This Privacy and Personal Data Processing Policy (the "Policy") describes how Tekbees collects, uses, shares, transfers, and protects personal data, and how data subjects can exercise their rights. This Policy is adopted in compliance with Colombian Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015), and other applicable Colombian regulations, as well as the data protection laws applicable in other jurisdictions where we operate, including the European Union General Data Protection Regulation ("GDPR") and U.S. state privacy laws, where applicable.
In this Policy, "Tekbees" refers to the applicable entity above.
2.1 Tekbees as controller. Tekbees acts as a data controller with respect to the personal data of: Website visitors, people who contact us or subscribe to our communications or our blog, people who respond to our marketing campaigns on third-party platforms, representatives of clients and prospective clients, vendors and their representatives, office visitors, and event attendees. This Policy applies fully to that processing.
2.2 Tekbees as processor (UNICUS identity verification and client engagements). When an End User is verified through the UNICUS platform, or when Tekbees processes personal data in the course of a software development project or another service provided to a Client, Tekbees acts as a data processor on behalf of and under the instructions of that Client, who is the data controller. In these cases:
3.1 End User data (UNICUS identity verification). Under our Clients' instructions, we may process: (a) identification data contained in or extracted from the identity document (names, surnames, document type and number, date of birth, nationality, sex, issue and expiry dates, and other document fields); (b) images of the identity document and its security features; (c) photographs and videos captured during the verification session; (d) biometric data, such as three-dimensional face maps or templates and facial measurements generated by the 3D facial recognition technology used by the platform; (e) results of the verification process and liveness checks; (f) device and network technical data (IP address, device type, operating system, session metadata, date and time); and (g) where instructed by the Client and permitted by law, results of checks against external registries or databases.
3.2 Website visitor, blog, and marketing campaign data. Browsing and technical data collected through cookies and similar technologies (IP address, pages visited, date and time, referring URL, browser and device attributes, approximate geographic location), as well as data you provide in contact or subscription forms (name, email, company, role, phone number). We also receive the data you choose to provide through contact or lead-generation forms on third-party platforms (for example, LinkedIn or Meta) when you respond to our campaigns, as well as through subscriptions to or comments on our blog and content. Those platforms act as independent controllers of the processing they perform within their own services, under their own privacy policies, which we recommend reviewing.
3.3 Client, prospective client, and vendor data. Business contact details of their representatives (name, role, email, phone), contractual, billing, and payment information, and communications with us.
3.4 Office visitor and event attendee data. Name, email, phone number, company, date and time of visit and, where duly signposted video surveillance systems exist, the images they capture. During outbreaks of infectious diseases, and only where permitted or required by law, we may request health information necessary to ensure a safe visit.
3.5 Sensitive data. Biometric data is sensitive data under Law 1581 of 2012 and other applicable laws. Its processing by Tekbees as processor is carried out solely under the instructions of the controller Client, who must obtain the data subject's prior, express, informed and, where applicable, qualified authorization. Data subjects are not obligated to authorize the processing of their sensitive data. If authorization is not granted, it may not be possible to complete identity verification through that method, without prejudice to alternative mechanisms the Client must provide or manage where required by applicable law. Tekbees applies enhanced security measures to sensitive data and does not use it for purposes other than providing the service engaged by the Client and maintaining and improving the Service's security and fraud detection mechanisms, in accordance with the Client's instructions and as described in Section 4.1.
4.1 As processor (under the Client's instructions): verifying and authenticating End Users' identity; performing liveness and fraud prevention checks; generating verification results and making them available to the Client; providing technical support; maintaining, training, and improving the Service's fraud detection and security mechanisms — using for this purpose, where the Client so instructs in the data processing agreement, information from sessions identified as fraudulent or suspicious, with the application of minimization measures and, where technically feasible, anonymization or obfuscation of identifying data before incorporation into training datasets —; and complying with the Client's other lawful instructions. The legal basis is secured by the controller Client (generally, the data subject's authorization and/or compliance with the Client's legal obligations, such as know-your-customer — KYC — regulations).
4.2 As controller, we process personal data to:
4.3 If we identify a new purpose not covered by this Policy, we will update it and, where required by law, request a new authorization from the data subject.
5.1 We use first-party and third-party cookies, pixels, and similar technologies to: enable essential Website functions; analyze usage and performance; remember your preferences; and, with your consent where required by law, conduct advertising and campaign measurement.
5.2 Types of cookies used: strictly necessary, performance/analytics, functionality, and targeting/advertising (including third-party cookies such as analytics tools and advertising pixels).
5.3 You can manage or delete cookies through your browser settings. More information is available at www.allaboutcookies.org, and you can manage interest-based advertising at www.aboutads.info/choices. Disabling certain cookies may affect Website functionality. The Website does not currently respond to browser "Do Not Track" signals, as there is no uniform industry standard.
6.1 Tekbees does not sell personal data. Tekbees does not sell, rent, or trade biometric data under any circumstances, nor does it share biometric data for behavioral advertising purposes. Where an applicable privacy law defines "sale" or "sharing" broadly in relation to advertising cookies, Tekbees will honor applicable opt-out rights.
6.2 We may share personal data with:
7.1 Tekbees operates from Colombia and the United States and uses cloud infrastructure that may be located in other countries. Consequently, personal data may be subject to international transfer or transmission.
7.2 Where this occurs, Tekbees will comply with the applicable regime: (a) for data subject to Colombian law, transfers will be made to countries offering an adequate level of protection under the criteria of the Superintendence of Industry and Commerce (SIC), or with the data subject's authorization, or under a legal exception, and transmissions to processors will be covered by transmission agreements compliant with Article 25 of Decree 1377 of 2013; (b) for data subject to the GDPR, adequacy decisions or standard contractual clauses approved by the European Commission will be used; and (c) for data subject to U.S. law, applicable state requirements will be met.
8.1 We retain personal data only for as long as necessary to fulfill the purposes described, comply with legal obligations (for example, accounting and tax retention periods), resolve disputes, and enforce our agreements.
8.2 End User data processed as processor is retained for the period instructed by the controller Client in the data processing agreement and, upon its expiry, is securely deleted or irreversibly anonymized, unless a legal retention obligation applies. Biometric data is retained only for the time strictly necessary to provide the service in accordance with the Client's instructions and applicable law, and is permanently destroyed upon expiry of that period. Information from fraudulent or suspicious sessions used to improve fraud detection mechanisms is retained for the period defined in the data processing agreement and is irreversibly anonymized or deleted upon expiry of that period. Backup copies are deleted or overwritten within reasonable backup and retention cycles, in accordance with our security policies.
8.3 At the end of the retention period, data is securely deleted or irreversibly anonymized. Aggregated or anonymized information does not identify any individual, and Tekbees will not attempt to re-identify it.
Tekbees implements reasonable technical, administrative, and physical measures, proportional to the nature of the data, to protect it against loss, unauthorized access, alteration, misuse, or disclosure, including encryption in transit and at rest, access controls, monitoring, environment segregation, and staff training. Sensitive data, including biometric data, is protected with a standard of care equal to or greater than that applied to other confidential information. No system is infallible: if you suspect unauthorized access to your data, contact us immediately at privacy@tekbees.com. In the event of security incidents affecting personal data, Tekbees will apply its incident management procedure and make the notifications required by applicable law (including reporting to the Colombian Superintendence of Industry and Commerce where applicable).
10.1 Under Law 1581 of 2012 and other applicable regulations, you have the right to: (a) know, update, and rectify your personal data; (b) request proof of the authorization granted; (c) be informed of the use made of your data; (d) file complaints with the Superintendence of Industry and Commerce for violations of the data protection regime; (e) revoke your authorization and/or request deletion of your data where no legal or contractual duty prevents it; and (f) access your data free of charge.
10.2 If the GDPR or another foreign law applies to you, you may also have rights of access, rectification, erasure, restriction, portability, objection, the right not to be subject to decisions based solely on automated processing with significant legal effects, and the right to withdraw your consent at any time. If you reside in a U.S. state with an applicable privacy law, you may have rights of access, correction, deletion, portability, and opt-out of targeted advertising, as well as the right not to be discriminated against for exercising them.
10.3 Automated decision-making. UNICUS biometric verification processes use automated algorithms to compare the End User's face with their identity document. The final decision to provide or deny a service to the End User rests with the controller Client, who must assess whether human review, alternative mechanisms, claims handling, or other safeguards are required under applicable law. End Users may request, through the Client, information about the general logic applied, as well as human review of a verification result where applicable.
11.1 The area responsible for handling inquiries and claims is the Tekbees privacy team, reachable at **privacy@tekbees.com**.
11.2 Inquiries. Data subjects (or their successors and duly accredited representatives) may inquire about their personal data. Inquiries will be answered within a maximum of ten (10) business days from receipt. If it is not possible to respond within that period, the data subject will be informed of the reasons for the delay and the response date, which will not exceed five (5) business days following the expiry of the initial period.
11.3 Claims. Where data subjects believe their data should be corrected, updated, or deleted, or identify a suspected breach, they may file a claim including: identification of the data subject, description of the facts, contact address, and supporting documents. If the claim is incomplete, the data subject will be asked to complete it within five (5) days; if two (2) months pass without a response, the claim will be deemed withdrawn. Claims will be resolved within a maximum of fifteen (15) business days from the day after receipt; if this is not possible, the data subject will be informed of the reasons and the response date, which will not exceed eight (8) business days following the expiry of the initial period.
11.4 To verify your identity before responding, we may request reasonable additional information. If your request concerns data we process as a processor on behalf of a Client, we will inform you and route your request to that controller Client.
11.5 You may also file complaints with the Superintendence of Industry and Commerce (www.sic.gov.co) in Colombia or, where applicable, with the data protection authority of your jurisdiction (for example, your national supervisory authority in the EU or your state attorney general in the United States).
The Website and Tekbees' commercial communications are directed at a business audience and at adults; we do not knowingly collect data from individuals under 18 through them. Where a Client instructs the identity verification of a minor through UNICUS, it is the controller Client's responsibility to ensure the legal basis and the authorization of the minor's legal guardian, with full respect for the minor's prevailing rights. If we learn that we have collected a minor's data without due authorization, we will promptly delete it.
The Website may contain links to or integrations with third-party sites and services whose privacy practices are beyond Tekbees' control. We recommend reading those third parties' privacy policies before providing them with any information.
14.1 This Policy is effective as of the date indicated in the header. Tekbees' databases will remain in force for as long as necessary to fulfill the processing purposes and applicable legal obligations.
14.2 Tekbees may amend this Policy at any time. Changes will be published on the Website with their update date and, where substantial, will be communicated to data subjects by appropriate means and, if required by law, new authorization will be requested.
Tekbees — Privacy team
Email: privacy@tekbees.com | General information: info@tekbees.com
Phone USA: (+1) 408 620 7677 | Phone Colombia: (+57) 601 4576958
TEKBEES S.A.S. — Calle 85 # 12-66, Bogotá, Colombia
TEKBEES INC. — 455 Market St Ste 1940 PMB 494218, San Francisco, CA 94105, USA