Tu Gerente Financiero S.A.S. — Privacy Policy
Last updated: May 2026
1. Data controller
The data controller for personal data collected through the tugerentefinanciero.app platform and its mobile applications is:
| Field | Details |
|---|---|
| Legal name | Tu Gerente Financiero S.A.S. |
| NIT | [pending registration] |
| Domicile | Bogota D.C., Colombia |
| Privacy email | privacidad@tugerentefinanciero.app |
2. Personal data we collect
| Category | Specific data |
|---|---|
| Identification data | Full name, type and number of identity document, date of birth, nationality, photograph of document. |
| Contact data | Email address, mobile phone number, city of residence. |
| Financial data | Monthly income, monthly expenses, economic activity, occupation, credit history, credit bureau score, outstanding obligations. |
| Browsing data | IP address, device type, operating system, browser, cookies, approximate geolocation data. |
| Biometric data | Facial biometric data used exclusively for identity verification (KYC). Not stored permanently. |
3. Purposes of data processing
Personal data will be processed for the following purposes:
- Credit assessment: Analysis of repayment capacity, internal scoring, credit bureau inquiries, and determination of loan conditions.
- Loan management: Disbursement, payment plan administration, collection management, and issuance of debt clearance certificates.
- Service communications: Sending transactional notifications, payment reminders, account statements, and service-related communications.
- Legal and regulatory compliance: Responding to requests from judicial or administrative authorities, fulfilling tax obligations, and reporting to credit bureaus.
- Fraud prevention and AML/CFT: Identity verification (KYC), restricted lists screening, due diligence, and anti-money laundering and counter-terrorism financing measures.
- Service improvement: Aggregate statistical analysis, scoring algorithm improvement, and user experience optimization.
4. Legal basis for processing
Data processing is based on the following legal grounds:
- Data subject consent: Express authorization granted by the data subject at the time of registration and loan application.
- Contract performance: Processing necessary for the performance of the loan agreement entered into between TGF and the Client.
- Legal obligation: Compliance with anti-money laundering regulations, credit bureau reporting, and regulatory authority requirements.
- Legitimate interest: Fraud prevention, credit risk management, and Platform security.
5. Data transfers to third parties
TGF may transfer or transmit personal data to the following third parties, who act as data processors or recipients:
| Third party | Purpose |
|---|---|
| Credit bureaus | Credit history inquiry and reporting (specific entities vary by country of operation). |
| Regulatory authorities | Compliance with legal requirements from superintendencies, judicial authorities, and oversight bodies. |
| Technology providers (AWS) | Cloud storage and processing with contractual data protection clauses. |
| Funding partners | Loan evaluation, approval, and disbursement. |
| Identity verification providers (KYC) | Data subject identity validation through biometric and document technology. |
All international transfers are carried out with adequate safeguards in accordance with the applicable data protection legislation in each jurisdiction.
6. Data retention
Personal data will be retained for the following periods:
| Data type | Retention period |
|---|---|
| Contractual data (identification, financial, credit) | During the term of the contract + 10 years after termination (legal obligation and statute of limitations). |
| AML/CFT prevention data | During the term of the relationship + 10 years (applicable anti-money laundering regulations). |
| Consent records | Indefinitely (proof of authorization granted). |
| Browsing data (IP, cookies, device) | Maximum 12 months from collection. |
7. Security measures
TGF implements technical, organizational, and administrative measures to protect personal data against unauthorized access, loss, alteration, or destruction, including:
- Encryption in transit and at rest: TLS 1.3 for data in transit and AES-256 for data at rest.
- Role-based access control: Role-based access control (RBAC) with multi-factor authentication for all operators.
- Access auditing: Logging and monitoring of all access to personal data with full traceability.
- AWS certified infrastructure: Hosted on Amazon Web Services infrastructure with SOC 2, ISO 27001, and ISO 27018 certifications.
8. Data subject rights
As a data subject, you have the following general rights, without prejudice to any additional rights recognized by the legislation of your country:
- Access: Know what personal data of yours is being processed by TGF.
- Rectification: Request the correction of inaccurate, incomplete, or outdated data.
- Erasure / Deletion: Request the deletion of data when there is no legal obligation to retain it.
- Objection: Object to the processing of your data for specific purposes.
- Portability: Obtain a copy of your data in a structured, commonly used format.
- Withdrawal of consent: Revoke the authorization granted, except where there is a legal or contractual obligation to retain the data.
9. Contact channels
To exercise your data protection rights or submit inquiries and complaints related to the processing of your personal information, you may contact us through:
| Channel | Details |
|---|---|
| privacidad@tugerentefinanciero.app | |
| Platform | "My account" > "Privacy" section in the app or website |
| Response time | Maximum 15 business days from receipt of the request (unless country-specific deadlines apply) |
The request must include: full name, identity document number, detailed description of the request, and contact information for response.
10. Cookies
The Platform uses cookies and similar technologies to improve the user experience, perform statistical analysis, and personalize content. For detailed information about the types of cookies used, their purpose, and how to manage them, please see our Cookie Policy.
11. Country-specific provisions — Colombia
Legal framework
- Ley 1581 de 2012 — Personal Data Protection.
- Decreto 1377 de 2013 — Partial regulation of Ley 1581.
- Decreto 1074 de 2015 — Unified Regulatory Decree for the Commerce, Industry and Tourism Sector (compilatory).
Data protection authority
Superintendencia de Industria y Comercio (SIC).
ARCO rights
Access, Rectification, Cancellation (Deletion), and Objection, pursuant to Ley 1581 de 2012.
Procedure
Written request addressed to privacidad@tugerentefinanciero.app, including full name, national ID number, description of the request, and contact information.
Response deadlines
- Inquiries: 10 business days.
- Complaints: 15 business days.
RNBD registration
National Database Registry with the SIC: pending registration.
International transfers
Carried out in accordance with the standards set forth in Ley 1581 de 2012, article 26, and Circular 005 de 2017 of the SIC, ensuring adequate levels of protection.
12. Country-specific provisions — Peru
Legal framework
- Ley 29733 — Personal Data Protection Law.
- Decreto Supremo 003-2013-JUS — Regulation of Ley 29733.
Data protection authority
Autoridad Nacional de Proteccion de Datos Personales (ANPDP), attached to the Ministerio de Justicia y Derechos Humanos.
ARCO rights
Access, Rectification, Cancellation, and Objection, pursuant to Ley 29733.
Response deadline
20 business days from receipt of the request.
Database
Personal data bank registered with the ANPDP.
International transfers
Carried out with adequate safeguards pursuant to Ley 29733 and its regulation, ensuring that the recipient country has equivalent levels of protection.
13. Country-specific provisions — Ecuador
Legal framework
- Ley Organica de Proteccion de Datos Personales (LOPDP) — Published in 2021.
- Implementing regulation of the LOPDP.
Data protection authority
Autoridad de Proteccion de Datos Personales (APDP).
Data subject rights
Access, rectification, erasure, objection, portability, and the right not to be subject to decisions based solely on automated processing.
Response deadline
15 business days from receipt of the request.
International transfers
Require adequate safeguards under the LOPDP, including standard contractual clauses or express consent of the data subject.
14. Country-specific provisions — Panama
Legal framework
- Ley 81 de 2019 — On Personal Data Protection.
- Decreto Ejecutivo 285 de 2021 — Regulation of Ley 81.
Data protection authority
Autoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI).
ARCO rights
Access, Rectification, Cancellation, and Objection, pursuant to Ley 81 de 2019.
Response deadline
30 business days from receipt of the request.
International transfers
Carried out with express consent of the data subject or with adequate safeguards pursuant to Ley 81 de 2019 and its regulatory decree.