Legal

Personal data processing and protection policy

Bioingred Tech S.A.S. · Tax ID 901.118.436-4 · Colombian Law 1581 of 2012

This is a courtesy translation. The Spanish version of this Policy is the binding one and prevails in the event of any discrepancy.

The document PERSONAL DATA PROCESSING AND PROTECTION POLICY, hereinafter the Policy, of BIOINGRED TECH S.A.S., tax ID (NIT) 901.118.436-4, aims to disclose the processing applicable to the personal data held in its databases, the rights of the data subjects and the mechanisms available to exercise them.

This Personal Data Processing Policy has been drafted in accordance with the constitutional, legal and regulatory provisions on the matter, in particular articles 15 and 20 of the Political Constitution of Colombia, Law 1581 of 2012 "establishing general provisions for the protection of personal data", Decree 1377 of 2013 "partially regulating Law 1581 of 2012" and any complementary rules that add to or amend them.

1. Definitions

For the purposes of this Policy, the following terms have the meanings set out below:

  • Authorization: prior, express and informed consent of the data subject to carry out the processing of personal data.
  • Privacy notice: verbal or written communication issued by the Data Controller and addressed to the Data Subject regarding the Processing of their Personal Data, informing them of the existence of the applicable information processing policies, how to access them and the purposes for which the Personal Data is intended to be processed.
  • Communication / Transfer of data: any disclosure of data made to a person or entity other than the data subject. Except as otherwise provided, the transfer of personal data must be consented to by the Data Subject. Accordingly, personal data will not be transferred to other natural or legal persons unless the data subject's consent has been obtained or one of the exceptions provided for by law applies.
  • Unequivocal conduct: behaviour that reasonably allows the conclusion that the data subject granted authorization for the Processing.
  • Database: an organized set of personal data subject to processing.
  • Personal data: any information linked to, or that may be associated with, one or more specific or identifiable natural persons.
  • Public data: data classified as such under the law or the Political Constitution, and all data that is not semi-private or private in accordance with the law. Public data includes, among others, data relating to a person's civil status, profession or trade, and their status as a merchant or public servant. By its nature, public data may be contained, among others, in public records, official gazettes and bulletins, and final court judgments not subject to confidentiality.
  • Semi-private data: data that is neither intimate, confidential nor public in nature, and whose knowledge or disclosure may be of interest not only to the data subject but also to a given sector or group of persons, or to companies in general — such as financial and credit data relating to commercial or service activities, as established by the applicable regulations.
  • Sensitive data: data that affects the data subject's privacy or whose misuse may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership of trade unions, social or human rights organizations, or data promoting the interests of any political party or guaranteeing the rights of opposition political parties, as well as data relating to health, sex life and biometric data.
  • Private data: data that, due to its intimate or confidential nature, is relevant only to the data subject.
  • Data processor: a natural or legal person, public or private, who alone or in association with others processes personal data on behalf of the data controller.
  • Purpose: the definition of the objective for which the collected data subject to Processing will be used.
  • Data controller: a natural or legal person, public or private, who alone or in association with others decides on the Database and/or the processing of the Personal Data.
  • Data subject: the natural person whose Personal Data is subject to processing.
  • Transfer: the transfer of Personal Data takes place when the Data Controller and/or Processor located in Colombia sends the information or Personal Data to a recipient who is in turn a Data Controller and is located outside the country.
  • Transmission: processing of Personal Data involving its communication within or outside Colombian territory where the purpose is for the Processor to carry out processing on behalf of the Controller.
  • Processing: any operation or set of operations on Personal Data, such as collection, storage, use, circulation or deletion.
  • User: the persons or processes authorized by the Controller to access the resources containing the Data.
  • Cookies: information sent by a website and stored in the user's browser, so that the website can consult the user's previous activity. All cookie processing can be consulted at www.bioingred.co

2. Principles for the processing of Personal Data

In the development, interpretation and application of Law 1581 of 2012, which establishes general provisions for the protection of personal data, and the rules that complement, amend or add to it, the following principles will be applied in a harmonious and comprehensive manner:

  • Principle of access and circulation: processing is subject to the limits arising from the nature of the data, the applicable regulations and the principles governing the administration of Personal Data, in particular the principles of temporality of the information and the purpose of the Processing.

    Except for public information, Personal Data may not be available on the internet or other means of mass disclosure or communication, unless access is technically controllable so as to provide restricted knowledge only to Data Subjects or authorized users in accordance with applicable regulations.

  • Principle of confidentiality: all natural or legal persons involved in the administration of Personal Data that is not public in nature are required at all times to guarantee the confidentiality of the information, even after their relationship with any of the tasks comprising data administration has ended. Data may only be supplied or communicated when this corresponds to the activities authorized by law and under its terms.

  • Principle of purpose: the administration of Personal Data must serve a legitimate purpose in accordance with the Constitution and the law. The purpose must be communicated to the Data Subject prior to or at the time the Authorization is granted, where such authorization is required, and generally whenever the data subject requests information in this regard.

  • Principle of legality: data Processing is a regulated activity that must comply with the provisions of the Law and any other rules developing it.

  • Principle of freedom: processing may only be carried out with the prior, express and informed consent of the data subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate replacing consent.

  • Principle of security: information subject to processing must be handled with the technical, human and administrative measures necessary to provide security to the records, preventing their alteration, loss, or unauthorized or fraudulent consultation, use or access.

  • Principle of transparency: Processing must guarantee the Data Subject's right to obtain from the data controller or processor, at any time and without restriction, information about the existence of data concerning them.

  • Principle of accuracy or quality of the records or data: the information contained in the databases must be truthful, complete, accurate, up to date, verifiable and comprehensible. The recording and disclosure of partial, incomplete, fragmented or misleading data is prohibited.

3. Controller information

BIOINGRED TECH S.A.S. is responsible for the collection and Processing of Personal Data, the Authorization and the stored records, in all cases preventing them from deteriorating, being lost, altered or used without authorization, and keeping them with due security.

The customer service area handles requests, complaints and enquiries from data subjects. Data Subjects may exercise their rights to know, update, rectify and delete their Personal Data through:

4. Purposes of the processing

Personal Data provided to the responsible company will be processed in accordance with the following general purposes:

  • To carry out the Mission of BIOINGRED TECH S.A.S. in accordance with its bylaws.
  • To comply with the rules applicable to suppliers, contractors and students, including but not limited to tax, commercial and academic rules.
  • To comply with the provisions of Colombian law on labour and social security matters, among others, applicable to former employees, current employees and candidates for future employment.
  • To store documentation as evidence of compliance with the rules required by the occupational health and safety management system (SG-SST) required for each job that the data subject performs.
  • To fulfil the obligations and/or commitments arising from existing business relationships with Data Subjects.
  • To comply with legal obligations involving Data Subjects' Personal Data.
  • For commercial management and relationship building with Data Subjects.
  • For prospective analysis of Data Subjects' trends and preferences in relation to their goods and/or services.
  • To prospectively understand Data Subjects' needs in order to innovate and meet those needs.
  • To communicate to Data Subjects information about goods, services, publications, training events, business activities and/or advertising associated with the business activity, whether goods and/or services.
  • To carry out corporate social responsibility activities involving Data Subjects.
  • To be processed by the company by virtue of corporate, contractual or legal relationships.
  • To share it with third parties in fulfilment of the purpose of the business relationship between the parties.
  • To send, by post, email, mobile phone or mobile device, via text messages (SMS and/or MMS), commercial, advertising or promotional information about products and/or services, events and/or promotions of a commercial nature or otherwise, in order to promote, invite, direct, execute, inform and, in general, carry out campaigns, promotions or contests of a commercial or advertising nature.
  • To manage all information necessary to comply with the tax obligations and the commercial, corporate and accounting records that may apply to the company.
  • To share it with each other or with third parties and to provide data on the fulfilment or non-fulfilment of legal and contractual obligations, either directly or through the public entities exercising supervisory and control functions.
  • For consultation of restrictive lists, know-your-customer forms, relationship management, corporate risk management and the application of mitigation measures regarding money laundering and terrorism financing.
  • For consultation and reporting of conduct and history to financial risk bureaus.

We will only keep your information for as long as required by law or due to the relevance of the purposes for which it was collected.

5. Content of the databases

The databases of BIOINGRED TECH S.A.S. store general information such as first and last names, type and number of identification document, age, gender, department, city, neighbourhood and home address, landline and mobile phone numbers, and email address. In addition, and depending on the nature of the database, BIOINGRED TECH S.A.S. may hold specific data required for the processing to which the data will be subject. The database of employees, contractors or collaborators additionally includes information on employment and academic history, and sensitive data required by the nature of the employment, commercial or service relationship (photographs, recordings, family group, biometric and financial data, etc.).

Types of personal data

BIOINGRED TECH S.A.S. collects the following Personal Data:

  • Name, identity document number, domicile, telephone, physical or postal address, email and contact information.
  • Nationality, date of birth, citizenship ID, sex and marital status.
  • Occupation, employer, position, seniority in the position and contact details.
  • Information sent to us or consulted through social media databases, among other means where you have included your Personal Data.
  • IP address and browser type when obtained by electronic means.
  • Information obtained through cookies, web beacons and web crawlers.
  • Financial information.
  • Any information necessary to meet special requests.
  • Information you provide in relation to your commercial preferences or in the course of participating in surveys, contests or promotional offers.
  • Images, recordings and photographs.
  • Personal Data considered sensitive.

Cookies and third-party analytics tools

This website uses first-party cookies, which are necessary for it to work, and analytics and marketing cookies that are only activated if you expressly accept them in the cookie notice. Until you accept them, no third-party tool is loaded in your browser.

If you accept them, the following tools are used:

  • Google Analytics 4, provided by Google Ireland Limited. Purpose: to measure site traffic (pages visited, traffic source, device) in aggregate form, in order to understand how the site is used and improve it. This involves an international transfer of data to the United States.
  • Meta Pixel, provided by Meta Platforms Ireland Limited. Purpose: to measure the results of our advertising campaigns and to show relevant ads on Facebook and Instagram. This involves an international transfer of data to the United States.

These tools may record your IP address, the cookie identifier assigned to you, the pages you visit and the actions you take on the site (for example, submitting a contact form or downloading a technical data sheet). We do not share your name, email address or any other directly identifying data with them.

You may withdraw your consent at any time from the "Cookies" link in the site footer, or by deleting cookies in your browser settings. Withdrawal does not affect the lawfulness of processing carried out before it.

6. Rights of data subjects

In accordance with the law, Data Subjects have the following rights:

  • Update: to update the Personal Data held in the databases of BIOINGRED TECH S.A.S. in order to maintain its integrity and accuracy.
  • Knowledge and access: to know and access their Personal Data stored by BIOINGRED TECH S.A.S. or its processors. Such access will be granted free of charge upon request whenever the Data Subject requires it.
  • Proof: to request proof of the authorization granted to BIOINGRED TECH S.A.S., unless the law states that such authorization is not required or that it has been validated.
  • Complaint: to file complaints for breaches of the law with the competent authorities once the admissibility requirement has been met, first approaching BIOINGRED TECH S.A.S.
  • Rectification: to rectify the information and Personal Data under the control of BIOINGRED TECH S.A.S.
  • Revocation: to request revocation of the authorization, provided that there is no legal duty or contractual obligation on the Data Subject towards BIOINGRED TECH S.A.S. under which the Data Subject is not entitled to request the deletion of their Personal Data.
  • Request: to submit requests to BIOINGRED TECH S.A.S. or the processor regarding the use made of their Personal Data.
  • Deletion: to request the deletion of their Personal Data from the databases of BIOINGRED TECH S.A.S., provided that there is no legal duty or contractual obligation on the Data Subject towards BIOINGRED TECH S.A.S. under which the Data Subject is not entitled to request the deletion of their Personal Data.

7. Revocation of the authorization and/or deletion of data

Data Subjects may at any time request the company to delete the Personal Data referred to in Law 1581 of 2012 and/or revoke the Authorization granted for its Processing, by submitting a claim in accordance with the procedure set out in this Policy.

If, upon expiry of the relevant legal term, the company has not deleted the Personal Data, the Data Subject is entitled to ask the Superintendency of Industry and Commerce to order the revocation of the Authorization and/or the deletion of the Personal Data. Notwithstanding the foregoing, Personal Data must be retained where required to comply with a legal or contractual obligation.

Where Controllers process Sensitive Data, it is guaranteed that Authorization for the Processing of such data will be obtained in advance and expressly, in compliance with the following obligations:

  • The Data Subject will be informed that, as the data is Sensitive Data, they are not obliged to authorize its Processing.
  • The Data Subject will be informed in advance and expressly which data is Sensitive and the purpose of the Processing to be applied to it.

8. Procedure for exercising the right of Habeas Data

Data Subjects may exercise their statutory rights and carry out the procedures set out in this Policy by contacting karinaroman@bioingred.co. BIOINGRED TECH S.A.S. will respond to complaints, requests or claims in accordance with the provisions of personal data protection regulations.

To exercise their rights to know, update, rectify and delete the Personal Data stored in the databases of BIOINGRED TECH S.A.S., and to revoke the authorization for the use and storage of such personal information, the Data Subject must send the relevant request or claim in writing to the contact details provided for the processing of Personal Data.

Data subjects or their successors may exercise the aforementioned rights under the following rules:

  1. The rights of consultation, rectification, update, deletion or revocation of consent may be exercised only by the data subject or their successors, subject to proof of identity; or by their representative, subject to proof of representation.
  2. Where the request is made by a person other than the data subject and it is not established that they act on the data subject's behalf, it will be deemed not to have been submitted. Requests for consultation, rectification, update, deletion or revocation must be submitted in writing through the channels enabled by BIOINGRED TECH S.A.S. and must contain at least the following information:
    • The name and domicile of the data subject or any other means of receiving the response.
    • The documents proving the identity of the applicant and, where applicable, that of their representative together with the relevant authorization.
    • A clear and precise description of the personal data in respect of which the data subject seeks to exercise any of the rights, and the specific request.
  3. The petition, complaint or claim must contain the identification of the Data Subject, a description of the facts giving rise to the claim, the address, and the supporting documents to be relied upon, submitted as follows:
    • By a written request to the notification address of BIOINGRED TECH S.A.S. Calle 46 # 41 – 69 Bloque A 43 Piso 3. Itagüí, Antioquia, Colombia
    • By a request sent by email to the following address: karinaroman@bioingred.co
  4. If the claim is incomplete, the interested party will be required, within five (5) days of receipt of the claim, to remedy the deficiencies. If two (2) months elapse from the date of the request without the applicant submitting the required information, the claim will be deemed withdrawn. If the recipient of the claim is not competent to resolve it, they will forward it to the appropriate party within a maximum of two (2) business days and will inform the interested party of the situation. Once the complete claim has been received, a note stating "claim in process" and its reason will be added to the database within no more than two (2) business days. That note must remain until the claim has been decided.
  5. The maximum term to address the claim is fifteen (15) business days from the day following the date of its receipt. Where it is not possible to address the claim within that term, the interested party will be informed of the reasons for the delay and the date on which the claim will be addressed, which may in no case exceed eight (8) business days following the expiry of the first term.

9. International transfer or transmission of Personal Data

BIOINGRED TECH S.A.S. may carry out the Transfer and Transmission, including internationally, of the Personal Data held in its Databases, provided that the applicable legal requirements are met and that the Data Subjects expressly authorize such Transfer and Transmission, including at international level.

For the Transfer of Data Subjects' Personal Data, the necessary measures will be adopted so that third parties are aware of and undertake to observe this Policy, on the understanding that the personal information they receive may only be used for matters directly related to the company or the purposes expressly authorized by the Data Subject, and only while this Authorization remains in force. It may not be used or intended for any different purpose.

10. Amendments to the Personal Data Protection Policy

BIOINGRED TECH S.A.S. reserves the right to make amendments or updates to this Personal Data Protection Policy at any time, to address legislative developments, internal policies or new requirements for the provision or offering of its services or products. These amendments will be made available to the public through the website www.bioingred.co

11. Term

This Policy takes effect from its publication date, 1 March 2026. It may be amended from time to time by BIOINGRED TECH S.A.S. and will form part of the contracts it enters into where relevant. Any substantial amendment to this Policy must be communicated in advance to Data Subjects through efficient mechanisms, such as the BIOINGRED TECH S.A.S. website and/or emails. Where required by applicable law, the Data Subjects' authorization will also be sought.

Substantial amendments include, among others, those relating to the exercise of Data Subjects' rights and to the purposes of the processing of Personal Data where this may affect the authorization.

In force since 1 March 2026

Download PDF