TITLE I: Responsible for the treatment
TITLE II: Objective
TITLE III: Definitions
- Authorization: Prior, express and informed consent of the Owner to carry out the Processing of personal data.
- Database: Organized set of personal data that is subject to processing.
- Personal information: Any information linked to or that can be associated with one or more specific or identifiable natural persons.
- Data Controller: Natural or legal person, public or private, who by itself or in association with others, carries out the processing of personal data on behalf of the Data Controller.
- Data Controller: Natural or legal person, public or private, who by itself or in association with others, decides on the database and/or the processing of data.
- Titular: Natural person whose personal data is subject to processing.
- Treatment: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
- Area in charge of Personal Data Protection/Privacy Officer: Designated person in charge within the Company, responsible for supervising, controlling and promoting the application of the Personal Data Protection Policy.
TITLE IV: Principles to which the treatment is subject
The processing of personal data carried out in connection with this Data Processing Policy must be strictly governed by the following principles:
- Legality: Treatment must be subject to the provisions of the Law.
- Purpose: The purpose of the Treatment must be legitimate, temporary and informed to the owner.
- Reasonable limit: The storage and processing of personal data will be limited to what is essentially necessary to fulfill the previously specified purposes of the business relationship, as well as the fulfillment of the purposes authorized by the Owner.
- Freedom: The data may only be processed with the prior, express, informed and self-determined consent of the owner or by legal or judicial order.
- Truthfulness or quality: The information must be true, complete, accurate, up-to-date, verifiable and understandable.
- Transparency: The right of the data subject to obtain information about his or her data at any time and without restrictions must be guaranteed.
- Restricted access and circulation: The Treatment may only be carried out by persons authorized by the Owner or by the persons provided for by Law.
- Security: Information must be handled with the necessary measures to ensure the security of records and prevent their alteration, loss, unauthorized or fraudulent consultation, use or access.
- Confidentiality: Personal data that is not public in nature is confidential and can only be provided under the terms of the Law. Any person involved in the processing of information must guarantee its confidential nature.
TITLE V: Purposes of the Treatment
Administrative and Accounting Management:
- Data administration for managing supplier and customer account statements.
- Obtaining authorization to consult credit history in risky entities.
- Formalization and management of commercial agreements, support for external and internal audits.
- Annual report to the National Tax and Customs Directorate (DIAN) in compliance with legal obligations.
- Recording and supporting financial and accounting information for transaction tracking.
- Administration of contracts with third-party service providers.
- Management of billing and collection processes to support internal and external audits.
Commercial Management, Suppliers and Contractors:
- Management of relationships with customers and suppliers to facilitate internal processes.
- Maintaining business relationships with suppliers and contractors.
- Management of training programs for workers according to the requirements of commercial areas.
- Control and monitoring of distribution and logistics with suppliers.
- Advertising commercial promotions and commercial prospecting through text messages to clients.
Human Resources and Occupational Health:
- Verification and evaluation of candidates in selection processes.
- Conducting and verifying comprehensive security studies for candidates.
- Control and monitoring of formalization of employment contracts.
- Monitoring and delivery of equipment to workers according to requirements and labor legislation.
- Statistical control of active and inactive personnel.
- Tracking temporary workers.
- Verification and management of payroll payments and reporting of employment developments.
- Management of the occupational health and safety system to mitigate risks and respond to incidents.
- Promotion of well-being activities and comprehensive development of workers in the work environment.
- Risk control and monitoring and development of action plans for their mitigation.
- Monitoring absenteeism and administering entry and exit medical examinations.
Technology and Security:
- Control of computer and technological systems for the administration of keys, users and licenses.
- Guaranteed security of personal, financial and educational information.
- Development and updating of computational tools.
- Management of security controls for entry and exit of the Company's facilities.
TITLE VI: Processing of Personal Data of a Sensitive Nature
Processing of data of minors:
- Respect the best interests of minors.
- Ensure respect for your fundamental rights.
- Obtain authorization from the minor's legal representative, considering the opinion of the minor himself or herself according to his or her maturity, autonomy and ability to understand the matter.
Rights of the owner of the information:
- Know, update and rectify your personal data that is being processed by THE CONTROLLER or those in charge of the processing.
- Request proof of the authorization granted to THE CONTROLLER, except when it is expressly excepted as a requirement for processing.
- Be informed by THE CONTROLLER upon request, regarding the use that has been given to your personal data.
- Revoke authorization and/or request deletion of data when the processing does not respect constitutional and legal principles, rights and guarantees.
- Be familiar with our Policy on the processing of Personal Data and any substantial changes that may occur in it.
- Access and know free of charge the personal data that is subject to processing in accordance with the provisions of the law, in the processing of personal data.
- Please refrain from answering questions about sensitive data. Answers regarding sensitive data or data about children and adolescents will be optional.
- Others granted by current legal regulations.
TITLE VII: Rights of the Information Holder
- Know, update and rectify your personal data that is being processed by THE CONTROLLER or those in charge of the processing.
- Request proof of the authorization granted to THE CONTROLLER, except when it is expressly excepted as a requirement for processing.
- Be informed by THE CONTROLLER upon request, regarding the use that has been given to your personal data.
- Revoke authorization and/or request deletion of data when the processing does not respect constitutional and legal principles, rights and guarantees.
- Submit complaints to the Superintendency of Industry and Commerce for violations of the provisions of Law 1581 of 2012.
- Be familiar with our Policy on the processing of Personal Data and any substantial changes that may occur in it.
- Access and know free of charge the personal data that is subject to processing in accordance with the provisions of the law, in the processing of personal data.
- Please refrain from answering questions about sensitive data. Answers regarding sensitive data or data about children and adolescents will be optional.
- Others granted by current legal regulations.
TITLE VIII: Obligations of the Company as Data Controller
- Guarantee the Owner, at all times, the full and effective exercise of his or her rights.
- The data controller must seek the means through which to obtain express authorization from the data owner to carry out any type of processing and keep a copy of said authorization.
- The Data Controller must clearly and expressly inform its users, employees, suppliers and third parties in general from whom it obtains data, the treatment to which they will be subjected, the purpose of said treatment and the rights that assist it by virtue of the authorization granted. To do so, THE CONTROLLER must design the strategy through which for each event, mechanism or request for data that is made, it will inform them of the respective treatment in question.
- Inform the data owners in each case of the optional nature of responding and providing the respective information requested.
- In all cases where data is collected, all data subjects must be informed of their rights with respect to their data.
- Keep the information under the necessary security conditions to prevent its adulteration, loss, consultation, unauthorized or fraudulent use or access.
- Provide the identification, physical or electronic address and telephone number of the person or area that will be responsible for the treatment.
- Guarantee at all times to the owner of the information the full and effective exercise of the right to habeas data and petition, that is, the possibility of knowing the information that exists or is stored in the database about him, requesting the updating or correction of data and processing queries, all of which will be carried out through the consultation or claim mechanisms provided for in this manual.
- Maintain the records of stored personal data with the appropriate security measures to prevent their deterioration, loss, alteration, unauthorized or fraudulent use and periodically and promptly update and rectify the data, whenever the data owners report new developments or requests.
- Ensure that the information provided to the Data Processor is true, complete, accurate, up-to-date, verifiable and understandable.
- Update the information, communicating in a timely manner to the Data Processor all new developments regarding the data that you have previously provided and adopt the other measures necessary to ensure that the information provided remains up to date.
- Rectify information when it is incorrect and communicate the relevant information to the Data Processor.
- Provide the Data Processor, as appropriate, only with data whose processing has been previously authorized in accordance with the provisions of this Manual.
- Demand that the Data Processor respect the security and privacy conditions of the Owner's information at all times.
- Process queries, complaints and requests made under the terms set out in the Law or in this Manual.
- Adopt an internal manual of policies and procedures to ensure proper compliance with the Personal Data Protection Law and, in particular, to address queries, complaints and requests.
- Inform the Data Processor when certain information is being discussed by the Owner, once the request has been submitted and the respective process has not been completed.
- Inform, at the request of the Owner, about the use given to their data.
- Inform the data protection authority when security code violations occur and there are risks in the management of the information of the Holders.
TITLE IX: Transmission and International Transfer of Data
TITLE X: Data Security
TITLE XI: Authorization for Treatment
TITLE XII: Procedure for the presentation of Claims, Queries and Complaints
Questions:
- Determine your identity, including your name and identification number.
- The reason for the consultation must be clearly and expressly specified.
- The legitimate interest with which the action is taken must be accredited, attaching in all cases the appropriate supporting documents.
- The physical or electronic correspondence address to which the response to the request can be sent is indicated.
Claims:
TITLE XIII: Handling of Queries and Complaints
THE CONTROLLER has an area responsible for handling and resolving queries and complaints from personal data holders or persons authorized to do so. Holders may submit their queries and complaints through the following channels:
- Email: comercial@corgasa.pe.
- Physical address: Riomar Street C-12, Belén, Maynas, Loreto, Peru.
TITLE XIII: Modifications to the Policy
TITLE XIII: Validity of Databases