<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1047658380635052&amp;ev=PageView&amp;noscript=1">

Data Processing and Privacy Policy

Thank you for using Truora! Your trust is our most important asset and we are committed to protecting the privacy and security of your personal data, and that of third parties about whom we may be consulted. We have a dedicated privacy team committed to protecting all the personal data we collect and ensuring it is handled correctly in all the countries where we provide services. Please carefully read our Data Processing and Privacy Policy (hereinafter the "Privacy Policy"). In order to use our site and receive the services we provide, it is necessary that you read and accept this Privacy Policy, as well as our Terms and Conditions available at https://www.truora.com/en/terms-and-conditions.

1. Introduction and Objectives.

This Privacy Policy is the document that governs the management of all Truora's Databases and/or files containing Personal Data of clients, contractors, suppliers, and third parties in general, that are subject to Processing by Truora, in events where it is considered as "Controller" and/or "Processor" of the Processing of such Personal Data, pursuant to the provisions of Statutory Law 1581 of 2012, Decree 1377 of 2013, External Circular No. 02 of November 3, 2015, and other regulations that modify and/or supplement them. It also aims to establish the information management and protection policies and procedures for Truora aligned with the Information Security Policy implemented by the company, with the purpose of preserving security in the exchange, transfer, or destruction of information.

If you are located in Mexico, click on the following button to learn about the data processing and privacy policy for that country.

2. Definitions

  • Authorization: Refers to the prior, express, and informed consent of the Data Subject to carry out the Processing of personal data.
  • Privacy Notice: Refers to the verbal or written communication addressed to Data Subjects whose personal data is being processed by Truora, informing them about the existence of applicable personal data processing policies, how to access them, and the purposes for which their personal data will be used.
  • Database: Refers to the organized set of Personal Data that is subject to Processing.
  • Biometric Data: Refers to the following data: fingerprints, facial recognition, iris recognition, handwritten signature recognition, voice recognition.
  • Deleted Data: Refers to data for which express authorization from the Data Subject could not be obtained to carry out its processing or which, at the request of the Data Subject, must be deleted, or data that Truora decides to delete from its Databases.
  • Personal Data: Refers to any information linked to or that can be associated with one or more determined or determinable natural persons; to information provided by any natural or legal person who registers on our website and/or mobile applications.
  • Public Data: Refers to data qualified as such by law and data that is not semi-private, private, or sensitive. Public data includes, among others, data relating to civil status, profession or trade, status as a merchant or public servant, and data that can be obtained without any reservation.
  • Private Data: Data that by its intimate or reserved nature is only relevant to the data subject.
  • Sensitive Data: Sensitive data is understood as data that affects the privacy of the Data Subject or whose improper use may generate discrimination, such as data that reveals racial or ethnic origin, political orientation, religious or philosophical beliefs, union membership, data related to health, sexual life, and biometric data.
  • Data Processor: Natural or legal person, public or private, that by itself or in association with others, processes Personal Data on behalf of the Data Controller.
  • Data Controller: Natural or legal person, public or private, that by itself or in association with others, decides on the Database and/or the Processing of the data.
  • Processing: Any operation or set of operations on Personal Data, such as collection, storage, use, circulation, or deletion thereof.
  • Data Subject: Corresponds to the owner of the information; can be a natural or legal person whose Personal Data is subject to Processing.
  • Data Transfer: Data transfer takes place when the Data Controller and/or Processor of personal data, located in Colombia, sends information or personal data to a recipient who is also a Data Controller and is located inside or outside the country.
  • Truora: Means collectively all companies belonging to the Truora Group, namely: Truora S.A.S. identified with NIT No. 901.189.979-5, Truora Fraud Prevention identified with RFC: TFP 191219TG0, Truora Chile SpA identified with RUT No. 77.140.321-2 and Truora Tecnologia LTDA identified with CNPJ No. 34.785.867/0001-11.
  • Affiliated and/or Related Entities: Corresponds to our parent company, subsidiaries, affiliates, allies, and controlled entities.

3. Processing and Scope of Personal Data

Truora, in the development of its corporate purpose and economic activity, acts as controller and/or Processor of personal data provided by clients, employees, contractors, and/or suppliers, which will be stored in its databases and in those of entities that, by virtue of this policy, may access them.

Consequently, Truora, collects, stores, uses, transmits, transfers, suppresses, and generally processes Personal Data provided by natural and legal persons with whom it has or has had some type of relationship, of any nature (civil, commercial, and/or labor); including, but not limited to, its clients, cloud software users, partners, suppliers, contractors, employees, creditors, debtors, and shareholders.

This document covers the processing of information managed at Truora. It covers all deliveries, transfers, or handovers of medium or high confidentiality information and/or data both within the organization and with the environment of clients, suppliers, external databases, social networks, and the general public.

4. Guiding Principles

We are committed to ensuring that any Processing of Personal Data we carry out always respects the rights enshrined in our Constitution and laws. Therefore, the following are the principles that guide our behavior:

  • Quality principle: Truora seeks to ensure that Personal Data under Processing is accurate, complete, relevant, correct, and updated to fulfill the necessary purposes indicated in the comprehensive privacy notice.
  • Confidentiality principle: All persons involved in the Processing of Personal Data are required to guarantee the confidentiality of the information, even after the termination of their relationship with any of the activities that comprise such processing.
  • Consent principle: Truora obtains consent for the Processing of Personal Data in a free, specific, and informed manner, except when not required pursuant to applicable law.
  • Information principle: Truora provides complete information about the Personal Data it processes and other requirements established by law, so that data subjects can exercise their rights of informational self-determination, privacy, and personal data protection.
  • Purpose principle: The Processing of Personal Data must comply with a legitimate purpose that will be communicated to the Data Subject.
  • Freedom principle: The Processing of Personal Data can only be carried out with the prior, express, and informed consent of the Data Subject.
  • Legality principle: Truora obtains data in compliance with applicable legislation both domestically and internationally.
  • Loyalty principle: Truora does not use deceptive or fraudulent means to collect Personal Data and processes them at all times in good faith and with the utmost diligence.
  • Proportionality principle: Truora only processes Personal Data that is necessary, adequate, and relevant for the purposes indicated in our comprehensive privacy notice.
  • Accountability principle: Truora has established policies and procedures for the management of Personal Data within its organization that are mandatory and in accordance with the best international practices.
  • Security principle: Information subject to Processing must be handled with commercially reasonable technical, human, and administrative measures necessary to provide security for records, preventing their alteration, loss, unauthorized or fraudulent consultation, use, or access.
  • Veracity principle: Information subject to processing must be truthful, complete, accurate, updated, verifiable, and understandable. The Processing of partial, incomplete, fragmented, or misleading Personal Data is prohibited.

5. Use of the Privacy Policy and Information Protection.

All Processing of Personal Data shall be subject to this Privacy Policy; therefore, if a Data Subject does not agree with this Privacy Policy, they may not provide any information that must be registered in one of Truora's Databases.

Truora commits to the security of the Data provided to it and, consequently, undertakes to give it appropriate use and to maintain the required confidentiality regarding the same, in accordance with the provisions of this Privacy Policy and the existing legislation on the matter.

Personal Data may be transferred to its shareholders, Affiliated and/or Related Entities, as well as to third parties and judicial or administrative authorities, whether natural or legal persons, Colombian or foreign, in those events in which the transfer or transmission of the data is necessary to carry out the uses and activities authorized by the Data Subjects pursuant to the corporate purpose of Truora.

Truora may use service providers and data processors that work on its behalf. Such services may include system hosting and maintenance services, encryption, analytics services, email messaging services, call-center services, delivery services, payment transaction management, and solvency and address checks, among others.

6. Scope of Liability

Truora makes its best efforts to comply with the current regulatory provisions, to safeguard the information that Data Subjects have provided or that clients have transmitted. However, it is possible that due to some unforeseen external attack, a breach in the security or in the databases that protect the information may result in loss or leakage of information. Taking the foregoing into account, Data Subjects declare that they understand the risk of disclosing, sharing, or allowing access to information through electronic means and therefore release Truora from all liability when unforeseen situations violate the rights of the holders of the information.

7. Effects of the Authorization

The Authorization granted by Data Subjects is understood to be an express and informed authorization granted by them in favor of Truora, its Affiliated and/or Related Entities, and third parties determined by Truora by virtue of the development of its corporate purpose, to process their Personal Data, regardless of the means (written, oral, or through unequivocal conduct) by which it was provided.

In the event of a sale, merger, consolidation, change in corporate control, asset transfer, reorganization, or liquidation of Truora and/or its Affiliated and/or Related Entities, Truora may transfer the Personal Data of Data Subjects to the parties involved, for which, through the acceptance of this document, Truora is understood to be authorized to do so.

8. Personal Data Subject to Processing

Truora collects or is transmitted information and Personal Data belonging to the following general categories:

  • Name and surnames
  • Email address
  • Unique population registration key or country of residence and/or origin
  • Date and place of birth
  • Official Identification
  • Biometric Data
  • Sex
  • Bank accounts

Data of Minors: Truora's websites and applications are not directed at minors or persons under 18 years of age. Truora does not deliberately collect any personal information directly from persons under 18 years of age. If you believe we are inappropriately processing personal information related to a minor, we urge you to contact Truora using the information provided in the 'Contact Us' section below.

Data from publicly accessible sources: Truora obtains data through remote or local electronic, optical, and other technology communication means from publicly accessible sources, i.e., sources to which any person may have access, including telephone directories, newspapers, gazettes, official bulletins, and social media, all in compliance with applicable regulations.

9. Purposes and uses of information

Personal data provided to Truora will be processed in accordance with the following purposes for the use of information, as applicable to each Data Subject:

  • The proper execution of the contract formalized between the Data Subject and Truora.
  • Account creation for access to the Truora Platform.
  • Identity verification with any valid official document that serves to prove identity.
  • Facilitating contact between Truora and the Data Subject.
  • Improvement of Truora's commercial and promotional initiatives, as well as analysis of pages visited and searches carried out, to improve the content and articles offered by Truora and personalization thereof.
  • Development of measurement studies regarding the participation of different sectors of the population in Truora.
  • Sending information or text messages to the provided cell phone number, email, about new services, service changes and fees, payment reminders, promotions, events, and information of interest to Data Subjects in general.
  • Billing and other tax purposes.
  • Analysis of Personal Information by Truora, its shareholders, Affiliated and/or Related Entities, and third parties contracted for the development and promotion of the sale of its services.
  • Completing the profile on the Truora Platform.
  • Processing payment for acquired services.
  • Identity validation.
  • Collection of the services that Data Subjects use and the way in which they make use of them.
  • Obtaining information from other sources and combining it with that collected by Truora through the Truora Platform.
  • Review of police, criminal, or sex offender registry records.
  • Fraud detection and security matters review.
  • Receipt of criminal background check results or fraud warnings from identity verification services for Truora's fraud prevention and risk assessment work.
  • Receipt of information about the Data Subject, their activities inside and outside the Truora Platform through the Platform's partners.
  • Other communications and activities related to Truora's corporate purpose.

9 BIS. Legal Bases for the Processing of Personal Data.

  • General rule. Truora processes Personal Data based on the prior, express, and informed authorization of the Data Subject, obtained pursuant to Statutory Law 1581 of 2012 and Decree 1074 of 2015.
  • Exceptions to authorization. Pursuant to Article 10 of Law 1581 of 2012, authorization from the Data Subject will not be necessary when: (a) information is required by a public or administrative entity in the exercise of its legal functions or by judicial order; (b) data is of a public nature; (c) there are cases of medical or public health emergency; (d) processing of information authorized by law for historical, statistical, or scientific purposes; and (e) data related to the Civil Registry of persons.
  • Sensitive and biometric data. Truora may process sensitive data — including biometric data used for identity validation — only when one of the circumstances of Article 6 of Law 1581 of 2012 concurs, in particular when the Data Subject has given their explicit authorization, except in cases where it is not required by law.

10. Data Subjects' Duties and Rights

Los Titulares de los Datos Personales suministrados a Truora tendrán los siguientes derechos:

  • The right to know, update, and rectify their Personal Information free of charge;
  • The right to request proof of the existence of the authorization granted to Truora, except when expressly exempt by law as a requirement for Processing.
  • The right to be informed, upon request, about the use given to their Personal Information;
  • The right to file complaints with the Superintendency of Industry and Commerce or the competent authority for violations of current law;
  • The right to revoke authorization and request deletion of the data when it is not used in accordance with the authorized purposes;
  • The right to file inquiries and claims regarding Personal Data;
  • The right to portability of their Personal Data, under the terms and limits provided in applicable regulations;
  • The right to request human review of decisions that affect them and that have been made based solely on automated processing;
  • The right to request information about the international transfer or transmission of their Personal Data and the guarantees adopted for it.

Data Subjects whose personal information has been provided to Truora shall have the following duties:

  • The duty to provide truthful information, which may be verified by Truora for control and validation purposes.
  • The duty to keep contact information updated, with the objective of ensuring more effective and timely service delivery.

10 BIS. Automated Decisions and Human Review.

Some Truora Services, in particular Background Checks and Validators, may involve the automated processing of Personal Data, including profiling for identity verification, fraud prevention, and risk assessment purposes. The results of such processing are informative and intended to support decision-making and do not constitute, by themselves, a definitive classification of the Data Subject.

When a decision that produces legal effects on the Data Subject or significantly affects them is made based solely on automated processing, the Data Subject may request information on the criteria used and require human intervention and review of such decision.

11. Confidentiality of Personal Data.

Personal Data provided by Data Subjects will be used solely by Truora, its shareholders, Affiliated and/or Related Entities, and authorized third parties for such purposes, as established in this Privacy Policy. Data will not be used, under any circumstances, for purposes other than those for which they were provided.

12. Information Security

In compliance with the provisions of the Federal Law on Protection of Personal Data Held by Private Parties (for Mexico), Statutory Law 1581 of 2012 (for Colombia), the General Data Protection Law (for Brazil), Law 19.628 (for Chile), the General Data Protection Regulation or GDPR, and other applicable legislation, international treaties, decrees, circulars, manuals, recommendations, and/or regulations related to and applicable in Personal Data Protection and Privacy, Truora has implemented administrative, physical, and technical security measures to guarantee the protection of Personal Data.

  • 12.1. Information Retention Files under Truora's responsibility must comply with the protocols and procedures established by the information security policy:

    • The information owner's data will be stored in separate instances, with read access controls.
    • Consultation of information by unauthorized personnel must be avoided.
    • All files are encrypted when stored in the designated repository.
    • Transfers of sensitive or restricted files must be made through reliable messaging systems, preferably with information encryption.

  • 12.2. Security Incident Notification. Without prejudice to what is provided in Sections 6 and 12, in the event of a security incident that compromises the confidentiality, integrity, or availability of Personal Data and that may represent a risk or harm to Data Subjects, Truora will report such incident to the Superintendency of Industry and Commerce (SIC), through the National Database Registry (RNBD) or the channel made available by the authority, within the terms and deadlines required by applicable regulations and guidelines.

Likewise, Truora will communicate the incident to the affected Data Subjects, when appropriate, without undue delay, with the reasonably available information about the nature of the incident, its possible consequences, and the measures taken or proposed to mitigate it.

13. Media Management

Truora will implement procedures for the management of removable media in accordance with the classification scheme adopted by Truora:

  • Truora will destroy the media on which it stores confidential information when it is no longer necessary to keep it for business reasons, so that the information is unrecoverable.
  • Controls will be defined and implemented to protect media with information that must be transported.
  • Strict control of internal or external distribution of all types of media on which confidential information is stored will be maintained.
  • Classification of media will be carried out to determine the confidentiality of Data.
  • All transfers of media before being moved from a secure area (including when distributing media to individuals) will be approved.
  • A detailed inventory record of all media will be maintained.
  • The use of mobile devices must be explicitly authorized and they must comply with all security policies, standards, and guidelines defined at Truora.

14. Transfers and remissions.

Truora carries out national and international remissions and transfers of its Personal Data in accordance with the comprehensive privacy notice and in compliance with applicable legal provisions.

  • 14.1. Personal Data Exchange. When formal information exchange agreements with third parties are executed, data transfer procedures and/or protocols for Personal Data must be established that include as a minimum requirement the following security conditions:

    • Establish responsibilities for control, dispatch, and receipt.
    • Mechanisms to ensure traceability and non-repudiation.
    • Establish responsibilities and obligations in the event of information security incidents, such as data loss.
    • Establish contractual safeguards regarding information ownership, personal data care, respect for copyright, software licenses, and similar legal considerations.
    • Establish formal confidentiality agreements with information recipients.
  • 14.2. Information Collection in Exchanges. All information to be managed or processed by Truora that is considered high or medium confidentiality, or its equivalent, will be received in a format previously established for such transmission between Truora and its clients and/or suppliers, through secure and encrypted means.

  • 14.3. Information Loading Information received through exchanges is processed using extraction, transformation, and loading processes:

    • Sensitive Data is pre-encrypted before loading information into the Grupo Truora databases.
    • Customer data must be stored in different databases.
    • All databases are encrypted at rest.
    • Extraction, transformation, and loading processes should be executed in different instances.
    • Validations of the integrity of loaded data are performed, considering the original base.

14 BIS. International Transfers and Transmissions — Guarantees.

  • In the context of the provision of Services and the operation of the Truora Group, Personal Data may be subject to international transfer and transmission to Truora Group companies and suppliers located, among other countries, in Colombia, Mexico, Chile, Brazil, and the United States.
  • Applicable conditions. Pursuant to Article 26 of Law 1581 of 2012, international transfers to countries that do not offer adequate levels of data protection according to the standards set by the SIC are prohibited, unless: (a) the Data Subject has given their express and unequivocal authorization; (b) it involves the exchange of medical data required for health or public hygiene reasons; (c) it involves banking or securities transfers; (d) the transfer is covered by international treaties of which Colombia is a party; (e) it is necessary for the execution of a contract between the Data Subject and Truora; or (f) it is legally required for the safeguarding of the public interest or for the recognition, exercise, or defense of a right in judicial proceedings.
  • Processors and sub-processors. When Truora transmits Personal Data to Processors who process it on its behalf, or when these engage sub-processors, data transmission contracts will be executed pursuant to Decree 1074 of 2015, or contractual clauses will be adopted that impose on the recipient substantially equivalent data protection obligations to those provided in this Policy and in the law.

15. Cookies and other technological tools.

  • Truora uses cookies and similar technologies to personalize and improve the experience of clients, as well as to show relevant online advertising. Cookies are small text files containing a unique identifier stored on the computer or mobile device through which you access the website and/or mobile applications. Data Subjects may choose to disable some or all of the cookies we use at any time. However, this could restrict their use of the sites and limit their experience thereon. The use of cookies does not contain or affect Personal Data and does not represent a virus risk.

16. Consultation, Rectification, and Claims Procedure.

Truora has specific manuals designed for the consultation, complaint, and claims procedure and for the personal data processing procedure available here.

  • 16.1. Consultation: Data Subjects' inquiries and requests will be addressed within a maximum period of ten (10) business days, counted from the date of receipt. If it is not possible to resolve the inquiry within this period, the Data Subject will be informed of this situation at the notification address included in the respective inquiry, and the response period may be extended for up to five (5) additional business days.

  • 16.2. Rectifications and Claims: When a Data Subject considers that their information must be corrected, updated, or deleted, or when they identify an alleged breach by Truora of its duties regarding Personal Data Protection, they may file a claim as follows:

    • A written request must be submitted regarding the specific requirement.
    • If the claim is incomplete, Truora will notify the interested party within five (5) days following receipt of the request to complete and rectify their petition.
    • If the claim is received in complete form or is subsequently completed, a "legend" must be included in the database within two (2) business days indicating "CLAIM IN PROCESS".

Truora will resolve the claim within a maximum period of fifteen (15) business days counted from the day following its receipt. If it is not possible to resolve the inquiry within this period, the Data Subject will be informed of the delay, the reasons, and the response date.

17. Data Protection Contact

Truora has created an area exclusively designated for the handling of Personal Data called Privacy Truora as responsible for the protection of your data. For any questions or concerns about this Privacy Policy or the Processing and use of Personal Information, please direct your inquiries, requests, complaints, or claims to:

  • DPO: David Alejandro Cuadrado Cabrera
  • Email: privacy@Truora.com
  • Address: Carrera 12 #90-20
  • Phone: 318 801 0571

18. Information Deletion.

Any information storage device that, by the determination of the information owner, has become obsolete or been decommissioned, must be securely deleted.

  • 18.1. Deletion procedure Files will be stored for the time requested by the information owner, having been previously communicated through written communication to the information security committee.

    • Extraordinarily, partial or total deletion of the information owner's information may be requested, which will affect both the received files and all data subsequently generated as a result of the management and Processing carried out by Truora.

    • When proceeding with the deletion or destruction of personal information, the deletion record must be prepared, signed by the areas present and involved in the process.

    • Magnetic (electronic) media must be destroyed before being discarded, ensuring they cannot be read by third parties.

    • In the case of decommissioned computers, their hard drive must be formatted or destroyed, so that the stored information and installed software are logically and physically deleted from the equipment.

  • 18.2. Destruction of backup media

    • Physical Media: These types of media are physical representations of data, generally associated with paper copies, payment card plastics, fax, photos, tapes, etc., including:
      • Magnetic media: floppy disks, hard drives, magnetic tapes, etc.
      • Optical media: CD, DVD, etc.
      • Magneto-optical media: Zip disks, Jaz disks, SuperDisk, etc.
      • Electronic media: Flash memories, ROM and RAM memories, solid-state drives (SSD), etc.
    • Logical Media: These types of media store logical representations of data in the form of bits and bytes and their corresponding structures (files, filesystems, drives, etc.).
  • 18.3. Deletion of logical data

    • Redact: This technique is used to remove certain parts of a digital document to prevent the display of confidential data during a declassification process, including the deletion of metadata and removal/truncation of images and text.
    • Delete: This technique simply performs a simple deletion in which the reference to files at the operating system level is removed (de-indexing) but their data remains on the storage medium and can be recovered using computer forensic techniques.
    • Clear: This method uses logical procedures (software-based) to securely erase data in storage locations to prevent such data from being recovered using computer forensic techniques.
    • Purge: This method uses physical or logical techniques to prevent data on the storage device from being recovered using laboratory techniques (e.g., recovery through magnetic remanence).
  • 18.4. Deletion of physical data

    • Redact: This action applies to written physical media and consists of the sanitization/truncation of certain parts of a document in order to prevent potential disclosures of confidential information.
    • Destroy: This final method eliminates data through physical destruction of the storage medium, rendering it unusable using techniques such as disintegration, incineration, pulverization, shredding, or melting.

19. Modifications to the Privacy Policy.

Truora is fully authorized to modify this Privacy Policy. Any changes will be published on our website and/or mobile applications. It is the responsibility of the Data Subject to review these Personal Data Privacy and Protection Policies frequently.

19 BIS. Specific Provisions for Data Subjects in the European Union (Regulation (EU) 2016/679 – GDPR).

  • Scope and roles. When Truora processes Personal Data of data subjects located in the European Union or the European Economic Area (EU/EEA) subject to the GDPR, it will act as data controller with respect to the data whose purposes and means it determines, and as data processor, pursuant to Article 28 of the GDPR, with respect to the data it processes on behalf of its Users.
  • Legal bases. Processing will be based on one of the grounds under Article 6 of the GDPR, in particular: the consent of the data subject; the performance of a contract; compliance with a legal obligation; or the legitimate interests of Truora or a third party.
  • Rights of the data subject (Articles 15 to 22 of the GDPR). EU/EEA data subjects have the right, free of charge, to: (a) access; (b) rectification; (c) erasure ("right to be forgotten"), with legal exceptions; (d) restriction of processing; (e) data portability; (f) objection, including objection to direct marketing; (g) not to be subject to decisions based solely on automated processing, including profiling, that produce legal or significant effects (Article 22); and (h) withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Complaint with the supervisory authority. Without prejudice to other administrative or judicial remedies, EU/EEA data subjects have the right to lodge a complaint with the competent supervisory authority of their habitual residence, place of work, or place of the alleged infringement (Article 77 of the GDPR).
  • International transfers. Transfers of Personal Data of EU/EEA data subjects to countries outside the EEA — including Colombia, Brazil, Mexico, Chile, and the United States — will be carried out based on the adequate safeguards of Chapter V of the GDPR, in particular, where applicable, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.
  • Breach notification. In the event of a breach of the security of Personal Data affecting EU/EEA data subjects, Truora will notify the competent supervisory authority without undue delay and, where possible, within seventy-two (72) hours of becoming aware of it.
  • Minors (Article 8 of the GDPR). The Services are not directed at persons under sixteen (16) years of age in the EU/EEA.
  • Contact point. Requests from EU/EEA data subjects may be directed to privacy@truora.com. Truora will respond without undue delay and, in any event, within one (1) month.

19 TER. Truora Pass and Electronic Signature Evidence.

  • Truora Pass. In the event that the Data Subject voluntarily chooses to create a Truora Pass account — the reusable digital identity wallet described in the Terms and Conditions —, Truora will process the associated Personal Data based on the specific, informed, and differentiated consent of the Data Subject. Such data will be retained during the active life of the account, for the purposes of creating, maintaining, and enabling the reuse of the verified identity, with the Data Subject being able to revoke consent or delete the account at any time.
  • Electronic signature evidence. When the Data Subject uses electronic signature functionalities, Truora will retain the associated evidence (such as authentication records, time stamps, and audit trails) for the time necessary to preserve the legal validity and integrity of signed documents and for the exercise or defense of rights, pursuant to Law 527 of 1999 and other applicable regulations. A request for deletion of such evidence may be legitimately denied, with reasons stated, when its retention is indispensable for compliance with a legal or contractual obligation.

20. Effective Date.

This Privacy Policy has been in effect since June 1, 2022, and will be reviewed periodically in the second week of March each year.

21. Issuing, Review, and Publication Authority.

This Privacy Policy was developed by our Privacy Truora team led by Gabriela Cala - Legal Counsel, this team is exclusively responsible for the protection of Personal Data and for ensuring the exercise of Data Subjects' rights. The Privacy Policy was approved by David Alejandro Cuadrado Cabrera - CTO/OSI.

Confidential, August 2026.