PRIVACY POLICY
DANIEL FELIPE SANCHEZ RODRIGUEZ, Colombian ID (CC) 1.020.775.086, and/or the brand DONTCARE (hereinafter "the company") is the party responsible for the processing of the personal data collected through the website www.dontcarebrand.com.
By accepting this policy, I, as the owner of my personal data, consent to its processing by the company, its strategic partners, affiliates, subsidiaries and parent companies, for the purpose of fulfilling the functions and obligations arising from the various transactions carried out through e-commerce or in person at its commercial establishments. I accept that my personal data will be used in the course of the relationship I currently have with the company and for the following purposes: statistics, marketing, contact, sending documentation, information, promotions, events of the company or its partners, or notifications, among others, unless I expressly or verbally request that my data be deleted, corrected or removed from the company's databases through the mechanisms established in this policy.
Below you will find the personal data processing policy adopted by the company in compliance with the obligations of Colombian Law 1581 of 2012 and any other regulations that amend it. This policy is adopted because protecting the personal data of its customers, employees, suppliers or any other individual related to the company is very important to the company, and it is our purpose to fulfill our obligations towards them.
The company guarantees the rights to privacy, intimacy and good name in the processing of personal data; consequently, all our actions will be based on the principles of legality, purpose, freedom, truthfulness or quality, transparency, restricted access and circulation, security and confidentiality.
All persons who, in the course of our commercial, labor or corporate activities, provide us with any type of personal information or data may access, update and correct their data at any time — that is, exercise their habeas data rights. This is the main objective of our policy.
Purpose of the personal data processing policy
This personal data processing policy aims to implement the provisions of Law 1581 of 2012 and any regulations that amend it, exclusively with regard to the databases, files and information containing personal data subject to processing, and explains how the company collects, stores, manages, uses, circulates and processes the information you provide to us through different channels.
It is in the company's interest to safeguard the privacy of the personal information of the data subject obtained through different channels, for which it undertakes to adopt this policy.
The data subject acknowledges that providing personal information through the different channels made available by the company is done voluntarily and in response to specific requests by the company in order to provide or offer a service or product, or to access interactive tools.
The data subject accepts that, through interaction with the company, the company may collect personal data, which may be transferred to third parties. To this end, by accepting this policy the data subject accepts and acknowledges that the company may process the data collected.
The automated collection and processing of personal data as a result of browsing and/or interacting with the company has the following purposes:
- The proper management and administration of the products and/or services offered through the different sales channels that the data subject decides to sign up for, use or contract.
- The quantitative and qualitative study of visits and use of the services by data subjects.
- Sending, by traditional and electronic means, information and/or products and/or services related to the company and its commercial partners.
- Carrying out any procedure before a public authority or a private person or entity for which the information is relevant.
- The proper commercial management that the company may carry out directly in order to offer products or services, including but not limited to the sale of products, advertising, among others.
- Sending information related to companies that have a direct relationship with the company. However, it is clarified that the company will remain responsible for the handling of such data.
Glossary
- Authorization: Prior, express and informed consent of the data subject to carry out the processing of personal data.
- Privacy notice: Verbal or written communication issued by the data controller, addressed to the data subject, informing them of the existence of the information processing policies applicable to them, how to access them, and the purposes of the intended processing of their personal data.
- Database: Organized set of personal data subject to processing.
- Personal data: Any information linked or that can be associated with one or more identified or identifiable natural persons.
- Public data: Data that is not semi-private, private or sensitive. Public data includes, among others, data relating to a person's marital status, profession or occupation, and their status as a merchant or public servant. By its nature, public data may be contained in public records, public documents, official gazettes and bulletins, and duly enforceable court rulings not subject to confidentiality.
- Semi-private data: Data that is not of an intimate, reserved or public nature and whose knowledge or disclosure may be of interest not only to its owner but to a certain sector or group of people or society in general, such as financial and credit data, or data on commercial or service activities.
- Private data: Any information relating to a person's private life, such as personal email, phone number, home address, employment data, education level, administrative or criminal offenses, data managed by tax, financial or social security entities, photographs, videos, and any other data referring to the person's lifestyle.
- Sensitive data: Data that affects the privacy of the data subject or whose improper use may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in trade unions, social or human rights organizations, or organizations promoting the interests of any political party or guaranteeing the rights of opposition parties, as well as data relating to health, sexual life and biometric data.
- Data processor: Natural or legal person, public or private, who, alone or in association with others, processes personal data on behalf of the data controller.
- Data controller: Natural or legal person, public or private, who, alone or in association with others, decides on the database and/or the processing of the data.
- Data subject: Natural person whose personal data is subject to processing.
- Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
- Transfer: Takes place when the data controller and/or processor, located in Colombia, sends the information or personal data to a recipient who is in turn a data controller and is located inside or outside the country.
Obligations of the company
The company will use the information solely and exclusively to fulfill the functions and obligations arising from the various transactions carried out through e-commerce or in person at our commercial establishments, if any, as well as the legal relationships with our employees, directors and dependents. It will also use such information for statistical, marketing and contact purposes, sending documentation, information, promotions, events of the company or its partners, or notifications, among others, unless you expressly or verbally request that your data be deleted, corrected or removed from the company's databases through the mechanisms established in this policy.
When carrying out any type of activity with the company, whether in person or through electronic means, the data subject must expressly or tacitly give consent for the handling of their information. Consent must be free, prior, express and informed on the part of the data subject for the processing of their personal data, except in cases expressly authorized by law.
You may give your authorization as follows: (i) verbally at the time of purchase, (ii) in writing, and (iii) when accepting the terms and conditions of the commercial relationship.
Exceptions to the authorization for the processing of personal data
- When such information is required by a public or administrative entity in the exercise of its constitutional or legal functions.
- When there is a court order requiring it.
- In the event of medical and/or health emergencies.
- Processing of information authorized by law for historical, statistical or scientific purposes.
- Data related to the civil registry of persons.
- Other cases established by law.
Rights of data subjects
Data subjects have the right to:
- Access, update and correct their personal data before the data controllers or processors. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented or misleading data, or data whose processing is expressly prohibited or has not been authorized. To this end, the company has established mechanisms to identify the person, in order to prevent unauthorized third parties from accessing the data subject's data.
- Request proof of the authorization granted to the company, except in cases where authorization is not required under Article 10 of Law 1581 of 2012.
- Be informed by the company, upon request, about the use given to their personal data.
- File complaints with the Colombian Superintendence of Industry and Commerce (Superintendencia de Industria y Comercio) for violations of the law and other regulations that amend, add to or supplement it.
- Revoke the authorization and/or request the deletion of the data when the processing does not respect constitutional and legal principles, rights and guarantees. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that the controller or processor has engaged in conduct contrary to the law and the Constitution.
- The request for deletion of information and revocation of authorization will not proceed when the data subject has a legal or contractual duty to remain in the controller's or processor's database.
- Access free of charge their personal data that has been subject to processing.
Duties of the company
- Guarantee the data subject, at all times, the full and effective exercise of the right of habeas data.
- Request and keep a copy of the respective authorization granted by the data subject, when the type of data processed requires it.
- Duly inform the data subject about the purpose of the collection and the rights they have by virtue of the authorization granted.
- Keep the information under the security conditions necessary to prevent its alteration, loss, unauthorized or fraudulent consultation, use or access.
- Guarantee that the information provided to the data processor is truthful, complete, accurate, up to date, verifiable and understandable.
- Update the information, promptly communicating to the data processor all changes regarding the data previously provided, and adopt any other measures necessary to keep the information provided up to date.
- Correct the information when it is incorrect and communicate the relevant changes to the data processor.
- Provide the data processor, as applicable, only with data whose processing has been previously authorized by the data subject.
- Require the data processor at all times to respect the security and privacy conditions of the data subject's information.
- Handle inquiries and complaints made by data subjects.
- Inform the data processor when certain information is under dispute by the data subject, once the complaint has been filed and the respective process has not been completed.
- Inform the data subject, upon request, about the use given to their data.
- Inform the data protection authority when security code violations occur and there are risks in the management of data subjects' information.
Transfer of data subjects' personal data to third parties
The company may transfer to third parties the personal data of data subjects collected through the website. The user expressly accepts such processing. In addition, the data subject consents to their personal data being transferred when so required by the competent administrative authorities or by court order.
The data subject also understands that the data they provide will form part of a file and/or database that may be used by the company for the purpose of carrying out a specific process or procedure. The data subject may modify or update the information provided at any time, provided that such modification is made before the delivery of the service or product requested from the company.
Since no transmission over the internet is absolutely secure and such security cannot be guaranteed, the data subject assumes the hypothetical risk this implies, which they know and expressly accept, fully releasing the company from it, including any risk that may arise for any reason on the platform used to make payments for services or products.
The company is not responsible for any consequence arising from improper access by third parties to the database and/or any technical failure in the operation and/or preservation of data in the system in any of the sections of its website.
The company has adopted the legally required security levels for the protection of personal data, implementing the technical and organizational measures.
The company may modify the personal data processing policies contained herein, at its sole discretion and at any time, and they will be in force once published on the website.
In the event that the company modifies the personal data processing policy contained herein, it may inform data subjects through its website or by other means it deems appropriate.
The company informs data subjects whose personal data it processes that they have the following rights:
- Access the personal data that has been subject to processing in accordance with Law 1581 of 2012 and other regulations that amend, add to or supplement it.
- Access, update and correct personal data before the data controller and the data processor. The right to update and correct data may be exercised, among others, in relation to partial, inaccurate, incomplete, fragmented or misleading data, or data whose processing is expressly prohibited or has not been authorized.
- Request proof of the authorization granted to the data controller, except when expressly exempted as a requirement for processing, in accordance with Article 10 of Law 1581 of 2012.
- Be informed by the data controller or data processor, upon request, about the use given to their personal data.
- File complaints with the Superintendence of Industry and Commerce for violations of Law 1581 of 2012 and other regulations that amend, add to or supplement it.
- Revoke the authorization and/or request the deletion of the data when the processing does not respect constitutional and legal principles, rights and guarantees. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that the controller or processor has engaged in conduct contrary to the Constitution, Law 1581 of 2012 and other regulations that govern, amend or replace it.
In compliance with Law 1581 of 2012, Decree 1377 of 2013 and other regulations that amend, add to or supplement them, we inform you that you can consult this personal data processing policy on our official website: WWW.DONTCAREBRAND.COM