Skip to content
sBPO NEXT-GEN BPO
ENES
Back to home

Legal

Personal Data Processing Policy

Privacy notice of SMARTBPO SAS for data subjects who interact with this website and with our commercial channels, under Colombian Law 1581 of 2012, Decree 1377 of 2013 and —where applicable— the European Union’s General Data Protection Regulation (GDPR).

Version
1.0
Last updated
2 August 2026
Scope
smartbpo.co and commercial channels

Contents

  1. Data controller
  2. Scope
  3. Personal data we collect
  4. Purposes of processing
  5. Authorisation and legal basis
  6. Your rights and how to exercise them
  7. Data about minors
  8. Information security
  9. Processors, third parties and international transfers
  10. Retention and deletion
  11. Data we process on behalf of our clients
  12. Cookies and similar technologies
  13. Validity and changes

1. Data controller

SMARTBPO SAS, a Colombian company with tax ID (NIT) 900.818.261-2, domiciled in Bogotá D.C., Colombia and supervised by the Superintendency of Companies, is the controller of the personal data collected through this website and our commercial channels.

  • General email: hola@smartbpo.co
  • Data Protection Officer (DPO): Daniel Serrano — dpo@smartbpo.co
  • Registered office: Bogotá D.C., Colombia

The Data Protection Officer is the single point of contact for enquiries, complaints and requests relating to personal data, and for liaison with Colombia’s Superintendency of Industry and Commerce (SIC) and with European Union data protection authorities where applicable.

2. Scope

This policy applies to the personal data of:

  • People who complete the contact form on smartbpo.co or book a meeting with our team.
  • Commercial contacts at current and prospective clients.
  • People who write to us directly by email.

It does not cover the data processing SMARTBPO SAS carries out on behalf of its clients as part of an outsourcing operation. That case is explained in section 11.

3. Personal data we collect

Through the contact form on this site we collect only what you provide voluntarily:

  • Full name
  • Company
  • Email address
  • Phone number
  • Industry and service of interest
  • The content of the message you choose to send us

None of these fields constitutes sensitive data under article 5 of Colombian Law 1581 of 2012. Please do not include sensitive data —health, biometric, racial or ethnic origin, political or religious beliefs, data about minors— in the message field.

We do not buy databases and we do not collect personal data from third-party sources without your knowledge.

4. Purposes of processing

We process your personal data exclusively to:

  1. Respond to your request, enquiry or message.
  2. Prepare and present commercial proposals for our services.
  3. Coordinate and schedule meetings, demos or calls.
  4. Follow up on the commercial relationship while it is active.
  5. Comply with legal, accounting and contractual obligations.

We do not use your data to build automated profiles, we do not make automated decisions with legal effects on you, and we do not transfer or sell your data to third parties for commercial purposes.

5. Authorisation and legal basis

Processing takes place with your prior, express and informed authorisation, which you give by ticking the corresponding box on the contact form or by writing to us voluntarily.

Applicable frameworks:

  • Law 1581 of 2012 and Decree 1377 of 2013 (Colombia) — the minimum baseline for any data processed in or from Colombia.
  • GDPR — where the data subject is located in the European Union. In those cases the lawful basis is your consent or the legitimate interest in responding to a commercial request you initiated.
  • Law 1755 of 2015 — response deadlines for enquiries and complaints.

You may withdraw your authorisation at any time, without affecting the lawfulness of processing carried out before the withdrawal.

6. Your rights and how to exercise them

As a data subject you have the right to:

  • Access, free of charge, the data we hold about you.
  • Know, update and rectify partial, inaccurate, incomplete or outdated data.
  • Request proof of the authorisation you granted.
  • Withdraw your authorisation or request deletion of your data, where no legal or contractual duty prevents it.
  • Object to the processing and file complaints with Colombia’s Superintendency of Industry and Commerce.

If you are located in the European Union, you additionally have the right to data portability, to restriction of processing and to erasure under the GDPR.

How to exercise them

Write to dpo@smartbpo.co with the subject line “Personal data request”, stating your name, the right you wish to exercise and a means of contact. Response times:

  • Enquiries: up to 15 business days.
  • Complaints: up to 10 business days, extendable as permitted by law.
  • GDPR requests: up to 30 calendar days.

7. Data about minors

This site and our commercial channels are intended for adults acting on behalf of an organisation. We do not knowingly collect personal data about minors. If we detect that we have received data about a minor without their legal guardian’s authorisation, we delete it.

8. Information security

SMARTBPO SAS maintains an internal information handling and data protection policy that applies across its entire operation. Controls in force include:

  • Encryption in transit (TLS 1.2 or higher) and at rest for stored information.
  • Multi-factor authentication (MFA) for access to systems containing data.
  • Role-based access control: each person accesses only what is strictly necessary for their function.
  • Audit logs of access, queries and exports.
  • Confidentiality agreements and mandatory training for every team member with access to data.

No system is infallible. In the event of a security incident affecting your personal data, we will notify the competent authority and the affected data subjects within the applicable legal deadlines.

9. Processors, third parties and international transfers

To run this site we use providers that may process data on our behalf:

  • Netlify — website hosting and receipt of contact form submissions. Data is stored on servers located in the United States.
  • Google — meeting scheduling service and corporate email. When you book a meeting, your data is additionally processed under Google’s terms.
  • Google Fonts — the site’s typefaces load from Google servers, which receive your IP address in order to deliver them.

These international transfers are made to jurisdictions and providers with equivalent or sufficient security standards, and under the corresponding data processing agreements. We do not transfer personal information to jurisdictions lacking such standards.

We keep an up-to-date register of our processors and sub-processors, available on request.

10. Retention and deletion

We keep your data for as long as necessary to fulfil the purpose for which it was collected and, after that, for the periods required by applicable legal, accounting or contractual obligations.

Once that period has elapsed, the data is securely deleted and the deletion is documented. Backup copies follow the same retention cycle as the original data.

11. Data we process on behalf of our clients

As part of our outsourcing services, SMARTBPO SAS processes data belonging to our clients’ end users. In those cases we act as the processor and the client is the controller: the client defines the purposes, obtains the authorisations and answers to the data subjects.

Every project is governed by the corresponding contract and, depending on the case, by a Data Processing Agreement (DPA) under the GDPR or a Business Associate Agreement (BAA) under HIPAA. Each account inherits the strictest regime that applies to it.

If you are an end user of one of our clients and wish to exercise your rights, please contact that company first. You may also write to us at dpo@smartbpo.co and we will route the request.

12. Cookies and similar technologies

This site does not use analytics, advertising or cross-site tracking cookies. There is no advertising profiling and no third-party pixels.

The only data transfer that occurs simply by visiting the site is your IP address reaching Google Fonts servers and Netlify’s infrastructure, which is necessary to deliver the page to you.

13. Validity and changes

This policy is effective from its publication date and is reviewed at least once a year, or sooner if there is a relevant regulatory change or a change in how we process data.

When there are substantial changes we will publish them on this same page with a new update date. We recommend reviewing it periodically.

For any question about this policy, write to dpo@smartbpo.co.

© SMARTBPO SAS · Tax ID 900.818.261-2. All rights reserved. · Home