Legal
Personal data processing policy
How Coresis S.A.S. collects, uses, retains and protects personal data, under Colombia's Ley 1581 de 2012, Decreto 1377 de 2013 and Ley 1266 de 2008.
Version 2.0. In force since 29 August 2026.
1. Purpose and applicable law
This policy sets out the criteria Coresis S.A.S. applies to the personal data it processes, together with the procedures through which any person may exercise their rights over that information. It is binding on Coresis and on those who process data on its behalf.
It rests on the following legal framework:
- Political Constitution of Colombia, article 15: recognises every person's right to know, update and rectify information collected about them.
- Ley 1581 de 2012: Colombia's general personal data protection regime.
- Decreto 1377 de 2013, compiled into Decreto Único Reglamentario 1074 de 2015: governs authorisation, processing policies and the exercise of rights.
- Ley 1266 de 2008: the regime for financial, credit and commercial data. It applies to Coresis in a limited way, regarding the commercial information of clients and suppliers.
- Ley 1273 de 2009: criminal protection of information and data.
- Circulars and doctrine issued by the Superintendencia de Industria y Comercio, Colombia's data protection authority.
Where a client contract imposes stricter obligations than this policy, the contract prevails.
2. Definitions
The following terms carry the meaning given to them by article 3 of Ley 1581 de 2012:
- Data subject (titular): the natural person whose personal data is processed.
- Personal data: any information linked to, or capable of being associated with, one or more identified or identifiable natural persons.
- Sensitive data: data affecting the data subject's privacy, or whose misuse may lead to discrimination, such as racial or ethnic origin, political orientation, religious convictions, trade union membership, health data, sex life and biometric data.
- Data controller (responsable): the party that decides on the database and the processing. In this policy, Coresis S.A.S.
- Data processor (encargado): the party that processes data on the controller's behalf.
- Processing: any operation on personal data, such as collection, storage, use, circulation or deletion.
- Authorisation: the data subject's prior, express and informed consent to the processing of their data.
- Privacy notice: the communication informing the data subject that this policy exists and how to access it.
- Transfer (transferencia): sending data to a recipient acting as a controller, inside or outside Colombia.
- Transmission (transmisión): communicating data to a processor so that it processes them on behalf of Coresis.
3. Data controller
Coresis S.A.S., a commercial company incorporated under the laws of the Republic of Colombia, tax identification NIT 9000555382-5, with its principal domicile in Bogotá D.C., Colombia.
Single channel for personal data matters: contacto@coresis.info. Phone and WhatsApp: +57 316 410 1007. Website: coresis.co.
Queries and complaints are handled by Coresis's administrative area, which performs the data protection function set out in article 23 of Decreto 1377 de 2013.
As regards the National Database Registry (Registro Nacional de Bases de Datos), Coresis registers its databases whenever this is required under the company-size criteria set by the Superintendencia de Industria y Comercio.
4. Scope
This policy applies to personal data processed by Coresis in any of these contexts:
- Communications sent to Coresis by email, telephone or WhatsApp.
- Browsing on coresis.co and the technical data that browsing generates.
- The contractual relationship with clients, suppliers and partners.
- Recruitment processes and the relationship with the team.
- Data that Coresis processes as a processor on behalf of a client, within a software project. In that case the client, as controller, defines the purposes and retention periods, and Coresis acts strictly as contractually agreed.
5. Governing principles
All processing is subject to the principles in article 4 of Ley 1581 de 2012: legality, purpose that is legitimate and disclosed to the data subject, freedom — data is processed only with prior consent or a legal mandate — accuracy, transparency, restricted access and circulation, security and confidentiality.
Coresis adds two operational criteria of its own: minimisation, meaning it does not request data that is unnecessary for the specific purpose; and traceability, meaning it can reconstruct who accessed what information and when.
6. Data we process
This website does not use contact forms. Communication happens through the channels we publish, so the data reaching Coresis is what each person chooses to send voluntarily. The categories are as follows:
6.1. Identification and contact data
Name, email address, phone number, company or public entity, job title, and the project details the person wishes to discuss. For clients and suppliers, the billing data required by tax rules is added: registered name, NIT or ID number, address and bank details.
6.2. Technical browsing data
IP address, browser and device type, operating system, pages viewed, visit duration and traffic source. This is collected through the technologies described in section 15 and processed in aggregate; Coresis does not use it to identify specific individuals.
6.3. Candidate data
CV, education, experience and any references the person provides during a recruitment process.
6.4. Data we do not request
Coresis does not request sensitive data or data concerning minors for any of the purposes in this policy. Nor does it buy databases or collect personal data from third-party sources for commercial purposes.
7. Purposes of processing
Data is processed solely for the purposes listed below, grouped by type of data subject.
7.1. People who contact us and prospective clients
- Answering the enquiry received by email, telephone or WhatsApp.
- Assessing the technical fit of the request and determining whether Coresis can provide the service.
- Preparing and sending proposals, quotes and estimates.
- Following up commercially on a conversation the data subject already started.
7.2. Clients
- Performing the contract and delivering the agreed development, support, migration or integration services.
- Managing invoicing, collection and the associated tax obligations.
- Handling support requests and managing production incidents.
- Keeping the project's historical record for warranty and service continuity purposes.
- Sending operational communications about the status of contracted services.
7.3. Suppliers and partners
- Managing contracting, payments and compliance with reciprocal obligations.
- Verifying the supplier's suitability and qualification status.
7.4. Candidates and team members
- Running recruitment processes and assessing suitability for a role.
- Maintaining a CV pool for future vacancies, where the candidate authorises it.
- Managing the employment or contractual relationship and its resulting obligations.
7.5. Cross-cutting purposes
- Analysing website use in aggregate in order to improve its content and performance.
- Protecting infrastructure security and preventing fraud and abuse.
- Responding to requests from competent administrative or judicial authorities.
- Complying with the legal, accounting and tax obligations applicable to Coresis.
Any purpose beyond those listed requires fresh, specific authorisation from the data subject.
8. Data subject authorisation
Authorisation is obtained before processing, by a means that allows proof of it to be kept. In Coresis's practice it is granted in the following ways:
- By unequivocal conduct: when a person voluntarily writes to Coresis by email, telephone or WhatsApp to enquire about a service, that communication constitutes authorisation to process their data for purposes 1 to 4 of section 7.
- By contractual clause: contracts with clients and suppliers incorporate authorisation for the purposes inherent to the relationship.
- By express statement: for purposes other than the above, through a written message from the data subject.
Under article 10 of Ley 1581 de 2012, no authorisation is required where the information is required by a public body exercising its legal functions or by court order, where the data is public in nature, in medical or health emergencies, for duly dissociated historical, statistical or scientific processing, or where the data relates to the Civil Registry.
Authorisation may be revoked at any time by writing to contacto@coresis.info, unless a legal or contractual duty requires the information to be retained. Revocation does not apply retroactively to processing already carried out lawfully.
9. Data subject rights
Article 8 of Ley 1581 de 2012 grants every person the following rights over their data:
- To know, update and rectify their personal data held by Coresis, particularly where it is partial, inaccurate, incomplete, fragmented or misleading.
- To request proof of the authorisation granted, except where the law does not require it.
- To be informed, upon request, of the use made of their personal data.
- To lodge complaints with the Superintendencia de Industria y Comercio for breaches of the regulations.
- To revoke authorisation or request deletion of the data, where the authority has determined that the processing breached the law, or where no legal or contractual duty to retain it exists.
- To access free of charge their personal data that has been processed.
These rights may be exercised by the data subject, their successors, their legal representative or attorney, or a party acting under a stipulation in their favour. Coresis charges nothing for handling these requests.
10. Procedure for queries and complaints
All requests should be sent to contacto@coresis.info, stating the data subject's name, a description of the request and a contact method for the reply. The time limits are those set by articles 14 and 15 of Ley 1581 de 2012.
10.1. Queries (consultas)
Where the data subject wishes to know their data or the information associated with it, Coresis replies within a maximum of ten (10) business days from the date of receipt. Where this is not possible, the reason and the reply date are communicated to the person concerned, and in no case does that date exceed five (5) business days after the expiry of the first period.
10.2. Complaints (reclamos)
Where the data subject considers that their information should be corrected, updated or deleted, or identifies an alleged breach of the regulations, they may lodge a complaint. Coresis resolves it within a maximum of fifteen (15) business days from the day following receipt. Where this is not possible, the reason and the reply date are communicated, and that date does not exceed eight (8) business days after the expiry of the first period.
If the complaint is incomplete, Coresis requests further detail within the following five (5) days. If two (2) months pass without a reply, the complaint is deemed withdrawn. While a complaint is pending, the disputed data is flagged with the notice "reclamo en trámite" (complaint pending).
11. Complaints to the authority
Data subjects may lodge a complaint with the Superintendencia de Industria y Comercio, Colombia's personal data protection authority. Under article 16 of Ley 1581 de 2012, this route is available only once the query or complaint procedure described in the previous section has been exhausted.
The Superintendencia may be reached at its Bogotá D.C. offices, through its website sic.gov.co and through its citizen service lines.
12. Sensitive data and minors
Coresis does not collect sensitive data for its own purposes. If, in the course of a project, a client requires Coresis to process sensitive data on its behalf, that processing is governed by the relevant contract, is limited to what is strictly necessary, and is subject to the reinforced safeguards of article 6 of Ley 1581 de 2012.
No one is obliged to authorise the processing of sensitive data, and such a refusal cannot be made a condition for providing a service.
Coresis likewise does not direct its services at minors, nor does it deliberately collect their data. Where processing the data of minors becomes necessary within a client's project, the best interests of the child are observed, their fundamental rights are respected, and the legal representative's authorisation is required, having first given the minor the right to be heard.
13. Data processors
Coresis relies on technology providers that process data on its behalf. Rather than referring to them generically, we identify them:
| Provider | Function | Data processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Content delivery network, DNS and attack protection | IP address, headers and request metadata | United States, with distributed nodes |
| Google LLC — Google Analytics 4 (identifier G-7WPG42NBTW) | Website usage analytics | Pseudonymised browsing data and cookie identifier | United States and European Union |
| jsDelivr | Delivery of third-party static libraries | IP address associated with the asset request | Distributed network |
| Hosting and infrastructure provider | Website and corporate email hosting | Content of communications and server logs | As per the contract in force |
| Dify and n8n | Workflow and agent orchestration in artificial intelligence projects | Whatever data the workflow processes, per project | Self-hosted or cloud, per project |
| Language model providers via API | Inference in artificial intelligence projects | The content sent to the model in each request | United States, unless self-hosted |
Coresis does not own data centres. The infrastructure supporting the website and client projects is contracted from third parties, under agreements requiring them to process data solely on the instructions of Coresis or its client.
Beyond these processors, Coresis does not sell, rent or transfer personal data to third parties for advertising purposes.
14. International transfer and transmission
Colombian law distinguishes two figures that are often conflated, and which are addressed separately here.
14.1. International transmission
This occurs when data is communicated to a processor so that it processes them on behalf of Coresis. That is the case for every provider in section 13. The purpose does not change and Coresis retains control over the data. These transmissions are governed by contracts setting out the scope of processing, the security obligations and the duty of confidentiality, under article 25 of Decreto 1377 de 2013.
14.2. International transfer
This occurs when data is sent to a recipient acting as an independent controller. Article 26 of Ley 1581 de 2012 prohibits transfers to countries that do not provide adequate levels of protection, save for the exceptions listed there, among them the data subject's express and unequivocal authorisation.
Coresis does not carry out international transfers as ordinary practice. Where they occur, they rely on the declaration of countries with an adequate level of protection issued by the Superintendencia de Industria y Comercio through Circular Externa 005 de 2017, or on the data subject's express authorisation.
15. Data processing in artificial intelligence workflows
Part of Coresis's work consists of building agents and automations that operate over a client's systems. Because those workflows process information, it is worth stating precisely what that involves.
- The data belongs to the client. In these projects Coresis acts as a processor: the client defines the purposes and retention periods, and Coresis confines itself to what was agreed.
- Client data is not used to train models. Neither our own nor third-party models. Information passing through a workflow is used to resolve that workflow's task, and nothing else.
- Minimisation in what reaches the model. Agents are designed to send only the fragment of context needed for the task, not entire records.
- Bounded, auditable actions. Agents execute only explicitly authorised tools, and their executions are logged, so that what was done and with which data can be reconstructed.
- Option to deploy on the client's own infrastructure. Where the sensitivity of the information justifies it, open models and orchestrators can be deployed inside the client's perimeter, so that data does not leave towards third-party services.
- Automated decisions. Coresis does not build workflows that take decisions with legal effects on a person without human intervention, save by express agreement with the client and with whatever safeguards that case requires.
16. Retention periods
Data is retained for as long as necessary for the purpose that justified its collection, and is then deleted or anonymised. The criteria are as follows:
| Category | Retention | Criterion |
|---|---|---|
| Commercial enquiries not leading to a contract | Up to 2 years from last contact | Reasonable commercial follow-up |
| Contractual and billing data | 10 years | Article 28 of Ley 962 de 2005 and accounting and tax rules |
| Server technical logs | Up to 12 months | Security and incident diagnosis |
| Aggregate web analytics | Per the provider's configuration, up to 14 months | Usage trend analysis |
| CVs of unsuccessful candidates | 1 year, or until the candidate requests deletion | Future vacancies, subject to authorisation |
| Data processed on a client's behalf | As set by the contract | The client is the controller |
17. Cookies and tracking technologies
The site uses cookies and equivalent technologies for two purposes. Technical cookies are necessary for the site to work: they hold the language preference and support the content delivery network's security measures. Analytics cookies, associated with Google Analytics 4, make it possible to know in aggregate which pages are consulted and through which channels traffic arrives.
Analytics cookies are not necessary for browsing. Anyone may block or delete them from their browser settings, or install the opt-out add-on published by Google, without this affecting access to the site's content.
18. Security measures
Coresis applies technical, human and administrative measures proportionate to the risk, aimed at preserving the confidentiality, integrity and availability of information:
- Encryption in transit via TLS across the whole site and corporate email.
- Role-based access control, on a least-privilege basis, with reinforced authentication on critical systems.
- Security updates to the core and modules of the platforms Coresis operates.
- Activity logging that allows access and changes to be reconstructed.
- Backups and tested restoration procedures.
- Confidentiality clauses with the team and with providers.
No measure removes risk entirely. Should an incident compromise personal data, Coresis reports it to the Superintendencia de Industria y Comercio and notifies the affected data subjects, in accordance with the duty set out in article 17(n) of Ley 1581 de 2012.
19. Coresis's duties
In addition to the above, Coresis assumes the duties in articles 17 and 18 of Ley 1581 de 2012: guaranteeing the data subject the full exercise of their rights, keeping proof of authorisation, disclosing the use made of the data, handling queries and complaints within the stated periods, keeping information up to date, observing security conditions and giving notice when particular information is under dispute.
20. Validity
This policy has been in force since 29 August 2026 and remains in force for as long as Coresis pursues its corporate purpose. Databases are retained for the periods set out in section 16.
Coresis may amend this policy when its practices or the applicable regulations change. Substantial changes are announced on this page at least ten (10) business days before they take effect. The applicable version is always the one published here, identified by its number and date.
21. Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 29 August 2026 | Initial publication of the policy. |
| 2.0 | 29 August 2026 | Expanded version. Adds definitions, principles, purposes by type of data subject, the query and complaint procedure with statutory time limits, a named list of processors, the distinction between international transfer and transmission, data processing in artificial intelligence workflows, retention periods and version history. |