Legal
Personal Data Transmission Agreement
This English version is provided for convenience. The Spanish version governs.
Version negocio-transmision-2026-10 · Effective September 24, 2026
Personal data transmission agreement under article 25 of Decreto 1377 de 2013 (article 2.2.2.25.5.2 of Decreto 1074 de 2015).
1. Parties
The Controller is the business identified in its Taply account and in «Datos legales del negocio» (business legal details). The Processor is Jesus Auriol Villamarin Ortiz, an individual identified with C.C. 1.034.318.093, domiciled at Calle 152 # 9-80, Bogotá D.C., Colombia, email support@gettaply.com and phone +57 311 566 3842, who operates the Taply platform.
2. Purpose of the agreement
The Controller transmits to the Processor the personal data of its customers and contacts so that the Processor processes it on the Controller's behalf when providing the Taply service, and the Processor undertakes to process it in accordance with this agreement, the Controller's instructions and Colombian law.
3. Data Subjects and data
The Controller's customers and contacts, members of its Club and, when the Controller enables it, children registered by their legal representative. Data: identification and contact (name, WhatsApp number, social media username, email), conversations and their files, fields and answers the Controller defines, birthdays, visits, rewards and redemptions, notification preferences, technical data of Wallet cards, appointments, campaign sends and the evidence of authorizations and requests.
4. Activities the Processor performs
Collecting the data through the forms, chats and integrations the Controller configures; storing and protecting it; showing it in the Controller's dashboard; operating the virtual assistant with the data the Controller enables; confirming WhatsApp numbers; issuing and updating Apple Wallet and Google Wallet cards; sending the notices and messages the Controller orders to those who authorized them; computing statistics for the Controller; keeping the evidence of authorizations and requests; making backups; and correcting, anonymizing or deleting data when appropriate.
5. Purposes
The Processor processes the data only for the purposes the Controller sets in its policy and in its forms, and for those inherent to providing the service: platform security and fraud prevention, evidence of authorizations and requests, and aggregated and anonymous statistics. It does not use it for its own purposes, does not sell or assign it, does not use it to train general-purpose artificial intelligence models and does not cross-reference it with that of other businesses.
6. Instructions
The Controller's instructions are this agreement, the configuration it makes in the dashboard and those it gives in writing. If the Processor considers that an instruction violates the law, it informs the Controller and may refrain from following it.
7. Standing instructions
The Controller hereby instructs the Processor to:
- Apply the rules on data of children and adolescents in Taply's policy (the representative's authorization, minimal data, use only with their representative, never in public replies or on Wallet cards).
- Mark questions on sensitive topics as voluntary, collect them only in forms with their notice (the assistant does not ask for or store them from the chat) and block them about children.
- Keep adults' data while their relationship with the Controller lasts and until they request its deletion, and children's data while their representative's relationship with the Controller lasts, until the representative asks for it to be deleted or until they turn 18, whichever comes first, asking the representative for a yearly confirmation.
- When carrying out a deletion, also delete the content of that person's conversations, keeping only what is needed to respect their decision not to receive messages.
- Carry out the deletions and revocations the Controller decides or that the Data Subject makes from their card.
- Notify the Controller of each data request recorded in Taply and remind it of its deadline when 5 business days and 1 business day remain before the end of the legal period.
- Show the Controller's privacy notice in the first private conversation with each person and record its evidence.
- Keep the evidence of authorizations and requests for up to 5 years after the Data Subject's relationship with the Controller ends, with the number stored only as an encrypted identifier.
8. Obligations of the Processor
(Ley 1581, art. 18, and Decreto 1377, art. 25):
- Process the data according to the principles of the law, the Controller's policy and this agreement.
- Guarantee Data Subjects the exercise of their rights, and forward to the Controller within 2 business days at most the inquiries and claims it receives, informing the Data Subject.
- Keep the data under security conditions that prevent its tampering, loss, consultation, use or unauthorized or fraudulent access.
- Keep the data confidential, also after the agreement ends, and require the same of its team.
- Update, rectify or delete the data when appropriate and record the legend «reclamo en trámite» (claim in progress) when applicable.
- Refrain from circulating information disputed by the Data Subject when the SIC so orders.
- Allow access to the data only to those who must have it.
- Inform the Controller of security incidents under clause 12 and report them to the SIC (Ley 1581, art. 18 lit. k).
- Comply with the SIC's instructions and requirements.
9. Obligations of the Controller
(Ley 1581, art. 17): obtain and keep the Data Subjects' authorization through the means Taply offers or its own; inform them of the purpose and their rights; have and publish its policy; handle their inquiries and claims within the legal deadlines; give the Processor only data whose processing is authorized; inform it of the corrections and claims it learns of through other means; register its databases in the RNBD (National Database Registry) if applicable; and report security incidents to the SIC within 15 business days of learning of them.
10. Sub-processors
The Controller authorizes the Processor to rely on the providers listed in the section «Con quién compartimos datos» (who we share data with) of Taply's policy. The Processor requires of them data protection obligations equivalent to those of this agreement and is answerable for them to the Controller. It will announce any new provider in the dashboard at least 15 calendar days in advance; if the Controller objects for a reasonable data protection reason, it may terminate the agreement without penalty.
11. International transmission
The Controller authorizes the data to be processed outside Colombia, mainly in the United States, a country with an adequate level of protection according to the SIC's Circular Externa 005 de 2017, and in the other countries of the listed providers, under contracts that require them to protect the data (Ley 1581, art. 26; Decreto 1377, arts. 24 and 25).
12. Security and incidents
The Processor maintains encryption in transit, access control by organization on every query, least privilege, encrypted credentials, limited technical logs and backups. In the event of an incident affecting the Controller's data, it notifies the Controller without undue delay and within 48 hours at most of becoming aware of it, with the information available (what happened, which data and Data Subjects, what measures were taken), and cooperates so that the Controller reports it to the SIC and to the Data Subjects when appropriate. The Processor also makes its own report to the SIC within 15 business days of becoming aware of it.
13. Demonstration and audit
The Processor provides the Controller, on request and at most once a year, with reasonable information to demonstrate compliance with this agreement, following the SIC's Guide on demonstrated accountability. On-site audits are agreed in writing, at the Controller's expense and without access to other businesses' data.
14. Term, return and deletion
The agreement lasts as long as the Controller uses Taply. When it ends, the Controller may export its data for 30 calendar days; once that period expires, the Processor deletes it, except the evidence in clause 7.8 and the data a law requires it to keep.
15. Liability
Each party is liable for its own obligations. The Processor is liable for processing it carries out outside the Controller's instructions or against the law. Otherwise, the Processor's liability to the Controller is limited to the amount paid by the Controller to Taply in the 12 months before the event, except in cases of willful misconduct or gross negligence. This limitation does not affect the rights of Data Subjects.
16. Changes
The Processor may update this agreement by giving notice in the dashboard at least 30 calendar days in advance. If the Controller does not agree, it may terminate the agreement before the change takes effect.
17. Law and disputes
This agreement is governed by Colombian law. The parties will seek to resolve any disagreement directly for 30 calendar days; if they do not succeed, they will go to the competent courts of Colombia.