EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. HEREBY INFORMS ALL OF ITS CLIENTS, EMPLOYEES, VISITORS AND SUPPLIERS OF ITS PERSONAL DATA PROCESSING POLICY.
PURPOSE
In connection with the enactment of Law 1581 of 2012 and Sole Regulatory Decree 1074 of 2015, and in order to comply with their provisions, which develop the right of individuals to know, update, rectify or delete the personal information that has been collected about them in any database or file, EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S., identified with Tax ID (NIT) 804.005.810-9, domiciled in Girón – Santander, requests authorization from the holders of personal data to use it in a legal, lawful, secure and reliable manner, in accordance with its Policies and procedures for the Processing of personal data.
OBJECTIVE
To ensure the appropriate processing of the personal data of clients, potential clients, employees, former employees, suppliers, contractors, shareholders, visitors and other data subjects linked to the organization.
To this end, ESSI SAS will define the respective purposes of the processing, the rights of the data subjects, the service channels and the internal procedure for inquiries and claims. Finally, it incorporates the guidelines for the processing of associated information.
SCOPE
This policy applies to all personal databases managed by ESSI SAS, in physical, digital, automated, semi-automated, cloud-based or any other medium, as well as to the data processors acting on behalf of the Company.
DEFINITIONS
For the purposes of implementing this policy, and in accordance with the applicable legal regulations, the following definitions shall apply:
a) Authorization: Prior, express and informed consent of the Data Subject to carry out the Processing of personal data;
b) Privacy notice: A physical, electronic or any other format document generated by the data controller and made available to the Data Subject for the processing of their personal data. The Privacy Notice informs the Data Subject of the information regarding the existence of the information processing policies that will apply to them, how to access such policies and the purpose for which the personal data is intended to be used;
c) Database: An organized set of personal data that is subject to Processing;
d) Personal data: Any information linked to, or that may be associated with, one or more specified or identifiable natural persons;
e) Public data: Data classified as such pursuant to the mandates of the law or of the Political Constitution, and any data that is not semi-private, private or sensitive. Public data includes, among others, data relating to the civil status of persons, to their profession or trade, to their status as a merchant or public servant, and any data that may be obtained without any restriction. By their nature, public data may be contained, among others, in public registries, public documents, official gazettes and bulletins;
f) Private data: Data that, due to its intimate or reserved nature, is only relevant to the data subject;
g) Sensitive data: Sensitive data is understood to be data that affects the privacy of the Data Subject or whose improper use may lead to discrimination, such as data that reveals racial or ethnic origin, political orientation, religious or philosophical convictions, membership in unions, social organizations, or human rights organizations, or that promotes the interests of any political party or that guarantees the rights and guarantees of opposition political parties, as well as data relating to health, sexual life and biometric data;
h) Data Processor: A natural or legal person, whether public or private, who, alone or in association with others, carries out the Processing of personal data on behalf of the data controller;
i) Data Controller: A natural or legal person, whether public or private, who, alone or in association with others, decides on the database and/or the Processing of the data;
j) Data Subject: A natural person whose personal data is subject to Processing;
k) Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, circulation or deletion thereof.
PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA
The processing of personal data at EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. shall be governed by the following principles:
a) Principle of purpose: The processing must serve a legitimate purpose in accordance with the Constitution and the Law, which must be communicated to the data subject. With respect to the collection of personal data, ESSI SAS will limit itself to data that is relevant and adequate for the purpose for which it was collected or required, which must be communicated at the time the information is collected;
b) Principle of freedom: Processing may only be carried out with the prior, express and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that waives consent;
c) Principle of truthfulness or quality: The information subject to Processing must be truthful, complete, accurate, up to date, verifiable and understandable. The Processing of partial, incomplete, fragmented or misleading data shall not be carried out;
d) Principle of transparency: In the Processing, the right of the Data Subject to obtain from EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S., at any time and without restrictions, information about the existence of data concerning them, must be guaranteed;
e) Principle of restricted access and circulation: Processing is subject to the limits arising from the nature of the personal data, the provisions of this law and the Constitution. Personal data, except for public information and as provided in the authorization granted by the data subject, may not be made available on the Internet or other means of mass dissemination or communication, unless access is technically controllable so as to provide restricted knowledge only to the Data Subjects or authorized third parties;
f) Principle of security: The information subject to Processing by EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. shall be protected through the use of such technical, human and administrative measures as may be necessary to provide security to the records, preventing their alteration, loss, consultation, unauthorized or fraudulent use or access;
g) Principle of confidentiality: All persons involved in the Processing of personal data are obligated to guarantee the confidentiality of the information, even after their relationship with any of the tasks comprising the Processing has ended.
FIRST PARAGRAPH: In the event that sensitive personal data is collected, the Data Subject may refuse to authorize its Processing.
CATEGORIES OF DATA SUBJECTS AND PROCESSING PURPOSES
Clients and potential Clients: To manage commercial offers, quotations, contact, attention to requests, the execution and performance of contracts, invoicing, accounts receivable, after-sales service, authorized marketing and compliance with legal and contractual obligations, and verification against Sagrilaft and PTEE restrictive lists.
Employees, Applicants and Former Employees: To carry out selection processes, profile validation, interviews, home visits where applicable, enrollment in the social security system, payroll administration, welfare, occupational health and safety, training, access control and compliance with labor and social obligations, and verification against Sagrilaft and PTEE restrictive lists.
Suppliers and contractors: To evaluate and select suppliers, validate documents, manage purchase orders and contracts, payments, accounting, tax and contractual control, as well as compliance monitoring, and verification against Sagrilaft and PTEE restrictive lists.
Shareholders: To administer the shareholders’ ledger, verify the corporate structure, address legal, corporate and accounting requirements and carry out communications associated with the corporate relationship.
Visitors: Control of access to the facilities, protection of assets, physical security and traceability of visits.
Accounting and administrative information: To support the recording of operations, the preparation of financial statements, tax compliance, attention to audits, requirements from authorities and the preservation of evidentiary supporting documents.
PROCESSING OF PERSONAL DATA
COLLECTION
Data is collected through the completion and/or submission of documents, the receipt of emails, by telephone and any other means by which it is requested or provided pursuant to the Privacy Notice or the express authorization for processing, whereby the Data Subject authorizes the retention and use of such information for the purposes set forth. Likewise, authorization will not be required when the data is collected pursuant to an express legal request from a State entity.
STORAGE
We retain the information for as long as is reasonable and necessary, in physical and magnetic media, in accordance with the purposes that justified the collection of such information. Once the information is no longer necessary for our purposes, we will delete the personal data in our possession.
In labor matters, the information provided in résumés or during the selection process will be retained even if the contractual relationship does not materialize, for the purpose of considering applicants for future calls.
USE
The information authorized for processing shall have as its ultimate purpose:
VIRTUAL CLIENT DATABASE: To promote and present commercial offers to potential clients.
PHYSICAL CLIENT DATABASE: To promote and present commercial offers to potential clients.
PHYSICAL EMPLOYEE DATABASE: To carry out all the procedures inherent to a pre-selection process of our candidates for positions, such as home visits and technical security analyses, and to comply with our employer obligation to enroll our dependent workers in the comprehensive general social security system and guarantee the rights granted to them by labor legislation.
VIRTUAL EMPLOYEE DATABASE: To comply with our employer obligation to enroll and pay contributions to the comprehensive general social security system for all of our dependent workers and to guarantee the rights granted to them by labor legislation, especially the recognition of salaries and social benefits.
PHYSICAL SUPPLIER DATABASE: To analyze the supplier market so as to efficiently satisfy the needs inherent to the course of our business.
PHYSICAL SHAREHOLDER DATABASE: To comply with our legal duties to keep the shareholding of the company’s partners up to date.
VIRTUAL ACCOUNTING DATABASE: To establish rigorous control over each of the resources and obligations of the business; to record, clearly and precisely, all operations carried out by the company during the fiscal year; to provide, at any time, a clear and truthful picture of the financial situation of the business; to anticipate the future of the company well in advance; and to serve as proof and a source of information, before third parties, of all legal acts in which the accounting records may have evidentiary value in accordance with the provisions of the law.
PHYSICAL ACCOUNTING DATABASE: To establish control over each of the physical accounting documents kept at the company, such as invoices, disbursement vouchers, deposit slips and financial statements, that are collected during the fiscal year; in order to evidence the accounting and legal situation of the company, and which may have to be provided to oversight entities.
AUTHORIZATION OF THE DATA SUBJECT
ESSI SAS will request prior, express and informed authorization from the data subject, except in the cases exempted by law. This authorization may be obtained through physical documents, data messages, emails, web registration, recording or other mechanisms that allow for its subsequent consultation and proof.
In the case of sensitive data, the data subject will be informed that they are not obligated to provide it for processing.
PROCESSING OF SENSITIVE DATA
The processing of sensitive data will be carried out only when necessary and proportionate for legitimate, labor, occupational health and safety, legal compliance, Sagrilaft and PTEE purposes, or any other purpose permitted by law. The company will adopt greater access, confidentiality and security controls for this type of information.
Processing of data of children and adolescents – NNA
ESSI SAS will only process the personal data of children and adolescents when such processing is of a public nature or when it is necessary, respects their best interests and ensures their fundamental rights established through the Constitution and case law.
In these cases, prior authorization from the legal representative and/or guardian must be obtained, where applicable, and the opinion of the minor will be heard in accordance with their maturity, autonomy and capacity for understanding.
Guidelines on new technologies, artificial intelligence, big data and e-commerce
When ESSI SAS implements artificial intelligence tools, data analytics, automation, profiling, Big Data solutions or e-commerce channels, the processing of personal data must respect the principles of purpose, necessity, proportionality, security, transparency and restricted access.
Technological projects must incorporate privacy-by-design and privacy-by-default measures, data minimization controls, segregation of access, traceability, incident management and prior risk assessment when the nature of the processing so advises.
In e-commerce scenarios, the company will adopt measures to protect identification, contact, billing, browsing, transaction and authentication data, clearly informing the purposes of the processing and the channels for exercising rights.
When third-party technology providers, cloud platforms, payment gateways, digital marketing or analytics solutions are used, the company will require commitments regarding confidentiality, security and compliance with personal data protection.
Security and confidentiality measures
ESSI SAS will adopt reasonable human, administrative, technical and organizational measures to protect the information against loss, misuse, unauthorized access, alteration, destruction or fraud.
RIGHTS THAT YOU HAVE AS A DATA SUBJECT AND THE PROCEDURE TO EXERCISE THEM
As the holder of the collected information, you may at any time file complaints with the Superintendence of Industry and Commerce for infringements of the provisions of the regulations on personal data, and you may know, update, rectify, expand or delete the personal information provided. To do so, you may submit your request through the PQRS (Petitions, Complaints and Claims) module on the website https://essi.com.co/pqrs and/or during the hours and at the telephone numbers and addresses detailed below.
The Data Subject is not obligated to provide data considered sensitive by law.
Claims: The Data Subject or their successors in title who consider that the information contained in a database should be corrected, updated or deleted, or who notice the alleged breach of any of the duties contained in this law, may file a claim with the Data Controller or the Data Processor, which will be processed under the following rules:
1. The claim shall be made by means of a request addressed to the Data Controller or the Data Processor, with the identification of the Data Subject, a description of the facts giving rise to the claim, the address, and attaching the documents to be relied upon. If the claim is incomplete, the interested party will be required, within five (5) days following receipt of the claim, to remedy the deficiencies. If, two (2) months after the date of the request, the petitioner has not submitted the required information, it will be understood that they have withdrawn the claim. In the event that the recipient of the claim is not competent to resolve it, it will be forwarded to the appropriate party within a maximum term of two (2) business days, and the interested party will be informed of the situation.
2. Once the complete claim is received, a notice reading “claim in process” and the reason for it will be included in the database within a term of no more than two (2) business days. This notice must be maintained until the claim is decided.
3. The maximum term to address the claim will be fifteen (15) business days from the day following the date of its receipt. When it is not possible to address the claim within this term, the interested party will be informed of the reasons for the delay and the date on which the claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the first term.
The Data Subject or successor in title may only file a complaint with the Superintendence of Industry and Commerce once they have exhausted the inquiry or claim procedure before the Compliance Officer, the Data Controller.
AREA IN CHARGE
The COMPLIANCE AREA of EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. will be responsible for addressing the petitions, complaints and claims filed by the data subject in the exercise of the rights set forth in the previous section of this policy. For such purposes, the data subject or their representative may send their petition, complaint or claim Monday to Friday from 7:30 a.m. to 5:00 p.m. to the email address compliance@essisas.com and/or through the PQRS module on the website https://essi.com.co/pqrs, or file it at the following address corresponding to our offices: CARRERA 16C No 60-110, La Esmeralda neighborhood, municipality of Girón – Santander.
VALIDITY OF THE PERSONAL DATA PROCESSING
Our Personal Data Processing Policy is effective as of the first (01) of September of two thousand seventeen (2017). The personal data that is stored, used or transmitted will remain in the corresponding databases safeguarded by the Company for as long as necessary for the purposes mentioned in this Policy, so that its processing is directly linked to the purposes for which the personal data was collected.
AMENDMENTS
EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. reserves the right to make such amendments to this policy as it deems pertinent and necessary; therefore, in the event of implementing any substantial change regarding the storage or use of your information, this will be published on our website or an electronic notification will be sent to your respective addresses.
With this notice, EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S. complies with all of the requirements of Law 1581 of 2012 and Sole Regulatory Decree 1074 of 2015.
Sincerely,
___________________________________
IVÁN EDUARDO MARTÍNEZ CARRASCAL
GENERAL MANAGER
EMPRESA DE SOLUCIONES, SERVICIOS E INNOVACIÓN ESSI S.A.S.
FUA: 08/05/2026