Legal

Privacy and data protection policy

Last updated: 2026-09-23


01 Data controller

InnDiTec — Jhors Maicken Giraldo Suárez, based in Medellín, Colombia, is the controller of the personal data collected through innditec.com. You can reach us at innditecc@gmail.com or on +57 324 599 1044.

02 Data we collect

Only what you voluntarily provide: name, email address, phone number, company, estimated budget and the message you write in the contact form. During a purchase we additionally collect the data needed to issue an invoice and grant you course access. We do not collect sensitive data or data from minors.

03 Card data

InnDiTec does not store, process or have access to card numbers. Payment is handled entirely within the payment gateway environment (Wompi or MercadoPago), which is PCI-DSS compliant.

04 Purpose

Data is used solely to answer your request, prepare quotations, deliver the contracted service, grant access to purchased courses and meet legal and accounting obligations. We do not send unsolicited marketing, nor do we sell or transfer your data to third parties for commercial purposes.

05 Legal basis

Processing is carried out with your prior, express and informed authorisation, given by ticking the consent box on the form, in accordance with Colombian Law 1581 of 2012 and Decree 1074 of 2015.

06 Retention

Contact data is kept while a commercial relationship or legitimate interest exists, and for no more than five years from the last contact. Accounting records are kept for the period required by law.

07 Processors and transfers

To run the site and email we use hosting and mail providers acting as data processors. Payment gateways act as independent controllers for transaction data.

08 Your rights

You may access, update, rectify and delete your data, and withdraw your authorisation, by writing to innditecc@gmail.com. We reply within the deadlines set by articles 14 and 15 of Law 1581 of 2012.

09 Cookies

This site uses no advertising, tracking or third-party cookies. Only one strictly necessary technical session cookie is used, to protect forms against cross-site request forgery (CSRF). It is marked HttpOnly, Secure and SameSite=Lax, and is removed when you close the browser.

10 Security

The site is served exclusively over HTTPS with HSTS, enforces a strict Content Security Policy, protects forms with single-use CSRF tokens and rate-limits submissions per IP address. Everything you send us travels encrypted.

Questions about this document? Write to innditecc@gmail.com.