eCloud · Engitech Cloud
User guideseCloud help and resources

ECLOUD / LEGAL INFORMATION

Personal data processing policy

ENG DAT 011.0 VersionEdition · 19 September 2026
Read document ↓

Comprehensive Personal Data Processing and Protection Policy

ENGITECH SOLUCIONES INFORMÁTICAS S.A.S.

NIT 900.611.904-1 | Colombia | ENG DAT 01

Unique corporate policy for the processing of personal data by ENGITECH and rules applicable to customers, users, employees, seekers, contractors, suppliers and other third parties.

1.0 Version · 19 September edition of 2026. Its application starts when it is adopted and made available by ENGITECH; the date of publication will be kept in the version register. Previous treatments continue to be subject to their authorizations and legal bases, without retroactive expansion of purposes.

This policy develops in an independent document the protection of personal data for the entire portfolio. Distinguish ENGITECH's own bases of the information it processes on behalf of its customers. Acceptance of the trade agreement does not constitute unlimited authorization to treat data, advertise or transmit them to any third party.

1 Identification and care channels

The head of this policy is ENGITECH SOLUCIONES INFORMATICAS S A S, NIT 900.611.904-1, commercial registration 02315759, domiciled in Bogotá D. C. Address: Carrera 96G Bis # 22-19, Bogotá D. C., Colombia. Phone: +57 601 432 2144. Email for data protection, queries and claims: info@engitech.com.co, subject “Protection of personal data”. Judicial notifications mail: ivan.torres@engitech.com.co. Site: https://engitech.com.co.

The management coordinates the care of rights and designates those responsible for their implementation internally. The designated person does not modify public channels or restrict rights. The legal representative identified in the certificate provided, issued the 17 of September of 2026, is Iván Camilo Torres León. Your personal identity document is not published because it is not necessary to exercise the rights described here.

The policy applies to all ENGITECH lines, including eCloud, Engitech Cloud, TrustNet Security and IT Solutions. A single corporate policy is used for all; the purposes and functions are determined by relationship and actual activity, not by unlimited generic authorizations.

2 Scope functions and principles

Personal data is information linked or associable to a particular or determinable natural person. Treatment includes collection, storage, use, circulation and suppression. Responsible is the one who decides on the basis or its purposes; commissioned is the one who executes treatment on his own. A data of public access does not enable any use incompatible with the law.

ENGITECH acts as responsible for its commercial contact bases, contracting, billing, human talent, suppliers, access and security. He acts as a manager when he lodges, supports, administers technically or processes information on a client's instructions. If he is in charge of another entity, he must have the power to link to ENGITECH and transfer instructions. The actual function prevails over the label of the contract.

Legality, purpose, freedom, quality, transparency, restricted access and movement, security and confidentiality are applied. The information is limited to the information required for an informed and legitimate purpose and is retained only during the justified period. Policy does not transfer the legal obligations of one party to the other.

3 Data categories and sources

According to the relationship, identification and contact data, representation and faculties, professional or labor information, billing and payments data, requests logs, communications and authorizations can be treated. Electronic recruitment can register user, order, date and time, accepted version, affirmative action and technical session data provided to the probative end.

Operating records may include IP, computer and account identifiers, authentication events, changes, alerts and support traces, limited to what is needed. ENGITECH does not need to generally review the content of all a customer's files to fulfill those purposes.

The information is obtained from the holder, its authorized representatives, the organization with which it relates or legitimate and verifiable sources. When a customer delivers data from employees, users or other third parties, he or she must credit his or her legitimization and provide the necessary information to the holders. The policy does not allow to collect sensitive or biometric categories only because an application admits to storing them.

4 Engitech Foundation Purposes

Customers, prospects and users: attend queries, prepare proposals, verify faculties, register orders and acceptance, enable access, execute services, coordinate support and changes, bill, manage payments, respond to claims and credit obligations. The communications necessary for the contract, incidents, security, delay and closure are limited to those purposes.

Suppliers, contractors and allies: assessing suitability and requirements, formalizing contracts, coordinating benefits, managing payments and complying with applicable legal checks. It is not authorized to hand over customer bases to an ally to use them commercially on its own.

Aspirants, workers and exemployees: managing selection, linkage, payroll, social security, training, safety and health at work, accesses and labor obligations. Sensitive information requires the appropriate special regime. If a life sheet for future vacancies is to be retained, this purpose and its period shall be reported, without indefinite implicit preservation.

Security and operation: protecting accounts, facilities and systems, investigating incidents, preventing fraud, registering authorized access and retaining relevant evidence. If cameras, call recording, biometric controls or other special measures are implemented, their purposes and conditions will be previously reported; this enumeration does not state that all these technologies are in place.

Advertising and marketing: send promotional information only with the appropriate authorization, through permitted channels and with a simple mechanism to stop receiving it. The refusal will not prevent the acquisition of services. The publication of image, testimony, case of success or contact as a commercial reference requires specific authorization.

Legal obligations and defence: meeting relevant requirements, meeting accounting, tax, labour and contractual obligations and preserving evidence necessary for an identified dispute. This purpose will not be used to indiscriminately preserve all the contents of the client.

5 Authorizations previous information and evidence

When the law requires authorization, ENGITECH will request it in a prior, informed and subsequent consultation manner, indicating data, purposes, responsible, channels and rights. It may be recorded in writing, electronic means or other legally admissible mechanism. Silence is not interpreted as consent. The legal exceptions will be documented in the specific case; the only commercial interest does not create them.

The registration of acceptance of terms and confidentiality and the authorization of data shall have differentiated purposes. They can be obtained in the same flow, but the system must allow to identify what was accepted and for what. Advertising, sensitive data and optional uses will not be concealed within a general contractual acceptance.

ENGITECH will keep the text and version informed, identity or attribution mechanism, action manifested and date. A click without link to the content or an editable row without integrity controls is not enough to credit all circumstances. The evidence will be backed up with restricted access.

Before changing a purpose that requires new consent, the corresponding authorization will be reported and obtained. The updating of this policy does not extend by itself previous authorizations. When it is not feasible to present the entire policy at the collection point, the privacy notice will identify responsible, purpose, rights and means of consultation of the full version.

6 Minor sensitive data and special technologies

Sensitive data, including health, biometry and others whose misuse can generate discrimination, will only be treated on a legal basis and enhanced guarantees. Its sensitive nature will be expressly reported and that the holder is not obliged to authorize his treatment, except for the applicable legal duty. A service to unnecessary sensitive data will not be conditioned to provide it.

The processing of data for children and adolescents requires respect for their rights and best interests and compliance with applicable requirements, including the intervention of the representative and consideration of the minor ' s opinion as ripe as appropriate. A business authorization from the client company does not replace these requirements.

Cookies, analytics, recordings and integrations must be invented and reported according to their actual operation. Non-essential tools that require consent will not be activated by accessing the site alone. AI providers and the functions involved in sending data to other environments will be evaluated before enabling them; customer data will not be used for own or other training without a legitimate purpose, instruction and authorization.

7 Rights and ways to exercise them

The holders may know, update and rectify their data; request proof of authorization where appropriate; know the use given to the information; access free of charge in the legal terms; request deletion or revocation when appropriate; and file complaints with the Superintendence of Industry and Commerce after the required prior procedure has been exhausted. They can act personally or through those who credit representation or legitimation.

The request will be sent to info@engitech.com.co or to the indicated physical address, with owner's identification, request, response channel and representation support when applying. Identity will be verified in a proportionate manner; no excessive data will be required and no third-party information will be delivered. Consultations and complaints will be based and followed up.

The revocation or deletion is not absolute when there is a legitimate legal or contractual duty of permanence. In this case the reason, scope and period will be explained, the use will be restricted and what is not necessary will be eliminated. No formalities will be conditioned on the payment of services or the waiver of claims.

When ENGITECH acts on behalf of a client, it will coordinate with the competent responsible without neglecting his duties as a manager. It shall inform the applicant of the transfer where appropriate and shall not decide autonomously for purposes or removals corresponding to the person responsible, except for legal obligation.

8 Terms for queries and claims

Consultations: they will be answered within ten working days from your receipt. If it is not possible, the cause and the new date will be notified before the expiration; the extension will not exceed five additional working days.

We claim: they will be resolved within fifteen working days counted from the day after receipt; a prompt, informed expansion will not exceed eight additional working days. Incomplete claims will be required within five days of receipt; if two months pass from the requirement without termination, the procedure will be discontinued. If it is not competent, the receiver will transfer within two working days and inform the interested party.

Received the full claim, the annotation “reclass in process” and its motif will be recorded within two working days, keeping it to the decision. The special rules that establish greater protection or lower terms prevail. The response will explain the action, its foundation and the mechanisms available.

9 Common rules for services rendered as commissioner

These uniform rules are incorporated into the order when the customer accepts the General Agreement on Services and Confidentiality and the offer or order that identifies this policy. Its acceptance is contractual between ENGITECH and the client; it does not replace the authorization that it must obtain from each holder. It does not require signing a separate tab per service.

The object of the order is to execute the contracted technical operations: storage, housing, operating transmission, authorized support, platform management, backup, restoration or deletion as appropriate. The duration coincides with the service and its technical closure or legal conservation. Unearthed services are not included because they appear on this list.

The client determines the purposes and categories of headlines and data and certifies their legitimation. The scope is individualized in the offer, order, accepted inventory and high configuration, without the subsequent internal records unilaterally expanding the contract. Service, permitted operations, data categories and holders, duration, locations, controls and subloads will be documented before processing. If an essential instruction is missing, it will be clarified by a verifiable channel, without creating a repeated signature form.

ENGITECH will treat the data in accordance with the documented instructions of the controller and its treatment policy, within the contracted purpose; maintain restricted reservation, security and access, and assist in rights and incidents within its function. It will invest manifestly unlawful instructions and may suspend the specific operation while clearing up. You will not sell the information, you will not use it for your own campaigns or decide new purposes on it.

The client maintains functional administration, users, permits, content and business decisions, except for expressly delegated tasks. ENGITECH responds for the correct execution of the technical operations it assumes. Hiring storage does not amount to contracting backup; when backup is contracted, ENGITECH maintains the execution and verification obligations assumed.

The compliance check will be done by means of relevant evidence and audits provided agreed, without exposing data from other customers, unnecessary credentials or secrets. The powers of the authorities shall be met. At the end, the withdrawal and deletion instructions of the 12 section will be applied, respecting the legal duties of each party.

10 Subcharged Suppliers and International Flows

The same policy governs the criteria applicable to all third parties. This does not mean that any third party can access all data. ENGITECH will verify need, suitability, function and safeguard, and impose obligations of limited use, reserve, safety and deletion compatible with the benefit. It will keep up-to-date inventory of recipients who access data and countries involved.

When a third party takes account of the responsible, the applicable transmission conditions shall be formalized. When the receiver decides its own purposes, the transfer and its legal basis shall be evaluated. Physical location, remote access from another country and support flows should be considered, without presumably all remains in Colombia for billing from Bogotá.

The customer will be informed of relevant subloadings, functions and countries before the start. The expected material changes will be reported at least fifteen calendar days before; it may formulate documented data protection objection. If there is no reasonable alternative, it may terminate the affected component without future criminality and with proportional return of the unpaid period.

International transfers shall respect Article 26 of Law 1581 and applicable mechanisms. Transmissions shall be carried out in accordance with Decree 1074 and the current instructions. Model clauses of the SIC External Circular 003 of 2025 are voluntary adoption and do not replace the assessment of legal requirements. This policy does not declare an unidentified country or supplier approved or automatically incorporates a model without its specific data.

Financial entities, authorities and other recipients with their own functions will receive only necessary and based information. ENGITECH is not required to publish credentials or details that compromise security to explain the existence and function of third parties.

11 Security and Incidents

ENGITECH will apply risk proportional controls, including access and privilege management, confidentiality duties, traceability, updating of components to your post and protection of information in transmission and storage according to the service. Specific controls will be documented by environment. This policy does not declare end-to-end encryption, certifications or universal immutability that are not implemented.

Access to data for support will be authorized and limited to what is required. Key management will be defined according to the modality; when a key is exclusively guarded by the client, the consequences of its loss will be warned. Users must maintain protected devices and credentials and communicate suspicious access.

In the face of a confirmed incident involving customer information under your treatment, ENGITECH will notify without unreasonable delay and within a maximum contract of twenty-four hours from the confirmation. The initial notice may be partial and updated. Facts, scope, measures and evidence will be documented, containment will be coordinated and legal reports will be carried out separately to appropriate authorities or holders. The contractual period does not replace the applicable legal terms.

No absolute absence of intrusions is promised. The existence of an attack does not automatically eliminate liability: the fulfilment of the obligations of each party and the causality of the damage will be reviewed.

12 Retirement and Removal Conservation

The bases themselves will be preserved for the period necessary for the informed purpose and legal duties of conservation; then they will be effectively abolished or anonymized. ENGITECH will document deadlines by category and review your need. Accounting, contractual, labour and acceptance documents are not automatically deleted when an account is closed when a maintenance duty or a dispute warrants their preservation.

For content hosted by the client, it has twenty-four continuous hours since the effective termination to remove it by its own means, according to the date and time reported in the service agreement. The customer must plan their copies before canceling. Exports made by ENGITECH, migrations, conversions or delivery of software are not included; technical assistance or third-party execution is quoted and accepted separately.

By overcoming the deadline, the withdrawal access is revoked and the logical deletion of the cancelled data and resources of the service is executed. The associated backups are incorporated into the deletion process, without an additional recovery window. Wastes on shared supports or third-party systems remain isolated and unused to their technical disposal through the informed mechanism prior to contracting; no instant physical destruction is offered that the architecture does not permit. Exceptions of conservation must respond to law, competent order or specific agreement valid and prior.

An imputable failure to ENGITECH that prevents withdrawal requires enabling equivalent functional access or replenishing the time actually lost before deleting. Lack of payment does not allow the rights of holders to be ignored. Removal shall not be carried out against a valid order of preservation or legal duty; the exception shall be limited to indispensable information, with restricted access.

Recording of deletion may be issued with scope, date, method and exceptions, without revealing other data. No customer presence is required in shared facilities. Legal rights for consultation and access of holders are different from a commercial export or migration service and will be served by their channels and rules, without charging them as migration assistance.

13 Internal responsibilities and update

The management coordinates this policy and the care of rights; the operatives execute controls on their systems; those who hire third parties verify the treatment obligations. Evidence of authorizations, consultations, incidents, instructions, suppliers and disposal will be maintained with restricted access. Registration and reporting obligations applicable to ENGITECH shall be assessed and fulfilled without presumption of exemptions for their size.

The policy will be available on recruitment channels and on request by mail. Material changes will be communicated prior to application and historical versions will be retained. If a change alters the purposes for which authorization is required, it will be obtained before the new use begins. The date of publication and validity will be recorded when the version is in use.

This policy is common for the entire company and its relations with third parties. The technical conditions of a service may specify controls or locations, but do not reduce rights or replace the identification of the actual flow. The adoption of the text should be accompanied by verifiable processes and legal review adjusted to the actual treatments performed.

References and origin of the identification data

The corporate data comes from the certificate provided by SB26632832DEB78.pdf from the Bogotá Chamber of Commerce, issued the 17 of September of 2026. The phone was supplied by management. The policy separates the regulation of personal data from the commercial agreement, whose confidentiality clause remains integrated in ENG LEG 01 version 2.0.

Law 1581 of 2012. Personal data system, rights, authorizations and obligations. Consult source

1074 Decree of 2015. Policies, exercise of rights and transmission of information. Consult source

Law 527 of 1999. Data messages and preservation of electronic evidence. Consult source

External Circular SIC 003 from 2025. International model clauses; copy of the act in external repository. Consult source

SIC. Institutional policy consulted as an organizational reference, without transferring its public functions to ENGITECH. Consult source