, implementation, and termination of the employment contract, as well as handling registrations, updates, reports, transfers, and other procedures with the entities that make up the Comprehensive Social Security System and the Social Protection System, such as Health Promotion Entities (EPS), Pension Fund Administrators (AFP), Occupational Risk Administrators (ARL), severance fund administrators, family compensation funds, and other applicable parafiscal or social security entities. Likewise, manage, document, report, and process workplace accidents, occupational illnesses, disabilities, leaves of absence, and other situations related to occupational safety and health, in compliance with current labor, social security, and occupational risk regulations.
- Comply with any legal and non-statutory employment obligations, if any, arising from the employment contract.
- Submit reports to administrative, police, and judicial authorities when requested to do so.
- Benefits administration; payroll processing; compliance with legal obligations; audits; accounting reports; statistical analysis; interaction with entities that manage or may come to manage the general social security system, entities responsible for collecting parafiscal contributions, the Ministry of Labor, UGPP, the Superintendency of Health, the operator of the Comprehensive Contribution Settlement Form, the Superintendency of Industry and Commerce, and the Regional and National Disability Assessment Boards; training and education; access to agreements with third parties; among other processes typical of personnel administration.
- Development of training programs.
- Monitor and use the images captured by the video surveillance systems installed at CARPOL’s facilities in order to monitor and verify the progress and performance of work activities, as well as to conduct administrative and disciplinary investigations when necessary.
- The others relate to events in which information may be shared.
- Implementation of processes related to promotions, workplace well-being, payroll, performance and competencies, onboarding, training, education, occupational safety and health, and the environment.
- To transfer, transmit, or share personal data with benefit administrators, employee benefit funds, insurance companies, wellness providers, training providers, occupational health providers, and other third parties involved in the implementation of employee benefit programs, when necessary for their administration and in accordance with applicable regulations.
- The collection and use of images and videos for activities related to occupational health, including their inclusion in CARPOL’s advertising materials for advertising, promotional, or marketing purposes, which will require express, specific, and separate authorization from the copyright holder when legally required.
- Implementation of control and security measures at CARPOL's various facilities.
- Issue employment certificates, proof of employment, clearance certificates, certificates of income and withholdings, and any other documents required by the employee or by public or private entities in connection with a current or terminated employment relationship.
8.2.3. Retention Period for Data on Candidates, Employees, and Former Employees
Candidates: Personal data processed for hiring purposes will be retained for a maximum of one (1) year from the candidate’s last interaction or upon completion of the selection and hiring process, after which it will be deleted or anonymized, unless the candidate grants authorization to retain it for a longer period.
Employees: If the candidate is hired, the data collected as part of the hiring process will be processed for human resources management purposes and will be stored for the duration of the employment contract and for the period specified by applicable labor, accounting, and social security regulations after the contract ends.
Former Employees: Information provided by former CARPOL employees during the term of their employment will be retained by CARPOL in accordance with applicable commercial, labor, and occupational safety and health regulations, and will remain stored physically, in electronic or other available formats, for a maximum of twenty (20) years from the termination of the contract, in order to guarantee the social security and pension rights of former employees and to comply with requests from competent authorities.
Access logs for the procurement platform (if applicable) will be automatically deleted after one (1) year.
These time limits are established without prejudice to (i) a specific legal requirement to retain the data for a specified period, or (ii) the need to retain the data for a longer period to defend any rights and interests in judicial or administrative proceedings, up to one (1) year after the relevant judgment becomes final.
8.3. Processing of Suppliers' Personal Data
Personal data from suppliers who provide services to CARPOL is collected and stored through the various communication channels or documents provided for this purpose, through which the relationship with suppliers and contractors is formalized. This information is provided directly by the supplier’s legal representative, if the supplier is organized as a legal entity, and/or directly by the data subjects, and is processed in accordance with this Policy, within the framework of Law 1581 of 2012 and its implementing regulations, and for the following purposes:
- Manage the processes of selection, onboarding, evaluation, contracting, execution, monitoring, renewal, and termination of commercial or contractual relationships with suppliers and contractors, including the preparation of requests for quotes, requests for goods or services, and verification of compliance with agreed-upon obligations.
- Handle the administrative, financial, accounting, tax, documentation, and operational matters arising from the commercial or contractual relationship, including invoicing, payments, reconciliations, accounting records, filing, updating, safekeeping, and preservation of documents and information.
- Evaluate the quality, suitability, performance, and compliance of the products and services provided by suppliers and contractors, as well as conduct satisfaction surveys and internal statistical analyses to ensure the continuous improvement of processes.
- Analyze, assess, and manage the risks associated with establishing, executing, and maintaining business or contractual relationships, including consulting and verifying information in public or private databases—whether domestic or foreign—restrictive lists, and criminal, disciplinary, tax, and security records, as well as other legally available sources for the prevention of fraud, money laundering, terrorist financing, corruption, and other illicit activities.
- To comply with legal, regulatory, contractual, tax, accounting, auditing, and internal control obligations, as well as to respond to requests from judicial, administrative, regulatory, inspection, oversight, and control authorities; internal or external auditors; and other competent entities.
- To contact suppliers and contractors via email, regular mail, phone calls, text messages (SMS/MMS), instant messaging apps, or other authorized channels for the development, execution, monitoring, and fulfillment of the business or contractual relationship.
- Issue certificates, statements, and other documents related to the existing business or contractual relationship between the parties.
- Conduct data update campaigns, notify stakeholders of changes to personal data processing policies, and keep supplier and contractor information up to date.
- Retain the information for historical, statistical, evidentiary, legal, accounting, contractual, and auditing purposes for the periods established by law.
- To transfer and disclose personal data to third parties, strategic partners, parent companies, subsidiaries, affiliates, service providers, or entities located in Colombia or abroad, when necessary for the conduct of the business or contractual relationship or to comply with legal and corporate obligations, in accordance with applicable legal provisions regarding the protection of personal data.
- Manage guarantees, compliance policies, construction quality and stability policies, civil liability insurance, and other required coverage within the framework of the contractual relationship with suppliers and contractors, including the data processing necessary for the issuance, monitoring, filing claims, and settling such policies with insurers and the relevant authorities.
8.3.1. Validity of Supplier Data
Suppliers’ personal data will be retained for a maximum of ten (10) years from the termination of the contractual relationship or the last activity, a period that will be automatically renewed for equal periods, unless the data subject requests the deletion of the data or revokes consent, provided there is no legal or contractual obligation to retain it. This period is established without prejudice to (i) a specific legal requirement to store the data for a specified period, or (ii) the need to store the data for a longer period to defend any rights and interests in judicial or administrative proceedings, up to one (1) year after the corresponding judgment becomes final.
8.4. Processing of Personal Data of Minors (Children and Adolescents)
In the normal course of its operations, CARPOL does not typically process the personal data of children. However, if it is necessary to do so (for example, for activities related to employees’ children or in specific programs), CARPOL will ensure that the best interests of children and their fundamental rights are respected.
CARPOL will not engage in marketing activities, commercial profiling, advertising segmentation, or automated decision-making with respect to children and adolescents.
8.4.1. Special Requirements for the Processing of Children's Data
The processing of children’s data requires the prior, express, and informed consent of the child’s legal representative (parents or whoever exercises parental authority or legal representation), after the child has exercised their right to be heard, and their opinion shall be taken into account in light of their maturity, autonomy, and ability to understand the matter.
The legal representative will be informed of the nature of the data to be collected, the purposes of the processing, and the rights of the child as the data subject.
Only those data regarding children and adolescents that are in the public domain or that are strictly necessary for the fulfillment of the authorized purpose will be processed.
8.4.2. Validity of Children's Data
When personal data of children, adolescents, and minors is collected, it will be retained for the time strictly necessary to fulfill the purpose for which it was obtained and in accordance with the authorizations granted by their legal representatives, or for a maximum period of ten (10) years, unless a request for deletion is made by the legal representative and there is no legal or contractual obligation to retain it. This period is established without prejudice to (i) a specific legal requirement to store the data for a specified period, or (ii) the need to store the data for a longer period to defend any rights and interests in judicial or administrative proceedings, up to one (1) year after the corresponding judgment becomes final.
8.5. Data Processing in Video Surveillance Systems
As part of its security policies, monitoring of its activities, and controls regarding entry to and exit from its offices, CARPOL may make audio and video recordings in its offices and common areas of its facilities. Such recordings, made using a video surveillance system, will be retained in the company’s archives for a maximum of thirty (30) days, after which they will be securely deleted or destroyed.
8.5.1. Retention Period for Video Surveillance Data
Personal images of individuals captured by video surveillance systems will be recorded and stored for a period of thirty (30) calendar days, counted from the date of capture, and will then be automatically deleted, unless: i) They are required to comply with a legal obligation; ii) They are requested as a precautionary measure by a competent judicial or administrative authority; iii) They are required to conduct administrative, disciplinary, or criminal investigations, in which case they will be retained for as long as necessary to carry out such investigations and proceedings, and for one (1) year after the corresponding decision becomes final. Access to these images will be restricted and will be granted only to authorized personnel or to CARPOL’s Security Department in the event of a violation or suspected violation of the implemented security measures, or for the purposes mentioned above.
9. RIGHTS OF DATA SUBJECTS
In accordance with Article 8 of Law 1581 of 2012, the data subject has the following rights:
- To access, update, and correct your personal data, which is stored in the company's databases.
- To learn, upon request, how your personal data will be processed.
- Request the relevant proof of authorization to use your personal data.
- To revoke, in whole or in part, your consent to the use of your personal data.
- File a complaint with the Superintendency of Industry and Commerce regarding violations of the provisions of Law 1581 of 2012, once you have exhausted the relevant procedures with the Data Controller.
- Access, free of charge, your personal data that has been processed.
The rights of data subjects may be exercised by the following persons:
- By the Account Holder, who must sufficiently verify his or her identity through the various means made available by CARPOL, which may maintain mechanisms for validating such information for this purpose.
- By their successors, who must provide proof of that status.
- By the Data Subject’s representative and/or authorized agent, upon presentation of proof of representation or power of attorney.
10. DUTIES OF THE DATA CONTROLLER
As the Data Controller, CARPOL must comply with the following obligations, without prejudice to the other provisions set forth in Law 1581 of 2012 and in other laws governing its activities:
- To guarantee the Data Subject, at all times, the full and effective exercise of the right to access personal data;
- Request and retain, under the conditions provided by law, a copy of the relevant authorization granted by the Data Subject;
- Properly inform the Data Subject of the purpose of the data collection and the rights to which he or she is entitled by virtue of the authorization granted;
- Store the information under the necessary security conditions to prevent its tampering, loss, unauthorized or fraudulent access, use, or disclosure;
- Ensure that the information provided to the Data Controller is truthful, complete, accurate, up-to-date, verifiable, and understandable;
- Correct the information when it is incorrect and notify the Data Controller accordingly;
- Provide the Data Controller, as applicable, only with data whose processing has been previously authorized in accordance with the provisions of the law;
- Process inquiries and complaints submitted in accordance with the terms set forth in the law;
- Adopt an internal policy and procedures manual to ensure proper compliance with the law and, in particular, to address inquiries and complaints;
- Notify the data protection authority when security breaches occur and there are risks to the management of data subjects' information;
- Enter the note “claim pending” into the database as set forth in this policy;
- Enter the note “information under judicial review” into the database once notified by the competent authority of any legal proceedings related to the accuracy of the personal data;
- Refrain from disseminating information that is being contested by the copyright holder and for which the Superintendency of Industry and Commerce has ordered a takedown;
- Allow access to information only to persons authorized by the data subject or empowered by law to do so.
11. AUTHORIZATIONS AND CONSENT
The collection, storage, use, disclosure, or deletion of personal data by CARPOL requires the free, prior, express, and informed consent of the data subject.
11.1. Obtaining and Granting Authorization
Consent may be provided in the form of a physical document, an electronic document, a data message, voice recordings, the Internet, websites, or through a suitable technical or technological mechanism that allows consent to be expressed or obtained via a single or double click, unambiguous actions, or in any other format that ensures it can be reviewed or verified at a later time.
The authorization will be issued by the company and made available to the Account Holder, informing him or her of the following:
- The processing to which your personal data will be subject and the purpose of such processing.
- The optional nature of answering questions posed to you, when such questions concern sensitive information or information about children or adolescents.
- Your rights as a data subject are set forth in Article 8 of Law 1581 of 2012.
- CARPOL's identification, physical address, or email address.
11.2. Cases in Which Authorization Is Not Required
The data subject's consent will not be required in the following cases:
- Information requested by a public or administrative entity in the exercise of its legal functions or pursuant to a court order;
- Publicly available data;
- Medical or health emergencies;
- Processing of information authorized by law for historical, statistical, or scientific purposes;
- Data related to the Civil Registry of Persons.
11.3. Consent for the Processing of Sensitive Data
When collecting sensitive data, the following requirements must be met:
- The authorization must be explicit.
- The Data Subject must be informed that he or she is not required to consent to the processing of such information unless it is absolutely necessary for CARPOL to provide its services.
- The data subject must be explicitly informed in advance which of the data to be processed are sensitive and the purposes of the processing.
11.4. Proof of Authorization
CARPOL will have the necessary procedures and processes in place to determine and identify when and how it obtained authorization from data subjects.
11.5. Revocation of Authorization
Data subjects may revoke their consent to the use and processing of their personal data at any time, provided that no legal or contractual provision prevents such revocation. The revocation may be partial or total; therefore, the data subject must clarify the scope of the revocation at the time of requesting it.
12. HANDLING OF INQUIRIES
The company will guarantee the right of access by providing data subjects with all information contained in its records that is directly related to their personal data, upon verification of their identity or that of their representative.
CARPOL has established the following channels for handling inquiries:
- Email: info@constructoracarpol.com
- Physical address: Calle 4 No. 7-32, Office 301, Popayán, Cauca, Colombia.
- Hours of operation: Monday through Friday, 9:00 a.m. – 5:00 p.m.
Inquiries, regardless of the method used to submit them, will be addressed within a maximum of ten (10) business days from the date of receipt. If it is not possible to respond to the inquiry within the aforementioned timeframe, the Data Subject will be notified before the expiration of the established period, explaining the reasons for the delay and specifying the date by which the inquiry will be addressed, which must be no later than five (5) business days following the expiration of the initial deadline.
13. PROCESSING OF CLAIMS OR COMPLAINTS
Data subjects who believe that the information contained in CARPOL’s databases should be corrected, updated, or deleted, or who identify a breach of the obligations set forth in Law 1581 of 2012, may file a complaint with the company through the channels listed below.
The following procedure will be followed for handling complaints:
- The complaint must be filed by submitting a request to CARPOL, including the claimant’s identification, a description of the facts giving rise to the complaint, the address, and any supporting documents the claimant wishes to submit.
- If the claim is incomplete, the claimant will be required to correct the deficiencies within five (5) days of receipt of the claim. If two (2) months have elapsed since the date of the request and the claimant has not submitted the required information, the claim will be deemed withdrawn.
- If the person who receives the complaint does not have the authority to resolve it, that person shall forward it to the appropriate party within a maximum of two (2) business days and inform the complainant of the situation.
- Once the complete claim has been received, a note stating «claim pending» and the reason for the claim will be added to the database within no more than two (2) business days. This note must remain in the database until a decision is made on the claim.
- The maximum time limit for addressing the complaint shall be fifteen (15) business days, counted from the day following the date of receipt. If it is not possible to address the complaint within that timeframe, the complainant will be informed of the reasons for the delay and the date by which the complaint will be addressed, which in no case may exceed eight (8) business days following the expiration of the initial timeframe.
14. REQUEST FROM JUDICIAL OR ADMINISTRATIVE AUTHORITIES
When providing information to judicial or administrative authorities, one must adhere to the Constitutional Court’s ruling in Case C-748 of 2011:
- The public or administrative entity must justify its request by explaining the connection between the need to obtain the data and the fulfillment of its constitutional or legal functions.
- Second, upon submission of the information, the public or administrative entity will be notified that it is responsible for complying with the obligations and requirements imposed by Law 1581 of 2012, either as the data controller or, in certain cases, as the data processor.
- The receiving administrative entity must comply with all applicable legal requirements in effect as of the date the information is received, particularly the principles of purpose, legitimate use, restricted circulation, confidentiality, and security.
15. TRANSMISSION OF INFORMATION
Contractual Obligations: In order to ensure the security of the databases, employment and service agreements—as well as any other agreements under which access to the databases is granted by virtue of the contractual purpose—include provisions regarding the obligation of privacy, accountability, and confidentiality with respect to such data. Thus, all persons involved in the processing of personal data are obligated to ensure the confidentiality of the information and data, even after their relationship with CARPOL has ended.
CARPOL enters into contracts with all suppliers or third parties that meet the criteria for Data Processors under the terms set forth in current legislation.
CARPOL establishes the data processing instructions to be followed by the Data Processor and verifies that the various suppliers handle information appropriately in accordance with the terms set forth in the contract and the law as “Personal Data Processors.”.
Once the contractual obligation has been fulfilled, personal data is destroyed or returned to the company, as are any media or documents containing personal data that was the subject of the processing.
If the data processor uses the data for another purpose, discloses it, or uses it in violation of the terms of the contract, the data processor shall also be considered the data controller and shall be personally liable for any violations it has committed.
CARPOL has established guidelines governing its relationship with external parties who have access or may potentially have access to information or IT resources—and, therefore, to its databases.
Any third party that accesses the information and IT resources must comply with the guidelines established by CARPOL in its Privacy Policy.
Confidentiality agreements are established regarding access to information and IT resources to ensure that access to information is not granted without explicit authorization and commitment.
The contract between CARPOL and external contractors specifies the need for access to information.
16. DATA TRANSFERS TO THIRD COUNTRIES
In accordance with Title VIII of Law 1581 of 2012, the transfer of personal data to countries that do not provide adequate levels of data protection is prohibited. A country is deemed to offer an adequate level of data protection when it complies with the standards established by the Superintendency of Industry and Commerce on this matter, which in no case may be lower than those required by law for the recipients of such data. This prohibition shall not apply in the following cases:
- Information for which the Data Subject has given his or her express and unambiguous consent to the transfer.
- Exchange of medical data, when required for the treatment of the Data Subject for health or public health reasons.
- Bank or securities transfers, in accordance with the applicable laws.
- Transfers agreed upon under international treaties to which the Republic of Colombia is a party, based on the principle of reciprocity.
- Transfers necessary for the performance of a contract between the Data Subject and the data controller, or for the implementation of precontractual measures, provided that the Data Subject has given consent.
- Transfers required by law to safeguard the public interest, or to recognize, exercise, or defend a right in legal proceedings.
It should be noted that, in cases not covered by an exception, the Superintendency of Industry and Commerce is responsible for issuing the declaration of compliance regarding the international transfer of personal data.
17. COOKIES OR WEB BUGS
The processing of information through cookies is governed by the Cookie Policy published on the website.
18. SAFETY MEASURES
CARPOL has internal information security mechanisms and protocols for accessing and managing the databases it administers to prevent the alteration, loss, unauthorized or fraudulent access to, or use of personal information. To this end, it will adopt the technical, human, and administrative measures necessary to ensure the security of the records.
However, CARPOL disclaims liability for unlawful actions by third parties, technical or technological failures, or any situation beyond its direct control and for which it is not responsible.
In the event of security incidents that compromise personal data, CARPOL will take the containment, mitigation, and reporting measures provided for in current regulations and, where appropriate, will notify the Superintendency of Industry and Commerce and the affected data subjects.
In addition to the above, CARPOL has developed and/or will implement contractual provisions to strengthen the accountability of Data Processors (if applicable) and, in general, of anyone with access to the databases, such as:
- Confidentiality agreements or clauses with suppliers, contractors, and third parties.
- Confidentiality Clauses and Personal Data Handling in Employee Employment Contracts.
- Inclusion of consent notices and privacy notices in forms and at events where personal information is collected.
All CARPOL employees and contractors involved in the processing of personal data are required at all times to ensure the confidentiality of the information.
19. TERM OF VALIDITY
This Policy will take effect on June 9, 2026.
The databases in which personal data will be stored will be retained for as long as the purpose for which the data was collected remains valid, the contractual relationship with the data subject continues, or until the data subject requests its deletion, provided that there is no legal or contractual obligation to retain it for a longer period.
CARPOL reserves the right to modify this Information and Personal Data Processing Policy at any time and unilaterally. Any substantial changes to the Data Processing Policies will be communicated to Data Subjects in a timely manner through publication on the CARPOL website, bulletin boards, email, or any other means deemed appropriate and effective for this purpose, indicating the date on which the new Policy will take effect. The changes will not take effect until after their publication.