Saltar al contenido principal
Procaps, S.A. and its affiliated entities are not related to Andrew Lessman or his company ProCaps Laboratories, Inc. which are based in the U.S. Procaps, S.A. and its affiliated entities have no U.S. operations using the name or mark 'Procaps' and do not offer products or services in the U.S. using the name or mark 'Procaps'.
Personal data protection and processing policy

Personal data protection and processing policy

  Code: POL-0046 | Version: 04

PROCAPS S.A. 
NIT 890.106.527-5
Calle 80 No. 78 B – 201

Phone: +57 (605) 3854321 | +57 (605) 3092286
contacto@procaps.com.co 
Barranquilla (Atlántico) – Colombia.

This "Personal Data Protection and Processing Policy" (hereinafter "the Policy") establishes the guidelines, rules and commitments adopted by the company PROCAPS S.A (hereinafter "PROCAPS") to guarantee the appropriate processing of personal data, in accordance with Ley 1581 de 2012, Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015), and other applicable rules in Colombia.

This Policy applies to the personal data that PROCAPS collects, administers, stores, uses, circulates, transfers or deletes, whether acting as Data Controller or as Data Processor on behalf of a third party, within the framework of its operations and activities. Likewise, this Policy applies to personal information that, due to the nature of PROCAPS' technological operation and its centralized infrastructure, is processed or held in its systems, platforms and technological environments, even when it is accessible or used from other jurisdictions under agreements and controls established by PROCAPS.

The purpose of this Policy is to compile the principles, rules and good practices governing the processing of personal data with respect to the Data Subjects with whom PROCAPS relates (including, among others, customers, consumers, suppliers, contractors, candidates, workers, shareholders and other stakeholders), in order to protect their rights, ensure regulatory compliance and promote demonstrated accountability in all operations and activities.

In the development of its operating and technological model, PROCAPS may process personal data on behalf of its affiliates and subsidiaries located in Colombia or abroad, when such entities act as Data Controllers and PROCAPS acts as Data Processor to provide technological, operational or support services. For these cases, PROCAPS has entered into and will continue to enter into data transmission agreements that define the scope of the processing, the Controller's instructions, confidentiality and security obligations, the prohibition on use for its own purposes, incident management, sub-processor control, remote access conditions, the return or deletion of information, and other safeguards required by Colombian regulations.

This Policy incorporates mechanisms to ensure that personal data is:

  • Processed lawfully, fairly and transparently in relation to the data subject.
  • Collected for determined, explicit and legitimate purposes, and not further processed in a manner incompatible with those purposes.
  • Adequate, relevant and limited to what is strictly necessary in relation to the purposes for which it is processed.
  • Accurate and up to date; adopting reasonable measures for its correction or deletion when appropriate.
  • Retained only for as long as necessary to fulfill the purposes of the processing and applicable legal or contractual obligations.
  • Processed under reasonable security controls and measures proportional to the risk, and under a demonstrated accountability approach.
This Policy is issued as part of PROCAPS' demonstrated accountability approach, in order to evidence the implementation of controls and measures for the protection of personal data and the management of risks associated with processing.

PROCAPS recognizes that, due to the nature of its operation and its technological infrastructure, certain processing activities may involve cross-border access, international transmission, or the involvement of third parties located outside Colombia. In such cases, PROCAPS will adopt contractual, technical and organizational safeguards that ensure standards equivalent to those required by Colombian regulations, particularly when the processing involves jurisdictions with different levels of protection.

PROCAPS will apply a demonstrated accountability and risk management approach to personal data protection, incorporating privacy by design and by default in its processes and technologies. When a processing activity may involve a high risk to the rights of data subjects — including sensitive data, biometric data, automated decisions or the use of artificial intelligence — PROCAPS will carry out prior assessments and, where appropriate, impact assessments, documenting technical, organizational and contractual safeguards. This Policy is supplemented by privacy notices and specific authorizations provided to the data subject at the time of collection, depending on the applicable channel or process.

This Policy does not constitute a contract; it reflects PROCAPS' commitment to the protection of the personal information of data subjects and to compliance with the Colombian personal data protection regime. In compliance with Ley 1581 de 2012 and its applicable regulations, PROCAPS makes available to data subjects this Personal Data Protection and Processing Policy, as well as the channels for the exercise of their rights.
 

1. OBJECTIVE

To establish the guidelines, criteria and rules applicable to the collection, consultation, storage, ordering, classification, cataloguing, analysis, processing, use, circulation, transfer, transmission, deletion and other forms of processing carried out by PROCAPS, whether in its capacity as Controller and/or Processor, in order to guarantee the protection of the rights of data subjects, compliance with the applicable principles and legal duties, and the appropriate management of risks associated with the processing of personal data, in accordance with Ley Estatutaria 1581 de 2012, Decreto 1074 de 2015 and other rules that modify, regulate, add to or replace them. The foregoing includes processing carried out through manual and automated processes, technological tools, digital platforms and, where applicable, advanced analytics or artificial intelligence systems.

2. SCOPE

This Policy applies to all processing of personal data contained in physical, electronic or digital databases or files, carried out by PROCAPS in the development of its corporate purpose, and its corporate, administrative, labor, commercial, contractual, security and stakeholder-relationship processes, whether it acts as "Data Controller" and/or "Data Processor" on behalf of a third party.

3. MANDATORY NATURE AND ADDRESSEES

This Policy is mandatory for direct and indirect employees, contractors, consultants, suppliers, legal representatives, executives, interns, partners, Processors, third parties and, in general, for any person who, by reason of their functions, activities or relationship with PROCAPS, accesses, collects, stores, uses, consults, circulates, deletes or otherwise processes personal data on behalf of the company.

Process leaders and Senior Management must promote its effective implementation, ensure the allocation of necessary resources, and adopt the supervision and control measures appropriate to their respective areas of competence.

4. IDENTIFICATION OF THE COMPANY RESPONSIBLE FOR PROCESSING

The Data Controller for the personal data covered by this Policy is PROCAPS S.A., a commercial company identified with NIT No. 890.106.527-5, with commercial registration No. 24802 dated July 26, 1976, with its principal domicile at Calle 80 NO. 78 B – 201, in the city of Barranquilla (Colombia).

For purposes of the exercise of data subjects' rights and the handling of inquiries, complaints and requests related to the protection and processing of personal data, PROCAPS will make available the contact channels indicated in this Policy or in the applicable Privacy Notice.

5. CONTACT CHANNELS

To exercise their rights to know, consult, update, correct, or delete their personal data, revoke Authorization when appropriate, or file petitions, inquiries or complaints related to the processing of their personal data, data subjects, their successors or their attorneys-in-fact may contact PROCAPS through the following contact channels:

City Address Email Phone
Barranquilla (Colombia) Calle 80 NO. 78 B - 201 habeasdata@procaps.com.co +57 (605) 3854321

Area responsible for handling petitions, inquiries and complaints: Legal Compliance Area.

The contact channels indicated herein may be updated by PROCAPS when necessary for operational, administrative or technological reasons. Such changes will not constitute a substantial modification of this Policy and will be communicated to data subjects through the update of the information published on the website, privacy notice, or other corporate media made available for that purpose.

6. APPLICABLE REGULATORY FRAMEWORK

This Policy is based on, among others, the following provisions:
  • Constitución Política de Colombia, artículo 15.
  • Ley 1266 de 2008, to the extent applicable.
  • Ley 1581 de 2012.
  • Decreto Reglamentario 1377 de 2013 and Decreto 886 de 2014, to the extent applicable and to the extent not compiled or developed by Decreto 1074 de 2015.
  • Decreto Único Reglamentario 1074 de 2015, particularly the provisions applicable to the processing of personal data.
  • Ley 2300 de 2023, with respect to channels, hours, frequency and contactability rules, when applicable.
  • Circular Externa 01 de 2024 de la Superintendencia de Industria y Comercio.
  • Circular Externa 02 de 2024 de la Superintendencia de Industria y Comercio.
  • Circular Externa 03 de 2024 de la Superintendencia de Industria y Comercio.
  • Circular Externa 02 de 2025 de la Superintendencia de Industria y Comercio.
  • Circular Externa 03 de 2025 de la Superintendencia de Industria y Comercio.
  • All other rules, instructions, guidelines, circulars and decisions of the competent authority that modify, add to, replace or are otherwise applicable to the processing and protection of personal data in Colombia.

7. DEFINITIONS

For purposes of the interpretation, application and implementation of this Policy, the following definitions shall apply:
AUTHORIZATION: Prior, express and informed consent of the data subject to carry out the processing of personal data.
PRIVACY NOTICE: Verbal or written communication generated by the party responsible for the information and addressed to the data subject regarding the processing of their data, by means of which the data subject is informed of the existence of the processing policies applicable to them, the way to access them, and the purposes of the processing intended to be given to the personal data.
DATABASE: An organized set of personal data that is subject to processing.
CHANNELS FOR EXERCISING RIGHTS: The means of receipt and handling of petitions, inquiries and complaints that the Data Controller and the Data Processor must make available to Data Subjects.
DATA TRANSMISSION AGREEMENT: Agreement by which PROCAPS, acting as Data Processor, is authorized by one of its subsidiaries and/or affiliates to process personal data on their behalf, delimiting the scope of the processing, and the obligations of confidentiality, security, restricted use, subcontracting, incidents, and deletion or return of information.
ANONYMIZED DATA: Information that has undergone a technical process that prevents the reasonable identification of the data subject, directly or indirectly, irreversibly or with a non-significant risk of re-identification.
BIOMETRIC DATA: Sensitive personal data relating to the physical, physiological or behavioral characteristics of a natural person, which allows or confirms their unique identification, such as fingerprints, facial recognition, iris, voice, hand geometry or similar.
PERSONAL DATA: Any piece of information linked to one or several identified or identifiable individuals, or that can be associated with a natural person.
PUBLIC DATA: Data that is not semi-private, private or sensitive. Public data includes, among others, data relating to a person's marital status, profession or occupation, and their status as a merchant or public servant. By their nature, public data may be contained, among others, in public records, public documents, official gazettes and bulletins, and duly enforced court rulings that are not subject to confidentiality.
SENSITIVE DATA: Sensitive data is understood as data that affects the privacy of the data subject or whose improper use may lead to their discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in unions, social organizations, human rights organizations or organizations promoting the interests of any political party or guaranteeing the rights of opposition political parties, as well as data related to health, sexual life, and biometric data.
AUTOMATED DECISION: A decision made wholly or partially through automated means, with no or minimal significant human intervention, which may produce legal effects or significantly impact a data subject.
DATA PROCESSOR: A natural or legal person, whether public or private, who by itself or in association with others, carries out the Processing of personal data on behalf of the Data Controller.
PERSONAL DATA PROTECTION IMPACT ASSESSMENT: A prior analysis tool through which PROCAPS identifies, evaluates and documents the risks that the processing of personal data may generate for the rights and freedoms of data subjects, as well as the measures foreseen to prevent, mitigate or control them.
HABEAS DATA: The right of any person to know, update and correct information collected about them in data banks and files of public and private entities.
INFORMATION SECURITY INCIDENT: An actual or potential event that compromises or may compromise the confidentiality, integrity, availability, authenticity or security of personal data processed by PROCAPS, including unauthorized access, loss, leakage, alteration, destruction, improper disclosure or unauthorized use of the information.
PUBLICLY ACCESSIBLE INFORMATION: Information available in environments or sources accessible to an indeterminate number of people, which does not by itself imply that it has the nature of public data, nor does it automatically enable its processing without a sufficient legal basis.
PERSONAL DATA PROTECTION AND PROCESSING POLICY: The formal document approved by PROCAPS reflecting the conditions applicable to any processing operation involving Personal Data.
PRIVACY BY DESIGN AND BY DEFAULT: An approach under which PROCAPS incorporates personal data protection measures from the planning, design, acquisition, development, implementation and operation of processes, products, services, technologies and information systems, ensuring that, by default, only the personal data necessary for each legitimate purpose is processed.
DATA CONTROLLER: A natural or legal person, whether public or private, who by itself or in association with others, decides on the database and/or the Processing of the data.
PSEUDONYMIZATION: The processing of personal data in such a way that the information can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the data is not attributed to an identified or identifiable person.
ARTIFICIAL INTELLIGENCE SYSTEM: A machine-based system that, for explicit or implicit objectives, can infer from the information it receives how to generate outputs such as predictions, content, recommendations, classifications or decisions that influence physical or virtual environments.
DATA SUBJECT: A natural person whose personal data is subject to processing.
PROCESSING: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.
TRANSFER: A transfer of data occurs when the Controller and/or Processor of personal data, located in Colombia, sends the information or personal data to a recipient who is, in turn, a Data Controller and is located inside or outside the country.
TECHNOLOGY TRANSFER: Any operation or legal transaction by which PROCAPS acquires, licenses, implements, assigns, integrates, develops, receives or makes available technologies, platforms, applications, tools, infrastructure or solutions that involve or may involve the processing of personal data.
TRANSMISSION: The processing of personal data that involves communicating such data within or outside the territory of the Republic of Colombia when its purpose is the carrying out of processing by the Processor on behalf of the Controller.

8. PRINCIPLES

In the development, interpretation and application of Ley 1581 de 2012, which sets out general provisions for the protection of personal data, and the rules that supplement, modify or add to it, the following guiding principles shall apply harmoniously and comprehensively:
PRINCIPLE OF LEGALITY: The Processing of data is a regulated activity that must be subject to the provisions of the law and other provisions developing it.
PRINCIPLE OF PURPOSE: Processing must respond to a legitimate purpose in accordance with the Constitution and the Law, which must be communicated to the data subject. With respect to the collection of personal data, PROCAPS will limit itself to data that is relevant, adequate and necessary for the purpose for which it was collected or requested, in accordance with applicable regulations and its internal procedures.
PRINCIPLE OF FREEDOM: Processing may only be carried out with the prior, express and informed consent of the data subject. Personal data may only be obtained or disclosed with prior authorization, or where there is a legal or judicial mandate that relieves the need for consent.
PRINCIPLE OF TRUTHFULNESS OR QUALITY: Information subject to processing must be truthful, complete, accurate, up to date, verifiable and understandable. The processing of partial, incomplete, fragmented or misleading data is prohibited.
PRINCIPLE OF TRANSPARENCY: Processing must guarantee the right of the data subject to obtain from the Data Controller or the Data Processor, at any time and without restrictions, information about the existence of data concerning them.
PRINCIPLE OF RESTRICTED ACCESS AND CIRCULATION: Processing is subject to the limits arising from the nature of personal data, the provisions of the law and the Constitution. Accordingly, processing may only be carried out by persons authorized by the data subject and/or by persons provided for by law. Personal data, except for public information, may not be available on the internet or other mass disclosure or communication media, unless access is technically controllable to provide restricted knowledge only to data subjects or third parties authorized in accordance with the law.
PRINCIPLE OF SECURITY: Information subject to processing by PROCAPS must be handled with technical, human, administrative and organizational measures that are reasonable and proportional to the risk, in order to provide security for records and prevent their adulteration, loss, unauthorized or fraudulent consultation, use, access or disclosure.
PRINCIPLE OF CONFIDENTIALITY: PROCAPS is obligated to guarantee the confidentiality of information, even after the end of its relationship with any of the tasks comprising the processing, and may only supply or communicate personal data when this corresponds to the development of activities authorized by law.
Without prejudice to the guiding principles set out in Ley 1581 de 2012, PROCAPS will adopt the following as complementary corporate criteria for the interpretation and application of this Policy:
DEMONSTRATED ACCOUNTABILITY: PROCAPS will adopt useful, timely, efficient, verifiable and documented measures to demonstrate compliance with the personal data protection regime, including the implementation of internal controls, allocation of responsibilities, retention of evidence, incident management, training and periodic monitoring.
NECESSITY, PROPORTIONALITY AND MINIMIZATION: PROCAPS will seek to limit the processing of personal data to what is strictly relevant, adequate and necessary for the legitimate purpose communicated to the data subject, avoiding excessive collection, use or retention of information.
PRIVACY BY DESIGN AND BY DEFAULT: PROCAPS will incorporate personal data protection measures from the planning, design, acquisition, development, implementation and operation of processes, products, services, contracts, technological tools and information systems, ensuring that, by default, only the personal data necessary for each purpose is processed.
COMPREHENSIVE RISK MANAGEMENT: PROCAPS will identify, assess, document and manage risks associated with the processing of personal data, particularly when it involves emerging technologies, mass processing, sensitive data, biometric data, automated decisions, international transfers or third parties acting on behalf of the company.

9. RIGHTS OF THE DATA SUBJECT

The data subject shall have the following rights:
  • To know, update and correct their personal data with respect to PROCAPS, in its capacity as Controller and/or Processor. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented data, data that is misleading, or data whose processing is expressly prohibited or has not been authorized.
  • To request proof of the authorization granted to PROCAPS, except where expressly exempted as a requirement for processing, in accordance with the law.
  • To be informed by PROCAPS, upon request, of the use given to their personal data.
  • To file complaints with the Superintendencia de Industria y Comercio for violations of the provisions of Ley 1581 de 2012 and other rules that modify, add to or supplement it, once the consultation or complaint procedure before PROCAPS has been exhausted, when applicable.
  • To revoke the authorization and/or request the deletion of data when the Processing does not respect the constitutional and legal principles, rights and guarantees.
  • To access, free of charge, their personal data that has been subject to processing.

10. RIGHTS OF CHILDREN AND ADOLESCENTS

PROCAPS will ensure at all times respect for the prevailing rights of children and adolescents. As a general rule, the processing of their personal data is prohibited, except for data that is public in nature or in cases where such processing is exceptionally appropriate in accordance with the law.
In cases where PROCAPS must process personal data of children or adolescents, such processing will only be carried out when:
  • it responds to and respects the best interests of the child or adolescent;
  • it ensures respect for their fundamental rights;
  • it is strictly necessary and proportional to the purpose pursued;
  • it has the prior and express authorization of the minor's legal representative; and
  • the right of the child or adolescent to be heard has been guaranteed, valuing their opinion according to their maturity, autonomy and ability to understand the matter, to the extent possible.

PROCAPS will ensure the appropriate use of the personal data of children and adolescents and will apply, in all cases, the principles and obligations set forth in the current regulations on personal data protection.

11. DUTIES OF PROCAPS

  • To use the information contained in databases only for the purpose for which it is authorized.
  • To guarantee the data subject, at all times, the full and effective exercise of the right of Habeas Data.
  • When collecting personal data, to limit itself to data that is relevant and adequate for the purpose for which it is required, in accordance with the law. No deceptive or fraudulent means shall be used for this purpose.
  • To keep the information under the security conditions necessary to prevent its adulteration, loss, unauthorized or fraudulent consultation, use or access.
  • To carry out, in a timely manner, the update, correction or deletion of data under the terms set forth in this Policy in the Procedures - Complaints section.
  • To enable electronic or other communication channels considered appropriate to timely address inquiries and complaints presented by data subjects.
  • The information requested must be provided free of charge and through any means, as required by the data subject. Information must be easy to read, free of technical barriers preventing access, and must strictly correspond to the information held in the database.
  • In the event the certification of authorized information is requested physically and/or needs to be sent by certified mail, PROCAPS may require the requester to pay the corresponding costs, without at any time charging more than what was actually billed; if required, PROCAPS must demonstrate to the Superintendencia de Industria y Comercio the support for such expenses.
  • To adopt other necessary measures to keep the information provided up to date.
  • To correct information when it is incorrect.
  • To comply with instructions and requirements issued by the Superintendencia de Industria y Comercio.
  • To refrain from circulating information that is being disputed by the data subject and whose blocking has been ordered by the Superintendencia de Industria y Comercio.
  • To allow access to information only to persons who may have access to it.
  • To inform the Superintendencia de Industria y Comercio when there are violations of security codes and risks in the administration of data subjects' information.
  • To establish the mechanisms necessary to obtain the authorization of data subjects for the processing of their data, which may be granted through a physical, electronic or any other format that guarantees its subsequent verification.
  • It is PROCAPS' obligation to retain proof of the authorization and provide a copy to the data subject if requested.
  • To establish simple and free mechanisms allowing the data subject to request the reporting, modification, deletion or update of data, which may be the same mechanisms used to grant consent, without prejudice to any costs that may arise in connection with the issuance and sending thereof.
  • Information subject to processing must be protected through the use of technical, human and administrative measures necessary to provide security for records, preventing their unauthorized or fraudulent adulteration, loss, consultation, use or access. For this purpose, PROCAPS will maintain mandatory security protocols for personnel with access to personal data and information systems.
  • PROCAPS personnel involved in the processing of personal data are obligated to guarantee the confidentiality of information, even after the end of their relationship with any of the tasks comprising the processing, in accordance with the provisions of the employment contract and/or other provisions applicable to the relationship between the employee and the company.
  • To designate a "Personal Data Officer" to assume the function of personal data protection and who will also ensure that, through the contact channels, data subjects' requests are processed.
  • In principle, the processing of personal data of children and adolescents is prohibited by law, except for data of a public nature and/or when such processing meets the parameters and requirements set forth in this Policy.
  • PROCAPS will use personal data in accordance with the authorization given by the data subject and will only transmit or transfer it to partners, affiliates or subsidiaries, or third parties who may use the information for the development of their tasks acting on behalf of PROCAPS and/or in compliance with authorities' requirements, adhering to applicable laws and respecting the Service Agreements in force with third parties.
  • Personal data may only be collected, stored, used or circulated for as long as reasonable and necessary, in accordance with the purposes that justified its processing, taking into account legal provisions and administrative, accounting, tax, legal and historical aspects of the information. Once the purpose of the processing has been fulfilled, and without prejudice to legal rules providing otherwise, PROCAPS must delete the personal data. However, personal data must be retained when required to comply with a legal or contractual obligation.
  • To evidence the existence of the "Personal Data Protection and Processing Policy" and the way to access it, which will be published on the company's website, on social media, and at the main office.
  • For the collection, use and processing of personal data, PROCAPS must comply with the following parameters: (i) the processing of collected personal data must respond to a legitimate purpose, of which the data subject must be informed; (ii) the processing of personal data may only be carried out with the prior, express and informed consent of the data subject; (iii) personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate relieving the need for consent; (iv) information subject to processing must be truthful, complete, accurate, up to date, verifiable and understandable; (v) the processing of partial, incomplete, fragmented or misleading data is prohibited; (vi) the right of the data subject must be guaranteed to obtain, at any time and without restrictions, information about the existence of data concerning them.
  • In the event of a substantial modification to this "Personal Data Protection and Processing Policy," PROCAPS must again request the data subject's authorization for the processing of their data.
  • To identify, assess, manage and monitor the risks associated with the processing of personal data, especially when they involve sensitive data, biometric data, minors, video surveillance, artificial intelligence, automated decisions, international transfers or third parties.
  • To incorporate privacy by design and by default criteria into processes, products, services, technologies, information systems and third-party relationships involving the processing of personal data.
  • To carry out personal data protection impact assessments when the processing may generate high risks to the rights of data subjects, especially in cases involving new technologies, artificial intelligence, mass processing, biometric data, automated decisions or sensitive data.
  • To maintain verifiable evidence of compliance with personal data protection regulations and of the measures adopted for their implementation.
  • When PROCAPS uses artificial intelligence, advanced analytics, profiling or automated processes involving the processing of personal data, to ensure that their use is legitimate, necessary, proportional, verifiable and supervised, and to adopt measures to prevent bias, errors, discrimination and disproportionate impacts on data subjects.
  • To guarantee mechanisms for supervision and human review when the processing of personal data serves as the basis for automated or semi-automated decisions with legal effects or relevant impacts on data subjects.
  • To refrain from processing personal data obtained from the internet, social media or open sources merely because it is publicly accessible, without first verifying the existence of a sufficient legal basis.
  • To verify that third parties who access personal data on behalf of PROCAPS offer sufficient guarantees of confidentiality, security and regulatory compliance, and to execute the corresponding contractual instruments.
  • To carry out prior due diligence in the acquisition, implementation or updating of technologies involving the processing of personal data, in order to identify their impacts and risks in terms of privacy and security.
  • To implement internal procedures for the identification, reporting, containment, analysis, mitigation, documentation, remediation and closure of security incidents affecting personal data, as well as adopting corrective and preventive measures aimed at preventing their recurrence.
  • To implement periodic training, awareness and updating programs aimed at personnel involved in the processing of personal data, according to the level of access, the criticality of the process and the risks associated with their functions.
  • To respect, where applicable, the channels authorized by data subjects for sending commercial or advertising communications, address requests for exclusion, opposition or revocation, and consult the applicable legal exclusion mechanisms before carrying out commercial prospecting activities. To define and implement internal criteria, deadlines or retention, blocking, anonymization, filing and secure deletion schedules for personal data, taking into account the purpose of the processing, the nature of the data, legal or contractual obligations and the risks of excessive retention. To periodically review and update this Policy, as well as internal procedures related to personal data protection, when there are regulatory, operational, technological, contractual or risk-related changes that make this necessary.

12. AUTHORIZATION POLICY

Without prejudice to the exceptions provided by Law, the processing of personal data by PROCAPS requires the prior, express and informed Authorization of the Data Subject, which must be obtained through any means subject to subsequent verification. The Authorization may be expressed in writing, orally, or through unambiguous conduct of the data subject allowing one to reasonably conclude that it was granted. Silence may under no circumstances be understood as Authorization.

When requesting Authorization, PROCAPS must clearly and expressly inform:
  • The name and identification of the person from whom Authorization is being requested.
  • The identification and contact channels of PROCAPS as Data Controller.
  • Identification of the data being collected, when applicable.
  • The specific purposes for which the Authorization is requested.
  • The contact channels and the procedure for exercising rights of consultation, updating, correction, deletion and revocation.
  • The rights held by the data subject.
  • The optional nature of responses to questions or requests concerning sensitive data or the data of children and adolescents, when applicable.

When the Authorization includes several purposes, PROCAPS will seek to clearly distinguish them, differentiating necessary purposes from ancillary or optional ones. The data subject's refusal with respect to the latter will not affect the main relationship, unless it involves data or purposes that are strictly indispensable.

PROCAPS may use privacy notices, short formats, forms, messages, electronic interfaces or any other suitable mechanism to inform the data subject about the processing of their personal data and how to access this Policy, without prejudice to the obligation to obtain Authorization when legally required.

When PROCAPS uses the privacy notice, it shall be intended to inform the data subject about the existence of this Policy, how to access it, the purposes of the processing, the rights held by the data subject, and the mechanisms available to learn of substantial changes thereto. Disclosure of the privacy notice does not exempt PROCAPS from making this Policy known to the data subject.

In the event of substantial changes to the identification of PROCAPS or to the purposes of the processing that may affect the content of the Authorization, PROCAPS will timely inform the data subject of such changes before implementing them. When the substantial change relates to the purpose of the processing, PROCAPS will request a new Authorization.

Sole Paragraph. When, for technical, operational, space, format, character-count or channel-related reasons, it is not possible to include all the information set forth herein in the Authorization, PROCAPS may supplement it by expressly referring to this Personal Data Protection and Processing Policy and/or to the applicable Privacy Notice, which shall be deemed incorporated by reference for all purposes, provided that the data subject is informed of a clear, simple and permanent way to access or consult them.

13. PRIVACY NOTICE

When it is not possible to make this Personal Data Protection and Processing Policy available to the data subject at the time information is collected, PROCAPS will inform, by means of a Privacy Notice, of the existence of this Policy, how to access it, the purposes of the processing and other relevant information about the processing of personal data, at the latest at the time of collection.

PROCAPS may use general or specific privacy notices, depending on the channel, medium, process, activity, service, form, application, microsite, event, program or point of contact through which personal data is collected. Such notices may supplement this Policy and further develop, in greater detail, aspects related to the scope of the processing, the categories of data collected, the specific purposes, the use of technologies such as cookies, the recipients of the information, retention conditions, the channels for exercising rights and other particular conditions applicable in each case.
The Privacy Notice shall contain, at a minimum:

  • The identification and contact details of PROCAPS.
  • The processing to which personal data will be subjected and its purpose.
  • The rights held by the data subject.
  • The mechanisms available for the data subject to learn of this Policy and any substantial changes made to it or to the corresponding Privacy Notice.

The Privacy Notice may be disclosed through physical or electronic documents, forms, data messages, web pages, applications, microsites, banners, printed notices, bulletin boards, phone recordings or any other suitable mechanism that guarantees the duty to inform the data subject.

The current Privacy Notice may be consulted by data subjects in the privacy section available on the following website: www.sofgenpharma.com
Sole Paragraph. The Privacy Notice may be modified, updated or replaced by PROCAPS when necessary. Substantial changes made to it will be communicated to data subjects through the same means or mechanisms used for its disclosure, or through any other suitable means allowing its knowledge and consultation.

14. EVENTS IN WHICH THE AUTHORIZATION OF THE DATA SUBJECT IS NOT REQUIRED

The Authorization of the data subject will not be required in the following cases:
  • Information required by a public or administrative entity in the exercise of its legal functions or by court order.
  • Data of a public nature.
  • Cases of medical or health emergencies.
  • Processing of information authorized by law for historical, statistical or scientific purposes.
  • Data related to the Civil Registry of persons.

First Paragraph. When PROCAPS processes personal data under the protection of any of the legal exceptions in which the data subject's Authorization is not required, it will keep an internal record of the applicable exception, the purpose of the processing, the source of the information and, where applicable, the legal, administrative, contractual, health or judicial basis justifying its appropriateness.

Second Paragraph. When applicable, PROCAPS may obtain the data subject's Authorization through unambiguous conduct that reasonably allows one to conclude that the data subject authorized the processing of their personal data, provided that they were previously clearly informed of the existence of the processing, its purpose, and how to access the Personal Data Protection and Processing Policy or the corresponding Privacy Notice. In telephone channels, the voluntary continuation of the call after the notice about the processing of data may constitute unambiguous conduct, provided there is sufficient prior information. In video surveillance systems, voluntary entry into or presence in duly marked areas may constitute unambiguous conduct for the capture of images for security purposes, access control or protection of assets and facilities.

15. LEGITIMATION FOR THE EXERCISE OF THE DATA SUBJECT'S RIGHT

The rights of the data subject established by Law may be exercised by the following persons:
  • By the data subject, who must sufficiently prove their identity through the various means made available by PROCAPS.
  • By the data subject's successors, who must prove such status.
  • By the representative and/or attorney-in-fact of the data subject, upon prior proof of representation or power of attorney.
  • By stipulation in favor of another or for another.
  • The rights of children and adolescents shall be exercised by the persons empowered to represent them.

Sole Paragraph. Before attending to a petition, inquiry or complaint, PROCAPS may verify the identity of the requester and require proof of the capacity in which they act, including, where applicable, documents proving the status of successor, legal representative or attorney-in-fact. The information requested for these purposes must be relevant and limited to what is strictly necessary to validate legitimation.

16. PROCESSING TO WHICH THE DATA WILL BE SUBJECTED AND ITS PURPOSE

The processing of the personal data of the data subjects with whom PROCAPS relates in the development of its corporate purpose, including customers, suppliers, consumers, distributors, contractors, candidates, employees, shareholders and other stakeholders, will be carried out in accordance with the applicable legal framework and with the following general purposes, without prejudice to the specific purposes communicated to the data subject at the time their personal data is collected:

  • To internally manage the commercial, contractual, operational and administrative relationship with customers, distributors, suppliers and other stakeholders of PROCAPS' various business segments.
  • To send communications, correspondence, text messages, instant messaging messages, emails or make telephone contact with customers, distributors and consumers, through channels authorized and permitted by law, in connection with commercial, advertising, marketing, promotional, sales and other related activities.
  • To carry out personnel selection processes, manage contractual and employment relationships, ensure compliance with the obligations arising therefrom, and grant benefits to employees, directly or through third parties.
  • To carry out potential analysis, segmentation and profiling for commercial purposes with respect to suppliers, distributors and/or customers, when applicable and in accordance with the authorizations granted and applicable regulations.
  • To manage procedures, requests, petitions, complaints and claims; carry out risk analysis; and conduct satisfaction surveys regarding PROCAPS' products and services.
  • To manage, analyze and investigate events, incidents, quality complaints and other developments related to the pharmaceutical products marketed by PROCAPS, including pharmacovigilance activities, when applicable.
  • To monitor persons who consume and/or acquire products marketed by PROCAPS, for purposes of attention, support, quality, product safety, management of requests and other related activities.
  • To carry out corporate social responsibility activities directed at PROCAPS' various stakeholders.
  • To manage the security of persons, property, facilities and information assets in PROCAPS' custody.
  • To organize, structure, store, safeguard and administer databases for the development of the purposes described in this Policy.
  • To comply with legal, regulatory, contractual, administrative and judicial obligations, and to respond to requirements of competent authorities.
In particular, and depending on the stakeholder group involved, PROCAPS may process personal data for the following specific purposes:
Purposes with respect to customers or users of products or services:
  • To carry out the relevant procedures for the development of the pre-contractual, contractual and post-contractual stage with PROCAPS, with respect to any of the products or services offered by the company, whether or not acquired by the Data Subject, or with respect to any underlying business relationship they have with PROCAPS.
  • To register the Data Subject in the systems, spreadsheets, lists, files or records, whether physical or electronic, administered by PROCAPS, for purposes of executing the commercial legal relationship established with the company.
  • To carry out electronic invoicing procedures for products or services acquired by the Data Subject.
  • To maintain support for operations, monitor incidents, and comply with contractual and legal obligations.
  • To comply with the legal, regulatory and contractual obligations incumbent on PROCAPS.
  • To send messages, notifications or alerts through channels authorized and permitted by law, to send and disclose legal, security, contractual, corporate, educational, commercial, advertising, promotional, marketing information, raffles, events or other benefits.
  • To send electronic messages, make telephone contact, or communicate through channels authorized and permitted by law, to confirm, update or validate the Data Subject's personal data when necessary for the execution of the legal relationship established with PROCAPS.
  • To contact the Data Subject through email, instant messaging, text messages, formal communications or phone calls, to send contractual or informational documents, account statements or invoices related to the obligations arising from contracts entered into with PROCAPS.
  • To provide information to third parties contractually linked to PROCAPS, when necessary for the execution of the contracted purpose, the provision of associated services, or compliance with legal or contractual obligations.
  • To carry out filing and document management tasks, in accordance with applicable legal provisions.
  • To carry out administrative and analytical activities, such as administration of accounting information systems, invoicing, audits, marketing and, where applicable, check processing and verification.
  • To share information with commercial partners for the offering of products and services, complying with the authorizations required by law and by this Policy.
  • To communicate PROCAPS product news and invite to events or programs organized by the company.
  • To handle petitions, complaints, claims, requests, returns, warranties and other procedures related to products or services offered by PROCAPS.
  • To consult, verify and confirm the Data Subject's credit and commercial information at Risk and/or Information Bureaus, or before any other public or private, national, foreign or multilateral entity administering or managing databases of credit, financial, commercial or service information, for purposes of evaluating and, where applicable, granting financing for goods or products acquired from PROCAPS, provided the corresponding authorization has been obtained.
  • To make reports to risk and information bureaus, complying with the conditions and procedures established in current regulations, especially Ley 1266 de 2008 and related rules.
  • To administer and manage the risks of Money Laundering, Terrorist Financing, corruption and, where applicable, financing of the proliferation of weapons of mass destruction, through procedures of counterparty and beneficial owner knowledge and verification, due diligence, list screening, alert identification, monitoring, adoption of control measures and attention to requirements of competent authorities.
  • To manage reports, alerts, quality complaints, product safety events, and pharmacovigilance or technovigilance activities, when applicable.
Purposes with respect to Job Applicants:
  • To process employment applications received by PROCAPS from candidates, process them, and resolve them within the stipulated time, according to the selection process or job posting;
  • To contact the Data Subject through email, instant messaging, text messages, formal communications, phone calls and other channels authorized and permitted by law, in connection with the selection process or job posting.
  • To verify and validate the information provided by the candidate, including, where applicable, their résumé, academic background, work experience, references and other supporting documents related to the selection process.
  • To schedule, conduct and evaluate interviews, tests, assessments or other selection mechanisms defined by PROCAPS.
  • To evaluate the candidate's aptitude and suitability for the position sought and, where applicable, comply with preventive and occupational medicine requirements in accordance with current regulations.
  • To carry out PROCAPS' filing and document management tasks, in accordance with applicable legal provisions.
  • To retain the candidate's information for future selection processes, when this has been communicated to the data subject and is appropriate under the law.
  • To administer and manage the risks of Money Laundering, Terrorist Financing, corruption and other applicable compliance risks, through knowledge, validation and verification procedures defined by PROCAPS.
  • To share the candidate's information with affiliates, subsidiaries or associated companies with which PROCAPS maintains corporate or collaborative ties, when there is a vacancy or selection process for which their profile may be considered, provided that this has been communicated to the data subject and applicable regulations are complied with.
  • To carry out validations related to ethics, transparency, fraud prevention, conflicts of interest and other integrity checks that are appropriate within the selection process.
Purposes with respect to workers (employees):
  • To manage compliance with the terms established in the employment relationship, including affiliation and contributions to the social security system, execution of the employment contract, management of changes, generation and processing of payroll payments and employment benefits.
  • To comply with applicable regulations regarding labor, social security, pensions, occupational risks, family compensation funds, taxes and other legal obligations incumbent on PROCAPS.
  • To comply with instructions, requirements and orders issued by competent judicial, administrative or control authorities.
  • To implement and execute PROCAPS' labor, organizational, administrative and operational policies, procedures and strategies.
  • To include the Data Subject in training, development, evaluation, wellness, occupational health and safety, organizational culture and other programs and activities aimed at PROCAPS personnel.
  • To carry out preventive and occupational medicine activities, occupational health and worker health surveillance, together with the occupational risk administrator, occupational health providers and other authorized third parties, in accordance with applicable regulations.
  • To contact the Data Subject to give instructions, coordinate activities, send communications and manage matters related to the functions, responsibilities and obligations arising from the employment relationship.
  • To carry out filing, custody and document management tasks for employment information, in accordance with applicable legal provisions.
  • To create cards, credentials and/or identification mechanisms for the Data Subject, including, where necessary, proportional and legally appropriate, the processing of biometric data for identification and security purposes, which will be managed as sensitive data with the measures and authorizations required by law.
  • To establish and maintain access controls to facilities, restricted areas and physical or technological resources of PROCAPS, including, where necessary, proportional and legally appropriate, the use of biometric data for authentication, security and access control purposes, subject to applicable regulations on sensitive data.
  • To contact the Data Subject through email, instant messaging, text messages, formal communications, phone calls and other channels authorized and permitted by law, to send contractual, employment-related, administrative, informational or support documents related to the employment relationship.
  • To share information with commercial partners for the offering of products and services, complying with the authorizations required by law and by this Policy.
  • To communicate PROCAPS product news and invite the Data Subject to events, programs or activities organized by the company.
  • To carry out administrative and analytical activities, such as administration of information systems, accounting, invoicing, audits and, where applicable, check processing and verification.
  • To publish the Data Subject's face and personal image in management reports, internal communications, bulletin boards and corporate materials of PROCAPS, to document the organizational structure or training, development, wellness, occupational health and safety and other institutional activities, in accordance with applicable authorizations.
  • With respect to former employees, PROCAPS may retain, even after the employment contract has ended, the information necessary to comply with legal or contractual obligations arising from the employment relationship, attend to requirements of competent authorities, and issue employment certifications requested by the former employee or by third parties authorized by them.
  • To carry out validations related to ethics, transparency, fraud prevention, conflicts of interest and other integrity checks that are appropriate within the employment relationship.
  • To administer and manage the risks of Money Laundering, Terrorist Financing, Corruption and other applicable compliance risks, through knowledge, verification, due diligence and validation procedures defined by PROCAPS.
  • To manage the Data Subject's access to platforms, information systems, technological tools, corporate accounts, devices, credentials and other physical or digital resources necessary for the performance of their functions.
  • To evaluate performance, monitor compliance with objectives, competencies and responsibilities of the Data Subject, and to support training, development, promotion, internal mobility and succession processes.
  • To carry out internal actions, verifications and investigations related to compliance with employment obligations, internal regulations, corporate policies, confidentiality duties, appropriate use of resources, business ethics and other provisions applicable to the Data Subject.
  • To manage the security of the Data Subject, business continuity, emergency response, activation of contingency protocols and the protection of persons, property, facilities and information assets of PROCAPS.
  • To manage the Data Subject's emergency contact information and use it when necessary to respond to incidents, emergencies, health situations or contingencies related to their employment relationship.
  • To manage occupational health and safety activities, including reports, incident or accident investigations, occupational assessments, monitoring of restrictions or work recommendations, and compliance with preventive programs, in accordance with applicable regulations.
  • To manage trips, travel expenses, reservations, access, authorizations and other logistical aspects associated with the performance of the Data Subject's functions.
  • To administer extralegal benefits, agreements, allowances, wellness programs, insurance and other initiatives offered by PROCAPS or by third parties in favor of the Data Subject, in accordance with applicable authorizations.
  • To use the Data Subject's information to address requirements, complaints, audits, administrative, judicial or extrajudicial proceedings, and to defend PROCAPS' rights and interests.
  • To retain and use the information of former employees to attend to legal or contractual obligations, issue certifications, manage authorized employment references, attend to requirements from authorities, and defend PROCAPS' interests.
Purposes with respect to Suppliers or Contractors:
  • To register the Data Subject in the systems, spreadsheets, lists, files or records, whether physical or electronic, administered by PROCAPS, for purposes of providing the contracted services.
  • To carry out electronic invoicing procedures for contracted services.
  • To maintain support for operations, monitor incidents, and comply with contractual and legal obligations.
  • To comply with the legal, contractual, regulatory and administrative obligations incumbent on PROCAPS.
  • To send electronic messages, make telephone contact or communicate through channels authorized and permitted by law, to confirm or validate the Data Subject's personal data necessary for the execution of the legal relationship established with PROCAPS.
  • To contact the Data Subject through email, instant messaging, text messages, formal communications or phone calls, to send contractual or informational documents, account statements or invoices related to the obligations arising from contracts entered into with PROCAPS.
  • To grant access to supplier and/or contractor interaction portals or platforms to support PROCAPS' internal processes associated with the contractual relationship.
  • To provide information to third parties contractually linked to PROCAPS, when necessary for the execution of the contracted purpose, the provision of the service, associated operational management, or compliance with legal or contractual obligations.
  • To carry out PROCAPS' filing and document management tasks, in accordance with applicable legal provisions.
  • To validate, verify and consult the Data Subject's economic, commercial and transactional information for the purpose of establishing, executing and maintaining the legal relationship with PROCAPS.
  • To carry out administrative and analytical activities, such as administration of information systems, accounting, invoicing, audits, marketing and, where applicable, check processing and verification.
  • To share information with commercial partners for the offering of products and services, complying with all authorizations required by law and by this Policy.
  • To communicate PROCAPS product news and invite to events or programs organized by the company.
  • To consult, verify and confirm the Data Subject's credit and commercial information at risk or information bureaus, or before national or foreign public or private entities administering credit, financial, commercial or service databases, when applicable to the relationship with PROCAPS.
  • In order to make reports to risk and information bureaus, all conditions and procedures established in current regulations will be complied with, especially Ley 1266 de 2008 and related rules.
  • To carry out validations related to ethics, transparency, fraud prevention, conflicts of interest and other integrity checks appropriate for the establishment, execution and monitoring of the contractual relationship.
  • To administer and manage the risks of Money Laundering, Terrorist Financing, corruption and other applicable compliance risks, through knowledge, verification, due diligence and list-screening procedures defined by PROCAPS.
  • To manage physical and logical access to facilities, restricted areas, systems or information assets of PROCAPS necessary for the execution of the contract, including security controls, credentials, entry logs and traceability measures.
  • To attend to audits, reviews, controls and performance evaluations of the supplier or contractor, as well as improvement plans, when necessary to ensure the quality, continuity and compliance of the service.
  • To manage occupational health and safety (OHS) obligations applicable to the execution of the contract, when the supplier/contractor provides services at PROCAPS facilities or under conditions that require it.
Purposes with respect to PROCAPS Shareholders:
  • To comply with the obligations and rights arising from their status as a PROCAPS shareholder.
  • To send electronic, physical and/or telephone communications to their contact details to inform, summon or convene them to meetings of PROCAPS' corporate bodies, and/or to send them documents and reports that will be presented for consideration at such meetings.
  • To send communications and information necessary for the exercise of their rights as a shareholder, and/or for compliance with the obligations incumbent on PROCAPS toward its shareholders.
  • To carry out comprehensive administration activities for the shareholder registry book, including updates, certifications, annotations and corresponding controls.
  • To contact the Data Subject through email, instant messaging, text messages, formal communications, phone calls and other channels authorized and permitted by law, to send documents, informational communications, account statements or documentation related to their status as a PROCAPS shareholder.
  • To carry out filing and document management tasks, in accordance with applicable legal provisions.
  • To attend to procedures, requests, complaints and claims presented by shareholders and respond through the channels made available for that purpose.
  • To communicate PROCAPS product news and invite to events or programs organized by PROCAPS, when applicable and in accordance with applicable authorizations.
  • To grant access to the information to judicial or administrative authorities that request it in the exercise of their legal functions.
  • To administer and manage the risks of Money Laundering, Terrorist Financing, corruption and other applicable compliance risks, through knowledge, verification, due diligence, list-screening and validation procedures defined by PROCAPS.
  • To carry out validations related to ethics, transparency, fraud prevention, conflicts of interest and other integrity checks appropriate for the issuer–shareholder relationship and compliance with corporate obligations.
  • To comply with the activities and purposes necessary for the issuer–shareholders relationship, in accordance with applicable regulations and the bylaws and decisions of PROCAPS' corporate bodies.

Processing of Sensitive Personal Data Obtained Through Video Surveillance
PROCAPS uses video surveillance systems installed in different internal and external areas of its facilities or offices. For this reason, it informs the general public about the existence of these mechanisms through visible and sufficient notices, indicating the existence of the system, the contact channels, and how to access the Policy governing the processing of the information captured.

The information collected through these systems is used to: (i) protect the safety of persons, property, facilities and information assets; (ii) control, verify and support access control to sites, offices and establishments; (iii) prevent, detect and investigate security incidents and respond to requirements of competent authorities; and (iv) serve as evidentiary support in internal or external proceedings, when necessary and appropriate.

Images and/or video recordings will have restricted access and may only be consulted by authorized personnel or by third parties who, in their capacity as Processors, provide services associated with the system (for example, monitoring, maintenance or support), under confidentiality and security obligations.

First paragraph. PROCAPS may provide images or video recordings only: (i) to competent judicial or administrative authorities, when there is a valid requirement or order; (ii) to the data subject or legitimated persons, when appropriate within the framework of exercising rights, upon prior verification of identity and legitimation; and (iii) in other cases permitted by law. In any event, PROCAPS will adopt reasonable measures to protect the rights of third parties who may appear in the images.

Second paragraph. Authorization for the processing of images captured through video surveillance may be obtained through unambiguous conduct, when the data subject, duly informed through visible notices, voluntarily enters or remains in areas marked as video surveillance areas.

Third paragraph. Recordings will be retained only for the time strictly necessary to fulfill the purposes described, in accordance with internal retention criteria and applicable legal provisions, and will then be deleted or subjected to secure restriction/archiving measures when appropriate.
Fourth paragraph. PROCAPS will inform the data subject, at the time of collection or through the notices and channels made available, of the purposes of the processing and how to exercise their rights.

Processing of biometric data for security and access control to restricted areas
PROCAPS may implement access control mechanisms based on biometric validation in restricted access or enhanced security areas, when necessary, proportional and reasonable for the protection of persons, property, facilities, information assets and compliance with internal security controls.

These areas may include, among others, storage or handling areas for controlled raw materials, inventory warehouses, laboratories, quality areas, production areas, technical rooms, server rooms, areas with sensitive or regulated documentation, and other spaces that, due to their operational or regulatory criticality, require strict entry and presence controls.

For these purposes, PROCAPS may require the prior collection of biometric data from employees and/or contractors authorized to access such areas, for the sole purpose of authentication, identity verification and access control. Biometric data, due to its nature, will be treated as sensitive personal data, and its collection and use will be carried out under an enhanced protection standard.


In implementing these mechanisms, PROCAPS will:
  • Inform, in advance and in a clear and express manner, the specific purpose of the biometric processing, the type of biometric data to be collected, the system to be used, the scope of the control and the areas to which it applies.
  • Obtain explicit, prior and informed authorization from the data subject (employee or contractor), keeping verifiable and consultable evidence of such authorization, unless a legal exception applies.
  • Inform of the optional nature of providing biometric data, as it constitutes sensitive data, and evaluate and implement, when reasonable, less intrusive authentication alternatives for those who do not grant authorization, especially when this does not compromise the security of the area.
  • Limit the processing to what is strictly necessary for access control, avoiding secondary or incompatible uses (for example, commercial purposes, disciplinary purposes unrelated to security, or reuse for different purposes).
  • Implement enhanced technical, human and administrative security measures, including strict access control, encryption or equivalent measures, segregation of environments, audit logs, and restrictions on consultation and use.
  • Restrict access to biometric data solely to strictly authorized personnel and/or to third-party Processors providing services associated with the system, under contractual obligations of confidentiality, security, non-use for their own purposes, and incident management.
  • Define retention and deletion criteria: biometric data will be retained only for the time necessary for access control or while the data subject has valid authorization to enter the restricted area, and will be deleted or rendered unusable when the purpose ceases, the authorization is revoked (when appropriate), or the contractual/employment relationship ends, without prejudice to legal retention obligations.
  • Adopt procedures to address requests for consultation, updating, deletion or revocation of authorization, when appropriate under the law and without affecting compliance with security obligations and internal controls.
  • In the event of security incidents that may compromise biometric data, activate internal incident management protocols and adopt corrective and preventive measures.

The implementation of biometric mechanisms will not imply that PROCAPS processes such data for purposes other than authentication and access control to restricted areas. Any expansion of purposes will require prior notice and, where applicable, a new authorization.

17. COLLECTIONS, MARKETING AND COMMERCIAL COMMUNICATIONS

PROCAPS may process personal data for the management of commercial, advertising, promotional, marketing and/or collections communications, when there is a sufficient legal basis and, where applicable, the data subject's prior, express and informed authorization, in accordance with personal data protection regulations and Ley 2300 de 2023, to the extent applicable.
1. Contact channels and data subject preferences. PROCAPS will conduct commercial or collections communications through suitable channels, authorized and permitted by law, respecting the preferences, revocations, objections, exclusions and no-contact requests registered by the data subject. PROCAPS will implement mechanisms so that the data subject may request, at any time, the cessation of commercial or promotional communications through the channels made available in the Policy and the Privacy Notice.
2. Exclusion registry and control measures. For commercial and advertising communications, PROCAPS will verify, when applicable, the Registro de Números Excluidos (RNE) and/or equivalent exclusion mechanisms defined by the competent authority, and will adopt internal controls (exclusion lists, segmentation, consent registry and "do not contact") to avoid improper communications.
3. Direct or third-party collections. When PROCAPS carries out collections activities directly or through third parties, it will establish controls so that the activity is carried out proportionally, respectfully and in accordance with the law, and will require suppliers or third-party Processors to assume contractual obligations of confidentiality, security, restricted use and traceability. The foregoing includes the third party's obligation to respect Procaps' instructions, authorized channels and applicable restrictions on processing.
4. Contact with references or third parties. When the operation involves contact with references or third parties, PROCAPS will limit the processing to the minimum necessary, will refrain from disclosing irrelevant information, and will apply criteria of necessity, purpose and restricted access, in accordance with the personal data protection regime and applicable contactability rules.
5. Evidence and demonstrated accountability. PROCAPS will retain verifiable evidence of (i) the authorizations granted when required, (ii) the exclusion or opposition mechanisms, (iii) the traceability of relevant campaigns or communications, and (iv) the measures adopted to address requests for cancellation or no-contact.

18. SENSITIVE DATA

PROCAPS will restrict the processing of sensitive personal data and, in general, will refrain from collecting or processing it except where strictly necessary, proportional and legally permitted. In any event, when PROCAPS collects sensitive data, it will inform the data subject: (i) of the optional nature of answering questions or providing sensitive data, and (ii) of the specific purpose of the processing:
In the case of sensitive personal data, PROCAPS may use and process it when:

  • The Data Subject has given their explicit authorization for such Processing, except in cases where the law does not require such authorization.
  • The Processing is necessary to safeguard the vital interest of the Data Subject and the Data Subject is physically or legally incapacitated. In such cases, legal representatives must grant their authorization.
  • The Processing relates to data necessary for the recognition, exercise or defense of a right in a judicial proceeding.
  • The Processing has a historical, statistical or scientific purpose. In this case, measures must be adopted to suppress the identity of Data Subjects.

First paragraph. Without prejudice to the provisions of this chapter, PROCAPS will apply enhanced rules for the processing of sensitive personal data. In particular, PROCAPS will:

  • Inform the data subject, in advance and clearly, of the optional nature of providing sensitive data and the specific purpose of the processing, unless a legal exception applies.
  • Limit the collection and processing of sensitive data to what is strictly necessary and proportional to the purpose communicated, avoiding excessive collection or incompatible uses.
  • Restrict access to sensitive data to strictly authorized personnel under the principle of need-based access, applying enhanced security and confidentiality measures (including access controls, traceability, segregation and reasonable technical measures such as encryption or equivalent).
  • Retain sensitive data only for the time necessary to fulfill the purpose communicated or for the terms required by law, and thereafter proceed with its deletion, anonymization or restriction, as appropriate.

PROCAPS, as a general rule, will not subject sensitive personal data to automated decision-making or profiling processes that produce legal effects or significant impacts on the data subject.

Likewise, PROCAPS will restrict the use of artificial intelligence or advanced analytics systems for the processing of sensitive data whenever possible, favoring less intrusive alternatives. When, exceptionally, it is necessary to use automated or AI technologies to process sensitive data, PROCAPS will:

  • Verify the existence of a sufficient legal basis and, where applicable, obtain explicit authorization;
  • Carry out a prior risk assessment and, when a high risk is likely, a personal data protection impact assessment;
  • Implement significant human oversight, controls to prevent bias or discrimination, and precautionary measures when there is uncertainty about relevant harms;
  • Document the justification, purpose, mitigation measures and traceability of the processing.

Sole Paragraph. Access to sensitive data will be restricted to strictly authorized personnel, and enhanced security, confidentiality and minimization measures will be applied. Sensitive data will be retained only for the time necessary to fulfill the purpose communicated or for the terms required by law. Biometric data is considered sensitive data and will be processed under the enhanced standards set forth in the preceding chapter.

19. PROCESSING OF PERSONAL DATA IN ARTIFICIAL INTELLIGENCE SYSTEMS AND AUTOMATED DECISIONS

When PROCAPS uses, develops, contracts or implements artificial intelligence (AI) systems, advanced analytics, profiling or automation involving the processing of personal data — including training, testing, validation, deployment, monitoring and continuous improvement — it will apply the principles of the Colombian personal data protection regime and the guidelines issued by the Superintendencia de Industria y Comercio.
1. Weighing, necessity and proportionality. PROCAPS will assess in advance whether the processing of personal data through AI is suitable, necessary, reasonable and proportional to the intended purpose, favoring less intrusive alternatives when possible.
2. Precautionary approach and risk management. PROCAPS will adopt a preventive and risk-management approach, such that, if there is reasonable uncertainty about relevant harms to data subjects, it will implement mitigation measures, restrictions or refrain from processing when appropriate.
3. Impact assessment (PIA/DPIA). When a high risk to the rights of data subjects is likely (for example, use of sensitive or biometric data, mass processing, automated decisions with relevant effects, use of new models or sources), PROCAPS will carry out a personal data protection impact assessment that, at a minimum, describes the processing, identifies risks, establishes mitigation measures, defines security controls and leaves a record of decisions.
4. Open-source data and "publicly accessible" information. PROCAPS will not process personal data obtained from the internet, social media or open sources merely because it is publicly accessible, without first verifying a sufficient legal basis and the applicable information and transparency conditions.
5. Sensitive data and minors. PROCAPS will restrict the use of AI for the processing of sensitive data and data of children and adolescents, favoring non-automated alternatives when possible. As a general rule, Procaps will not subject sensitive data to automated decision-making processes with legal effects or significant impacts on the data subject, except with legal authorization and enhanced controls.
6. Quality, bias and operational explainability. PROCAPS will adopt measures to ensure the quality, relevance and updating of data used by AI systems, and will apply controls to prevent undue bias, discrimination and relevant errors. When the processing involves automated decisions with significant impact, Procaps will implement significant human oversight and review mechanisms.
7. Suppliers, platforms and sub-processor chain. When PROCAPS uses third-party tools (including AI as a service), it will require contractual and technical guarantees: restricted use, confidentiality, security, sub-processors, incidents, audit, international transfer/transmission, and deletion/return of data as applicable.
8. Evidence and demonstrated accountability. PROCAPS will document: the legal basis, purposes, risk assessment, impact assessment when applicable, mitigation decisions, controls implemented, relevant tests and audits, in order to demonstrate compliance before data subjects and authorities.

20. DATA OF CHILDREN AND ADOLESCENTS

The processing of personal data of children and adolescents is prohibited, except when it involves data of a public nature, and when such processing complies with the following parameters and/or requirements:

  • That it responds to and respects the best interests of children and adolescents.
  • That the prior, express and informed authorization of the child's or adolescent's legal representative be obtained, unless a legal exception applies.
  • That the right of the child or adolescent to be heard be guaranteed, and that their opinion be valued taking into account their maturity, autonomy and ability to understand the matter.
  • That respect for their fundamental rights be ensured.
  • That the processing be limited to data strictly necessary for the purpose communicated, and that enhanced security, confidentiality and restricted-access measures be adopted.

Sole Paragraph. The processing of personal data of children and adolescents will be exceptional and will be carried out with enhanced security, confidentiality and restricted-access measures. PROCAPS will not use such data for advertising or commercial prospecting purposes, nor will it subject it to profiling or automated decisions with significant impacts, except with express legal authorization. PROCAPS may implement reasonable mechanisms to verify the identity and status as legal representative of whoever grants the authorization, and will retain such data only for the time strictly necessary for the purpose communicated, unless a legal obligation requires otherwise.

21. TECHNOLOGY TRANSFER AND ADOPTION OF PLATFORMS THAT PROCESS PERSONAL DATA

PROCAPS recognizes that the acquisition, licensing, implementation, integration, updating or use of technologies involving the processing of personal data (including platforms, software, cloud services, analytical tools, AI systems, cybersecurity solutions, HR, CRM, ERP, quality and laboratory management solutions) may generate risks to the rights of data subjects. For this reason, it will adopt the applicable instructions issued by the Superintendencia de Industria y Comercio for technology transfer processes with an impact on personal data.

1. Prior due diligence. Before implementing or contracting a technology that processes personal data, PROCAPS will carry out a prior assessment that includes, as applicable:

  • a) description of the processing, categories of data, purposes and roles (Controller/Processor);
  • b) identification of flows, remote access, sub-processors and possible international transfers/transmissions;
  • c) review of security measures (access control, segregation, audit logs, encryption or equivalent measures, retention and deletion);
  • d) risk assessment and definition of mitigation measures; and
  • e) when a high risk is likely, a personal data protection impact assessment.

2. Privacy by design and by default. PROCAPS will incorporate privacy-by-design and by-default controls into technology planning and adoption, such that, by default, only the information necessary for each purpose is processed, and exposure surfaces are reduced.
3. Contracts and minimum guarantees. PROCAPS will require that contracts with suppliers or affiliated companies participating in the processing include, at a minimum: scope, instructions, purposes, confidentiality, security, incident management, sub-processors, audit, return/deletion, cooperation with data subjects and authorities, and international transmission/transfer rules when applicable.
4. Countries with a lower level of protection and equivalent standards. When a technology involves access or processing from jurisdictions with a lower level of protection, PROCAPS will establish agreements that ensure minimum standards equivalent to those required by Colombian regulations, including contractual, technical and organizational safeguards. Procaps may use standard contractual clauses as a complementary tool when applicable.
5. Implementation, monitoring and continuous improvement. PROCAPS will not put critical technologies into operation without having implemented the safeguards defined in the prior assessment. It will subsequently carry out periodic monitoring and reviews (technical and compliance-related) to verify the continuity of controls, changes in suppliers, new sub-processors, software updates, changes in international flows, and emerging risks.
6. Evidence. PROCAPS will retain evidence of the prior assessment, internal approvals, mitigation decisions, contracts, audits and reviews, as part of its demonstrated accountability.

22. PERSONS TO WHOM THE INFORMATION MAY BE PROVIDED

Information meeting the conditions established by law may be provided to the following persons:
  • To data subjects, their duly proven successors, or their legal representatives or attorneys-in-fact.
  • To public or administrative entities in the exercise of their legal functions or by court order.
  • To third parties authorized by the data subject or by law.

Sole Paragraph. Before providing information, PROCAPS may request and verify the identity of the requester and the capacity in which they act, in order to guarantee restricted access and prevent unauthorized disclosures. Likewise, when PROCAPS communicates personal data to third parties acting as Data Processors, such communication will be carried out under the applicable legal and contractual conditions, with obligations of confidentiality, security and restricted use of the information.

23. INTERNATIONAL DATA TRANSFER

PROCAPS will not carry out transfers of personal data to countries that do not provide adequate levels of protection, in accordance with artículo 26 de la ley 1581 de 2012 and the standards set by the Superintendencia de Industria y Comercio.

A country is understood to offer an adequate level of protection when it complies with the standards set by the Superintendencia de Industria y Comercio. When the destination country is not recognized as having an adequate level, PROCAPS will verify whether the transfer is covered by any legal exception or whether it is necessary to request a declaration of conformity from the Superintendencia de Industria y Comercio.

Exceptionally, PROCAPS may carry out international transfers of personal data when any of the grounds set forth in artículo 26 de la ley 1581 de 2012 are met, including:
  • The data subject has granted prior, express and unambiguous authorization to carry out the transfer.
  • Exchange of medical data when required by treatment for health or public hygiene reasons.
  • The transfer is necessary for the performance of a contract between the data subject and PROCAPS as Controller and/or Processor.
  • Bank and stock market transfers in accordance with the legislation applicable to such transactions.
  • Data transfers agreed within the framework of international treaties to which Colombia is a party, based on the principle of reciprocity.
  • Transfers legally required to safeguard a public interest or for the recognition, exercise or defense of a right in a judicial proceeding.

First Paragraph. When an international transfer occurs, PROCAPS will execute agreements regulating in detail the obligations, burdens and duties of the parties, including technical, human and administrative measures ensuring a level of protection equivalent to that required by Colombian regulations, especially when the destination country has a lower level of protection.

Second Paragraph. When the destination country is not on the list of countries with an adequate level and the operation falls within the exceptions of artículo 26, PROCAPS may incorporate standard contractual clauses (Circular Externa 003 de 2025) as a tool to reinforce the protection of data subjects and standardize obligations between the parties.

Third Paragraph. Prior to carrying out an international transfer, PROCAPS must: (i) classify the flow as a transfer or transmission depending on the role of the recipient; (ii) document the legal basis (exception, adequacy or declaration of conformity); (iii) verify technical safeguards (security, access, encryption/equivalent measures, access logs, segregation) and contractual safeguards; and (iv) retain evidence of the analysis and of the agreements executed, for purposes of demonstrated accountability.

The technical feasibility opinion must be issued by the Technology and Information Security area, and the legal feasibility opinion by the area responsible for data protection and/or legal affairs, in accordance with PROCAPS' internal procedures.

 

24. INTERNATIONAL TRANSMISSION OF PERSONAL DATA

The international transmission of personal data (that is, the communication of data from PROCAPS as Controller to a third party abroad acting as Processor to carry out processing on behalf of PROCAPS) will not require notice to the data subject or their additional consent, provided there is a contract under the terms of artículo 25 del Decreto 1377 de 2013.

First paragraph. When affiliated companies of the corporate group (parent company, affiliates or subsidiaries) access, from abroad, the technological infrastructure hosted at PROCAPS to carry out support, technological operation or other processing activities on behalf of PROCAPS, such cross-border access will be managed as an international transmission and will be subject to the legal, technical and contractual safeguards set forth herein.


In any event, Procaps will require the execution of a contract (or intercompany agreement) regulating, at a minimum:
  • a. Scope of the processing and categories of data.
  • b. Specific activities to be carried out by the Processor on behalf of PROCAPS.
  • c. Obligations of the Processor to PROCAPS and to data subjects, in accordance with the Colombian regime.
  • d. Use limited to instructed purposes and prohibition on unauthorized or own use.
  • e. Confidentiality rules, restricted access, and security measures proportional to the criticality of the information.
  • f. Incident management: immediate notification to PROCAPS and cooperation in containment, investigation and remediation.
  • g. Sub-processors: prior authorization (general or specific), equivalent obligations and traceability.
  • h. Location/processing environments, remote access, access logs and auditing.
  • i. Return or deletion of data upon completion of the service, except for applicable legal retention requirements.
  • j. Cooperation in addressing inquiries, complaints and requirements from authorities.

First Paragraph. PROCAPS may incorporate standard contractual clauses (Circular Externa 003 de 2025) as a complementary instrument to standardize obligations and reinforce safeguards in international transmissions, especially when the Processor is located in countries without an adequate level of protection.

Second Paragraph. PROCAPS will maintain central control and administration of its technological infrastructure and will apply security controls for cross-border access (identity management, role-based profiles, strong authentication when applicable, access logs, monitoring, environment segregation, and cryptographic or equivalent measures), such that access from abroad does not imply a lowering of the protection standards required by Colombian regulations.

25. RETENTION, BLOCKING AND DELETION OF PERSONAL DATA

PROCAPS will retain personal data only for the time necessary to fulfill the purposes for which it was collected and/or authorized, or for as long as there is a legal, contractual, administrative or judicial obligation requiring its retention.

Retention periods may be communicated to the data subject at the time of collection and/or defined internally by PROCAPS based on: (i) the purpose of the processing, (ii) the nature of the data, (iii) the type of relationship with the data subject (employment, contractual, commercial, corporate, etc.), and (iv) the terms provided under special regulations (labor, accounting, tax, regulatory, security and risk-management regulations).

PROCAPS may establish and maintain internal retention and final disposition tables, criteria or matrices for information. Once the applicable periods have expired, and provided there is no retention obligation, Procaps will proceed to:

  • a. Securely delete the data, preventing its recovery; or
  • b. Anonymize the information when possible and appropriate; or
  • c. Restrict/Block the processing, when it must be retained solely for filing, evidentiary support, complaint-handling, legal compliance or defense-of-rights purposes.

Deletion or restriction will be carried out applying reasonable technical and organizational measures to prevent unauthorized access, improper disclosures or re-identification, as applicable.

26. PROCEDURES FOR HANDLING INQUIRIES, COMPLAINTS AND PETITIONS

Data subjects, their successors, legal representatives or attorneys-in-fact may exercise their rights through the contact channels made available by PROCAPS. Before addressing a request, PROCAPS may verify the identity of the requester and the capacity in which they act, in order to prevent unauthorized access or disclosures.
Contact channels:

City Address Email
Barranquilla (Colombia) Calle 80 NO. 78 B - 201 habeasdata@procaps.com.co
 

INQUIRIES. Data subjects or their successors may consult the data subject's personal information held in any PROCAPS database. The data subject may send their questions or inquiries related to their personal data collected and processed by PROCAPS through the contact channels indicated.

PROCAPS will resolve the inquiry within ten (10) business days following the date it was received. When it is not possible to address the inquiry within that term, the interested party will be informed before the 10-day period expires, stating the reasons for the delay and indicating the date on which the inquiry will be addressed, which in no case may exceed the five (5) business days following the expiration of the first term.

COMPLAINTS. A data subject (or their successors) who considers that information contained in a PROCAPS database should be corrected, updated or deleted, or who notices the alleged breach of any legal duty, may file a complaint through the contact channels indicated.

The complaint must contain, at a minimum: (i) identification of the data subject, (ii) description of the facts giving rise to the complaint, (iii) address and contact details for receiving a response, and (iv) documents to be relied upon.

If the complaint is incomplete, PROCAPS will request the interested party, within five (5) business days of its receipt, to correct the deficiencies. If two (2) months elapse from the date of the request without the requester providing the required information, the complaint will be deemed withdrawn.
Once a complete complaint is received, PROCAPS will include in the database a note stating "COMPLAINT IN PROGRESS" and the reason therefor, within a term not exceeding two (2) business days. Such note must be maintained until the complaint is resolved.

The maximum term for resolving the complaint will be fifteen (15) business days from the day following the date of its receipt. When it is not possible to address it within that term, the interested party will be informed before the expiration of said term of the reasons for the delay and the date on which the complaint will be addressed, which in no case may exceed the eight (8) business days following the expiration of the first term.

REVOCATION OF AUTHORIZATION. The data subject may request the revocation of the authorization granted for the processing of their personal data when appropriate. PROCAPS will assess the request and, if feasible, will cease processing for the affected purposes. Revocation will not have retroactive effects on processing validly carried out prior thereto and will not proceed when there is a legal or contractual duty requiring the retention or continued processing of certain information.


DELETION. The right to deletion of data is not absolute; PROCAPS may deny it when:
  • The data subject has a legal or contractual duty to remain in the database.
  • Deletion of the data would hinder judicial or administrative proceedings related to tax obligations, the investigation and prosecution of crimes, or the enforcement of administrative sanctions.
  • The data is necessary to protect the data subject's legally protected interests; to carry out an action in the public interest; or to comply with an obligation legally acquired by the data subject.

If the cancellation of personal data is appropriate, PROCAPS must operationally carry out the deletion in such a way that the information cannot be recovered.

27. AREA RESPONSIBLE FOR PERSONAL DATA PROTECTION

PROCAPS has designated a person and/or area responsible for the personal data protection function, in charge of handling data subjects' requests for the exercise of the rights set forth in the law and coordinating the implementation of the personal data protection program within the organization.


Personal Data Protection Officer

This shall be the person and/or unit in charge of leading the personal data protection program at Procaps, handling data subjects' requests, and coordinating the cross-functional implementation of the system. In developing the foregoing, it will have, among others, the following functions:

  • a. To receive, process and attend to requests, petitions, inquiries or complaints presented by data subjects, their successors, representatives or attorneys-in-fact, including reasonable verification of identity and legitimation when necessary.
  • b. To administer and maintain PROCAPS' internal personal data protection system and coordinate its implementation with the areas involved.
  • c. To maintain a database inventory and coordinate compliance with obligations associated with the RNBD, including registrations, updates and periodic reports in accordance with the requirements of the competent authority.
  • d. To coordinate the management of international transfers and transmissions from a data protection perspective, including the review of contractual safeguards and, where applicable, the management of declarations of conformity or other applicable instruments.
  • e. To plan and coordinate training and organizational culture strategies on personal data protection, with a focus by profile and level of access.
  • f. To coordinate internal audits or periodic reviews to verify compliance with the Policy and associated procedures.
  • g. To assist in addressing visits, requirements, investigations and communications from competent authorities on personal data protection matters.
  • h. To manage and monitor the personal data processing risk management program, promoting controls and continuous improvement.
  • i. To coordinate the management of security incidents affecting personal data and their reporting to the Superintendencia de Industria y Comercio within applicable terms, including reporting through the RNBD when appropriate.
  • j. To present periodic reports to Senior Management on the status of the program, relevant risks, incidents, audits and improvement plans.
  • k. To propose adjustments, updates or new internal guidelines on personal data protection and submit them for approval when appropriate.

The Personal Data Protection Officer will act in coordination with the Technology/Information Security, Legal/Compliance and Human Talent areas and process leaders, to ensure the effective implementation of technical, administrative and contractual controls, as well as the management of incidents, access and risks associated with processing.

28. INFORMATION SECURITY

PROCAPS implements and maintains reasonable technical, human, administrative, physical and organizational measures, proportional to the risk, aimed at protecting personal data against unauthorized access, loss, misuse, alteration, destruction or unauthorized disclosure. These measures form part of PROCAPS' information security system and are applied in harmony with this Policy.

PROCAPS may allow access to personal data by third parties acting as Data Processors (including technology suppliers and/or affiliated companies providing services to PROCAPS), provided there are agreements or contracts imposing obligations of confidentiality, security, restricted use, incident management, subcontracting and other conditions required by applicable regulations and by this Policy.

PROCAPS does not guarantee the absolute absence of security incidents; however, it is committed to maintaining reasonable controls proportional to risk, as well as procedures for prevention, detection, response and continuous improvement.

First paragraph. In the event of a security incident that may compromise personal data, PROCAPS will activate its internal response protocols, including containment, analysis, remediation, documentation and adoption of corrective measures. When appropriate, PROCAPS will report the incident to the Superintendencia de Industria y Comercio under applicable terms, including reporting through the RNBD when appropriate.
Second paragraph. Before implementing, acquiring, contracting, licensing, integrating or using platforms, applications, technological tools, cloud services, software, advanced analytics or artificial intelligence systems that involve the processing of personal data, PROCAPS will carry out a prior assessment aimed at verifying privacy and security risks and safeguards.

Such assessment may include, as applicable: (i) definition of the scope of the processing, categories of data and purposes; (ii) identification of roles (Controller/Processor), flows and international transfers or transmissions; (iii) review of access controls, encryption or equivalent measures, audit logs, segregation, retention and deletion; (iv) verification of sub-processors and the technological supply chain; (v) risk analysis and mitigation measures, including, when a high risk is likely, the performance of a personal data protection impact assessment; and (vi) review of contractual clauses on confidentiality, security, incidents, cooperation and restricted use.

PROCAPS will document the conclusions of this assessment and adopt corrective or preventive measures before putting the technology into operation, especially in the case of tools based on artificial intelligence or processing involving sensitive data, biometric data or automated decisions.

29. HANDLING OF REQUIREMENTS FROM ADMINISTRATIVE AND JUDICIAL ENTITIES

The Personal Data Protection Officer, together with the legal representative and/or the responsible areas determined internally, will attend to visits, information requirements or requests related to personal data made by competent judicial or administrative authorities.

PROCAPS may disclose personal data when there is a valid requirement or order issued by a competent authority, in accordance with applicable regulations. In such cases, PROCAPS will verify the scope of the requirement and provide only the information strictly necessary, keeping an internal record of the request and the response provided.

30. TERM AND MODIFICATIONS

This Policy was approved by PROCAPS' Senior Management and modifies all provisions previously issued within the organization.

The databases in which personal data will be registered will have a term equal to the time during which the information is maintained and used for the purposes described in this Policy. Once those purposes have been fulfilled, and provided there is no legal or contractual duty to retain the information, the data will be deleted from our databases.

31. APPROVAL AND DISCLOSURE

This document was reviewed, analyzed and approved for implementation by PROCAPS' Board of Directors. PROCAPS will carry out the corresponding disclosure to stakeholders and will keep a record thereof.