PERSONAL DATA PROCESSING POLICY

This policy is issued in compliance with Law 1581 of 2012, Decree 1377 of 2013, and any rules that modify or supplement the personal data protection regime, and seeks to ensure that CIRCULAR FACTORING S.A.S.

as the party responsible for the management of personal information, processes such information in strict compliance with applicable regulations, guaranteeing the rights of Data Subjects. This Privacy Policy sets forth the terms, conditions, and purposes under which CIRCULAR FACTORING S.A.S. collects, stores, uses, circulates, deletes, and otherwise processes the personal data of its clients, suppliers, investors, shareholders, contractors, employees, and others, whether in physical and/or electronic form, whether in documents or through emails, electronic systems, photos, videos, and other available media, whose personal data have been provided by the individuals themselves, or obtained through information operators, risk bureaus, legally authorized databases, or publicly accessible sources, among others; all of which have been collected for the development of various procedures directly related to our corporate purpose, and which establishes the institutional procedures so that Data Subjects may exercise the rights established under personal data protection laws.

By accessing, browsing, or using the CIRCULAR FACTORING S.A.S. web portal, the user acknowledges that they have read and understood, and undertakes to comply with, the terms and conditions set forth in this Personal Data Processing Policy and with all applicable laws and regulations; the use of our products and services implies that the User has read and accepted the conditions set forth in the Terms and Conditions and in this Personal Data Processing Policy, and agrees to be bound by them.

INFORMATION OF THE DATA CONTROLLER.

The company responsible for processing personal data is:

Corporate name: CIRCULAR FACTORING S.A.S.
Domicile: Medellín, Colombia
Address: Km 5 vía Las Palmas, Cra 28 No 17-452, Edf. Cortezza, Office 06-110
Email: circular@circularfactor.com
Phone: 3108743616

1.1 Data collection

CIRCULAR FACTORING S.A.S., through its various contact channels with its clients, suppliers, investors, shareholders, contractors, employees and former employees, among others, may collect personal data such as full name, telephone number, and email address that allow subsequent contact; with respect to such information, the client, supplier, investor, shareholder, contractor, employee or former employee, among others, as Data Subject, by providing such data, expressly authorizes CIRCULAR FACTORING S.A.S. to use it in accordance with the purpose stated herein.

The Data Subject expressly accepts that CIRCULAR FACTORING S.A.S. may use, obtain, compile, exchange, update, collect, process, reproduce and/or dispose of their personal data or personal information, partially or totally, for the purposes stated in this Privacy Policy.

We remind the user that the use of our products and services implies that they have read and accepted the conditions set forth in our Terms and Conditions and in this Privacy Policy, and that they agree to be bound by them; however, because the foregoing relates to sensitive data, the user is not obliged to authorize its processing, and providing it is optional.

Nevertheless, you should keep in mind that we will not be able to accept you as a client if you decide not to provide your biometric data, which are used for security confirmations of our products, subscription to documents, and identity validation.

CIRCULAR FACTORING S.A.S. may collect information from its clients, suppliers, shareholders, contractors, employees and former employees, among others, through third parties such as business partners, subcontractors and/or financial institutions, for the purposes stated in this Privacy Policy.

1.2 Authorization for the Processing of Personal Data

CIRCULAR FACTORING S.A.S., through its various contact channels with its clients, suppliers, investors, shareholders, contractors, employees and former employees, among others, may collect personal data such as full name, telephone number, and email address that allow subsequent contact; with respect to such information, the client, supplier, investor, shareholder, contractor, employee or former employee, among others, as Data Subject, by providing such data, expressly authorizes CIRCULAR FACTORING S.A.S. to use it in accordance with the purpose stated herein.

The Data Subject expressly authorizes CIRCULAR FACTORING S.A.S. to collect the data under the terms stated, as well as to report, consult, supplement, and update such personal data at any time, with other databases managed by an information operator, in order to keep the information of its clients, suppliers, shareholders, contractors, employees and former employees updated, among others.

Negative reporting will be notified in the orderly timeframe required by national legislation for delinquency events; for such purpose, the Data Subject hereby authorizes that such notification be made through digital channels, such as email, SMS message or WhatsApp, or any other known or future means, as informed by the Data Subject in the credit application.

In the event the Data Subject has incurred delinquency in their commercial, financial, or credit obligations, for purposes of collection in out-of-court or judicial proceedings, and with those entities with which CIRCULAR FACTORING S.A.S. carries out assignment and/or purchase and sale operations of its portfolio, which may be determined at the time such negotiation is carried out, and which will be fully empowered and/or authorized under the same terms set forth in this authorization, for the handling and processing of the Data Subject’s personal data.

By virtue of the foregoing, whoever in the future holds the status of creditor of the obligation(s) contracted by the Data Subject due to a sale, endorsement, or assignment of portfolio is authorized to consult, share, inform, modify, update, process, request, report, clarify, dispose of, remove and/or disclose to database consultation entities or Information and Risk Operators everything related to the Data Subject’s financial, commercial and credit information, indebtedness, and the origin, modification, or extinguishment of the Data Subject’s rights and obligations arising from any contract entered into or operation carried out or that may be entered into or carried out.

Especially for the following purposes:

  1. As an element of analysis to establish, maintain, and terminate a contractual relationship, and to conduct market studies or commercial, statistical, and financial research,

  2. To monitor the level of indebtedness and/or non-compliance in the financial, commercial, and services sector,

  3. To periodically update the Data Subject’s financial, commercial, credit, and contact information,

  4. To develop or use tools that make it possible to understand the Data Subject’s financial and credit behavior.

  5. To carry out judicial and extrajudicial collection management, through calls or the sending of communications to the Data Subject’s physical or electronic addresses, telephones and/or any medium, with prior notice of negative reporting to risk bureaus, with financial, commercial or other information when required or necessary, as well as to conduct asset investigations and personal location efforts, to obtain payment of the obligations in their charge,

  6. To develop tools that prevent fraud.

This authorization extends to the disclosure and transfer of the information mentioned above, ensuring confidentiality and protection of the Data Subject’s personal data in accordance with applicable laws and regulations.

The use and management of the foregoing is carried out under strict standards of responsibility, within which respect for due process and information protection is included.

Clients, suppliers, investors, shareholders, contractors, employees and former employees, among others, authorize CIRCULAR FACTORING S.A.S. to use, obtain, compile, exchange, update, collect, process, reproduce and/or dispose of their personal data or personal information, partially or totally, as well as to share and transfer such data or information, partially or totally, to third parties, such as banking entities, among others, for the purposes stated above, and these third parties will be obliged to comply with all regulations and privacy policies of CIRCULAR FACTORING S.A.S.

In this sense, the applications or services offered by CIRCULAR FACTORING S.A.S., through, among others, physical and/or electronic forms, its website or applications, that require the processing of personal data, including those that may be classified as sensitive, will request the Data Subject’s express authorization in a clear and simple manner in order to obtain acceptance of the corresponding processing.

In any case, at any time the Data Subject may revoke their consent and exercise their right to the deletion of personal data enshrined in Law 1581 of 2012.

PROCESSING TO WHICH PERSONAL DATA WILL BE SUBJECT AND ITS PURPOSE.

In furtherance of its corporate purpose, CIRCULAR FACTORING S.A.S. processes the personal data of its suppliers, investors, shareholders, contractors, employees and former employees, among others, as well as clients and users of its products.

Likewise, in compliance with applicable legislation, the Company described in its corporate purpose may be required to transmit or transfer such data to the indicated platforms and/or to the security systems implemented by it.

In developing the principles of purpose and freedom, the collection of personal data by the Company CIRCULAR FACTORING S.A.S. will be limited to those personal data that are relevant and adequate for the purpose for which they are collected or required in accordance with current regulations.

Except in cases expressly provided by Law, personal data may not be collected without the Data Subject’s authorization.

Personal data are collected, stored, organized, used, circulated, transmitted, transferred, updated, rectified, deleted, eliminated and managed in accordance with the purpose or purposes applicable to each type of Processing, as indicated in numeral 3 of this Policy.

2.1 Processing of personal data of children and adolescents.

The processing of personal data of children and adolescents that are of a public nature will comply with the following parameters and requirements:

That it responds to and respects the best interests of children and adolescents. That it ensures respect for their fundamental rights. Assessment of the minor’s opinion when they have the maturity, autonomy, and capacity to understand the matter.

Once the above requirements are met, the legal representative of the child or adolescent may grant authorization for Processing, subject to the prior exercise of the minor’s right to be heard, an opinion that must be assessed taking into account their maturity, autonomy and capacity to understand the matter.

2.2 Processing of sensitive data

CIRCULAR FACTORING S.A.S. will strictly observe the legal limitations on the Processing of sensitive data, and will therefore ensure that

Processing is necessary to safeguard the vital interest of the Data Subject and the Data Subject is physically or legally incapacitated. In such events, legal representatives must grant authorization. Processing is carried out in the course of legitimate activities and with due guarantees by a foundation, NGO, association or any other non-profit organization, whose purpose is political, philosophical, religious or union-related, provided that it refers exclusively to its members or persons who maintain regular contacts by reason of its purpose. In such events, the data may not be provided to third parties without the Data Subject’s authorization. Processing relates to data that are necessary for the recognition, exercise or defense of a right in a judicial proceeding. Processing has a historical, statistical or scientific purpose. In this event, measures must be adopted to suppress the identity of the Data Subjects.

In this sense, when CIRCULAR FACTORING S.A.S. requires the processing of personal data that may be classified as sensitive, it will request the Data Subject’s express authorization in a clear and simple manner, for the authorization of the corresponding processing.

In any case, at any time you, as Data Subject, may revoke your consent and exercise your right to the deletion of personal data enshrined in Law 1581 of 2012.

2.3 Video surveillance

CIRCULAR FACTORING S.A.S. uses various video surveillance media installed in different areas of its facilities or offices.

The information collected will be used for the security of persons, assets and facilities.

This information may be used as evidence in any type of proceeding before any authority and organization.

PURPOSES OF THE PROCESSING.

The purposes of the Processing of Personal Data carried out by CIRCULAR FACTORING S.A.S. are as follows

Provision of the services offered by CIRCULAR FACTORING S.A.S. Execution of the contracts entered into with CIRCULAR FACTORING S.A.S. Customer service and marketing. Sending information related to news, promotions, and topics of interest to clients of CIRCULAR FACTORING S.A.S. Sending information related to the contractual relationship. Recording statistical information of clients of CIRCULAR FACTORING S.A.S. Recording information of suppliers and contractors. Recording information of employees of contractors who provide services in the companies of the clients and/or suppliers of CIRCULAR FACTORING S.A.S. Contractual statistics and statistics of services offered or provided. Communication, consolidation, organization, updating, control, accreditation, assurance, statistics, reporting, maintenance, interaction, and management of actions, information, and activities in which suppliers, contractors and their employees are related to or linked with CIRCULAR FACTORING S.A.S. Execution of the corresponding employment contract. Compliance with obligations arising from the commercial relationship, such as carrying out all procedures required before authorities, such as carrying out procedures before the National Tax and Customs Directorate -DIAN, or any other activity derived from applicable legislation. To notify family members, the 123 emergency line, and any priority assistance service in case of emergencies during their stay at the facilities of CIRCULAR FACTORING S.A.S. Communication in general, records, training, authorizations and for the management of activities or actions in which employees and their families are related with CIRCULAR FACTORING S.A.S. Communication, recordkeeping, filing, organization of processing and management of actions, strategies, and activities in which the shareholders of CIRCULAR FACTORING S.A.S. are linked. To access, consult, compare and evaluate all information about the Data Subjects stored in the databases of any legally constituted credit, financial, judicial or security background risk bureau, whether public or private, national or foreign. To investigate, verify and validate the information provided by the Data Subjects, with any information that CIRCULAR FACTORING S.A.S. lawfully has. Human Talent management linked to CIRCULAR FACTORING S.A.S. Data Processing will be carried out for onboarding, performance of functions or service provision, withdrawal or termination, depending on the type of legal relationship established with CIRCULAR FACTORING S.A.S. (including, among others, employees, former employees, interns and applicants). To maintain physical or electronic communication with its clients, suppliers, shareholders, contractors, employees and former employees, among others, including sending information related to the contract entered into between the parties, as well as sending information about other services, products or goods acquired from CIRCULAR FACTORING S.A.S. As an element of analysis in pre-contractual, contractual and post-contractual stages to establish and/or maintain any contractual relationship, including, as part of it, the following purposes: i. Update databases and process the opening and/or linking of products and/or services ii. Evaluate risks derived from the contractual relationship potential, current or concluded, iii. Perform, validate, authorize or verify transactions including, when required for such effect, the consultation and reproduction by CIRCULAR FACTORING S.A.S., of sensitive data such as fingerprint, image or voice, all in accordance with what is established in this document and in the respective authorization iv. Obtain knowledge of the Data Subject’s commercial and transactional profile, which allows defining the products that fit their needs, tastes and preferences, for the origin, modification (refinancing, novation), celebration and/or extinction of direct, contingent or indirect obligations, and breach of obligations acquired with CIRCULAR FACTORING S.A.S. or any third party, as well as news related to such obligations, payment habits and credit behavior with CIRCULAR FACTORING S.A.S. and/or third parties. v. Know the status of active or passive ongoing operations of any nature, or those that in the future may be entered into with CIRCULAR FACTORING S.A.S., with other financial or commercial entities, with information operators or database administrators or any similar entity that in the future is established and whose purpose is any of the above activities. vi. Know information from the Data Subject about the management of checking accounts, savings, deposits, credit cards, commercial behavior, employment and other products or services and, in general, compliance and management of credits and obligations, whatever their nature. This authorization includes information relating to management, status, compliance with relationships, contracts and services, payment habits, obligations and current debts, past due and unpaid, processes, or misuse of services financial vii. Exercise the rights of CIRCULAR FACTORING S.A.S., including those relating to judicial and extrajudicial collection activities and related management to obtain payment of the obligations in charge of the Data Subject or their employer, if applicable, and the reincorporation of the negative record when applicable due to change of employer viii. Implementation of software and technological services, ix. Process and ensure compliance and delivery of products and/or services acquired by the Data Subject, x. Comply with commercial obligations within the framework of contractual relationships. To carry out assignment and/or endorsement and/or sale operations of products and/or services offered by CIRCULAR FACTORING S.A.S., among which its portfolio is included. To verify personal and/or commercial references provided, regarding the management of accounts and/or products that are in the Data Subject’s name, as well as any other type of information about the transparency and legality of the activities carried out. To record and listen, only when CIRCULAR FACTORING S.A.S. requires it, to the conversations of the Personal Data Subject with CIRCULAR FACTORING S.A.S. related to business, so that CIRCULAR FACTORING S.A.S. has support and valid evidentiary means in any judicial proceeding, as well as support for the operations carried out. To subcontract third parties to process the information of its clients, suppliers, shareholders, contractors, employees and former employees, among others, and/or to carry out any other activity required by CIRCULAR FACTORING S.A.S. in relation to the contract entered into between the parties. To consult credit information with information operators (Experian, Transunion, risk bureaus or any other entity that may manage databases with the same objectives), as well as to report the creation, modification, extinction, fulfillment or non-fulfillment of the obligations incurred in favor of CIRCULAR FACTORING S.A.S. and the improper use of the products and/or services provided or offered by the entity. To consult, request, provide, report, process, use and, in general, process all the information contained in my employment history, including current and non-current employment ties, base contribution index (IBC), contact data, employee information, pension status, date of birth, affiliation date, transfer date, and other information related to my employment situation and employer, related to my income and mandatory and/or voluntary contributions to health, pension, and severance with the social security entities, pension funds or severance funds and/or other similar entity in which I am affiliated, reported or administered in the RAIS (Individual Savings Regime with Solidarity), administered by the Colombian Association of Pension Fund Administrators (Asofondos de Colombia), PILA Information Operators, allied technologies, Online Contributions S.A., and other social security information operators authorized by the Ministry of Health and Social Protection that are part of the Social Security system, and to these in turn so that they provide CIRCULAR FACTORING S.A.S., by the means they consider pertinent and secure, my personal data related to affiliation and payment of contributions to the Integral Social Security System, such as base contribution income and other information related to my employment situation and employer, who may access such information as many times as they require, keep it updated and, in general, handle it, directly or through a person in charge, for the purpose of carrying out credit application and approval processes, credit risk evaluation, collection processes carried out directly or through authorized third parties and to offer and process products and services. To validate information with different databases of authorities and/or state entities and third parties such as the National Civil Registry and its certified technology allies, information operators and other entities that are part of the Integral Social Security System, public utilities companies and mobile telephone service providers, among others, to develop activities related to the main and related corporate purpose of CIRCULAR FACTORING S.A.S. and/or to comply with legal obligations. To carry out contacts for commercial and promotional purposes, whether about its own services and products, or those of third parties with whom CIRCULAR FACTORING S.A.S. has commercial relationships or alliances, through mail, telephone, mobile phone, email or any other known or future means, or to supplement, optimize or deepen the portfolio of products and/or services currently offered. To carry out collection management activities; deliver statements of obligations; prior notice of negative reporting to risk bureaus or financial information, which will be carried out, no later than 20 days after the notice or notification, upon non-payment of the obligation and the consequent termination of the mutual loan contract, subject to the provisions of Habeas Data legislation, through physical or electronic mail, telephone, mobile phone, SMS message or WhatsApp, or any other known or future means; for obligations less than or equal to (15 %) of one (1) current legal monthly minimum wage, the negative item will only be reported after at least two communications on different days have been made. And between the last communication and the report, 20 calendar days must elapse; and to update information through different activities such as consulting public databases, internet pages, social networks and references from third parties, in particular the persons who have served as references for the use of the services of CIRCULAR FACTORING S.A.S. For security at CIRCULAR FACTORING S.A.S. facilities, Processing will be carried out for surveillance and security of persons, assets and the facilities themselves. For security in logical access at CIRCULAR FACTORING S.A.S., for user management in applications, developments, web platforms or in general any technological solution used by CIRCULAR FACTORING S.A.S., personal information will be collected for the creation and administration of profiles, which will be processed in accordance with this policy. To validate and verify the identity of clients and users, as well as to profile them, among others, through artificial intelligence (AI) systems, to determine the degree of risk for the granting of credits and other products or services that CIRCULAR FACTORING S.A.S. offers or may offer over time, in cases where a client or CIRCULAR FACTORING S.A.S. has not been able to accept their application previously.

This analysis includes, without limitation, the following

Consulting and reporting to restrictive lists, politically exposed persons lists, and information bureaus, for the prevention and mitigation of money laundering, terrorism financing, financial risks, impersonation and fraud risks. Consulting, whenever necessary, information about credit history, contact information, financial data and information related to your situation with information operators and risk bureaus Implementing relationship and/or segmentation strategies with clients, suppliers and other third parties with whom CIRCULAR FACTORING S.A.S. has contractual or legal relationships. For other purposes, such as statistical and market analysis; development and improvement of services and products of CIRCULAR FACTORING S.A.S., commercial and promotional initiatives; data updates; to carry out regulatory controls; to comply with legal duties, including within these, those related to the prevention of tax evasion, money laundering and terrorism financing or other similar purposes issued by competent authorities. Other purposes established in the Terms and Conditions and in this Privacy Policy.

CIRCULAR FACTORING S.A.S. may engage third parties located in Colombia or abroad to process the information of clients, suppliers, shareholders, contractors, employees and former employees, among others, and/or to carry out any other activity in relation to using, obtaining, compiling, exchanging, updating, collecting, processing, reproducing and/or disposing of the data or information of clients, suppliers, contractors, employees and former employees, among others, of CIRCULAR FACTORING S.A.S.

This process may involve the collection, filing, processing, transfer and/or transmission of such information and personal data to third parties, among companies linked or contractually related with CIRCULAR FACTORING S.A.S., such as call center and contact center service providers, messaging service providers, collection companies and legal professionals who collaborate with the entity in the recovery of its portfolio, located within or outside Colombia.

In any case, those entities will also be subject to the same confidentiality obligations in the handling of information to which CIRCULAR FACTORING S.A.S. is subject, with the legal limitations imposed by applicable laws on the matter, in the jurisdiction where such information is collected, filed, processed or transmitted.

Likewise, with acceptance of this Privacy Policy, clients, suppliers, investors, shareholders, contractors, employees and former employees, among others, acknowledge that CIRCULAR FACTORING S.A.S. may provide this information to judicial or administrative entities and government entities that perform operational oversight functions when required by law to do so.

Likewise, you agree that you may be subject to internal audit processes or external audits by companies in charge of this type of control.

In the event that CIRCULAR FACTORING S.A.S. is not able to carry out processing by its own means, it may transfer the collected data so that it is processed by a third party, prior notice to the Data Subjects whose data were collected, who will be in charge of the processing and must ensure suitable conditions of confidentiality and security of the information transferred for processing.