Teamcore Solutions | Privacy and Personal Data Treatment Policy

PRIVACY POLICY AND PROCESSING OF PERSONAL DATA

Teamcore Solutions / Grupo BIT S.A.S.

Version 2.0 | 2025 | Applicable in Colombia, Mexico, Chile, and Peru

1. Identification of the Data Controller

Business name Teamcore Solutions S.p.A. (Also operating in Colombia and Mexico as Grupo BIT S.A.S. and BI-PPR S.A. de C.V. respectively)
NIT / Identification In accordance with the current commercial registry
Principal residence Colombia
Website www.teamcore.net
Privacy email privacidad@teamcore.net
Data Protection Officer (DPO) Available via privacidad@teamcore.net

This Privacy Policy and Personal Data Processing Policy (hereinafter, the «Policy») describes how Teamcore Solutions collects, uses, stores, transfers, and protects the personal data of data subjects who interact with its website, SaaS platform, and other contact channels. This Policy has been prepared in compliance with the applicable regulations in the jurisdictions where Teamcore Solutions operates, including, without limitation:

  • Colombia: Law 1581 of 2012 and Regulatory Decree 1377 of 2013 (incorporated into Single Regulatory Decree 1074 of 2015).
  • Mexico: Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
  • Chile: Law 19.628 on the Protection of Private Life (and its amendments) / Law 21.719 (pending entry into force).
  • Peru: Personal Data Protection Law No. 29733 and its Regulations (Supreme Decree No. 003-2013-JUS).

2. Scope of Application

This Policy applies to any natural person (hereinafter, the «Data Subject») whose personal data is processed by Teamcore Solutions in the context of:

  • The navigation and use of the website www.teamcore.net and any associated subdomain.
  • The contracting, use, and support of Teamcore Solutions' SaaS services (Visibility, Actions, Visibility Pro, among others).
  • The process of sales prospecting, customer service, and management of suppliers or strategic partners.
  • Communications by email, phone, contact forms, or other channels enabled by Teamcore Solutions.

 

It does not apply to data processing carried out exclusively by Teamcore Solutions customers through the SaaS platform, a situation in which Teamcore Solutions acts as a Data Processor under the instructions of the customer (Controller), in accordance with the Terms and Conditions of the service and the corresponding Data Processing Agreement (DPA).

3. Categories of Personal Data Collected

3.1 Identification and contact data

  • Full name, position, and company or employer.
  • Corporate or personal email address.
  • Landline or mobile phone number.
  • Physical or mailing address (when necessary for the provision of the service).

3.2 Usage and navigation data

  • IP address, device identifiers, and approximate geolocation data.
  • Pages visited, session duration, browser type, operating system, and referral source.
  • Interactions with forms, buttons, and other interactive elements of the website.

3.3 Commercial and contractual data

  • Information on products or services of interest, communication history, and requests.
  • Data necessary for the execution, performance, or termination of service contracts.

3.4 Data from external and public sources

  • Professional profile information available in public sources such as LinkedIn, which the Data Subject has made publicly accessible, used solely for initial business contact.
  • Data obtained from authorized business partners, provided they have a legal basis for the transfer.

Teamcore Solutions does NOT process data considered «sensitive» (health data, biometric data, political ideology, trade union affiliation, sexual orientation, religious beliefs, among others) unless it is strictly necessary for the provision of a specific service and upon prior obtaining of the Data Subject's express consent.

4. Purposes of Processing

Teamcore Solutions will process personal data for the following purposes, always based on one of the legal grounds provided for in the applicable regulations:

4.1 Main purposes (linked to the execution of the service or contractual relationship)

  • Handle requests for information, demonstrations, or quotes for Teamcore Solutions services.
  • Execute, perform, and manage SaaS service agreements.
  • Issue invoices, manage collections, and handle related financial requests.
  • Provide technical support and resolve incidents reported by users.
  • Comply with legal, tax, accounting, or regulatory obligations in the applicable jurisdictions.

4.2 Secondary purposes (based on consent or legitimate interest, as applicable)

  • Send commercial communications, product updates, and digital marketing material (requires prior consent or the possibility to opt out).
  • Perform statistical and website usage behavior analyses for service improvement purposes (anonymized or pseudonymized where possible).
  • Manage referral programs, partnerships, or corporate events.
  • Execute supplier selection processes, partner evaluation, or commercial due diligence.


The Data Subject may refuse the processing of their data for secondary purposes without this affecting their access to the contracted services.

5. Legal Basis for Processing

The processing of personal data is based on one or more of the following legal bases, in accordance with the regulations of each jurisdiction:

Contract execution The processing is necessary to provide the contracted services or to take steps at the request of the Data Subject prior to entering into a contract.
Consent The Data Subject has given their free, informed, specific, and prior consent for one or more specific purposes.
Legal obligation The processing is necessary for compliance with an applicable legal or regulatory obligation.
Legitimate interest Teamcore Solutions has a legitimate interest that does not override the rights and freedoms of the Data Subject (e.g., fraud prevention, network security, internal analytics).
Mission of public interest In the cases provided for by applicable law, when the processing serves a function of public interest.

6. Use of Cookies and Tracking Technologies

The Teamcore Solutions website uses cookies and similar technologies (tracking pixels, local storage, etc.) for the following purposes:

6.1 Types of cookies used

Strictly necessary cookies They enable the basic operation of the website and cannot be disabled. They do not require consent.
Analytical / performance cookies They collect information about site usage (visited pages, session duration, errors) for internal improvements. Consent is required.
Preference / functional cookies They remember the user's settings (language, region). They may require consent depending on the jurisdiction.
Marketing / advertising cookies They allow the display of personalized content and the measurement of campaign effectiveness. They require explicit consent.

6.2 Cookie Consent Management

Upon first entering the website, the Data Subject will see a cookie management banner that will allow them to accept, reject, or customize non-essential cookies. You can modify your preferences at any time through the «Cookie Preferences» link available in the footer of the site.

For more information on how to manage cookies from your browser settings, please consult your browser's official documentation. Disabling non-essential cookies does not affect access to the contracted services, although it may limit certain functionalities of the website.

Teamcore Solutions uses Google Analytics or similar tools for traffic analysis. These tools may transfer data to overseas servers. In such cases, Teamcore Solutions ensures that appropriate safeguards are adopted (standard contractual clauses, certification mechanisms, or others) in accordance with applicable regulations.

7. Data Transfer and Transmission

Personal data may be shared with the following categories of recipients, always within the limits of the stated purposes and with the corresponding legal guarantees:

  • Companies of the corporate group of Teamcore Solutions / Grupo BIT S.A.S., for internal administrative purposes.
  • Technology service providers (cloud infrastructure, support tools, CRM, analytics) acting as Data Processors under confidentiality agreements and/or DPAs.
  • Business partners or authorized distribution channels, exclusively to manage the provision of the contracted service.
  • Public authorities, regulatory or judicial bodies, when there is a legal obligation or duly substantiated official request.
  • Acquirers in merger, acquisition, or corporate restructuring processes, subject to confidentiality and the continuity of this Policy.


Teamcore Solutions does not sell, transfer, or distribute personal data for commercial purposes to third parties unrelated to the stated purposes. International data transfers are carried out solely to destinations that offer adequate levels of protection or under recognized legal mechanisms (standard contractual clauses, equivalent Privacy Shields, etc.).

8. Data Subject Rights

In accordance with applicable data protection regulations, the Data Subject has the following rights, the specific scope of which may vary depending on the jurisdiction from which they access the service:

Access Know what personal data Teamcore Solutions processes, for what purposes, and the origin of said data.
Rectification Request the correction of inaccurate, incomplete, or outdated data.
Suppression / Cancellation / Erasure Request the deletion of your data when it is no longer necessary for the purposes for which it was collected, or when you withdraw your consent (subject to legal exceptions).
Opposition Object to the processing of your data for specific purposes (especially for direct marketing or processing based on legitimate interest).
Portability Receive your data in a structured and commonly used format, where regulations provide for it (this applies especially in Mexico and, progressively, in Chile).
Revocation of consent Withdraw the consent given at any time, without retroactive effect.
Restriction of processing Request the suspension of processing while the accuracy of the data is verified or a complaint is resolved.
Not to be subject to automated decisions Not to be subject to decisions with significant effects based exclusively on automated processing, without human intervention.

8.1 Procedure for exercising rights

To exercise any of the aforementioned rights, the Data Subject must send a written request to the email address privacidad@teamcore.net, indicating:

  • Full name and ID document.
  • Clear description of the right you wish to exercise and the data to which your request refers.
  • Contact methods to receive the response.


Teamcore Solutions will respond within the timeframes established by the regulations of each jurisdiction: 10 business days for inquiries and 15 business days for claims in Colombia (Law 1581/2012); 20 business days in Mexico (LFPDPPP); 30 business days in Chile and Peru. If a satisfactory response is not received, the Data Subject may turn to the competent supervisory authority in their country.

Supervisory Authorities

Colombia: Superintendency of Industry and Commerce (SIC) — www.sic.gov.co
Mexico: National Institute for Transparency, Access to Information and Personal Data Protection (INAI) — www.inai.org.mx
Chile: Council for Transparency (CPLT) / future Data Protection Agency — www.consejotransparencia.cl
Peru: National Authority for Personal Data Protection (ANPDP) — www.minjus.gob.pe

9. Security Measures

Teamcore Solutions has implemented a set of technical, organizational, and legal measures to guarantee the confidentiality, integrity, and availability of the personal data it processes, including, by way of example:

  • Encryption in transit using TLS/SSL protocols and encryption at rest for databases containing personal data.
  • Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) for internal system access.
  • Documented information security policies and incident management procedures.
  • Confidentiality agreements with employees, contractors, and suppliers who have access to personal data.
  • Periodic security audits and vulnerability assessments.
  • Security breach response plan with notification to authorities and data subjects within the timeframes required by law.


Notwithstanding the foregoing, no data transmission or storage system is completely invulnerable. In the event of a security breach affecting personal data, Teamcore Solutions will notify the affected Data Subjects and the competent authorities in accordance with the deadlines and procedures established in the applicable regulations (72 hours as a reference standard for notification to authorities, when applicable).

10. Retention Periods

Personal data will be retained for the time strictly necessary to fulfill the purposes for which it was collected and, in any case, during the limitation periods for legal actions arising from the commercial or contractual relationship (generally no less than five (5) years in the jurisdictions where Teamcore Solutions operates, in accordance with applicable commercial and tax legislation). Once these periods have elapsed, the data will be securely deleted or anonymized.

Minors

Teamcore Solutions' services are aimed exclusively at legal entities and natural persons over eighteen (18) years of age. Teamcore Solutions does not knowingly collect personal data from minors. If a minor has provided personal data without the consent of their parents or legal representatives, the Data Subject or their representative may request the immediate deletion of such data through the email privacidad@teamcore.net. Teamcore Solutions will proceed to delete them immediately once the situation has been verified.

12. Websites and Third-Party Services

The Teamcore Solutions website may contain links to third-party websites or integrate external services (maps, videos, social media, analytics tools, etc.). Access to such sites or services is subject to the privacy policies of each third party, over which Teamcore Solutions has no control or liability. The Data Subject is advised to review the privacy policies of third parties before providing their data on such sites.

The third-party integrations used on the Teamcore Solutions platform (infrastructure providers, analytical tools, payment services, etc.) are selected based on security and privacy criteria, and are subject to contractual agreements that guarantee the proper handling of data.

13. Privacy Notice and Consent

For users located in Mexico, this Policy also acts as a Privacy Notice pursuant to Article 15 of the LFPDPPP. By providing personal data through the website, contact forms, or any other channel enabled by Teamcore Solutions, the Data Subject declares having read and understood this Notice and expresses their consent to the processing of their data in accordance with the terms established herein, to the extent that such consent is the applicable legal basis.

In Colombia, Peru, and Chile, consent is understood to be granted at the time the data is provided with prior knowledge of this Policy, unless the processing is based on another of the enabling grounds provided for in the corresponding regulations. Teamcore Solutions shall maintain evidence of the consent granted in accordance with the standards required by each regulation.

14. Updates to this Policy

Teamcore Solutions reserves the right to modify this Policy at any time in order to adapt it to legislative, jurisprudential, or industrial developments, or to changes in its data processing practices. Any substantial modification will be communicated to the Data Subject through a prominent notice on the website at least ten (10) business days prior to its entry into force, or by email when such information is available. The current version will always be available at www.teamcore.net. Continued use of the services after notification of changes implies acceptance of the updated version.

15. Contact Information

Privacy Channel — Teamcore Solutions

Email: privacidad@teamcore.net
General email: contacto@teamcore.net
Website: www.teamcore.net

For requests related to the exercise of ARCO rights (Access, Rectification, Cancellation/Deletion, Opposition), revocation of consent, or any inquiry regarding the processing of your personal data, please write to the privacy email indicating in the subject line: "ARCO RIGHTS – [your name]".

Data protection authorities can be contacted directly in accordance with Section 8.1 of this Policy.

16. Governing Law and Jurisdiction

This Policy is governed by the data protection legislation of the jurisdiction from which the Data Subject accesses the services of Teamcore Solutions or from which the contractual relationship is entered into. In the event of a conflict between the provisions of this Policy and the applicable local regulations, the local regulations shall prevail to the extent that they are more favorable to the Data Subject.

Version 2.0  —  2025  |  contacto@teamcore.net