This personal data processing policy is prepared in accordance with the provisions of Law 1581 of 2012 regulated by Decree 1377 of 2013, and other complementary provisions, which will be applied by HELIX BODY JEWELRY in relation to the processing of personal data.
I. OBJECTIVE
In this policy, HELIX BODY JEWELRY establishes the necessary guidelines to protect the Personal Data of the Owners, as well as the purpose of collecting the information, establishes the criteria for the collection, storage, use and deletion of the owners' data, their rights, the obligations of HELIX BODY JEWELRY as responsible, the channels for handling queries and complaints, the procedures for handling them, and the validity of the databases.
II. DEFINITIONS:
● Authorization: prior, express and informed consent of the owner to carry out the processing of personal data.
● Database (BB.DD): organized set of personal data that is subject to processing.
● Personal data: any information linked or that can be associated with one or more specific or determinable natural persons.
● Owner: natural person whose personal data is processed.
● Data processor: natural or legal person, public or private, who, by themselves or in association with others, processes personal data, on behalf of the data controller.
● Data controller: natural or legal person, public or private, who alone or in association with others, decides on the database and/or the processing of data.
III. BEGINNING:
● Principle of legality regarding data processing: the processing of personal data is a regulated activity that must be subject to the provisions of Law 1581 of 2012 and other provisions that develop it.
● Security principle: the information subject to Treatment by the Data Controller or Data Processor referred to in Law 1581 of 2012 must be handled with the technical, human and administrative measures that are necessary to provide security to the records, avoiding its adulteration, loss, unauthorized or fraudulent consultation, use or access.
● Principle of purpose: the Processing of personal data obeys a legitimate purpose in accordance with the Constitution and Law 1581 of 2012, which must be informed to the Owner.
● Principle of freedom: Treatment can only be carried out with the prior, express and informed consent of the Owner. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that requires consent.
● Principle of truthfulness or quality: the information subject to processing must be truthful, complete, exact, verifiable and understandable. The Processing of partial, incomplete, fragmented or misleading data is prohibited.
● Principle of transparency: in the Treatment, the right of the Owner to obtain from the Data Controller or the Data Processor, at any time and without restrictions, information about the existence of data that concerns him or her must be guaranteed.
● Principle of restricted access and circulation: Treatment is subject to the limits derived from the nature of the personal data, the provisions of this law and the Constitution. In this sense, the Treatment can only be carried out by people authorized by the Owner and/or by the people provided for in Law 1581 of 2012.
● Principle of confidentiality: all persons involved in the Processing of personal data that are not public in nature are obliged to guarantee the confidentiality of the information, even after their relationship with any of the tasks included in the Processing has ended, and may only supply or communicate personal data when this corresponds to the development of the activities authorized in Law 1581 of 2012 and in the terms thereof.
IV. RESPONSIBLE :
● Company name: HELIX BODY JEWELRY
● Address: Kilometer 26 via Girardota - Guarne
● City: Girardota - Colombia
● Email: contacto@helixbj.com
● Telephone: +57 3147403150
V. PROCESSING TO WHICH PERSONAL DATA/PURPOSES WILL BE SUBJECTED:
We use the personal information that you provide to us for purposes including, but not limited to:
● We use your email address to help you create, manage and maintain an account on our Services, to communicate with you, provide you with updates or information you request, respond to comments and questions.
● We use your email address and phone number to send you security alerts, shipping notifications and other administrative messages and to provide customer support.
● Fill orders for products, services or information
● Track and confirm orders online
● Deliver products
● Manage any loyalty or fidelity program
● Provide customer service, respond to requests, complaints or claims.
● Manage giveaways, promotions or surveys.
● Offer new products and services.
● Improve the effectiveness of our web portal, our marketing efforts and our services and offers.
● Conduct research and analysis for commercial purposes.
● Evaluate the quality of our products and carry out studies on consumer habits, preference, purchase interest, product testing, concept, service evaluation, satisfaction and others related to our products.
● Send marketing communications, offers or promotions.
● Control and prevent fraud in all its forms.
● To monitor and analyze trends, usage and activities, and improve our Services and product offerings;
● To facilitate transactions and payments;
● To record purchases you have made through our Services.
● Eventually, queries may be made in external databases to guarantee the reliability and conformity of the information that the client provides.
● Control and prevent fraud in all its forms.
If you provide us with information about other people, or if other people give us information about you, we will only use that information for the specific reason for which it was provided. Some examples include providing an address for shipping advertising, purchases sent to an address other than the buyer's as a gift, gift list.
SAW. WHAT INFORMATION DO WE COLLECT?
to. INFORMATION PROVIDED BY THE USER:
● registration and profile information: When you create an account or place an order, we ask for your first name, last name, email address, WhatsApp or phone number, ID number, payment information, shipping and billing address, neighborhood , city and department where you reside, demographic information may eventually be requested.
● Payment Information: When you make a purchase, depending on the payment option chosen, we may use a third-party service provider to handle payments for us so we only receive approval or rejection information for your payment. Payments made through the site will be processed by our payment gateway Epayco and Addi. only your information should be provided on our site. Such information must be accurate and truthful and must be kept up to date.
Our e-commerce technology platform and our payment partners Epayco have PCI, DSS certification, PCI DSS Level 1 transactional processing certification, for the secure handling of credit card information.
● COMMUNICATIONS: All our orders are confirmed via WhatsApp where we establish direct contact with our customers and we can receive additional information about you. For example, change of product, change of measurements, additions to the order, modification of address, telephone number and data that are necessary to successfully complete the provision of the service.
b. INFORMATION WE COLLECT WHEN USING OUR SITE:
● Location Information: When you use our Services, we receive your precise location information. We also infer your more general location information (for example, your IP address may indicate your more general geographic region).
● Device information: We receive information about the device and software you use to access our Services, including Internet Protocol (IP) address, web browser type, operating system version, carrier, and device. manufacturer, app installs, device identifiers, mobile advertising identifiers, and push notification tokens.
● usage information: To help us understand how you use our services and help us improve them, we automatically receive information about your interactions with our Services, such as the pages or other content you view, the searches you perform, the purchases you make, and the dates and hours. of your visits.
● User Feedback: We receive information about ratings and comments that you post when you use our Services.
c. INFORMATION WE RECEIVE FROM THIRD PARTIES:
● Information from Third Party Services: If you choose to link our Services to a third party account, we may receive information about you, including your profile information, and your use of the third party account. If you want to limit the information available to us, you should visit the privacy settings of your third-party accounts to learn your options, for example, to log in to our site, you can choose whether to do so with your Google or Facebook account.
VII. PROCESSING OF SENSITIVE PERSONAL DATA
According to Law 1581 of 2012, sensitive personal data are “those that affect the privacy of the Owner or whose improper use may generate discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership in unions, social organizations, human rights organizations or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties as well as data related to health, sexual life and biometric data.” Within them, the data of minors is also recognized.
HELIX BODY JEWELRY must process data of this nature, in the development of relationships with its employees and/or candidates in selection processes, especially those related to health, and eventually biometric data in the implementation of security measures in security systems. access control to its facilities or to some physical spaces, in any case in the processing of said data special security measures will be adopted, and in any case when authorization for the processing of sensitive data is to be requested, the owner will be warned of the purposes. for which they will be processed and they will be informed that they have the right to refrain from answering questions about sensitive data or about data of children and adolescents.
VIII. PROCESSING THE DATA OF MINORS
HELIX BODY JEWELRY tries in the development of its economic activity not to collect information from minors. If you are under 18 years of age, your data may only be entered into our databases with the express consent of the legal representative of the minor or tutor.
Without prejudice to the above and in the event that data is provided to us by minors, said data will be subject to the rules indicated below.
Special requirements for the processing of personal data of children and adolescents.
The Processing of personal data of children and adolescents is prohibited, except when it involves data of a public nature, in accordance with the provisions of article 7 of Law 1581 of 2012 and when said Processing complies with the following parameters and requirements:
IX. AUTHORIZATION
For the processing of personal data by HELIX BODY JEWELRY, the prior, informed and express authorization of the Owner is required, which will be obtained by any verbal means (leaving its record), written, physical or electronic that may be the subject of consultation. later; without prejudice to the exceptions provided for by law, it being understood in any case that this authorization is given when registering in our offices or on the website and accepting the collection and processing of data. HELIX BODY JEWELRY will retain proof of such authorizations in an appropriate manner, respecting the principles of confidentiality and privacy of information.
Any changes to these policies or the way we use your Personal Information will be announced and published by notice prior to the application of the new conditions, and all modified terms will automatically take effect five (5) days after the appearance of a notice on our website.
X. cases in which Helix Body Jewelry does not require authorization for the processing of the data, or for the delivery of the data in its possession
XI. DATA SECURITY: We use certain organizational security measures, physical techniques that are designed to ensure the integrity and security of the personal information we process. We take steps to ensure that your personal information is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure and we cannot guarantee the security of the information you provide to us, we will do everything possible and within our power to ensure that the information you provide to us is under our domain and control. avoiding its alteration, loss, consultation, unauthorized or fraudulent use or access.
XII. VALIDITY OF THE POLICY: This Policy comes into effect on April 20, 2020.
The Personal Data provided will be kept as long as its deletion is not requested by the interested party (unless it is requested and there is a legal duty to preserve it). The HELIX BODY JEWELRY databases will have an indefinite period of validity since their processing will be necessary as long as HELIX BODY JEWELRY subsists and the development of its corporate purpose, in any case this term will not be less than (50) years. This version of this policy is effective from the date of its publication, which completely replaces any previous provision or data processing policy, and will be in force indefinitely and for as long as HELIX BODY JEWELRY carries out the activities described. in it and they correspond to the processing purposes that inspired this policy.
Any modification made to this policy will be published in the same form as the initial policy.
XIII. RIGHTS OF THE OWNERS: The owners of personal data have the following rights:
d. Know, update and rectify your personal data in front of those responsible or in charge of the treatment, in the case of HELIX BODY JEWELRY. This right may be exercised, among others, against partial, inaccurate, incomplete, divided, misleading data, or those whose processing is expressly prohibited or has not been authorized.
and. Request proof of authorization granted to the person responsible for treatment, except when it is expressly excepted as a requirement for treatment, in accordance with the provisions of article 10 of Law 1581 of 2012.
F. Be informed by the person responsible or in charge of the treatment, upon request, regarding the use that has been given to your personal data.
g. Submit complaints to the Superintendency of Industry and Commerce for violations of the provisions of this Policy and the regulations that regulate it.
h. Voluntarily revoke the authorization and/or request the deletion of the data when the processing does not respect constitutional and legal principles, rights and guarantees. The revocation and/or deletion will proceed when the Superintendency of Industry and Commerce has determined that in the processing the person responsible or in charge has engaged in conduct contrary to the Constitution and the Law.
Yo. Access free of charge to your personal data that has been processed.
XIV. PROCEDURE FOR EXERCISE OF RIGHT BY THE OWNERS: The owners of personal data must direct their queries, requests or complaints to the email: contacto@helixbj.com
j. Queries: HELIX BODY JEWELRY must respond to queries within a period of ten (10) business days from the date it was received. When it is not possible to meet this time, the interested party must be informed, expressing the reasons for the delay and the date on which the query will be answered within a period of no more than five (5) days.
k. Claims: The owner or successor in title who considers that the information contained in a database must be corrected, updated or deleted, or when they notice the alleged breach of any of the duties contained in the law or in this policy, may present a claim to HELIX BODY JEWELRY, which will be processed under the following rules:
● The claim will be made by request addressed to the person responsible or in charge of the treatment, to the email contacto@helixbj.com with the identification of the owner, the description of the facts that give rise to the claim, the address, and accompanying the documents that are desired. enforce.
● If the claim is incomplete, HELIX BODY JEWELRY will require the interested party to correct the deficiencies within five (5) days following receipt of the claim.
● After two (2) months from the date of the request, without the applicant presenting the required information, it will be understood that the claim has been abandoned.
● The maximum term to address the claim will be fifteen (15) business days counted from the day following the date of receipt. When it is not possible to address the claim within said term, the interested party will be informed of the reasons for the delay and the date on which their claim will be addressed, which in no case may exceed eight (8) business days following the expiration of the first term.
● The owner or successor in title may file a complaint with the Superintendence of Industry and Commerce, once the consultation or claim process has been exhausted before the person responsible or in charge of the treatment without having had a satisfactory response to their request.
l. Revocation of authorization and/or deletion of data: Owners may at any time request HELIX BODY JEWELRY to delete their personal data and/or revoke the authorization granted for their processing, by submitting a claim, in accordance with the provisions of article 15 of Law 1581 of 2012, Decree 1377 of 2013 and the procedure indicated in this policy. Said revocation may be requested by the owner or successor in title to the email contacto@helixbj.com . If the respective legal term expires, HELIX BODY JEWELRY has not deleted the personal data, the owner will have the right to request the Superintendence of Industry and Commerce to order the revocation of the authorization and/or the deletion of the personal data. However The above, personal data must be preserved when required to comply with a legal or contractual obligation.
LEGITIMIZED TO ADVANCE CLAIMS AND INQUIRIES AND TO WHOM INFORMATION ABOUT THE OWNERS MAY BE SUPPLIED:
To the owners of the data, their heirs or representatives at any time and through any means when they request it from HELIX BODY JEWELRY.
To judicial or administrative entities in the exercise of functions that raise any requirement to the company so that the information is delivered.
To third parties who are authorized by Law.
To third parties to whom the Data Owner expressly authorizes the delivery of the information and whose authorization is delivered to HELIX BODY JEWELRY
CONTACT: To learn about HELIX BODY JEWELRY's data protection policy, you can contact +57 3123960310, or by email: contacto@helixbj.com where you can make the respective request.