Personal Data Protection
I. IDENTIFICATION OF THE PERSON RESPONSIBLE FOR THE PROCESSING OF PERSONAL DATA
|
NAME OF THE ORGANIZATION
|
SIDOC FOUNDATION
|
|
NIT.
|
900053142-1
|
|
ADDRESS AND DOMICILE
|
CALLE 12 A No. 37-15 - YUMBO (VALLE DEL CAUCA)
|
|
E-MAIL
|
contafundacion@sidocsa.com
|
|
WEB SITE
|
www.fundasidoc.org
|
II. OBJECTIVE
Establish guidelines and general criteria for employees of FUNDACION SIDOC to make an assessment and effectively deal with the handling of personal data of employees, customers and suppliers and possible claims that may be filed with the company. And thus ensure that the level of satisfaction of these people is in accordance with current Colombian legislation.
III.SCOPE
This Policy applies from the moment in which the personal data of employees, customers and suppliers are being collected until the moment a response is provided according to the request submitted with reference to any personal information that is stored in FUNDACION SIDOC's databases.
IV. REGULATORY FRAMEWORK
The following is a list of the regulations related to Personal Data Protection:
- Law 1266 of 2008
- Law 1581 of 2012
- Decree 1377 of 2013
V. APPLICATION
Personal data registered in any database, which makes them susceptible to processing by public or private entities, carried out in the Colombian territory or in countries where the Colombian legislation is applicable.
VI. DEFINITIONS
Actors in the processing of Personal Data: Are the companies or persons who carry out the provision, collection and processing of personal data, these are:
-"Data Controller": Natural or legal person, public or private, who by itself or in association with others, decides on the database and/or the Processing of the data.
-Data Processor": Natural or legal person, public or private, who by itself or in association with others, decides on the database and/or the processing of the data.
private, that by itself or in association with others, carries out the Processing of Personal Data on behalf of the Controller of the Processing of Personal Data.
"Personal Data Controller": Natural person whose personal data is the object of Processing.
"User": The natural or legal person who may access personal information of one or more data subjects provided by the operator or by the source, or directly by the data subject. The user must guarantee the protection of the data owner's rights. In the event that the user in turn delivers the information directly to an operator, the latter will have the dual status of user and source, and will assume the duties and responsibilities of both.
"Authorization": Prior, express and informed consent of the owner to carry out the Processing of Personal Data.
"Privacy Notice": Physical, electronic or any other format document, generated by the Data Controller, which is made available to the Data Subject to communicate the existence of the information processing policies that will be applicable, how to access them and the characteristics of the Processing that is intended to be given to the personal data.
"Database": Organized set of personal data that is subject to processing.
"Consultation": Process through which the Personal Data Subject may request FUNDACION SIDOC. for his/her personal information contained in the databases.
"Personal Data": Any information linked or that can be associated to one or several determined or determinable natural persons.
"Public data": Data qualified as such according to the mandates of the law or the Political Constitution and all those that are not semi-private or private, in accordance with the law. Among others, data contained in public documents, court rulings that are not subject to confidentiality and those relating to the civil status of persons are public.
"Sensitive Data: Data that affect the privacy of the Data Subject or whose improper use may generate discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions, social organizations, human rights organizations or those that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data related to health, sex life and biometric data.
"Claim": Process through which the Owners of the Personal Data or their assignees, may request FUNDACION SIDOC. the update, rectification, partial or total deletion of the information, proof of authorization or revocation of the same.
"SIC: Superintendence of Industry and Commerce.
"Processing of Personal Data": Any operation or set of operations on Personal Data, such as collection, storage, consultation, exchange, transfer, use, circulation or deletion.
VII. RULES AND CRITERIA OF APPLICATION
1. GENERAL PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
The following principles shall be complied with in the Processing of Personal Data:
a) Principle of purpose: The Processing of Personal Data must obey a legitimate purpose, which shall be informed to the Data Subject.
b) Principle of freedom: The Processing of Personal Data may only be carried out with the prior, express and informed consent of the Data Subject. Personal Data may not be obtained or disclosed without prior authorization or legal or judicial mandate that relieves the consent of the Data Subject.
c) Principle of truthfulness or quality: The information subject to processing must be truthful, complete, accurate, updated, verifiable and understandable. The processing of partial, incomplete, fractioned or misleading data is prohibited.
d) Principle of transparency: The right of the Data Subject to obtain from FUNDACION SIDOC, at any time and without restrictions, information about the existence of data concerning him/her, must be guaranteed in the Processing.
e) Principle of restricted access and circulation: Personal Data, except for public information, may not be available on the Internet or other means of dissemination or mass communication, unless access is technically controllable to provide restricted knowledge only to the Data Controllers or third parties authorized by them.
f) Principle of security: The information subject to processing shall be handled with the technical, human and administrative measures necessary to provide security to the records, avoiding their adulteration, loss, consultation, use or unauthorized or fraudulent access.
g) Principle of confidentiality: All persons involved in the Processing of Personal Data are obliged to guarantee the confidentiality of the information, even after the end of their relationship with any of the tasks involved in the processing.
2. SPECIAL CATEGORIES OF DATA
2.1 Sensitive Data:
Processing of sensitive data is prohibited, except when:
(a) The Data Subject has given his/her explicit authorization to such Processing, except in cases where the granting of such authorization is not required by law.
b) The Processing is necessary to safeguard the vital interest of the Data Subject and he/she is physically or legally incapacitated. In these events, the legal representatives must grant their authorization.
c) The Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association or any other non-profit organization, whose purpose is political, philosophical, religious or trade union, provided that it refers exclusively to its members or persons who maintain regular contacts for its purpose. In these events, the data may not be provided to third parties without the authorization of the Data Controller.
d) The Processing refers to data that are necessary for the recognition, exercise or defense of a right in a judicial process.
e) The Processing has a historical, statistical or scientific purpose. In this event, measures must be taken to suppress the identity of the Data Controllers.
2.2 Rights of children and adolescents:
According to the provisions of Article 7o of Law 1581 of 2012 and Article 12 of Decree 1377 of 2013, FUNDACION SIDOC. will only carry out the Processing, that is, the collection, storage, use, circulation and/or deletion of Personal Data corresponding to children and adolescents, provided that this Processing responds to and respects the best interests of children and adolescents and ensures respect for their fundamental rights.
Once the above requirements have been met, FUNDACION SIDOC shall obtain the authorization of the legal representative of the child or adolescent, after the minor has exercised his or her right to be heard, an opinion that will be assessed taking into account the maturity, autonomy and ability to understand the matter.
3. TREATMENT TO WHICH THE DATA WILL BE SUBJECTED AND ITS PURPOSE
The personal data that customers and suppliers provide or have provided to FUNDACION SIDOC. are subject to processing (collection, storage, use, circulation or deletion) in order to adequately provide services for the purchase and sale of products, materials and raw materials of the steel and metalworking industry, marketing activities, sales, billing, collection management, collection, service improvement, sending commercial information through e-mails, provide assistance, service and technical support of our products, perform the necessary steps to comply with the obligations inherent to our business and products purchased with FUNDACION SIDOC, report on changes in products related to the ordinary course of business of FUNDACION SIDOC, control and
prevent fraud in general, facilitate the execution for the acquisition and disposal of our service. The personal data that are subject to treatment are: name and surname, identity document, age, address, region, country, city, zip code, landline phone number, cell phone number, address, email address, consumer preference, complaints and claims, service news.
3.1. Processing of Sensitive Data
The holder has the right to choose not to provide any information requested by FUNDACION SIDOC. that is considered sensitive data.
4. AUTHORIZATION
The Processing of Personal Data carried out by FUNDACION SIDOC, requires the free, prior, express and informed consent of the Data Subject. FUNDACION SIDOC, in its capacity as Responsible for the Processing of Personal Data, has provided the necessary mechanisms to obtain the authorization of the Data Subject, their successors or legitimate representatives.
The authorization may be given by means of a physical, electronic document or any other format that allows guaranteeing its subsequent consultation, and that, in addition, it may be demonstrated, in an unequivocal manner, that the Data Controller of the Personal Data:
(a) authorized the processing, (b) knows and accepts that FUNDACION SIDOC will collect and use the information for the purposes for which he/she has been informed.
By virtue of the above, the authorization requested must include:
(a) The Data Controller and what data is collected;
b) The purpose of the data processing;
c) The rights of access, correction, updating or deletion of the personal data provided by the holder; and,
d) If Sensitive Data is collected.
e) The identification, physical or electronic address and telephone number of the Data Controller.
5. PRIVACY NOTICE
FUNDACION SIDOC has the Privacy Notice, which contains the information required by Law 1581 of 2012, Decree 1377 of 2013 and any other regulation that modifies and/or complements them; which will be communicated to the Personal Data Holder through the company's means of communication. To facilitate disclosure, its content may be included within the authorization.
6. RIGHTS AND DUTIES OF THE OWNERS
The Personal Data Holder shall have the following rights:
(a) To know, update and rectify the Personal Data.
b) Request proof of the authorization granted to FUNDACION SIDOC.
c) To be informed by FUNDACION SIDOC, upon request, regarding the use given to their Personal Data.
d) Submit queries to the Controller or Data Processor, in accordance with the provisions of paragraph 9 of this policy.
e) File complaints before the Superintendence of Industry and Commerce for infringements to the provisions of this law and other regulations that modify, add or complement it, once the consultation or complaint process has been exhausted before the Controller or the Data Processor, according to Article 16 of Decree 1377.
f) Access free of charge to the Personal Data that are subject to Processing.
g) Request FUNDACION SIDOC. the deletion of their Personal Data and/or revoke the authorization granted for the Processing thereof, by filing a complaint, in accordance with the procedures set forth in paragraph 10 of this Policy. However, the request for deletion of information and the revocation of the authorization will not proceed when the Holder of the information has a legal or contractual duty to remain in the Database and/or Files, nor while the relationship between the Holder and FUNDACION SIDOC. is in force, by virtue of which their data were collected.
The Holder of the Personal Data shall have the duty to keep his/her information updated and guarantee, at all times, the veracity of the same. FUNDACION SIDOC will not be responsible, in any case, for any kind of liability arising from the inaccuracy of the information provided by the Data Subject.
7. SECURITY MEASURES
FUNDACION SIDOC will adopt the technical, human and administrative measures necessary to provide security to the records avoiding their adulteration, loss, consultation, use or unauthorized or fraudulent access. Such measures will respond to the minimum requirements made by the current legislation and their effectiveness will be periodically evaluated.
8. PERSON IN CHARGE OF THE TREATMENT
FUNDACION SIDOC will be responsible and/or in charge of the collection and/or Processing of Personal Data, will keep the Authorization and other stored records, preventing their deterioration, loss, alteration or unauthorized use.
9. CONTACT INFORMATION FOR SUBMISSION OF REQUESTS:
The Owners of the Information may exercise their rights to revoke the authorization for the processing of data, know, update, rectify and delete their Personal Data, by sending communications to the Administrative Management Area, in Acopi Yumbo Valle del Cauca, at Carrea 12a # 37 - 15, telephone 664 4717, ext. 137, Likewise, the Owners of the information may direct their requests to the email contafundacion@sidocsa.com and these must contain the following information:
9.1. Name and identification of the Data Subject.
9.2. 9.2. Precise and complete description of the facts giving rise to the request.
9.3. Physical or electronic address to send the response and report on the status of the procedure.
9.4. Documents and other evidence that are intended to be asserted.
10. REQUESTS BY THE OWNER OF
DATA 10.1 Consultation
The Owners of Personal Data or their assignees may, at any time, consult the personal information contained in the databases of FUNDACION SIDOC. Likewise, they may request proof of the existence of their authorization for the processing of Personal Data.
10.1.1Term for Consultation Attention
In accordance with Law 1581 of 2012, the request for consultation must be answered within a maximum period of ten (10) working days from the date of receipt thereof. When it is not possible to attend the consultation within such term, the interested party will be informed, stating the reasons for the delay and indicating the date on which the consultation will be attended, which in no case may exceed five (5) business days following the expiration of the first term.
10.2 Claims
The Owners of the Personal Data or their assignees may request the updating, rectification or total or partial deletion of data. Likewise, they may request the revocation of the authorization.
10.2.1 Revocation of authorization: The Personal Data Owner or its assignees may revoke the authorization granted, in accordance with the regulations in force.
10.2.2 Deletion of Personal Data: The Data Subject may request the Controller and/or Data Processor the total or partial deletion of personal data.
The request for deletion of the information and the revocation of the authorization shall not proceed when the Data Subject has a legal, contractual or commercial duty to remain in the database.
In accordance with Article 16 of Decree 1377 of 2013, the Data Subject or assignee may only file a complaint before the Superintendence of Industry and Commerce once the consultation or complaint process has been exhausted before the Controller or the Data Processor.
When a claim is received from the Data Subject regarding inconsistencies in the information, or that the data is under discussion by the same, the Data Controller, and when acting on its behalf, the Data Processor, must suspend the use of the same, for a period of time not less than the date of completion of the procedure. For this, FUNDACION SIDOC, responsible for the database, must ensure that there is a record where the following notes are recorded: "claim in process" or "information in judicial discussion" according to the status of processing in which the claim is found.
10.2.3 Term for the attention of Claims related to Personal Data:
In accordance with Law 1581 of 2012, when a claim request is received from the Personal Data Holder, the Data Controller, shall proceed to review whether it contains sufficient information to be addressed, and, in the event that more information is required, shall communicate to the Data Subject, within the following 5 business days following the receipt of the claim so that he/she may remedy the faults. After two (2) months from the date of the request, without the applicant submitting the required information, it will be understood that the claim has been withdrawn.
Likewise, the Law indicates that the maximum term to address the claim shall be fifteen (15) business days from the day following the date of receipt. When it is not possible to attend to it within such term, the following will be informed
The reasons for the delay and the date on which the claim will be attended, which in no case may exceed eight (8) business days following the expiration of the first term.
11. ENTRY INTO FORCE, MODIFICATION AND PERIOD OF VALIDITY OF THE DATA BASES.
This policy applies from July 27, 2013 and the information provided by stakeholders will remain stored for a period of ten (10) years from the date of the last treatment, to allow FUNDACION SIDOC. Compliance with legal obligations and / or contractual obligations especially in accounting, fiscal and tax matters.
This policy may be modified at any time and unilaterally by FUNDACION SIDOC.
General Consideration:
The areas and/or managers in charge of each process are responsible for ensuring the application of the respective corporate policies. The internal auditor, in his role as internal auditor, is responsible for verifying compliance with these policies, according to his annual audit plan, and for reporting the results of his evaluations in his audit reports to both management and the corresponding audit committee.

