Our last update: May 2023
This policy explains when, why and how we collect personal information from the people who visit our website(s), sign up or purchase any of our services or request or contact us in any other manner. The policy also details the conditions under which we may disclose the information to others and how we keep it secure.
- We will never sell your data on.
- We will never share your data for marketing to by any third parties.
- We will always keep your personal data secure using strong encryption, abiding by data protection rules and by implementing good security practice.
We will never send you direct email marketing without your consent, our newsletter requires you to explicitly opt-in, you can opt-out at any time using the unsubscribe link contained within the email or through our communications channels.
2. About us
We are a Colombian company based in Colombia with operations on United Kingdom, Europe, USA, Panamá and Chile. Our legal information below:
Address: Calle 16 AA Sur # 42-91 Piso 15 Of 27, Medellín, Antioquia, Colombia
Phone: +57 601 917 1234 and +57 300 890 7554
Company Number in Colombia: 901.565.519-3
For the purpose of the Data Protection Act 2018 (the Act) and GDPR (General Data Protection Regulation), the data controller is AYCON SAS, a company registered in Colombia.
Our nominated representative for the purpose of the Act is Mr. Carlos Serrano.
3. When do we collect your personal data
We may collect data about you in the following ways:
- By filling in forms on any of our websites, this includes information provided at the time of registering to use our websites, subscribing to any of our services, posting material or requesting further services. We may also ask you for information when you enter a competition or promotion sponsored by us or if you report a problem with our site.
- If you contact us, we may keep a record of that correspondence.
- We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
- Details of transactions you carry out through our site and of the fulfilment of your orders.
- Visiting our sites, including, but not limited to, traffic data, location data and other communication data required for our own security, diagnostic, authentication and billing.
- Social networks interaction that you authorize.
4. What personal data do we collect
If you are simply viewing our website then we will collect the following information within our logs:
- IP Address (See cookies and IP addresses)
If you sign up to use our services we will then collect the following information:
- Email Address(s)
- Telephone number(s)
- IP address
- Payment details
While not actively collected we may store any other personal information that you may disclose during live chat, tickets or emails.
5. Cookies and IP Addresses
We collect IP address information for security (DDoS prevention, anti-hacking and fraud prevention), diagnostics and statistical analysis of traffic used for improvements to the performance and usability of our services, for GDPR purposes we collect this information under legitimate interest.
A cookie is a small file saved on your computer that is used to help store preferences and other information that is used by websites you may visit.
- Authentication of users when logging in or out of our services.
- Analysis of traffic to our website via Google Analytics (see Google Analytics).
- Tracking of website preferences.
- Third party services such live chat.
You can block cookies by activating the setting in your browser which allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies you may not be allowed access to all or parts of our site.
6. Where we store and process your personal data
The data that we collect from you is stored in Colombia, USA and Zürich servers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services.
By submitting your personal data, you agree to the processing of this data outside of the EEA and outside of USA.
7. How we Protect your personal data
We treat all data with the utmost care and take appropriate steps in compliance with data protection regulation to ensure it is kept safe.
- All data we collect is done so over encrypted connections (https).
- All data is stored behind state of the art firewalls managed by our security team.
- All systems storing personal data have access logging.
- All passwords are encoded at rest.
- All systems are subject to regular penetration testing and are monitored for vulnerabilities and attacks.
8. Uses we make of personal data
We use information held about you in the following ways:
- To verify your identity.
- To provide you with the products and services you have purchased from us.
- To carry out our obligations arising from any contracts entered into between you and us.
- To ensure that content from our site is presented in the most effective manner for your device.
- To respond to queries.
- To provide you with information, products or services that you request from us where you have consented to be contacted.
- To notify you about changes to our services.
- To send you marketing emails where you have given explicit consent.
- To display personalised Ads from us.
- To prevent fraud.
- To detect, prevent and diagnose potential security breaches.
9. Legal basis for the collection and processing
Data protection law sets out the conditions under which personal data can be collected and which we use as the basis for collection and processing, these include:
When you purchase a service, we need to collect personal data to fulfil our legal contractual obligation, for example: so we can manage and invoice your account and contact you for technical support purposes.
The law requires we collect and process data for certain purposes such as for keeping financial records (i.e. invoicing) and that we can comply with law enforcement requests for data.
We collect data under legitimate interest in a way that is reasonably expected as part of the day to day running of our business.
For example, we collect and log IP addresses for fraud protection and security as well as analysis of our site usage.
In certain cases, we may collect and process your data with your consent, for example our newsletter and hot offers emails. Consent to receive these can be withdrawn at any time.
10. How long we keep personal data
Your data will be kept until it is no longer required for the purpose of its collection.
At the end of the retention period the data will either be deleted or anonymised so it can no longer be linked back to an individual.
Personal data linked to purchases or any other financial transaction are kept for a minimum of 6 years as required by UK law to retain financial data.
11. Who we share personal data with
Like many websites we use a number of third-party services for functionality such as email sign-up and payment processing. The following is a list of companies we share data with on a day to day basis. This list does not include services we share anonymous data with or that provide services on an ad-hoc basis such as IT contractors. All the suppliers below have been carefully selected to ensure they provide suitable protections under GDPR.
Respond io inc
Respond io provide our live chat service available on our website, or many other ways to contact and support you, if you contact us by live chat your conversation will be recorded and archived on livechat inc’s servers, these archives may include personal information that you may have disclosed during a conversation.
Our newsletter and marketing email lists are managed through Mailchimp, or our own CRM that it’s managed in our own servers, these emails are opt-in, when you opt-in to our newsletter your name and email address will be added to our mailing list which is held securely on mailchimp’s servers, by opting in you agree to:
Transfer your contact information to MailChimp
Store your contact information in our MailChimp account
To being sent marketing emails from our MailChimp account (These will be for our services only)
To have tracked interactions for email marketing and ad placement purposes.
Emails are initiated and managed by ourselves.
We use Google Workspace for document storage, email, forms collect, meeting and recording, contacts, calendar and collaboration, in some instances your personal data may be stored on Google servers, any data stored there is encrypted and controlled by us.
12. Ads and Remarketing
We use Google AdWords remarketing services on our blog and forum to display our ads on third party websites (including Google) to previous visitors of those pages, this is done in the form of a cookie that contains anonymous data regarding your visit.
If you have a google account you can opt-out of receiving these ads here http://www.google.com/settings/ads
Google are also a member of the NAI (Network Advertising Initiative), you can also use their site to opt out here http://www.networkadvertising.org/managing/opt_out.asp
13. Google Analytics
Like many websites we use Google Analytics to collect anonymous data about the users of our sites such as how often they visit, what pages they visit, what time they visit, how long the stay and what country they are visiting from.
This data is collected using cookies and from your IP address, the resulting statistics are used for the following purposes:
- Improving website usability
- Tracking the success of marketing campaigns
- Pattern analysis
You can prevent Google Analytics from collecting this information by installing the google opt-out browser addon: Tools google dlpage gaoptout
To learn how Google uses data collected from our own and partner sites please see the following link: Policies google privacy partners
14. Newsletter and Marketing Emails
All our marketing emails are opt-in, we will never sell on your details or pass them on to third parties for marketing purposes. If you have opted in to receive these then you can opt out at any time in one of three ways:
- If you have received an email, click on the unsubscribe link located in the email footer.
- Log into your client area and select: Communication > Manage E-mail Subscriptions
- By contacting our customer services department.
15. Disclosure of your personal information
We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries.
We may disclose your personal information to third parties:
If AYCON SAS or substantially all of its assets are acquired by a third party, in which case personal data held by it (AYCON SAS) about its customers will be one of the transferred assets.
If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms and conditions of supply Terms and Conditions and other agreements; or to protect the rights, property, or safety of our customers or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
16. External links
Our site may, from time to time, contain links to and from the websites of our partners. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.