ADDICTION REHABILITATION CENTER IN BOGOTÁ
CALL US: PBX (601) 525 54 39
The Best Mental, Emotional & Spiritual Health in the Americas

Personal Data Processing Policy

Presentation

This Personal Data Processing Policy constitutes the institutional framework through which the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL establishes the principles, procedures, responsibilities, and mechanisms applicable to the processing of personal data, in compliance with the Political Constitution of Colombia, Law 1581 of 2012, Single Regulatory Decree 1074 of 2015, and all other applicable regulations. It applies to the processing of personal data belonging to users, employees, volunteers, contractors, suppliers, donors, and other data subjects, including sensitive personal data related to their physical, mental, emotional, and spiritual health.

Confidentiality Notice

Compliance with this document is mandatory for directors, employees, contractors, volunteers, and all other individuals involved in the processing of personal data under the responsibility of the Foundation.

Its content may be updated whenever legal, regulatory, technological, or institutional changes require its revision, while at all times ensuring respect for the rights of data subjects and the principle of demonstrated accountability established under Colombia’s personal data protection framework.

General Information

  • Legal Name: FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL

  • Tax ID (NIT): 900.217.716-2

  • Document: Personal Data Processing Policy

  • Code: PTDP-001

  • Version: 2.0

  • Issue Date: July 9, 2026

  • Responsible Party: Legal Representative – Carla Andrea Jaramillo Ortiz

  • Validity: Until updated

1. Version Control

1.1. Purpose

The purpose of this chapter is to establish document control for the Personal Data Processing Policy of the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL, ensuring traceability of its amendments, identification of issued versions, corresponding approvals, and the validity of each update.

Any amendment to this policy must result from regulatory, organizational, technological, or operational changes, or from the implementation of best practices in personal data protection, and must be duly documented through this version control record.

1.2. Version History

  • Version 1.0 (05/05/2015): Initial issuance of the Personal Data Processing Policy. Prepared by: Fundación Función Futuro. Reviewed by: Management. Approved by: Legal Representative.

  • Version 2.0 (07/09/2026): Comprehensive update of the policy in accordance with Law 1581 of 2012, Single Regulatory Decree 1074 of 2015, guidelines issued by the Superintendence of Industry and Commerce, and alignment with the Foundation’s current processes involving the processing of sensitive personal data arising from the provision of mental, emotional, and spiritual health services, psychological and psychiatric care, and rehabilitation programs. New procedures were incorporated for inquiries and complaints, processing of children’s and adolescents’ data, information security measures, national and international data transfers, document retention, and strengthening of the personal data protection compliance model. Prepared by: Audit & Co. Latam ACL Auditores S.A.S. Reviewed by: Executive Management. Approved by: Legal Representative.

1.3. Approval Control

This policy must be reviewed and approved by the Foundation’s Legal Representative before it enters into force. Any subsequent amendment must follow the same institutional review, approval, and disclosure procedure.

  • Prepared by: Audit & Co. Latam ACL Auditores S.A.S. — 07/09/2026

  • Reviewed by: Executive Management

  • Approved by: Carla Andrea Jaramillo Ortiz — Legal Representative

1.4. Distribution Control

The current version of this Policy will be published through the official channels established by the Foundation and will be available for consultation by data subjects, employees, contractors, volunteers, and other stakeholders.

Only the version approved by the Legal Representative and published through authorized institutional channels shall be considered the official version.

Previous versions will be retained as part of the Foundation’s document management system solely for historical reference, auditing, traceability, and regulatory compliance purposes, and may not be used for the application of current procedures.

1.5. Review Frequency

This Policy shall be reviewed at least once every two (2) years, or before such period if any of the following circumstances occur:

  • Enactment or amendment of regulations related to personal data protection.

  • Changes in the Foundation’s organizational structure.

  • Implementation of new processes or technologies involving the processing of personal data.

  • Changes in the purposes for which information is processed.

  • Requirements issued by the Superintendence of Industry and Commerce or any other competent authority.

  • Identification of risks requiring an update to this Policy.

2. Objective

This Personal Data Processing Policy aims to establish the guidelines, principles, procedures, and responsibilities governing the collection, storage, use, circulation, transmission, transfer, updating, retention, and deletion of personal data by the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL in the course of its mission-related, healthcare, academic, administrative, contractual, and support activities.

This policy seeks to guarantee the constitutional right of all individuals to access, update, correct, and control the information collected about them in databases or files managed by the Foundation, ensuring that such processing is carried out in accordance with the principles of legality, purpose, freedom, accuracy, transparency, restricted access and circulation, security, confidentiality, and demonstrated accountability, pursuant to the Political Constitution of Colombia, Law 1581 of 2012, Single Regulatory Decree 1074 of 2015, and all other regulations governing personal data protection.

In particular, this policy establishes the necessary measures to ensure the proper processing of sensitive personal data related to the physical, mental, emotional, and spiritual health of users and beneficiaries of the programs carried out by the Foundation, as well as information relating to employees, volunteers, healthcare professionals, contractors, suppliers, donors, and other data subjects whose personal data is processed.

Likewise, this policy is intended to strengthen the Foundation’s institutional culture of personal data protection, promote good practices in privacy and information security, prevent risks arising from improper personal data processing, and demonstrate the Foundation’s ongoing commitment to complying with applicable legal and regulatory obligations, thereby building trust among its users, strategic partners, authorities, and other stakeholders.

3. Scope

This Policy applies to all activities involving the collection, storage, use, circulation, consultation, updating, correction, organization, retention, transmission, transfer, deletion, and, in general, any other operation involving the processing of personal data carried out by the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL in connection with its corporate purpose and the activities performed in fulfillment of its institutional mission.

The provisions contained in this Policy are mandatory for all directors, administrators, members of governing bodies, employees, staff members, contractors, volunteers, interns, healthcare professionals, consultants, suppliers, strategic partners, and any natural or legal person who, by reason of their duties or contractual or legal relationship with the Foundation, has access to personal data or participates in any stage of information processing.

Likewise, this Policy applies to the processing of personal data belonging to the Foundation’s various stakeholder groups, including, among others:

  • Users and beneficiaries of the programs and services offered by the Foundation.

  • Parents, guardians, or legal representatives of children and adolescents, where applicable.

  • Family members or persons authorized by the data subjects.

  • Employees, staff members, and former employees.

  • Applicants participating in recruitment processes.

  • Members of administrative and governing bodies.

  • Volunteers and collaborators.

  • Healthcare professionals affiliated with or providing services to the Foundation.

  • Contractors and subcontractors.

  • Suppliers of goods and services.

  • Donors, sponsors, and benefactors.

  • Strategic partners and entities with which the Foundation develops joint projects or programs.

  • Visitors to the Foundation’s physical facilities.

  • Users of digital channels, the institutional website, social media platforms, and other technological platforms managed by the Foundation.

This Policy covers the processing of all categories of personal data managed by the Foundation, including public, semi-private, private, and sensitive personal data, particularly information related to the physical, mental, emotional, and spiritual health of data subjects, clinical or therapeutic information, biometric data when collected, socioeconomic, academic, and employment information, and any other information necessary for the proper performance of institutional activities.

This Policy also applies to databases directly managed by the Foundation, as well as those processed by third parties acting as Data Processors on behalf of the Foundation under contracts, agreements, or any other legal instrument involving access to personal data.

The provisions set forth herein apply to processing carried out through physical, electronic, automated, or manual means, including information systems, technological platforms, applications, cloud services, communication tools, physical files, administrative records, and any other means used to manage personal information.

This Policy applies throughout the entire life cycle of personal data, from collection through deletion or anonymization, in accordance with the purposes authorized by data subjects, the principles established under Colombian law, and applicable legal data retention obligations.

4. Regulatory Framework

This Policy is based on the constitutional, legal, and regulatory provisions governing the fundamental right to habeas data, the protection of personal data, and information privacy in Colombia, as well as on the special regulations applicable to the provision of services related to health, well-being, and comprehensive care.

4.1. Political Constitution of Colombia

  • Article 15: establishes the fundamental right to habeas data, personal and family privacy, and a good name, providing that all individuals have the right to access, update, and rectify information about them contained in databases or files held by public or private entities.

  • Article 20: relates to the right to receive truthful and impartial information, while ensuring respect for privacy and the protection of personal information.

  • Article 74: recognizes the right of access to public documents, subject to the limitations established by law to protect confidential information and personal data.

4.2. Law 1581 of 2012

Establishes the general provisions for the protection of personal data. It constitutes Colombia’s general personal data protection regime and sets forth the principles, rights, duties, and obligations governing the processing of personal information by Data Controllers and Data Processors.

4.3. Single Regulatory Decree 1074 of 2015

Book 2, Part 2, Title 2, Chapter 25. It compiles the regulations applicable to the general personal data protection regime and addresses matters related to authorization for data processing, privacy notices, data subject rights, procedures for inquiries and complaints, transfers and transmissions of personal data, and accountability measures applicable to Data Controllers and Data Processors.

4.4. Law 1266 of 2008

Where applicable, particularly with respect to the processing of financial, commercial, credit, or economic obligation information relating to employees, contractors, suppliers, or third parties.

4.5. Law 1751 of 2015

Regulates the fundamental right to health. The processing of health-related information must comply with the principles of confidentiality, human dignity, autonomy, and respect for users’ rights.

4.6. Law 23 of 1981

Establishes rules governing Medical Ethics. Professional secrecy and the confidentiality of clinical information shall be guaranteed in accordance with this law.

4.7. Resolution 1995 of 1999

Establishes rules for the management of Medical Records. The preparation, administration, custody, and retention of medical records are the exclusive responsibility of the duly authorized treating professional. The Foundation does not administer or maintain custody of medical records. When it incidentally becomes aware of information related to such records, it shall comply with the confidentiality and privacy requirements established under this regulation.

4.8. Law 1098 of 2006

Childhood and Adolescence Code. When data processing involves children and adolescents, enhanced protection shall be guaranteed, safeguarding the best interests of the child.

4.9. Colombian Commercial Code and Civil Code

Where applicable, the Foundation shall comply with provisions relating to document retention, contractual and non-contractual liability, and obligations arising from legal relationships involving the processing of personal data.

4.10. Circulars, Guidelines, and Directives of the Superintendence of Industry and Commerce

The Foundation shall adopt the recommendations and guidelines issued by the SIC in its capacity as the National Data Protection Authority, particularly those relating to the principle of Demonstrated Accountability, risk management, implementation of comprehensive data management programs, information security, handling of inquiries and complaints, and good practices for Data Controllers and Data Processors.

4.11. Case Law and Administrative Doctrine

The interpretation and application of this Policy shall take into account the guiding criteria issued by the Constitutional Court regarding habeas data and privacy, as well as the doctrine, opinions, guidelines, and circulars issued by the Superintendence of Industry and Commerce.

4.12. Other Applicable Regulations

This Policy shall be interpreted and applied in accordance with all other provisions governing the processing of personal data. In the event of amendment, repeal, or enactment of new regulations, the Foundation shall update this Policy accordingly.

5. Identification of the Data Controller

In accordance with Law 1581 of 2012 and Decree 1074 of 2015, the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL acts as the Data Controller with respect to the personal data it collects, stores, uses, circulates, transmits, transfers, updates, retains, or deletes in the course of its institutional activities.

In this capacity, the Foundation is responsible for ensuring that personal data is processed lawfully, transparently, securely, and in accordance with the purposes previously disclosed to and authorized by data subjects, adopting the necessary technical, human, administrative, and organizational measures to protect the information.

5.1. Data Controller Information

  • Legal Name: FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL

  • Tax ID (NIT): 900.217.716-2

  • Legal Nature: Nonprofit Entity – Foundation

  • Principal Place of Business: Bogotá D.C., Colombia

  • Address: Carrera 13 No. 102-28, Chicó, Bogotá D.C., Colombia

  • Data Protection Email: funcionfuturo@hotmail.com

  • Website: www.funcionfuturo.org

  • Contact Numbers: +57 601 5255439 / +57 316 5362141

  • Legal Representative: Carla Andrea Jaramillo Ortiz

5.2. Responsibilities of the Data Controller

  • Guarantee data subjects the full and effective exercise of their fundamental right to habeas data.

  • Request and retain the authorization granted by data subjects whenever required.

  • Clearly, sufficiently, and in advance inform data subjects of the purposes for which their personal data will be processed.

  • Adopt technical, administrative, legal, and organizational measures to protect the information.

  • Ensure the confidentiality of personal information processed by the Foundation.

  • Promptly address inquiries, requests, petitions, complaints, and claims.

  • Update, correct, or delete information where appropriate.

  • Inform Data Processors of the obligations arising from this Policy and verify their compliance.

  • Implement continuous improvement mechanisms for the institutional data protection system.

  • Comply with all other obligations established under Law 1581 of 2012, Decree 1074 of 2015, and any regulations that amend them.

5.3. Channel for Exercising Data Subject Rights

Data subjects may exercise their rights to access, update, correct, or delete their information, revoke authorization, submit inquiries, or file complaints through the official channels provided by the Foundation. Requests will be handled within the legally established timeframes and through procedures designed to protect the identity of the data subject and the confidentiality of the information.

6. Definitions

For the purposes of interpreting and applying this Policy, the following definitions are adopted, based on Law 1581 of 2012, Decree 1074 of 2015, and other applicable regulations:

  • Authorization: Prior, express, and informed consent granted by the Data Subject allowing the Foundation to process their personal data, except in cases provided for by law.

  • Privacy Notice: Verbal or written communication addressed to the Data Subject informing them of the existence of the data processing policies, the purposes of processing, the Data Subject’s rights, and the mechanisms for accessing the information.

  • Database: An organized collection of personal data subject to processing, regardless of the manner or method used for its creation, storage, organization, and access.

  • Personal Data: Any information linked or that may be associated with an identified or identifiable natural person.

  • Public Data: Data classified as such by law or the Constitution, as well as data that is not semi-private, private, or sensitive, such as marital status, profession or occupation, status as a merchant, or status as a public servant.

  • Private Data: Data that, due to its intimate or confidential nature, is only relevant to the Data Subject.

  • Semi-Private Data: Data that is not intimate, confidential, or public in nature and whose disclosure may be of interest both to the Data Subject and to a particular sector or group.

  • Sensitive Data: Data that affects the privacy of the Data Subject or whose misuse may result in discrimination. This includes, among others: physical health, mental health, medical, psychological, or psychiatric diagnoses, medical records, therapeutic information, psychoactive substance use, genetic information, biometric data, and religious or philosophical beliefs disclosed within the context of care and spiritual guidance voluntarily provided by the Data Subject. Such data shall be processed under enhanced confidentiality and security measures.

  • Data Processor: A natural or legal person that processes personal data on behalf of the Data Controller.

  • Data Controller: A legal entity that makes decisions regarding the database and/or the processing of personal data. For purposes of this Policy, the Data Controller is the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL.

  • Data Subject: A natural person whose personal data is subject to processing.

  • Processing: Any operation performed on personal data, including collection, recording, organization, storage, retention, consultation, use, updating, modification, correction, circulation, transmission, transfer, blocking, deletion, erasure, and destruction.

  • Transfer of Personal Data: Sending personal data to a Data Controller located within or outside Colombian territory, who will act independently as a Data Controller.

  • Transmission of Personal Data: Communication of personal data to a Data Processor so that it may be processed on behalf of the Data Controller, within or outside the national territory.

  • Medical Record: A private and mandatory document subject to confidentiality, in which the user’s health conditions, medical and healthcare actions, and other procedures are recorded chronologically. It may only be accessed by persons authorized by law.

  • Clinical Information: Information related to the user’s physical, mental, emotional, psychiatric, psychological, or therapeutic condition, regardless of whether it forms part of a formal medical record.

  • Healthcare Professional: A natural person legally authorized to provide healthcare services, including physicians, psychiatrists, psychologists, occupational therapists, social workers, nurses, and other professionals.

  • Out-of-Facility Care: Professional, healthcare, therapeutic, educational, or support services provided outside the Foundation’s physical facilities.

  • Anonymization: A technical process through which personal data is irreversibly transformed to prevent identification of the Data Subject.

  • Pseudonymization: Processing through which information can no longer be attributed to a specific Data Subject without the use of additional information that is kept separately and protected.

  • Information Security Incident: An actual or potential event that compromises the confidentiality, integrity, availability, or authenticity of personal data.

  • Demonstrated Accountability Principle: The institutional commitment through which the Foundation adopts policies, procedures, controls, and mechanisms designed to ensure and demonstrate ongoing compliance with personal data protection regulations.

7. Guiding Principles for Personal Data Processing

The Foundation shall carry out all activities related to the processing of personal data in strict compliance with the principles established in Law 1581 of 2012, Decree 1074 of 2015, and all other applicable provisions.

7.1. Principle of Legality

Data processing is a regulated activity that must at all times comply with the Constitution, Law 1581 of 2012, Decree 1074 of 2015, and all other applicable regulations. No processing may be carried out outside the framework of current legal provisions.

7.2. Principle of Purpose

Processing shall serve a legitimate, specific, explicit, and disclosed purpose. The Foundation shall only process information necessary to fulfill its corporate purpose. Data shall not be used for purposes incompatible with those for which it was collected.

7.3. Principle of Freedom

Processing may only be carried out with the prior, express, and informed authorization of the Data Subject, except where otherwise provided by law. The Foundation shall refrain from obtaining or processing data through deceptive or coercive practices.

7.4. Principle of Accuracy or Data Quality

Information must be truthful, complete, accurate, up to date, verifiable, and understandable. The Foundation shall adopt reasonable mechanisms to keep information updated and shall promptly correct data when requested by the Data Subject.

7.5. Principle of Transparency

The Foundation shall guarantee the right to obtain, at any time and without undue restrictions, information regarding the existence of personal data, the purposes of processing, and the mechanisms available to exercise Data Subject rights.

7.6. Principle of Restricted Access and Circulation

Personal data may only be processed by persons authorized or legally entitled to do so. Information shall not be made available through publicly accessible channels. The Foundation shall implement physical and logical access controls.

7.7. Principle of Security

The Foundation shall adopt the technical, administrative, legal, organizational, and human measures necessary to protect personal data against alteration, loss, consultation, use, access, or unauthorized disclosure. Such measures shall be proportionate to the nature of the information and the level of risk, with enhanced protection for sensitive data.

7.8. Principle of Confidentiality

All persons involved in data processing shall be required to maintain the confidentiality of the information, even after their relationship with the Foundation has ended.

7.9. Principle of Necessity and Proportionality

The Foundation shall only collect and process data that is strictly necessary. Excessive, irrelevant, or disproportionate information shall not be requested.

7.10. Principle of Demonstrated Accountability

The Foundation shall implement policies, procedures, internal controls, and continuous improvement mechanisms to demonstrate effective compliance with applicable regulations, promoting a culture of risk prevention and privacy protection.

7.11. Principle of Privacy by Design and by Default

When implementing new processes, technologies, platforms, or projects, the Foundation shall incorporate privacy protection measures from the design stage and, by default, collect only the information strictly necessary.

7.12. Principle of Enhanced Protection of Sensitive Data

The processing of data related to physical, mental, emotional, psychological, psychiatric, or spiritual health shall be carried out under enhanced standards of confidentiality, security, and restricted access, with measures designed to prevent any form of discrimination or stigmatization.

7.13. Principle of Data Retention Limitation

Personal data shall be retained only for as long as necessary to fulfill the stated purposes, comply with legal obligations, or protect the Foundation’s rights. Once the applicable retention periods expire, the information shall be deleted, anonymized, or archived.

7.14. Principle of Good Faith

All actions shall be carried out in accordance with standards of loyalty, diligence, ethics, transparency, and respect for the fundamental rights of Data Subjects.

8. Categories of Personal Data Processed

The Foundation may collect, store, use, update, consult, transmit, transfer, retain, and delete different categories of personal data, in accordance with the purposes disclosed and the authorizations granted.

8.1. Identification Data

First and last names; type and number of identification document; date and place of birth; nationality; marital status when necessary; photograph; handwritten or electronic signature; civil registry, identity card, or equivalent document where applicable.

8.2. Contact Data

Residential address; city and department; landline and mobile phone numbers; email address; address for notifications; emergency contact person.

8.3. Socioeconomic Data

Income level; socioeconomic classification; household composition; occupation; educational level; employment status; conditions of vulnerability. Such data is processed when necessary for the development of programs, profiling processes, or access to institutional benefits.

8.4. Employment Data

Résumé; academic background; professional experience; employment references; certifications; contractual information; affiliations with the Social Security System; performance evaluations; training records.

8.5. Academic Data

Educational level; degrees obtained; academic certificates; participation in courses, workshops, or diploma programs; results of training processes.

8.6. Financial, Banking, Accounting, and Tax Data

Bank accounts, financial certificates, payment information, tax information, billing, donations, contributions, accounting records, and other information necessary for administrative and financial management. When processing involves information regulated by Law 1266 of 2008, the Foundation shall ensure that such information is truthful, complete, accurate, up to date, verifiable, and used only for authorized purposes.

8.7. Sensitive Data

Information regarding physical and mental health; psychological and psychiatric diagnoses; medical records and clinical progress notes known only incidentally within the context of administrative coordination, without the Foundation administering or maintaining custody of them; interdisciplinary assessments; therapeutic information; medical treatments; disabilities; psychoactive substance use or treatment; results of psychoactive substance and alcohol screening tests conducted by the Foundation under its internal safety and conduct protocols, treated as a category separate from medical records; biometric data used for authentication or security; and spiritual, religious, or philosophical beliefs voluntarily provided by the Data Subject.

8.8. Data of Children and Adolescents

Such data is processed when doing so serves the best interests of the child and respects their fundamental rights, in accordance with Law 1581 of 2012, Decree 1074 of 2015, and the Childhood and Adolescence Code.

8.9. Biometric Data

Photographs; facial images; fingerprints; voice recordings; audiovisual records. Such data is considered sensitive and is subject to enhanced protection.

8.10. Audiovisual Data

Images, photographs, audio recordings, or video recordings used for institutional, security, academic, scientific, research, outreach, or institutional memory purposes, with the corresponding authorizations obtained when required.

8.11. Browsing and Electronic Data

IP address; browser type; operating system; cookies; device identifiers; access logs; date and time of browsing; technical information necessary for platform security.

8.12. Data of Third Parties Related to the Data Subject

Information concerning family members, guardians, legal representatives, emergency contacts, or persons authorized by the Data Subject, when necessary for the provision of services or to respond to emergencies.

8.13. Differentiated Processing of Sensitive Data

Data related to physical, mental, emotional, psychological, psychiatric, and spiritual health constitutes specially protected information. The Foundation shall adopt enhanced security, confidentiality, and restricted-access measures, in accordance with the principles of human dignity, confidentiality, necessity, proportionality, professional secrecy, and respect for the autonomy of the Data Subject.

9. Processing of Sensitive Personal Data

9.1. General Rule

The Foundation recognizes that sensitive data is subject to enhanced protection. It shall process such data only when strictly necessary to fulfill its institutional purposes, in accordance with the principles of legality, purpose, freedom, necessity, proportionality, confidentiality, and security. Processing shall be carried out for legitimate purposes previously disclosed to the Data Subject or their legal representative, with access restricted to authorized personnel.

9.2. Definition of Sensitive Data

Data that affects the privacy of the Data Subject or whose improper use may result in discrimination, pursuant to Article 5 of Law 1581 of 2012. This may include, among others: physical and mental health; medical, psychological, and psychiatric diagnoses; medical records; clinical progress notes; interdisciplinary assessments; therapeutic information; medical and psychological treatments; rehabilitation or recovery processes; disabilities; psychoactive substance use or treatment; biometric data; information concerning sexual life when relevant to the therapeutic process; and religious, philosophical, or spiritual beliefs voluntarily provided.

9.3. Purposes of Processing Sensitive Data

  • Provision of psychological, psychiatric, emotional, spiritual, or therapeutic care services.

  • Conducting interdisciplinary assessments.

  • Development, implementation, and monitoring of intervention, rehabilitation, or support plans.

  • Comprehensive care for users and beneficiaries.

  • Protection of the life or physical or mental integrity of the Data Subject or third parties.

  • Verification of compliance with internal rules of conduct regarding psychoactive substance and alcohol use through screening tests, when necessary for the safety of the user and the program community.

  • Compliance with legal, regulatory, contractual, or judicial obligations.

  • Development of research, educational, or statistical programs, subject to prior anonymization or pseudonymization where appropriate.

  • Other purposes authorized by the Data Subject and compatible with the Foundation’s institutional mission.

9.4. Authorization for the Processing of Sensitive Data

Prior, express, and informed authorization shall be requested, except where the law permits processing without authorization. The Data Subject shall be informed that they are not required to authorize the processing of sensitive data, except where required by law or contract, which data will be processed, the specific purposes of processing, their rights, and the mechanisms available to exercise those rights. When the Data Subject is a child or adolescent, authorization shall be granted by their legal representative, while respecting the child’s evolving autonomy and right to be heard.

9.5. Special Protection Measures

  • Access restricted exclusively to authorized personnel.

  • Execution of confidentiality agreements.

  • Authentication controls and access profile management.

  • Protection of physical and electronic files.

  • Backups where necessary.

  • Protocols for secure storage and retention.

  • Procedures for managing security incidents.

  • Ongoing staff training.

9.6. Professional Secrecy and Confidentiality

Healthcare professionals, employees, volunteers, contractors, and all other persons with access to sensitive data shall be required to maintain strict confidentiality and professional secrecy. This obligation shall remain in effect even after their relationship with the Foundation has ended, except where disclosure is required by a competent authority or authorized by the Data Subject.

9.7. Prohibition of Incompatible Processing

The Foundation shall refrain from using sensitive data for purposes other than those for which it was collected. Under no circumstances shall such data be used to cause discrimination, stigmatization, or exclusion.

9.8. Transfer and Transmission of Sensitive Data

Sensitive data may only be transferred or transmitted where there is a legal or contractual basis, compliance with Colombian law is ensured, and the third party implements equivalent or stronger security measures. The necessary legal agreements shall be executed.

9.9. Institutional Responsibility

The Foundation shall adopt a preventive approach based on risk management, continuous improvement, and the principle of demonstrated accountability, implementing mechanisms for ongoing supervision, control, and updating of its procedures.

10. Tratamiento de Datos Personales de Niños, Niñas y Adolescentes

10.1. General Principle

The personal data of children and adolescents is subject to special protection. Its processing shall be carried out in strict compliance with the Constitution, Law 1581 of 2012, Law 1098 of 2006, Decree 1074 of 2015, and all other applicable regulations. The Foundation shall process such data only when necessary for the fulfillment of its corporate purpose, the provision of its services, the implementation of programs, or compliance with legal obligations.

10.2. Criteria for Processing

  • The processing must serve and respect the best interests of the child or adolescent.

  • It must ensure respect for their fundamental rights.

  • It must be strictly necessary for the provision of services or implementation of programs.

  • Prior, express, and informed authorization must be obtained from the parent or legal representative when required by law.

  • The child or adolescent’s right to be heard must be guaranteed, taking into account their level of maturity.

10.3. Purposes of Processing

  • Provision of psychological, psychiatric, emotional, spiritual, and therapeutic care services.

  • Interdisciplinary assessment and monitoring of therapeutic processes.

  • Implementation of prevention, promotion, education, and well-being programs.

  • Coordination with parents, guardians, legal representatives, or competent authorities.

  • Compliance with legal, regulatory, or judicial obligations.

  • Other purposes compatible with the institutional mission and disclosed to the legal representative.

10.4. Authorization for Processing

Authorization shall be granted by the person exercising parental authority, legal representation, or custody of the child or adolescent. When the child or adolescent’s age, development, and maturity allow, the Foundation shall explain the processing in clear and understandable language and take their opinion into account, in accordance with the principle of evolving autonomy.

10.5. Sensitive Data of Minors

When services involve the processing of sensitive data of minors, including physical, mental, emotional, psychological, psychiatric, or therapeutic health information, the Foundation shall adopt enhanced protection, confidentiality, and security measures, with access restricted to healthcare professionals and authorized personnel.

10.6. Rights of Minors and Their Representatives

Through their legal representatives, they may access the data being processed; request its updating, correction, or rectification; request deletion where applicable; revoke authorization, except where a legal or contractual obligation applies; and submit inquiries, petitions, complaints, or claims.

10.7. Special Protection Measures

Restricted access; confidentiality protocols; enhanced protection of administrative information; ongoing staff training; risk management; and measures designed to prevent unauthorized access, use, modification, or disclosure.

10.8. Prohibition of Improper Use

The Foundation shall not use such data for purposes other than those authorized, nor for discriminatory, commercial, or advertising purposes that may affect the dignity, comprehensive development, privacy, or rights of children and adolescents.

10.9. Institutional Commitment

The Foundation reaffirms its commitment to the comprehensive protection of the rights of children and adolescents, based on principles of ethics, confidentiality, security, respect for human dignity, and the best interests of the child.

11. Purposes of Personal Data Processing

The Foundation shall process the personal data of its stakeholders for legitimate, specific, explicit, and disclosed purposes, either directly or through third parties acting as Data Processors.

11.1. General Purposes

  • Fully identify Data Subjects and keep databases up to date.

  • Comply with legal, regulatory, and statutory obligations.

  • Respond to requests from judicial or administrative authorities.

  • Manage legal, contractual, academic, healthcare, and administrative relationships.

  • Implement physical, logical, and administrative security measures and manage institutional risks.

  • Conduct audits, internal controls, and quality management processes.

  • Handle inquiries, petitions, complaints, and claims, and conduct statistical and continuous improvement processes.

  • Manage social responsibility, research, and institutional development programs.

11.2. Users and Beneficiaries

Manage admission, registration, and profiling; provide emotional, spiritual, and comprehensive support services; provide psychological and psychiatric care through authorized professionals; conduct interdisciplinary assessments; design, implement, and evaluate intervention plans; coordinate referrals; schedule appointments and follow-ups; provide in-person, virtual, or out-of-facility care; manage administrative processes; implement mental health prevention and promotion programs; and ensure continuity and quality of services.

11.3. Parents, Guardians, and Legal Representatives

Manage authorizations; coordinate care processes; provide information on treatment progress where applicable; manage administrative matters; and respond to requests, inquiries, and complaints.

11.4. Employees, Applicants, Interns, and Volunteers

Recruitment and hiring; reference verification; security screenings where applicable; human resources management; enrollment in the General Social Security System; payment of salaries, fees, and benefits; performance evaluations; education and training; employee well-being; disciplinary management; and compliance with labor and occupational health and safety obligations.

11.5. Contractors, Suppliers, and Strategic Partners

Evaluate proposals; manage contracting processes; execute, perform, and close contracts; process payments; verify compliance with contractual and tax obligations; manage audits; administer business relationships; and assess the quality of goods and services.

11.6. Donors, Cooperating Partners, and Sponsors

Manage donations and contributions; implement cooperation agreements; comply with legal and tax obligations; prepare financial and management reports; maintain institutional communications; publicly acknowledge contributions when authorized; and strengthen cooperation relationships.

11.7. Events, Programs, and Institutional Activities

Manage registration and participation; attendance control; issuance of certificates; logistics; photographic and audiovisual records; institutional communication when authorized; and evaluation of program impact.

11.8. Website, Digital Platforms, and Social Media

Manage contact forms; respond to information requests; improve the browsing experience; ensure information security; manage cookies; develop usage statistics; share institutional information; promote educational and well-being campaigns; and manage paid digital advertising campaigns and lead generation through platforms such as Meta (Facebook and Instagram), including directing interested individuals to institutional messaging channels such as WhatsApp.

11.9. Facility Security

Protect the safety and integrity of individuals; ensure facility security; protect Foundation assets; prevent fraud or incidents; and support internal investigations or requests from authorities.

11.10. Research, Statistics, and Institutional Improvement

Develop management indicators; conduct statistical studies; evaluate programs; design improvement strategies; and carry out scientific or academic research. Whenever possible, information shall be anonymized or pseudonymized in advance.

11.11. Legal and Regulatory Compliance

Comply with legal and regulatory obligations; respond to requests from authorities; meet accounting, tax, and labor obligations; exercise judicial and extrajudicial defense; and manage internal and external audits.

11.12. Institutional Communications

Provide information about services; confirm appointments and activities; send administrative information; communicate institutional changes; share prevention, promotion, and educational campaigns; and send institutional newsletters, while respecting the Data Subject’s right to request that such communications be discontinued.

11.13. Other Compatible Purposes

Other purposes compatible with those described above, provided they are consistent with the existing relationship, do not violate applicable law, are disclosed in advance when appropriate, and are supported by the Data Subject’s authorization when required by law.

12.Rights of Personal Data Subjects

The FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL guarantees respect for and protection of the rights of personal data subjects whose information is processed, in accordance with the Political Constitution of Colombia, Law 1581 of 2012, Single Regulatory Decree 1074 of 2015, and all other applicable regulations.

Data Subjects, or persons legally authorized to act on their behalf, may exercise the following rights:

12.1. Right to Access

To know whether their personal data is being processed and to access, free of charge, the information stored in the Foundation’s databases.

12.2. Right to Update

To request the updating of their personal data when it has changed or no longer reflects their current situation.

12.3. Right to Rectification

To request correction of personal data when it is inaccurate, incomplete, incorrect, outdated, or misleading.

12.4. Right to Request Proof of Authorization

To request evidence of the authorization granted, except where the law permits processing without authorization.

12.5. Right to Be Informed

To request information regarding the purposes of processing, how the data has been used, the categories of data processed, the third parties with whom the information has been shared, and the general protection measures in place.

12.6. Right to Revoke Authorization

To request revocation of authorization when no legal or contractual obligation prevents it. The request shall be assessed in accordance with applicable law and legal data retention requirements.

12.7. Right to Request Data Deletion

To request deletion when the processing does not comply with legal principles and safeguards, the original purpose no longer exists, or deletion is legally appropriate. Deletion shall not apply where there is a legal or contractual obligation to retain the information.

12.8. Right to Submit Inquiries and Complaints

To submit inquiries, petitions, complaints, or claims through the channels provided. The Foundation shall respond within the legally established timeframes.

12.9. Right to File Complaints with the Superintendence of Industry and Commerce

To file complaints with the SIC when they believe their rights have been violated, once internal procedures have been exhausted where applicable.

12.10. Right to Confidentiality

To require that their information be processed with strict confidentiality, particularly sensitive data related to physical, mental, emotional, psychological, psychiatric, or spiritual health.

12.11. Right to Information Security

To require the implementation of reasonable technical, administrative, and organizational measures to protect their personal data.

12.12. Right to Refuse Authorization for the Processing of Sensitive Data

Except in cases provided by law, the Data Subject has the right not to provide or authorize the processing of sensitive data. When such data is necessary for the provision of a service, the Data Subject shall be informed in advance of the consequences of refusing to provide it.

12.13. Rights of Children and Adolescents

These rights shall be exercised by their parents or legal representatives, without prejudice to the child or adolescent’s right to be heard. All processing shall serve the best interests of the child.

12.14. Exercise of Rights

These rights may be exercised by: the Data Subject; their successors, upon proof of such status; their legal representative or authorized agent; the legal representative of a minor; and any other persons authorized by law. The Foundation may request documents to verify identity or legal authority.

12.15. Free Exercise of Rights

The exercise of these rights shall be free of charge, without prejudice to any exceptional costs related to reproduction, delivery, or certification. The Foundation shall not impose unjustified burdens.

12.16. Institutional Commitment

The Foundation shall promote a culture of respect for the rights of Data Subjects by adopting internal procedures and continuous improvement measures to ensure the effective exercise of habeas data rights.

13. Duties of the Foundation as Data Controller

The Foundation shall comply with, among others, the following duties:

13.1. Guarantee the Exercise of Habeas Data Rights

Allow Data Subjects to access, update, rectify, and, where applicable, request the deletion of their personal data.

13.2. Obtain Authorization from the Data Subject

Request and retain prior, express, and informed authorization, except in cases exempted by law.

13.3. Inform the Data Subject of the Purpose of Processing

Clearly, sufficiently, and understandably inform Data Subjects of the purposes of processing, their rights, and the mechanisms available to exercise them.

13.4. Retain Proof of Authorization

Maintain evidence of authorizations for auditing purposes or requests from competent authorities.

13.5. Ensure Data Quality

Adopt reasonable measures to ensure that information is truthful, complete, accurate, up to date, verifiable, and understandable.

13.6. Implement Security Measures

Adopt technical, administrative, physical, organizational, and legal measures proportionate to the level of risk, particularly when processing sensitive data.

13.7. Ensure Confidentiality

Ensure that all persons involved in data processing maintain confidentiality, even after the relationship has ended.

13.8. Handle Inquiries, Petitions, and Complaints

Implement internal procedures to receive, manage, and respond to requests in a timely manner.

13.9. Update and Rectify Information

Update, correct, or rectify information when appropriate and communicate such changes to Data Processors.

13.10. Process Deletion and Revocation Requests

Handle valid requests when there is no legal or contractual obligation to retain the information.

13.11. Report Security Incidents

Adopt procedures to identify, manage, and document security incidents and implement corrective actions.

13.12. Supervise Data Processors

Verify that third parties comply with applicable law, this Policy, and the agreements entered into.

13.13. Train Personnel

Promote ongoing training and awareness programs.

13.14. Apply the Principle of Demonstrated Accountability

Implement management, monitoring, and continuous improvement mechanisms that demonstrate effective compliance.

13.15. Review and Update the Policy

Periodically review the Policy in response to regulatory, technological, or organizational changes.

13.16. Comply with Other Legal Obligations

Comply with Law 1581 of 2012, Decree 1074 of 2015, instructions issued by the SIC, and all other applicable provisions.

Institutional Commitment

The Foundation considers the protection of personal data an essential component of its institutional governance and its commitment to ethics, transparency, and respect for fundamental rights.

14. Authorization for the Processing of Personal Data

14.1. Authorization from the Data Subject

The Foundation shall request prior, express, and informed authorization, except in cases exempted by law. Authorization is the free, specific, unequivocal, and informed expression through which the Data Subject agrees to the processing of their personal data for the purposes disclosed. Before granting authorization, the Data Subject shall be informed of: the identity and contact details of the Data Controller; the specific purposes of processing; the optional nature of answering questions related to sensitive data or minors; their rights; the channels available to exercise those rights; and this Policy.

14.2. Methods for Obtaining Authorization

Authorization may be obtained through any means that allows subsequent consultation and proof of consent, including: signed physical forms; electronic forms; digital platforms; the website; email; handwritten, electronic, or digital signatures; voice recordings; biometric systems where permitted by law; data messages; mobile applications; and any other technological means that preserves evidence of consent.

14.3. Content of the Authorization

At a minimum, the authorization shall include: identification of the Data Controller; identification of the Data Subject where applicable; purposes of processing; reference to this Policy; indication of the Data Subject’s rights; and an express statement of consent.

14.4. Retention of Authorization

Evidence of authorization shall be retained for as long as necessary to demonstrate compliance with legal obligations, using physical, electronic, or digital means that ensure its integrity, availability, and authenticity.

14.5. Authorization for the Processing of Sensitive Data

Express and specific authorization shall be requested, informing the Data Subject that they are not required to authorize such processing, except where there is a legal obligation or where the information is essential for the provision of the service, which data will be processed, the purposes of processing, and the general protection measures in place.

14.6. Authorization for the Processing of Personal Data of Children and Adolescents

Authorization shall be granted by the person exercising parental authority, legal representation, or custody, without prejudice to the child or adolescent’s right to be heard. Processing shall serve the best interests of the child.

14.7. Cases Where Authorization Is Not Required

Pursuant to Article 10 of Law 1581 of 2012:

  • Information requested by a public entity or administrative authority in the exercise of its legal functions, or by court order.

  • Publicly available data.

  • Cases of medical or health emergencies.

  • Processing authorized by law for historical, statistical, or scientific purposes, while protecting the identity of Data Subjects.

  • Data related to individuals’ Civil Registry records.

14.8. Revocation of Authorization

The Data Subject may revoke authorization at any time, provided there is no legal, contractual, or judicial obligation requiring the Foundation to continue processing or retaining the information. Where applicable, the Foundation shall cease processing the data for the purposes covered by the revoked authorization.

14.9. Updating Authorization

If the Foundation intends to use personal data for different or incompatible purposes, it shall request new authorization, unless otherwise permitted by law.

Institutional Commitment

Authorization shall be obtained in accordance with the principles of transparency, freedom, good faith, and respect for the autonomy of Data Subjects, while preserving the corresponding evidence.

15. Procedure for Handling Inquiries

15.1. Right to Submit Inquiries

Data Subjects or persons legally authorized to act on their behalf may submit inquiries to: determine whether the Foundation processes their personal data; access their information; request information about the purposes of processing; obtain a copy of the authorization where applicable; learn which categories of data are stored; request information about third parties to whom the information has been transmitted or transferred; and submit any other related inquiry.

15.2. Persons Authorized to Submit Inquiries

The Data Subject; their successors, upon proof of such status; their legal representative; a duly authorized agent; legal representatives of minors; and any other persons authorized by law. The Foundation may request documentation to verify identity and legal authority.

15.3. Service Channels

Inquiries must include: the Data Subject’s full name; type and number of identification document; contact information; a clear description of the inquiry; and documents proving representation where applicable.

15.4. Filing and Registration

Every inquiry shall be registered and assigned a filing number and date of receipt. The institutional form (Annex G) or any other method that allows the request to be properly recorded may be used.

15.5. Verification of the Request

The Foundation shall verify the identity of the requester, their legal authority, the sufficiency of the information provided, and the existence of the relevant data. If the information is insufficient, the requester may be asked to provide additional information.

15.6. Timeframe for Responding to Inquiries

A maximum of ten (10) business days from receipt. If it is not possible to respond within this period, the interested party shall be informed before the deadline of the reasons for the delay and the new response date, which may not exceed five (5) additional business days after the initial deadline, pursuant to Article 14 of Law 1581 of 2012.

15.7. Response to the Inquiry

The response shall be issued by the competent department or official using clear, complete, and understandable language. It may be provided through the same channel used by the requester or another authorized channel, while ensuring confidentiality. When the inquiry involves sensitive data or confidential information, additional identity verification measures shall be implemented.

15.8. Inquiries Related to Sensitive Data

When an inquiry concerns sensitive data or health information managed by an independent professional, the Foundation shall direct the Data Subject to the responsible professional or custodian of the information. When the Foundation has access to health information, it shall only process such information within the scope of its responsibilities.

15.9. Recordkeeping and Retention

The Foundation shall retain evidence of inquiries and responses for as long as necessary, ensuring their integrity, availability, and confidentiality.

15.10. Summary of the Procedure

  • Receipt and filing of the inquiry — Data Protection Responsible Area — Date of receipt.

  • Verification of identity and legal authority — Data Protection Responsible Area — During processing.

  • Analysis of the inquiry — Competent Area — According to the complexity of the case.

  • Response to the Data Subject — Foundation — Maximum ten (10) business days.

  • Exceptional extension — Foundation — Up to five (5) additional business days, with prior notice to the Data Subject.

15.11. Continuous Improvement

The Foundation shall periodically monitor inquiries to identify opportunities for improvement and ensure timely, transparent, and efficient service. Related Annex: Annex G — Form for the Exercise of Data Subject Rights (PQR).

16. Procedure for Handling Complaints

16.1. Right to Submit Complaints

Data Subjects or persons legally authorized to act on their behalf may submit complaints when they believe that: the information must be corrected, updated, or deleted; there has been an alleged violation of Law 1581 of 2012, Decree 1074 of 2015, or this Policy; personal data has been processed for purposes other than those authorized; or any of their rights have been violated.

16.2. Persons Authorized to Submit Complaints

The Data Subject; their successors; legal representative; duly authorized agent; legal representatives of minors; and any other persons authorized by law.

16.3. Content of the Complaint

At a minimum: the Data Subject’s full name; type and number of identification document; contact information; a clear description of the facts; identification of the data in dispute where possible; supporting documents or evidence; and the signature of the Data Subject or representative where applicable. The Institutional Form (Annex G) shall be made available, without prejudice to other methods that allow proper receipt and traceability.

16.4. Service Channels

16.5. Verification of Requirements

If the complaint is incomplete, the interested party shall be asked to provide the missing information within the following five (5) business days. If two (2) months pass after the request for additional information without a response, the complaint shall be considered withdrawn, without prejudice to the right to submit a new request.

16.6. Registration of the Complaint

Once the requirements are met, the complaint shall be registered in the internal systems. If it concerns information contained in a database, the record shall be marked “Complaint in Process”, which shall remain until the complaint is finally resolved.

16.7. Processing of the Complaint

The responsible area shall analyze the facts, verify the information, and, where necessary, request input from the relevant departments. When the complaint involves sensitive data, medical records, or confidential information, access shall be limited to authorized personnel.

16.8. Timeframe for Resolving the Complaint

A maximum of fifteen (15) business days from the business day following receipt. If it is not possible to respond within this period, the interested party shall be informed before the deadline of the reasons for the delay and the new response date, which may not exceed eight (8) additional business days.

16.9. Decision on the Complaint

The decision shall be communicated in writing and shall indicate: the facts reviewed; the actions taken; the decision adopted; the legal and technical grounds; the actions implemented where applicable; and any additional remedies or mechanisms available. It shall be sent through an authorized channel while ensuring confidentiality.

16.10. Deletion of Personal Data

The Foundation shall assess whether deletion is appropriate. It shall not apply where there is a legal, contractual, regulatory, or judicial obligation to retain the information, including medical records, accounting records, employment documents, tax records, and similar documentation.

16.11. Revocation of Authorization

The Foundation shall verify the applicable legal basis. Revocation shall not apply where processing is necessary to comply with legal or contractual obligations or to properly provide services previously requested.

16.12. Retention of the Case File

Documents related to the procedure, including the request, supporting documents, actions taken, and response, shall be retained in accordance with the Document Management Policy and applicable legal retention periods.

16.13. Filing Complaints with the Superintendence of Industry and Commerce

When the Data Subject believes that their complaint was not properly addressed or that their rights were violated, they may file a complaint with the SIC after completing the internal procedure, in accordance with Law 1581 of 2012.

16.14. Procedure Summary

  • Receipt and filing of the complaint — Data Protection Responsible Area — Date of receipt.

  • Verification of requirements — Data Protection Officer — Within the following five (5) business days.

  • Correction by the Data Subject, if applicable — Data Subject — Up to two (2) months from the request.

  • Registration of the complaint and notation “Complaint in Process” — Data Protection Officer — Immediately.

  • Analysis of the complaint — Competent Area — During the procedure.

  • Response to the Data Subject — Foundation — Maximum fifteen (15) business days.

  • Exceptional extension — Foundation — Up to eight (8) additional business days, with prior notice to the Data Subject.

  • Case file closure and archiving — Document Management — Upon completion of the procedure.

16.15. Continuous Improvement

The Foundation shall periodically monitor complaints to identify recurring causes, implement preventive and corrective actions, and strengthen its internal controls. Related Annex: Annex G — Form for the Exercise of Data Subject Rights (PQR).

17. Information Security

17.1. Institutional Commitment

The Foundation shall implement technical, administrative, physical, and organizational measures to protect the confidentiality, integrity, availability, authenticity, and traceability of information, according to the nature of the data and associated risks. These measures shall be periodically reviewed and updated.

17.2. Security Objectives

  • Preserve the confidentiality of information.

  • Ensure the integrity of personal data.

  • Maintain availability for authorized persons.

  • Prevent loss, alteration, destruction, or unauthorized disclosure.

  • Prevent improper access to information systems.

  • Ensure the continuity of institutional processes.

  • Comply with legal obligations regarding data protection.

17.3. Information Classification

  • Public Information: information whose disclosure does not create risks.

  • Internal Use Information: information intended for institutional activities, with restricted access.

  • Confidential Information: information protected by Law 1581 of 2012, whose unauthorized disclosure may affect the rights of the Data Subject.

  • Highly Confidential Information: information requiring the highest level of protection, including medical records and medical diagnoses incidentally known to the Foundation, without being administered or held in custody by the Foundation; psychological and psychiatric information; biometric data; genetic information; physical and mental health data; spiritual beliefs obtained during therapeutic processes; and any other sensitive data protected by law. Access shall be limited to authorized personnel.

17.4. Security Measures

Administrative Measures

  • Definition of roles and responsibilities.

  • Confidentiality agreements with employees and contractors.

  • Periodic training on data protection.

  • Internal procedures for information processing.

  • Management of risks associated with data processing.

Technical Measures

  • Access control through usernames and passwords.

  • Management of access profiles and privileges.

  • Periodic backups.

  • Protection against malicious software.

  • Updates to information systems.

  • Access logging where technically possible.

  • Encryption or equivalent mechanisms for sensitive information during storage or transmission, where technically and economically feasible.

Physical Measures

  • Access control to facilities.

  • Restricted access to physical files.

  • Protection of printed documents.

  • Protection of administrative information related to healthcare services.

  • Video surveillance systems in authorized areas.

17.5. Access Control

Access shall be granted only to individuals who require it to perform their duties. Each user shall be responsible for the proper use of their credentials and for maintaining their confidentiality. The Foundation may suspend, modify, or revoke permissions when there is no longer a functional need or when noncompliance is identified.

17.6. Confidentiality

Any person with access to personal data shall be required to maintain strict confidentiality, even after their relationship with the Foundation has ended.

17.7. Security Incident Management

Procedures shall be established to identify, record, analyze, and manage incidents, including: unauthorized access; loss of information; theft of equipment; accidental deletion; improper disclosure; cyberattacks; unauthorized alteration of records; and misuse of credentials. When an incident may significantly affect the rights of Data Subjects, measures shall be adopted to contain its effects, correct its causes, and document the actions taken.

17.8. Risk Management

The Foundation shall promote preventive risk management by identifying, assessing, and controlling threats, with periodic reviews of databases, systems, internal processes, authorized access, contracts with Data Processors, and security measures.

17.9. Backups and Recovery

Backups shall be performed at intervals appropriate to the criticality of the data, with reasonable recovery mechanisms in place and protected by controls that prevent unauthorized access.

17.10. Retention and Secure Disposal of Information

Personal data shall be retained only for as long as necessary. Once the applicable retention periods have expired and there is no legal obligation to retain the information, it shall be deleted or anonymized using procedures designed to reduce the risk of unauthorized recovery.

17.11. Responsibility of Personnel

All employees, contractors, volunteers, and interns must comply with this Policy and apply the required security measures. Noncompliance may result in disciplinary, contractual, civil, or legal action.

17.12. Continuous Improvement

The Foundation shall promote continuous improvement through periodic review of procedures, updating of controls, staff training, and adoption of new measures. Related Annex: Annex H — Inventory and Internal Registry of Personal Data Databases.

18. Transfer and Transmission of Personal Data

18.1. General Provisions

The Foundation may transfer and/or transmit personal data to third parties in accordance with Colombian law, adopting measures to ensure security, confidentiality, and integrity, and verifying that such third parties provide sufficient safeguards.

18.2. Definitions

  • Transfer of personal data: disclosure of personal data to a recipient in Colombia or abroad that acts as a Data Controller and independently determines the purposes and means of processing.

  • Transmission of personal data: processing carried out by a third party acting as a Data Processor on behalf of the Foundation and following its instructions, pursuant to a contract or other legal instrument.

18.3. Domestic Transmission of Data

Personal data may be transmitted to third parties located in Colombia when necessary, including: technology service providers; software providers; cloud storage providers; technical support providers; courier services; audit firms; legal and accounting advisors; statutory auditors; administrative service providers; digital platform operators; and document custody providers. Data transmission agreements or contractual clauses shall be executed to ensure compliance with Law 1581 of 2012, Decree 1074 of 2015, and the instructions issued by the SIC.

18.4. Domestic Transfer of Data

Personal data may be transferred to other Data Controllers located in Colombia when authorized by the Data Subject or permitted by law, including: administrative and judicial authorities; entities within the General Social Security Health System; healthcare provider institutions (IPS); health insurance entities (EPS); inspection, surveillance, and control authorities; and cooperating or funding entities, while respecting the principles of purpose limitation and data minimization.

18.5. International Transfer of Data

The Foundation shall first verify that the processing complies with Colombian law. International transfers may take place when: the Data Subject has given express authorization; the transfer is necessary for the performance of a contract with the Data Subject or in their interest; there is a legal obligation; it is required by competent authorities; one of the exceptions under Article 26 of Law 1581 of 2012 applies; or the recipient country provides an adequate level of protection or the required safeguards have been implemented.

18.6. International Transmission of Data

The Foundation may engage technology or administrative service providers located abroad for services such as: cloud computing; institutional email; videoconferencing; document management; institutional collaboration; backup and recovery; and digital advertising and messaging platforms such as Meta Platforms, Inc. (Facebook, Instagram, and WhatsApp). When the Foundation runs paid advertising through platforms such as Meta, the platform shall act as a Data Processor with respect to information generated through ad interactions and, where applicable, custom audiences, subject to the provider’s terms and Colombian law. The Foundation shall verify that the provider implements appropriate security measures and shall execute the required data transmission agreements.

18.7. Safeguards for Transfers and Transmissions

Where applicable, the Foundation shall verify: the legitimacy of the operation; the existence of authorization when required; the purpose of processing; reasonable security measures; the execution of contracts or confidentiality agreements; the third party’s compliance with legal obligations; and application of the data minimization principle.

18.8. Obligations of Third-Party Recipients

Third-party recipients shall: process the information only for authorized purposes; implement security measures; maintain confidentiality; refrain from using the information for other purposes; allow compliance verification; and promptly report any security incident.

18.9. Special Restrictions for Sensitive Data

The transfer or transmission of sensitive data, including physical, mental, psychological, psychiatric, or spiritual health information or medical records, shall only be permitted where there is a legal basis or authorization from the Data Subject and enhanced safeguards are implemented. Applicable rules regarding medical records, professional secrecy, and healthcare regulations shall be observed.

18.10. Records and Traceability

The Foundation shall seek to maintain records identifying: the third-party recipient; the purpose; the date; the legal basis; and the security measures implemented.

18.11. Prohibitions

No transfer or transmission shall be carried out in violation of applicable law, in a manner that infringes the rights of Data Subjects, or beyond the authorized purposes. Sensitive data shall not be shared without a legal basis, valid authorization, or legitimate necessity.

18.12. Continuous Improvement

Contracts, procedures, and controls shall be periodically reviewed. Related Annex: Annex K — Record of Personal Data Transfers and Transmissions.

19. Retention and Deletion of Personal Data

19.1. General Principle

The Foundation shall retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal, contractual, regulatory, and administrative obligations, defend its rights, and ensure the provision of its services. Once the purpose no longer exists and there is no legal obligation to retain the data, the Foundation shall proceed with its deletion, anonymization, or secure disposal.

19.2. Retention Criteria

  • The purpose for which the data was collected.

  • The nature of the personal data.

  • Legal or regulatory retention obligations.

  • Limitation periods for judicial, disciplinary, tax, or administrative actions.

  • Special regulations applicable to the healthcare sector.

  • The Document Retention Schedules (TRD) adopted by the Foundation.

  • Audit, internal control, and risk management requirements.

19.3. Retention of Personal Data

Personal data shall be retained under conditions that guarantee its confidentiality, integrity, availability, and authenticity, whether in physical, electronic, digital, or any other appropriate format.

19.4. Retention of Sensitive Data

Sensitive data shall receive enhanced protection. In particular, information related to health status, diagnoses, psychological or psychiatric assessments, mental health, diagnostic or toxicology test results, biometric data, and spiritual information shall only be retained for the purpose that justifies its processing. When such information forms part of a medical record under the custody of an independent professional, its retention and confidentiality shall be the sole responsibility of that professional. The Foundation shall retain only the administrative information necessary.

19.5. Retention of Medical Records

The preparation, administration, custody, retention, access, archiving, and final disposal of medical records created by independent professionals shall be the sole responsibility of the treating professional, in accordance with healthcare sector regulations issued by the Ministry of Health and Social Protection and the General Archive of the Nation. The Foundation shall not administer or retain medical records as part of its files, unless required by law or due to a change in its operating model. It shall retain the administrative information necessary for service coordination, contractual management, billing, and compliance with legal obligations.

19.6. Retention of Employment, Contractual, and Tax Information

Such information shall be retained for the periods established by applicable labor, commercial, tax, accounting, and archival regulations.

19.7. Deletion of Personal Data

The Data Subject may request deletion when the processing does not comply with applicable principles and safeguards or when the purposes for processing no longer exist. The Foundation shall evaluate each request and proceed with deletion where legally appropriate.

19.8. Cases Where Deletion Does Not Apply

Deletion shall not apply when there is a legal or contractual obligation to retain the information, particularly to: comply with legal or regulatory obligations; respond to requests from authorities; comply with tax, labor, accounting, or commercial obligations; address judicial, administrative, or disciplinary proceedings; defend the Foundation’s rights; or fulfill obligations arising from current or terminated contracts.

19.9. Secure Disposal of Information

The following methods may be used: controlled physical destruction of documents; shredding or secure disposal of paper records; logical deletion of electronic files; secure overwriting of digital information; anonymization of databases where sufficient; and secure destruction of storage devices at the end of their useful life.

19.10. Retention of Evidence

The Foundation may retain: authorizations granted; records of inquiries and complaints; evidence of responses to requests; security incident records; data transmission agreements; internal audit records; and training records.

19.11. Periodic Review

Periodic reviews shall be conducted to verify the continued relevance of information, update data, delete records without a legal basis, identify duplicate or unnecessary information, and ensure compliance with the principle of retention limitation.

19.12. Responsibility for Retention

The internal parties responsible for each database shall ensure compliance with retention periods, Document Retention Schedules (TRD), and document management policies.

19.13. Continuous Improvement

Retention, archiving, anonymization, and deletion procedures shall be periodically reviewed. Related Annex: Annex L — Personal Data Retention Matrix.

20. Processing of Information Related to the Provision of Healthcare Services

The Foundation develops programs related to the promotion of mental health and the provision of out-of-facility care services through independent professionals duly licensed to practice psychology and psychiatry.

The preparation, completion, administration, custody, retention, confidentiality, access, and disposal of medical records are the exclusive responsibility of the healthcare professional providing the care, who must comply with applicable regulations, including Law 23 of 1981, Resolution 1995 of 1999, Law 1751 of 2015, and all other relevant provisions.

The Foundation does not administer or maintain custody of medical records as part of its institutional processes, unless it assumes such responsibility in the future due to changes in its operating model or as required by law.

However, the Foundation may process administrative information related to the provision of services, including identification and contact information, appointment scheduling, contracting, agreement management, administrative follow-up, and other necessary information, while respecting confidentiality and the provisions of Law 1581 of 2012 and this Policy.

Related Annex: Annex M — Protocol for Relationships with Independent Professionals Regarding Personal Data Protection.

21. Out-of-Facility Care

21.1. General Provisions

The Foundation may provide out-of-facility care services through healthcare, preventive, promotional, educational, therapeutic, and support activities in mental health, psychology, psychiatry, bioethics, and spiritual intelligence, carried out outside its facilities, including: home care; services in educational institutions; companies or organizations; community centers; health promotion and prevention programs; mental health outreach programs; and services in public or private institutions. When services are provided through independent professionals, the preparation, custody, retention, and administration of medical records shall be the responsibility of the treating professional.

21.2. Processing of Personal Data During Out-of-Facility Care

The Foundation may collect, store, use, update, transmit, and, where applicable, transfer the necessary personal data in accordance with Law 1581 of 2012 and this Policy. Sensitive data shall only be processed with the Data Subject’s authorization or another valid legal basis. The Foundation shall process only the data necessary for its purposes. Clinical information contained in medical records shall remain the responsibility of the professional who prepares and maintains custody of such records.

21.3. Security Measures

Professionals shall: verify the user’s identity in advance; ensure privacy during consultations; avoid discussing clinical information in the presence of unauthorized third parties; use authorized forms, devices, and systems; maintain custody of clinical documentation under their responsibility and protect administrative information; and immediately report any loss, unauthorized access, or security incident.

21.4. Electronic Devices

Devices used shall include: access through usernames and passwords or equivalent mechanisms; automatic locking after periods of inactivity; periodic software updates; protection against malicious software; and encryption where technically and economically feasible. Independent professionals shall be responsible for ensuring that temporarily stored clinical information is protected by the required security measures and is promptly incorporated into the records under their custody.

21.5. Document Custody

Professionals shall ensure proper custody of physical documents and prevent their loss, deterioration, unauthorized access, or improper reproduction. Once the activity has concluded, administrative documents shall be incorporated into the institutional records, while clinical documentation shall form part of the medical record administered by the professional.

21.6. Confidentiality

Out-of-facility care shall be provided under conditions that preserve the user’s privacy. When the location does not allow adequate privacy, the professional shall assess whether to reschedule the service or implement additional measures.

21.7. Access to and Recording of Information

Administrative information shall be recorded in institutional systems when necessary. Clinical information shall be recorded and retained by the responsible professional as part of the medical record.

21.8. Responsibilities of Professionals

Comply with this Policy; protect confidentiality; prepare, maintain custody of, retain, and administer medical records in accordance with Law 23 of 1981, Resolution 1995 of 1999, Resolution 839 of 2017, and all other applicable regulations; safeguard documents and devices; report security incidents; use only institutional channels; refrain from sharing information through unauthorized means; and keep administrative information separate from clinical information.

21.9. Monitoring and Oversight

Monitoring activities shall focus on compliance with this Policy regarding administrative information and shall not involve access to the contents of medical records, except with the Data Subject’s authorization or where required by law.

21.10. Allocation of Responsibilities for Medical Records

The preparation, completion, custody, retention, confidentiality, and administration of medical records are the exclusive responsibility of the treating professional, in accordance with Law 23 of 1981, Resolution 1995 of 1999, Resolution 839 of 2017, Law 1751 of 2015, and all other applicable regulations. The Foundation shall process only the administrative information necessary and shall not assume the role of custodian of medical records, unless its operating model changes or such responsibility is imposed by law.

Related Annex: Annex N — Protocol for Out-of-Facility Care and Personal Data Protection.

22. Independent Professionals

22.1. General Provisions

The Foundation may engage independent professionals to provide services related to healthcare, mental health, psychology, psychiatry, social work, spiritual support, training, consulting, or other activities. When they have access to personal or sensitive data managed by the Foundation, they must comply with this Policy, applicable data protection laws, and the professional standards governing their practice.

22.2. Duty of Confidentiality

They must maintain strict confidentiality regarding: user identification data; clinical information; medical records; diagnoses; psychological and psychiatric assessments; family and social information; administrative data; financial information where applicable; and any other data to which they have access. This obligation shall remain in effect even after the contractual relationship has ended.

22.3. Processing of Personal Data

Personal data may only be processed: for the performance of contracted activities; in accordance with the Foundation’s instructions; within the purposes authorized by the Data Subject; and in compliance with the principles of Law 1581 of 2012. The use of information for personal, commercial, academic, or other unauthorized purposes is prohibited.

22.4. Access to Information

Access shall be granted only when necessary to fulfill contractual obligations, applying the principle of least privilege. Access permissions may be modified, restricted, or revoked at any time.

22.5. Use of Equipment and Systems

Independent professionals shall preferably use authorized equipment, platforms, and systems. When the use of personal devices is authorized, they must implement: username and password authentication; software updates; protection against malicious software; automatic locking; and encryption where feasible. Medical records or institutional databases may not be stored on personal devices without express authorization.

22.6. Exchange of Information

Any communication containing personal data must be carried out through authorized institutional channels. Personal email accounts, messaging applications, or unauthorized platforms must not be used unless expressly authorized by the Foundation and appropriate security measures are in place.

22.7. Retention of Information

Independent professionals may not retain copies of medical records, databases, or other information once the service has ended. Upon termination of the relationship, they must: return all information; deliver physical documents; securely delete unauthorized electronic copies; and, when requested, certify the destruction or return of the information.

22.8. Reporting of Incidents

They must immediately report any incident, including: loss of information; unauthorized access; theft or loss of devices; accidental disclosure; alteration of records; cyberattacks; and misuse of credentials.

22.9. Contractual Obligations

Contracts shall include clauses covering: data protection; confidentiality; professional secrecy; information security; processing of sensitive data; management of medical records; incident reporting; return or deletion of information; and liability for noncompliance.

22.10. Training and Compliance

The Foundation may provide guidelines, training, or instructions that independent professionals must understand and follow as a condition for carrying out their activities.

22.11. Audit and Verification

The Foundation may verify compliance through monitoring, document review, audits, or other mechanisms permitted by law and contract.

22.12. Noncompliance

Noncompliance may result in termination of the contract, without prejudice to any civil, administrative, disciplinary, or criminal actions that may apply.

Related Annex: Annex O — Confidentiality Agreement for Independent Professionals.

23. Video Surveillance

23.1. Purpose

The Foundation may implement video surveillance systems to protect people, property, infrastructure, information, and assets, as well as to support physical security, risk prevention, access control, incident investigation, and compliance with legal obligations. Images shall be processed exclusively for authorized purposes.

23.2. Scope

Video surveillance may operate in: access areas; reception; common areas; hallways; parking areas; administrative areas; and other spaces where necessary and proportionate. Cameras shall never be installed in bathrooms, changing rooms, consultation rooms during clinical care, except where required by law, justified for healthcare purposes, or expressly consented to, staff rest areas, or any location where there is a reasonable expectation of privacy.

23.3. Personal Data Processed

Images; videos; date and time of entry or presence; location within the facilities; and data associated with access control. When individuals can be identified, such information shall constitute personal data processed in accordance with Law 1581 of 2012.

23.4. Informational Notices

The Foundation shall inform individuals of the existence of video surveillance through visible notices indicating: that the premises are under video surveillance; identification of the Data Controller; the general purpose; contact channels for exercising rights; and reference to this Policy.

23.5. Access to Recordings

Recordings shall be treated as confidential. Access shall be limited to: authorized personnel; competent judicial or administrative authorities; the Data Subject appearing in the images where applicable and without affecting the rights of third parties; and other persons authorized by law. Internal controls shall be maintained over access, playback, or disclosure whenever technically possible.

23.6. Retention of Recordings

Recordings shall be retained only for as long as necessary or while a legal obligation or authority request remains in effect. Once the applicable period has expired, recordings shall be securely deleted or destroyed, unless they must be retained as evidence in investigations or proceedings.

23.7. Security Measures

Access control through authorized users; secure passwords; access logs where possible; physical protection of equipment; backups where necessary; and restrictions on playback or export of video recordings.

23.8. Rights of Data Subjects

Individuals captured by video surveillance may exercise the rights established under Law 1581 of 2012, including the rights to access, update, rectify, and request proof of processing, subject to the protection of third-party rights and applicable legal limitations.

23.9. Disclosure of Recordings

Recordings may only be provided to the Data Subject where applicable; to competent authorities upon formal request; or in compliance with a legal obligation or court order. Any disclosure shall be documented, indicating: date of the request; requester; legal basis; information provided; and responsible staff member.

23.10. Responsibilities

Authorized personnel must: maintain confidentiality; use recordings only for authorized purposes; protect equipment and devices; report incidents; and comply with this Policy and applicable instructions.

23.11. Review and Audit

The Foundation may conduct reviews to verify equipment operation, regulatory compliance, retention of recordings, authorized access, and the effectiveness of security measures.

Related Annex: Annex P — Protocol for the Processing of Personal Data through Video Surveillance Systems.

24. Website, Cookies, and Social Media

24.1. Institutional Website

The Foundation may maintain a website to provide information about its programs, services, activities, events, publications, and campaigns. Data provided through the website shall be processed in accordance with this Policy. Personal data may be collected through: contact forms; information requests; appointment or service requests; registration for events, courses, or training programs; donation forms; volunteer forms; employment forms; satisfaction surveys; newsletter subscriptions; and other services offered through the website.

24.2. Purposes of Processing

Respond to requests; manage appointments or service processes; provide information about services; manage academic, community, and social programs; administer registrations; comply with legal and contractual obligations; improve website quality; prepare internal statistics; handle PQR requests; and fulfill other purposes disclosed to the Data Subject.

24.3. Cookies

The website may use cookies and similar technologies to: facilitate browsing; remember preferences; improve the user experience; analyze browsing behavior; obtain usage statistics; and optimize website performance. Cookies shall not collect information beyond what has been authorized or permitted by law. Where required, consent shall be obtained before installing cookies that are not strictly necessary.

24.4. Cookie Management

Users may configure their browsers to accept, reject, or delete cookies. Disabling certain cookies may affect the operation of some services. The Foundation may update its cookie management technologies in accordance with technological developments and applicable regulations.

24.5. Social Media

The Foundation may maintain institutional profiles on: Facebook; Instagram; LinkedIn; YouTube; TikTok; X (formerly Twitter); and other future platforms. These channels shall be used for informational, educational, institutional, scientific, academic, mental health promotion, and comprehensive well-being purposes.

24.6. User Interaction

Data voluntarily provided through comments, messages, or forms may be processed to: respond to information requests; answer inquiries; manage service requests; invite users to events; manage prevention and promotion campaigns; improve community engagement; and comply with legal obligations. Information published by users may also be subject to the privacy policies of each platform.

24.7. Use of Images and Multimedia Content

Photographs, videos, recordings, and audiovisual materials may be published when the corresponding authorization has been obtained where required. In the case of minors, publication shall require authorization from those exercising parental authority, legal representation, or custody, while also respecting the best interests of the child. Images or clinical information that could identify users shall not be disclosed unless all applicable legal requirements have been met.

24.8. Links to Third-Party Websites, Digital Advertising, and Lead Generation

The website may contain links to third-party websites. The Foundation shall not be responsible for their privacy policies. The Foundation may run advertisements on digital platforms, including Meta (Facebook and Instagram). When an interested person clicks on an advertisement and is redirected to a channel such as WhatsApp, the Foundation shall provide, from the first contact, a brief notice referring them to this Policy and the Privacy Notice. The Foundation shall not use interactions with advertisements related to mental health programs or addiction treatment to infer, classify, or segment audiences based on their health status, unless there is a legal basis or valid authorization. Data collected through this channel shall be processed in accordance with Chapter 11.8 and Chapter 18.

24.9. Third-Party Services

The Foundation may use third-party tools for website administration, analytics, hosting, forms, videoconferencing, institutional email, or other services. When such third parties have access to personal data, the Foundation shall verify compliance with applicable legislation and implement the corresponding contractual and security measures.

24.10. Information Security

Technical, administrative, and organizational measures shall be implemented to protect information collected through the website and social media against unauthorized access, alteration, disclosure, loss, destruction, and misuse.

24.11. Exercise of Rights

Data Subjects may exercise their rights regarding information collected through the website or social media by using the Foundation’s official channels.

24.12. Technological Updates

The Foundation may modify the operation of the website, incorporate new tools, implement new channels, or update its data processing mechanisms. When such changes are substantial, this Policy shall be updated.

Related Annex: Annex Q — Cookies and Digital Media Policy.

25. Validity

This Personal Data Processing Policy of the FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL shall enter into force as of XX July 2026, the date of its approval by the Legal Representative, and shall remain in effect for as long as the Foundation carries out activities involving the processing of personal data and until it is amended or replaced by a new version.

The Foundation may update, amend, or supplement this Policy when:

  • Changes occur in the applicable personal data protection legislation.

  • The Superintendence of Industry and Commerce or any other competent authority issues new regulations or guidelines.

  • New processes, services, technologies, or data collection and processing channels are implemented.

  • Opportunities for improvement are identified through audits, internal reviews, or risk management activities.

  • Changes occur in the Foundation’s organizational structure or activities.

Any amendment shall be approved by the Legal Representative or the corresponding authority, incorporated into the document’s version control, and communicated to Data Subjects when required by the nature of the changes, through the available institutional channels.

Databases managed by the Foundation shall be retained for as long as necessary to fulfill the purposes of processing, comply with legal, contractual, accounting, tax, healthcare, and archival obligations, and protect the Foundation’s interests, in accordance with applicable law and the Personal Data Retention Matrix (Annex L).

Approval Clause

Approved by: Legal Representative, FUNDACIÓN FUNCIÓN FUTURO DEL SANCTI SPIRITU INTELIGENCIA ESPIRITUAL.
Approval Date: XX July 2026.