Privacy Policy and Personal Data Processing

What personal data SaintSoft collects, what it is used for, how long it is kept, and how you can exercise your rights as a data subject.

Version
1.0
In force since

1. Data controller

SaintSoft S.A.S. ("SaintSoft", "we", "us"), a company domiciled in Bogotá D.C., Colombia, is the Data Controller (Responsable del Tratamiento) for the personal data collected through the saintsoft.us website and its associated contact channels.

Registered address
Carrera 63 #174B-11, Bogotá D.C., Colombia
Contact email
contacto@saintsoft.com
Phone (United States)
+1 786-948-3374
WhatsApp (Colombia and Latin America)
+57 302-777-5527
Website
https://saintsoft.us

Requests, queries and complaints regarding personal data are handled by our Customer Service team, reachable at the email address above.

3. Definitions

Personal data
Any information linked to, or capable of being linked to, an identified or identifiable natural person. This includes online identifiers such as an IP address or the identifier a cookie assigns to your browser.
Sensitive data
Data affecting the intimacy of the data subject or whose misuse could lead to discrimination: racial or ethnic origin, political opinions, religious beliefs, trade union membership, health data, sex life and biometric data.
Data subject (Titular)
The natural person the personal data relates to.
Data Controller (Responsable del Tratamiento)
The party that decides on the database and on the processing of the data. On this site, SaintSoft.
Data Processor (Encargado del Tratamiento)
A party that processes personal data on the Controller's behalf, such as a hosting or email provider.
Authorization
The data subject's prior, express and informed consent to the processing of their personal data.
Privacy notice
The verbal or written communication made available to the data subject informing them of the processing and of the existence of this policy.

4. What data we collect

We collect only the data described below. We do not request sensitive data, and you do not need to provide any in order to use the site or to contact us.

Data you give us voluntarily
Through the contact form: name, email address, company and message (required), plus phone number and product of interest (optional). If you write to us by WhatsApp, email or phone, we also receive whatever you choose to include in that conversation.
Technical connection data
Our server automatically logs the IP address, the date and time of the request, the page requested, the response code, and the browser and operating system your device reports. This is a technical record inherent to any web server and is used for security and diagnostics.
Browsing data
If you accept analytics cookies, a random identifier and aggregate usage metrics. If you do not accept them, this collection does not happen at all.

The free-text message field is yours: we recommend not including sensitive data, credentials, third-party data or confidential company information you are not yet ready to share.

5. What we use your data for

We process your personal data exclusively for the following purposes:

  1. 1To handle your request for information, an assessment or a quote, and to reply through the channel you indicated.
  2. 2To manage the pre-contractual stage: preparing proposals, scheduling meetings and following up commercially on your request.
  3. 3To perform and administer the contractual relationship, should we reach an agreement, including invoicing, support and compliance with legal, accounting and tax obligations.
  4. 4To send you communications about our products and services, only where you have authorized it, with the ability to unsubscribe at any time.
  5. 5To keep the site secure, prevent fraud and abuse, and diagnose technical incidents.
  6. 6To measure site usage in aggregate in order to improve its content, where you have accepted analytics cookies.
  7. 7To respond to requirements from competent administrative or judicial authorities.

We do not sell, rent or transfer your personal data to third parties for those third parties' own commercial purposes.

6. Legal basis for processing

In Colombia, the general basis for processing is your prior, express and informed authorization, which you give by ticking the corresponding box before submitting the form, or by accepting the cookie categories in the settings panel. Authorization is not required in the cases listed in article 10 of Ley 1581 de 2012, among them requirements issued by a competent authority.

If you are located in the European Economic Area, the legal bases under article 6 GDPR that we rely on are:

Consent (art. 6(1)(a))
For the contact form submission, for commercial communications and for cookies that are not strictly necessary.
Performance of a contract or pre-contractual steps (art. 6(1)(b))
To prepare a proposal at your request and to perform the contract if one is entered into.
Legitimate interests (art. 6(1)(f))
For infrastructure security and the retention of technical server logs, balanced against your rights and limited to what is strictly necessary.
Legal obligation (art. 6(1)(c))
To retain accounting, tax and corporate records.

7. How long we keep the data

We keep data for as long as necessary to fulfil the purpose that justified collecting it and, thereafter, for the applicable statutory limitation periods:

Contact requests that do not lead to a commercial relationship
Up to two (2) years from the last contact, unless you ask us to delete them sooner. After that period they are erased.
Clients
For the duration of the contractual relationship and, once it ends, for the periods required by Colombian commercial, accounting and tax rules, which for accounting records extends to ten (10) years under article 28 of the Colombian Commercial Code.
Technical server logs
Rotated and deleted automatically within a maximum of twelve (12) months.
The record of your cookie decision
Six (6) months, after which we will ask you again. It is kept precisely so that we can evidence what you decided.

8. Who we share the data with

We do not share your data with third parties except with the providers we need in order to operate, who act as Data Processors under our instructions and subject to confidentiality and security obligations:

Amazon Web Services (AWS)
Hosting of the website and server infrastructure, in the us-east-1 region (United States).
Google (Gmail / Google Workspace)
Receipt and handling of the email in which contact form submissions arrive.
Google Analytics and Google Ads
Audience and campaign measurement, only if you have accepted the corresponding categories in the cookie panel.
Meta Platforms (WhatsApp)
If you choose to start a WhatsApp conversation, that conversation is additionally governed by WhatsApp's own terms and privacy policy.

We may also disclose information where there is a court order or a requirement from a competent administrative authority, and to our legal and accounting advisers where necessary to defend our rights.

9. International transfers

Our hosting and email infrastructure is located in the United States. Your personal data is therefore transferred to and stored outside Colombia.

This transfer relies on article 26 of Ley 1581 de 2012: on the one hand, on your express and unequivocal authorization for the transfer, which you give by accepting this policy; and on the other, on the transfer being made to providers that offer adequate levels of protection and that contractually assume security and confidentiality obligations equivalent to those required by Colombian law.

For data subjects located in the European Economic Area, transfers to the United States are made with the safeguards set out in Chapter V GDPR, including the Standard Contractual Clauses adopted by the European Commission or the provider's certification under the applicable adequacy framework.

10. Your rights as a data subject

As the data subject, article 8 of Ley 1581 de 2012 grants you the following rights:

  • To access, update and rectify your personal data held by SaintSoft.
  • To request proof of the authorization you gave, except where the law does not require it.
  • To be informed, upon request, of the use we have made of your data.
  • To lodge complaints with the Superintendencia de Industria y Comercio for breaches of the law, once the query or complaint procedure with us has been exhausted.
  • To withdraw your authorization and request deletion of your data where no legal or contractual duty requires us to keep it.
  • To access, free of charge, the data that has been processed.

If you are located in the European Economic Area, you additionally have the rights of access, rectification, erasure, restriction of processing, portability and objection, as well as the right not to be subject to automated decisions producing legal effects — processing we do not carry out in any event — and the right to lodge a complaint with your supervisory authority.

11. How to exercise your rights

You can exercise any of these rights by writing to contacto@saintsoft.com, or by post to Carrera 63 #174B-11, Bogotá D.C., Colombia. So that we can act on it, the request needs to include:

  1. 1Your full name and a document or detail allowing us to verify your identity.
  2. 2A specific description of what you are requesting (access, update, rectification, deletion, withdrawal of authorization, and so on).
  3. 3An email or postal address at which you want to receive our reply.
  4. 4Any documents you wish to provide in support, if any.
Queries (art. 14, Ley 1581 de 2012)
We will reply within a maximum of ten (10) business days, extendable by a further five (5) business days. If the query cannot be answered within the initial period, we will tell you why and when it will be dealt with.
Complaints (art. 15, Ley 1581 de 2012)
These will be resolved within a maximum of fifteen (15) business days, extendable by a further eight (8) business days. If the complaint is incomplete, we will ask you within the following five (5) days to complete it; if you do not provide the information within two (2) months, it will be treated as withdrawn.

Before lodging a complaint with the Superintendencia de Industria y Comercio, the law requires that the query or complaint procedure has first been exhausted directly with us (art. 16 of Ley 1581 de 2012).

12. Children's data

This site and our services are aimed at companies and at adults. We do not knowingly collect data from children or adolescents. Processing of a minor's data is only permissible where it serves their best interests, respects their fundamental rights and has the authorization of their legal representative, after the minor's right to be heard has been exercised.

If you become aware that a minor has provided us with personal data, write to contacto@saintsoft.com and we will delete it.

13. Security measures

We apply reasonable technical, human and administrative measures to protect data against tampering, loss, unauthorized or fraudulent access, use or consultation. Among them:

  • Encryption of traffic between your browser and our server using TLS (HTTPS) across the whole site.
  • Storage of credentials and secrets in an encrypted secrets manager, never in the source code or the repository.
  • Access to mailboxes and infrastructure limited to staff who need it for their role, with strong authentication.
  • Regular updates of the infrastructure and server software.

No security measure is infallible. Should an incident compromising personal data occur, we will report it to the competent authority and to the affected data subjects on the terms and within the deadlines required by applicable law.

14. Cookies

The use of cookies and other storage technologies on your device is described in detail in the Cookie Policy, which forms an integral part of this policy. There you will find the complete inventory of what we store, for what purpose and for how long, and you can change your decision at any time.

15. Effective date and changes

This policy takes effect on 13 August 2026. The databases administered by SaintSoft will remain in force for as long as needed to fulfil the purposes described and the applicable statutory retention periods.

We may amend it to reflect regulatory, organizational or technological changes. Where a change is substantial and affects the purposes of processing, we will notify you through an effective means before it takes effect and, where the law requires it, we will request fresh authorization. The version in force is always the one published on this page, with its version number and date shown at the top.

16. Language

This policy is published in Spanish and in English. The Spanish version is the only authentic one and prevails in the event of any discrepancy, contradiction or doubt as to interpretation between the two. The English translation is provided to assist English-speaking visitors and creates no rights or obligations different from those set out here.