Privacy Policy and Processing of Personal Data
VALION S.A.S. — In force since July 2026. Adopted in accordance with Law 1581 of 2012, Decree 1074 of 2015 and any rules amending or implementing them, on the protection of personal data in Colombia.
1. Who the data controller is
VALION S.A.S., a company domiciled in Colombia, is the controller of the personal data described in this policy. VALION® is a registered trademark of VALION S.A.S.
Channel for personal data matters: soporte.valion.com.co. Every request related to this policy is received and answered through that channel.
2. Who it applies to
This policy covers three groups of data subjects, with different processing for each:
| Group | Who they are | Where their data comes from |
|---|---|---|
| Platform users | People on a customer team with access to VALION INSIGHTS or another of our tools. | Provided by the customer when requesting that the user be created. |
| Commercial contacts | People who receive our commercial and content communications. | Forms, events, direct commercial relationships or a previous contractual relationship. |
| Contacts within an AWS account | Identifiers of people that appear inside a customer AWS infrastructure (for example, an IAM user). | Read from the customer own account, with their express authorization. |
3. What personal data we process
From platform users: name, corporate email address, job title, phone number (if provided), the company they belong to, and technical records of their activity on the platform (sign-in date, actions performed) for security and support purposes.
From commercial contacts: name, email address, company and job title. In addition, the email interaction data described in the Commercial communications section.
From connected AWS accounts: configuration, cost and usage information. This information may include metadata that identifies people within the customer organization — for example, the name of an IAM user, the age of their credentials or whether they have multi-factor authentication enabled — because that is exactly what is needed to detect a security finding.
4. What we use the information for
- Delivering the contracted service: producing dashboards, savings recommendations and security findings; managing access and users.
- Support and assistance: answering requests, diagnosing incidents and following up.
- Service communications: operational notices, relevant changes, security alerts. These communications are part of the service and do not depend on a marketing subscription.
- Commercial and content communications: news, event invitations, technical material and service offers. See the next section.
- Service improvement: aggregate usage analysis to prioritize features. This analysis is not used to make automated decisions with legal effects on a person.
- Legal, accounting and contractual compliance.
5. Commercial email communications
This section describes how our email campaigns work in detail, because it is where most questions come up.
How we obtain your email address
From three sources only: (i) a form or registration where you gave us your details and authorized commercial contact; (ii) a direct commercial relationship with you or your company, including events and meetings; or (iii) a current or previous contractual relationship with VALION. We do not buy databases, we do not scrape third-party email addresses and we do not use lists of unknown origin.
What we measure on each send
Our sending platform records, per recipient: whether the email was delivered, whether it bounced, whether it was marked as spam, whether it was opened and whether any link was clicked. We use that information in aggregate to assess whether the content is useful, and individually only for the deliverability management described below.
Unsubscribes, bounces and complaints
All our commercial emails include a visible unsubscribe link, in addition to the technical header that allows unsubscribing with one click from the email client itself (Gmail, Outlook and similar). Unsubscribing is immediate and requires no justification, nor any reply from us.
When an address unsubscribes, hard bounces or reports the email as unwanted, it is added to a suppression list and stops receiving commercial communications. That list exists precisely so as not to contact you again: we keep your address for the sole purpose of guaranteeing that your decision is respected.
Content generated with the assistance of artificial intelligence
We design part of the content of our campaigns with artificial intelligence tools. The personal data of recipients is not sent to those models: personalization (for example, your name in the greeting) is applied at send time, on an already generated template, within our own infrastructure.
6. Consent and how to withdraw it
The processing of your data is based on the prior, express and informed consent you gave when providing us with your information, except in those cases where the law permits processing without it (a legal obligation, information required by a public entity in the exercise of its functions, or data necessary to perform a contract to which you are a party).
You may withdraw that consent at any time, in whole or in part, through the channel indicated in the How to exercise your rights section. The most common partial withdrawal — stopping commercial communications — is resolved immediately with the unsubscribe link in any of our emails.
7. Who the information is shared with
We do not sell, rent or assign personal data to third parties for commercial purposes. We share information only with providers that process it on our behalf, under our instructions and only as necessary to operate the service:
| Type of provider | What for |
|---|---|
| Cloud infrastructure | Hosting the platforms, the databases and the files. |
| Email delivery service | Delivering the communications and recording deliveries, bounces and unsubscribes. |
| Artificial intelligence models | Generating summaries of the technical information in the customer account and answering questions inside the product. |
| Competent authorities | Where there is a legal obligation, court order or valid administrative request. |
8. International transfer and transmission
Our infrastructure and that of our providers is hosted in data centers located outside Colombia, mainly in the United States. This means your personal data may be transmitted and stored abroad.
By authorizing the processing of your data, you authorize this international transmission. We work with providers that demonstrate security and confidentiality standards equivalent to or higher than those required by Colombian regulations, and our relationship with them is governed by contracts that limit the use of the information to the purposes described here.
9. How long we keep the information
- Platform user data: for as long as the account is active. When the relationship ends, it is deleted or kept only for the period required by legal, accounting or contractual obligations.
- Customer AWS account data: for as long as the account remains connected. On disconnection, all new collection ceases.
- Commercial contacts: for as long as the purpose remains valid and you have not withdrawn your consent.
- Suppression list: indefinitely. It is the only way to guarantee that an unsubscribe is respected permanently.
10. Your rights as a data subject
Under article 8 of Law 1581 of 2012, you have the right to:
- Know what personal data of yours we process, free of charge.
- Update and rectify data that is inaccurate, incomplete or out of date.
- Request proof of the consent you gave, except in those cases where the law does not require it.
- Be informed, on request, about the use we have made of your data.
- Withdraw consent and request deletion of your data, where no legal or contractual duty requires us to keep it.
- File complaints with the Superintendency of Industry and Commerce for breaches of data protection regulations. The law requires that you first exhaust the query or claim process directly with us.
- Access your personal data free of charge.
11. How to exercise your rights and how long we take to respond
Every query or claim is submitted through soporte.valion.com.co, stating your name, a contact detail and a description of your request. If you are acting on behalf of another person, you will need to provide evidence of that.
| Type of request | Maximum response time | Extension |
|---|---|---|
| Query (to know your data and the use made of it) | 10 business days | Up to 5 additional business days, informing you of the reason and the new date. |
| Claim (to correct, update, delete or withdraw consent) | 15 business days | Up to 8 additional business days, informing you of the reason and the new date. |
| Unsubscribe from commercial communications | Immediate | Not applicable — it is carried out with the unsubscribe link in the email. |
If a claim arrives incomplete, we will ask you for the missing information within the following five (5) business days. If two (2) months go by without a reply from you, we will understand that you have abandoned the request.
12. Information security
We apply reasonable technical, human and administrative measures to protect information against unauthorized access, loss, alteration or fraudulent use: encryption in transit and at rest, role-based access control with the minimum necessary privilege, individual authentication per user, activity logging, and separation of permissions between the components that face the public and those that process data.
No security measure is infallible. Should an incident compromising personal data occur, we will inform the affected data subjects and the Superintendency of Industry and Commerce on the terms required by law.
13. Cookies and browser storage
This help center is a static site and uses no tracking, analytics or advertising cookies.
Our product platforms use browser local storage exclusively to keep you signed in and to remember interface preferences. It is not shared with third parties and is not used for advertising. You can clear it from your browser at any time; the effect will be that you have to sign in again.
14. Minors
Our services are aimed exclusively at adults acting in a professional or business capacity. We do not knowingly collect data from minors. If we detect that we have, we will proceed to delete it.
15. Changes to this policy
We may update this policy when our practices or the applicable regulations change. The version in force is always the one published on this page, with its effective date at the top. Substantial changes — in particular those that modify the purposes of the processing — will be communicated in advance by email or through the platform, and where the law requires it, new consent will be requested.
If anything in this policy is unclear, write to us at soporte.valion.com.co. We would rather explain it than leave you wondering.