top of page

Privacy Policy and Personal Data Processing

1. Identification of the Data Controller

Nalanda Analytica SAS (hereinafter, "Nalanda Analytica", "the Firm" or "we") is a simplified joint-stock company incorporated under the laws of the Republic of Colombia, with its registered office in Bogotá DC

Company name: Nalanda Analytica SAS

Address: Bogotá DC, Colombia

Email: contacto@nalandaanalytica.com

Website: www.nalandaanalytica.com

Regulatory Authority (Colombia): Superintendency of Industry and Commerce (SIC) — www.sic.gov.co

Supervisory authority (EEA): Data protection authority of the competent Member State

2. Regulatory framework

This Privacy Policy is based on the following provisions:

Colombia:

  • Statutory Law 1581 of 2012 (General Regime for the Protection of Personal Data)

  • Decree 1377 of 2013 (regulating Law 1581/2012), incorporated into the Single Regulatory Decree of the Trade, Industry and Tourism Sector 1074 of 2015

  • Law 1266 of 2008 (financial and credit data)

  • External Circular SIC 002 of 2015 and other instructions from the Superintendency of Industry and Commerce

International:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), applicable where the processing involves persons located in the European Economic Area

  • OECD Guidelines on Privacy Protection and Cross-Border Flows of Personal Data

3. Scope of application

This Policy applies to:

  • All personal data collected through the website www.nalandaanalytica.com , including the contact form and tracking technologies (cookies).

  • Personal data of clients, contractors, suppliers, collaborators and other natural persons with whom Nalanda Analytica maintains or has maintained contractual or commercial relationships, to the extent that such data are accessible or managed through the Site.

This Policy does not apply to the processing of data within the framework of service provision contracts entered into with clients, which is governed by the specific agreements signed with each client.

4. Definitions

For the purposes of this Policy, the definitions established in Article 3 of Law 1581 of 2012 and in Article 4 of the GDPR are adopted, as applicable:

  • Personal data: Any information linked to or that can be associated with one or more specific or identifiable natural persons.

  • Sensitive data: Data that affects the privacy of the data subject or whose misuse could lead to discrimination (racial origin, health status, sexual orientation, biometric data, political or religious beliefs, among others). Nalanda Analytica does not collect sensitive data through the Site.

  • Data Subject: Natural person whose data is being processed.

  • Data controller: The person who decides on the purpose, means, and extent of the processing. In this case: Nalanda Analytica SAS.

  • Data processor: Person who carries out the processing on behalf of the controller (e.g., technology providers).

  • Processing: Any operation on personal data (collection, storage, use, circulation, deletion, among others).

  • Authorization: Prior, express and informed consent of the data subject for the processing of their personal data.

  • Transfer: Sending personal data to a recipient located inside or outside the country.

5. Personal data collected

5.1 Data supplied directly by the User

Through the Site's contact form, the User may voluntarily provide:

  • Full name

  • Email address

  • Phone number

  • Position and organization to which he/she belongs

  • Message or query

Providing this data is voluntary. However, refusing to provide it may prevent Nalanda Analytica from processing the User's request.

5.2 Automatically Collected Data

When browsing the Site, the following data is automatically collected through cookies and similar technologies:

  • IP Address

  • Browser type and version

  • Device operating system

  • Pages visited and time spent

  • Source URL (referrer)

  • Date and time of access

For more details on the use of cookies, see section 9 of this Policy and the Cookie Policy included in the Site's Terms and Conditions of Use.

6. Purposes of the processing and legal basis

Finalidad
Base jurídica (Colombia)
Base jurídica (GDPR)
Cumplimiento de obligaciones legales

Obligación legal

Art. 6.1(c) — obligación legal

Cookies analíticas y de preferencias

Autorización del titular

Art. 6.1(a) — consentimiento

Cookies esenciales para el funcionamiento del Sitio

Necesidad técnica

Art. 6.1(f) — interés legítimo

Análisis estadístico y mejora del Sitio

Interés legítimo de la Firma

Art. 6.1(f) — interés legítimo

Envío de comunicaciones comerciales sobre servicios de la Firma

Autorización del titular

Art. 6.1(a) — consentimiento

Atender solicitudes de contacto e información

Autorización del titular / ejecución de relación precontractual

Art. 6.1(b) — ejecución de contrato o medidas precontractuales

Nalanda Analytica does not use personal data collected through the Site for automated decision-making with legal or significant effects on the data subject, nor for behavioral profiling for purposes other than those stated.

7. Rights of the holders

7.1 Rights under Law 1581 of 2012 (holders in Colombia)

Data subjects have the following rights, in accordance with Article 8 of Law 1581 of 2012:

  • To know the personal data that the Firm has about them.

  • Update and correct your data when it is inaccurate, incomplete, or has changed.

  • Request the deletion of your data when there is no legal or contractual obligation to retain it, or when it has been collected without authorization.

  • Revoke the authorization granted for the treatment, unless there is a legal or contractual impediment.

  • Access your personal data free of charge at least once a month and whenever there are substantial changes.

  • File complaints with the Superintendency of Industry and Commerce when they believe their rights have been violated, once the process with the data controller has been exhausted.

7.2 Additional rights under the GDPR (data subjects in the EEA)

Holders located in the European Economic Area also have the following rights:

  • Right to data portability (Art. 20): to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another controller.

  • Right to object (Art. 21): to object to processing based on legitimate interest, including profiling.

  • Right to limit processing (Art. 18): request the temporary suspension of processing in the cases provided for by law.

  • Right not to be subject to automated decisions (Art. 22): not to be subject to decisions based exclusively on automated processing that produce significant legal effects.

7.3 Procedure for exercising rights

To exercise any of the above rights, the holder must send their request to:

contacto@nalandaanalytica.com

The request must include: (i) full name and identification of the holder; (ii) clear description of the right you wish to exercise; (iii) documents that prove the identity of the holder or the representation, if applicable.

Response times:

  • Inquiries: 10 business days (extendable by an additional 5 business days with prior notification), in accordance with Art. 14 of Law 1581/2012.

  • Claims: 15 business days (extendable for an additional 8 business days with prior notification), in accordance with Art. 15 of Law 1581/2012.

  • Applications under the GDPR: 1 calendar month (extendable for an additional 2 months in complex cases, with prior notification), in accordance with Art. 12 of the GDPR.

8. Data retention

Personal data will be kept for the time strictly necessary to fulfill the purposes for which it was collected, applying the following criteria:

  • Contact information and inquiries: up to 2 years from the last interaction, unless a contractual relationship is established that justifies a longer retention period.

  • Browsing data and analytical cookies: up to 13 months from collection, in accordance with the recommendations of the data protection authorities.

  • Customer and contractor data: during the term of the contractual relationship and for the additional period required by the applicable tax, commercial and labor regulations in Colombia (generally up to 10 years).

Once these deadlines have passed, the data will be securely deleted or anonymized.

9. Cookies and tracking technologies

The Site is operated on the Wix platform and may use the following categories of cookies:

9.1 Essential Cookies

Necessary for the basic technical operation of the Site. They do not require prior consent. Examples: session cookies, Wix security cookies.

9.2 Analytical Cookies

They allow us to analyze user behavior on the Site for statistical purposes. They require prior consent. Example: Google Analytics (_ga, _gid).

9.3 Preference Cookies

They allow the user's settings and preferences to be remembered. Prior consent is required.

9.4 Marketing Cookies

Used for tracking and segmentation for advertising purposes. They require prior consent.

Cookie management: Users can manage their preferences through the consent banner that appears upon first entering the Site, or by configuring their browser. Withdrawing consent will not affect the lawfulness of processing prior to such withdrawal.

10. Suppliers and processors

To operate the Site and provide its services, Nalanda Analytica may share personal data with the following types of data processors, who act under the Firm's instructions and are subject to confidentiality and security obligations:

Categoría de encargado
Finalidad
Ejemplos
Proveedor de almacenamiento en nube

Gestión documental interna

Microsoft, Google

Proveedor de correo electrónico

Gestión de comunicaciones

Google LLC (Google Workspace)

Proveedor de analítica web

Estadísticas de uso

Google LLC (Google Analytics)

Proveedor de plataforma web

Alojamiento y operación del Sitio

Wix.com Ltd.

Nalanda Analytica does not sell, assign or transfer personal data to third parties for the commercial purposes of those third parties.

11. International data transfers

Since Nalanda Analytica uses technology providers with servers located outside of Colombia (including in the United States and the European Union), personal data may be transferred internationally. In such cases, the Firm will adopt appropriate safeguards, which may include:

  • Standard contractual clauses approved by the European Commission (for transfers from the EEA).

  • Verification that the recipient adheres to recognized adequacy frameworks or equivalent safeguards.

  • Data transmission only to processors who offer sufficient guarantees in accordance with SIC standards.

12. Security measures

Nalanda Analytica implements reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or improper disclosure. These measures include, but are not limited to:

  • Use of HTTPS encryption protocols for data transmission on the Site.

  • Restricting access to personal data to authorized personnel with a need to know it.

  • Use of technological platforms with recognized security certifications (Wix, Google).

  • Periodic review of safety practices.

However, no data transmission or storage system is completely secure. In the event of a security breach that could affect the rights of data subjects, Nalanda Analytica will notify the SIC and, where applicable, the affected data subjects, in accordance with the timeframes and procedures established by applicable regulations.

13. Minors

The Site is not directed at individuals under the age of 18 and does not knowingly collect personal data from minors. Should Nalanda Analytica become aware that it has collected data from a minor without verifiable parental or guardian consent, it will delete that data immediately. If you have reason to believe that we have collected data from a minor, please contact us at contacto@nalandaanalytica.com

14. Policy Amendments

Nalanda Analytica reserves the right to update this Policy at any time to reflect regulatory, technological, or data processing practice changes. The updated version will be posted on the Website with the date of the last modification. Users are advised to review this Policy periodically.

15. Contact and complaints

For inquiries, to exercise your rights, or to file complaints related to the processing of personal data:

Nalanda Analytica SAS Bogotá DC, Colombia contacto@nalandaanalytica.com www.nalandaanalytica.com

If the holder believes that their request was not handled satisfactorily, they may contact:

Superintendency of Industry and Commerce (SIC) Carrera 13 No. 27-00 floors 1-5, Bogotá DC www.sic.gov.co National toll-free line: 01800-910165

Data subjects in the EEA may also lodge complaints with the data protection authority of their Member State of residence.

bottom of page