DOCUMENT CONTROL
Identification
| Field | Detail |
|---|---|
| Document | MLD-04 — Personal Data Processing and Protection Policy |
| Master document | VHG Group Digital Legal Framework (MLD-VHG) |
| Issuing entity | Valencia Holding Group — Parent Company |
| Legal nature | Information Processing Policy (política de tratamiento de la información) under Article 2.2.2.25.3.1 of Colombian Decree 1074 of 2015 |
| Related instruments | MLD-01 (Terms), MLD-02 (Privacy Notice), MLD-03 (Cookie Notice) |
| Version | 2.0 |
| Effective date | 1 October 2026 |
| Material scope | All personal databases of the VHG Group, digital and non-digital |
| Validity of databases | For as long as the declared purposes and statutory retention periods subsist (Annex D) |
| Governing language | Spanish |
| Status | In force |
Version history
| Version | Date | Description | Status |
|---|---|---|---|
| 1.0 to 1.1 | July to September 2026 | Internal working versions. Not published. | Superseded |
| 2.0 | 1 October 2026 | First published version. Completion of controller identification, single contact channel, alignment of the governing law with the State of Delaware, trademark regime pending registration, and effectiveness with ordinary annual review. | In force |
Regulatory traceability convention
| Category | Meaning | Treatment |
|---|---|---|
| Mandatory rule | Public-policy provision of compulsory application | No derogation permitted |
| Group standard | Rule adopted by VHG above the statutory minimum | Binding on all adhering entities |
| Operational parameter | Time limit, threshold or procedure defined by the Group | Reviewable in the annual update |
| Deployment variable | The single field completed at the time of publication | Marked as 1 October 2026 |
Use notice
Document subject to mandatory adoption. This Policy is the instrument that Colombian law requires of every data controller and cannot be replaced by the Privacy Notice. Its formal adoption by each adhering entity, through a Deed of Adhesion, is a condition for the lawful operation of its databases. Non-compliance exposes the entity to the sanctions in Article 23 of Law 1581 of 2012.
CONTENTS
- Purpose, scope and group architecture
- Identification of the controller and governance structure
- Definitions
- Governing principles
- Data classification and special regimes
- Databases and purposes of processing
- Authorisation regime
- Data subject rights
- Duties of the VHG Group
- Procedure for handling enquiries and complaints
- Data processors and the supplier chain
- Data circulation within the VHG Group
- International transfers and transmissions
- Information security
- Security incident management
- National Database Register
- Retention, deletion and anonymisation
- Demonstrated accountability
- Special processing activities
- Sanctions regime and consequences of non-compliance
- Jurisdictional supplements
- Effectiveness, updating and regulatory monitoring
- Annexes and contact channels
1. Purpose, scope and group architecture
A processing policy is not a declaratory document but the instrument that legally organises the relationship between the Group and the persons whose data it administers. Its effectiveness depends on precisely delimiting what it covers, who applies it, and how it articulates with the Group's corporate structure.
1.1 Purpose
This Policy establishes the principles, criteria, procedures, safeguards and responsibilities governing the processing of personal data by Valencia Holding Group ("VHG" or the "Parent Company") and by the entities adhering to the VHG Group Digital Legal Framework (the "Adhering Entities" and, together, the "VHG Group").
It is adopted in compliance with Article 15 of the Political Constitution of Colombia, Law 1581 of 2012, Decree 1074 of 2015 — which consolidated Decree 1377 of 2013 — and concordant provisions, as well as the rules applicable in the other jurisdictions in which the Group operates.
1.2 Material scope
This Policy covers all personal databases of the VHG Group, irrespective of their medium, format or collection channel. It includes, without limitation:
● Databases fed by digital platforms, portals, applications and online forms. ● Databases arising from contracting with clients, investors, suppliers and contractors. ● Human resources databases, including candidates, employees and former employees. ● Due diligence and counterparty knowledge records. ● Physical, documentary and contractual files. ● Video surveillance and access control systems. ● Communications and customer service records.
This delimitation expressly corrects the exclusively digital scope of earlier instruments.
1.3 Subjective scope
Bound entities. VHG and every Adhering Entity. These include, among others, Valencia Capital Group (VCG) and Valencia Investment Group (VIG), as well as any other affiliate, subsidiary, company, brand or business unit that may in future join the Group, be incorporated by it or come under its direct or indirect control. This list is illustrative and not exhaustive: a new entity joins by executing the Deed of Adhesion under section 1.4, without any need to amend this Policy.
Data subjects covered. Any natural person whose data is processed by the VHG Group: platform users and visitors; current and prospective clients; investors and prospective investors; commercial counterparties; suppliers, contractors and their personnel; candidates and employees; and legal representatives, ultimate beneficial owners and contact persons of legal entities with which the Group deals.
Bound personnel. Directors, legal representatives, employees, contractors and third parties accessing personal data under the responsibility of the VHG Group, whose non-compliance shall give rise to the consequences set out in section 20.2.
1.4 Group architecture and adhesion
Valencia Holding Group is the Parent Company and the issuing unit of this Policy. It defines the mandatory minimum data protection standard for the entire Group and exercises coordination, verification and reporting functions through the Group Data Protection Office.
Each Adhering Entity is an autonomous Data Controller in respect of the databases whose purposes and means it determines. Adhesion creates no commingling of assets, no automatic joint controllership and no transfer of controller status to the Parent Company.
Adhesion is effected through a Deed of Adhesion in the form of Annex E, with the effects set out in section 2.2 of instrument MLD-01. As a condition of adhesion, each Adhering Entity must:
First. Complete and publish its Annex A — Identification Sheet.
Second. Formally designate its Data Protection Area and its contact point for the exercise of rights.
Third. Prepare and maintain its Annex D — Register of Databases, Purposes and Retention.
Fourth. Register its databases in the National Database Register where required under section 16.
Fifth. Execute Annex F — Intragroup Personal Data Transmission Master Agreement.
Power to supplement. Each Adhering Entity may issue its own supplements that raise the standard of this Policy, having regard to its activity, its regulated sector or its jurisdiction. No supplement may reduce, contradict or derogate from it.
1.5 Territorial scope and order of precedence
Under Article 2 of Law 1581 of 2012, the Colombian regime applies to processing carried out in Colombian territory and to controllers or processors not domiciled in Colombia to whom Colombian law applies by virtue of international rules and treaties.
The order of precedence, from which no derogation is permitted, is as follows:
| Order | Source |
|---|---|
| 1 | Mandatory and public-policy rules of the data subject's jurisdiction |
| 2 | Applicable Jurisdictional Supplement (Annex B and section 21) |
| 3 | Adhering Entity supplement, where it raises the standard |
| 4 | This Policy (MLD-04) |
2. Identification of the controller and governance structure
The law requires that data subjects know precisely against whom they exercise their rights. This section satisfies that requirement and also defines the internal structure that makes the Policy operational.
2.1 Identification of the controller
| Field | Detail |
|---|---|
| Corporate name | Valencia Holding Group LLC |
| NIT / RUC / EIN | Withheld from publication. Recorded in Annex A and disclosed to any authority so requiring |
| Principal domicile | Delaware, United States of America |
| Physical address for service | Delaware, United States of America. Designated formal channel for service: info@vhg.capital |
| Email address for the exercise of rights | info@vhg.capital |
| Telephone | Not published. Single contact channel: info@vhg.capital |
| Website | https://vhg.capital |
The full identification of each Adhering Entity is set out in Annex A.
2.2 Area responsible for handling requests, enquiries and complaints
In compliance with Article 2.2.2.25.3.1(d) of Decree 1074 of 2015, the following area is designated as responsible for handling requests, enquiries and complaints before which data subjects may exercise their rights:
| Field | Detail |
|---|---|
| Name of the area | VHG Group Data Protection Office |
| Email address | info@vhg.capital |
| Physical address | Delaware, United States of America |
| Telephone | Not published. Single contact channel: info@vhg.capital |
| Service hours | Permanent electronic intake. Response within the statutory periods, counted in business days |
2.3 Group Data Protection Office
VHG designates a Group Data Protection Office (DPO) with the following functions:
● To maintain, interpret and update the Digital Legal Framework. ● To coordinate and verify implementation of this Policy across the Adhering Entities. ● To advise on impact assessments for high-risk processing. ● To consolidate incident reporting and act as interlocutor with supervisory authorities. ● To present an annual compliance report to the highest management body. ● To approve Adhering Entity supplements.
The DPO exercises its functions with functional independence and may not receive instructions that compromise its technical judgment. Its identification is set out in Annex A.
2.4 Data Protection and Information Governance Committee
A Committee is constituted with participation from the DPO, legal, technology, compliance and risk functions, meeting at least twice a year, responsible for reviewing the state of compliance, materialised incidents, identified gaps and the remediation plan.
3. Definitions
For the purposes of this Policy, the definitions in Article 3 of Law 1581 of 2012 and Article 2.2.2.25.1.3 of Decree 1074 of 2015 are adopted:
Authorisation. The data subject's prior, express and informed consent to the processing of their personal data.
Privacy notice. Verbal or written communication addressed to the data subject informing them of the existence of the processing policies, how to access them, and the purposes of processing.
Database. An organised set of personal data subject to processing.
Personal data. Any information linked to, or capable of being associated with, one or more identified or identifiable natural persons.
Public data. Data that is not semi-private, private or sensitive, such as data relating to civil status, profession or occupation and status as a merchant or public servant, and data contained in public documents, final judgments and public registers.
Semi-private data. Data that is neither intimate nor public in nature and whose knowledge is of interest to the data subject and to a specific group of persons.
Private data. Data of an intimate or restricted nature of interest only to its data subject.
Sensitive data. Data affecting the data subject's privacy or whose misuse may give rise to discrimination.
Data processor. A person who processes personal data on behalf of the controller.
Data controller. A person who decides on the database and on the processing of the data.
Data subject. The natural person whose personal data is processed.
Transfer. The sending of data to a recipient that is itself a controller, located inside or outside the country.
Transmission. The communication of data to a processor so that the latter may process it on behalf of the controller.
Processing. Any operation on personal data, such as collection, storage, use, circulation or deletion.
Security incident. An event compromising the confidentiality, integrity or availability of personal data.
4. Governing principles
The processing of personal data by the VHG Group is subject to the principles set out in Article 4 of Law 1581 of 2012, which operate as criteria for the interpretation of the entire Policy:
Lawfulness. Processing is a regulated activity that must comply with the law and its implementing provisions.
Purpose limitation. Processing serves a legitimate, specified purpose previously communicated to the data subject. No database is used for purposes other than those declared in Annex D.
Freedom. Processing is carried out only with the data subject's prior, express and informed consent. Data is neither obtained nor disclosed without authorisation, save under a legal or judicial mandate.
Accuracy or quality. Information is truthful, complete, exact, current, verifiable and comprehensible. The processing of partial, incomplete, fragmented or misleading data is prohibited.
Transparency. Data subjects are guaranteed the right to obtain, at any time and without restriction, information about the existence of data concerning them.
Restricted access and circulation. Processing is subject to the limits deriving from the nature of the data. Personal data other than public information may not be made available through mass dissemination media unless access is technically controllable.
Security. Information is handled with the technical, human and administrative measures necessary to secure records, preventing their alteration, loss, or unauthorised or fraudulent consultation, use or access.
Confidentiality. All persons involved in processing are obliged to maintain the confidentiality of the information, an obligation that subsists even after their relationship with the Group has ended.
Demonstrated accountability. As an additional Group standard, compliance is not declared: it is documented, measured and evidenced to the data subject and to the authority, in accordance with section 18.
5. Data classification and special regimes
Not all data admits the same treatment. Classification determines the level of authorisation required, the applicable security measures and the limits on circulation, and is therefore the operational starting point for every decision concerning data.
5.1 General classification
Under Law 1581 of 2012 and Constitutional Court Judgment C-748 of 2011, data is classified as public, semi-private, private and sensitive, with increasing levels of protection and restriction on circulation.
5.2 Sensitive data
Rule. The processing of sensitive data is prohibited, save in the cases set out in Article 6 of Law 1581 of 2012: where the data subject has given explicit authorisation, unless the law does not require it; where processing is necessary to safeguard the vital interest of a data subject who is physically or legally incapacitated; where processing is carried out in the course of legitimate activities by a foundation, NGO, association or other non-profit body with a political, philosophical, religious or trade union purpose, in respect of its members; where the data is necessary for the recognition, exercise or defence of a right in judicial proceedings; or where processing has a historical, statistical or scientific purpose and identity-suppression measures are adopted.
Additional safeguards. Where the VHG Group needs to process sensitive data, it shall:
● Inform the data subject that the data is sensitive and of the specific purpose. ● Obtain explicit authorisation, separate from the general authorisation. ● Expressly inform the data subject that they are not obliged to authorise the processing of sensitive data or to answer questions about it. ● Apply enhanced access controls, encryption and distinct audit logging. ● Refrain from conditioning any activity on the provision of sensitive data, save under a legal mandate.
5.3 Children's and adolescents' data
The processing of minors' data is prohibited, save where the data is of a public nature and the processing meets the parameters of Article 2.2.2.25.2.9 of Decree 1074 of 2015: responding to and respecting the best interests of the child, and ensuring respect for their fundamental rights.
The VHG Group:
● Does not direct its platforms or products to minors. ● Requires the authorisation of the legal representative, having taken account of the minor's views where their maturity permits. ● Immediately deletes minors' data collected inadvertently. ● Refrains from profiling or advertising directed at minors.
5.4 Financial and credit data
Where an Adhering Entity administers, reports or consults financial, credit, commercial or service information with information operators, such processing is additionally governed by Law 1266 of 2008 and its implementing rules, with the safeguards specific to that regime — prior notice before an adverse report, right of defence, information retention periods and lapse of adverse data.
Clarification. Law 1266 of 2008 governs financial and credit habeas data; the general personal data protection regime is that of Law 1581 of 2012. The two regimes are concurrent and do not replace one another. This clarification corrects the generic reference to the "Habeas Data Law" used in earlier versions of the Framework.
5.5 Data of legal entities
Data of legal entities is not personal data. However, data of their legal representatives, directors, ultimate beneficial owners, individual shareholders and contact personnel is personal data and is fully subject to this Policy.
6. Databases and purposes of processing
6.1 Register of databases
Each Adhering Entity prepares and keeps current Annex D — Register of Databases, Purposes and Retention, with the following minimum structure:
| Database | Categories of data subjects | Categories of data | Purposes | Lawful basis | Processors | Transfers | Retention period | Security measures |
|---|---|---|---|---|---|---|---|---|
| Web contacts and enquiries | Visitors and contacts | Identification, contact details and message content | Handling enquiries and relationship management | Data subject authorisation | Hosting and email provider | United States | Two (2) years from the last interaction | Encryption in transit and at rest; access control |
| Suppliers and contractors | Counterparty personnel | Identification, contact and contractual data | Contract performance and regulatory compliance | Authorisation and contract performance | Legal, accounting and audit advisers | Colombia and United States | Limitation period for contractual actions | Access control and audit logging |
| Talent management | Employment candidates | Identification, contact details and professional background | Candidate selection and assessment | Data subject authorisation | Not applicable | Colombia | Twelve (12) months from the close of the process | Restricted access control |
Annex D is updated at least annually and whenever a database is created, a purpose is modified or a new processor is engaged.
6.2 Declared purposes
The VHG Group processes personal data exclusively for the purposes declared in section 5 of instrument MLD-02, which are incorporated here in full: relationship management; contract performance; regulatory compliance, including anti-money-laundering and counter-terrorist-financing; risk management and security; corporate governance; platform improvement; institutional and commercial communications subject to specific authorisation; and talent management.
Prohibition on undeclared secondary purposes. No Group entity may use personal data for purposes other than, or incompatible with, those declared. Adding a new purpose requires updating Annex D, prior communication to the data subject and fresh authorisation.
7. Authorisation regime
Authorisation is the cornerstone of the Colombian data protection system and the point at which non-compliance most frequently materialises. This section sets out its regime without reference to foreign standards that Colombian law does not recognise.
7.1 Requirements
Authorisation must be prior to collection, express — manifested through unequivocal conduct — and informed, that is, preceded by communication to the data subject of the controller's identity, the purposes of processing, the optional nature of answering questions about sensitive data or minors' data, their rights, and how to access this Policy.
7.2 Absence of legitimate interest as an autonomous basis
Mandatory rule. Colombian law does not recognise "legitimate interest" as an autonomous lawful basis for processing. The only cases in which authorisation is not required are those exhaustively listed in Article 10 of Law 1581 of 2012: (i) information required by a public or administrative body in the exercise of its statutory functions or by court order; (ii) data of a public nature; (iii) medical or health emergencies; (iv) processing authorised by law for historical, statistical or scientific purposes; and (v) data relating to the Civil Registry of Persons. No Group entity may invoke legitimate interest as the basis for processing subject to Colombian law.
7.3 Manner of obtaining and evidence
Authorisation is obtained by means permitting subsequent consultation: a physical document, an electronic signature, an unchecked verification box, an acceptance button, a voice recording with prior warning, or unequivocal conduct of the data subject reasonably permitting the conclusion that authorisation was granted.
The VHG Group retains evidence of authorisation as required by Article 9 of Law 1581 of 2012, recording the date, time, channel, version of the text disclosed and technical traces. This record is retained throughout the processing and, at a minimum, for five (5) years after its termination.
The following do not constitute authorisation: silence, inactivity, pre-ticked boxes, continued browsing or continued use of a service.
7.4 Authorisation for data collected before this Policy took effect
In respect of previously collected data, the VHG Group shall conduct the authorisation request process set out in Article 2.2.2.25.2.4 of Decree 1074 of 2015, using efficient means of communication with the data subject. If, thirty (30) business days after the communication, the data subject has not objected and has continued using the services, authorisation shall be deemed to subsist; otherwise, the data shall be deleted.
7.5 Withdrawal and requests for deletion
Data subjects may withdraw authorisation and request deletion of their data at any time, free of charge, in whole or in part in respect of specific purposes.
Deletion does not proceed where the data subject is under a legal or contractual duty to remain in the database, or where deletion would obstruct judicial or administrative proceedings relating to tax obligations, the investigation of offences or the updating of administrative sanctions. In such cases, the refusal shall be communicated to the data subject with reasons within the time limits in section 10.
8. Data subject rights
Under Article 8 of Law 1581 of 2012, data subjects have the right to: know, update and rectify their data; request evidence of the authorisation granted; be informed of the use made of their data; lodge complaints with the Superintendency of Industry and Commerce once the procedure before the controller has been exhausted; withdraw authorisation and request deletion where applicable; and access their data free of charge.
Standing. These rights may be exercised by the data subject; by their successors, who must evidence that status; by the data subject's representative or attorney-in-fact; and under a stipulation in favour of a third party. Minors' rights shall be exercised by the person empowered to represent them.
Proof of identity. The VHG Group shall verify the applicant's identity through proportionate mechanisms, refraining from requesting excessive information or collecting additional data on the occasion of the request.
9. Duties of the VHG Group
9.1 As controller
Under Article 17 of Law 1581 of 2012, the VHG Group must: guarantee the data subject full exercise of habeas data; request and retain a copy of the authorisation; duly inform the data subject of the purpose and of their rights; keep the information under conditions of security; ensure the information is truthful, complete, exact, current, verifiable and comprehensible; update and rectify the information; supply the processor only with data whose processing has been authorised; require the processor to observe security and privacy conditions; handle enquiries and complaints; adopt an internal manual of policies and procedures; inform the processor where information is under dispute; inform the data subject, on request, of the use made of their data; and inform the data protection authority where breaches of security codes occur and risks arise in the administration of information.
9.2 As processor
Where a Group entity acts as processor on behalf of a third party, it shall observe the duties in Article 18 of Law 1581 of 2012, in particular processing data only in accordance with the controller's instructions and refraining from using it for its own purposes.
10. Procedure for handling enquiries and complaints
A right without a defined procedure is unenforceable. This section adopts the statutory procedure and time limits expressly and verifiably, and constitutes the mandatory minimum standard for every Adhering Entity.
10.1 Channels
Requests are submitted through the channels in section 23.2, stating: the data subject's name and identification; the capacity in which they act and evidence of standing where applicable; a precise description of the request; a physical or electronic address for service; and supporting documents.
10.2 Enquiries
Time limit: ten (10) business days from the date of receipt. Where the enquiry cannot be answered within that period, the interested party shall be informed before its expiry, stating the reasons and the date on which it will be answered, which may not exceed five (5) business days following expiry of the first period. (Article 14, Law 1581 of 2012.)
10.3 Complaints
Time limit: fifteen (15) business days from the day following receipt. Where the complaint cannot be handled within that period, the interested party shall be informed of the reasons for the delay and of the response date, which may not exceed eight (8) business days following expiry of the first period. (Article 15, Law 1581 of 2012.)
| Situation | Action | Time limit |
|---|---|---|
| Incomplete complaint | Request to the interested party to remedy | 5 days from receipt |
| Interested party fails to remedy | Complaint deemed withdrawn | 2 months from the request |
| Entity not competent | Referral to the competent party and notice to the interested party | 2 business days |
| Complaint pending | Inclusion of the legend "complaint pending" and its subject matter in the database | 2 business days |
10.4 Procedural prerequisite
Under Article 16 of Law 1581 of 2012, a data subject may lodge a complaint with the Superintendency of Industry and Commerce only once the enquiry or complaint procedure before the controller or processor has been exhausted.
10.5 Record and traceability
Each Adhering Entity maintains a register of requests with a unique reference, date and time of receipt, intake channel, type of request, response date, the substance of the decision and evidence of notification. This register feeds the DPO's annual report and serves as evidence before the authority.
Special rule arising from the single channel. The VHG Group operates a single contact mailbox (info@vhg.capital). Traceability is therefore provided not by the email address but by the procedure: every incoming communication is classified upon receipt as an enquiry, a complaint, a withdrawal request, legal service, an incident report or general correspondence, and those constituting an exercise of rights are immediately entered in the register, triggering the running of statutory periods. Incorrect or late classification of a request neither suspends nor interrupts the periods in sections 10.2 and 10.3.
10.6 No charge
The exercise of rights is free of charge. No payment shall be required and handling shall not be conditioned on any consideration. Information may be supplied by any means, including electronic means, requested by the data subject.
11. Data processors and the supplier chain
The risk of a processing activity does not stop at the boundaries of the organisation: it extends to the entire supplier chain that accesses the data. Its contractual governance is therefore an integral part of the security duty.
11.1 Prior due diligence
Before engaging a processor, the Adhering Entity assesses its technical and organisational security conditions, its location and that of its subcontractors, its certifications, its incident history and its mechanisms for handling data subject rights. The assessment is documented.
11.2 Transmission agreement
Every transmission to a processor is documented in an agreement which, under Article 2.2.2.25.5.2 of Decree 1074 of 2015, must contain at least: the scope and purposes of the processing; the activities the processor will carry out on behalf of the controller; the processor's obligations to the data subject and to the controller; the duty to process data in accordance with the authorised purpose and applicable law; the duty to safeguard the security of the databases; the duty of confidentiality; and the return or deletion of data at the end of the relationship.
11.3 Sub-processors
The processor may not subcontract processing without the controller's prior written authorisation. Authorisation is conditioned on the sub-processor assuming equivalent obligations and on the processor retaining responsibility towards the controller.
11.4 Audit
The controller reserves the right to audit the processor, directly or through an independent third party, on reasonable notice and without disrupting operations.
12. Data circulation within the VHG Group
Membership of the same corporate group does not, on its own, permit the free flow of data between its entities. Each flow requires legal characterisation and its own basis.
12.1 Characterisation of the flow
Transmission. Where a Group entity processes data on behalf of another, following its instructions and without determining its own purposes, it acts as a processor. The flow is governed by the agreement in section 11.2 and requires no additional authorisation from the data subject, provided the purpose has been declared.
Transfer. Where the receiving entity determines its own purposes, it acts as an independent controller. The flow constitutes a transfer and requires the data subject's authorisation, disclosed at the time of collection or requested subsequently.
12.2 Intragroup Master Agreement
VHG and the Adhering Entities execute Annex F — Intragroup Personal Data Transmission Master Agreement, which documents the flows, characterises each entity's position, defines the permissible purposes, establishes common security measures and governs the handling of rights requests where a data subject approaches an entity other than the controller.
12.3 Single point of entry
Data subjects may exercise their rights before any VHG Group entity. The entity receiving the request shall refer it to the controller within two (2) business days and inform the data subject accordingly, without the internal referral affecting the statutory response periods owed to the data subject.
13. International transfers and transmissions
13.1 Applicable regime
Mandatory rule. Article 26 of Law 1581 of 2012 prohibits the transfer of personal data to countries that do not provide adequate levels of protection, meaning those meeting the standards set by the Superintendency of Industry and Commerce. The prohibition does not apply where: the data subject has given express and unequivocal authorisation; the transfer concerns the exchange of medical data required for the data subject's treatment on grounds of health or public hygiene; the transfer concerns banking or stock-exchange transfers under the applicable legislation; the transfer has been agreed in an international treaty to which Colombia is a party; the transfer is necessary for the performance of a contract between the data subject and the controller or for pre-contractual measures, provided authorisation exists; or the transfer is legally required to safeguard the public interest or for the recognition, exercise or defence of a right in judicial proceedings.
13.2 Countries with an adequate level of protection
Under External Circular 005 of 2017 of the Superintendency of Industry and Commerce, the following countries, among others, are declared to provide an adequate level of protection: Germany, Austria, Belgium, Bulgaria, Cyprus, Costa Rica, Croatia, Denmark, Slovakia, Slovenia, Spain, the United States of America, Estonia, Finland, France, Greece, Hungary, Ireland, Iceland, Italy, Latvia, Lithuania, Luxembourg, Malta, Mexico, Norway, the Netherlands, Peru, Poland, Portugal, the United Kingdom, the Czech Republic, the Republic of Korea, Romania, Serbia and Sweden, as well as countries declared adequate by the European Commission.
Current processing destinations. As at the publication date of this Policy, the VHG Group's only processing destinations are Colombia and the United States of America, the latter declared to provide an adequate level of protection by External Circular 005 of 2017. The Group carries out no transfers or transmissions to jurisdictions not declared adequate, including Panama, which does not appear on that list.
Activation rule. Before enabling any flow to a destination not declared adequate, the Group Data Protection Office must verify and document its basis, which may only be: (i) the data subject's express and unequivocal authorisation, specifically informed as to the destination; (ii) a declaration of conformity issued by the Superintendency of Industry and Commerce; or (iii) one of the exceptions in Article 26 of Law 1581 of 2012. No such flow may commence without that prior verification.
13.3 Periodic verification
The list of countries with an adequate level of protection is dynamic. The DPO verifies its currency at least annually and upon any pronouncement by the authority, updating Annex D accordingly.
13.4 Contractual safeguards
Irrespective of the adequacy status of the destination, every international transfer or transmission is documented with clauses imposing on the recipient obligations equivalent to those in this Policy as regards purpose, security, confidentiality, handling of rights, incident notification and return or deletion.
13.5 Declaration of conformity
Where a flow cannot rely on a statutory exception or on the data subject's authorisation, the Adhering Entity shall obtain a declaration of conformity from the Superintendency of Industry and Commerce before commencing the transfer.
14. Information security
The security principle is evidenced not by a statement of intent but by verifiable controls proportionate to the risk. The VHG Group adopts the following minimum standard, binding on every Adhering Entity.
14.1 Administrative measures
● An internal manual of policies and procedures, of which this Policy forms part. ● Formal allocation of roles and responsibilities for each database. ● Confidentiality agreements executed by all personnel and contractors. ● An annual training programme with attendance records and assessment. ● A documented procedure for granting, modifying and revoking access.
14.2 Technical measures
● Access control under the principles of least privilege and need to know. ● Enhanced authentication for access to databases containing sensitive or high-volume information. ● Encryption of information in transit and at rest, in line with the state of the art. ● Audit logging of accesses and operations, retained for a minimum of twelve (12) months and protected against alteration. ● Periodic backups and documented restoration testing. ● Environment segregation and a prohibition on using real personal data in development and testing environments without prior pseudonymisation. ● Vulnerability management and timely patching.
14.3 Physical measures
● Access control to premises, data centres and documentary archives. ● Secure custody and destruction of physical media. ● Clear desk and clear screen protocols.
14.4 Duty of confidentiality
All persons involved in processing are obliged to maintain the confidentiality of the information. This obligation subsists even after their relationship with the VHG Group has ended.
15. Security incident management
15.1 Definition and detection
A security incident is any event that compromises or may compromise the confidentiality, integrity or availability of personal data, including unauthorised access, loss or destruction of information, improper disclosure, cyberattacks and human error affecting data.
15.2 Protocol
| Phase | Action | Maximum time |
|---|---|---|
| Detection and internal reporting | Immediate communication to the Data Protection Area and the DPO | Without delay, upon becoming aware |
| Containment | Measures to halt the incident and limit its scope | Immediate |
| Assessment | Determination of scope, categories of data and data subjects affected, and risk to their rights | 72 hours |
| Reporting to the authority | Report to the Superintendency of Industry and Commerce through the National Database Register | Within 15 business days of detection |
| Communication to data subjects | Where the incident entails a risk to data subjects' rights | Without undue delay |
| Remediation and closure | Corrective actions and lessons learned | 30 calendar days |
Reporting to the authority is made in compliance with Article 17(n) of Law 1581 of 2012 and the instructions issued by the Superintendency of Industry and Commerce through the National Database Register. Where an incident affects additional jurisdictions, the notification duties of each shall be discharged in parallel.
15.3 Incident register
Each Adhering Entity maintains an incident register recording the description, date of detection, categories and volume of data affected, measures adopted, reports made and closure status. The DPO consolidates the Group register.
16. National Database Register
Private legal entities are required to register their databases containing personal data in the National Database Register (RNBD) administered by the Superintendency of Industry and Commerce, under Article 25 of Law 1581 of 2012 and its implementing rules.
Applicability threshold. Decree 090 of 2018 limited the registration obligation to companies and non-profit entities with total assets exceeding 100,000 UVT.
Current position of the Group. As at the publication date of this Policy, no VHG Group entity reaches the 100,000 UVT threshold in total assets, so RNBD registration is not required of it. This position is not permanent: the threshold is assessed against each financial year's statements and the UVT value in force for that year. Accordingly, the Group Data Protection Office shall verify the threshold annually, within one month of approval of each Adhering Entity's financial statements, and shall document that verification whether or not the threshold is exceeded. Once exceeded, registration must be effected within the period set by the authority.
Associated obligations. Registered entities must keep the information on their databases current and report, through the RNBD, complaints submitted by data subjects and security incidents, within the time limits set by the authority.
Verification. The DPO verifies annually the registration status of each Adhering Entity and documents that verification, whether or not the entity exceeds the threshold.
17. Retention, deletion and anonymisation
17.1 Retention criteria
Personal data is retained only for as long as necessary to: fulfil the declared purpose; meet legal, accounting, tax, employment and regulatory obligations; and exercise or defend rights during the applicable limitation and lapse periods.
Specific periods by database are set out in Annex D. In the absence of a special rule, the default period is the general limitation period for ordinary actions applicable in the relevant jurisdiction.
17.2 Secure deletion
Once the retention period expires, data is deleted through procedures preventing its recovery, in both production systems and backups, with documentary evidence of the deletion. Where immediate deletion from backups is not technically feasible, the data shall be blocked until backup rotation.
17.3 Anonymisation
As an alternative to deletion, the VHG Group may subject data to irreversible anonymisation, after which it ceases to be personal data. Anonymisation must prevent re-identification by reasonably available means; mere pseudonymisation is not equivalent to anonymisation and does not exempt from compliance with this Policy.
18. Demonstrated accountability
Compliance is not declared: it is evidenced. The principle of demonstrated accountability, incorporated in Article 2.2.2.25.6.1 of Decree 1074 of 2015 and developed by the Superintendency of Industry and Commerce, requires the controller to adopt appropriate, effective and verifiable measures and to demonstrate their implementation.
18.1 Comprehensive Personal Data Management Programme
Each Adhering Entity implements a programme comprising, at a minimum: this Policy and its derived procedures; a current Annex D; the register of authorisations; the register of data subject requests; the incident register; contracts with processors; the international transfer matrix; the annual training plan; and the annual compliance report.
18.2 Privacy by design and by default
Every new product, platform, feature or process involving the processing of personal data incorporates data protection considerations from the design phase, applying by default the most protective configuration, data minimisation and purpose limitation.
18.3 Impact assessment
High-risk processing — large-scale processing of sensitive data, systematic profiling, automated decisions with legal effects, extensive video surveillance, use of biometric data or the incorporation of artificial intelligence systems — requires a prior impact assessment, documented and approved by the DPO.
18.4 Training
Personnel receive training on joining and at least annually, with content differentiated according to their level of access to data. Attendance and assessment records are retained.
18.5 Audit and review
The DPO conducts an annual compliance review of each Adhering Entity, the results of which are presented to the Committee and to the highest management body, together with a remediation plan and assigned owners.
19. Special processing activities
19.1 Video surveillance
The installation of video surveillance systems is limited to the security of persons and property, with visible signage at capture points, a prohibition on capture in areas of reasonable expectation of privacy, restricted access to recordings and a retention period not exceeding thirty (30) calendar days, unless the images document an incident under investigation.
19.2 Commercial communications
Sending commercial communications requires specific and separate authorisation, revocable at any time. In Colombia, Law 2300 of 2023 additionally applies: contact only through channels authorised by the consumer, within permitted hours — Monday to Friday from 7:00 to 19:00 and Saturdays from 8:00 to 15:00, prohibited on Sundays and public holidays — respecting frequency limits and immediately honouring any request not to be contacted.
19.3 Biometric data
Biometric data is sensitive data. Its processing requires explicit and separate authorisation, a prior impact assessment, encrypted storage, a prohibition on use for purposes other than the declared authentication or access control, and the availability of a non-biometric alternative for data subjects who do not authorise it.
19.4 Automated decisions, profiling and artificial intelligence
The VHG Group does not take decisions based solely on automated processing that produce legal effects on, or significantly affect, a data subject, without qualified human intervention and without prior disclosure.
Any artificial intelligence system processing personal data is subject to: a prior impact assessment; documentation of the processing logic and the categories of data used; a prohibition on using personal data for model training without the data subject's specific and informed authorisation; and periodic review of outputs to detect discriminatory bias.
19.5 Employment and candidate data
Candidate data is retained for a maximum of twelve (12) months from the conclusion of the process, unless express authorisation is given for retention in a talent pool. It is prohibited to request information on pregnancy status, sexual orientation, political or trade union affiliation, or any sensitive data unrelated to suitability for the role.
19.6 Anti-money-laundering compliance
The processing of data for due diligence, counterparty knowledge, restrictive list screening and reporting to authorities is carried out on the basis of compliance with legal obligations. Where applicable, the regimes of External Circular 100-000016 of 2020 of the Superintendency of Companies (SAGRILAFT), the Business Transparency and Ethics Programme and the rules of the Financial Information and Analysis Unit shall be observed. The statutory confidentiality of suspicious transaction reports prevails over the data subject's right of access, as provided by law.
20. Sanctions regime and consequences of non-compliance
20.1 Administrative sanctions
Non-compliance with the data protection regime exposes the controller to the sanctions in Article 23 of Law 1581 of 2012, imposed by the Superintendency of Industry and Commerce:
● Personal and institutional fines of up to the equivalent of two thousand (2,000) current statutory monthly minimum wages. ● Suspension of processing-related activities for up to six (6) months. ● Temporary closure of processing-related operations where the suspension period elapses without corrective measures being adopted. ● Immediate and permanent closure of operations involving the processing of sensitive data.
In Panama, the sanctions under Law 81 of 2019 imposed by the competent authority apply; in other jurisdictions, those provided by the relevant regime.
20.2 Internal consequences
Breach of this Policy by directors, employees or contractors constitutes serious misconduct and gives rise to the applicable disciplinary and contractual measures, without prejudice to applicable civil and criminal actions, including those arising from Article 269F of the Criminal Code — breach of personal data, added by Law 1273 of 2009.
21. Jurisdictional supplements
This Policy constitutes the Group's minimum standard. In each jurisdiction, the local regime applies in addition and prevails where more protective.
21.1 Colombia
Principal regime: Article 15 of the Political Constitution; Law 1581 of 2012; Decree 1074 of 2015; Law 1266 of 2008 on financial habeas data; Law 1273 of 2009 on criminal matters; Law 1480 of 2011 on consumer protection; Law 2300 of 2023 on contact with consumers; Law 527 of 1999 on data messages. Supervisory authority: Superintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data.
21.2 Other jurisdictions — contingency regime
The VHG Group does not currently operate databases in jurisdictions other than Colombia and the United States. Should an Adhering Entity become established in, or process data in, another territory, its adhesion shall trigger the issuance of the corresponding jurisdictional supplement before processing begins.
By way of provision, it is recorded that in Panama — a jurisdiction referenced in earlier versions of the Framework — Law 81 of 26 March 2019 on Personal Data Protection applies, as implemented by Executive Decree 285 of 28 May 2021, under the supervision of the National Authority for Transparency and Access to Information (ANTAI), with a regime likewise structured around the data subject's consent.
21.3 United States
Valencia Holding Group LLC is incorporated in the State of Delaware. There is no general federal data protection regime in the United States. The following apply as relevant: Section 5 of the Federal Trade Commission Act on unfair or deceptive practices; state consumer privacy laws where their applicability thresholds are met — which the Group does not currently reach; and any applicable sector-specific regulation. The Group Data Protection Office shall review annually whether any state law becomes applicable by reason of revenue or data-subject volume thresholds being exceeded, and shall document that determination.
21.4 European Economic Area and United Kingdom
The VHG Group does not declare general subjection to Regulation (EU) 2016/679. Where an Adhering Entity offers goods or services to persons in the European Economic Area or monitors their behaviour, within the meaning of Article 3 of the Regulation, it must carry out a formal applicability determination and, where appropriate, adopt the additional measures the Regulation requires, including the possible designation of a representative under its Article 27.
References to "GDPR-aligned standards" in Group documents are voluntary best practice and do not constitute a declaration of applicability.
22. Effectiveness, updating and regulatory monitoring
22.1 Effectiveness
This Policy takes effect upon publication at https://vhg.capital, on the date stated in the Document Control block, and remains in force until superseded by a later version. The publication date is displayed prominently on the site, in compliance with Article 2.2.2.25.3.1(f) of Decree 1074 of 2015.
22.2 Validity of the databases
In compliance with Article 2.2.2.25.3.1(f) of Decree 1074 of 2015, the VHG Group's databases shall remain in force for as long as the declared purposes and the statutory retention periods set out in Annex D subsist, after which the data shall be deleted or anonymised in accordance with section 17.
22.3 Updating
The DPO subjects this Policy to ordinary review on 1 January each year and to extraordinary review in the event of regulatory changes, corporate reorganisations, the addition of new Adhering Entities, the enabling of new platform functionality or material incidents. Each review is documented, whether or not it results in an amendment.
Substantial amendments are communicated to data subjects in advance of taking effect. Where an amendment entails a change in the purpose of processing, fresh authorisation from the data subject is required; silence shall not be construed as acceptance.
22.4 Regulatory monitoring
Monitoring alert. In August 2025 the National Government filed a bill to update the Colombian personal data protection regime, contemplating, among other matters, an expansion of the lawful bases, strengthened autonomy for the supervisory authority, mandatory designation of a data protection officer in certain cases, reinforced protections for minors, new rights in relation to automated decisions and incident notification duties. As at the issuance date of this Policy, Law 1581 of 2012 remains in force and constitutes the applicable regime. The DPO shall monitor the legislative process and shall present to the Committee, within sixty (60) days of any enactment of the new law, a plan to bring the Framework into line with it.
23. Annexes and contact channels
23.1 Annexes
| Annex | Title | Responsible for completion |
|---|---|---|
| A | Adhering Entity Identification Sheet | Issued and published |
| B | Jurisdictional Supplements | Incorporated in section 21 of this Policy |
| C | Inventory of Cookies and Similar Technologies | Incorporated in section 6 of MLD-03 |
| D | Register of Databases, Purposes and Retention | Issued — internal document |
| E | Model Deed of Adhesion to the MLD-VHG | Issued — pending execution by VCG and VIG |
| F | Intragroup Personal Data Transmission Master Agreement | Activated upon the first formal adhesion |
| G | Contact Form Authorisation | Issued — texts and implementation specification |
| H | Security Incident Management Procedure | Incorporated in section 15 of this Policy |
23.2 Contact channels
| Subject | Channel |
|---|---|
| Exercise of rights (enquiries and complaints) | info@vhg.capital |
| Area responsible for handling requests | VHG Group Data Protection Office — info@vhg.capital |
| Group Data Protection Office | info@vhg.capital |
| Security incident reporting | info@vhg.capital |
| Physical service | Delaware, United States of America — formal channel: info@vhg.capital |
23.3 Supervisory authorities
| Jurisdiction | Authority |
|---|---|
| Colombia | Superintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data |
| Other jurisdictions | The competent supervisory authority in the territory, under the supplement issued when operations are enabled |
| United States | Federal Trade Commission and competent state authorities |
END OF INSTRUMENT MLD-04
Valencia Holding Group — VHG Group Digital Legal Framework MLD-04 — Personal Data Processing and Protection Policy | Version 2.0 | Governing language: Spanish