Privacy Policy and Personal Data Processing Notice

Last updated: 2026-06-15 — tentative draft

This is a tentative draft drafted under Colombian Law 1581 of 2012 and Decree 1377 of 2013. Pending legal review and completion of corporate identification data for the Data Controller (legal name, tax ID, registered address) before final publication. To exercise rights or report incidents during this phase write us at info@saiacore.com.

This Policy describes how SAIA CORE collects, uses, stores, shares, and protects the personal data processed through the platform. It applies to all users of the Service and is governed by the Political Constitution of Colombia, Law 1581 of 2012, Decree 1377 of 2013, and related regulations.

1. Identification of the Data Controller

SAIA CORE, with registered office in Colombia and email info@saiacore.com, is the Data Controller of the personal data collected through the platform. For formal requests relating to personal data, exercise of rights, or incident reports, the official channel is info@saiacore.com.

2. Personal Data We Process

We collect the following types of data:

(a) Identification data: full name, email address, ID number when provided.

(b) Organization data: legal name, sector, team size, tax ID where applicable.

(c) Technical data: IP address, browser type, operating system, access and activity logs.

(d) Usage data: pages visited, actions taken within the Service, dates and times of activity, preference settings.

(e) Uploaded content: documents, forms, templates, workflow data, electronic signatures. This content belongs to the Customer; SAIA acts as Data Processor.

(f) Payment data: processed directly by Wompi (Bancolombia S.A.). SAIA does not store full credit card numbers or CVV codes.

3. Purposes of Processing

We process your personal data for the following purposes:

(a) To create, manage, and maintain your account and your organization's account.

(b) To deliver the contracted Service and all of its functionality.

(c) To process payments, issue invoices, and meet tax obligations.

(d) To provide technical support and respond to inquiries or requests.

(e) To send necessary operational communications (renewals, trial-end reminders, security notifications, changes to the Terms).

(f) To comply with legal, accounting, regulatory, or judicial obligations applicable to SAIA.

(g) To improve the Service, develop new functionality, and produce aggregated, anonymized statistical analysis.

(h) To prevent, detect, and investigate fraud, misuse of the Service, or breaches of these Terms.

Marketing or promotional communications are sent only with your prior, express, and informed consent, which you may withdraw at any time from the panel or by writing to info@saiacore.com.

4. Legal Basis for Processing

The processing of your personal data is based on: (a) your prior, express, and informed consent, given when creating the account and accepting this Policy; (b) performance of the Service contract; (c) compliance with legal obligations applicable to SAIA; (d) SAIA's legitimate interests in maintaining Service security, preventing fraud, and improving user experience, balanced against your rights. Where processing relies solely on consent, you may withdraw it at any time.

5. Sharing Data with Third Parties

SAIA does not sell, rent, or commercially transfer your personal data. We share only strictly necessary information with processors that handle data on our behalf, under confidentiality agreements and in accordance with applicable regulation:

(a) Wompi (Bancolombia S.A.) — electronic payment processing.

(b) Google Drive (Google LLC) and OneDrive (Microsoft Corp.) — file storage integration when the user activates that feature. Connection is made via OAuth and files remain in the user's account.

(c) Transactional email provider (e.g. Resend) — delivery of operational notifications.

(d) Cloud infrastructure providers hosting the platform and its databases.

(e) Legal, accounting, or audit advisors when necessary and under a duty of confidentiality.

We may share data with competent authorities upon court order, legitimate administrative request, or where required by law.

6. International Data Transfers

Some of our providers process data outside Colombia, primarily in the United States and the European Union (for example, cloud infrastructure and Google or Microsoft services). These international transfers are made under standard contractual clauses, recognized adequacy mechanisms, or your express consent, in accordance with Article 26 of Law 1581 of 2012.

7. Data Retention

We retain your personal data for the duration of your subscription and for thirty (30) days after termination to allow data export. Data related to billing, accounting, and tax obligations is retained for the legally required period in Colombia (typically ten years). Audit records associated with electronic signatures are retained for the probative validity period of each signed document.

8. Data Subject Rights

As a data subject you have the right to:

(a) Know, update, rectify, and delete your personal data.

(b) Request proof of the consent granted, except where consent is not required by law.

(c) Be informed about the use given to your personal data.

(d) File complaints with the Superintendencia de Industria y Comercio for infringements of data protection regulation.

(e) Revoke the consent granted and/or request deletion of your data where no legal or contractual obligation to retain it exists.

(f) Access your personal data processed by SAIA free of charge.

9. How to Exercise Your Rights

To exercise any of the rights above, send a request to info@saiacore.com including: (a) full name of the data subject; (b) a precise description of the right being exercised and the facts giving rise to the request; (c) contact information for our response; (d) supporting documents where applicable. We will respond within a maximum of fifteen (15) business days, extendable for up to eight (8) additional business days where case complexity warrants, in accordance with Article 14 of Law 1581 of 2012.

10. Data Security

SAIA applies reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or accidental destruction: TLS encryption in transit, encryption of sensitive data at rest, role-based access control, logical tenant segmentation, audit logging of critical operations, periodic backups, and security reviews. No online system is absolutely secure; in the event of an incident affecting personal data, SAIA will notify the data subjects and the Superintendencia de Industria y Comercio in accordance with applicable regulation.

11. Cookies and Similar Technologies

We use cookies strictly necessary for Service operation (session management, language preference, CSRF security) and, optionally, anonymized analytics cookies to understand aggregate website use and improve the experience. We do not use third-party advertising cookies and do not sell information to ad networks. You can manage cookies from your browser settings; disabling necessary cookies may affect Service functionality.

12. Changes to this Policy

SAIA may update this Policy to reflect legal, technical, or operational changes. Versions are identified by the last-updated date shown at the top of the document. Material changes will be notified with thirty (30) days prior notice via email and/or prominent notice inside the Service. Continued use of the Service after the effective date constitutes acceptance of the then-current version.

13. Contact

For questions, requests to exercise rights, incident reports, or any communication relating to this Policy, write us at info@saiacore.com.