Personal Data Processing Policy

Effective as of July 26, 2026.

Courtesy translation. This is an English rendering of a policy issued in Spanish under Colombian law. If the two versions differ, the Spanish version is the one that governs.

This policy describes how Webbidor collects, uses, stores and protects personal data, in compliance with Colombian Law 1581 of 2012, Decree 1377 of 2013 and other Colombian personal data protection regulations.

1. Data controller

Nestor Fabio Gómez Toro, an individual operating under the trade name Webbidor.

The channel for questions and complaints regarding personal data is the email address above.

2. Two distinct roles

Webbidor processes personal data in two different capacities, and the distinction matters because the responsibilities are not the same.

As Controller

For the data of people who contact us directly: website visitors, people who fill out the contact form or message Webbidor on WhatsApp, and contact persons at our clients. For this data, Webbidor determines the purposes and answers directly to the data subject.

As Processor

For the data of our clients' own end customers: the people who message the WhatsApp number of a business using an assistant configured by Webbidor. In those cases, the Controller is the contracting business, not Webbidor. Webbidor processes that data only under that business's instructions and in order to provide the contracted service. Data subject requests concerning that data must be directed to the corresponding business, although Webbidor cooperates in handling them.

3. What data we process

On the website

In the WhatsApp assistants

We do not collect data that is not necessary for the process the assistant handles.

4. Purposes

We do not sell, rent or transfer personal data to third parties for commercial purposes.

5. Third parties involved

To provide the service we rely on technology vendors that may process data on our behalf or on behalf of the contracting business:

You may request the current list of vendors by writing to contacto@webbidor.com.

6. International data transfers

The vendors listed above operate servers outside Colombia. In particular, the content of messages is sent to a language model provider located abroad in order to generate the assistant's reply. This constitutes an international transfer of personal data.

By using an assistant operated by Webbidor, or by contracting our services, the data subject and the contracting business authorize this transfer. Contracting businesses must disclose this circumstance to their own end customers in their own data policy.

7. Sensitive data

Webbidor's assistants are not designed to process sensitive data: health data, biometric data, financial data such as card numbers, or identity documents.

The assistants are configured to explicitly ask users not to share that kind of information over chat. If it is received anyway, it is deleted from the record. We do not provide automation services for healthcare practices or for processes involving clinical data.

8. Retention

9. Data subject rights

Under article 8 of Colombian Law 1581 of 2012, you have the right to:

10. How to exercise your rights

Write to contacto@webbidor.com stating your name, a contact detail, a description of your request and any documents you wish to rely on.

If your request concerns a conversation held with a business's assistant, tell us which business it is: as Processors, we will forward the request to the Controller and cooperate in handling it.

11. Security

We apply reasonable technical and administrative measures to protect data: restricted access to credentials and systems, encryption in transit, and separation between each client's information. No measure removes risk entirely; in the event of a security incident affecting personal data, we will notify those affected and the competent authority as required by law.

12. Data obtained from Google APIs

When a client connects their Google account to Webbidor, they do so through Google's consent screen, granting specific permissions that they can revoke at any time from their Google account settings.

Which permissions we request and why. We request only the narrowest permission that solves each automation:

How we use, store and share it. This data is used only to run and display the functionality the client contracted. We do not use it for advertising, we do not sell it, we do not transfer it to data brokers or to third parties for commercial purposes, and we do not use it to determine creditworthiness or for credit assessment. It is not used to train artificial intelligence models. We store access credentials encrypted and separated per client, and we retain the minimum content necessary to operate the process. No one at Webbidor accesses this data, except with the client's express authorization, for security reasons, to resolve a fault the client reports to us, or where required by law. On termination of the contract, or on revocation of the permission, we stop accessing the account and delete the operational copies under our control.

Webbidor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13. Effective date and changes

This policy is effective as of July 26, 2026. Databases will remain active for as long as the purpose that justified their collection lasts. Any substantial change will be published on this same page with its new effective date.

Have a question about your data? Write to us at contacto@webbidor.com. See also our Terms of service.