Privacy and Personal Data Processing Policy

Last updated: July 2026

1. Introduction

QUOLIX S.A.S. (hereinafter “QUOLIX”, “we”, or “the company”), in compliance with the Political Constitution of Colombia (Article 15), Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013 (compiled in Sole Regulatory Decree 1074 of 2015) and, where applicable, Law 1266 of 2008 on financial and credit information, adopts this Privacy and Personal Data Processing Policy (hereinafter, the “Policy”).

Because QUOLIX may provide services to clients located outside Colombia and process data of individuals in other jurisdictions, the company additionally adopts, as a best-practice standard, principles aligned with the European Union's General Data Protection Regulation (GDPR), without this implying recognition of any supervisory authority other than the Superintendence of Industry and Commerce (SIC) for the purposes of Colombian law, nor the automatic application of the GDPR unless it is enforceable due to the location or nationality of the data subject.

By accessing, browsing, or using the website, forms, software, automation services, virtual assistants, artificial intelligence agents, chatbots, and other technological tools developed by QUOLIX, the user declares that they have read and accepted the terms described herein.

2. Data Controller and Data Processor

For the purposes of this Policy, QUOLIX may act as Data Controller (when it determines the purposes and means of processing, for example regarding the data of its own clients, prospects, and website visitors) or as Data Processor (when it processes data on behalf of a client that contracts its automation or artificial intelligence services, following the client's instructions). The capacity in which QUOLIX acts with respect to each category of data is specified, where possible, in the corresponding service agreement.

3. Definitions

  • Data subject: the natural person whose personal data is subject to processing.
  • Personal data: any information linked to, or that can be associated with, one or more specific or identifiable natural persons.
  • Sensitive data: data affecting the data subject's privacy or whose misuse may lead to discrimination (racial or ethnic origin, political orientation, religious or philosophical beliefs, union membership, health data, biometric data, sex-life data, among others).
  • Processing: any operation on personal data, such as collection, storage, use, circulation, transmission, transfer, or deletion.
  • Data Controller: the party that decides on the database and/or the processing of the data.
  • Data Processor: the party that carries out the processing on behalf of the Controller.
  • Authorization: the data subject's prior, express, and informed consent to the processing of their personal data.
  • Privacy notice: a verbal or written communication addressed to the data subject informing them of the existence of the processing policy, how to access it, and the purposes of the processing.
  • Transmission: the communication of data between a Controller and a Processor, inside or outside Colombia, so that the latter processes it on behalf of the former.
  • International transfer: sending data to a recipient that is itself a Data Controller and is located in a country other than Colombia.

4. Data We Collect

We may collect the following categories of data:

  • Identification and contact data: full name, company, position, email address, phone number.
  • Commercial data: business contact information, automation needs, and information provided in forms.
  • Technical and browsing data: IP address, browser, operating system, device type, approximate location, cookie identifiers, and similar technologies.
  • Data generated by use of the services: conversations with bots and virtual assistants, requests made to the software, activity logs, and usage metadata.
  • Sensitive and biometric data: QUOLIX does not intentionally request or collect sensitive data (health, racial or ethnic origin, religious or political beliefs, sex life, union membership) or biometric data as a condition for providing its services. If, due to the nature of a custom development, the client configures agents or bots that capture sensitive or biometric data of third parties, that client will be responsible for obtaining the explicit and independent authorization required by Article 6 of Law 1581 of 2012. No data subject is obliged to answer questions about sensitive data.
  • Voluntarily provided data: any information the user chooses to provide via forms, emails, chats, or meetings.

5. Purposes of Processing

We process personal data for the following purposes:

  • Service delivery: implementing automations and configuring virtual assistants, creating and adjusting the artificial intelligence solutions contracted by the client, and managing client accounts and the contractual relationship.
  • Customer support: resolving requests, providing technical support, and handling incidents.
  • Operation and security: detecting errors, preventing fraud, identifying unauthorized access, and monitoring platform performance.
  • Service improvement: analyzing software usage and optimizing features; training or fine-tuning internal models only when the information has been previously anonymized or aggregated so that it does not allow re-identification of the data subject.
  • Commercial communications: sending information about services, marketing campaigns, and news, where authorization or a legitimate interest compatible with the original purpose exists, and always with an immediate and free opt-out option.
  • Legal compliance: responding to requirements from competent judicial or administrative authorities and complying with accounting, tax, or regulatory obligations.

6. Principles and Legal Basis for Processing

In accordance with Article 4 of Law 1581 of 2012, the processing of personal data by QUOLIX is governed by the principles of: legality, purpose, freedom, truthfulness or quality, transparency, restricted access and circulation, security, and confidentiality. In line with the GDPR, QUOLIX also adopts the principles of data minimization, storage limitation, and demonstrated accountability.

Processing is based, as applicable, on:

  • The data subject's prior, express, and informed consent (Art. 9, Law 1581 of 2012).
  • The performance of a contract to which the data subject is a party, or pre-contractual measures.
  • Compliance with a legal obligation applicable to QUOLIX.
  • QUOLIX's legitimate interest, where the data subject's fundamental rights and freedoms do not prevail, and in the cases expressly permitted by Article 10 of Law 1581 of 2012.

7. Data Subject's Authorization

Except in cases exempted by law, the processing of personal data requires the data subject's prior, express, and informed authorization. QUOLIX obtains such authorization through verifiable mechanisms such as: non-pre-checked opt-in boxes on web forms, acceptance of terms upon first use of a bot or virtual assistant, signing of service agreements, or recording of verbal acceptance where applicable.

  • Authorization must be freely given, specific to the informed purposes, and unambiguous.
  • The data subject may revoke it at any time, without retroactive effect on processing already carried out under the authorization in force at the time.
  • QUOLIX will keep proof of the authorization granted for the duration of the processing and the limitation period of any actions arising from it.
  • When authorization is not required under Article 10 of Law 1581 of 2012, QUOLIX will state this expressly to the data subject where reasonably possible.

8. Use of Artificial Intelligence

QUOLIX's services may use artificial intelligence, machine learning, and automation technologies, including language models operated by third-party providers. The user acknowledges and accepts that:

  • Responses generated by AI systems may contain errors or inaccuracies.
  • The information generated does not constitute legal, financial, medical, or professional advice.
  • QUOLIX does not guarantee the absolute accuracy of the results produced by AI models.
  • Decisions producing significant legal effects or similarly affecting the data subject will not be based solely on automated processing without meaningful human intervention, unless the data subject has expressly consented or there is a legal basis for it.
  • The data subject may request information about the general logic applied by the automated systems that process their data, to the extent that this does not infringe trade secrets or third-party rights.

Final responsibility for the use that the client or user makes of the information produced by AI systems lies with that client or user.

9. Data Entered into Bots and AI Agents

When a QUOLIX client configures bots, virtual assistants, or AI agents to process personal data of its own end users, that client acts as Data Controller with respect to such data, and QUOLIX acts as Data Processor, processing the information solely in accordance with the client's documented instructions.

In that scenario, the client is responsible for:

  • Obtaining the necessary authorizations from data subjects and third parties.
  • Ensuring the legality, truthfulness, and lawfulness of the data loaded into the system.
  • Complying with the data protection regulations applicable in its jurisdiction, including providing appropriate privacy notices to its own end users.
  • Instructing QUOLIX on the deletion or return of the data at the end of the service.

In its capacity as Processor, QUOLIX undertakes to maintain confidentiality over the data processed, not to use it for purposes other than those instructed by the client, and to implement reasonable security measures, under the terms of Article 4 of Law 1581 of 2012.

10. Technology Providers and Sub-processors

QUOLIX may rely on external providers (sub-processors) to deliver its services, including for: hosting, cloud storage, artificial intelligence and natural language processing services, analytics tools, email, and payment processing. These providers may only process information for the contracted purposes, under contractual confidentiality and security obligations, and QUOLIX will reasonably select providers that offer adequate data protection guarantees.

11. International Transfers and Transmissions

Information may be stored or processed on servers located outside Colombia, including in countries that the SIC has not classified as providing an adequate level of data protection. In such cases, QUOLIX will adopt at least one of the following safeguards, in accordance with Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and, where applicable, GDPR standards:

  • The data subject's express and informed authorization for the specific international transfer.
  • Contractual clauses or data transfer agreements with providers/recipients, including confidentiality, security, and use-limitation obligations equivalent to those in this Policy.
  • Verification that the recipient country holds an adequacy declaration from the SIC, where such a declaration exists.

QUOLIX will endeavor, to the extent reasonable, to ensure that its providers maintain security and privacy standards comparable to those required in Colombia.

12. Data Retention

QUOLIX will retain personal data only for as long as necessary to fulfill the purposes that motivated its collection, and in any case:

  • For the duration of the contractual relationship.
  • While a legal, accounting, tax, or regulatory retention obligation exists.
  • During the limitation period of any judicial or administrative actions that may arise from the processing.
  • Until the data subject validly requests its deletion and there is no overriding legal duty or legitimate interest preventing it.

Once the purpose has been fulfilled and the above periods have elapsed, the data will be securely deleted or anonymized.

13. Data Subject Rights

In accordance with Article 8 of Law 1581 of 2012 and Article 15 of the Political Constitution, and complementarily with GDPR standards, the data subject has the right to:

  • Access, update, and rectify their personal data with QUOLIX, including partial, inaccurate, incomplete, fragmented, or misleading data.
  • Request proof of the authorization granted, unless the law exempts this requirement.
  • Be informed, upon request, about the use that has been made of their personal data.
  • File complaints with the Superintendence of Industry and Commerce (SIC) for violations of Law 1581 of 2012 and related regulations.
  • Revoke the authorization granted and/or request deletion of the data, where no legal or contractual duty prevents its removal.
  • Access their personal data that has been processed, free of charge.
  • As a best practice aligned with the GDPR: request restriction of processing in certain cases, object to processing based on legitimate interest, and request portability of the data provided directly, where technically feasible.
  • For children and adolescents, these rights must be exercised through their legal representatives.

14. Procedure to Exercise Rights (Inquiries and Claims)

The data subject, or their duly accredited successors, may exercise their rights by sending a request through the channels indicated in the Contact section, fully identifying themselves and clearly describing the request.

  • Inquiries: will be handled within a maximum of ten (10) business days from the date of receipt. Where this is not possible, the data subject will be informed before the deadline, stating the reasons for the delay and the date on which the inquiry will be handled, which may not exceed five (5) business days after the expiry of the first term.
  • Claims (rectification, update, deletion, or revocation): if the claim is incomplete, QUOLIX will notify the data subject within five (5) days to remedy the deficiencies; if two (2) months pass without a response, the claim will be deemed withdrawn. The maximum term to address it will be fifteen (15) business days from the day after receipt, extendable by eight (8) more business days with notice of the reasons.
  • Supervisory authority: if the data subject considers that their request was not handled appropriately, they may file a complaint with the Superintendence of Industry and Commerce (Delegate Office for the Protection of Personal Data).

15. Information Security and Incident Management

QUOLIX implements reasonable administrative, technical, and organizational security measures aimed at protecting the confidentiality, integrity, and availability of personal data, and at preventing its alteration, loss, unauthorized or fraudulent access, consultation, or use.

In the event of a security incident constituting a personal data breach (for example, unauthorized access, loss, or theft of information), QUOLIX will report the incident to the Superintendence of Industry and Commerce and, where the risk to data subjects warrants it, will inform the affected data subjects, adopting the relevant containment and remediation measures within the deadlines required by applicable regulations.

No system is completely secure; QUOLIX cannot guarantee absolute security against events beyond its reasonable control.

16. Limitation of Liability

Without prejudice to the non-delegable duties of personal data protection, QUOLIX will not be liable for:

  • Errors or inaccuracies generated by artificial intelligence systems, to the extent reasonable oversight measures have been adopted.
  • Decisions made by the client or user based solely on automated results.
  • Information entered incorrectly, incompletely, or fraudulently by users.
  • Losses arising from internet outages or third-party services beyond QUOLIX's control.
  • Cyberattacks that exceed the reasonable security standards implemented.
  • Misuse of credentials by the user.

QUOLIX's total liability toward a client, in any case and except for willful misconduct or gross negligence, will be limited to the amount actually paid by that client during the last twelve (12) months.

17. Prohibited Uses

Users agree not to use QUOLIX's services to:

  • Carry out illegal or fraudulent activities.
  • Send spam or unsolicited communications.
  • Impersonate others.
  • Distribute malware or malicious code.
  • Infringe intellectual property rights or third parties' personal data.
  • Generate unlawful, discriminatory content, or content that violates fundamental rights.

QUOLIX may suspend or cancel access to the services for anyone who breaches these provisions, without prejudice to any applicable legal action.

18. Cookies and Similar Technologies

The website uses first-party and third-party cookies to remember preferences, analyze traffic, improve the user experience, and measure the performance of marketing campaigns. The user may configure, block, or delete cookies from their browser settings; however, this may affect the operation of some site features. Where applicable regulations require it (for example, for users in the European Union), QUOLIX will present a prior consent banner for non-essential cookies.

19. Minors

QUOLIX's services are aimed at adults and businesses. QUOLIX does not deliberately collect personal information from children or adolescents without the authorization of their legal representatives and without complying with their best interests and prevailing rights, in accordance with Article 7 of Law 1581 of 2012. If QUOLIX becomes aware that a minor's data has been collected without such authorization, it will delete it as soon as possible.

20. Financial and Credit Information (Law 1266 of 2008)

If, within the scope of specific services, QUOLIX were to process data of a financial, credit, commercial, or service nature relating to the economic solvency of data subjects (financial Habeas Data), such processing will additionally be governed by Law 1266 of 2008, its implementing decrees, and SIC circulars, including the principles of truthfulness, purpose, restricted circulation, and expiry of negative data. This scenario does not apply to QUOLIX's general operation unless expressly stated in a service agreement.

21. National Database Registry (RNBD)

Under current regulations, legal entities with total assets exceeding 100,000 UVT are required to register their databases containing personal data in the National Database Registry (RNBD) administered by the SIC. QUOLIX will periodically assess whether it falls within this scenario and, if so, will keep such registration up to date.

22. Amendments

QUOLIX may update this Policy at any time to reflect regulatory, operational, or technological changes. Substantial changes affecting the purposes of processing will be communicated to data subjects through the available channels (for example, email or a notice on the website) before they take effect, and may require new authorization where the law so requires. Non-substantial changes will be published on the website with an indication of the update date.

23. Governing Law and Jurisdiction

This Policy is governed by the laws of the Republic of Colombia. For data subjects located in other jurisdictions that grant additional or different rights (for example, the GDPR in the European Union), QUOLIX will handle such requests in accordance with the standards described in this Policy, without prejudice to the fact that the competent authority for the purposes of Law 1581 of 2012 is the Superintendence of Industry and Commerce of Colombia.

24. Contact

To exercise your rights or resolve questions about this Policy, you can contact us through the following channels:

  • Company: QUOLIX S.A.S.
  • General email: contacto@quolix.com
  • Privacy requests email: privacidad@quolix.com
  • Website: www.quolix.com
  • Country: Colombia
  • Tax ID (NIT) and physical address: to be completed before publication.