Privacy Policy and Personal Data Processing
In compliance with Law 1581 of 2012, Decree 1377 of 2013 and Decree 1074 of 2015 of the Republic of Colombia.
1. Data controller
CONIKA is a trade name operated by Juan José Lima Mesías, a natural person, with no company registration.
Domicile: Pasto (Nariño), Colombia.
Email: legal@conika.co
Phone: +57 323 3745216
Your enquiries and claims are handled by the controller himself, Juan José Lima Mesías, through those channels.
2. What data we collect
Only what you give us voluntarily, or what is generated automatically when you use the site or your project portal:
· Your name, email address, phone number, and the city or country you tell us.
· Whatever information about your project you decide to share.
· If your project moves forward, in order to give you access to your portal: your email address (to send you the key or the entry code) and, automatically, an approximate location (city and country), the device and browser type and the time of each sign-in, and also the IP address of each action you take in the portal (for example, signing, starting a payment, paying, approving a deliverable, starting performance, viewing The Dossier, downloading a delivery, requesting a change or a payment reversal), for the security of your account (for example, to alert you to a new sign-in) and as a record of the formation and performance of your contract. We also keep the country of your last sign-in, for one purpose only: to compare it with the next one and detect a sign-in from a new country, or a change that could not have happened in the time elapsed.
· If you sign The Commitment (the contract) electronically: the full name you type when signing, the type and number of your identity document, your IP address, the browser you sign from, the time of signing and the record of the one-time code we send to the email on your file (and, when SMS verification is active, to the phone on your file). If you sign for a company, also the capacity in which you sign and the email the code was sent to. This is a simple electronic signature (not a digital signature certified by a certification authority), valid under article 7 of Law 527 of 1999, and whose evidentiary weight is assessed under the rules of sound judicial assessment (sana crítica) pursuant to article 11 of that same law; your document number is stored encrypted at rest. When the document is sealed we also compute a cryptographic hash (SHA-256) of the signed file, which we keep alongside the contract, record in The Log and show you in your portal: it exists so that you yourself can verify that the PDF you downloaded was not altered after you signed it.
· If you turn on two-step verification with an authenticator app: the secret key your app and our server share in order to generate the codes, which we store encrypted, and the cryptographic fingerprints (hashes) of your eight backup codes. What we store cannot produce a usable code: it can only check the one you type.
· The messages you exchange with us in your project chat, which we store encrypted.
· The amount and payment plan agreed in The Commitment, shown in your portal («The Balance»). Payment is processed through a certified payment gateway integrated into the portal (cards, PSE, Nequi). Your full card or account details are processed directly by the gateway and never reach us or are stored by us. For each payment we do keep the payment method in masked form (for example, the card brand and its last four digits), the email used to pay and the transaction references; and if a claim is made about that payment, we check with the gateway its status, the name recorded at checkout and the result of its authentication (for example, 3-D Secure).
· Browsing data, aggregated and measured without cookies (site usage measurement).
· If you make a cookie choice: a random consent code, the date, what you chose, the version of the cookie policy, the language and your approximate country, as proof of your authorization. Without your IP, your name or your email.
We do not ask you for sensitive data. If, when describing your project, you tell us something about the health, disability or mobility of someone who will use the place, we use it only to design and with your express authorization; you are not required to give it to us. On the signature, which is what usually raises the question: we do not capture your handwritten signature. You sign by typing your full name, which is text, exactly as when you write your name on a form. We keep no image of your stroke, no physical features, and no behavioral data.
If you enable access with Face ID or a fingerprint, that biometric data never leaves your device and never reaches our servers: it is a standard (WebAuthn) under which we only receive a cryptographic signature from which your fingerprint or your face cannot be reconstructed.
The site and the portal are for adults. If, as their representative, you tell us about a minor who will live in the place, we use that data only for the design and in the minor’s best interest.
3. What we use it for (purposes)
· To handle your enquiry and schedule the conversation (the video call is arranged through Google Calendar and Google Meet).
· To reply to you and keep in touch about a possible project.
· To follow up on your request and your project.
· To give you secure access to your project portal and to protect it: detecting improper access and letting you close your active sessions.
· To give legal validity to the electronic signature of your contract.
· To handle claims concerning your payments, including payment reversals and chargebacks, and to prove to the bank or entity that issued your payment instrument, the payment gateway or the competent authority that the contract was entered into and performed, using the portal records described in section 2.
· To host your project's pieces (images, drawings, virtual tours and interactive 3D models) so that you can view and download them from your portal and, where the contracted service includes it, to publish them online at the address we hand over to you.
· To measure in aggregate how the site is used, in order to improve it.
· To send you communications from CONIKA, only if you authorize it.
· To comply with legal obligations.
4. Legal basis
Your prior, express and informed authorization (article 9 of Law 1581 of 2012). In addition, we keep evidence of the commercial relationship as required by law (article 50(e) of Law 1480 of 2011) and provide an authority with the information it requests in the exercise of its functions (article 10(a) of Law 1581 of 2012).
5. How we protect your access
Your project portal does not use a password: we send you a one-time key or a 6-digit code by email, valid for 15 minutes. We limit attempts to prevent guessing, and we apply request limits per email address and per IP.
Every time you sign in from a new device we alert you by email, with a one-click link to close all your sessions if it was not you.
If you want, you can add a second step: an authenticator app on your phone that generates a six-digit code. It is optional, you turn it on and off yourself from your portal, and it comes with eight backup codes in case you lose your phone. You can also mark a device as trusted so that step is not repeated for thirty days on that same device.
We compare the country you sign in from with the one from your previous sign-in. If the country changes, or if the change happened in less time than the journey would take, we alert both you and the studio. It is an alert, never a block: whenever there is any doubt the system lets you in, because locking out a client who is traveling would be worse than alerting one time too many.
We store your access keys and codes as cryptographic fingerprints (hashes), never in plain text.
6. Your rights
You may know, access free of charge, update, rectify and delete your data, request proof of the authorization you gave us, be informed of the use we have made of it, withdraw your authorization, and file complaints with the Superintendency of Industry and Commerce (SIC).
They may be exercised by you, your successors or your representative or attorney-in-fact. The enquiry or the claim is filed in writing at legal@conika.co, or at +57 323 3745216, with your identification, a description of the facts, the address where you want the answer and any documents you wish to rely on. If the claim is incomplete, we ask you to complete it within the following five (5) business days; if two (2) months pass without your doing so, we take it that you withdrew it. While it is being handled, your data carries the legend «claim in progress». We answer enquiries within a maximum of ten (10) business days and claims within a maximum of fifteen (15) business days; if we cannot meet that period, we tell you why and the new date, which does not exceed eight (8) further business days. Before going to the Superintendency of Industry and Commerce, you must first complete this procedure with us (articles 14, 15 and 16 of Law 1581 of 2012).
Because CONIKA is a natural person, it is not subject to the obligation to register with the SIC's National Database Registry (Decree 1074 of 2015, art. 2.2.2.26.1.2).
7. Minors
The site and the project portal are intended for adults, and we do not ask you for data about minors. If, as their representative, you tell us about a minor who will live in the place we design, we use that data only for the design and in the minor’s best interest. You may ask for its deletion at any time, and if a parent or guardian finds that a minor has given us data, they may request its immediate deletion by writing to the contact address in this policy.
8. Processors and third parties
To run the site and the project portal we use providers that process data on our behalf (data processors), under CONIKA's instructions and bound by contract to confidentiality and security: hosting, database and storage (Vercel, Supabase); scheduling and video calls (Google Calendar and Google Meet, to which we send your name and email address in order to create the appointment and the meeting link); hosting of your project's images (Cloudinary); storage of your project's files, meaning drawings, deliverables, virtual tours and interactive 3D models (Cloudflare R2); phone verification where applicable (Twilio); email delivery (Resend); abuse protection and access control (Upstash); and the payment gateway (Wompi), which also receives your card details in its own form and processes them as a controller as well, under its own policy. None of these providers is authorized to use your data for purposes of their own beyond providing the service to us, and each is bound by contract to this policy.
The design lead of the project, Sofía Solarte Cabrera, receives your project data on behalf of CONIKA, solely for the design and under this policy.
If you, or the holder of the instrument used to pay, file a claim concerning a payment (a reversal or a chargeback), we provide the payment and agreement data and the portal records described in section 2 to those who must resolve it, and for that purpose only: the payment gateway, which handles it on our behalf; the bank or entity that issued the payment instrument and the card network, which decide it as controllers of that processing; and, should the matter reach an authority, that authority, when it requests them in the exercise of its functions or as evidence in the proceedings (Law 1581 of 2012, article 10(a); Law 1480 of 2011, article 50(e)). We never provide the content of the chat, your full identity document or your full card details.
The Meta pixel is different from the above and therefore stands on its own. It only loads if you accept cookies, and Meta does not act as our processor: it also processes that data for purposes of its own, so before the law it is an independent controller and CONIKA answers jointly with it for what is collected through the pixel. Meta also uses that data to decide whom to show our ads on Facebook and Instagram. If you do not accept cookies, the pixel does not load and nothing travels to Meta. You may change your decision at any time from the cookie notice.
The site's typefaces are served from Adobe Fonts, under its own terms of service and from outside Colombia: it receives your browser's IP address, without your name, email address or phone number. To estimate your country we use the approximate location that Vercel derives from your IP address, and if, while scheduling, you ask to detect your location, the coordinates are turned into a city on your own device. We do not send either of them to any other third party or store them: only the country and city you confirm when you schedule remain.
9. International transfer of data
Several of those providers store or process data on servers outside Colombia, mainly in the United States. When they do so on our behalf and following our instructions this is a transmission, and it does not require any additional authorization from you, because with each of them there is a contract setting out the scope of the processing and their obligations (Decree 1377 of 2013, articles 24 and 25).
When the recipient processes the data for purposes of its own this is an international transfer, and that is the case of the Meta pixel. There we rely on your express authorization, which is the one you grant by accepting cookies (article 26, subparagraph a, of Law 1581 of 2012), or on the transfer being necessary to perform the contract between you and CONIKA (subparagraph e of that same article).
If you paid with a card issued outside Colombia and file a claim concerning that payment, the records described in section 8 reach the issuing bank in your country through the payment gateway and the card network. This is an international transfer, based on your express authorization and on its being necessary to perform the contract (article 26(a) and (e) of Law 1581 of 2012).
10. Security incident notification
Should there be a security breach compromising the confidentiality, integrity or availability of your data, we will inform you by email without undue delay, together with the measures taken to mitigate it, and we will report the incident to the Superintendency of Industry and Commerce within the fifteen (15) business days following its detection. If you reside outside Colombia, we also meet the notification periods set by the law of your country.
11. Cookies
The site uses cookies as described in the Cookie Policy.
If your browser sends the Global Privacy Control signal, advertising starts switched off. We do not respond in any other way to the «Do Not Track» signal. Only Meta, if you turn advertising on, can follow your activity on other sites.
12. How long we keep each thing
These are the periods, counted from the last contact or from the end of the project, as applicable:
· Enquiries and bookings that did not lead to a project: two (2) years.
· Project data, the signed Commitment and the evidence of that signature (including your identification document number, which is stored encrypted): ten (10) years from termination. That is the period during which the law still allows a claim to be brought over that contract, so it is also the period in which both parties need to be able to prove what was agreed.
· Messages from your project chat: for the duration of the project and five (5) years thereafter.
· Records of your cookie choices: three (3) years from each choice.
· Access and security logs. Your project keeps a sealed register: every act with an effect on the contract (the signature, a payment, a decision) is recorded with the date, the IP address and a description of the device, chained with a cryptographic hash: changing an entry would require recomputing every hash after it, and they would no longer match those in any copy you have downloaded. That register is what lets you prove what happened and when, so the IP address of those acts is kept for the same period as The Commitment: ten (10) years. For your simple sign-ins to the portal we do not keep the IP address: the date, the device, the city and the country remain. The device description, the city and the country are not part of the hash, and are deleted once one (1) year has elapsed from each entry. Expired access credentials (single-use keys, codes and closed sessions) are also deleted after one (1) year.
· Your project's pieces hosted in the portal: heavy deliverables (drawings, working files and video) stay in your portal while your project is ongoing and for one (1) year after it closes, and we warn you before that runs out. Once the period has elapsed it is the heavy file that leaves our servers, not your project: the portal, the images, your history and the signed Commitment all stay. Of the package we keep our own copy and restore it to you, at no cost, whenever you ask. It is never published at an open address; it lives in private storage and each download generates a signed link that expires shortly afterwards.
· Virtual tours, and any other piece served from our servers: one (1) year of hosting from delivery, included in the price. After that year they stay online only if you take out the hosting subscription; if you do not, the address stops responding and the file is handed over to you to keep or to host wherever you prefer.
· Accounting records of payments: ten (10) years, by legal obligation. We never held your full card or account details: they are processed and kept by the payment gateway.
If you request deletion of your data, we erase everything we are not required to keep by a legal or contractual obligation, and we tell you what remains, why and until when.
We apply reasonable security measures (encryption of your identification document number and of the chat messages, cryptographic fingerprints of your access keys, attempt limits, restricted access to the databases); no system is 100% infallible.
13. Term and changes
This version is in force from October 1, 2026. We may update it to reflect legal, technical or service changes; the version in force is the one published on this page, with its date. If a change is substantial, we notify everyone whose data we keep before applying it, and if it adds a purpose, we ask you for a new authorization.