Personal data processing policy
This policy sets the rules for MicroPOS databases managed by Digital Consulting Plus S.A.S. and Digital Consulting Plus LLC.
Last updated: September 1, 2026
1. Legal framework and scope
Where Colombian law applies, processing follows Law 1581 of 2012, Decree 1377 of 2013 as compiled in Decree 1074 of 2015, and applicable authority instructions. Where EU GDPR or another mandatory territorial law applies, those rules and rights also apply.
2. Controllers and principles
Digital Consulting Plus S.A.S. and Digital Consulting Plus LLC apply legality, purpose limitation, transparency, restricted access, security, confidentiality, minimization and accountability to prospects, customers, users, suppliers and commercial contacts.
3. Data and purposes
We process contact, business, market, commercial, contractual, billing, payment, support, security and preference data to manage leads, quote, contract, implement, operate, support, bill and protect MicroPOS, comply with legal duties and send authorized communications.
4. Consent and sensitive data
When consent is required it must be informed and verifiable. The commercial form is not intended to collect sensitive data or information about minors.
5. Data-subject rights
Data subjects may access, update, correct and, where applicable, delete their data; request proof of consent and information about use; withdraw consent; object or restrict processing; and exercise any additional rights provided by applicable law.
6. Requests and complaints
Requests must identify the data subject and describe the right being exercised. Colombian statutory response periods apply when Law 1581 of 2012 governs the processing; other jurisdictions follow their mandatory deadlines.
7. Processors and international transfers
We may use infrastructure, hosting, communications, analytics, support and payment processors. Transfers and transmissions use the legal bases, contracts and safeguards required by the applicable jurisdiction.
8. Security, retention and deletion
We use reasonable access, authentication, session, encryption, backup and file controls. Data is retained only as necessary for the purpose, relationship and legal periods, then deleted, anonymized or blocked as appropriate.
9. Contact and validity
Rights requests are received through the configured service email. This policy remains effective while relevant databases or processing responsibilities exist, and material updates are published here.
