Privacy policy
Last updated: May 29, 2025
This is a courtesy translation. The document governs a Colombian company under Colombian law, and the Spanish version is the binding one in the event of any discrepancy.
PERSONAL DATA PROCESSING POLICY
1. Purpose
This personal data processing policy (hereinafter, the "Policy") sets out the terms under which KIWARE.CO S.A.S. (hereinafter, the "Company"), owner and administrator of the website www.visabot.com.co (hereinafter, the "Website"), collects, stores, processes, updates, uses, consults, discloses and deletes the information supplied to it by data subjects (hereinafter, the "Data Subjects") for the purposes they authorise the Company to pursue in the Data Processing Authorisation (hereinafter, the "Authorisation").
This Policy covers the processing of personal data and its protection, the purposes of that processing, the rights of data subjects, and the procedures for handling enquiries, complaints and claims relating to that processing before the Company.
Data Subjects undertake to know and observe this Policy from the moment they authorise the processing of their information through the Authorisation. If a Data Subject does not agree with this Policy, the Company will refrain from establishing any contractual or commercial relationship with that person. That Data Subject must therefore refrain from requesting any service or providing information to the Company. Likewise, a Data Subject may at any time, through the official channels the Company makes available and states on its website, request that the Company refrain from processing their personal data.
2. Data Controller
For all purposes and obligations under this Policy, the party carrying out the processing and acting as Controller of the data supplied by the Data Subject shall be KIWARE.CO S.A.S., tax ID (NIT) pending, with registered address at KR 73 B # 6A - 35 - Colombia, email: info@visabot.com.co, a legal entity domiciled in Colombia and governed by Colombian law.
Company Legal Information
Registered name: KIWARE.CO S.A.S.
Trade name: Visa Bot
NIT: pending
Principal address: KR 73 B # 6A - 35
City: Bogotá, Colombia
Legal representative: Julián Camilo Valdés Bello
Email for judicial notices: legal@visabot.com.co
3. Definitions
a) Authorisation: The Data Subject's prior, express and informed consent to the processing of personal data.
b) Privacy Notice: The communication the controller makes to the personal data subject informing them of the existence of the Company's Policy, how to access it, and the purposes for which their personal data will be used.
c) Database: An organised set of personal data that is subject to processing.
d) Confidentiality: The information security principle that establishes who is authorised to access certain data and under what conditions. For the Company, protecting the confidentiality of data that is not public in nature is essential to ensure information remains private and is not improperly disclosed.
e) Sensitive Data: Data that affects the Data Subject's privacy, or whose misuse may lead to discrimination against them and/or affect their integrity, such as data revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership of trade unions, social or human rights organisations or organisations promoting the interests of any political party, as well as data concerning health, sexual life, the source of their resources and assets, and biometric data, among others.
f) Personal data: Any information linked to, or that can be associated with, one or more determined or determinable natural persons. "Personal data" is therefore to be understood as information relating to a natural person (an individually considered person).
g) Data of Minors (children and adolescents): The personal information of those who have not reached 18 years of age.
h) Processor: A natural or legal person, whether public or private, who processes personal data on behalf of the Controller, either independently or jointly with others. The Company acts as Processor of Personal Data when, alone or in collaboration with others, it carries out such processing on behalf of a Controller.
i) Legislation: Privacy legislation is contained in Statutory Law 1581 of 2012, Decree 1377 of 2013, and any other rules supplementing or adding to them.
j) Controller: A natural or legal person, public or private, who alone or jointly with others decides on the database and/or the processing of the data. For the purposes of this Privacy Policy, where processing is carried out by the Company, the Company is understood to be the Controller.
k) Data Subject: The natural person whose personal data is subject to processing.
l) Transmission of Personal Data: Processing of personal data involving its communication within or outside the territory of the Republic of Colombia where the purpose is for processing to be carried out by the Processor on the Controller's behalf.
m) Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
4. Principles
In accordance with Law 1581 of 2012 on the processing and protection of personal data, the Company, in its capacity as Controller, will observe the following principles when processing personal data:
- Principle of lawfulness in data Processing: The Processing of personal data is a regulated activity that must comply with Law 1581 of 2012 and the provisions that develop it.
- Principle of purpose: The Processing of collected personal data must serve a legitimate purpose under the Constitution and the law, which must be communicated to the Data Subject.
- Principle of freedom: Processing may only be carried out with the Data Subject's prior, express and informed consent. Personal data may not be obtained or disclosed without prior authorisation, or in the absence of a legal or judicial mandate dispensing with consent.
- Principle of accuracy or quality: Information subject to Processing must be truthful, complete, accurate, up to date, verifiable and comprehensible. The Processing of partial, incomplete, fragmented or misleading data is prohibited.
- Principle of transparency: Processing must guarantee the Data Subject's right to obtain from the Controller or the Processor, at any time and without restriction, information about the existence of data concerning them.
- Principle of restricted access and circulation: Processing is subject to the limits arising from the nature of the personal data, the provisions of this law and the Constitution. Accordingly, Processing may only be carried out by persons authorised by the Data Subject and/or by the persons provided for in this law.
- Principle of security: Information subject to Processing by the Controller or the Processor on the Company's behalf must be handled with the technical, human and administrative measures necessary to secure the records, preventing their alteration, loss, or unauthorised or fraudulent consultation, use or access.
- Principle of confidentiality: All persons involved in the Processing of personal data that is not public in nature are obliged to guarantee the confidentiality of the information, including after their relationship with any of the tasks comprising the Processing has ended.
5. Authorisation to use personal data
The Company will request the Data Subject's authorisation to process personal data before collecting any information, in strict compliance with privacy regulations, save for the exceptions provided by law. In cases involving sensitive personal data and/or data of children and adolescents, the Company will implement special and appropriate security measures, will comply with the specific legal requirements for obtaining authorisation from their parents or guardians, and will handle such information appropriately.
6. Necessity of the data
The Company will collect only the personal data necessary to fulfil the purposes authorised by the Data Subjects through the Authorisation the Company requests from them. To that end, it will establish procedures, mechanisms and controls to ensure that only indispensable personal data is collected.
Data Retention Periods
Active service data: For the duration of the service and up to 2 years after it ends
Accounting and tax data: 5 years, in accordance with tax regulations
Marketing data: Until the data subject revokes their authorisation
Complaint data: 3 years after the complaint is resolved
The Company will retain personal data only for as long as is reasonable and necessary in light of the purposes that justified the processing. Once those purposes have been fulfilled and the legal periods have elapsed, it will delete the personal data in its possession in accordance with the procedures the Company has established.
7. Data security
By authorising the processing and providing their personal data, the Data Subject accepts that it will form part of the Company's database for the purposes authorised in the Authorisation. The Company will implement and maintain administrative, technical and physical security measures to protect the data against damage, loss, alteration and destruction, as well as against unauthorised access, use or processing.
In the event of security breaches that may affect data subjects' rights and freedoms, the Company will:
- Notify the Superintendency of Industry and Commerce within the following 72 hours
- Inform affected data subjects within 72 hours where the breach involves high risk
- Document the breach, including the facts, effects and corrective measures adopted
- Implement immediate measures to contain and remedy the breach
8. Exercise of Data Subjects' rights
Data Subjects have rights under article 8 of Law 1581 of 2012 and supplementary rules, in particular the right to:
- Know, update and rectify their personal data before the Controller or the Processors. This right may be exercised, among other cases, in respect of partial, inaccurate, incomplete or fragmented data, data that is misleading, or data whose Processing is expressly prohibited or has not been authorised by the Data Subject.
- Request proof of the authorisation granted to the Controller, except where it is expressly excepted as a requirement for Processing under article 10 of Law 1581 of 2012 or the rules supplementing it.
- Be informed by the Controller or the Processor, upon request, of the use made of their personal data.
- File complaints with the Superintendency of Industry and Commerce for breaches of Law 1581 of 2012 and the rules that amend, add to or supplement it.
- Revoke the authorisation and/or request deletion of the data where the Processing does not respect constitutional and legal principles, rights and guarantees.
- Access their personal data that has been subject to Processing, free of charge.
9. Standing to exercise the data subject's rights
The rights of personal information Data Subjects may be exercised by the following persons:
- By the data subject themselves, who must sufficiently prove their identity
- By their successors in title, duly accredited
- By the data subject's representative and/or attorney, whose capacity is duly accredited
- In the case of minors, the rights may only be exercised by the persons duly empowered by law
10. The Company's obligations as Controller
In its role as Controller, the Company must comply with the following duties, in addition to other provisions established by law and by the regulations applicable to its activity:
- Guarantee the Data Subject, at all times, the full and effective exercise of the right of habeas data
- Request and retain, under the conditions provided for in this law, a copy of the relevant authorisation granted by the Data Subject
- Duly inform the Data Subject of the purpose of the collection and of the rights afforded to them by virtue of the authorisation granted
- Keep the information under the security conditions necessary to prevent its alteration, loss, or unauthorised or fraudulent consultation, use or access
- Ensure that the information supplied to the Processor is truthful, complete, accurate, up to date, verifiable and comprehensible
- Update the information, adopting such other measures as are necessary to keep the information supplied up to date
- Rectify Data Subjects' information where it is incorrect and communicate the relevant details to the Processor
- Supply the Processor, as applicable, only with data whose Processing has been previously authorised in accordance with Law 1581 of 2012
- Require the Processor at all times to respect the security and privacy conditions of the Data Subject's information
- Handle the enquiries and complaints submitted by Data Subjects on the terms set out in the law and in this Policy
- Inform the Processor when particular information is in dispute by the Data Subject, once the claim has been submitted and the relevant procedure has not concluded
- Inform the Data Subject, upon request, of the use made of their data
- Inform the data protection authority when breaches of security codes occur and there are risks in the administration of Data Subjects' information
- Comply with the instructions and requirements issued by the Superintendency of Industry and Commerce
11. Data Collected, Processing and Purpose of Processing
Some of the general purposes of the data processing carried out by the Company include:
- Performing and managing the service contracted by Data Subjects, as described in the Terms and Conditions and in the Data Processing Authorisation
- Managing the contractual relationship held with the Data Subject
- Communicating with Data Subjects about developments relating to the provision of the service, requesting feedback, providing technical support, and informing Data Subjects about the Company's Services and promotions
- Generating and maintaining the documents required for internal and external audit processes
- Transmitting the data required by the national government and/or the authorities, in compliance with legal provisions and the exercise of their functions
- Reporting changes that may occur in the provision of the service, the contractual relationship, or the policies adopted by the Company, including the data protection policy
- Collecting and storing information in order to improve the data subject's experience, personalise services, and develop new products and services that respond to market needs
- Sending information, advertising and promotions relating to the Company's products and services through various communication channels, including email, text messages and WhatsApp messages
- Complying with and applying the constitutional, legal and regulatory provisions established in Colombian law and applicable to the Company in relation to data protection
12. Designated area for personal data matters and contact channels
Contact Information for Personal Data
Designated area: Customer Service Department
Channel for enquiries and complaints: info@visabot.com.co
Telephone: +57 300 944 5554
Legal email: legal@visabot.com.co
13. Processing of Sensitive Data
Important statement: The Company states that it does NOT process sensitive data in the normal course of its services.
Should processing sensitive data exceptionally be required, the Company will:
- Explicitly inform the Data Subject that providing such data is optional
- Specify the concrete purposes of the processing
- Obtain express and separate authorisation for sensitive data
- Apply reinforced security measures given the sensitive nature of the information
- Restrict access strictly to the personnel who need it
14. Processing of Minors' Data
Restrictive policy: Visa Bot's services are aimed exclusively at persons over 18 years of age.
Should data of minors exceptionally be received:
- Express authorisation from the legal representative or guardian will be required
- The principle of the best interests of the child will be applied
- Processing will be limited to the minimum necessary
- Special security measures will be implemented
- If appropriate authorisation cannot be obtained, the data will be deleted immediately
15. Procedure for exercising data subjects' rights
To exercise their rights or make any request relating to the processing of their personal data by the Company, Data Subjects may contact the designated area or person. The Data Subject, their representative or their successor in title may consult the Data Subject's personal information held in databases processed by the Company.
15.1. Procedure for handling enquiries and complaints
a) Enquiries
Data Subjects, their representatives or their successors in title may consult the data subject's personal data held in any database processed by the Company. To do so, they must submit a request through the channels established in this policy.
The Company will respond to the enquiry within a maximum of ten (10) business days from the date the request is received. Where it is not possible to respond within that period, the Company will inform the data subject of the reasons for the delay and set a new response date, which will in no case exceed five (5) business days after the expiry of the first period.
b) Complaints
The data subject, their representative or their successors in title may request the correction, updating or deletion of the data, or submit a complaint in the event of alleged non-compliance with Law 1581 of 2012 on data processing, by way of a written request or complaint addressed to the Company through the channels established in this policy.
A request or complaint addressed to the Company must include at least:
- Identification of the data subject and of the applicant, if they are different
- A detailed description of the facts giving rise to the request or complaint
- A physical address or email address for notices
- Documents supporting the request or complaint, and the representation or succession invoked where applicable
Where the request or complaint is incomplete, the Company will ask the interested party to remedy the defects or complete the information within the five (5) business days following its receipt. If two (2) months elapse from the date the request was sent without the interested party providing the information required, the complaint will be deemed withdrawn.
Once the complaint is received, the Company will add a note to the database indicating "complaint in progress" and the corresponding reason, within the two (2) business days following its receipt. That note must remain until the complaint is decided.
The maximum period for the Company to handle the request or complaint is fifteen (15) business days from the day following its receipt. Where it is not possible to handle the complaint within that period, the Company will inform the interested party of the reasons for the delay and the date on which the complaint will be handled, which may in no case exceed eight (8) additional business days after the expiry of the first period.
c) Deletion of data
The data subject has the right to request that the Company delete their personal data in cases such as:
- Where they consider that the data is not being processed in accordance with the principles, duties and obligations established by the regulations in force
- Where the data is no longer necessary or relevant for the purpose for which it was collected
- Where the period necessary to fulfil the purposes for which it was collected has elapsed
Note that in some cases this right to request deletion may not be granted, for reasons such as:
- Where the data subject has a legal or contractual duty to remain in the database
- Where deleting the data could hinder judicial or administrative actions relating to tax obligations, the investigation and prosecution of offences, or the imposition of administrative penalties
- Where the data is necessary to protect the data subject's legally protected interests, or to comply with obligations of public interest
- To comply with an obligation legally acquired by the data subject
16. Information shared with third parties
Some services provided by the Company may be delivered in collaboration with external suppliers or partners, who may manage or process Data Subjects' Personal Information. The Data Subject therefore acknowledges and authorises that their Personal Information may be shared with these partners for various purposes, such as: support in providing the services offered by the Company, data processing, marketing activities, customer assistance, custody of documents or digital information, and statistical analysis of the services the Company offers, among other activities.
When sharing Personal Information with our partners, the Company will ensure that they protect the information consistently with our Data Protection Policy and use it solely for the previously identified purposes. Accordingly, the Company may request from third-party partners any relevant information allowing it to verify due compliance with the provisions of this Policy and with the regulations in force.
Should a third party with whom the Company has a contractual or agreed relationship breach this Policy, both parties will draw up an action plan to ensure compliance with the standards required by law.
17. International Data Transfers
The Company may transfer personal data to countries that do not provide adequate levels of data protection only where:
- It is strictly necessary for the provision of the service (access to consular systems)
- Appropriate safeguards are implemented through contractual clauses
- Express authorisation is obtained from the data subject for the specific transfer
- The requirements established in Decree 1377 of 2013 are met
Important: By authorising the service, the User expressly accepts that their consular credentials may be used to access systems located in the United States.
18. Requests from authorities
The Company will cooperate with the competent authorities to ensure compliance with the laws applicable to data protection. By granting the authorisation, Data Subjects expressly permit the Company to provide their personal data to those authorities in order to comply with any legal requirement and to cooperate with them as they consider necessary and appropriate for investigations into unlawful activities, infringements of intellectual or industrial property rights, or other illegal activities that may affect the Company. Data subjects are further understood to authorise the communication of their personal data to the competent authorities in connection with these or other investigations those authorities may carry out.
19. Updates and validity of the policy
The Company reserves the right to review and amend this policy at any time, in accordance with article 5 of Decree 1377 of 2013. Where substantial changes are made, they will be communicated to data subjects before or at the time the changes are implemented. The Notice or Authorisation will state that the new policy can be consulted at the relevant site, together with the date from which the amended policy takes effect. Where the amendments affect the purposes of the processing, a new authorisation will be requested from data subjects.
20. Applicable law
This Personal Data Protection Policy is governed by, and will be construed in accordance with, the law in force in the Republic of Colombia, in particular but not limited to Statutory Law 1581 of 2012, Decree 1377 of 2013, and other supplementary or amending provisions. Any dispute arising from the processing of personal data by the company will be submitted to the jurisdiction of the competent courts of the Republic of Colombia.
21. Effective date
This Policy took effect from the date of its publication on the Website.
Contact Information
KIWARE.CO S.A.S.
Email: info@visabot.com.co
Legal email: legal@visabot.com.co
WhatsApp: +57 300 944 5554
Jurisdiction: Colombia
