Personal data processing policy
Last updated: Version: 1.5The Spanish version is the legally binding text.
Effective: from its publication on the Site.
The Spanish version of this Policy is the legally binding text. This translation is provided for reference only.
1. Data controller
| Item | Information |
|---|---|
| Controller | BCL Group S.A.S., a company incorporated under the laws of the Republic of Colombia, operating under the trade name Greyfield Strata |
| Tax ID (NIT) | 901.371.032 |
| Domicile and address | Cr 23 No. 80-35 D. 103, Bogotá D.C., Colombia |
| Email for personal data matters | datospersonales@greyfieldstrata.com |
| Phone | +57 601 521 2514 |
| Website | greyfieldstrata.com |
| Area responsible for queries and complaints | Administrative Management |
Hereinafter, “the Company”.
2. Legal framework and scope
This Policy is adopted in compliance with article 15 of the Colombian Constitution, Statutory Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and the instructions of the Superintendence of Industry and Commerce (SIC).
It applies to the personal data the Company collects, stores, uses, circulates or deletes through the Website and the channels linked to it: the contact form, the waitlist form, email and phone.
Data the Company processes on behalf of its clients when providing its services is not governed by this Policy, but by the corresponding contract and, where applicable, by the Data Processing Addendum (DPA) published in the Legal section of the Site.
3. Definitions and principles
For the purposes of this Policy, the definitions in article 3 of Law 1581 of 2012 apply:
- Personal data: any information linked or that may be associated with an identified or identifiable natural person.
- Sensitive data: data that affects the data subject’s privacy or whose misuse may lead to discrimination (racial origin, political orientation, religious beliefs, health, sex life, biometric data, among others).
- Data subject: the natural person whose data is processed.
- Processing: any operation on personal data, such as collection, storage, use, circulation or deletion.
- Controller: whoever decides on the database and the processing. In this case, the Company.
- Processor: whoever processes data on behalf of the Controller.
- Authorization: the data subject’s prior, express and informed consent.
- Transmission: communication of data to a Processor, inside or outside Colombia, so that it processes it on behalf of the Controller.
- Transfer: sending data to another Controller, inside or outside Colombia.
The Company applies the principles of legality, purpose, freedom, accuracy or quality, transparency, restricted access and circulation, security and confidentiality set out in article 4 of Law 1581 of 2012.
4. Data we collect and purposes
The Company only processes the data necessary for the purposes described in this table. Any new purpose will require a new authorization.
| Category | Data | How it is obtained | Purpose | Retention |
|---|---|---|---|---|
| Contact | Name, email, company, reason for contact, message and approximate country of the connection | The Site’s contact form, or direct email and phone | Answering requests, scheduling meetings and sending quotes or the information requested by the data subject | 24 months from the last contact, unless there is a commercial relationship |
| Waitlist | Name, email, organization, sector, products of interest, preferred channel, use case and approximate country of the connection | The Greyfield Data & Compute waitlist form | Letting the data subject know when access opens to what they ticked, and deciding what to build first, using aggregated data | Up to 12 months after access opens, or earlier if the data subject requests deletion |
| Commercial communications (optional) | Name and email | A separate, optional box on the contact form | Sending news, offers and invitations from the Company by email | Until the data subject revokes the authorization |
| Technical data | IP address, browser type, date and time of access and page requested | Automatic logs of Cloudflare, the hosting and security provider | Site security, fraud and spam prevention, checking that forms are submitted by a person, and error diagnosis | According to the retention periods of Cloudflare’s logs |
| Analytics (with consent) | Analytics cookie identifier, pages visited, device type and approximate location | Google Analytics, only if the data subject accepts it in the cookie notice | Understanding in aggregate how the Site is used, to improve its content | 14 months |
| Site preferences | gs-theme, gs-view and gs-consent values | Browser local storage | Remembering the chosen appearance and the cookie decision. They are not sent to our servers | Until the data subject deletes them; gs-consent, 12 months |
Form data is not used to train artificial intelligence models.
Data may also be used to respond to requests from competent authorities and to exercise or defend the Company’s rights.
Commercial communications will respect the times, frequency and channels set by Law 2300 of 2023. Every communication will include a way to stop receiving them.
5. Authorization, sensitive data and minors
Authorization. The Company requests the data subject’s authorization in a prior, express and informed manner, through an unticked box on each form of the Site. Authorization for commercial communications is requested in a separate box, also unticked, and is optional: not accepting it does not prevent submitting the form. The Company keeps proof of each authorization: date and time, version of the Policy accepted and data provided.
The use of analytics cookies requires a separate authorization, requested in the Site’s cookie notice, which can be changed at any time from the “Cookie settings” link. Details are in the Cookies and Local Storage Policy.
No authorization is required in the cases of article 10 of Law 1581 of 2012, such as public data or information required by a public entity in the exercise of its functions.
Sensitive data. The Site does not request sensitive data. Please do not include it in the messages you send us. If it were ever required, you would be told that providing it is optional and explicit authorization would be requested.
Children and adolescents. The Site is intended for people over 18. The Company does not knowingly collect data from minors. If we detect that it has been received, we will delete it.
6. Processors and international circulation
The Company does not sell or assign personal data. To operate the Site it relies on providers that act as Processors and process data only on our instructions, under transmission contracts with confidentiality and security obligations.
| Provider | Service | Server location |
|---|---|---|
| Cloudflare, Inc. | Hosting of the Site, form database, security logs and bot verification (Turnstile) | United States and Cloudflare’s global data center network |
| Resend | Sending the internal notifications generated by the forms | United States |
| Microsoft Corporation and Google LLC | Corporate email: receiving and managing messages (Microsoft 365, with a planned migration to Google Workspace) | United States and other countries |
| Google LLC | Site analytics (Google Analytics), only with consent | United States and other countries |
Since these providers have servers outside Colombia, data is transmitted internationally. Circulation complies with article 26 of Law 1581 of 2012 and articles 2.2.2.25.5.1 et seq. of Decree 1074 of 2015: mainly to the United States, a country the SIC recognizes as having an adequate level of protection (External Circular 005 of 2017), and in all cases under transmission contracts with each provider. By accepting this Policy, you authorize that international transmission.
The Company may hand over data to authorities that request it in the exercise of their legal functions.
7. Data subjects’ rights and the Company’s duties
Under article 8 of Law 1581 of 2012, you have the right to:
- Know, update and correct your personal data.
- Request proof of the authorization granted.
- Be informed about how your data has been used.
- File complaints with the Superintendence of Industry and Commerce, after completing the query or complaint procedure with the Company.
- Revoke the authorization and request deletion of your data, where there is no legal or contractual duty to keep it.
- Access your personal data free of charge.
To stop receiving commercial communications, just use the link included in each one or write to the personal data email.
The Company complies with the duties in article 17 of Law 1581 of 2012. Among them: guaranteeing the exercise of these rights, keeping proof of authorization, keeping information secure, handling queries and complaints within the legal deadlines and reporting security incidents to the SIC.
8. How to exercise your rights
You can submit queries and complaints to datospersonales@greyfieldstrata.com or in writing at Cr 23 No. 80-35 D. 103, Bogotá D.C., Colombia. They may be submitted by the data subject, their successors, representative or attorney, proving their standing. The request must include name, identity document, a description of what is requested, a response address or email and any documents to be relied on.
| Procedure | Purpose | Response time |
|---|---|---|
| Query (art. 14, Law 1581) | Find out what data of yours we hold and how we use it | 10 business days from receipt, extendable by up to 5 more business days, stating the reason |
| Complaint (art. 15, Law 1581) | Correct, update or delete data, revoke the authorization or report a breach | 15 business days from the day after receipt, extendable by up to 8 more business days, stating the reason |
If a complaint is incomplete, we will ask you to complete it within 5 days of receipt. If 2 months pass without it being completed, it will be deemed withdrawn. While the complaint is in progress, the database will show the legend “complaint in progress”, added within a maximum of 2 business days.
Before going to the SIC, the data subject must complete this procedure with the Company.
9. Security, validity and changes
Security. The Company applies reasonable technical, human and administrative measures to protect data against loss, consultation, use or unauthorized access. They include: HTTPS encryption across the Site, bot verification and submission limits on forms, access control with authentication, access limited to the staff who need it, and confidentiality agreements with providers. The Site does not store the IP address of those who submit the forms.
Validity. This Policy is in force from its publication on the Site. The databases will remain in force while the purposes described are being fulfilled and for the retention periods set out in section 4 or those required by law.
Changes. Any substantial change will be published on the Site with a new date and version number before it applies. If the change affects the authorized purposes, we will request a new authorization.