DOCUMENT CONTROL
Identification
| Field | Detail |
|---|---|
| Document | MLD-02 — Privacy Notice |
| Master document | VHG Group Digital Legal Framework (MLD-VHG) |
| Issuing entity | Valencia Holding Group — Parent Company |
| Legal nature | Privacy Notice (aviso de privacidad) under Articles 2.2.2.25.3.2 and 2.2.2.25.3.3 of Colombian Decree 1074 of 2015 |
| Developing document | MLD-04 — Personal Data Processing and Protection Policy |
| Version | 3.0 |
| Effective date | 1 October 2026 |
| Scope | Personal data processed by VHG and by the entities adhering to the MLD-VHG |
| Governing language | Spanish |
| Status | In force |
Version history
| Version | Date | Description | Status |
|---|---|---|---|
| 1.0 to 2.1 | July to September 2026 | Internal working versions. Not published. | Superseded |
| 3.0 | 1 October 2026 | First published version. Completion of controller identification, single contact channel, alignment of the governing law with the State of Delaware, trademark regime pending registration, and effectiveness with ordinary annual review. | In force |
Use notice
Nature and function of this document. This Privacy Notice is the summary, readily accessible communication by which the VHG Group informs data subjects about the processing of their personal data. It does not replace the Personal Data Processing and Protection Policy (MLD-04), which is the complete document whose adoption is mandatory under Article 2.2.2.25.3.1 of Decree 1074 of 2015 and which is permanently available at the link indicated in section 14 of this Notice.
CONTENTS
- Purpose and nature of this Notice
- Identification of the Data Controller
- Scope of application and group architecture
- Categories of personal data processed
- Purposes of processing
- Basis for processing: authorisation
- Sensitive data and children's data
- Data subject rights
- Procedure and time limits for exercising rights
- Processors, intragroup circulation and international transfers
- Retention of information
- Information security and incidents
- Commercial communications
- Access to the Processing Policy and amendment regime
- Supervisory authorities and contact channels
1. Purpose and nature of this Notice
Transparency towards the data subject requires that essential information about the processing of their data be accessible clearly, concisely and prior to collection. This Notice fulfils that function and refers, for the detailed development of each matter, to instrument MLD-04.
This Privacy Notice (the "Notice") informs any natural person whose personal data is processed by Valencia Holding Group ("VHG" or the "Parent Company") and by the entities adhering to the VHG Group Digital Legal Framework (the "Adhering Entities" and, together, the "VHG Group") of the existence of the applicable processing policies, how to access them, and the essential characteristics of the processing.
It is issued in compliance with Colombian Law 1581 of 2012, Decree 1074 of 2015 — which consolidated Decree 1377 of 2013 — and other concordant provisions of Colombian law, as well as the data protection rules applicable in the other jurisdictions in which the VHG Group operates.
2. Identification of the Data Controller
Precise identification of the controller is not a formality: it determines against whom the data subject exercises their rights and who is answerable to the supervisory authority. It is therefore stated expressly and verifiably.
2.1 Data Controller
| Field | Detail |
|---|---|
| Corporate name of the controller | Valencia Holding Group LLC |
| Tax identification number (NIT / RUC / EIN) | Withheld from publication. Recorded in Annex A and disclosed to any authority so requiring |
| Principal domicile | Delaware, United States of America |
| Physical address for service | Delaware, United States of America. Designated formal channel for service: info@vhg.capital |
| Email address for the exercise of rights | info@vhg.capital |
| Contact telephone number | Not published. Single contact channel: info@vhg.capital |
| Area responsible for handling enquiries and complaints | VHG Group Data Protection Office |
| Group Data Protection Office | info@vhg.capital |
2.2 Determining the controller in each case
Each Adhering Entity is an autonomous Data Controller in respect of the databases whose purposes and means it determines. The entity operating each digital platform, channel or collection point is identified in Annex A — Adhering Entity Identification Sheet, published and accessible from each platform and available through the channels in section 15.
Valencia Holding Group acts as the Parent Company, exercising governance, coordination and verification functions over the Framework, and is itself a controller in respect of its own databases. Adhesion to the Framework creates no commingling of assets and no joint and several liability among Group entities, save where the law imposes it.
3. Scope of application and group architecture
This Notice applies to personal data processed by VHG and by the Adhering Entities — including Valencia Capital Group (VCG) and Valencia Investment Group (VIG), as well as any other affiliate, subsidiary or business unit that may in future join the Group, be incorporated by it or come under its control; an illustrative, non-exhaustive list — irrespective of the channel through which the data was collected.
Material scope. Unlike instruments of exclusively digital scope, this Notice and instrument MLD-04 cover all databases of the VHG Group, whether digital or physical, including those fed by in-person, telephone, documentary and contractual channels.
Data subjects covered. Visitors and users of digital platforms; current and prospective clients; investors and prospective investors; commercial counterparties; suppliers and contractors and their personnel; candidates for employment; and any natural person interacting with the VHG Group.
Order of precedence. Mandatory data protection rules of the data subject's jurisdiction of residence prevail over this Notice. The applicable jurisdictional supplements are set out in Annex B.
4. Categories of personal data processed
Depending on the nature of the relationship, the VHG Group may process the following categories of data:
| Category | Data included |
|---|---|
| Identification and contact | Full name, type and number of identity document, nationality, email address, telephone, address, country of residence |
| Professional and business information | Company, position, sector, professional background, corporate contact details |
| Financial and asset information | Only where necessary for the contractual relationship, due diligence or compliance with legal obligations |
| Technical and browsing data | IP address, device identifiers, browser type, usage logs, cookie and similar technology data |
| Communications data | Messages, requests, correspondence and records of interaction with the VHG Group |
| Compliance data | Information required for anti-money-laundering and counter-terrorist-financing purposes, restrictive list screening and counterparty due diligence |
The VHG Group does not knowingly collect sensitive data, save in the circumstances and with the safeguards set out in section 7 and developed in section 5.2 of instrument MLD-04.
5. Purposes of processing
The purpose limitation principle requires that processing serve legitimate, specified purposes communicated to the data subject prior to collection. The purposes declared by the VHG Group are as follows:
Relationship management. Handling enquiries, requests and communications; managing relationships with clients, investors, counterparties, suppliers and contractors; assessing business opportunities and service requests.
Contract performance. Conducting pre-contractual negotiations, entering into, performing, administering and settling contracts, and exercising or defending rights arising from them.
Regulatory compliance. Meeting legal, regulatory, tax, accounting and reporting obligations; responding to requests from competent authorities; and conducting due diligence and counterparty knowledge procedures for anti-money-laundering and counter-terrorist-financing purposes.
Risk management and security. Preventing fraud, protecting the security of information and of persons, and ensuring the traceability of transactions.
Corporate governance. Preparing internal reports, management indicators and controls, and coordinating Group operations.
Platform improvement. Analysing the use of digital platforms to improve their performance, structure and user experience.
Institutional and commercial communications. Sending institutional information, invitations, newsletters and commercial communications, only where the data subject has given specific authorisation and subject to section 13.
Talent management. Conducting candidate selection and assessment processes.
The VHG Group shall not process personal data for purposes other than, or incompatible with, those declared here. Any new purpose shall require the data subject's prior authorisation.
6. Basis for processing: authorisation
This is the point at which international standards and Colombian law differ materially, and treating it imprecisely exposes the controller to a defect of lawfulness. It is therefore stated expressly.
6.1 General rule in Colombia
In Colombia, the processing of personal data requires the data subject's prior, express and informed authorisation, in accordance with Article 9 of Law 1581 of 2012. Authorisation must be obtained by means allowing subsequent consultation, and the controller has a duty to retain evidence of it.
Material clarification. Colombian law does not recognise "legitimate interest" as an autonomous lawful basis for processing. The only cases in which authorisation is not required are those exhaustively listed in Article 10 of Law 1581 of 2012, namely: (i) information required by a public or administrative body in the exercise of its statutory functions or by court order; (ii) data of a public nature; (iii) medical or health emergencies; (iv) processing authorised by law for historical, statistical or scientific purposes; and (v) data relating to the Civil Registry of Persons. Any reference to legitimate interest in VHG Group documents applies exclusively to jurisdictions whose legal systems recognise it.
6.2 Manner of obtaining and evidence
Authorisation is obtained through an express affirmative action — an unchecked box, an acceptance button, a physical or electronic signature, or an equivalent mechanism — with a record of the date, time, version of the text disclosed and technical traces of the transaction. Silence, inactivity or continued use of a platform do not constitute authorisation.
6.3 Withdrawal
The data subject may withdraw authorisation at any time, free of charge, through the channels in section 15. Withdrawal may be total or limited to specific purposes. Withdrawal does not proceed where a legal or contractual duty requires the data to remain in the database, a circumstance that will be communicated to the data subject with reasons.
6.4 Other jurisdictions
In the United States, the applicable federal and state frameworks apply, including Section 5 of the Federal Trade Commission Act. Should the Group come to operate in other jurisdictions, the corresponding supplement will be issued before processing begins. Where Regulation (EU) 2016/679 is applicable, its own lawful bases shall be observed. Details are set out in section 21 of instrument MLD-04.
7. Sensitive data and children's data
7.1 Sensitive data
Sensitive data is data affecting the data subject's privacy or whose misuse may give rise to discrimination, such as data relating to racial or ethnic origin, political orientation, religious or philosophical convictions, trade union or social organisation membership, health data, data concerning sexual life and biometric data.
The processing of sensitive data is prohibited, save in the circumstances set out in Article 6 of Law 1581 of 2012. Where the VHG Group needs to process such data, it shall inform the data subject of the sensitive nature of the data and of the specific purpose, and shall obtain explicit authorisation. The data subject is not obliged to authorise the processing of sensitive data or to answer questions concerning it.
7.2 Children's and adolescents' data
The VHG Group does not direct its platforms to minors and does not knowingly collect their data. Where exceptionally necessary, processing shall be carried out only in respect of data of a public nature, having regard to the best interests of the child and respect for their fundamental rights, with the prior authorisation of the legal representative and taking account of the minor's views where their maturity permits, in accordance with Article 7 of Law 1581 of 2012, Article 2.2.2.25.2.9 of Decree 1074 of 2015 and Constitutional Court Judgment C-748 of 2011.
If the inadvertent collection of a minor's data is detected, the VHG Group shall proceed to its immediate deletion.
8. Data subject rights
Under Article 8 of Law 1581 of 2012, data subjects have the following rights:
To know, update and rectify their personal data before the controller or processor, particularly where the data is partial, inaccurate, incomplete, fragmented, misleading, or where its processing is expressly prohibited or has not been authorised.
To request evidence of the authorisation granted, except where the law provides that authorisation is not required.
To be informed, upon request, of the use made of their personal data.
To lodge complaints with the Superintendency of Industry and Commerce for infringements of the law, once the enquiry or complaint procedure before the controller has been exhausted.
To withdraw authorisation and request deletion of the data where processing does not respect constitutional and statutory principles, rights and guarantees, or where the authority has established an infringement.
To access free of charge their personal data that has been processed.
These rights may be exercised by the data subject, their duly accredited successors, their representative or attorney-in-fact, and by any person acting under a stipulation in favour of a third party.
9. Procedure and time limits for exercising rights
A right without a defined procedure and time limit is illusory. The VHG Group expressly adopts the statutory procedure and periods.
9.1 Available channels
Requests may be submitted through the channels listed in section 15, stating the data subject's name and identification, a precise description of the facts or of the request, an address for service, and any supporting documents.
9.2 Enquiries
Enquiries shall be answered within a maximum of ten (10) business days from the date of receipt. Where this is not possible, the interested party shall be informed before expiry, stating the reasons and the date on which the enquiry will be answered, which may not exceed five (5) business days following expiry of the first period. (Article 14, Law 1581 of 2012.)
9.3 Complaints
Complaints shall be handled within a maximum of fifteen (15) business days from the day following receipt. Where this is not possible, the interested party shall be informed of the reasons for the delay and of the response date, which may not exceed eight (8) business days following expiry of the first period. (Article 15, Law 1581 of 2012.)
If the complaint is incomplete, the interested party shall be requested within five (5) days of receipt to remedy the deficiencies. If two (2) months elapse from the date of that request without the applicant providing the required information, the complaint shall be deemed withdrawn.
If the VHG Group is not competent to resolve the complaint, it shall refer it to the competent party within a maximum of two (2) business days and shall inform the interested party accordingly.
While a complaint is pending, the database shall bear the legend "complaint pending" together with its subject matter, within no more than two (2) business days.
9.4 Procedural prerequisite
Under Article 16 of Law 1581 of 2012, a data subject may lodge a complaint with the Superintendency of Industry and Commerce only once the enquiry or complaint procedure before the controller or processor has been exhausted.
9.5 No charge
The exercise of these rights is free of charge. The VHG Group shall not require payment or condition the handling of a request on any consideration.
10. Processors, intragroup circulation and international transfers
10.1 Data processors
The VHG Group may rely on third parties processing personal data on its behalf — providers of technology, hosting, communications, audit, legal, financial and compliance services — acting as processors under a transmission agreement imposing obligations of confidentiality, security, use limited to the controller's instructions, and return or deletion at the end of the relationship, in accordance with Article 2.2.2.25.5.2 of Decree 1074 of 2015.
10.2 Intragroup circulation
Data flows between VHG and the Adhering Entities take place under the Intragroup Personal Data Transmission Master Agreement (Annex F) and are limited to the purposes declared in section 5. Where the receiving entity determines its own purposes, the flow constitutes a transfer and requires the data subject's authorisation.
10.3 International transfers
Given the Group's international structure, data may be processed in Colombia and the United States of America, the only destinations enabled as at the publication date.
Applicable regime and current destinations. Article 26 of Law 1581 of 2012 prohibits the transfer of personal data to countries that do not provide adequate levels of protection, unless the data subject has given express and unequivocal authorisation or one of the statutory exceptions applies. Under External Circular 005 of 2017 of the Superintendency of Industry and Commerce, the United States of America is among the countries declared to provide an adequate level of protection. As at the publication date, the VHG Group's only processing destinations are Colombia and the United States, both covered by that regime. Any future transfer to a destination not declared adequate shall be made only with the data subject's express and unequivocal authorisation, by means of a declaration of conformity before the Superintendency of Industry and Commerce, or under one of the exceptions in Article 26, and always with contractual clauses guaranteeing an equivalent level of protection.
Full details are set out in section 13 of instrument MLD-04.
11. Retention of information
Personal data shall be retained only for as long as necessary to fulfil the purpose for which it was collected, to meet legal, accounting, tax and regulatory obligations, and to exercise or defend rights during the applicable limitation and lapse periods.
Once those periods expire, data shall be securely deleted or subjected to irreversible anonymisation. Specific criteria and periods are set out in Annex D — Register of Databases, Purposes and Retention.
12. Information security and incidents
The VHG Group adopts administrative, technical, physical and organisational measures that are reasonable and proportionate to the risk, designed to protect personal data against unauthorised access, loss, destruction, alteration, disclosure or misuse, in accordance with the security principle in Article 4(g) of Law 1581 of 2012.
In the event of a security incident compromising personal data, the VHG Group shall activate its incident management protocol, report the event to the Superintendency of Industry and Commerce through the National Database Register within the terms and time limits required by the authority, and notify affected data subjects where the incident entails a risk to their rights.
13. Commercial communications
Sending commercial or promotional communications requires the data subject's specific and separate authorisation, distinct from the general processing authorisation. Such authorisation may be withdrawn at any time, free of charge, through the channels in section 15 or through the unsubscribe mechanism included in each communication.
Special rule for Colombia. Contact with consumers is subject to Law 2300 of 2023: contact shall be made only through channels authorised by the consumer and within permitted hours — Monday to Friday from 7:00 to 19:00 and Saturdays from 8:00 to 15:00, with contact prohibited on Sundays and public holidays — respecting the applicable frequency limits and immediately honouring any request not to be contacted.
14. Access to the Processing Policy and amendment regime
14.1 Access to the Policy
The Personal Data Processing and Protection Policy (MLD-04) contains the full development of the matters summarised in this Notice and is permanently available at:
● Website: https://vhg.capital, through the permanent footer link. ● Email address for requests: info@vhg.capital ● Copy in physical or electronic form: provided free of charge upon the data subject's request through the same channel.
14.2 Amendments
The VHG Group may amend this Notice and Policy MLD-04. Substantial amendments — in particular those affecting the identification of the controller, the purpose of processing, the categories of data or the recipients — shall be communicated to data subjects in advance of taking effect through the available contact channel and prominently published.
Where an amendment entails a change in the purpose of processing, fresh authorisation from the data subject shall be required. The data subject's silence shall not be construed as acceptance.
14.3 Effectiveness
This Notice takes effect upon publication at https://vhg.capital, on the date stated in the Document Control block, and is subject to ordinary review on 1 January each year, as well as to extraordinary review upon any regulatory change that so requires. The VHG Group's databases shall remain in force for as long as the declared purposes and the statutory retention periods subsist, as set out in Annex D.
15. Supervisory authorities and contact channels
15.1 VHG Group channels
| Subject | Channel |
|---|---|
| Exercise of rights (enquiries and complaints) | info@vhg.capital |
| Area responsible for handling requests | VHG Group Data Protection Office — info@vhg.capital |
| Group Data Protection Office | info@vhg.capital |
| Withdrawal from commercial communications | info@vhg.capital |
| Physical service | Delaware, United States of America — formal channel: info@vhg.capital |
15.2 Supervisory authorities
| Jurisdiction | Authority |
|---|---|
| Colombia | Superintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data |
| Other jurisdictions | The competent supervisory authority in the data subject's territory of residence |
| United States | Federal Trade Commission and the competent state authorities |
| European Economic Area / United Kingdom | Competent supervisory authority, where applicable |
END OF INSTRUMENT MLD-02
Valencia Holding Group — VHG Group Digital Legal Framework MLD-02 — Privacy Notice | Version 3.0 | Governing language: Spanish