Privacy Policy and Personal Data Processing
What personal data SaintSoft collects, what it is used for, how long it is kept, and how you can exercise your rights as a data subject.
- Version
- 1.0
- In force since
1. Data controller
SaintSoft S.A.S. ("SaintSoft", "we", "us"), a company domiciled in Bogotá D.C., Colombia, is the Data Controller (Responsable del Tratamiento) for the personal data collected through the saintsoft.us website and its associated contact channels.
- Registered address
- Carrera 63 #174B-11, Bogotá D.C., Colombia
- Contact email
- contacto@saintsoft.com
- Phone (United States)
- +1 786-948-3374
- WhatsApp (Colombia and Latin America)
- +57 302-777-5527
- Website
- https://saintsoft.us
Requests, queries and complaints regarding personal data are handled by our Customer Service team, reachable at the email address above.
2. Applicable law
This policy is governed by Colombian law and, where relevant to visitors located outside Colombia, recognises the standards set out below:
- Political Constitution of Colombia, article 15 (the right to habeas data).
- Ley Estatutaria 1581 de 2012, Colombia's general personal data protection statute.
- Decreto 1074 de 2015 (which consolidated Decreto 1377 de 2013), implementing Ley 1581 de 2012.
- Ley 1266 de 2008, as regards financial and credit data, where applicable.
- Ley 1480 de 2011 (Consumer Statute) and Ley 527 de 1999 (electronic commerce and data messages).
- Regulation (EU) 2016/679 (GDPR) and Directive 2002/58/EC, as regards visitors located in the European Economic Area.
The supervisory authority in Colombia is the Superintendencia de Industria y Comercio (SIC), through its Delegate Office for Personal Data Protection.
3. Definitions
- Personal data
- Any information linked to, or capable of being linked to, an identified or identifiable natural person. This includes online identifiers such as an IP address or the identifier a cookie assigns to your browser.
- Sensitive data
- Data affecting the intimacy of the data subject or whose misuse could lead to discrimination: racial or ethnic origin, political opinions, religious beliefs, trade union membership, health data, sex life and biometric data.
- Data subject (Titular)
- The natural person the personal data relates to.
- Data Controller (Responsable del Tratamiento)
- The party that decides on the database and on the processing of the data. On this site, SaintSoft.
- Data Processor (Encargado del Tratamiento)
- A party that processes personal data on the Controller's behalf, such as a hosting or email provider.
- Authorization
- The data subject's prior, express and informed consent to the processing of their personal data.
- Privacy notice
- The verbal or written communication made available to the data subject informing them of the processing and of the existence of this policy.
4. What data we collect
We collect only the data described below. We do not request sensitive data, and you do not need to provide any in order to use the site or to contact us.
- Data you give us voluntarily
- Through the contact form: name, email address, company and message (required), plus phone number and product of interest (optional). If you write to us by WhatsApp, email or phone, we also receive whatever you choose to include in that conversation.
- Technical connection data
- Our server automatically logs the IP address, the date and time of the request, the page requested, the response code, and the browser and operating system your device reports. This is a technical record inherent to any web server and is used for security and diagnostics.
- Browsing data
- If you accept analytics cookies, a random identifier and aggregate usage metrics. If you do not accept them, this collection does not happen at all.
The free-text message field is yours: we recommend not including sensitive data, credentials, third-party data or confidential company information you are not yet ready to share.
5. What we use your data for
We process your personal data exclusively for the following purposes:
- 1To handle your request for information, an assessment or a quote, and to reply through the channel you indicated.
- 2To manage the pre-contractual stage: preparing proposals, scheduling meetings and following up commercially on your request.
- 3To perform and administer the contractual relationship, should we reach an agreement, including invoicing, support and compliance with legal, accounting and tax obligations.
- 4To send you communications about our products and services, only where you have authorized it, with the ability to unsubscribe at any time.
- 5To keep the site secure, prevent fraud and abuse, and diagnose technical incidents.
- 6To measure site usage in aggregate in order to improve its content, where you have accepted analytics cookies.
- 7To respond to requirements from competent administrative or judicial authorities.
We do not sell, rent or transfer your personal data to third parties for those third parties' own commercial purposes.
6. Legal basis for processing
In Colombia, the general basis for processing is your prior, express and informed authorization, which you give by ticking the corresponding box before submitting the form, or by accepting the cookie categories in the settings panel. Authorization is not required in the cases listed in article 10 of Ley 1581 de 2012, among them requirements issued by a competent authority.
If you are located in the European Economic Area, the legal bases under article 6 GDPR that we rely on are:
- Consent (art. 6(1)(a))
- For the contact form submission, for commercial communications and for cookies that are not strictly necessary.
- Performance of a contract or pre-contractual steps (art. 6(1)(b))
- To prepare a proposal at your request and to perform the contract if one is entered into.
- Legitimate interests (art. 6(1)(f))
- For infrastructure security and the retention of technical server logs, balanced against your rights and limited to what is strictly necessary.
- Legal obligation (art. 6(1)(c))
- To retain accounting, tax and corporate records.
7. How long we keep the data
We keep data for as long as necessary to fulfil the purpose that justified collecting it and, thereafter, for the applicable statutory limitation periods:
- Contact requests that do not lead to a commercial relationship
- Up to two (2) years from the last contact, unless you ask us to delete them sooner. After that period they are erased.
- Clients
- For the duration of the contractual relationship and, once it ends, for the periods required by Colombian commercial, accounting and tax rules, which for accounting records extends to ten (10) years under article 28 of the Colombian Commercial Code.
- Technical server logs
- Rotated and deleted automatically within a maximum of twelve (12) months.
- The record of your cookie decision
- Six (6) months, after which we will ask you again. It is kept precisely so that we can evidence what you decided.
8. Who we share the data with
We do not share your data with third parties except with the providers we need in order to operate, who act as Data Processors under our instructions and subject to confidentiality and security obligations:
- Amazon Web Services (AWS)
- Hosting of the website and server infrastructure, in the us-east-1 region (United States).
- Google (Gmail / Google Workspace)
- Receipt and handling of the email in which contact form submissions arrive.
- Google Analytics and Google Ads
- Audience and campaign measurement, only if you have accepted the corresponding categories in the cookie panel.
- Meta Platforms (WhatsApp)
- If you choose to start a WhatsApp conversation, that conversation is additionally governed by WhatsApp's own terms and privacy policy.
We may also disclose information where there is a court order or a requirement from a competent administrative authority, and to our legal and accounting advisers where necessary to defend our rights.
9. International transfers
Our hosting and email infrastructure is located in the United States. Your personal data is therefore transferred to and stored outside Colombia.
This transfer relies on article 26 of Ley 1581 de 2012: on the one hand, on your express and unequivocal authorization for the transfer, which you give by accepting this policy; and on the other, on the transfer being made to providers that offer adequate levels of protection and that contractually assume security and confidentiality obligations equivalent to those required by Colombian law.
For data subjects located in the European Economic Area, transfers to the United States are made with the safeguards set out in Chapter V GDPR, including the Standard Contractual Clauses adopted by the European Commission or the provider's certification under the applicable adequacy framework.
10. Your rights as a data subject
As the data subject, article 8 of Ley 1581 de 2012 grants you the following rights:
- To access, update and rectify your personal data held by SaintSoft.
- To request proof of the authorization you gave, except where the law does not require it.
- To be informed, upon request, of the use we have made of your data.
- To lodge complaints with the Superintendencia de Industria y Comercio for breaches of the law, once the query or complaint procedure with us has been exhausted.
- To withdraw your authorization and request deletion of your data where no legal or contractual duty requires us to keep it.
- To access, free of charge, the data that has been processed.
If you are located in the European Economic Area, you additionally have the rights of access, rectification, erasure, restriction of processing, portability and objection, as well as the right not to be subject to automated decisions producing legal effects — processing we do not carry out in any event — and the right to lodge a complaint with your supervisory authority.
11. How to exercise your rights
You can exercise any of these rights by writing to contacto@saintsoft.com, or by post to Carrera 63 #174B-11, Bogotá D.C., Colombia. So that we can act on it, the request needs to include:
- 1Your full name and a document or detail allowing us to verify your identity.
- 2A specific description of what you are requesting (access, update, rectification, deletion, withdrawal of authorization, and so on).
- 3An email or postal address at which you want to receive our reply.
- 4Any documents you wish to provide in support, if any.
- Queries (art. 14, Ley 1581 de 2012)
- We will reply within a maximum of ten (10) business days, extendable by a further five (5) business days. If the query cannot be answered within the initial period, we will tell you why and when it will be dealt with.
- Complaints (art. 15, Ley 1581 de 2012)
- These will be resolved within a maximum of fifteen (15) business days, extendable by a further eight (8) business days. If the complaint is incomplete, we will ask you within the following five (5) days to complete it; if you do not provide the information within two (2) months, it will be treated as withdrawn.
Before lodging a complaint with the Superintendencia de Industria y Comercio, the law requires that the query or complaint procedure has first been exhausted directly with us (art. 16 of Ley 1581 de 2012).
12. Children's data
This site and our services are aimed at companies and at adults. We do not knowingly collect data from children or adolescents. Processing of a minor's data is only permissible where it serves their best interests, respects their fundamental rights and has the authorization of their legal representative, after the minor's right to be heard has been exercised.
If you become aware that a minor has provided us with personal data, write to contacto@saintsoft.com and we will delete it.
13. Security measures
We apply reasonable technical, human and administrative measures to protect data against tampering, loss, unauthorized or fraudulent access, use or consultation. Among them:
- Encryption of traffic between your browser and our server using TLS (HTTPS) across the whole site.
- Storage of credentials and secrets in an encrypted secrets manager, never in the source code or the repository.
- Access to mailboxes and infrastructure limited to staff who need it for their role, with strong authentication.
- Regular updates of the infrastructure and server software.
No security measure is infallible. Should an incident compromising personal data occur, we will report it to the competent authority and to the affected data subjects on the terms and within the deadlines required by applicable law.
15. Effective date and changes
This policy takes effect on 13 August 2026. The databases administered by SaintSoft will remain in force for as long as needed to fulfil the purposes described and the applicable statutory retention periods.
We may amend it to reflect regulatory, organizational or technological changes. Where a change is substantial and affects the purposes of processing, we will notify you through an effective means before it takes effect and, where the law requires it, we will request fresh authorization. The version in force is always the one published on this page, with its version number and date shown at the top.
16. Language
This policy is published in Spanish and in English. The Spanish version is the only authentic one and prevails in the event of any discrepancy, contradiction or doubt as to interpretation between the two. The English translation is provided to assist English-speaking visitors and creates no rights or obligations different from those set out here.