The KII Public Sale is live!Join now →
KiiChain Logo
App

Privacy Policy

1. OBJECTIVE

To establish the guidelines, principles, policies, procedures, controls, and mechanisms that Kii applies to the Processing of personal data, in order to:

1. Guarantee the constitutional right to Habeas Data (art. 15 of the Political Constitution), that is, the right of every person to know, update, rectify, and delete information collected about them in databases or files.

2. Comply with Statutory Law 1581 of 2012, Decree 1377 of 2013 (compiled in Sole Regulatory Decree 1074 of 2015, Title 2, Chapter 25), Law 1266 of 2008, Law 1273 of 2009, Law 2300 of 2023, and the instructions issued by the Superintendency of Industry and Commerce (SIC) in its Single Circular and external circulars.

3. Define the legitimate purposes of the Processing, the service channels, and the procedures for the exercise of the Data Subjects' rights.

4. Implement a demonstrated accountability model that allows the Company to show, before the Data Subject and the authority, the existence of appropriate and effective measures to comply with the regulations.

5. Prevent, detect, and manage security incidents affecting personal data.

This Policy is mandatory for all administrators, employees, contractors, interns, suppliers, Data Processors, and third parties who, in the course of their relationship with the Company, access personal data under its responsibility. Kii, its Temporary Unions and Consortia are companies and entities that store and collect personal data, in accordance with Article 7 of Decree 1377 of 2013, and therefore require obtaining your authorization so that, freely, in advance, expressly, voluntarily, and duly informed, you allow our companies and entities to collect, gather, store, use, circulate, delete, process, compile, exchange, treat, update, and dispose of the data that has been provided and incorporated into the different banks or databases. The objective that Kii, as well as each of the consortia, Temporary Unions, and parent companies that comprise it, pursues is to comply with and give effect to the Constitutional Right that every person has to know, update, and rectify the information that has been collected about them in databases or files, by establishing policies, procedures, and controls for their due protection, providing the information required by data subjects, and attending to petitions, complaints, and claims from each of them.

2. SCOPE OF APPLICATION

2.1. Material scope. This Policy applies to all Processing of personal data of natural persons contained in databases and files —physical, electronic, in the cloud, in distributed ledgers, or in any other medium— administered by Kii or by Data Processors acting on its behalf.

2.2. Subjective scope. It covers, among others, data of: candidates for vacancies; employees and their beneficiaries; former employees; apprentices and interns; contractors and their collaborators; shareholders and investors; members of governing bodies; clients and users of the Company's platforms, applications, and services; suppliers; legal representatives and contact persons of legal entities; visitors to facilities and websites; and any other third party whose data is processed.

2.3. Organizational scope. It applies to all areas, departments, branches, agencies, consortia, temporary unions, and joint ventures in which the Company participates, insofar as it acts as data controller or determines the conditions of the Processing. When the Processing is carried out jointly with another entity, the allocation of roles and obligations will be documented in writing.

2.4. Exclusions. It does not apply to: (i) databases for strictly personal or domestic use; (ii) information about legal entities that does not allow the identification of a natural person; (iii) intelligence and counterintelligence databases; and (iv) data of a public nature under legal terms, without prejudice to its Processing being subject to the principles of this Policy.

2.5. Territoriality. This Policy is governed by Colombian law and applies to Processing carried out in Colombian territory, as well as that carried out by Data Processors abroad on behalf of the Company. When the Company offers goods or services to persons located in other jurisdictions, it will adopt the additional measures required by the applicable regulations therein, without this reducing the level of protection established herein.

3. REGULATORY FRAMEWORK

• Political Constitution of Colombia, arts. 15 and 20.

• Law 1581 of 2012 — General regime for the protection of personal data.

• Decree 1377 of 2013, compiled in Decree 1074 of 2015 (Title 2, Chapter 25).

• Law 1266 of 2008 — Financial, credit, and commercial Habeas Data.

• Law 1273 of 2009 — Computer crimes and protection of information and data.

• Law 527 of 1999 and Decree 2364 of 2012 — Data messages and electronic signatures.

• Law 1480 of 2011 — Consumer Protection Statute.

• Law 2300 of 2023 — Regime for contact with consumers and processing of contact data.

• Decree 090 of 2018 — National Database Registry (RNBD).

• SIC Single Circular (Title V) and applicable external circulars, particularly those relating to international transfers and incident reporting.

• Judgments C-1011 of 2008 and C-748 of 2011 of the Constitutional Court.

• Sector regulations applicable to the Company regarding the prevention of money laundering and financing of terrorism (AML/CFT/PF), including reporting and information retention obligations before the UIAF.

4. DEFINITIONS

For the interpretation of this Policy, the definitions of Law 1581 of 2012 and Decree 1074 of 2015 are adopted. In particular:

• Authorization: prior, express, and informed consent of the Data Subject to carry out the Processing.

• Privacy notice: verbal or written communication addressed to the Data Subject, with information about the existence of this Policy, how to access it, and the purposes of the Processing.

• Database: organized set of personal data subject to Processing.

• Personal data: any information linked or that can be associated with one or several identified or identifiable natural persons (names, identity documents, contact details, images, voice, online identifiers, IP addresses, device identifiers, wallet addresses when they allow a person to be identified, among others).

• Public data: data that is not semi-private, private, or sensitive; for example, data relating to civil status, profession or occupation, status as a merchant or public servant, and data contained in public records, public documents, and final court judgments not subject to reservation.

• Semi-private data: data that is not of an intimate or reserved nature, whose knowledge is of interest to the Data Subject and to a certain sector of persons (for example, financial and credit data).

• Private data: data that, due to its intimate or reserved nature, is only relevant to the Data Subject.

• Sensitive data: data that affects the privacy of the Data Subject or whose misuse may generate discrimination; this includes racial or ethnic origin, political orientation, religious or philosophical convictions, membership in unions, social or human rights organizations, data relating to health, sexual life, and biometric data.

• Biometric data: data obtained from physical, physiological, or behavioral characteristics that allow the unique identification of a person (fingerprint, facial geometry, iris, voice, signature pattern). At the Company, these are typically processed in identity verification (KYC) and access control processes.

• Data Processor ("Encargado"): a natural or legal person, public or private, that, by itself or in association with others, carries out the Processing of personal data on behalf of the data controller.

• Data Controller ("Responsable"): a natural or legal person, public or private, that, by itself or in association with others, decides on the database and/or the Processing. For purposes of this Policy, Kii acts as data controller, without prejudice to the fact that, in certain services, it may act as Data Processor for its clients, in which case it will be subject to their documented instructions.

• Data Subject: natural person whose personal data is subject to Processing.

• Processing: any operation or set of operations on personal data, such as collection, storage, use, circulation, transmission, transfer, or deletion.

• Transmission: communication of personal data from the data controller to a Data Processor, within or outside national territory, so that the latter carries out the Processing on behalf of the data controller.

• Transfer: sending of personal data to a recipient who is, in turn, a data controller and is located within or outside the country.

• Anonymization: irreversible process that prevents the identification of the Data Subject. Anonymized data is not considered personal data.

• Pseudonymization: Processing that prevents attributing the data to a Data Subject without additional information. Pseudonymized data remains personal data.

• Security incident: any event that causes or may cause the destruction, loss, alteration, disclosure, or unauthorized access to personal data.

• Profiling: automated Processing of personal data aimed at evaluating, analyzing, or predicting aspects relating to a natural person.

• Terminological clarification: the expressions "Data Processor" or "Procesador de Datos" used in previous Company documents should be understood in accordance with the definitions of Data Controller and Data Processor adopted herein, according to the role applicable in each case.

5. GUIDING PRINCIPLES

All Processing carried out by the Company is subject to the following principles (art. 4, Law 1581 of 2012), applied in a harmonious and comprehensive manner:

1. Legality: Processing is a regulated activity that must be subject to the law.

2. Purpose: Processing responds to legitimate, specific, explicit purposes previously informed to the Data Subject.

3. Freedom: Processing is only carried out with the prior, express, and informed consent of the Data Subject, or by legal or judicial mandate that relieves such consent.

4. Veracity or quality: information must be truthful, complete, accurate, up to date, verifiable, and understandable. The Processing of partial, incomplete, fragmented data, or data that may lead to error, is prohibited.

5. Transparency: the Data Subject is guaranteed the right to obtain, at any time and without restrictions, information about the existence of data concerning them.

6. Restricted access and circulation: data may only be processed by authorized persons or by the Data Subject themselves; it will not be available on the Internet or other means of mass disclosure unless access is technically controllable.

7. Security: information is handled with the technical, human, and administrative measures necessary to provide security, avoiding its adulteration, loss, unauthorized or fraudulent consultation, use, or access.

8. Confidentiality: all persons involved in the Processing of non-public data are obliged to guarantee the confidentiality of the information, even after their relationship with the Company has ended.

Additionally, as a voluntary internal standard, the Company adopts the principles of:

9. Demonstrated accountability: maintaining documentary evidence of compliance.

10. Minimization: processing only data that is adequate, relevant, and limited to what is necessary for the informed purpose.

11. Time limitation: retaining data only for the time necessary or legally required.

12. Privacy by design and by default: incorporating privacy controls from the conception of products, services, contracts, and technological developments.

6. TYPES OF DATA PROCESSED

6.1. Identification and contact data: first and last names, type and number of identity document, date and place of birth, nationality, signature, physical address, email, telephone.

6.2. Socioeconomic and contractual data: occupation, position, employer, tax information, financial and asset information, credit history (with specific authorization), banking and payment method data.

6.3. Employment data: résumé, academic background, references, employment history, performance evaluations, social security affiliation information, beneficiary data.

6.4. Technical and browsing data: IP address, device and session identifiers, operating system, browser, approximate geolocation, audit logs, cookies, and similar technologies.

6.5. Identity verification data (KYC/AML): image of the identity document, photograph or verification video (selfie/liveness check), derived biometric data, information on Politically Exposed Person (PEP) status, restrictive and sanctions lists, source and destination of funds.

6.6. Data associated with digital assets: public wallet addresses, transaction identifiers and associated metadata, when they allow a natural person to be identified or made identifiable.

6.7. Sensitive data: the Company processes sensitive data only exceptionally, with express authorization and prior information to the Data Subject about its sensitive nature and their right not to answer, in the following cases:

• Biometric data for identity verification and access control.

• Health data for the management of occupational health and safety, absenteeism, occupational medical examinations, and social security affiliation.

• Image and voice captured through video surveillance systems or call recording.

• Fingerprint or facial recognition data on access devices.

6.8. Data of children and adolescents. The Company's services are directed exclusively at persons over 18 years of age. The Company does not intentionally collect data from minors. When it must exceptionally process such data (for example, beneficiaries of employees in social security or compensation funds), it will do so (i) respecting the best interests of the minor, (ii) respecting their fundamental rights, and (iii) with the prior authorization of the legal representative, after having heard the minor's opinion when possible. If it is detected that data of a minor has been collected without legitimate grounds, it will be deleted immediately.

7. PURPOSES OF THE PROCESSING

The Company processes personal data for the following purposes, depending on the category of Data Subject:

7.1. General purposes (all Data Subjects)

1. Identify and validate the identity of the Data Subject.

2. Manage the contractual, commercial, or employment relationship and perform the obligations derived from it.

3. Address inquiries, petitions, complaints, claims, and requests.

4. Comply with legal, accounting, tax, contractual, regulatory, and reporting obligations before competent authorities.

5. Prevent, detect, and investigate fraud, misuse of services, crimes, and illicit activities.

6. Comply with obligations regarding the prevention of money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction (AML/CFT/PF), including due diligence, transaction monitoring, and reporting to the UIAF and other authorities.

7. Exercise and defend the Company's rights in administrative, judicial, or arbitral proceedings.

8. Prepare statistical, analytical, and aggregate information, preferably anonymized.

9. Conduct internal and external audits and address requirements from control entities.

10. Manage the security of information and facilities.

7.2. Clients and users of platforms and services

11. Create, manage, and validate user accounts and profiles.

12. Provide, operate, maintain, and improve the products, platforms, applications, and services.

13. Process transactions, payments, collections, refunds, and reconciliations.

14. Send transactional, service, technical, security, and administrative communications.

15. Provide technical support and user assistance, including recording of interactions.

16. Conduct satisfaction surveys and market studies.

17. Send commercial, promotional, and advertising communications about the Company's own products or those of its partners.

18. Segment and personalize the user experience and content.

19. Assess the risk, capacity, and transactional profile of the user, with human oversight over decisions that produce relevant legal effects.

7.3. Candidates, employees, and former employees

20. Carry out selection processes, verification of references and background checks in accordance with the law, and retain résumés in a talent bank for the authorized period.

21. Manage the employment relationship: hiring, payroll, benefits, changes, training, performance evaluation, wellbeing, discipline, and termination.

22. Comply with obligations before the social security system, compensation funds, ARL (occupational risk insurers), funds, and labor and tax authorities.

23. Manage the occupational health and safety system.

24. Issue employment certifications and address requests from third parties authorized by the Data Subject or by law.

25. Manage compensation, incentive, and benefit plans.

7.4. Suppliers, contractors, and partners

26. Carry out selection, onboarding, evaluation, and due diligence processes for suppliers.

27. Manage contract execution, invoicing, payments, and withholdings.

28. Verify compliance with legal, tax, and social security obligations.

7.5. Shareholders, investors, and governing bodies

29. Maintain the shareholders' book and corporate records.

30. Call and manage meetings of corporate bodies, distribute profits, and exercise corporate rights.

31. Comply with disclosure and reporting duties to authorities and counterparties.

7.6. Visitors and facilities

32. Control access to facilities and ensure the security of persons and property, including video surveillance through duly signposted closed-circuit systems.

7.7. The Company will not process personal data for purposes other than those informed herein or those compatible with them. Any new purpose will require new authorization or, where applicable, prior communication to the Data Subject under the terms of art. 5 of Decree 1377 of 2013.

8. AUTHORIZATION OF THE DATA SUBJECT

8.1. General rule. The Company will request and retain the prior, express, and informed authorization of the Data Subject, except in legally excepted cases.

8.2. Means of obtaining. Authorization may be granted by: (i) signed physical document; (ii) electronic form with a non-pre-checked acceptance box; (iii) data message, email, or SMS; (iv) voice recording with verbal confirmation; (v) unequivocal conduct of the Data Subject that reasonably allows concluding that authorization was granted.

8.3. Content of the authorization. When requesting it, the Data Subject will be informed of: (i) the Processing to which their data will be subject and its purpose; (ii) the optional nature of the response when it involves sensitive data or data of minors; (iii) the rights available to them as a Data Subject; and (iv) the identification, physical or electronic address, and telephone number of the data controller.

8.4. Proof and retention. The Company will retain proof of the authorization through technical mechanisms that guarantee its integrity, availability, and traceability (record of date, time, IP, version of the accepted text, and means used). Such proof will be retained while the Processing subsists and, at least, for the statute of limitations period of actions arising from the relationship with the Data Subject.

8.5. Cases in which authorization is not required (art. 10, Law 1581 of 2012): a) Information required by a public or administrative entity in the exercise of its legal functions, or by judicial order; b) Data of a public nature; c) Cases of medical or sanitary emergency; d) Processing authorized by law for historical, statistical, or scientific purposes; e) Data related to the Civil Registry of Persons.

In these cases, the Processing will likewise be subject to the principles of this Policy.

8.6. Data collected before June 27, 2013. With respect to data collected before the entry into force of Decree 1377 of 2013, and for which it was not possible to obtain authorization, the Company applied and will apply alternative mechanisms to communicate with the Data Subject (publication on its website and direct communication when possible), informing them of their right to request deletion and understanding that the absence of any objection, together with the continuity of the relationship, allows the Processing to continue under the terms of the law.

8.7. Revocation. The Data Subject may revoke the authorization at any time, in whole or in part (by purposes), except when there is a legal or contractual duty that prevents deletion. The Company will process the revocation under the terms of section 11.

8.8. Privacy notice. When it is not possible to make this Policy available to the Data Subject at the time of collection, a Privacy Notice will be used in accordance with the model in Annex 2, and this Policy will remain permanently available at [URL].

9. RIGHTS OF DATA SUBJECTS

In accordance with art. 8 of Law 1581 of 2012, the Data Subject has the right to:

1. Know, update, and rectify their personal data before the data controller or the Data Processor, especially when it is partial, inaccurate, incomplete, fragmented, misleading, or when its Processing is prohibited or unauthorized.

2. Request proof of the authorization granted, except when the law does not require it.

3. Be informed, upon request, about the use given to their data.

4. File complaints with the SIC for violations of the law, once the consultation or claim procedure before the Company has been exhausted.

5. Revoke the authorization and/or request the deletion of the data when the Processing does not respect the principles, rights, and legal guarantees, or when the SIC has determined that conduct contrary to the law occurred.

6. Access their personal data that has been subject to Processing free of charge. The Company will handle at least one free monthly inquiry per Data Subject; additional inquiries may generate a charge for reproduction costs, when permitted by law.

As an additional standard, the Company will address, to the extent technically and legally feasible, requests for data portability, objection to Processing for marketing purposes, and human review of automated decisions that produce relevant legal effects.

Standing. Rights may be exercised by: (i) the Data Subject, proving their identity; (ii) their successors, proving such capacity; (iii) the representative or attorney-in-fact of the Data Subject; and (iv) whoever acts under a stipulation in favor of another. The rights of minors will be exercised by their legal representatives.

10. RESPONSIBLE AREA AND SERVICE CHANNELS

10.1. Personal Data Protection Officer. The Company designates the Compliance Officer as the Personal Data Protection Officer, responsible for:

• Addressing inquiries, claims, and requests from Data Subjects.

• Coordinating the assessment of privacy risks and impacts.

• Leading the management of security incidents and reports to the authority.

• Training personnel and verifying compliance with this Policy.

10.2. Official channels.

• Email: [email protected]

• Web form: https://forms.gle/9q4NyLeUczz4gcp3A

• Physical address: Calle 93 13 42 Of 308, Bogotá D.C.

Any request received through a different channel will be forwarded internally to the Data Protection Officer within the following business day of its receipt, without altering the legal terms, which will be counted from the initial receipt.

11. PROCEDURES FOR THE EXERCISE OF RIGHTS

11.1. Inquiries (art. 14, Law 1581 of 2012)

1. The Data Subject or their representative submits the inquiry through any of the channels, indicating their name, identity document, response channel, and purpose of the inquiry.

2. The Company verifies the identity of the requester through proportional and non-excessive mechanisms.

3. Term: the inquiry will be addressed within a maximum term of fifteen (15) business days from the date of receipt.

4. When it is not possible to address it within said term, the interested party will be informed before its expiration, stating the reasons and the date on which it will be addressed, which may not exceed five (5) business days following the expiration of the first term.

11.2. Claims (art. 15, Law 1581 of 2012)

1. The claim is submitted through a request addressed to the Company containing: (i) identification of the Data Subject; (ii) description of the facts giving rise to the claim; (iii) address or notification channel; and (iv) documents to be relied upon.

2. Incomplete claim: if the claim is incomplete, the requester will be asked within the following five (5) days of its receipt to correct the deficiencies. If two (2) months have elapsed since the request without the requester providing the required information, the claim will be deemed withdrawn.

3. Lack of competence: if the Company is not competent to resolve it, it will refer it to the appropriate party within a maximum term of two (2) business days and will inform the interested party accordingly.

4. "Claim in process" legend: once the complete claim is received, a legend stating "claim in process" and the reason for it will be included in the database within a term not exceeding two (2) business days. This legend will remain until the claim is decided.

5. Decision term: the claim will be addressed within a maximum term of twenty (20) business days from the day following the date of its receipt. When this is not possible, the interested party will be informed of the reasons for the delay and the response date, which may not exceed eight (8) business days following the expiration of the first term.

11.3. Deletion and revocation

1. The request is processed in accordance with the claim procedure.

2. The Company will not proceed with deletion when: (i) the Data Subject has a legal or contractual duty to remain in the database; (ii) deletion would hinder judicial or administrative proceedings related to tax obligations, investigations, or sanctions; or (iii) there is a legal obligation to retain the information (for example, retention of employment, accounting, tax, or AML/CFT due diligence information). In these cases, the Data Subject will be informed with reasons.

3. When deletion is applicable, it will extend to backups and to Data Processors, who will be instructed in writing. The Company will retain only a minimum record of the request and its processing as evidence of compliance.

11.4. Procedural requirement

The Data Subject may only file a complaint with the Superintendency of Industry and Commerce once the consultation or claim procedure before the Company has been exhausted (art. 16, Law 1581 of 2012).

11.5. Record and traceability

Every request will be recorded in the Personal Data PQRS (Petitions, Complaints, Claims, and Requests) Log, with a filing number, date of receipt, type of request, applicable term, date and content of the response, and person responsible for handling it. This record will feed the quarterly reports to the RNBD, when the Company is required to register with it.

12. DUTIES OF THE COMPANY

12.1. As data controller (art. 17, Law 1581 of 2012)

1. Guarantee the Data Subject, at all times, the full and effective exercise of the right to Habeas Data.

2. Request and retain a copy of the respective authorization granted by the Data Subject.

3. Duly inform the Data Subject about the purpose of the collection and the rights available to them by virtue of the authorization granted.

4. Retain the information under the security conditions necessary to prevent its adulteration, loss, unauthorized or fraudulent consultation, use, or access.

5. Ensure that the information provided to the Data Processor is truthful, complete, accurate, up to date, verifiable, and understandable.

6. Update the information, promptly communicating to the Data Processor all changes, and adopting the measures necessary to keep the information up to date.

7. Rectify the information when it is incorrect and communicate this to the Data Processor.

8. Provide the Data Processor only with data whose Processing has been previously authorized.

9. Require the Data Processor, at all times, to respect the security and privacy conditions of the Data Subject's information.

10. Process inquiries and claims within the terms set forth by law.

11. Adopt an internal manual of policies and procedures to ensure due compliance with the law, especially for handling inquiries and claims.

12. Inform the Data Processor when certain information is under discussion by the Data Subject, once the claim has been filed and the respective procedure has not concluded.

13. Inform, upon the Data Subject's request, about the use given to their data.

14. Inform the data protection authority when security breaches occur and there are risks in the administration of Data Subjects' information.

15. Comply with the instructions and requirements issued by the Superintendency of Industry and Commerce.

12.2. When the Company acts as Data Processor (art. 18, Law 1581 of 2012)

1. Guarantee the Data Subject the full and effective exercise of Habeas Data.

2. Retain the information under the necessary security conditions.

3. Timely carry out the update, rectification, or deletion of data.

4. Update information reported by data controllers within five (5) business days of its receipt.

5. Process inquiries and claims made by Data Subjects.

6. Adopt an internal manual of policies and procedures.

7. Record in the database the legend "claim in process" as regulated by law.

8. Insert in the database the legend "information under judicial discussion" when applicable.

9. Refrain from circulating information that is being disputed by the Data Subject and whose blocking has been ordered by the SIC.

10. Allow access to information only to persons who may have access to it.

11. Inform the SIC when security breaches occur.

12. Comply with the instructions and requirements of the SIC.

13. Process data only in accordance with the documented instructions of the data controller and not use it for its own purposes.

12.3. Duties of personnel and third parties

• Sign confidentiality agreements and commitments to comply with this Policy.

• Access data only to the extent strictly necessary for their duties (principle of least privilege and need to know).

• Immediately report any incident or suspected incident to the Data Protection Officer.

• Refrain from extracting, copying, transmitting, or storing personal data on devices, accounts, or services not authorized by the Company.

13. INFORMATION SECURITY

The Company implements a set of technical, human, and administrative measures that are reasonable and proportional to the risk.

13.1. Technical measures

• Encryption of data in transit (TLS 1.2 or higher) and at rest for sensitive data and credentials.

• Identity and access management with role-based profiles, multi-factor authentication for privileged access, and periodic permission reviews.

• Network segmentation, firewalls, protection against malicious code, and vulnerability and patch management.

• Immutable audit logs of access to and operations on personal data, with a minimum retention period of 12 months.

• Encrypted backups, with periodic restoration testing and a business continuity and disaster recovery plan.

• Prevention of information leakage and control over removable media.

13.2. Administrative and organizational measures

• Inventory and classification of information assets and personal databases.

• Complementary policies: information security, access control, incident management, acceptable use of resources, clean desk and clean screen, retention and document disposal.

• Due diligence and contractual clauses with suppliers and Data Processors; periodic evaluation of their privacy performance.

• Mandatory data protection training upon hiring and at least once a year, with attendance and evaluation records.

• Annual internal audits on compliance with this Policy.

13.3. Physical measures

• Access control to facilities, data centers, and physical files.

• Locked custody of documents containing personal data and secure destruction (shredding) at the end of their life cycle.

13.4. The Company does not guarantee the absolute security of information, as no system is invulnerable; it commits, however, to applying the required standard of diligence and to continuously improving its controls.

14. SECURITY INCIDENT MANAGEMENT

1. Detection and internal reporting. Every collaborator or third party must immediately report any incident or suspicion to the Data Protection Officer through the channel [email protected], within a period not exceeding twenty-four (24) hours from becoming aware of it.

2. Containment and assessment. The incident response team will contain the event, preserve the evidence, and assess the scope: affected data, number of Data Subjects, root cause, risk of harm.

3. Report to the authority. The Company will report the incident to the Superintendency of Industry and Commerce through the National Database Registry or another enabled means, within fifteen (15) business days following the moment it is detected and brought to the attention of the person or area in charge, in accordance with the SIC's current instructions.

4. Notification to Data Subjects. When the incident implies a significant risk to the rights of Data Subjects, they will be informed clearly and promptly, indicating the nature of the incident, the data compromised, the measures adopted, and recommendations to mitigate the impact.

5. Other notifications. The need to inform insurers, financial institutions, criminal authorities (Law 1273 of 2009), sector CSIRTs, and contractual counterparties will be assessed.

6. Closure and lessons learned. The incident will be documented in the Incident Registry, with a corrective action plan, persons responsible, and dates, and its implementation will be verified.

15. TRANSMISSION AND TRANSFER OF DATA

15.1. Third parties with whom information is shared. The Company may communicate personal data to: (i) companies within the same corporate group; (ii) technology, cloud, hosting, cybersecurity, analytics, messaging, and support providers; (iii) identity verification, fraud prevention, and restrictive list screening providers; (iv) financial institutions and payment processors; (v) legal and accounting advisors, auditors, and insurers; (vi) financial and credit information operators, with specific prior authorization; and (vii) competent administrative and judicial authorities, in the exercise of their legal functions.

15.2. Transmission agreements. Every transmission to a Data Processor will be documented through a contract or clause containing, at a minimum: (i) the scope and purposes of the Processing; (ii) the activities the Data Processor will carry out on behalf of the Data Controller; (iii) the Data Processor's obligations toward the Data Subject and toward the Data Controller; (iv) the duty to apply the Data Controller's Policy; (v) the required security measures; (vi) the prohibition on using the data for its own purposes; (vii) the subcontracting regime, subject to prior authorization; (viii) the duty to assist in addressing rights and incidents; and (ix) the return or deletion of the data upon termination of the relationship.

15.3. International transfers. The transfer of personal data to countries that do not provide adequate levels of protection is prohibited, unless one of the exceptions in art. 26 of Law 1581 of 2012 is met (express and unequivocal authorization of the Data Subject; exchange of medical information for health or public hygiene reasons; banking or stock market transfers in accordance with applicable law; transfers agreed in international treaties to which Colombia is a party; transfers necessary for the execution of a contract between the Data Subject and the Data Controller; and transfers legally required to safeguard the public interest or the recognition of a right in judicial proceedings). Alternatively, a declaration of conformity will be requested from the SIC.

Before any international transfer, the Data Protection Officer will verify: (i) whether the destination country is on the list of countries with adequate standards published by the SIC; (ii) whether a legal exception applies; or (iii) whether a declaration of conformity is required. The analysis and its outcome will be documented.

15.4. Contractual clauses. In international transmissions, protection clauses equivalent to the Colombian standard will be signed, including audit rights, incident notification, and restrictions on unauthorized government access.

16. NATIONAL DATABASE REGISTRY (RNBD)

In accordance with Decree 090 of 2018, the obligation to register databases with the RNBD falls on companies and non-profit entities whose total assets exceed 100,000 UVT, and on legal entities of a public nature.

The Data Protection Officer will annually verify, based on the year-end financial statements, whether the Company is obligated. If so:

• It will register each database within the terms set by the SIC.

• It will update the registered information when there are substantial changes, within the following ten (10) business days.

• It will carry out the annual update of the registry within the term set by the SIC.

• It will report Data Subjects' claims and security incidents at the frequency and in the manner required.

Regardless of the formal obligation, the Company will maintain an internal inventory of databases with: name of the database, purpose, categories of Data Subjects and data, means of collection, channel, Data Processors, storage location, transfers, security measures, and retention period.

17. RETENTION AND DELETION OF DATA

17.1. Personal data will be retained only for the time necessary to fulfill the purposes informed and, in any case, for the term required by applicable regulations. As a reference:

| Category | Reference retention period | | --- | --- | | Employment and payroll information | Duration of the relationship and up to [20] years thereafter, in accordance with labor and pension regulations | | Résumés of non-selected candidates | Up to [12] months, unless authorized for a talent bank | | Accounting and tax information | Ten (10) years (art. 28, Law 962 of 2005 and tax regulations) | | AML/CFT due diligence documentation and transaction records | A minimum of five (5) years from the termination of the relationship, or the longer term required by applicable regulations | | Platform user and transaction records | Duration of the account and [5] years thereafter | | Authorizations and evidence of consent | While the Processing subsists and for the statute of limitations period of actions |

17.2. Once the term has expired, the data will be securely deleted or irreversibly anonymized. The destruction will be documented through a record or technical log.

18. SPECIFIC PROCESSING ACTIVITIES

18.1. Identity verification and AML/CFT prevention

The Processing of KYC/AML data is carried out in compliance with legal and regulatory duties and, consequently, its provision is mandatory to access the services. The Company will consult restrictive lists and public sources and may deny, suspend, or terminate the relationship when due diligence cannot be completed. Reports of suspicious transactions to the UIAF are subject to legal reservation and may not be disclosed to the Data Subject.

18.2. Data associated with distributed ledger technologies (blockchain)

The Company recognizes that information recorded on a public blockchain may, by design, be immutable and not subject to deletion or rectification. Consequently:

• The principle of privacy by design is applied: personal data is not directly recorded, in identifiable form, on public chains.

• Personal information (identity, KYC, contact data) is stored off-chain, in systems controlled by the Company or its Data Processors, with the controls set forth in section 13.

• When it is essential to link information to the chain, hashes, references, or pseudonymized data will be used, so that legible information is only accessible through additional data under the Company's control.

• The Data Subject is expressly informed that, with respect to records entered on public chains, the exercise of rectification and deletion rights may be technically impossible; in such cases, the Company will adopt equivalent measures: deletion or rotation of the keys and off-chain information that enable the link, entry of corrective records, and de-indexing in its own systems.

• Wallet addresses and transaction identifiers are treated as personal data when they can be associated with an identifiable natural person.

18.3. Automated decisions and profiling

When the Company uses automated rules or analytical models to assess risk, detect fraud, or segment users, it will inform the Data Subject of this circumstance, maintain documentation on the general logic applied, and ensure human intervention in decisions that produce relevant legal effects or prevent access to the service, as well as a channel to request their review.

18.4. Cookies and tracking technologies

The use of cookies and similar technologies is governed by the Cookie Policy published on the Company's sites and applications, which allows the user to accept, reject, or configure non-essential cookies before their installation.

18.5. Commercial communications

Communications for commercial or advertising purposes will be sent only to Data Subjects who have granted authorization for that purpose, within the hours and conditions permitted by Law 2300 of 2023, and will always include a free, simple, and effective opt-out mechanism, which will be addressed within a maximum term of [5] business days.

18.6. Video surveillance and access control

Video surveillance systems are visibly marked, are not installed in areas with an expectation of privacy (restrooms, changing rooms, break areas), and their recordings are used exclusively for the security of persons and property.

18.7. Artificial intelligence and analytics

When the Company uses artificial intelligence tools, uploading Data Subjects' personal data to tools not approved by the technology area is prohibited. Approved uses will be recorded in the processing inventory, with a prior impact assessment when sensitive data or decisions about individuals are involved.

19. DEMONSTRATED ACCOUNTABILITY AND GOVERNANCE

The Company will maintain documentary evidence of its compliance, which will include at least:

1. This Policy and its version history, with an approval record.

2. Inventory of databases and Processing activities.

3. Record of authorizations and privacy notices used.

4. Internal manual of procedures for handling inquiries and claims, and the filing log.

5. Transmission agreements and evaluations of suppliers and Data Processors.

6. Analysis of international transfers.

7. Risk assessments and privacy impact assessments.

8. Training records and confidentiality agreements.

9. Incident registry and reports to authorities.

10. Internal audit reports and improvement plans.

11. Periodic reports to the Legal Representative and the Board of Directors (at least semi-annually).

20. SANCTIONS REGIME

Failure to comply with data protection regulations may result in sanctions imposed by the Superintendency of Industry and Commerce, consisting of personal and institutional fines, suspension of activities related to the Processing for up to six months, temporary or permanent closure of Processing operations, under the terms of arts. 22 to 24 of Law 1581 of 2012, without prejudice to any applicable civil, criminal, and disciplinary liability.

Pending reform bills contemplate a substantial tightening of the sanctions regime. The Company will calibrate its controls in accordance with the standard in force.

21. VALIDITY

21.1. This Policy is effective as of June 1, 2026, and supersedes the previous version.

21.2. Databases administered by the Company will remain in effect for as long as the purposes of the Processing subsist and within the legal retention terms set forth in section 17.

21.3. Any substantial change to this Policy —relating to the identification of the data controller or the purposes of the Processing— will be communicated to Data Subjects before its implementation, through efficient means of communication, and will be published at https://kiiex.io/. If the change relates to the purpose, new authorization will be required when the law so requires.

21.4. This Policy will be interpreted in accordance with the Political Constitution, Law 1581 of 2012, and its supplementary regulations. In case of contradiction between this Policy and a mandatory rule, the latter will prevail.

22. LEGAL NOTICE FOR PUBLICATION ON THE WEBSITE

22.1. Nature of this document. This Policy exclusively regulates the Processing of personal data and does not constitute, nor replace, the Terms and Conditions of Use of the Company's website and platforms, nor any service agreement, which are governed by their own documents, available at Kii - Cross-border Payments & Trading Platform.

22.2. Accuracy of information provided by the Data Subject. The Data Subject is responsible for the truthfulness, accuracy, and timeliness of the data they provide to the Company. The Company does not independently verify each piece of data provided by the Data Subject, except in the identity verification (KYC) processes described in section 18.1, and will not be liable for the consequences arising from false, inaccurate, or outdated information provided by the Data Subject or by a third party impersonating them.

22.3. Links to third-party sites. The Company's website and platforms may contain links to sites, applications, or services of third parties not operated by Kii. This Policy does not apply to the Processing of data carried out by those third parties, who are solely responsible for their own privacy policies. Data Subjects are advised to review them before providing information.

22.4. Service availability and limitation of liability. Without prejudice to the security duty described in section 13, the Company does not guarantee the uninterrupted availability of the website or the absolute absence of vulnerabilities, and will not be liable for damages arising from force majeure, fortuitous events, acts of third parties, or cyberattacks that, despite the application of the required standard of diligence, could not reasonably have been avoided.

22.5. Language and jurisdiction. This Policy is published in Spanish as the original and reference version; any translation into another language is for informational purposes only and, in case of discrepancy, the Spanish text will prevail. For any dispute related to the Processing of personal data not resolved through the mechanisms in sections 9 to 11, the parties submit to the laws of the Republic of Colombia and to the jurisdiction of the courts of Bogotá D.C., without prejudice to the jurisdiction of the Superintendency of Industry and Commerce.

22.6. Severability. If any provision of this Policy is declared invalid or unenforceable, the remaining provisions will remain in full force and effect.