Privacy Policy and Personal Data Processing

In compliance with Law 1581 of 2012, Decree 1377 of 2013 and Decree 1074 of 2015 of the Republic of Colombia.

1. Data controller

CONIKA is a trade name operated by Juan José Lima Mesías, a natural person, with no company registration.

Domicile: Pasto (Nariño), Colombia.

Email: legal@conika.co

2. What data we collect

Only what you give us voluntarily, or what is generated automatically when you use the site or your project portal:

· Your name, email address, phone number, and the city or country you tell us.

· Whatever information about your project you decide to share.

· If your project moves forward, in order to give you access to your portal: your email address (to send you the key or the entry code) and, automatically, your IP address, an approximate location (city and country) derived from that IP, the device and browser type, and the time of each sign-in, for the security of your account (for example, to alert you to a new sign-in). We also keep the country of your last sign-in, for one purpose only: to compare it with the next one and detect a sign-in from a new country, or a change that could not have happened in the time elapsed.

· If you sign The Commitment (the contract) electronically: the full name you type when signing, your identification document number, your IP address and the time of signing. This is a simple electronic signature (not a digital signature certified by a certification authority), valid under article 7 of Law 527 of 1999, and whose evidentiary weight is assessed under the rules of sound judgement pursuant to article 11 of that same law; your document number is stored encrypted at rest. When SMS verification is active, we use your phone number to send you a one-time code confirming your identity as you sign, and we record the device you sign from as part of the evidence. When the document is sealed we also compute a cryptographic fingerprint (SHA-256) of the signed file, which we keep alongside the contract and show you in your portal: it exists so that you yourself can verify that the PDF you downloaded was not altered after you signed it.

· If you turn on two-step verification with an authenticator app: the secret key your app and our server share in order to generate the codes, which we store encrypted, and the cryptographic fingerprints (hashes) of your eight backup codes. What we store cannot produce a usable code: it can only check the one you type.

· The messages you exchange with us in your project chat, which we store encrypted.

· The amount and payment plan agreed in The Commitment, shown in your portal («The Balance»). Payment is processed through a certified payment gateway integrated into the portal (cards, PSE, Nequi); that data is processed directly by the gateway and never reaches us or is stored by us.

· Browsing data, aggregated and anonymous (site usage measurement).

We do not collect sensitive data. On the signature, which is what usually raises the question: we do not capture your handwritten signature. You sign by typing your full name, which is text, exactly as when you write your name on a form. We keep no image of your stroke, no physical features, and no behavioural data.

If you enable access with Face ID or a fingerprint, that biometric data never leaves your device and never reaches our servers: it is a standard (WebAuthn) under which we only receive a cryptographic signature from which your fingerprint or your face cannot be reconstructed.

We do not collect data from minors. If we receive it by mistake, it is deleted.

3. What we use it for (purposes)

· To handle your enquiry and schedule the conversation (the video call is arranged through Google Calendar and Google Meet).

· To reply to you and keep in touch about a possible project.

· To manage our relationship with clients and prospective clients.

· To give you secure access to your project portal and to protect it: detecting improper access and letting you close your active sessions.

· To give legal validity to the electronic signature of your contract.

· To host your project's pieces (images, drawings, virtual tours and interactive 3D models) so that you can view and download them from your portal and, where the contracted service includes it, to publish them online at the address we hand over to you.

· To measure in aggregate how the site is used, in order to improve it.

· To send you communications from CONIKA, only if you authorize it.

· To comply with legal obligations.

4. Legal basis

Your prior, express and informed authorization, and the need to perform the contractual relationship you enter into with us, pursuant to articles 6, 9 and 10 of Law 1581 of 2012.

5. How we protect your access

Your project portal does not use a password: we send you a one-time key or a 6-digit code by email, valid for 15 minutes. We limit attempts to prevent guessing, and we apply request limits per email address and per IP.

Every time you sign in from a new device we alert you by email, with a one-click link to close all your sessions if it was not you.

If you want, you can add a second step: an authenticator app on your phone that generates a six-digit code. It is optional, you turn it on and off yourself from your portal, and it comes with eight backup codes in case you lose your phone. You can also mark a device as trusted so that step is not repeated for thirty days on that same device.

We compare the country you sign in from with the one from your previous sign-in. If the country changes, or if the change happened in less time than the journey would take, we alert both you and the studio. It is an alert, never a block: whenever there is any doubt the system lets you in, because locking out a client who is travelling would be worse than alerting one time too many.

We store your access keys and codes as cryptographic fingerprints (hashes), never in plain text.

6. Your rights

You may know, access, update, rectify and delete your data, withdraw your authorization, and file complaints with the Superintendency of Industry and Commerce (SIC). To exercise them, write to us at legal@conika.co. We answer enquiries within a maximum of 10 business days and claims within a maximum of 15 business days; if we cannot resolve your claim within that period, we will tell you the reasons for the delay and the new date, which will not exceed 8 further business days.

Because CONIKA is a natural person, it is not subject to the obligation to register with the SIC's National Database Registry (Decree 1074 of 2015, art. 2.2.2.26.1.2).

7. Minors

The site and the project portal are intended for adults. We do not knowingly request or collect data from minors. If a parent or guardian finds that a minor has given us data, they may request its immediate deletion by writing to the contact address in this policy.

8. Processors and third parties

To run the site and the project portal we use providers that process data on our behalf (data processors), under CONIKA's instructions and bound by contract to confidentiality and security: hosting, database and storage (Vercel, Supabase); scheduling and video calls (Google Calendar and Google Meet, to which we send your name and email address in order to create the appointment and the meeting link); hosting of your project's images (Cloudinary); storage of your project's files, meaning drawings, deliverables, virtual tours and interactive 3D models (Cloudflare R2); phone verification where applicable (Twilio); email delivery (Resend); abuse protection and access control (Upstash); and the payment gateway (Wompi). None of these providers is authorized to use your data for purposes of their own beyond providing the service to us.

The Meta pixel is different from the above and therefore stands on its own. It only loads if you accept cookies, and Meta does not act as our processor: it also processes that data for purposes of its own, so before the law it is an independent controller and CONIKA answers jointly with it for what is collected through the pixel. If you do not accept cookies, the pixel does not load and nothing travels to Meta. You may change your decision at any time from the cookie notice.

9. International transfer of data

Several of those providers store or process data on servers outside Colombia, mainly in the United States. When they do so on our behalf and following our instructions this is a transmission, and it does not require any additional authorization from you, because with each of them there is a contract setting out the scope of the processing and their obligations (Decree 1377 of 2013, articles 24 and 25).

When the recipient processes the data for purposes of its own this is an international transfer, and that is the case of the Meta pixel. There we rely on your express authorization, which is the one you grant by accepting cookies (article 26, subparagraph a, of Law 1581 of 2012), or on the transfer being necessary to perform the contract between you and CONIKA (subparagraph e of that same article).

10. Security incident notification

Should there be a security breach compromising the confidentiality, integrity or availability of your data, we will inform you by email without undue delay, together with the measures taken to mitigate it, and we will report the incident to the Superintendency of Industry and Commerce where the law requires it.

11. Cookies

The site uses cookies as described in the Cookie Policy.

12. How long we keep each thing

These are the periods, counted from the last contact or from the end of the project, as applicable:

· Enquiries and bookings that did not lead to a project: two (2) years.

· Project data, the signed Commitment and the evidence of that signature (including your identification document number, which is stored encrypted): ten (10) years from termination. That is the period during which the law still allows a claim to be brought over that contract, so it is also the period in which both parties need to be able to prove what was agreed.

· Messages from your project chat: for the duration of the project and five (5) years thereafter.

· Access and security logs (IP address, device and time of each sign-in): one (1) year.

· Your project's pieces hosted in the portal: heavy deliverables (drawings, working files and video) are withdrawn from the portal thirty (30) days after they are published. The studio keeps its own copy and restores them to you whenever you need them; the period belongs to the portal, not to the file.

· Virtual tours and interactive 3D models: one (1) year of hosting from delivery, included in the price. After that year they stay online only if you take out the hosting subscription; if you do not, the address stops responding and the file is handed over to you to keep or to host wherever you prefer.

· Accounting records of payments: ten (10) years, by legal obligation. We never held your card or account details: they are processed and kept by the payment gateway.

If you request deletion of your data, we erase everything not subject to one of the legal periods above, and we tell you exactly what remains and why.

We apply reasonable security measures (encryption of your identification document number and of the chat messages, cryptographic fingerprints of your access keys, attempt limits, restricted access to the databases); no system is 100% infallible.

13. Term and changes

This policy is in force from the date it is published. We may update it to reflect legal, technical or service changes; the version in force is the one published on this page, with its update date. If the change is material and affects clients with an active project, we will notify you by email.