
Data protection and regulatory compliance
We handle the information of our clients, users and partners in accordance with Colombia's Law 1581 of 2012 and Decree 1377 of 2013, with technical and organizational measures to protect every piece of data entrusted to us.
LEGAL FRAMEWORK
Compliance with Law 1581 of 2012
Law 1581 of 2012, regulated by Decree 1377 of 2013, establishes Colombia's general framework for personal data protection (Habeas Data). At Shark Technology we align our data collection, use and storage processes with these principles, and apply them both in our own platforms and in the projects we build for our clients.
PRINCIPLES
How we handle information
These principles guide every system we build, from contact forms to full institutional platforms.
Purpose limitation
Each piece of data is collected for a specific, disclosed purpose and is not used for other ends without authorization.
Data minimization
We request only the information necessary to provide the service or fulfill the stated purpose.
Security
We apply technical controls — encryption in transit, access control and monitoring — to protect information against loss or unauthorized use.
Confidentiality
Access to personal data is restricted to the teams that need it to operate the service.
DATA SUBJECT RIGHTS
Your rights over your information (Habeas Data)
As a data subject, the law grants you the following rights over any information we process:
Know, update and rectify your personal data.
Request proof of the authorization granted for the processing of your data.
Be informed about how your information has been used.
Revoke the authorization and/or request deletion of your data when legal principles are not respected.
Access your processed personal data free of charge.
File complaints with Colombia's data protection authority (Superintendencia de Industria y Comercio) for violations of the law.
TECHNICAL MEASURES
Security measures we apply
Beyond regulatory compliance, we apply technical practices to reduce risk to the information we manage.
Encryption in transit
Connections to our platforms use HTTPS/TLS to protect information while it travels.
Access control
Internal systems require authentication and limit access according to each person's role.
Verifiable traceability
Actions by our AI agents are recorded in an auditable way, including anchoring to a public blockchain for critical operations.
Continuity and backup
We keep periodic backups of critical information to reduce the risk of loss.
Have questions about how we handle your data?
Write to us and we'll be glad to answer any questions about this policy or to exercise any of the rights described here.
