Policy for the Treatment of Personal Data

This policy is issued in compliance with Law 1581 of 2012, Decree 1377 of 2013, Law 1266 of 2008, and regulations that modify or add to the regime for the protection of personal data. It aims to ensure that NAAK S.A.S., as the controller of personal information, processes it in strict compliance with applicable regulations, guaranteeing the rights of the data subjects. Personal data will be used solely for the purposes for which the organization is authorized, especially those indicated in the section "Treatment of data and its purpose" of this policy and based on the law and current regulations.

  1. Identification data of the data controller: • Name: NAAK S.A.S.
    • Name: NAAK S.A.S.
    • Address: Calle 30 # 4 A-45 Edificio Forever W&L Oficina: 506; Medellín, Colombia
    • Phone: +573202322680
    • Email: customers@devierparfums.com
    • Website: www.devierparfums.com
  2. Definitions: To complying with and executing the procedures established in this policy, the following definitions apply:
    • Authorization: The prior, express, and informed consent of the data subject to process personal data.
    • Privacy Notice: Verbal or written communication generated by the controller, addressed to the data subject for the processing of their personal data. It informs the data subject about the existence of the information processing policies that will apply, how to access them, and the purposes of the data processing.
    • Database: An organized set of personal data that is subject to processing.
    • Personal Data: Any information linked to or that can be associated with one or more identified or identifiable natural persons.
    • Public Data: Data that is not semi-private, private, or sensitive. Public data includes, among others, information related to the civil status of individuals, their profession, trade, and their status as a merchant or public servant. By their nature, public data can be found in public records, public documents, official gazettes, and court judgments that are not subject to confidentiality.
    • Sensitive Data: Sensitive data refers to information that affects the privacy of the data subject or whose misuse could lead to discrimination, such as data that reveals racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in unions, social organizations, human rights organizations, and guarantees of opposition political parties, as well as data related to health, sexual life, and biometric data.
    • Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.
    • Data Processor: A natural or legal person, public or private, that, either on their own or in association with others, processes personal data on behalf of the data controller.
    • Data Controller: A natural or legal person, public or private, that, either on their own or in association with others, makes decisions about the database or the processing of data.
    • Data Subject: A natural person whose personal data is subject to processing.
    • Information: Refers to an organized set of data contained in any document generated, obtained, acquired, transformed, or controlled by the data controller and processor.
  3. Principies: In accordance with the law, NAAK S.A.S. will act in all data collection, handling, and deletion in accordance with the principles that must be followed in all processing of personal data and the protection of the right to habeas data. These principles are:
    • Legality: The processing of personal data will adhere to what is established in the law and other provisions.
    • Purpose: The data subject will be informed of the purpose of the data processing, which must be legitimate according to the constitution and the law.
    • Freedom: The processing of personal data will only be carried out by NAAK S.A.S. with the prior, express, and informed consent of the data subject, or by legal or judicial mandate.
    • Truth or Quality: The information subject to processing of personal data must be truthful, complete, accurate, up-to-date, verifiable, and comprehensible. Processing of partial, incomplete, fragmented, or misleading data is prohibited.
    • Transparency: NAAK S.A.S. guarantees the data subject the right to obtain information at any time and without restrictions regarding the existence of their data.
    • Access and Restricted Circulation: The processing of personal data will comply with the provisions established by law and the Constitution. Personal data shall not be available on the internet or in other means of disclosure or mass communication, except for data of a public nature or data for which access can be technically controlled to provide limited knowledge to the data subject or authorized third parties.
    • Security: The information subject to processing will be protected through technical, human, and administrative measures that provide security to the records, preventing their alteration, loss, consultation, use, or unauthorized or fraudulent access.
    • Confidentiality: Persons involved in the processing of personal data that do not have a public nature are obligated to ensure the confidentiality of the information provided. This obligation remains in place even after the completion of the tasks related to processing.
  4. Processing of Data and its Purpose: The data will be used by NAAK S.A.S. for the development of its social purpose and the contractual relationship, if applicable, with the data subject. Personal data is collected, stored, organized, used, circulated, transmitted, transferred, updated, corrected, deleted, and managed in accordance with the purpose or purposes of each type of processing.
    • 4.1. WEB PAGE DATA PROCESSING: The following are the obligations, duties, minimum practices, and warnings that should guide the conduct of users on the website:
      • The user agrees to provide NAAK S.A.S. with true and complete information about themselves. Additionally, the user commits to keeping this information up to date.
      • NAAK S.A.S. reserves the right to withdraw the user without prior notice if the information is considered harmful or detrimental.
      • NAAK S.A.S. is not responsible for the use that third parties may make of information that is inadequately secured and protected by the user.
      • The user will not collect or disclose the personal data or information of other users of NAAK S.A.S.'s website.
      • The provision of false information or the omission of any obligation gives NAAK S.A.S. the right to terminate the provision of services to the user automatically, without prior notice, and definitively.
    • By using the website or providing personal information, you authorize us to obtain, use, and disclose your personal information as described in this policy.
    • 4.1.1. GENERAL ASPECTS OF THE WEBSITE: The following are the general aspects that guide the privacy policy of the website:
      • This website, its information, and content are publicly available. Therefore, acceptance of this privacy policy is a mandatory condition for access and use.
      • This policy may be modified in the future, so users should periodically review its content.
    • 4.1.2. INFORMATION COLLECTED: The website may collect personal information, such as names, contact information (email, phone number), and other personal information provided voluntarily by the user.
    • 4.1.3. USE OF INFORMATION: Information collected may be used for the following purposes:
      • Responding to user requests
      • Providing information about products or services
      • Internal record keeping
      • Improving products and services
      • Marketing purposes
      • Conducting market research
    • 4.1.4. SECURITY: NAAK S.A.S. is committed to ensuring that user information is secure. To prevent unauthorized access or disclosure, we have implemented suitable physical, electronic, and managerial procedures to safeguard and secure the information we collect online.
    • 4.1.5. LINKS TO OTHER WEBSITES: The website may contain links to other websites of interest. However, once the user has used these links to leave our site, they should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information that users provide while visiting such sites, and such sites are not governed by this privacy statement. Users should exercise caution and review the privacy statement applicable to the website in question.
    • 4.2. DATA PROCESSING RELATED TO BUSINESS RELATIONSHIPS: If a business relationship is established between the data subject and NAAK S.A.S., the personal data that the latter provides will be processed as necessary for the development of the contractual relationship. Such processing may include:
      • Registering the data in the customer database
      • Providing information about products or services
      • Responding to inquiries or requests
    • 4.3. JOB APPLICANT DATA PROCESSING: If the data subject is applying for a job at NAAK S.A.S., their personal data will be processed as necessary for evaluating and managing the job application process. This may include:
      • Assessing the candidate's qualifications
      • Communicating with the candidate
      • Managing the recruitment process
    • 4.4. CONTACT DATA PROCESSING: If the data subject contacts NAAK S.A.S. through various communication channels (e.g., email, phone, social media), the personal data provided will be processed to respond to inquiries, comments, or requests.
    • 4.5. OTHER DATA PROCESSING PURPOSES: NAAK S.A.S. may process personal data for other legitimate purposes. In such cases, the data subject will be informed of the purpose at the time of data collection or processing.
  5. Rights of Data Subjects: Data subjects have the following rights in relation to their personal data:
    • Right to know, update, and rectify personal data: Data subjects have the right to access, update, and correct their personal data.
    • Right to delete personal data: Data subjects can request the deletion of their personal data when it is no longer necessary for the purposes for which it was collected.
    • Right to revoke authorization: Data subjects can revoke their authorization for the processing of their personal data.
    • Right to information: Data subjects have the right to obtain information about the use of their personal data.
    • Right to file complaints: Data subjects can file complaints with the competent authority.
    • Right to access: Data subjects have the right to obtain information about the personal data stored by NAAK S.A.S.
    • Right to be informed of data processing: Data subjects have the right to be informed about how their personal data is processed and the purpose of the processing.
  6. Duties and Obligations: In accordance with current regulations, NAAK S.A.S. undertakes to comply with the following duties and obligations:
    • Adopt a security manual and establish procedures to guarantee the protection of data.
    • Maintain the database for the purpose for which it was authorized and avoid its alteration by third parties.
    • Make the personal data available to the data subject, guaranteeing that only the data subject has access to their data.
    • Keep the information up to date to ensure its accuracy.
    • Ensure that the information is complete and accurate.
    • Correct the information when required.
    • Keep a copy of the authorization for data processing.
    • Register in its database any corrections made to the personal data.
    • Keep proof of the authorizations granted by the data subjects for data processing.
    • Manage inquiries and complaints made by data subjects concerning the processing of their data.
    • Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.
  7. Data Transfer: NAAK S.A.S. may share personal data with third parties under the following circumstances:
    • With the data subject's consent
    • To comply with legal obligations or requests from competent authorities
    • To protect our rights, privacy, safety, or property, and that of our affiliates, customers, or others
    • To conduct investigations of potential violations of our policies
    • In the event of the sale, acquisition, or merger of some or all of our assets.
  8. Data Protection Officer: NAAK S.A.S. will appoint a Data Protection Officer (DPO) responsible for ensuring compliance with data protection regulations. The DPO can be contacted at customers@devierparfums.com.
  9. Complaints and Inquiries: Data subjects can contact NAAK S.A.S. to exercise their rights, file complaints, or make inquiries about data processing by using the following contact information:
    • Name: NAAK S.A.S.
    • Address: Calle 30 # 4 A-45 Edificio Forever W&L Oficina: 506; Medellín, Colombia
    • Phone: +573202322680
    • Email: customers@devierparfums.com
    • Website: www.devierparfums.com
  10. Updates and Amendments: NAAK S.A.S. reserves the right to modify this policy to adapt it to new legal or jurisprudential developments, as well as to industry practices. In such cases, NAAK S.A.S. will announce changes on its website and will update the "Effective Date" at the beginning of the policy.

Effective Date: October 26, 2023