The handling, actions, and protocols Netmask S.A.S. applies to the processing of personal data, in compliance with the Colombian Personal Data Protection Regime (Law 1581 of 2012).
In force · from 2026
Netmask S.A.S. is committed to respecting the rights of its clients, suppliers, employees, and third parties in general. It therefore adopts the following personal data processing policy, which establishes the handling, actions, and protocols that are mandatory in all activities involving the processing of personal data, and sets out the rights of data subjects and the mechanisms available to exercise them.
This policy applies to all personal data recorded in databases processed by Netmask S.A.S. and associated with clients, suppliers, employees, and third parties required for its commercial and core activities.
This policy complies with the Personal Data Protection Regime in Colombia, articles 15 and 20 of the National Constitution, Statutory Law 1581 of 2012, its implementing decrees, and the regulations issued by the Superintendence of Industry and Commerce.
General Management, the Document Management process, the Information Security and Cybersecurity Policy, Commercial Processes, Marketing, and the entire ISMS; likewise the company Netmask S.A.S.
Personal data must be processed in accordance with the general and specific rules on the matter and only for activities permitted by law.
Operations that constitute processing of personal data by Netmask S.A.S., whether as controller or processor, are governed by the following parameters and purposes:
Netmask S.A.S. informs candidates of the rules applicable to the processing of their data. Once the process ends, it retains the data of candidates who were not selected — unless deletion is requested in writing — in order to consider them for future recruitment processes.
Employees' personal data and information is stored in identified folders, accessed only by Management / Human Resources, in order to administer the employment relationship. The data subject authorizes the processing of sensitive data (biometric data, health data, data of minor beneficiaries) and its transmission to strategic partners for social security enrollment, as well as its possible transfer or transmission to other countries according to the company's needs.
Once the employment relationship ends, data is stored in a central archive with adequate security measures, for the sole purpose of complying with obligations arising from the relationship and reporting to the competent labor and tax authorities.
Shareholder data is treated as confidential and restricted information. It is used only for the purposes of the statutory relationship, to give notice of meetings or financial reports, and to manage relationships with other entities where their involvement is required.
Only data necessary for the selection, evaluation, and execution of the commercial agreement is collected. In addition, supplier data is processed to manage payments and collections; to inform and evidence their status as a supplier; to respond to inquiries and complaints; to transfer information to related areas and companies in Colombia and abroad; to respond to judicial or administrative requirements; for video surveillance on the premises; and for screening against national and international lists (UN, OFAC) regarding money laundering and terrorism financing.
Only data necessary to offer the goods and/or services within the company's corporate purpose is collected. In addition, client data is processed to manage payments and collections; to record and update data; to manage loyalty programs; to contact clients through authorized channels; to respond to inquiries and complaints; to transfer information to related areas and companies; to respond to judicial requirements; for tax, accounting, and invoicing purposes; for video surveillance; and for screening against UN / OFAC lists.
Any processing of sensitive data without the authorization of the data subject and/or of Netmask S.A.S. is prohibited. Non-compliance is considered serious misconduct for employees and grounds for termination for suppliers, without prejudice to any legal action.
The assignment, communication, or circulation of personal data without the prior, written, and express consent of the data subject or the authorization of Netmask S.A.S. is prohibited.
Processing the data of children and adolescents is prohibited, except with the express authorization of their legal representatives, always safeguarding their prevailing rights.
Transfers to countries that do not provide adequate levels of protection are prohibited, except with the data subject's prior, express, and unequivocal authorization.
In order to process personal data, Netmask S.A.S. requests and obtains the data subject's prior, express, and informed authorization. By accepting this policy, any data subject who provides or makes available their personal data consents to its processing under the terms and conditions set out herein.
Inquiries are channeled through the email address contacto@netmask.co, indicating "Right of access or inquiry" in the subject line, or by postal mail to Calle 38 sur # 47A-21, office 201, Envigado, Antioquia — Edificio Portal de Alcalá, postal code 055422. The request must include: the data subject's first and last names, a copy of the data subject's ID (and of their representative's, where applicable), the specific request, an address for notices, the date and signature, and the corresponding supporting documents.
A response will be provided within a maximum of ten (10) business days from receipt. If it is not possible to respond within that term, the reasons and the new date will be communicated, which may not exceed five (5) additional business days.
Complaints seek to correct, update, or delete data, or to raise a grievance for alleged non-compliance with the duties set out in Law 1581 of 2012 and this policy. They are channeled through the Data Protection Officer. If a third party is competent, the complaint is forwarded within a maximum of two (2) business days.
If the complaint is incomplete, the interested party will be asked to complete it within the following five (5) days; if two (2) months pass without a response, the complaint will be deemed withdrawn. If it is complete, the note "complaint under review" will be added within no more than two (2) business days. The maximum term to resolve it is fifteen (15) business days from the day after receipt, extendable by up to eight (8) additional business days with notice of the reasons.
When data is sent or transferred to another country, the authorization of the data subject whose data is being transferred is mandatory. Unless the law provides otherwise, such authorization is a necessary condition for the international circulation of data.
International transmissions between a controller and a processor, so that the processor may carry out the processing on behalf of the controller, do not need to be communicated to the data subject nor require their consent, provided a personal data transmission agreement is in place.
In application of the security principle of Law 1581 of 2012, Netmask S.A.S. adopts the technical, human, and administrative measures necessary to secure records, preventing their alteration, loss, or unauthorized or fraudulent consultation, use, or access. Personnel follow the established protocols to guarantee information security.
Through the execution of transmission agreements, Netmask S.A.S. has required data processors to implement the security measures necessary to guarantee the security and confidentiality of the information.
This policy is in force from 2026 until further notice.