VALION VALION
Language English
Legal document

Privacy Policy and Processing of Personal Data

VALION S.A.S. — In force since July 2026. Adopted in accordance with Law 1581 of 2012, Decree 1074 of 2015 and any rules amending or implementing them, on the protection of personal data in Colombia.

Courtesy translation. This English version is provided for convenience. The Spanish version is the binding one; if the two ever disagree, the Spanish text prevails. This policy is governed by Colombian law, and the legal terms it uses have the meaning given to them by that law.
This policy applies to all relationships with VALION: customers, users of our platforms, commercial prospects and people who receive our email communications. If you are only interested in how we handle data in our email campaigns, go straight to Commercial communications.

1. Who the data controller is

VALION S.A.S., a company domiciled in Colombia, is the controller of the personal data described in this policy. VALION® is a registered trademark of VALION S.A.S.

Channel for personal data matters: soporte.valion.com.co. Every request related to this policy is received and answered through that channel.

2. Who it applies to

This policy covers three groups of data subjects, with different processing for each:

GroupWho they areWhere their data comes from
Platform usersPeople on a customer team with access to VALION INSIGHTS or another of our tools.Provided by the customer when requesting that the user be created.
Commercial contactsPeople who receive our commercial and content communications.Forms, events, direct commercial relationships or a previous contractual relationship.
Contacts within an AWS accountIdentifiers of people that appear inside a customer AWS infrastructure (for example, an IAM user).Read from the customer own account, with their express authorization.

3. What personal data we process

From platform users: name, corporate email address, job title, phone number (if provided), the company they belong to, and technical records of their activity on the platform (sign-in date, actions performed) for security and support purposes.

From commercial contacts: name, email address, company and job title. In addition, the email interaction data described in the Commercial communications section.

From connected AWS accounts: configuration, cost and usage information. This information may include metadata that identifies people within the customer organization — for example, the name of an IAM user, the age of their credentials or whether they have multi-factor authentication enabled — because that is exactly what is needed to detect a security finding.

What we never request or process: sensitive data as defined in article 5 of Law 1581 of 2012 (ethnic origin, religious or political beliefs, health data, biometric data, sexual orientation), card financial data, or access credentials to our customers AWS accounts. Our access to an AWS account is always through a read-only role that the customer creates and can revoke.

4. What we use the information for

5. Commercial email communications

This section describes how our email campaigns work in detail, because it is where most questions come up.

How we obtain your email address

From three sources only: (i) a form or registration where you gave us your details and authorized commercial contact; (ii) a direct commercial relationship with you or your company, including events and meetings; or (iii) a current or previous contractual relationship with VALION. We do not buy databases, we do not scrape third-party email addresses and we do not use lists of unknown origin.

What we measure on each send

Our sending platform records, per recipient: whether the email was delivered, whether it bounced, whether it was marked as spam, whether it was opened and whether any link was clicked. We use that information in aggregate to assess whether the content is useful, and individually only for the deliverability management described below.

Unsubscribes, bounces and complaints

All our commercial emails include a visible unsubscribe link, in addition to the technical header that allows unsubscribing with one click from the email client itself (Gmail, Outlook and similar). Unsubscribing is immediate and requires no justification, nor any reply from us.

When an address unsubscribes, hard bounces or reports the email as unwanted, it is added to a suppression list and stops receiving commercial communications. That list exists precisely so as not to contact you again: we keep your address for the sole purpose of guaranteeing that your decision is respected.

Unsubscribing from commercial communications does not cancel the operational notices of any service you have contracted (for example, a security notice or a platform change), nor does it affect your access to it.

Content generated with the assistance of artificial intelligence

We design part of the content of our campaigns with artificial intelligence tools. The personal data of recipients is not sent to those models: personalization (for example, your name in the greeting) is applied at send time, on an already generated template, within our own infrastructure.

6. Consent and how to withdraw it

The processing of your data is based on the prior, express and informed consent you gave when providing us with your information, except in those cases where the law permits processing without it (a legal obligation, information required by a public entity in the exercise of its functions, or data necessary to perform a contract to which you are a party).

You may withdraw that consent at any time, in whole or in part, through the channel indicated in the How to exercise your rights section. The most common partial withdrawal — stopping commercial communications — is resolved immediately with the unsubscribe link in any of our emails.

7. Who the information is shared with

We do not sell, rent or assign personal data to third parties for commercial purposes. We share information only with providers that process it on our behalf, under our instructions and only as necessary to operate the service:

Type of providerWhat for
Cloud infrastructureHosting the platforms, the databases and the files.
Email delivery serviceDelivering the communications and recording deliveries, bounces and unsubscribes.
Artificial intelligence modelsGenerating summaries of the technical information in the customer account and answering questions inside the product.
Competent authoritiesWhere there is a legal obligation, court order or valid administrative request.

8. International transfer and transmission

Our infrastructure and that of our providers is hosted in data centers located outside Colombia, mainly in the United States. This means your personal data may be transmitted and stored abroad.

By authorizing the processing of your data, you authorize this international transmission. We work with providers that demonstrate security and confidentiality standards equivalent to or higher than those required by Colombian regulations, and our relationship with them is governed by contracts that limit the use of the information to the purposes described here.

9. How long we keep the information

10. Your rights as a data subject

Under article 8 of Law 1581 of 2012, you have the right to:

11. How to exercise your rights and how long we take to respond

Every query or claim is submitted through soporte.valion.com.co, stating your name, a contact detail and a description of your request. If you are acting on behalf of another person, you will need to provide evidence of that.

Type of requestMaximum response timeExtension
Query (to know your data and the use made of it)10 business daysUp to 5 additional business days, informing you of the reason and the new date.
Claim (to correct, update, delete or withdraw consent)15 business daysUp to 8 additional business days, informing you of the reason and the new date.
Unsubscribe from commercial communicationsImmediateNot applicable — it is carried out with the unsubscribe link in the email.

If a claim arrives incomplete, we will ask you for the missing information within the following five (5) business days. If two (2) months go by without a reply from you, we will understand that you have abandoned the request.

12. Information security

We apply reasonable technical, human and administrative measures to protect information against unauthorized access, loss, alteration or fraudulent use: encryption in transit and at rest, role-based access control with the minimum necessary privilege, individual authentication per user, activity logging, and separation of permissions between the components that face the public and those that process data.

No security measure is infallible. Should an incident compromising personal data occur, we will inform the affected data subjects and the Superintendency of Industry and Commerce on the terms required by law.

13. Cookies and browser storage

This help center is a static site and uses no tracking, analytics or advertising cookies.

Our product platforms use browser local storage exclusively to keep you signed in and to remember interface preferences. It is not shared with third parties and is not used for advertising. You can clear it from your browser at any time; the effect will be that you have to sign in again.

14. Minors

Our services are aimed exclusively at adults acting in a professional or business capacity. We do not knowingly collect data from minors. If we detect that we have, we will proceed to delete it.

15. Changes to this policy

We may update this policy when our practices or the applicable regulations change. The version in force is always the one published on this page, with its effective date at the top. Substantial changes — in particular those that modify the purposes of the processing — will be communicated in advance by email or through the platform, and where the law requires it, new consent will be requested.

If anything in this policy is unclear, write to us at soporte.valion.com.co. We would rather explain it than leave you wondering.