1. ABOUT US (DATA CONTROLLER)
| Legal name | Code Labs S.A.S. |
| Tax ID (NIT) | 900.209.980-7 |
| Registered office and address | Calle 93 # 5-50, Apt. 704, Bogotá D.C., Colombia |
| Email for personal data matters | info@code-labs.com |
| Request form | https://www.code-labs.com/contact |
| Telephone | +57 320 962 8797 |
| Website | https://www.code-labs.com |
Code Labs S.A.S. is a Colombian technology company that provides custom software development, SaaS services, infrastructure and managed cloud services, ICT consulting, information assurance and security, process automation consulting, web and mobile development, UX/UI design, conversational solutions (chatbots), and digital marketing services.
2. SCOPE AND LANGUAGE
This Policy applies to all personal data Processing carried out by Code Labs as Data Controller, including data relating to website visitors, prospects, clients and their contacts, employees, job applicants, suppliers, and contractors.
Personal data Processing carried out by Code Labs as Data Processor on behalf of its clients is governed by the applicable client privacy policy, where the client acts as Data Controller, and by the agreement entered into between the parties. Section 11 describes the obligations assumed by Code Labs in that capacity.
Language. This Policy is issued in Spanish. Any translation into another language is provided solely for convenience of reference. In the event of any discrepancy between versions, the Spanish version shall prevail and shall be the only binding version.
3. LEGAL FRAMEWORK
This Policy is issued in accordance with:
- Articles 15 and 20 of the Political Constitution of Colombia.
- Statutory Law 1581 of 2012.
- Decree 1074 of 2015, which compiles Decree 1377 of 2013 and related regulations.
- Law 2300 of 2023, regarding commercial and debt collection communications.
- External Circular 005 of 2017 issued by the Superintendence of Industry and Commerce (SIC), regarding international data transfers.
- Resolution 2346 of 2007 issued by the Ministry of Social Protection, regarding occupational medical evaluations.
- Any other rules that amend, supplement, or replace the foregoing.
4. DEFINITIONS
- Personal Data: any information linked to or capable of being associated with an identified or identifiable natural person.
- Data Subject: the natural person whose personal data is subject to Processing.
- Processing: any operation performed on personal data, such as collection, storage, use, circulation, or deletion.
- Data Controller: the party that decides on the database and the Processing of personal data.
- Data Processor: the party that Processes personal data on behalf of the Data Controller.
- Subprocessor: a third party engaged by a Data Processor to perform all or part of the Processing entrusted to it.
- Authorization: the Data Subject’s prior, express, and informed consent.
- Privacy Notice: a verbal or written communication provided to the Data Subject at the time of collection, informing them of the existence of this Policy, how to access it, and the purposes of the Processing.
- Sensitive Data: data affecting the Data Subject’s privacy or whose improper use may lead to discrimination, such as health data, biometric data, racial or ethnic origin, political orientation, religious or philosophical beliefs, and membership in trade unions or social organizations.
- Transfer: disclosure of personal data to a Data Controller located inside or outside Colombia.
- Transmission: disclosure of personal data to a Data Processor, inside or outside Colombia, so that it may Process such data on behalf of the Data Controller.
- Anonymization: an irreversible process through which data can no longer be used to identify the Data Subject.
- Security Incident: an event that compromises the confidentiality, integrity, or availability of personal data.
5. PRINCIPLES
Code Labs Processes personal data in accordance with the principles of legality, purpose limitation, freedom, truthfulness or quality, transparency, restricted access and circulation, security, and confidentiality.
6. PERSONAL DATA WE PROCESS
| Data Subjects | Data | How We Obtain It |
|---|---|---|
| Website visitors and prospects | Name, email address, telephone number, company, job title, and message content | Contact forms, email, and calls |
| Clients and their contacts | Name, identity document, email, telephone number, job title, and billing information | Agreements, proposals, and communications |
| Employees and job applicants | Identification and contact information, résumé/CV, education, experience, references, verification results where applicable (Section 7), social security enrollment information, banking details, and occupational fitness assessment | Recruitment processes and employment relationship |
| Employee beneficiaries and dependents | Name, document number, relationship, and date of birth | Social security enrollment and benefits |
| Suppliers and contractors | Identification, contact, tax, and banking information | Contracting processes |
| Website users | IP address, browser, device, and browsing data | Cookies and similar technologies (Section 14) |
| Users of conversational solutions | Identification and contact information, and conversation content | Chatbots operated by Code Labs through its own channels |
| Visitors to our facilities | Name, document number, and entry record | Facility access control |
Personal data contained in platforms that Code Labs develops, hosts, or supports for its clients is not Processed under this section. In those cases, Code Labs acts as Data Processor in accordance with Section 11.
7. PURPOSES OF PROCESSING
Code Labs Processes personal data solely for the following purposes.
PROSPECTS AND CLIENTS
- Respond to requests and prepare and send proposals.
- Enter into and perform agreements, provide contracted services, and provide support.
- Issue invoices, manage collections, and comply with tax and accounting obligations.
- Send information about our services only when authorized by the Data Subject and through the channels selected by the Data Subject. The Data Subject may withdraw such authorization at any time.
EMPLOYEES AND JOB APPLICANTS
- Conduct recruitment processes, including verification of employment and academic references.
- Conduct background checks only when required by law, by the nature of the position, or by an express contractual requirement of a client. In such cases, Code Labs informs the applicant in advance of the source to be consulted and retains only the verification result, not the underlying supporting documentation.
- Manage the employment relationship, including payroll, social security, the Occupational Health and Safety Management System (SG-SST), training, and access to company tools.
- Comply with legal obligations and security requirements agreed with our clients.
- Retain résumés/CVs of unsuccessful applicants in a talent pool only with the Data Subject’s separate and express authorization.
EMPLOYEE BENEFICIARIES AND DEPENDENTS
- Manage social security enrollment and benefits arising from the employment relationship, in compliance with legal obligations.
SUPPLIERS AND CONTRACTORS
- Select and evaluate suppliers, enter into agreements, make payments, and comply with tax obligations.
WEBSITE USERS AND USERS OF CONVERSATIONAL SOLUTIONS
- Operate, secure, and improve the website and conversational channels.
- Prevent fraud and unauthorized access.
- Respond to requests submitted through conversational channels.
ALL DATA SUBJECTS
- Comply with legal obligations and requests from competent authorities.
- Exercise and defend Code Labs’ rights in judicial or administrative proceedings.
Code Labs will not use personal data for purposes incompatible with those communicated to the Data Subject. Where a new purpose requires authorization under applicable law, Code Labs will obtain such authorization in advance, in accordance with Section 23.
8. SENSITIVE DATA
Code Labs Processes sensitive data only where strictly necessary and where a valid legal basis exists. Where authorization is required by law, it shall be prior, express, and informed.
Within the employment relationship, the sensitive data Processed includes:
- The occupational fitness assessment issued by the occupational physician (fit, fit with restrictions, or unfit).
- Records required under the Occupational Health and Safety Management System pursuant to applicable regulations.
The occupational medical record is confidential and remains under the custody of the specialist physician or healthcare institution conducting the evaluation. Code Labs does not access or retain such medical records, in accordance with Resolution 2346 of 2007.
The Data Subject is not required to authorize the Processing of sensitive data or to answer questions relating to such data, unless an applicable legal obligation exists. Code Labs will not condition an activity, service, recruitment process, or benefit on the provision of sensitive data when such data is not necessary for the stated purpose or legally required.
9. DATA OF CHILDREN AND ADOLESCENTS
Code Labs does not collect personal data from children or adolescents through its website or commercial channels.
Processing of minors’ data is mainly limited to information relating to employee beneficiaries and dependents that is necessary to manage legal obligations, social security matters, and benefits arising from the employment relationship.
Whenever Code Labs Processes personal data of children or adolescents, Code Labs:
- Applies necessity and data minimization criteria, collecting only the data required for the stated purpose or by law.
- Gives priority to the best interests of the minor and ensures respect for their fundamental rights.
- Obtains authorization from the legal representative where applicable and, where appropriate, takes into account the minor’s right to be heard according to their maturity, autonomy, and ability to understand the matter.
- Applies enhanced security and confidentiality measures to such information.
10. AUTHORIZATION AND PRIVACY NOTICE
Authorization. Where required, Code Labs obtains the Data Subject’s prior, express, and informed authorization before Processing personal data. Authorization may be granted in writing, verbally, through electronic mechanisms, or by other unequivocal conduct that reasonably demonstrates the Data Subject’s intent. Digital forms and channels should use explicit acceptance mechanisms whenever possible, and Code Labs will retain evidence of such authorization. Silence shall never be deemed authorization.
Code Labs retains evidence of each authorization granted and of the version of the Policy in effect at the time the authorization was provided.
Authorization is not required in the cases provided for under Article 10 of Law 1581 of 2012, including information requested by a public authority in the exercise of its legal functions, publicly available data, medical or health emergencies, Processing authorized by law for historical, statistical, or scientific purposes, and data relating to the Civil Registry of Persons.
Privacy Notice. Where this Policy cannot be made available to the Data Subject at the time of collection, Code Labs will provide a Privacy Notice that includes, at a minimum, the identity and contact details of the Data Controller, the Processing to which the data will be subject and its purpose, the rights available to the Data Subject, and the mechanisms for accessing this Policy. Where sensitive data is requested, the Privacy Notice will expressly state that responding is optional.
Code Labs displays the Privacy Notice through its web forms, conversational channels, recruitment processes, and commercial telephone contacts.
11. CODE LABS AS DATA PROCESSOR
When Code Labs develops, hosts, manages, or supports platforms, infrastructure, or services for its clients, it Processes the personal data contained in them as Data Processor, on behalf of the client, which acts as Data Controller.
In that capacity, Code Labs:
- Processes personal data exclusively in accordance with the client’s documented instructions and for the purposes of the contracted service, unless an applicable legal provision requires different Processing.
- Enters into a personal data transmission agreement with each client in accordance with Article 2.2.2.25.5.2 of Decree 1074 of 2015, defining the scope and purpose of the Processing, authorized activities, and security and confidentiality obligations.
- Applies the security measures agreed with the client and, at a minimum, those described in Section 15.
- Maintains the confidentiality of the information and does not use it for any of its own purposes, subject to Section 12.
- Engages subprocessors only with the client’s authorization, imposes on them the same obligations assumed toward the client, maintains an updated list of such subprocessors available to the client, and provides prior notice of any change no less than 30 days in advance so the client may object.
- Notifies the client of any security incident affecting such data in accordance with Section 16.
- Forwards to the client, within two (2) business days of receipt, any inquiry or complaint from Data Subjects relating to such platforms, assists the client in responding, and informs the Data Subject of the referral.
- Returns or deletes personal data upon termination of the agreement according to the client’s instructions and provides written certification of deletion upon the client’s request.
- Allows the client to audit compliance with these obligations, directly or through an independent third party, with reasonable prior notice and without compromising the confidentiality of other clients.
- Informs the client when personnel assigned to the service access the data from outside Colombia and treats such access as an international data transmission subject to Section 13.
12. USE OF ARTIFICIAL INTELLIGENCE TOOLS
Code Labs does not use personal data from production environments, whether its own or those of its clients, to train general-purpose artificial intelligence models, whether proprietary or third-party, unless there is a valid legal basis, authorization where applicable, and previously approved contractual, technical, and security controls.
Code Labs may use AI-assisted development tools with source code, technical documentation, and synthetic or properly anonymized data as part of its working methodology, always subject to internal security and confidentiality controls.
Code Labs personnel are prohibited from entering personal data, credentials, secrets, confidential information, or information from production environments, whether Code Labs’ own or clients’, into artificial intelligence tools that have not been previously approved by Code Labs and made subject to appropriate contractual and technical requirements concerning confidentiality, security, and use of information.
In development, testing, and quality assurance environments, Code Labs uses synthetic or anonymized data. Use of copies of production data in such environments requires the client’s prior express authorization and the application of masking techniques.
13. DATA TRANSMISSIONS, LEGAL OBLIGATIONS, AND INTERNATIONAL TRANSFERS
Code Labs does not sell, lease, or commercialize personal data.
13.1 TRANSMISSIONS TO DATA PROCESSORS
Code Labs relies on technology providers that Process personal data on its behalf and under its instructions in the following categories: cloud hosting and infrastructure, email and collaboration, conversational platforms, development tools, and commercial management tools.
Code Labs enters into a personal data transmission agreement with each such provider in accordance with Article 2.2.2.25.5.2 of Decree 1074 of 2015, defining the scope and purpose of the Processing, authorized activities, and the Data Processor’s security and confidentiality obligations.
An updated list of providers, including their hosting country and purpose, is available to Data Subjects and clients upon request through the channel indicated in Section 19.
Some technology providers may store or Process information outside Colombia. Where this occurs, Code Labs applies the legal mechanisms required under Colombian law for international personal data transmissions and establishes the applicable contractual obligations concerning security, confidentiality, purpose limitation, and restricted use. Where an operation constitutes an international transfer, Code Labs applies the rules and exceptions established under applicable regulations.
13.2 DISCLOSURES REQUIRED BY LAW
Code Labs discloses personal data to administrative, judicial, or regulatory authorities where required by law or by an order issued in the exercise of their legal authority. Such disclosures do not require the Data Subject’s authorization, in accordance with Article 10(b) of Law 1581 of 2012.
13.3 TRANSFER IN CONNECTION WITH CORPORATE REORGANIZATION
In the event of a merger, spin-off, acquisition, assignment, or sale of the business, personal data may be transferred to the acquirer or successor, which will assume the role of Data Controller and will be required to comply with this Policy and the authorized purposes.
Code Labs will inform Data Subjects in advance through its usual communication channels, and Data Subjects may exercise their rights, including withdrawal of authorization and deletion of personal data, before the transfer becomes effective.
13.4 AGGREGATED OR ANONYMIZED INFORMATION
Code Labs may use aggregated or anonymized information that does not identify any individual for statistical purposes and to improve its services. Such information does not constitute personal data.
14. COOKIES AND SIMILAR TECHNOLOGIES
The Code Labs website uses cookies and similar technologies. We classify them as follows:
| Type | Purpose | Consent Required |
|---|---|---|
| Technical or necessary | Enable website functionality, maintain sessions, and protect security | No |
| Analytics | Understand how the website is used and improve it | Yes, prior and express |
| Marketing | Measure campaigns and display relevant content | Yes, prior and express |
Upon first access, the website displays a banner allowing users to accept, reject, or configure by category non-essential cookies. No analytics or marketing cookies are installed before consent is obtained. The Data Subject may change their selection at any time through https://www.code-labs.com/.
Details of each cookie—including name, provider, purpose, and duration—are available at https://www.code-labs.com/.
The website records technical data such as IP addresses, used solely for security and statistical purposes. The Data Subject may also block or delete cookies through browser settings; some website functions may no longer operate correctly as a result.
15. SECURITY MEASURES
Code Labs applies technical, organizational, and administrative measures to protect personal data against loss, unauthorized access, alteration, or misuse. These include:
- Access restricted to authorized personnel under the principle of least privilege, with multi-factor authentication.
- Access lifecycle management covering onboarding, role changes, and personnel offboarding.
- Encryption of information in transit and at rest, with controlled key management.
- Segregation of production and non-production environments.
- Vulnerability management and timely application of patches.
- Secure development practices and code review.
- Backups and periodic restoration testing.
- Activity logging and monitoring in cloud environments.
- A documented incident response plan.
- Confidentiality and data protection obligations in personnel agreements, as well as periodic training on these matters.
16. SECURITY INCIDENTS
Code Labs maintains a documented procedure for managing security incidents involving personal data. In the event of an incident affecting the confidentiality, integrity, or availability of personal data, Code Labs contains and documents the incident and assesses its impact on Data Subjects.
As Data Controller. Code Labs reports security incidents to the Superintendence of Industry and Commerce within fifteen (15) business days after the incident is detected and brought to the attention of the person or area responsible for handling it, through the mechanisms enabled by that authority. Where appropriate, Code Labs will inform affected Data Subjects of the nature of the incident, its possible consequences, and the measures adopted.
As Data Processor. Code Labs informs the client without undue delay and within the applicable contractual period, provides the available information necessary to manage the incident, and assists the Data Controller in complying with its obligations. Where Code Labs is required to submit a report to the Superintendence of Industry and Commerce in its capacity as Data Processor, it will do so within the applicable statutory period and through the mechanism established for that purpose.
17. DATA RETENTION AND DELETION
Code Labs retains personal data only for as long as necessary to fulfill the purposes communicated to the Data Subject and to comply with applicable legal, accounting, tax, employment, contractual, and legal defense obligations. Specific retention periods are defined based on necessity, proportionality, and Code Labs’ internal information retention schedule. As a general reference:
| Category | Retention Period |
|---|---|
| Prospects with no contractual relationship | 2 years from the last contact |
| Clients and suppliers | Term of the agreement plus 10 years, in accordance with applicable commercial, accounting, and tax periods |
| Employees | Duration of the employment relationship plus the limitation period for employment claims and the applicable employment record retention period |
| Beneficiaries and dependents | For as long as the enrollment arising from the employment relationship remains in effect, plus the applicable legal retention period |
| Unsuccessful job applicants | 6 months; up to 2 years where the Data Subject has expressly authorized inclusion in the talent pool |
| Conversations through Code Labs’ own conversational channels | 12 months |
| Website technical records (logs) | 6 to 12 months |
| Facility access records | 3 months |
Once the applicable period expires, the data is securely deleted or irreversibly anonymized.
Personal data Processed by Code Labs as Data Processor is retained for the term of the client agreement and is returned or deleted upon termination in accordance with the client’s instructions.
18. DATA SUBJECT RIGHTS
The Data Subject has the right to:
- Know, update, and rectify their personal data held by Code Labs.
- Request evidence of the authorization granted, except where authorization is not required by law.
- Be informed, upon request, of the use made of their personal data.
- File complaints with the Superintendence of Industry and Commerce for violations of applicable data protection regulations, after first completing the inquiry or complaint procedure before Code Labs.
- Withdraw authorization or request deletion of personal data where there is no legal or contractual duty requiring retention, or where the Superintendence determines that the Processing has involved conduct contrary to law.
- Access their personal data free of charge.
- Request a copy of their data in a structured and commonly used format where Processing is automated and technically feasible.
- Object to the Processing of their personal data for direct marketing purposes at any time and without having to provide justification.
- Request human intervention in decisions made exclusively through automated Processing that produce legal effects concerning them or significantly affect them, as well as receive information about the general logic of such decisions and challenge them.
Additionally, as a privacy best practice, Code Labs voluntarily recognizes the mechanisms set forth in items 7, 8, and 9, without prejudice to the rights expressly established under current Colombian law.
Code Labs does not make automated decisions that produce legal effects concerning Data Subjects.
19. HOW TO EXERCISE YOUR RIGHTS
Channel. Email info@code-labs.com with the subject line "Personal Data Request," or use the form available at https://www.code-labs.com/contact. Requests may also be submitted by physical mail to the address listed in Section 1. Each request receives an acknowledgment of receipt with a reference number and date.
Who may submit a request. The Data Subject, upon verification of identity; their successors, upon proof of such status; their legal representative or attorney-in-fact; or a third party authorized by the Data Subject or by law.
Inquiries (to learn what data is held in our databases and how it has been used):
- Inquiries are answered within a maximum period of ten (10) business days from the date of receipt.
- If it is not possible to answer within that period, Code Labs will inform the interested party of the reasons and the expected response date, which shall not exceed five (5) additional business days after the initial period expires.
- Inquiries are free of charge. Information may be provided through any consultation mechanism, at least once per calendar month and whenever substantial changes to this Policy give rise to new inquiries.
Complaints (correction, update, deletion, withdrawal of authorization, or alleged non-compliance with applicable regulations):
- The complaint must include the Data Subject’s identification, a description of the facts giving rise to the complaint, a contact address, and any supporting documents.
- If the complaint is incomplete, Code Labs will request completion within five (5) business days of receipt. If the required information is not provided within two (2) months, the complaint will be deemed withdrawn.
- Within two (2) business days after receipt of a complete complaint, Code Labs will include the notation "complaint in process" and the reason in the relevant database until the complaint is resolved.
- The complaint will be answered within a maximum of fifteen (15) business days starting on the day after receipt. If it is not possible to answer within that period, Code Labs will inform the interested party of the reasons and the expected response date, which shall not exceed eight (8) additional business days after the initial period expires.
Lack of authority. If Code Labs is not competent to resolve the inquiry or complaint, it will inform the interested party within two (2) business days of receipt and indicate the party to whom the request should be directed.
Requests concerning client platforms. Where a request relates to personal data that Code Labs Processes as Data Processor on behalf of a client, Code Labs will forward the request to the client, as Data Controller, within two (2) business days of receipt, assist with the response, and inform the Data Subject accordingly.
Procedural prerequisite. A complaint may be filed with the Superintendence of Industry and Commerce only after the inquiry or complaint procedure before Code Labs has first been completed.
20. COMMERCIAL COMMUNICATIONS AND PRIVACY CHOICES
Commercial communications. Code Labs sends commercial or advertising information regarding its services only where the applicable authorization or legal basis exists and through channels permitted or selected by the Data Subject. Such communications are made within the hours and under the conditions established by applicable law. Where Code Labs engages in debt collection activities, it also applies the special rules on contact frequency, hours, and channels under Law 2300 of 2023:
- Complies with the legally permitted hours for commercial communications and, where applicable, debt collection activities.
- Respects the channels authorized by the Data Subject and the Data Subject’s decision to exclude any channel.
- In debt collection activities, applies legal restrictions on contact frequency and use of multiple channels.
- Enables the Data Subject to easily exercise privacy choices and unsubscribe from non-essential communications.
Unsubscribe. The Data Subject may stop receiving commercial communications at any time by using the unsubscribe option included in each message or by writing to info@code-labs.com. Code Labs will process the request in accordance with applicable law. This does not prevent Code Labs from sending communications that are strictly necessary to perform a contractual relationship, comply with legal obligations, provide security notices, or deliver a requested service.
Cookies. The Data Subject may change cookie settings at any time (Section 14).
Withdrawal. The Data Subject may withdraw authorization or request deletion of personal data by following the procedure described in Section 19.
21. EXTERNAL LINKS
The website may contain links to third-party websites or services. Their privacy practices are governed by their own policies, and Code Labs is not responsible for them. We recommend reviewing those policies before providing any information.
22. RESPONSIBLE AREA
The Personal Data Protection Area of Code Labs S.A.S. is responsible for handling Data Subject requests, inquiries, and complaints and for overseeing compliance with this Policy, in accordance with Article 2.2.2.25.3.1(d) of Decree 1074 of 2015.
Contact: info@code-labs.com · +57 320 962 8797.
23. CHANGES TO THIS POLICY
Any material change to this Policy will be published on this page and communicated to Data Subjects through the usual channels, including email where appropriate, before the change becomes effective.
Where a change introduces a new purpose or another modification that, under applicable law, requires new authorization, Code Labs will obtain such authorization from the Data Subject before applying the change.
24. POLICY AND DATABASE VALIDITY
This Policy is effective as of January 1, 2026 and will remain in effect for as long as Code Labs Processes personal data, until it is amended, updated, or replaced by a subsequent version. Any material change will be communicated in accordance with Section 23 of this Policy.
Database validity period. Code Labs databases will remain in effect for as long as the purposes described in this Policy remain applicable and throughout the retention periods specified in Section 17, or for as long as a legal rule or contractual relationship requires retention.