Personal Data Processing Policy
Last updated: · Effective since:
1. Data controller
The processing of data collected through www.d57.ai is carried out by the following companies of the Digital57 group, depending on the country from which the relationship is established:
Colombia
DIGITAL57 S.A.S.
NIT 900.698.380-4
Carrera 3 #74A-41, oficina 402
Bogotá D.C., CP 110221, Colombia
Mexico
Digital57 S. de R.L. de C.V.
Av. Presidente Masaryk 111, Piso 1
Ciudad de México, CP 11560, México
D57 AI Solutions is a business unit of the Digital57 group and does not constitute an independent legal entity. For data subjects residing in Spain and the European Union, the data controller is DIGITAL57 S.A.S., which handles requests through the channel indicated below.
Single channel for personal data matters, in all three countries: the site's contact form. Requests received through this channel are logged with a date and answered within the deadlines set out in section 11.
Data protection delegate officer, acting as data protection officer for GDPR purposes: Juan Hoyos, reachable via the same email, with the subject line “Privacy.”
2. Scope and roles
This policy governs the processing of personal data that DIGITAL57 S.A.S. carries out as data controller: the data it collects through www.d57.ai, the diagnostic form, and the resulting commercial and contractual communications.
In consulting and development projects, D57 acts as data processor with respect to the personal data entrusted to it by the client. That processing is governed by the contract and the data processing agreement signed with each client, not by this policy.
This policy does not cover the processing that D57's clients carry out in their own systems, nor that of linked third-party sites.
3. Applicable legal framework
D57 applies, in each case, the law of the data subject's country of residence. When more than one applies, the most protective standard governs.
- Colombia
- Law 1581 of 2012 (Colombia), Decree 1074 of 2015 (which consolidated Decree 1377 of 2013), Law 1266 of 2008 where applicable, and the circulars of the Superintendency of Industry and Commerce.
- Mexico
- Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP, Mexico) and its regulations, including privacy notice duties and the exercise of ARCO rights before the competent authority in force.
- European Union and Spain
- Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD) and, for cookies and electronic communications, Article 22.2 of Law 34/2002 (LSSI-CE).
4. Data collected and its source
All data comes from the data subject, except for technical browsing data, which is generated automatically when using the site. D57 does not purchase databases or enrich profiles with third-party sources.
| Category | Data | Source |
|---|---|---|
| Professional identification | First and last name, job title. | Form |
| Professional contact | Corporate email, company, country. | Form |
| Content of the request | Selected business challenge and free-text message. | Form |
| Technical data | IP address, user agent, device, pages viewed, traffic source, date and time. | Automatic |
| Campaign attribution | UTM parameters, landing page, and referrer. | Automatic, subject to prior consent |
No sensitive data is collected nor special categories under Article 9 of the GDPR: no health data, ethnic origin, beliefs, union affiliation, or biometric data. No identity document, date of birth, precise geolocation, or social media identifiers are requested. The site is not directed at minors and does not knowingly collect data from minors.
5. Purposes and legal basis
Each purpose has a stated legal basis. In Colombia and Mexico, the ordinary basis is the data subject's prior, express, and informed authorization, collected through the form checkbox and the cookie manager.
| Purpose | Legal basis (GDPR) | Basis in CO / MX |
|---|---|---|
| Handling the diagnostic request and coordinating the session. | Art. 6(1)(b) — pre-contractual measures | Authorization |
| Managing the commercial and contractual relationship. | Art. 6(1)(b) — performance of a contract | Authorization / contractual relationship |
| Sending communications about services, publications, and events. | Art. 6(1)(a) — consent | Authorization, revocable |
| Measuring site performance in aggregate. | Art. 6(1)(a) — consent (cookies) | Authorization |
| Attributing campaigns and measuring conversions. | Art. 6(1)(a) — consent (cookies) | Authorization |
| Preventing fraud and maintaining site security. | Art. 6(1)(f) — legitimate interest | Legal security duty |
| Complying with legal, accounting, and tax obligations. | Art. 6(1)(c) — legal obligation | Legal obligation |
Consent may be withdrawn at any time, without retroactive effect, by writing to the channel in section 1 or through the cookie preferences link in the footer. Every commercial email includes an unsubscribe link.
Databases are not sold, transferred, or rented to third parties for advertising purposes.
6. Automated decisions and profiling
D57 does not make decisions based solely on automated processing that produce legal effects on the data subject or similarly significantly affect them, within the meaning of Article 22 of the GDPR. Internal request prioritization may rely on automated tools, but any decision with commercial effect is made by a person.
No individual behavioral profiles are built for advertising purposes. Analytics are consumed in aggregate form.
7. Artificial intelligence and confidentiality
Explicit commitment
The data provided in the form and the information shared during a diagnostic session are not used to train artificial intelligence models, whether proprietary or third-party.
When AI tools are used to process information within a project, this is done under a confidentiality agreement and with contractual configurations that exclude the use of that data to train or improve the provider's model.
Data entrusted to D57 by the client remains subject to the residency and retention rules agreed with the client before development begins.
8. Data processors and international transfers
D57 relies on technology providers that act as data processors, under contract terms that prevent them from using the data for their own purposes. Categories, not commercial names, are listed to avoid becoming outdated; the current named list is provided upon the data subject's request.
- Web hosting and content delivery network.
- CRM and marketing automation.
- Corporate and transactional email.
- Web analytics and campaign attribution.
- Language model providers, under the conditions of section 7.
Some of these providers are located outside the data subject's country of residence, including the United States and the European Union. Transfers are based, as applicable, on: a European Commission adequacy decision; standard contractual clauses under the GDPR, accompanied by a transfer impact assessment; or, in Colombia, the compliance declaration and transmission contracts required by Law 1581 of 2012 (Colombia). In Mexico, Digital57 S. de R.L. de C.V. discloses the transfers in this document and in its privacy notice, as required by law.
9. Retention
| Data | Retention period |
|---|---|
| Diagnostic request with no subsequent commercial relationship | Up to 2 years from the last contact, unless withdrawn earlier. |
| Client data under a contractual relationship | The term of the contract and, after termination, the legal statute-of-limitations period and the accounting and tax retention period. |
| Subscription to communications | Until the data subject unsubscribes. |
| Cookie consent records | 12 months, to be able to demonstrate the decision. |
| Technical and security logs | Up to 12 months. |
Once the period expires, the data is irreversibly deleted or anonymized.
10. Data subject rights
The applicable rights depend on the data subject's regime:
- Colombia
- Know, update, and correct the data; request proof of the authorization; be informed of the use given to the data; file complaints with the SIC; withdraw the authorization and request deletion when there is no legal or contractual duty to retain it.
- Mexico — ARCO rights
- Access, rectification, cancellation, and objection, in addition to limiting the use or disclosure of the data and withdrawing consent.
- European Union and Spain
- Access, rectification, erasure, restriction of processing, portability, objection, not being subject to decisions based solely on automated processing, and withdrawing consent at any time.
How to exercise these rights: submit a request through the channel in section 1, stating full name, a specific description of the request, contact details, and, when necessary to verify identity, a reasonable means of proof. Exercising these rights is free of charge.
11. Response deadlines
| Regime | Procedure | Deadline |
|---|---|---|
| Colombia | Inquiries | 10 business days, extendable by 5 more. |
| Colombia | Complaints | 15 business days, extendable by 8 more. |
| Mexico | ARCO rights | 20 business days to respond and 15 additional business days to give effect to the determination. |
| European Union | Any right | 1 month, extendable by 2 more months for complex requests, with notice of the extension. |
In Colombia, if the complaint is incomplete, the data subject is notified within the following 5 days; if 2 months pass without a response from the data subject, it is deemed withdrawn.
12. Supervisory authorities
- Colombia
- Superintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data.
- Mexico
- Competent authority on the protection of personal data held by private parties, under applicable regulations.
- Spain
- Spanish Data Protection Agency (AEPD). In other Member States, the supervisory authority of the data subject's place of residence.
The data subject may file a complaint with the authority if they consider their rights have been violated. In Colombia, the procedure before the data controller must be exhausted first; in the European Union, the complaint may be filed directly.
13. Security and incident notification
D57 applies reasonable technical, human, and administrative measures to protect the data against loss, misuse, unauthorized access, alteration, and destruction: encryption in transit, role-based access control, strengthened authentication on management systems, activity logging, and periodic review of providers.
In the event of a personal data breach, D57 notifies the competent supervisory authority within 72 hours of becoming aware of it when the GDPR so requires, reports it to the Superintendency of Industry and Commerce under Colombian regulations, and informs affected data subjects when the incident poses a high risk to their rights.
14. Cookies and similar technologies
The site does not install non-essential cookies before obtaining the user's consent. On the first visit, a consent manager is shown that allows accepting all categories, rejecting them, or choosing them individually, with the same level of ease.
| Category | What it is for | Basis |
|---|---|---|
| Necessary | Security, load balancing, and remembering the cookie decision. Without them, the site does not work. | Exempt from consent |
| Analytics | Aggregate measurement of pages viewed and traffic source. | Consent |
| Marketing | Campaign attribution and conversion measurement. | Consent |
The decision is kept for 12 months and can be changed at any time from the link Cookie preferences in the footer. Withdrawing consent is as easy as giving it.
Declining does not restrict access
Access to the content of www.d57.ai is not conditioned on accepting non-essential cookies. Anyone who declines analytics and marketing can browse the entire site with technical cookies only, and keeps the same reading experience and the same contact channel.
Accept and decline are offered with the same visual hierarchy and the same number of clicks, and consent can be withdrawn at any time without consequence for access, in accordance with Article 7(3) of the GDPR.
15. Third-party links
The site may link to other sites and to corporate social media profiles. D57 is not responsible for third-party privacy policies or cookies.
16. Term and changes
This policy is effective as of its effective date and remains in force for as long as D57 processes personal data under it. Material changes are communicated through a prominent notice on the site or by email, with at least ten business days' notice when the nature of the change requires it.
DIGITAL57 S.A.S.'s databases are registered in the National Database Registry of the Superintendency of Industry and Commerce when required by law.
Document under legal review. See terms and conditions.