Privacy and Personal Data Processing Policy

Last updated: July 2026

1. Introduction

QUOLIX S.A.S. (hereinafter “QUOLIX”, “we”, or “the company”), in compliance with the Colombian Constitution (Article 15), Statutory Law 1581 of 2012, Regulatory Decree 1377 of 2013 (compiled in Sole Regulatory Decree 1074 of 2015), and, where applicable, Law 1266 of 2008 on financial and credit information, adopts this Privacy and Personal Data Processing Policy (hereinafter, the “Policy”).

Since QUOLIX may provide services to clients located outside Colombia and process the data of data subjects in other jurisdictions, the company additionally adopts, as a best-practice standard, principles aligned with the European Union's General Data Protection Regulation (GDPR), without this implying recognition of any supervisory authority other than the Superintendence of Industry and Commerce (SIC) for purposes of Colombian law, nor the automatic application of the GDPR unless required by the data subject's location or nationality.

By accessing, browsing, or using the website, forms, the SaaS platform, AI-based automation services, artificial intelligence agents, chatbots, and other technological tools developed by QUOLIX, the user represents that they have read and accepted the terms described herein.

2. Data Controller and Data Processor

  • Legal name: QUOLIX S.A.S.
  • Tax ID (NIT): 902083213-1
  • Registered address: Cra 8 No. 29-44, Ibagué, Colombia
  • Email: info@quolixai.com
  • Privacy complaints channel: info@quolixai.com
  • Website: www.quolixai.com
  • Country: Colombia

For purposes of this Policy, QUOLIX may act as Data Controller (when it determines the purposes and means of processing, for example with respect to data of its own clients, prospects, and website visitors) or as Data Processor (when it processes data on behalf of a client that has contracted its automation or artificial intelligence services, following that client's instructions). The capacity in which QUOLIX acts with respect to each category of data is specified, where possible, in the corresponding services agreement.

3. Definitions

  • Data subject: the natural person whose personal data is processed.
  • Personal data: any information linked to, or that can be associated with, one or more identified or identifiable natural persons.
  • Sensitive data: data that affects the data subject's privacy or whose misuse may cause discrimination (racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, health data, biometric data, sexual life data, among others).
  • Processing: any operation performed on personal data, such as collection, storage, use, circulation, transmission, transfer, or deletion.
  • Data Controller: the party that decides on the database and/or the processing of data.
  • Data Processor: the party that carries out the processing on behalf of the Data Controller.
  • Authorization: the data subject's prior, express, and informed consent for the processing of their personal data.
  • Privacy notice: a verbal or written communication addressed to the data subject informing them of the existence of the processing policy, how to access it, and the purposes of the processing.
  • Transmission: the communication of data between a Data Controller and a Data Processor, within or outside Colombia, for the latter to carry out the processing on behalf of the former.
  • International transfer: the sending of data to a recipient who is itself a Data Controller located in a country other than Colombia.

4. Data We Collect

4.1 Identification and contact data: full name, company, job title, email address, phone number.

4.2 Business data: business contact information, automation needs, information provided in forms.

4.3 Technical and browsing data: IP address, browser, operating system, device type, approximate location, cookie identifiers, and similar technologies.

4.4 Data generated from the use of the services: conversations with bots and virtual assistants, requests made to the platform, activity logs, and usage metadata.

4.5 Sensitive and biometric data: QUOLIX does not intentionally request or collect sensitive data (health, racial or ethnic origin, religious or political beliefs, sexual life, union membership) or biometric data as a condition for providing its services. If, due to the nature of the platform configuration contracted as a Cloud Service, a client configures agents or bots that capture sensitive or biometric data of third parties, that client is responsible for obtaining the explicit and independent authorization required by Article 6 of Law 1581 of 2012. No data subject is required to answer questions about sensitive data.

4.6 Voluntarily provided data: any information the user chooses to provide through forms, emails, chats, or meetings.

5. Purposes of Processing

5.1 Service delivery: implementing automations and configuring virtual assistants; creating and adjusting artificial intelligence solutions contracted by the client; managing client accounts and the contractual relationship.

5.2 Customer service: resolving requests, providing technical support, and managing incidents.

5.3 Operation and security: detecting errors, preventing fraud, identifying unauthorized access, and monitoring platform performance.

5.4 Service improvement: analyzing platform usage and optimizing features; training or adjusting internal models only when the information has been previously anonymized or aggregated so that the data subject cannot be re-identified.

5.5 Commercial communications: sending information about services, marketing campaigns, and news, when there is authorization or a legitimate interest compatible with the original purpose, and always with an immediate, free opt-out option.

5.6 Legal compliance: responding to requests from competent judicial or administrative authorities and complying with accounting, tax, or regulatory obligations.

6. Principles and Legal Basis for Processing

In accordance with Article 4 of Law 1581 of 2012, QUOLIX's processing of personal data is governed by the principles of: lawfulness, purpose, freedom, accuracy or quality, transparency, restricted access and circulation, security, and confidentiality. In line with the GDPR, QUOLIX also adopts the principles of data minimization, storage limitation, and accountability.

Processing is based, as applicable, on:

  • The data subject's prior, express, and informed consent (Art. 9, Law 1581 of 2012).
  • The performance of a contract to which the data subject is a party, or to take pre-contractual steps.
  • Compliance with a legal obligation applicable to QUOLIX.
  • QUOLIX's legitimate interest, when the data subject's fundamental rights and freedoms do not prevail, and in cases expressly permitted by Article 10 of Law 1581 of 2012 (for example, information of public record or required by a public entity in the exercise of its functions).

7. Data Subject's Authorization

Except in cases exempted by law, the processing of personal data requires the data subject's prior, express, and informed authorization. QUOLIX obtains such authorization through verifiable mechanisms such as: unchecked opt-in boxes on web forms, acceptance of terms on first use of a bot or virtual assistant, signed services agreements, or recording/logging of verbal acceptance where applicable.

  • Authorization must be freely given, specific to the purposes disclosed, and unambiguous.
  • The data subject may withdraw it at any time, without retroactive effect on processing already carried out under the authorization in force at the time.
  • QUOLIX will keep evidence of the authorization granted for as long as the processing continues and for the statute-of-limitations period for related actions.
  • When authorization is not required under Article 10 of Law 1581 of 2012 (for example, data of a public nature, requests from a judicial or administrative authority, or data related to the Civil Registry), QUOLIX will expressly indicate this to the data subject whenever reasonably possible.

8. Use of Artificial Intelligence

QUOLIX's services may use artificial intelligence, machine learning, and automation technologies, including language models operated by third-party providers. The user acknowledges and accepts that:

  • Responses generated by AI systems may contain errors or inaccuracies.
  • The information generated does not constitute legal, financial, medical, or professional advice.
  • QUOLIX does not guarantee the absolute accuracy of results produced by AI models.
  • Decisions that produce significant legal effects or similarly affect the data subject will not be based exclusively on automated processing without meaningful human intervention, unless the data subject has expressly consented or there is a legal basis for it.
  • The data subject may request information about the general logic applied by the automated systems that process their data, to the extent this does not infringe trade secrets or third-party rights.

Ultimate responsibility for the use a client or user makes of the information produced by AI systems rests with that client or user.

9. Data Entered into Bots and AI Agents

When a QUOLIX client configures bots, virtual assistants, or AI agents to process the personal data of its own end users, that client acts as the Data Controller for that data, and QUOLIX acts as the Data Processor, processing the information solely in accordance with the client's documented instructions. In this scenario, the client is responsible for:

  • Obtaining the necessary authorizations from data subjects and third parties.
  • Ensuring the legality, accuracy, and lawfulness of the data loaded into the system.
  • Complying with applicable data protection regulations in its jurisdiction, including providing adequate privacy notices to its own end users.
  • Instructing QUOLIX on the deletion or return of data upon completion of the service.

QUOLIX undertakes, in its capacity as Processor, to maintain confidentiality over the data processed, not to use it for purposes other than those instructed by the client, and to implement reasonable security measures, in accordance with Article 4 of Law 1581 of 2012.

10. Technology Providers and Sub-Processors

QUOLIX may rely on external providers (sub-processors) to deliver its services, including, among others: cloud infrastructure (Cloud Service / SaaS) supporting AI processing, hosting and other platform components, natural language processing, analytics tools, email, and payment processing. These providers may only process information for the contracted purposes, under contractual confidentiality and security obligations, and QUOLIX will make a reasonable selection of providers that offer adequate data protection guarantees.

11. International Transfers and Transmissions

Information may be stored or processed in cloud infrastructure for the Cloud Service that may be located outside Colombia, including countries the SIC has not classified as providing an adequate level of data protection. In such cases, QUOLIX will adopt at least one of the following safeguards, in accordance with Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and, where applicable, GDPR standards:

  • Express and informed authorization from the data subject for the specific international transfer.
  • Contractual clauses or data transfer agreements with providers/recipients that include confidentiality, security, and use-limitation obligations equivalent to those in this Policy.
  • Verification that the recipient country has been declared by the SIC to provide an adequate level of protection, where such a declaration exists.

QUOLIX will make reasonable efforts to ensure its providers maintain security and privacy standards comparable to those required in Colombia.

12. Data Retention

QUOLIX will retain personal data only for as long as necessary to fulfill the purposes that led to its collection, and in any case:

  • For the duration of the contractual relationship.
  • While there is a legal, accounting, tax, or regulatory retention obligation.
  • For the statute-of-limitations period for judicial or administrative actions that may arise from the processing.
  • Until the data subject validly requests its deletion and there is no prevailing legal duty or legitimate interest preventing this.

Once the purpose has been fulfilled and the above periods have expired, the data will be securely deleted or anonymized.

13. Data Subject Rights

In accordance with Article 8 of Law 1581 of 2012 and Article 15 of the Colombian Constitution, and in a manner complementary to GDPR standards, the data subject has the right to:

  • Know, update, and rectify their personal data held by QUOLIX, including partial, inaccurate, incomplete, fragmented, or misleading data.
  • Request proof of the authorization granted, unless the law exempts this requirement.
  • Be informed, upon request, about the use given to their personal data.
  • File complaints with the Superintendence of Industry and Commerce (SIC) for violations of Law 1581 of 2012 and other related regulations.
  • Withdraw the authorization granted and/or request the deletion of the data, when there is no legal or contractual duty preventing it.
  • Access, free of charge, their personal data that has been processed.
  • Additionally, as a best practice aligned with the GDPR: request the restriction of processing in certain cases, object to processing based on legitimate interest, and request the portability of data the data subject has directly provided, where technically possible.
  • In the case of children and adolescents, these rights must be exercised by their legal representatives.

14. Procedure for Exercising Rights (Inquiries and Complaints)

The data subject, or their duly accredited successors, may exercise their rights by sending a request through the channels indicated in the Contact section, fully identifying themselves and clearly describing the request.

14.1 Inquiries: inquiries will be addressed within a maximum term of ten (10) business days from the date of receipt. When it is not possible to address the inquiry within that term, the data subject will be informed before it expires, stating the reasons for the delay and the date on which it will be addressed, which may not exceed five (5) business days following the expiration of the first term.

14.2 Complaints (rectification, updating, deletion, or withdrawal): if a complaint is incomplete, QUOLIX will require the data subject, within five (5) days of receipt, to remedy the deficiencies; if two (2) months pass without the data subject providing the required information, the complaint will be deemed withdrawn. The maximum term for addressing the complaint will be fifteen (15) business days from the day following the date of receipt. When it is not possible to address it within that term, the data subject will be informed of the reasons for the delay and the date on which it will be addressed, which may not exceed eight (8) business days following the expiration of the first term.

14.3 Supervisory authority: if the data subject believes their request was not adequately addressed, they may file a complaint with the Superintendence of Industry and Commerce (Delegate for the Protection of Personal Data).

15. Information Security and Incident Management

QUOLIX implements reasonable administrative, technical, and organizational security measures aimed at protecting the confidentiality, integrity, and availability of personal data, and at preventing its alteration, loss, unauthorized or fraudulent access, or use.

In the event of a security incident constituting a personal data breach (for example, unauthorized access, loss, or theft of information), QUOLIX will report the incident to the Superintendence of Industry and Commerce and, when the risk to data subjects warrants it, will inform the affected data subjects, adopting appropriate containment and remediation measures within the timeframes required by applicable regulations.

No system is completely secure; QUOLIX cannot guarantee absolute security against events beyond its reasonable control.

16. Limitation of Liability

Without prejudice to non-delegable personal data protection duties, QUOLIX will not be liable for:

  • Errors or inaccuracies generated by artificial intelligence systems, to the extent reasonable oversight measures have been adopted.
  • Decisions made by the client or user based exclusively on automated results.
  • Information entered incorrectly, incompletely, or fraudulently by users.
  • Losses arising from internet interruptions or third-party services beyond QUOLIX's control.
  • Cyberattacks that exceed the reasonable security standards implemented.
  • Misuse of credentials by the user.

QUOLIX's total liability to a client, in any case and except in cases of willful misconduct or gross negligence, will be limited to the amount actually paid by that client during the preceding twelve (12) months.

17. Prohibited Uses

Users agree not to use QUOLIX's services for:

  • Illegal or fraudulent activities.
  • Sending spam or unsolicited communications.
  • Identity theft.
  • Distribution of malware or malicious code.
  • Infringement of intellectual property rights or third parties' personal data.
  • Generating unlawful, discriminatory content or content that violates fundamental rights.

QUOLIX may suspend or cancel access to services that violate these provisions, without prejudice to any legal action that may be applicable.

18. Cookies and Similar Technologies

The website uses its own and third-party cookies to remember preferences, analyze traffic, improve the user experience, and measure the performance of marketing campaigns. Details on the types of cookies used, their specific purposes, the third parties involved, and the mechanisms for managing them are described in QUOLIX's Cookie Policy, which forms an integral part of this Policy.

The user can configure, block, or delete cookies through their browser settings or through the consent banner displayed on the website; however, this may affect the functioning of some features. Where applicable regulations require it, QUOLIX will display a consent banner prior to installing non-essential cookies.

19. Minors

QUOLIX's services are directed at adults and businesses. QUOLIX does not knowingly collect personal information from children or adolescents without the authorization of their legal representatives and without complying with the best-interest standard and respect for their prevailing rights, in accordance with Article 7 of Law 1581 of 2012. If QUOLIX becomes aware that data has been collected from a minor without such authorization, it will proceed to delete it as soon as possible.

20. Financial and Credit Information (Law 1266 of 2008)

If, in connection with specific services, QUOLIX comes to process financial, credit, commercial, or service data related to data subjects' economic solvency (financial Habeas Data), such processing will additionally be governed by Law 1266 of 2008, its implementing decrees, and SIC circulars, including the principles of accuracy, purpose, restricted circulation, and expiration of negative data. This scenario does not apply to QUOLIX's general operations unless expressly stated in a services agreement.

21. National Database Registry (RNBD)

Under current regulations, legal entities with total assets exceeding 100,000 UVT are required to register their databases containing personal data with the National Database Registry (RNBD) administered by the SIC. QUOLIX will periodically assess whether it falls within this scenario and, if so, will keep such registration up to date.

22. Modifications

QUOLIX may update this Policy at any time to reflect regulatory, operational, or technological changes. Substantial changes affecting the purposes of processing will be communicated to data subjects through available channels (for example, email or a notice on the website) before they take effect, and may require new authorization when required by law. Non-substantial modifications will be published on the website indicating the update date.

23. Applicable Law and Jurisdiction

This Policy is governed by the laws of the Republic of Colombia. For data subjects located in other jurisdictions that grant additional or different rights (for example, the GDPR in the European Union), QUOLIX will handle such requests in accordance with the standards described in this Policy, without prejudice to the fact that the competent authority for purposes of Law 1581 of 2012 is the Superintendence of Industry and Commerce of Colombia.

24. Contact

For any inquiries related to this Policy, you may contact:

  • General email: info@quolixai.com
  • Privacy complaints email: info@quolixai.com
  • Website: www.quolixai.com
  • Physical address: Cra 8 No. 29-44, Ibagué, Colombia