TERMS AND CONDITIONS OF USE OF THE FRESHCODE APP AND THE WEBSITE WWW.FRESHCODE.COM.CO

CLAUSE 1. CONTRACTUAL RELATIONSHIP

1.1. FRESHCODE sets out below these Terms of Use that govern the access to or use that the user, as an individual, from any country in the world, makes through applications and/or websites, in order to access the content, products and services, including, but not limited to:
(i) Building a large-scale support network among users; (ii) Collecting personal information to be provided in emergency situations, (iii) Push notification by email to the emergency contacts selected by each user.
1.2. The user understands and accepts that in order to access the Services, certain terms and conditions will be established, which must be accepted at the time of registering in the Freshcode application or on the web portal WWW.FRESHCODE.COM.CO.

CLAUSE 2. CONDITIONS FOR ACCESSING OR USING THE SERVICES.

2.1. By entering the Portals, the User agrees to be bound by and to comply with the terms and conditions established for the provision of services offered by FRESHCODE. If the user does not accept these Conditions, they may not access or use the Services.
2.2. FRESHCODE may modify the Conditions whenever it deems appropriate or whenever it becomes necessary to amend them in order to guarantee the proper functioning of the App and the web portal for users; such modifications will take effect after FRESHCODE publishes the corresponding information.
2.3. FRESHCODE does not guarantee continuous and uninterrupted access to any of the Portals, nor that such access will be free of faults, or that the service or the server that runs it will be free of viruses or other harmful agents. When the user accesses the Portals, it will be their responsibility to take the appropriate measures to prevent and/or correct viruses or other existing harmful agents. FRESHCODE is exempt from any liability for damages of any kind that may arise from the lack of availability or continuity of operation of the Portals or the services.
2.4. The user will be solely responsible for the use of the information they enter on the Portals.

CLAUSE 3. LINKS BETWEEN FRESHCODE AND OTHER SITES ON THE INTERNET

3.1. FRESHCODE may facilitate access to other Internet sites through links contained in the Portals; but the inclusion of these on the FRESHCODE site does not imply any contractual or commercial relationship between FRESHCODE and the operator of the linked site.
3.2. FRESHCODE is not responsible for the content of any of these sites. FRESHCODE does not guarantee the products or services offered by the linked site. Therefore, any transaction that the user or provider carries out with them is performed solely and exclusively between the user or provider and the advertiser of the linked site, under their own responsibility and autonomy.

CLAUSE 4. PERSONAL INFORMATION OF THE USER OR PROVIDER

4.1. To access certain specific services of the Portals, the user must be registered, on a voluntary basis.
4.2. The user authorizes the data collected through the Portals, concerning their personal information, to be used by FRESHCODE, its employees, representatives, agents and contractors, in accordance with the provisions established in FRESHCODE's Data Processing Policy, which is published on the website www.freshcode.com.co
4.3. The user authorizes FRESHCODE and any of its affiliates, for commercial, administrative, financial, statistical and informational purposes and those established in the preceding point, between companies, between these and the competent authorities, and for information administration purposes through duly authorized third parties, to consult, store, manage, confirm, correct, modify, transfer and report to the data centers it deems necessary, or to any other authorized entity located within or outside the national territory, the information provided and filled in, and that results from all operations directly or indirectly derived from or related to the use of the Portals.
4.4. All the user's personal information included in databases may be subject to modification, update, correction or disabling, upon consideration of the request submitted by the user at any time, in accordance with the procedure established in the data processing policy.
4.5. The user declares that they are fully aware of their rights in relation to the personal information included in databases, especially in relation to habeas data and the right of petition, in accordance with the provisions of Law 1581 of 2012, Decree 1377 of 2013 and other rules that modify, add to or supplement them.

CLAUSE 5. THE SERVICES

5.1. Through the web Portals or applications for electronic devices, the information provided by each user may be stored so that, at the time an emergency situation arises, by simply scanning the QR code designed, provided and used exclusively by FRESHCODE, the emergency contacts selected will be notified of said situation. The services are made available solely for the user.
5.2. Profile. Subject to compliance with these Conditions, FRESHCODE grants the user a non-exclusive, revocable, non-transferable account or profile for access to and use of the Portals on their personal device or computer, solely in connection with their use of the Services. FRESHCODE reserves any right not expressly granted herein.
5.3. Restrictions. The user may not: (i) remove any copyright notice, trademark or other proprietary notice from any part of the Services or the Portals; (ii) reproduce, modify, prepare derivative works based on the Services, distribute, lease, resell, transfer, publicly display, publicly perform, transmit, retransmit or otherwise exploit the Services or the Portals, except as expressly permitted by FRESHCODE; (iii) cause or launch any program or script with the purpose of extracting, indexing, analyzing or otherwise data-mining any part of the Services, or unduly overloading or blocking the operation and/or functionality of any aspect of the Services; or (iv) attempt to gain unauthorized access to or damage any aspect of the Services or their related systems or networks.
5.4. Provision of the Services. The user understands and accepts that the services will be provided in accordance with the provisions established in the special conditions.
5.5. Third-Party Services and Content. The Services may be made available or accessible in connection with third-party services and content (including advertising) that FRESHCODE does not control. The user acknowledges that different conditions and privacy policies may apply to their use of such third-party services and content. FRESHCODE does not endorse such third-party services and content, and under no circumstances will FRESHCODE be liable for any product or service of such third-party providers. Additionally, Apple Inc., Google, Inc. and/or their respective subsidiaries or international affiliates will be third-party beneficiaries in the event that you access the Services using Applications developed for mobile devices with iOS or Android systems, respectively. These third-party beneficiaries are not responsible for the provision or support of the Services in any way. Your access to the Services using these devices is subject to the conditions established in the applicable terms of service of the third-party beneficiaries.

CLAUSE 6. USE OF THE SERVICES

6.1. User accounts. In order to use most aspects of the Services, the user must register and maintain an active personal account, the registration of which does not have a required minimum age. Account registration requires that the user provide FRESHCODE with certain personal information, such as their name, address, mobile phone number, blood type, allergies, medical conditions, prescribed medications, email address and telephone number of the contacts registered as emergency contacts, among others. The user agrees to keep the information in their account accurate, complete and up to date, otherwise access to and provision of the Services may become impossible. The user is responsible for all activity that occurs on their Account and agrees to keep their Account's username and password secure and secret at all times.
6.2. Network access and devices. The user is responsible for obtaining the network access necessary to use the Services. Rates and fees for data and messages from their mobile network may apply if the user accesses or uses the Services from a wireless device, and the user will be responsible for such rates and fees. The user is responsible for acquiring and updating compatible hardware or devices necessary to access and use the Services and the Portals, and any updates thereto. FRESHCODE does not guarantee that the Services, or any part thereof, will function on any particular hardware or device. In addition, the Services may be subject to malfunctions or delays inherent to the use of the Internet and electronic communications.

CLAUSE 7. OBLIGATIONS OF THE USER

7.1. Keep confidential and make proper use of their account, their username and private access key, which is non-transferable.
7.2. Notify FRESHCODE by electronic means, to the email …………….., in any of the following situations:
(a) Loss or theft of their account or private key.
(b) Unauthorized use or access to their account.
(c) Failures, errors or unusual events upon receiving any message related to an order executed by the user through the electronic system, or that has been received and/or executed through it.
(d) Cancellation of orders not issued by the user, or of inaccuracies or disagreements in the transmission of information.
7.3. Change the personal, non-transferable private key provided by FRESHCODE during the first authorized access to the Portals.
7.4. Assume responsibility for the access keys and user accounts that they may delegate or disclose to third parties.
7.5. Respect the industrial property and copyright owned by FRESHCODE over any distinctive sign, information, material or content on the Portals. The user acknowledges and accepts that use of or access to the site does not grant the user any right whatsoever over FRESHCODE's trademarks, trade names or distinctive signs of any kind.
7.6. Accept the modifications to the terms and conditions in order to continue using the Portals, and waive any present or future claim arising from such changes to the terms and conditions.

CLAUSE 8. LIMITATIONS OF LIABILITY

8.1. FRESHCODE will not be held liable for any of the following circumstances:
(a) Advertising of goods or services not provided directly by FRESHCODE or any of its affiliates;
(b) Intermittency or suspension of the operation of the Portals.
(c) Suspension of the user or provider for reasons not attributable to FRESHCODE.
(d) Changes without prior notice to the content of the Portals.
(e) Links or connections to other Web pages not owned by FRESHCODE.
(f) Terminating this service and preventing access to the Portals when the user has lost such status or has not accepted the modifications to the terms and conditions.
(g) Failures in accessing the application or web portal due to lack of mobile data or internet connection on the devices used to access it.
(h) Damage caused to clothing items by attaching FRESHCODE's exclusive QR code.

FRESHCODE
COMMERCIAL MANAGER
JUAN DAVID HINCAPIE CORREAL
Tel. +57 320 665 4239
Comercial@freshcode.com.co



FRESHCODE DATA PROCESSING POLICIES AND PROCEDURES

I. OBJECTIVE OF THE PERSONAL DATA PROCESSING POLICY

FRESHCODE is a company committed to the security of the personal information of its users, affiliates, beneficiaries, suppliers, employees and the general public, and, in order to strictly comply with the regulations in force on the protection of Personal Data, especially the provisions established in Law 1581 of 2012, Decree 1377 of 2013 and other provisions that modify, add to or supplement them, hereby presents the Data Processing Policy regarding the protection of Personal Data (hereinafter the "Policy") in relation to the collection, use and transfer thereof, by virtue of the authorization granted by the Data Subjects. All areas of FRESHCODE that are involved or in any way engage in the Processing of personal data must observe and be subject to the provisions of this Policy; any gap will be filled by the Law. This document applies to all databases that contain personal data and that are subject to Processing and Protection by FRESHCODE. In this Policy, FRESHCODE details the general guidelines taken into account in order to protect the Personal Data of the Data Subjects, such as the purpose of collecting the information, the rights of the Data Subjects, the area responsible for handling complaints and claims, as well as the procedures that must be completed to know, update, correct and archive the information. FRESHCODE, in compliance with the constitutional right to Habeas Data, only collects Personal Data when it has been previously authorized by its Data Subject, implementing for that purpose clear measures regarding the confidentiality and privacy of Personal Data.

II. DEFINITIONS FOR PURPOSES OF THE PERSONAL DATA PROCESSING POLICY

For the purposes of this Policy, the definitions set out in Law 1581 of 2012 will be taken into account, transcribed below:
a) Data Subject: Natural or legal person whose Personal Data is subject to Processing.
b) Data Controller: Natural or legal person, public or private, who by itself or in association with others, decides on the database and/or the Processing of the data. In this specific case, this will be FRESHCODE.
c) Data Processor: Natural or legal person, public or private, who by itself or in association with others, carries out the Processing of personal data on behalf of the Data Controller.
e) Personal data: Any information linked to or that may be associated with one or more identified or identifiable natural persons.
f) Private data: Data that, due to its intimate or reserved nature, is only relevant to the Data Subject.
g) Public data: Data that is not semi-private, private or sensitive. Public data is considered to include, among others, data relating to the civil status of persons, their profession or occupation, and their status as a merchant or public servant. By their nature, public data may be contained, among others, in public records, public documents, official gazettes and bulletins, and duly executed court rulings that are not subject to reservation.
h) Semi-private data: Data that does not have an intimate, reserved or public nature, and whose knowledge or disclosure may be of interest not only to its Data Subject but also to a certain sector or group of people.
i) Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation, transfer, transmission or deletion.
j) Transmission: Processing of personal data that involves the communication thereof within or outside the territory of the Republic of Colombia, when its purpose is to carry out Processing by the processor on behalf of the Controller, in accordance with the purpose authorized and contained in this policy.
k) Personal Data Protection Processing Policies: Refers to this document.
l) Sensitive Data: Data that affects the privacy of the Data Subject or whose misuse may generate discrimination against them.

III. PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA

In accordance with article 4 of Law 1581 of 2012, the principles governing the Processing of Personal Data are:
(a) Principle of legality in data Processing matters: The Processing referred to in Law 1581 of 2012 is a regulated activity that must be subject to the provisions set forth therein and in other provisions that develop it.
(b) Principle of purpose: Processing must serve a legitimate purpose in accordance with the Constitution and the Law, which must be communicated to the Data Subject.
(c) Principle of freedom: Processing may only be carried out with the prior, express and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate releasing such consent.
(d) Principle of accuracy or quality: Information subject to Processing must be truthful, complete, accurate, up to date, verifiable and comprehensible. The Processing of partial, incomplete, fragmented data, or data that leads to error, is prohibited.
(e) Principle of transparency: Processing must guarantee the Data Subject's right to obtain from the Data Controller or the Data Processor, at any time and without restrictions, information regarding the existence of data concerning them.
(f) Principle of restricted access and circulation: The administration of personal data is subject to the limits derived from the nature of the data, the provisions of this policy, and the principles of personal data administration, especially the principles of the temporality of information and the purpose of the database. Personal data, except for public information, may not be made accessible via the Internet or other means of mass disclosure or communication, unless access is technically controllable so as to provide restricted knowledge only to the data subjects or authorized users in accordance with this policy.
(g) Principle of security: Information subject to Processing by the Data Controller or Data Processor referred to in this law must be handled with the technical, human and administrative measures necessary to provide security to the records, preventing their adulteration, loss, unauthorized or fraudulent consultation, use or access.
(h) Principle of confidentiality: All persons involved in the Processing of personal data that is not public in nature are obligated to guarantee the confidentiality of the information, even after their relationship with any of the duties comprising the Processing has ended, and may only supply or communicate personal data when this corresponds to the development of activities authorized under this law and under its terms.

IV. AUTHORIZATION FOR THE PROCESSING OF PERSONAL DATA

In order to comply with data processing regulations regarding FRESHCODE's databases, the following measures were taken, as provided in article 10 of Decree 1377 of 2013:
1. FRESHCODE, at the time of collecting Personal Data, requests authorization from the Data Subjects, informing them of the specific purposes of the Processing for which such consent is obtained.
The Authorization for processing personal data must be obtained beforehand, expressly and with the consent of the Data Subject, in order to carry out the processing of their personal data, without prejudice to legal exceptions. The Authorization will always be governed by the principles established in the law and in this policy. FRESHCODE will not require Authorization when the law so permits. The authorization of the Data Subjects may be given through: (i) websites, or (ii) through the Freshcode App, through which it is understood that, had the Data Subject not given such authorization, the data would not be stored in the Database.
FRESHCODE will keep proof of such authorizations in a suitable manner, respecting the principles of confidentiality and privacy of the information.
Legal exceptions to obtaining authorization: The Data Subject's Authorization must be prior, express and informed, except for the following exceptions:
a) Information required by a public or administrative entity in the exercise of its legal functions or by judicial order.
b) Data of a public nature.
c) Cases of medical or health emergency.
d) Processing of information Authorized by Law for historical, statistical or scientific purposes.

V. PURPOSES OF PERSONAL DATA PROCESSING

1. User Databases
Users are the ones who enable FRESHCODE's corporate purpose to be carried out; therefore it is essential to collect, store and use their personal data in order to understand, in essence, the nature of the service to be provided to them; customers' personal data are necessary to maintain constant contact with them. The following are the Personal Data of the Data Subjects that are collected by FRESHCODE, in furtherance of its corporate purpose, and included in its user databases: (i) Type of identity document; (ii) Identity document number; (iii) Gender; (iv) First and Last Names; (v) Date of birth; (vi) Home address; (vii) blood type (viii) medical conditions (ix) allergies (x) Prescribed Medications (xi) Cell phone; (xii) Email address; (xiii) EPS (health insurer); (xiv) Emergency contacts.
1.1. Purposes of Personal Data Processing The Personal Data collected by FRESHCODE are included in a Database to which FRESHCODE personnel have access, in the exercise of their duties, and it is noted that under no circumstances are they authorized to Process the information for purposes other than those described herein:
a) Provide the services of (i) Building a large-scale support network among users; (ii) Collecting personal information to be provided in emergency situations, (iii) Push notification by email to the emergency contacts selected by each user.
b) Inform about changes to our products or services;
c) Evaluate the quality of our products and services;
d) Carry out commercial agreements, events or institutional programs directly or in association with third parties;
e) Provide our products and services required directly or through third parties, and receive feedback;
f) Georeferencing activities and statistical studies;
g) Send information about activities carried out by FRESHCODE, or send information deemed of interest through different means;
h) Comply with legal reporting obligations to administrative entities, as well as to the competent authorities that require it;
i) Support FRESHCODE's audit processes;
j) Provide information about service scheduling, follow up on services and evaluate the provision of services;
k) Conduct satisfaction surveys;
l) Carry out the procedures for handling compliments, thanks, requests, complaints and claims ("FAPQRS") submitted to FRESHCODE;
m) Enter into agreements with third parties.
The information provided by the Data Subject will only be used for the purposes set out herein, and once the need for Processing the Personal Data ceases, it may be archived by FRESHCODE in a secure manner, to be disclosed only when the law so requires.
2. Supplier Databases
FRESHCODE requires various suppliers of products and/or services in order to comply with its contractual obligations; to that extent, in order to contract suppliers and for FRESHCODE to comply with its obligations, certain personal data must be collected from:
a) Suppliers.
b) Potential suppliers.
Therefore, FRESHCODE requires collecting, storing, using, circulating, and in general carrying out activities related to the Processing of personal data that allow it to guarantee compliance with its obligations and other activities in order to properly, efficiently and fully carry out its corporate purpose. The Supplier Database is mainly, but not exclusively, composed of:
1. Name.
2. Tax identification number.
3. General and specific identification data of the contacts of each one.
4. Economic activity engaged in.
4. Data of Minors:
The processing of personal data must always respect the rights of minors. To obtain Authorization, where applicable, parents, or otherwise legal representatives, have the authority to authorize or not authorize the processing of the personal data of minors, provided that:
1. It responds to and respects the best interests of minors.
2. Respect for the fundamental rights of minors is ensured.
3. Due Authorization for the Processing of the minor's personal data is obtained from their parents or, failing that, their legal representative; after the minor has exercised their right to be heard, taking into account the minor's maturity, autonomy and capacity to understand the matter.
6. Topic applicable to all of FRESHCODE's Databases
By accepting this Policy, the Data Subject authorizes that the Personal Data will be used only for the purposes set out herein, and understands that FRESHCODE will not sell, license, transmit or disclose it outside of FRESHCODE, except (i) if the Data Subject expressly authorizes it to do so, (ii) if it is necessary to allow our partners, affiliated companies or agents to provide the services we have entrusted to them, (iii) in order to provide our products or services, (iv) if it is related to a merger, consolidation, acquisition, divestiture or other restructuring process, or (v) as required or permitted by law.
In order to implement the purposes described above, the Data Subject's personal data may be disclosed for the purposes set out in this Policy to FRESHCODE personnel and other persons and companies as applicable.
Additionally, FRESHCODE informs that once the need for processing the data ceases, it may be archived in a secure manner so that it is only disclosed when applicable in accordance with the law. Such data will not be deleted despite the Data Subject's request when its retention is necessary for compliance with an obligation.

VI. PROCEDURES FOR THE PROCESSING OF PERSONAL DATA

The Personal Data included in FRESHCODE's Database come from information collected in the course of activities carried out due to commercial or other ties with users, suppliers and/or the general public.
Channels such as our website, social networks, satisfaction and service surveys, electronic messages and business partners, among others, are the means through which FRESHCODE obtains the Personal Data referred to in this Policy.
The Databases administered by FRESHCODE are subject to strict security measures, compliance with which must be guaranteed by FRESHCODE. The Databases contained in electronic files, whether on staff computers or in FRESHCODE's backup, are password-protected, which only employees who need to access them for the ordinary performance of their duties may know. Any kind of breach or threat to the databases must be immediately reported to the systems area and the administrative area, who must report it as promptly as possible to the Superintendence of Industry and Commerce.
Procedure to know, update, correct, delete information or revoke the Authorization:
In order to protect and maintain the confidentiality of the Personal Data of the Data Subjects, FRESHCODE determines that the procedure for handling petitions, inquiries or claims by Data Subjects — petitions, complaints, claims, requests for update, deletion of data, compliments and acknowledgments, together with the request for revocation of the Authorization — will be received at: (i) The email address: …………………. (ii) Filling out the Compliments, Acknowledgments, Petitions, Complaints and Claims Form ("FAPQRS"), available on FRESHCODE's website, at the link: WWW.FRESHCODE.COM.CO
These requests will be handled and processed under the following procedure:
1. Inquiries. Inquiries will be handled within the legal term granted for that purpose. When it is not possible to handle the inquiry within said term, the interested party will be informed before the expiration of the ten (10) business days from the date of receipt of the inquiry, explaining the reasons for the delay and indicating the date on which their inquiry will be handled, which in no case may exceed the five (5) business days following the expiration of the first term.
2. Claims, updates or corrections: The Data Subject may submit claims, updates or corrections when the information must be corrected, deleted or updated, and/or in the event that FRESHCODE is failing to comply with the duties contained in this policy or the law. The claim will be processed under the following rules:
a. The claim must include a description of the facts giving rise to the claim, the address, and the supporting documents to be relied upon.
b. If the person who receives the claim is not competent to resolve it, they will forward it to the appropriate party within a maximum term of three (3) business days and will inform the interested party of the situation.
c. Once the complete claim is received, it will be classified as "claim in process" and the reason for it, within a term not exceeding three (3) business days. This label will remain until the claim is decided.
d. The maximum term to handle the claim will be fifteen (15) business days counted from the day following the date of its receipt. When it is not possible to handle the claim within said term, the interested party will be informed of the reasons for the delay and the date on which their claim will be handled, which in no case may exceed the five (5) business days following the expiration of the first term. 3. Request for archiving or disabling of data: The Data Subject of the personal data has the right to request its archiving or disabling in any of the following events:
a. They consider that the data is not being processed in accordance with the principles, duties and obligations provided for in the regulations in force.
b. They are no longer necessary or relevant for the purpose for which they were collected.
c. The period necessary for fulfilling the purposes for which they were collected has been exceeded. This archiving of personal information will be carried out in accordance with what was requested by the Data Subject in the records, databases or Processing carried out by FRESHCODE. Notwithstanding the foregoing, FRESHCODE may deny the archiving of data when:
d. The archiving or disabling of data hinders judicial or administrative proceedings related to tax obligations, the investigation and prosecution of crimes, or the enforcement of administrative sanctions.

VII. INFORMATION AND MECHANISMS PROVIDED BY FRESHCODE

AS DATA CONTROLLER
FRESHCODE
Company name
………..
Tax ID
………..
Domicile
Armenia - Quindío
Address
…………
Telephone
Armenia: 320 665 4239
Website
https://www.freshcode.com.co

VIII. AREA RESPONSIBLE FOR THE PROCESSING OF PERSONAL DATA

The Customer Service Area will be in charge of receiving petitions, complaints or claims from Data Subjects. This area will be responsible for carrying out the internal handling necessary to guarantee a clear, efficient and timely response to the Data Subject.

IX. RIGHTS OF THE PERSONAL DATA SUBJECT

In accordance with art. 8 of Law 1581 of 2012, the Data Subject of the Personal Data will have the following rights:
a) To know, update and correct their personal data before the Data Controllers or Data Processors. This right may be exercised, among others, with respect to partial, inaccurate, incomplete, fragmented data, or data that leads to error, or that whose Processing is expressly prohibited or has not been authorized;
b) To request proof of the authorization granted to the Data Controller, except when it is expressly exempted as a requirement for Processing, in accordance with the provisions of article 10 of this law;
c) To file complaints with the Superintendence of Industry and Commerce for violations of the provisions of this law and other rules that modify, add to or supplement it;
d) To revoke the authorization and/or request the archiving of the data when the Processing does not respect the constitutional and legal principles, rights and guarantees. Revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that, in the Processing, the Controller or Processor has engaged in conduct contrary to this law and to the Constitution;
e) To access their personal data that has been subject to Processing free of charge.
In accordance with art. 20 of Decree 1377 of 2013, the exercise of the aforementioned Rights may be carried out by:
1. The Data Subject, who must sufficiently prove their identity through the various means made available to them by the controller.
2. Their successors, who must prove such status.
3. The representative and/or attorney-in-fact of the Data Subject, upon prior proof of representation or power of attorney.
4. By stipulation in favor of another or for another.
5. The rights of children or adolescents will be exercised by the persons authorized to represent them.

X. DUTIES OF THE DATA CONTROLLER

In accordance with art. 17 of Law 1581 of 2012, the Data Controller will have the following duties:
a) Guarantee the Data Subject, at all times, the full and effective exercise of the right of habeas data;
b) Request and retain, under the conditions provided for in this law, a copy of the corresponding authorization granted by the Data Subject;
c) Duly inform the Data Subject about the purpose of the collection and the rights afforded to them by virtue of the authorization granted;
d) Keep the information under the security conditions necessary to prevent its adulteration, loss, unauthorized or fraudulent consultation, use or access;
e) Guarantee that the information provided to the Data Processor is truthful, complete, accurate, up to date, verifiable and comprehensible;
f) Update the information, promptly communicating to the Data Processor all developments regarding the data previously provided to it, and adopt other measures necessary so that the information provided to it remains up to date; g) Correct the information when it is incorrect and communicate the relevant matter to the Data Processor;
h) Provide the Data Processor, as applicable, only with data whose Processing has been previously authorized in accordance with the provisions of this law;
i) Require the Data Processor, at all times, to respect the security and privacy conditions of the Data Subject's information;
j) Process inquiries and claims submitted under the terms established in this law; k) Inform the Data Subject, upon their request, about the use given to their data;
l) Inform the data protection authority when violations of security codes occur and there are risks in the administration of the Data Subjects' information;
m) Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.

XI. TERM OF THE POLICY

This Personal Data Processing Policy of FRESHCODE is effective as of ………… of …………… 2021.
The Personal Data or databases subject to Processing will be in effect for the contractual term of the product or service, during the period in which the purpose for which they were collected persists, plus the term established by law.

XII. OTHER PROVISIONS

1. FRESHCODE, for purposes of the Processing of Personal Data of children and adolescents, will respect their best interests and will also ensure respect for their fundamental rights. Additionally, FRESHCODE will request authorization from the Representative of the child or adolescent in order to carry out the Processing of their Personal Data.
FRESHCODE
Date: