You will not be allowed to compare more than 4 products at a time
View compareData Processing Policy
PERSONAL DATA PROTECTION PROCESSING POLICY
In compliance with the provisions of Statutory Law 1581 of 2012 and its Regulatory Decree 1377 of 2013, the International School of Business and Entrepreneurial Development of Colombia, EIDEC, adopts this policy for the processing of personal data, which will be informed to all data subjects whose data has been collected or will be obtained in the future in the exercise of academic, cultural, commercial or labor activities.
Thus, the International School of Business and Entrepreneurial Development of Colombia, EIDEC, states that it guarantees the rights to privacy, intimacy, good name, and university autonomy in the processing of personal data, and consequently, all its actions will be governed by the principles of legality, purpose, freedom, veracity or quality, transparency, restricted access and circulation, security and confidentiality.
All individuals who, in the course of various cultural, academic, contractual, commercial, labor, among other activities, whether permanent or occasional, provide the International School of Business and Entrepreneurial Development of Colombia, EIDEC, with any type of information or personal data, may access, update, and rectify it.
I. IDENTIFICATION OF THE DATA CONTROLLER
INSTITUTION NAME: The International School of Business and Entrepreneurial Development of Colombia, EIDEC, hereinafter referred to as EIDEC, a private law institution.
DOMICILE AND ADDRESS: EIDEC is domiciled in the city of Bucaramanga, and its main office is located at Cra 33 No 52-67.
EMAIL: direccion@eidec.com.co
PHONE: (607) 6915136
II. LEGAL FRAMEWORK
- Political Constitution, Article 15. Law 1266 of 2008
- Law 1581 of 2012
- Regulatory Decrees 1727 of 2009 and 2952 of 2010, Partial Regulatory Decree 1377 of 2013
- Sentences C – 1011 of 2008, and C - 748 of 2011, of the Constitutional Court
III. SCOPE OF APPLICATION
This policy will apply to personal data registered in any EIDEC database whose data subject is a natural person.
IV. DEFINITIONS
For the purposes of this policy and in accordance with current regulations on personal data protection, the following definitions will be taken into account:
Authorization: Prior, express, and informed consent of the Data Subject to carry out the Processing of personal data.
Privacy Notice: Verbal or written communication generated by the controller, addressed to the Data Subject for the processing of their personal data, informing them about the existence of the applicable information processing policies, how to access them, and the purposes of the intended processing of personal data.
Database: Organized set of personal data that is subject to processing. Beneficiary: a person who has succeeded another due to the latter's death (heir).
Personal data: Any information linked to or that can be associated with one or more determined or identifiable natural persons.
Public data: Data that is not semi-private, private, or sensitive. Public data includes, among others, data related to the civil status of persons, their profession or trade, and their status as a merchant or public servant. Due to their nature, public data may be contained, among others, in public records, public documents, official gazettes and bulletins, and duly executed judicial sentences that are not subject to reservation.
Sensitive data: Sensitive data refers to data that affects the Data Subject's intimacy or whose improper use may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions, social organizations, human rights organizations, or that promote the interests of any political party or guarantee the rights and guarantees of opposition political parties, as well as data related to health, sexual life, and biometric data.
Data Processor: Natural or legal person, public or private, who by themselves or in association with others, processes personal data on behalf of the Data Controller.
Data Controller: Natural or legal person, public or private, who by themselves or in association with others, decides on the database and/or the processing of the data.
Data Subject: Natural person whose personal data is subject to Processing.
Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.
Transfer: data transfer occurs when the data controller and/or data processor of personal data, located in Colombia, sends the information or personal data to a recipient, who in turn is the data controller and is located inside or outside the country.
Transmission: processing of personal data that implies the communication of the same within or outside the territory of the Republic of Colombia when its purpose is to carry out processing by the data processor on behalf of the data controller.
V. PRINCIPLES
To guarantee the protection of personal data, EIDEC will apply the following principles harmoniously and integrally, under which the processing, transfer, and transmission of personal data must be carried out:
Principle of legality in data Processing: Data processing is a regulated activity, which must be subject to the current and applicable legal provisions governing the matter.
Principle of purpose: the activity of personal data processing carried out by EIDEC or to which it has access will serve a legitimate purpose in line with the Political Constitution of Colombia, which must be informed to the respective data subject.
Principle of freedom: the processing of personal data can only be carried out with the prior, express, and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal, statutory, or judicial mandate that waives consent.
Principle of veracity or quality: the information subject to personal data Processing must be truthful, complete, accurate, updated, verifiable, and understandable. The processing of partial, incomplete, fragmented, or misleading data is prohibited.
Principle of transparency: In the processing of personal data, EIDEC will guarantee the Data Subject their right to obtain, at any time and without restrictions, information about the existence of any type of information or personal data that is of interest to them or of which they are the owner.
Principle of access and restricted circulation: The processing of personal data is subject to the limits derived from their nature, the provisions of the law, and the Constitution. Consequently, processing can only be carried out by persons authorized by the data subject and/or by the persons provided for in the law. Personal data, with the exception of public information, may not be available on the internet or other mass dissemination or communication media, unless access is technically controllable to provide restricted knowledge only to the data subjects or authorized third parties in accordance with the law. For these purposes, EIDEC's obligation will be a best-efforts obligation.
Principle of security: the information subject to processing by EIDEC must be handled with the technical, human, and administrative measures necessary to ensure the security of the records, preventing their alteration, loss, consultation, unauthorized or fraudulent use or access.
Principle of confidentiality: All individuals at EIDEC who administer, manage, update, or have access to any type of information contained in Databases are obliged to guarantee the confidentiality of the information, committing to preserve and maintain all information they become aware of in the execution and exercise of their duties in a strictly confidential manner and not to disclose it to third parties; except when it concerns activities expressly authorized by data protection law. This obligation persists and will be maintained even after the termination of their relationship with any of the tasks involved in the Processing.
VI. RIGHTS OF THE DATA SUBJECT
In accordance with the provisions of current applicable regulations on data protection, the following are the rights of personal data subjects:
a. Access, know, update, and rectify their personal data before EIDEC in its capacity as data controller. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented, misleading data, or data whose processing is expressly prohibited or has not been authorized. b. Request proof of the authorization granted to EIDEC for data processing, by any valid means, except in cases where authorization is not necessary3.
c. Be informed by EIDEC, upon request, regarding the use given to their personal data.
d. File complaints before the Superintendence of Industry and Commerce, or the entity that takes its place, for violations of Law 1581 of 2012 and other rules that modify, add to, or complement it, after completing the consultation or request procedure before EIDEC.
e. Revoke authorization and/or request the suppression of data when the Processing does not respect constitutional and legal principles, rights, and guarantees.
f. Access their personal data that has been subject to processing free of charge, at least once every calendar month, and each time there are substantial modifications to this policy that motivate new queries.
These rights may be exercised by:
- The data subject, who must sufficiently prove their identity by the various means made available by EIDEC.
- The data subject's beneficiaries, who must prove such status.
- The data subject's representative and/or agent, after proving representation or agency.
- Another on behalf of or for whom the data subject has stipulated.
Rights of children and adolescents
In the processing of personal data, respect for the prevailing rights of minors will be ensured.
The processing of personal data of minors is prohibited, except for data that is of a public nature, and in this case, the processing must comply with the following parameters:
3 Law 1581 of 2012. Article 10. Cases in which authorization is not necessary. The Data Subject's authorization will not be necessary when it concerns:
a) Information required by a public or administrative entity in the exercise of its legal functions or by judicial order;
b) Public data;
c) Cases of medical or sanitary emergency;
d) Processing of information authorized by law for historical, statistical, or scientific purposes;
e) Data related to the Civil Registry of Persons.
Anyone who accesses personal data without prior authorization must in any case comply with the provisions contained in this law.
a. Respond to and respect the best interests of minors
b. Ensure respect for the fundamental rights of minors.
It is the task of the State and educational entities of all kinds to provide information and train legal representatives and guardians about the potential risks that children and adolescents face regarding the improper processing of their personal data, and to provide knowledge about the responsible and safe use by children and adolescents of their personal data, their right to privacy and protection of their personal information and that of others.
VII. EIDEC'S DUTIES AS CONTROLLER AND PROCESSOR OF PERSONAL DATA
EIDEC recognizes that individuals own their personal data and, consequently, only they can decide on it. Therefore, EIDEC will use personal data to fulfill the purposes expressly authorized by the data subject or by current regulations.
In the processing and protection of personal data, EIDEC will have the following duties, without prejudice to others provided for in the provisions that regulate or may regulate this matter:
a. Guarantee the data subject, at all times, the full and effective exercise of the right of habeas data.
b. Request and keep a copy of the respective authorization granted by the data subject for the processing of personal data.
c. Duly inform the data subject about the purpose of the collection and the rights they have by virtue of the authorization granted.
d. Preserve the information under the necessary security conditions to prevent its alteration, loss, consultation, unauthorized or fraudulent use or access.
e. Guarantee that the information is truthful, complete, accurate, updated, verifiable, and understandable.
f. Update the information in a timely manner, thus addressing all new developments regarding the data subject's data. Additionally, all necessary measures must be implemented to keep the information updated.
g. Rectify the information when it is incorrect and communicate what is pertinent.
h. Respect the security and privacy conditions of the data subject's information.
i. Process queries and claims formulated in the terms indicated by law.
j. Identify when certain information is under discussion by the data subject.
k. Inform, at the data subject's request, about the use given to their data.
l. Inform the data protection authority when security code violations occur and there are risks in the administration of data subjects' information.
m. Comply with the requirements and instructions issued by the Superintendence of Industry and Commerce on the particular matter.
n. Use only data whose processing is previously authorized in accordance with the provisions of Law 1581 of 2012.
o. Ensure the appropriate use of personal data of children and adolescents, in cases where the processing of their data is authorized.
p. Register the legend "claim in process" in the database in the manner regulated by law.
q. Insert the legend "information under judicial discussion" in the database once notified by the competent authority about judicial processes related to the quality of the personal data.
r. Refrain from circulating information that is being disputed by the data subject and whose blocking has been ordered by the Superintendence of Industry and Commerce.
s. Allow access to information only to persons who can have access to it.
t. Use the data subject's personal data only for those purposes for which it is duly authorized and always respecting the current regulations on personal data protection.
VIII. AUTHORIZATION AND CONSENT OF THE DATA SUBJECT
EIDEC requires the free, prior, express, and informed consent of the personal data subject for its processing, except in cases expressly authorized by law, namely:
a. Information required by a public or administrative entity in the exercise of its legal functions or by judicial order.
b. Public data.
c. Cases of medical or sanitary emergency.
d. Processing of information authorized by law for historical, statistical, or scientific purposes.
e. Data related to the Civil Registry of Persons. Manifestation of Authorization.
Authorization to EIDEC for the processing of personal data will be granted by:
- The data subject, who must sufficiently prove their identity by the various means made
- available by EIDEC.
- The data subject's beneficiaries, who must prove such status.
- The data subject's representative and/or agent, after proving representation or
- agency.
- Another on behalf of or for whom the data subject has stipulated.
Means for granting authorization
EIDEC will obtain authorization through different means, including physical document, electronic document, data message, Internet, Websites, or any other format that in any case allows obtaining consent through unequivocal conduct from which it is concluded that if it had not been granted by the data subject or the person legitimate to do so, the data would not have been stored or captured in the database.
Authorization will be requested by EIDEC prior to the processing of personal data.
Proof of authorization EIDEC
will keep proof of the authorization granted by the personal data subjects for its processing, for which it will use the mechanisms currently available to it and will also adopt the necessary actions to maintain a record of the form and date on which it obtained it. Consequently, EIDEC may establish physical files or electronic repositories created directly or through third parties contracted for this purpose.
Revocation of authorization.
Data subjects may at any time revoke the authorization granted to EIDEC for the processing of their personal data or request their deletion, provided that no legal or contractual provision prevents it. EIDEC will establish simple and free mechanisms that allow the data subject to revoke their authorization or request the deletion of their personal data, at least by the same means by which it was granted.
For the foregoing, it should be noted that the revocation of consent can be expressed, on the one hand, completely in relation to the authorized purposes, and therefore EIDEC must cease any data processing activity; and on the other hand, partially in relation to certain types of processing, in which case these will be the ones over which processing activities will cease, such as for advertising purposes, among others. In this latter case, EIDEC may continue to process personal data for those purposes for which the data subject has not revoked their consent.
IX. DATA PROCESSING AND ITS PURPOSE
EIDEC will process the personal data of students, applicants, graduates, alumni, professors, employees, former employees, retirees, suppliers, contractors, or any person with whom EIDEC has or establishes a permanent or occasional relationship, within the legal framework that regulates the matter and by virtue of its status as a Higher Education Institution, and all processing will be necessary for the fulfillment of its institutional mission.
In any case, personal data may be collected and processed for:
a. Sending information related to programs, activities, news, content by area of interest, products and other goods or services offered by EIDEC.
b. Developing EIDEC's mission in accordance with its statutes.
c. Complying with current regulations in Colombia for Higher Education Institutions, including, but not limited to, any requirement from the Ministry of National Education, accrediting entities, or local authorities.
d. Complying with applicable regulations for suppliers and contractors, including, but not limited to, tax and commercial regulations.
e. Complying with the provisions of Colombian legal regulations regarding labor and social security, among others, applicable to former employees, current employees, and candidates for future employment.
f. Conducting surveys related to EIDEC's services or goods.
g. Developing programs in accordance with its statutes.
h. Keeping alumni in contact with professions or interests related to theirs.
i. Informing about job opportunities, fairs, seminars, or other studies at local and international levels.
j. Promoting research in all fields, including scientific.
k. Fulfilling all its contractual commitments.
For the processing of personal data of children and adolescents, the procedure will be in accordance with the provisions of this policy in the section related to their rights.
Sensitive data
In the case of sensitive personal data, EIDEC may use and process them when:
a. The data subject has given their explicit authorization, except in cases where the law does not require such authorization.
b. Processing is necessary to safeguard the vital interest of the Data Subject and the Data Subject is physically or legally incapacitated. In these events, legal representatives must grant their authorization.
c. Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association, or any other non-profit organization whose purpose is political, philosophical, religious, or trade union, provided that they refer exclusively to its members or to persons who maintain regular contact by reason of their purpose. In these events, the data may not be provided to third parties without the authorization of the data subject.
d. The processing refers to data that is necessary for the recognition, exercise, or defense of a right in a judicial process.
e. The processing has a historical, statistical, or scientific purpose. In this event, measures conducive to the suppression of the identity of the data subjects must be adopted.
Notwithstanding the exceptions provided by law, the processing of sensitive data requires the prior, express, and informed authorization of the data subject, which must be obtained by any means that can be subject to subsequent consultation and verification.
X. PRIVACY NOTICE
The Privacy Notice is the physical, electronic, or any other format document made available to the data subject to inform them about the processing of their personal data. Through this document, the data subject is informed about the existence of EIDEC's information processing policies that will be applicable to them, how to access them, and the characteristics of the intended personal data processing.
The privacy notice must contain, at a minimum, the following information:
a. The identity, address, and contact details of the data controller.
b. The type of processing to which the data will be subjected and its purpose.
c. The data subject's rights.
d. The general mechanisms provided by the data controller for the data subject to be aware of the information processing policy and any substantial changes that occur therein. In all cases, the data subject must be informed how to access or consult the information processing policy.
e. The optional nature of the answer to questions about sensitive data.
XI. GUARANTEES OF THE RIGHT OF ACCESS
To guarantee the data subject's right of access, EIDEC will make the respective personal data available to them, after accreditation of their identity, legitimacy, or the personality of their representative, free of charge or expense, in a detailed and specific manner, through all types of means, including electronic means that allow the data subject direct access to them. Such access must be offered without any limit and must allow the data subject to know and update them online.
XII. PROCEDURE FOR ATTENDING TO QUERIES, COMPLAINTS, REQUESTS FOR RECTIFICATION, UPDATE, AND DELETION OF DATA
a. Queries:
Data subjects or their successors in title may consult their personal information held by EIDEC, which will provide all information contained in the individual record or linked to the identification of the Data Subject.
With regard to attending to personal data consultation requests, EIDEC guarantees:
- Enabling electronic communication means or others deemed relevant.
- Establishing simplified forms, systems, and other methods, which must be
- informed in the privacy notice.
- Using the customer service or complaint services it has in operation.
- In any case, regardless of the mechanism implemented for attending to consultation requests, they will be addressed within a maximum period of ten (10) business days from the date of receipt. When it is not possible to attend to the query within said period, the interested party will be informed before the expiration of the 10 days, stating the reasons for the delay and indicating the date on which their query will be attended, which in no case may exceed five (5) business days following the expiration of the first period.
Queries can be sent to direccion@eidec.com.co
b. Complaints
The Data Subject or their successors in title who consider that the information contained in a database should be subject to correction, updating, or deletion, or when they notice the alleged breach of any of the duties contained in the law, may file a complaint with EIDEC, which will be processed under the following rules:
1. The Data Subject's complaint will be submitted by request addressed to EIDEC at the email address direccion@eidec.com.co or by written communication addressed to the Institutional Marketing department, with the identification of the data subject, the description of the facts giving rise to the complaint, the address, and enclosing the documents that are intended to be asserted. If the complaint is incomplete, the interested party will be required within five (5) days following receipt of the complaint to remedy the flaws. After two (2) months from the date of the request, if the applicant does not submit the required information, it will be understood that they have withdrawn the complaint.
In the event that the person receiving the complaint is not competent to resolve it, they will transfer it to the appropriate party within a maximum period of two (2) business days and inform the interested party of the situation.
2. Once the complete complaint is received, it will be categorized with the label "complaint in process" and the reason for it, within a maximum of two (2) business days. This label will be maintained until the complaint is resolved.
3. The maximum period to address the complaint will be fifteen (15) business days from the day following the date of its receipt. When it is not possible to address the complaint within said period, the interested party will be informed of the reasons for the delay and the date on which their complaint will be addressed, which in no case may exceed eight (8) business days following the expiration of the first period.
c. Request for update and/or rectification
EIDEC will rectify and update, at the request of the data subject, the information of the data subject that proves to be incomplete or inaccurate, in accordance with the procedure and terms indicated above, for which the following will be taken into account:
1. The data subject must send the request to the email direccion@eidec.com.co or in physical form addressed to the Institutional Marketing department, indicating the update and/or rectification to be made and providing the documentation that supports their request.
2. EIDEC may enable mechanisms that facilitate the exercise of this right for the data subject, provided that these benefit them. Consequently, electronic means or others deemed relevant may be enabled, which will be informed in the privacy notice and will be made available to interested parties on the website.
d. Request for data deletion
The data subject has the right to request EIDEC to delete their personal data in any of the following events:
1. They consider that they are not being processed in accordance with the principles, duties, and obligations provided in current regulations.
2. They are no longer necessary or relevant for the purpose for which they were collected.
3. The period necessary for the fulfillment of the purposes for which they were collected has been exceeded.
This deletion implies the total or partial elimination of personal information according to what is requested by the data subject in the records, files, databases, or processing carried out by EIDEC. However, this right of the data subject is not absolute and consequently EIDEC may deny the exercise of it when:
a. The data subject has a legal or contractual duty to remain in the database.
b. The deletion of data hinders judicial or administrative actions linked to tax obligations, the investigation and prosecution of crimes, or the updating of administrative sanctions.
c. The data are necessary to protect the legally protected interests of the data subject; to carry out an action in the public interest; or to comply with a legally acquired obligation by the data subject.
XIII. NATIONAL DATABASE REGISTRY
EIDEC reserves, in the events contemplated by law and its internal statutes and regulations, the right to maintain and categorize certain information held in its databases or data banks as confidential in accordance with current regulations, its statutes, and regulations, all of the foregoing.
EIDEC will proceed in accordance with current regulations and the regulations issued by the National Government for this purpose, to register its databases with the National Database Registry (RNBD), which will be administered by the Superintendency of Industry and Commerce. The RNBD is the public directory of databases subject to Processing that operate in the country; and it will be freely accessible to citizens, in accordance with the regulations issued by the National Government for this purpose.
XIV. INFORMATION SECURITY AND SECURITY MEASURES
In compliance with the principle of security established in current regulations, EIDEC will adopt the technical, human, and administrative measures necessary to ensure the security of records, preventing their alteration, loss, consultation, unauthorized use, or fraudulent access.
XV. INTERNATIONAL USE AND TRANSFER OF PERSONAL DATA AND PERSONAL INFORMATION BY EIDEC
In fulfillment of its institutional mission and EIDEC's strategic development plan, and considering the nature of the permanent or occasional relationships that any personal data subject may have with EIDEC, the latter may carry out the transfer and transmission, including international, of all personal data, provided that the applicable legal requirements are met; and consequently, by accepting this policy, data subjects expressly authorize the transfer and transmission, even internationally, of personal data. The data will be transferred for all relationships that may be established with EIDEC.
For the international transfer of personal data of the data subjects, EIDEC will take the necessary measures to ensure that third parties are aware of and commit to observing this policy, with the understanding that the personal information they receive may only be used for matters directly related to EIDEC and only for its duration, and may not be used or intended for any different purpose. For the international transfer of personal data, the provisions of Article 26 of Law 1581 of 2012 will be observed.
International transmissions of personal data carried out by EIDEC will not require informing the data subject or obtaining their consent when there is a personal data transmission contract in accordance with Article 25 of Decree 1377 of 2013.
EIDEC may also exchange personal information with governmental or other public authorities (including, but not limited to, judicial or administrative authorities, tax authorities, and criminal, civil, administrative, disciplinary, and fiscal investigation bodies), and third parties involved in civil legal proceedings and their accountants, auditors, lawyers, and other advisors and representatives, because it is necessary or appropriate: (a) to comply with applicable laws, including laws other than those of your country of residence; (b) to comply with legal processes; (c) to respond to requests from public and government authorities, and to respond to requests from public and government authorities other than those of your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations; (f) to protect our rights, privacy, security, or property, yours or that of third parties; and (g) to obtain applicable indemnities or limit damages that may affect us.
XVI. DATA CONTROLLER AND PROCESSOR OF PERSONAL DATA
EIDEC will be the data controller for personal data.
The Marketing department will be the data processor for personal data, on behalf of EIDEC.
XVII. EFFECTIVE DATE
This policy is effective as of September 2, 2021, and supersedes any special regulations or manuals that may have been adopted by academic and/or administrative bodies at EIDEC.
