PRIVACY POLICY

PURPOSE

To establish guidelines for the handling of personal data.

SCOPE

This policy applies to personal databases administered by ISL, whether in physical or electronic form.

CRITICAL ASPECTS

Not applicable.

DEFINITIONS

This manual adopts the definitions set out in Article 3 of Colombian Law 1581 of 2012 and Decree 1377 of 2013, including:

Authorization

The data subject's prior, express, and informed consent to carry out the processing of personal data.

Database

An organized set of personal data that is subject to Processing.

Personal Data

Any information linked to or that may be associated with one or more identified or identifiable natural persons.

Data Processor

A natural or legal person, public or private, that processes personal data on behalf of the Data Controller, either alone or jointly with others.

Data Controller

A natural or legal person, public or private, that decides on the database and/or the Processing of the data, either alone or jointly with others.

Data Subject

The natural person whose personal data are subject to Processing.

Processing

Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.

Privacy Notice

A verbal or written communication generated by the Data Controller, addressed to the Data Subject for the Processing of their personal data, informing them of the existence of the information processing policies that will apply, how to access them, and the purposes for which the personal data will be processed.

Public Data

Data that is not semi-private, private, or sensitive. Public data includes, among others, information relating to a person's marital status, profession or occupation, and status as a merchant or public servant. By their nature, public data may be contained in public records, public documents, official gazettes and bulletins, and duly enforceable judicial rulings that are not subject to confidentiality.

Sensitive Data

Sensitive data are those that affect the Data Subject's privacy or whose improper use may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in trade unions, social organizations, or human rights organizations, or data relating to health, sexual life, and biometric data.

Transfer

Transfer of data occurs when the Data Controller and/or Data Processor, located in Colombia, sends information or personal data to a recipient who is also a Data Controller and is located inside or outside the country.

Transmission

Processing of personal data that involves communicating the data inside or outside the territory of the Republic of Colombia for the purpose of Processing by the Data Processor on behalf of the Data Controller.

 

INTRODUCTION

The organization processes information and Personal Data according to the requirements arising in fulfillment of its corporate purpose, including data relating to clients, suppliers, and employees.
This document establishes policies for the handling of personal data, in accordance with Articles 15 and 20 of the Political Constitution of Colombia, the provisions of Law 1581 of 2012 and Regulatory Decree 1377 of 2013. Its scope of application is the processing of personal and financial data collected and processed by ISL S.A.


OBJECTIVES

• To adopt an internal manual of policies and procedures to comply with Article 17 of Law 1581 of 2012 regarding the duties of controllers of personal and financial data processing, and to ensure proper handling of inquiries and claims.

• To establish procedures for the collection, handling, and processing of data in order to guarantee and protect the fundamental right of habeas data as established in the same Law.


PURPOSE OF PROCESSING

The organization, Data Controllers, and Data Processors will process Personal Data solely for the following purposes:

• To comply with the company's internal processes related to suppliers and contractors

• To carry out marketing and commercialization activities for products and services.

• Human resource management within the Organization, including processes such as training, social welfare, occupational health, labor processes, and payroll management.

• Control and prevention of money laundering and financing of terrorism.

• Management of information necessary and relevant to fulfill tax obligations.

• Submission of reports to supervisory and control entities.

• Fulfillment of contracts entered into with clients and suppliers.

• Transmission of personal data to third parties with whom data processing agreements have been entered into for commercial, administrative, and operational purposes.

• To maintain and process information relating to clients, necessary to provide the company's services and products.

• Consultation, storage, administration, transfer, processing, and reporting of information to duly constituted credit bureaus or databases regarding credit, financial, and commercial behavior.


DATA COLLECTION

• Data will be collected directly or taken from documents provided by clients, suppliers, or employees of ISL S.A., or through its information systems.

• Data obtained from video recordings made inside or outside ISL S.A. facilities are used for the security of persons, assets, and facilities and may be used as evidence in any type of proceeding.


DATA PROTECTION

ISL S.A. commits to adopting the technical, human, and administrative measures necessary to guarantee the security of personal and financial data of Data Subjects, preventing unauthorized consultation or access, alteration, or fraudulent use by third parties.
Physical files are likewise subject to protection through control measures that ensure their proper use.
ISL S.A. will maintain mandatory security protocols for personnel with access to personal and financial data, including:


• Measures, standards, procedures, rules, and protocols aimed at guaranteeing the level of security required under Law 1581 of 2012

• Staff roles and obligations

• Structure of personal databases and description of information systems that process them.

• Notification, management, and response procedure for incidents.

• Backup and data recovery procedure.

• Periodic controls to verify compliance with the implemented security procedure.

• Ongoing review and updating of procedures when relevant changes occur in the organization's information handling, and due to changes in applicable personal data security regulations.

• Review and updating of the scope of application of the procedure when necessary.


PRINCIPLES

ISL S.A. takes the following principles into account in the collection, storage, use, and processing of personal and financial data:


Legality. Data Processing must comply with the law and regulations that implement it.

Transparency. Data Processing must have a legitimate purpose in accordance with the Constitution and the Law, and the Data Subject must be informed. It must also guarantee the Data Subject's right to obtain information about the existence of their data at any time and without restriction.

Freedom. Data Processing may only be carried out with the Data Subject's prior and informed consent. Personal and financial data may not be obtained or disclosed without prior authorization, or except as required by law or court order.

Accuracy. Information must be truthful, complete, accurate, up to date, verifiable, and understandable. Processing of partial, incomplete, fragmented, or misleading data is prohibited.

Temporality. ISL S.A. will use the Data Subject's information only for the period required by the purpose communicated to the Data Subject when Authorization was obtained.

Security. Data Processing will be carried out in accordance with the law and the Constitution and only by persons authorized by the Data Subject and/or by persons provided for in the law. Access to and availability of personal data must be limited to Data Subjects or authorized third parties in accordance with the law, guaranteeing against alteration, loss, consultation, use, or fraudulent access.

Individuality. ISL S.A. will keep separate the Databases in which it acts as Data Processor from those in which it is the Data Controller.

Confidentiality. All persons involved in the Processing of personal data that are not public in nature are obliged to guarantee the confidentiality of the information, even after their relationship with the Processing activities has ended. Personal data may only be supplied or communicated when authorized by law.


AUTHORIZATION

The processing of personal and financial data by ISL S.A. requires the free, prior, express, and informed consent of the Data Subject. ISL S.A., as Data Controller, will provide the necessary mechanisms to obtain authorization from data subjects, ensuring in all cases that authorization can be granted through physical, electronic, or any other means that allows subsequent consultation.
Authorization will be issued by ISL S.A. and made available to the data subject in accordance with Law 1581 of 2012. Through the consent procedure, it is guaranteed that the data subject has been informed that their personal information will be collected and used for specific and known purposes, and that they have the option to learn of any changes to those purposes and the specific use made of their data.
ISL S.A. will adopt all mechanisms it considers necessary to maintain a record of when and how authorization was obtained from data subjects for the processing of their data.


PRIVACY NOTICE

The privacy notice is the physical or electronic document made available to the data subject informing them of the existence of the information processing policies that will apply to their personal data, how to access them, and the type of processing that will be carried out.


AUTHORIZATION FOR THIRD PARTIES

The Data Subject may AUTHORIZE, through a duly authenticated document, a third party to request their information.


RIGHTS OF DATA SUBJECTS

(Law 1581 of 2012, Article 8).

• The Data Subject may know, update, and rectify their personal data before Data Controllers or Data Processors when the data are partial, inaccurate, incomplete, fragmented, or misleading.

• To request proof of the authorization granted to the Data Controller, except where expressly exempted as a requirement for Processing under Article 10 of Law 1581 of 2012.

• To request and be informed by the Data Controller or Data Processor regarding the use given to their personal data.

• To file complaints with the Superintendence of Industry and Commerce for violations of this law and other regulations that amend, add to, or supplement it.

• To revoke authorization and/or request deletion of data when Processing does not respect constitutional and legal principles, rights, and guarantees. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that the Data Controller or Data Processor has engaged in conduct contrary to this law and the Constitution.

• To access their personal data that have been subject to Processing free of charge.

• Data Subjects may exercise their legal rights and follow the procedures established in this Policy by presenting their national ID card or original identification document, or through a duly accredited and identified representative. Minors may exercise their rights through their parents or legal guardians, who must demonstrate this with the appropriate documentation.


CLAIMS

The Data Subject, their representatives, and/or authorized agents may file CLAIMS regarding:

a) Personal Data processed by ISL S.A. that should be corrected, updated, or deleted.

b) The alleged failure by ISL S.A. to comply with its legal duties. These mechanisms may be physical or electronic.

In any case, ISL S.A. must keep proof of the inquiry and its response.
To process a CLAIM, it must be submitted as follows:

1. Address ISL S.A. at Calle 35 No. 16-24 Oficina 1305, or email info@islsa.com

2. Include the name and identification document of the Data Subject, address and contact details, together with documentation supporting the claim.

3. Include a detailed description of the facts giving rise to the claim and the objective sought: update, correction, deletion, or fulfillment of duties.

To proceed with the claim, the Data Controller will verify:

  1. The identity of the Data Subject or authorized agent, requiring presentation of the original national ID card or identification document of the Data Subject, and special or general powers of attorney, as applicable.
  2. If the claim or documentation is incomplete, ISL S.A. will request the claimant once, within five (5) business days following receipt of the claim, to remedy the deficiencies. If the claimant does not provide the required documentation and information within thirty (30) calendar days from the date of the claim, it will be deemed withdrawn.


INQUIRIES

In accordance with Article 14 of Law 1581 of 2012, the data subject or their authorized agent may inquire about the personal or financial information of the data subject held in any database of ISL S.A.
The power of disposition or decision that the data subject has over information concerning them necessarily entails the right to access and know whether their personal information is being processed, as well as the scope, conditions, and general terms of such processing.
ISL S.A. guarantees the right of inquiry so that the Data Subject or their authorized agent may know the effective existence of the processing to which their personal data are subject and the essential circumstances of such processing.
The procedure for handling data inquiries is:

a) Address ISL S.A. at Calle 35 No. 16-24 Oficina 1305, or email info@islsa.com

b) Include the name and identification document of the Data Subject, address and contact details.

c) The maximum term for responding to the request is fifteen (15) business days from the date of receipt.

d) When it is not possible to respond to the inquiry within that term, the interested party will be informed before the fifteen (15) business days expire, stating the reasons for the delay and indicating the date on which the inquiry will be answered.


EFFECTIVE DATE

This Policy takes effect as of November 1, 2016.
Personal Data that are Processed will remain in the Database of ISL S.A. for as long as necessary for the purposes mentioned in this Policy and for which they were collected.