Personal data processing policy
Last updated: September 12, 2026
This policy describes how cautia processes personal data, when it does so as a controller and when as a processor, and how you can exercise your rights. It is adopted under Colombian Law 1581 of 2012 and article 13 of Decree 1377 of 2013.
Courtesy translation
This is a courtesy translation. In case of any discrepancy, the Spanish version prevails, and Colombian law and courts apply.
The binding text is the Spanish-language version of this personal data processing policy, published in the Spanish section of this site under the same name. If you need the authoritative wording, please refer to that version.
1. Data controller
Legal name: [TODO(legal): legal name]. Tax ID (NIT): [TODO(legal): NIT]. Domicile: [TODO(legal): city]. Address for notices: [TODO(legal): address for notices]. Email: hola@cautia.co. Phone: [TODO(legal): contact phone].
The area responsible for handling requests, queries and complaints relating to personal data is [TODO(legal): responsible area or role], at hola@cautia.co.
This policy applies to every database and personal data processing activity carried out by cautia in the course of its business.
2. Dual role: controller and processor
cautia acts as controller with respect to the data it collects directly: contact data of prospects and clients provided through the form on this site, by email or in commercial meetings, and data of the contact persons at the agencies with which it has a contractual relationship.
cautia acts as processor with respect to the personal data contained in the documents and databases that agencies and brokers hand over so that it can run the contracted workflows — quotations, policies, receivables reports, group policy schedules. In that role, cautia processes the information solely following the controller instructions and the terms agreed in the contract, and does not use it for its own purposes.
When acting as processor, the controller is the agency or broker. Data subjects may address their requests to the agency with which they have the relationship; if they address cautia, it will forward them to the controller and provide the support needed to respond within the legal deadlines.
3. Personal data processed
As controller, cautia processes identification and professional contact data: name, corporate email, phone, name of the agency or brokerage, job title, the content of the message and the technical data associated with the form submission.
As processor, cautia processes the personal information contained in the documents and databases handed over by the agency or broker, and only to the extent required by the contracted workflow. Those documents may contain sensitive data — for example, health-related information in life or health quotations — which is processed exclusively to run the contracted workflow, with reinforced security measures and without the data subject being obliged to authorise its processing where the law so provides.
Depending on the contracted workflow, the categories of data that may appear in that information include, among others:
- Name and identity document of the policyholder, insured party or beneficiary.
- Contact details, city and location of the risk.
- Data about the insured asset.
- Coverages, deductibles, sums insured, premiums and policy terms.
- Policy and endorsement numbers.
- Payment status and ageing of receivables.
- Additions, removals and increases in group policies.
4. Purposes of processing
As controller: handling contact and pilot requests; sending commercial information about cautia services to those who have authorised it; managing the contractual relationship and invoicing; complying with legal, accounting and tax obligations; and responding to requests from authorities.
As processor: running the workflows contracted by the agency, which includes reading and extracting information from documents, normalising it, cross-checking it against the client databases, producing the deliverables and delivering them through the agreed channels; as well as providing support, correcting errors and keeping technical execution records for audit and invoicing purposes.
cautia does not use the personal data contained in its clients documents for its own commercial purposes, nor does it transfer it to third parties other than the processors and sub-processors described in this policy.
6. Data subject rights
As a data subject whose personal data is processed by cautia — whether as controller or as processor — Colombian law grants you the rights listed in article 8 of Law 1581 of 2012.
Exercising these rights is free of charge and may be done by the data subject, their successors, their representative or attorney-in-fact, or by anyone acting under a stipulation in favour of another. Before replying, cautia verifies the identity of the person submitting the request.
Specifically, you may:
- Know, update and rectify your personal data held by cautia.
- Request proof of the authorisation granted, except where the law does not require it.
- Be informed about the use made of your data.
- File complaints with the Superintendence of Industry and Commerce for breaches of the law.
- Withdraw the authorisation and request deletion of the data where applicable.
- Access your personal data free of charge.
7. Procedure and deadlines for queries and complaints
Queries and complaints are submitted to hola@cautia.ai, stating full name, identity document, the specific request and an address or email at which to receive the reply.
Queries are handled within a maximum of ten (10) business days from receipt, in accordance with article 14 of Law 1581 of 2012. If it is not possible to handle them within that term, the interested party will be informed before it expires, stating the reasons and the date on which the query will be handled, which shall in no case exceed the following five (5) business days.
Complaints are handled within a maximum of fifteen (15) business days counted from the day following receipt, in accordance with article 15 of the same law. If it is not possible to handle them within that term, the interested party will be informed before it expires, with the reasons and the date on which the complaint will be handled, which shall not exceed the following eight (8) business days. If the complaint is incomplete, the interested party will be asked to complete it within the five (5) days following its receipt; if two (2) months pass from that request without a reply, the complaint is deemed withdrawn.
8. Processors, sub-processors and international transfers
To provide its services, cautia relies on infrastructure and processing providers that act as processors or sub-processors and that are located outside Colombia.
This means that personal data may be subject to international transmission and transfer. cautia adopts the contractual measures needed so that those third parties meet protection standards equivalent to those required by Colombian law and process the information solely in accordance with its instructions.
By authorising the processing and by contracting the services, the data subject and the client are informed of this international transfer and transmission, under articles 24 and 25 of Decree 1377 of 2013.
The providers currently involved in the service are:
- Cloudflare: site hosting, content delivery network and aggregated, cookieless analytics.
- Google Cloud: execution infrastructure.
- Google Gemini: artificial intelligence models for classification and information extraction.
- Mistral: text recognition in scanned documents.
- [TODO(legal): transactional email provider].
9. Artificial intelligence and human review
cautia workflows use artificial intelligence systems to read, classify, extract and organise the information contained in the documents it processes. This use is expressly disclosed, in line with the guidelines of External Circular 002 of 2024 of the Superintendence of Industry and Commerce on the processing of personal data in artificial intelligence systems.
Processing with these systems is limited to what is necessary for the contracted purpose, under criteria of suitability, necessity and proportionality. No automated decisions with legal effects on people are made: the outputs are subject to human review before being used or sent.
[TODO(legal): add here the statement on whether or not data is used for model training, once the contractual terms of each provider are confirmed].
10. Information security
cautia adopts reasonable technical, human and administrative measures to protect information against unauthorised access, loss, alteration or misuse: per-client access control, separate credentials per agency, encryption in transit and activity logging.
No system is entirely infallible. In the event of incidents affecting personal data, cautia will inform the affected controllers and the Superintendence of Industry and Commerce, in compliance with the duty set out for controllers in article 17 (n) and for processors in article 18 (k) of Law 1581 of 2012.
[TODO(legal): review the detail of the measures before publishing, and do not claim any certification that is not held].
11. Data retention
Data processed as controller is kept for as long as the commercial relationship or the legitimate interest in the request lasts, and for the period needed to comply with legal obligations.
Data processed as processor is kept for the period agreed with the controlling agency and, at the end of the contract, is returned or deleted as agreed. Technical execution records are kept for a limited period, for audit and invoicing purposes.
[TODO(legal): set the exact retention periods for documents, deliverables and technical records].
12. National Database Registry
[TODO(legal): verify whether the owning company is required to register its databases in the National Database Registry administered by the Superintendence of Industry and Commerce, based on its nature and the amount of its assets, and state it in this section].
Regardless of that obligation, cautia keeps an internal inventory of the databases it administers, with their purpose, their controller and their retention period.
13. Term and changes
This policy is in force from [TODO(legal): effective date]. The databases administered by cautia will remain in force for as long as the purpose that justified their processing is maintained.
Any substantial change will be communicated through the usual contact channels and published on this page with its new update date. Use of the site or of the services after publication implies acceptance of the version in force.
Note
This document must be reviewed by a Colombian lawyer before its final publication.
Questions about this document: hola@cautia.ai