What data we collect, what we use it for and what you can do about it.
Last updated:
Bitsideas processes personal data when you fill in the contact form, email us or reach us on WhatsApp. This policy explains what we collect, what for, for how long and what you can do about it. It applies only to this website, not to data we process on behalf of our clients inside their own systems.
Bitsideas is not required to appoint a Data Protection Officer for the activity of this website. Article 37.1 GDPR only requires one from public authorities, from those whose core activity is regular and systematic monitoring of data subjects on a large scale, and from those processing special categories of data on a large scale. Processing arising from a contact form falls into none of those cases.
Data protection enquiries are handled at consultorias@bitsideas.com.
We do not collect special categories of data — health, beliefs, biometrics — through this site. Please do not include any in the form message.
We do not build profiles or make automated decisions with your data. We do not send marketing to anyone who has not asked for it.
We do not sell, rent or transfer your data to third parties for commercial purposes. It may be accessed, as processors and under contract with the safeguards of article 28 GDPR, by the technology providers that support our operation:
We may also disclose data to public authorities where there is a legal obligation.
BITSIDEAS, LLC is incorporated in the United States and has no permanent establishment in the European Union. Article 27 GDPR waives the duty to appoint a representative where processing is occasional, does not include special categories of data and poses no risk to people's rights and freedoms. The processing arising from this site — a contact form with no sensitive data — falls under that exemption.
If in future Bitsideas regularly directs its offering at residents of the European Union, it will appoint a representative under that article and publish their details here.
Bitsideas operates from the United States and Colombia and serves Latin America, Spain and the United Kingdom; most of its providers are US-based, so international data transfers do occur. These rely on the standard contractual clauses approved by the European Commission, on the EU-US Data Privacy Framework where the provider is certified, or on the equivalent safeguards provided by Colombian law.
You may at any time request access to your data, its rectification or erasure, restriction of or objection to processing and portability, as well as withdraw any authorisation you gave us, by writing to consultorias@bitsideas.com stating the right you wish to exercise. We reply within the statutory deadlines: fifteen business days in Colombia and one month in the European Union and the United Kingdom.
If you believe we have not handled your request properly, you may complain to the competent supervisory authority: the Superintendencia de Industria y Comercio in Colombia, the Agencia Española de Protección de Datos in Spain or the Information Commissioner’s Office in the United Kingdom.
We apply technical and organisational measures to protect your data against unauthorised access, loss or alteration: encryption in transit, role-based access control and providers with recognised certification. No system is infallible, but we work to standard industry practice and review our measures periodically.
Registration of databases with the Colombian Superintendencia de Industria y Comercio is only required from controllers whose total assets exceed 100,000 UVT. Bitsideas reviews annually whether it passes that threshold and, if so, registers and updates its databases within the deadlines set by the Superintendencia.
We may update this policy to reflect legal or operational changes. The date of the last revision appears at the top. If a change materially affects the processing of your data, we will tell you through the channel you used to contact us.