Last update: Feb 8, 2023
What does Servicio UniTeller do with your personal information?
Why?
Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do.
What?
The types of personal information we collect and share depend on the product or service you have with us. This information can include without limitation:
• Information that you provide us in the course of using the Service, such as your name, address, e-mail address, and telephone or mobile number, number of transactions, transaction amounts, government identification.
• We may also collect certain sensitive information from you including your bank account number, credit card/prepaid card/debit card number, and date of birth.
• Information that you provide us in the course of your participating in various partner promotional programs.
• To facilitate our Service, we request certain third party personal information from you such as your recipient's full name, physical address, email address, and phone number. We may also collect from vou the recipient's sensitive financial information including their bank account and routing number.
• Information aboutyour usage of the Service, including your transaction history, and how and to whom you use the Service to send or receive monev:
• Information that we lawfully obtain from third parties, such as identity verification services, electronicdatabase services, and credit reporting agencies;
For Mobile and online customers we also collect.
• Information that we indirectly obtain from vou, such as information about the hardware and software you use when accessing the Service, vour IP address, the pages you access on this website, and other websites that you visit and that refer you to us prior to accessing the Service.
• We may also use "cookies" to track vour use of this website. A cookie is a small data file that we may place on vour computer to identifyy o u when vou return to the website. You are free to
decline our cookies if your browser permits, but doing so may interfere with your use of the Service.
• At this time uniteller.com websites do not recognize automated browser signals regarding tracking mechanisms, including do not track (DNT)instructions. These tracking mechanisms may use session DI and cookies to enhance our websites, and to present you with UniTeller advertising on othersites based on your interaction on our website. Although blocking all cookies may affect your online experience and prevent you from enjoying the full features offered on uniteller.com websites, we believe that consumers should exercise choice regarding the collection of personally identifiable information. To change your privacy preferences regarding the use of cookies and similar technologies, please consult the "Help section of your browser.
• We may use, and we may allow you to use sign-in services such as Facebook Connect, which will authenticate o u r identity and provide you the option to share certain personal information with us as your name and email address to pre-populate our sign up form. These services as Facebook Connect will give you the option to post information about your activities on our site to your profile page to share with others. We encourage vou to review and understand the privacy policies and practices of such sites or services.
How?
Al financial companies need to share customers' personal information to run their e v e r d a y business. In the section below we list the reasons financial companies can share their customers' personal information; the reasonsServicio UniTeller chooses to share; and whether you can limit this sharing.
When?
This Privacy Policy was last modified on 12/15/2022.


To limit our sharing
OPT OUT RIGHT (EXCEPT FOR CALIFORNIA CONSUMERS)
If you prefer that we limit sharing with affiliates or non-affiliated third parties as described above, you may opt out of those disclosures as follows:
Call 1.800.456.3492 or visit us online at www.uniteller.com and modify o u r user settings, or Mail the form below to: Servicio UniTeller, Servicio UniTeller INC 4516 Seton Center Pkwy Ste 125; Austin, TX. USA. 78759.
California Customers:
Servicio Uniteller will disclose information about consumers with a California mailing address only with
your consent, unless otherwise permitted or required by law. California consumers should contact us for instructions on how to deliver their consent.
Note: Disclosures not subject to an opt-out choice include: disclosures necessary to effect, administer or enforce a transaction you request; disclosures to our authorized service providers, and disclosures permitted or required by l a w to prevent fraud or other illegal activities.
Please note:
If you are a newcustomer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing.
Questions
Call 1.800.456.3492 or visit us online: www.uniteller.com
Mail-in form
Mark any/all you want to limit:
( ) Do not share information about my creditworthiness with your affiliates for their everyday business purposes.
( ) Do not allow your affiliates to use my personal information to market to me.
( ) Do not share my personal information with non affiliates to market their products and services to me.


Who are we?
Who is providing this notice? Servicio UniTeller Inc
What do we do?


Definitions

Other important information
Texas Consumers:
fI you have a complaint, first contact the consumer service division at Servicio Uniteller at 1.800.456.3492, fi you still have an unresolved complaint regarding our activities, please direct your complaint to: Texas Department of Banking, 2601 North Lamar Blvd, Austin, Texas 78705,
1.877.276.5554 (toll free) www.dobtexas.gov
Children's Privacy:
Our website is not directed at children or anvone under the age of 18. Servicio Uniteller does not knowingly collect or maintain information at our website from persons under the age of 18.
External Websites:
Our website may be linked to or from third party websites. Servicio Uniteller is not responsible for the content or privacy practices of websites that are linked to or from our website. We encourage you to familiarize ourself with the privacy policy or practices of these other sites prior to submitting vour personal information to them.
Changes:
Servicio Uniteller reserves the right to modifythis Privacy Policy
Important privacy choices for California consumers
You have the right to control whether we share some of your personal information.
Please read the following information carefully before you make your choices below.
YOUR RIGHTS
You have the following rights to restrict the sharing of personal and financial information with our affiliates (companies we own or control, or that we have common ownership) and outside companies that we do business with. Nothing in this form prohibits the sharing of information necessary for us to follow the law, as permitted by law, or to give you the best service on your accounts) with us. This includes sending you information about additional products and/or services.
YOUR CHOICE
Restrict promotions: Unless you say no, we may send you UniTeller promotions to vour registered email from time to time.
[ ] No, please do not send me UniTeller exclusive Promotions.
Restrict information sharing with our Affiliates (Companies we own, or control, or that we have common ownership): Unless you say "no," we may share personal and financial information about you with our affiliated companies.
[ ] No, please do not share personal and financial information with your affiliated companies.
Restrict information sharing with other companies we do business with to provide financial products and services: Unless you say "no," we may share personal and financial information about you with outside companies we contract with to provide financial products and services to you.
[ ] No, please do not share personal and financial information with outside companies you contract with to provide financial products and services
TIME SENSITIVE REPLY
You may make your privacy choice(s) at any time.Your choices) marked here will remain unless vou state otherwise. However, if we do not hear from you, we may share some of your information with affiliated companies and other companies with who we have contracts to provide products and services.
Name _______________________________________________________________________
Signature____________________________________________________________________
Date_________________________________________________________________________
To exercise your choice, do one of the following:
1. Fill out, sign, and mail this form to us using the envelope provided (you may want to make a copy for your records).
2. Fill out, sign, and fax this form to us at: 1.866.235.3279
3. Call us toll-free at: 1-800-456-3492
Effective Date: 12/2024Last Update: 7/2026
Cross River Bank knows that you expect privacy and security for your personal information. This privacy policy is designed to inform you of the types of information we collect from our website users ("visitors") and from our business clients ("customers"). It discusses how we use that information and the circumstances under which we will share it with third parties. Please note that if you are an individual client of Cross River Bank, our collection, use, and sharing of your information is not governed by this Online Privacy Policy, and is discussed in our separate Cross River Bank's Privacy Notice found in the footer of the homepage of our website (https://www.crossriver.com).
We collect visitor and customer information from the following sources:
For the purposes of this Privacy Policy, nonpublic personal information means any personally identifiable financial information provided by a customer to Cross River Bank as a financial institution, resulting from any transaction or any service performed for the customer's business, or otherwise obtained by Cross River Bank as a financial institution.
We restrict access of customer information to those associates (persons employed by Cross River Bank) who have a business reason for knowing such information. We educate our associates about the importance of confidentiality and privacy of customer and consumer information. We maintain physical, electronic and procedural safeguards that comply with federal and international standards to protect customer information from unauthorized access. However, no security program is 100% secure, and thus we cannot guarantee the absolute security information. In the event that we are required by law to inform the customer of a breach of personal information we may notify the customer electronically, in writing, or by telephone, if permitted to do so by law.
We retain personal information for only as long as necessary to fulfill the purposes outlined in this Privacy Policy, including for the purposes of satisfying any legal, accounting, or reporting requirements, unless a longer retention period is required or permitted by law. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of the information, the purposes for which we obtained the information and whether we can achieve those purposes through other means, as well as applicable legal requirements.
For California residents, California law provides specific rights regarding personal information, including:
To make such a request, contact us at privacy@crossriver.com, call 1-877-55CRB55, or send a written inquiry to Cross River Bank c/o Online Banking Department; 2115 Linwood Ave., Fort Lee, NJ 07024. Requests must include "California Privacy Rights Request" in the first line of the description and include name, street address, city, state, and ZIP code. If a request is submitted, we may ask to verify the customer's identity by submitting: name, last name, driver's license or California card ID number, and account number(s). Please note that the Bank will make an official request for sensitive identifying information to ensure secure transmission.
Customers also have the right not to be discriminated against if they exercise any rights under California privacy law. Customers may designate in writing an agent to exercise these rights on their behalf. Cross River Bank may require identity verification and provide documentation of the agent's authorization before we respond to the request.
We may have collected the following categories of personal information of California residents in the past 12 months:
This information is collected and used for the purposes disclosed in this Privacy Policy. Cross River Bank has not sold personal information of California residents in the past 12 months. Cross-River does, however, engage in cross context behavioral advertising using online tracking technologies. You can opt-out of cross-context behavioral advertising as described in the Information Sharing and California Privacy Rights sections above. Cross River Bank may have disclosed any of the above categories of personal information pursuant to an individual's consent or under a written contract with a service provider for a business purpose in the past 12 months.
California Sensitive Information Disclosure. We collect the following categories of sensitive personal information (as defined under California law): a business owner's social security number, driver's license, state identification card, or passport number, a customer's account log in, financial account, debit card or credit card number in combination with any required security code, password or credentials allowing access to an account. This information is collected in order to process transactions, comply with laws, manage our business, or provide services. Note that we do not use such information for any purposes that are not identified within the California Privacy Rights Act Section 1798.121. We do not "sell" or "share" sensitive personal information for purposes of cross-context behavioral advertising.
The European Union ("EU") General Data Protection Regulation ("GDPR") lays down rules relating to the protection of natural persons in the EU with regard to the processing of their personal data. For the purposes of this Privacy Policy, personal data means any information relating to an identified or identifiable natural person. To exercise any of the rights described below, please contact our Group by calling toll-free at 1-877-55CRB55; by sending a written inquiry to Cross River Bank c/o Online Banking Department, 2115 Linwood Ave., Fort Lee, NJ 07024; or emailing us at privacy@crossriver.com.
Right to Access, Rectification, or Erasure. You have the right to access, update, correct, or delete your personal data. You also have the right to rectify any inaccuracies in your personal data.
Right to Restrict Data Processing. You have the right to restrict the processing of your personal data upon request if it is (a) inaccurate or unlawful, (b) under contest, or (c) no longer being processed for the original purpose. Cross River Bank may continue to process the data if it is necessary to resolve legal claims, for the protection of the rights of another person, or for reasons of important public interest. If Cross River Bank objects to the restriction of data processing, we will notify you promptly after receiving your request.
Right to Data Portability. You have the right to request and obtain your personal data that you provided to us or that we collected through your consent or contractual agreements. We will provide your information in a commonly used, machine-readable format promptly, but no longer than 90 days from the initial request depending on the complexity and volume of requests. If circumstances arise where we are unable to complete your request, we will promptly provide a relevant explanation, as well as inform you of additional steps that you may take.
Retaining Your Personal Information and Data. We will retain your personal data to comply with our legal obligations, resolve disputes, and enforce our agreements. We will retain your personal information for as long as needed to provide you with Cross River Bank services, but no longer than the period necessary to fulfill the purposes outlined in this Privacy Policy.
Receiving Promotional and Other Communications. We will obtain your consent before sending you promotional, newsletter, or product information emails that we feel may interest you. We may obtain consent from you through a website contact or consent form or by email. You may opt out by either checking the relevant box on the communication consent form, by following the opt-out instructions provided in our emails to you, or by emailing us with your specific request. If you opt out, we may still send you non-promotional communications, such as security alerts and notices related to your access to or use of any Cross River Bank products or services or about our ongoing business relations.
Withdrawing Your Consent. You may withdraw any consent you previously provided to us for the processing of your personal data. As required by applicable law, we will apply your preferences going forward, within a reasonable amount of time. Even where you withdraw your consent, we may still process your personal data for limited purposes, for example, to give effect to your request or to safeguard our business. In some circumstances, withdrawing your consent to our use or disclosure of your personal information will mean that you cannot use our products or services.
Lodging a Complaint with a Supervisory Authority. You have the right to submit a complaint to an EU supervisory authority if you believe that your personal data has been processed in a manner that is not compliant with the GDPR. You also have the right to submit a complaint to an EU supervisory authority if Cross River Bank is unable to comply with your right of data portability or does not respond to your request within a timely manner.
We appreciate our customer's business and we are committed to maintaining the privacy of our customer's information, as expressed in this Privacy Policy. This Privacy Policy applies only to visitors to our website and our business clients.
We reserve the right to amend the Privacy Policy at any time. To the extent that our policy changes in a material way, the policy that was in place at the time that personal information was submitted to us will generally govern that information unless we receive consent to the new privacy policy. Our privacy policy includes an "effective" and "last updated" date. The effective date refers to the date that the current version took effect. The last updated date refers to the date that the current version was last substantively modified. If we make a material change to our privacy notice, we will attempt to notify you through email or through a website pop-up.
For questions, comments, or complaints concerning our privacy practices or the need to access this privacy policy in an alternative format due to having a disability, please contact Customer Service at 1-877-55CRB55 or email privacy@crossriver.com.
For Cross River Technologies (Spain) employment related privacy notices, click here.
For Cross River Technologies (Israel) employment related privacy notices, click here.
Effective Date: 11/2018Last Update: 12/2024
Why? Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share and protect your personal information. Please read this notice carefully to understand what we do.
What? The types of personal information we collect and share depend on the product or service you have with us. This information can include: Social Security number and Account balances; Payment history and Transaction history; Account transactions and Wire transfer instructions. When you are no longer our customer, we continue to share your information as described in this notice.
How? All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Cross River Bank chooses to share; and whether you can limit this sharing.
For our everyday business purposes — such as to process your transactions, maintain your accounts, respond to court orders and legal investigations, or report to credit bureaus. Does Cross River Bank share? Yes. Can you limit this sharing? No.
For our marketing purposes — to offer our products and services to you. Does Cross River Bank share? Yes. Can you limit this sharing? No.
For joint marketing with other financial companies. Does Cross River Bank share? Yes. Can you limit this sharing? No.
For our affiliates' everyday business purposes — information about your transactions and experiences. Does Cross River Bank share? No. Can you limit this sharing? We don't share.
For our affiliates' everyday business purposes — information about your creditworthiness. Does Cross River Bank share? No. Can you limit this sharing? We don't share.
For nonaffiliates to market to you. Does Cross River Bank share? No. Can you limit this sharing? We don't share.
Questions? Call toll-free 1-877-55CRB55 or contact us at www.crossriver.com
How does Cross River Bank protect my personal information? To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. We also maintain other physical, electronic and procedural safeguards to protect this information and we limit access to information to those employees for whom access is appropriate.
How does Cross River Bank collect my personal information? We collect your personal information, for example, when you: open an account or apply for a loan; make deposits or withdrawals from your account or provide employment information; give us your contact information. We also collect your personal information from others, such as credit bureaus, affiliates, or other companies.
Why can't I limit all sharing? Federal law gives you the right to limit only: sharing for affiliates' everyday business purposes – information about your creditworthiness; affiliates from using your information to market to you; sharing for nonaffiliates to market to you. State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law.
Affiliates — Companies related by common ownership or control. They can be financial and nonfinancial companies. Cross River Bank does not share with our affiliates.
Nonaffiliates — Companies not related by common ownership or control. They can be financial and nonfinancial companies. Nonaffiliates we share with can include loan finance companies.
Joint marketing — A formal agreement between nonaffiliated financial companies that together market financial products or services to you. Our joint marketing partner(s) include loan finance companies.
For California Customers. We will not share personal information for joint marketing without your authorization.
For Nevada Customers. We are providing you this notice pursuant to Nevada law. If you prefer not to receive marketing calls from us, please let us know by calling us at 1-877-55CRB55 or contact us at www.crossriver.com. Additional information concerning our privacy policies can be found at www.crossriver.com or call 1-877-55CRB55.
For Vermont Customers. We will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information, credit report, or health information to nonaffiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. Additional information concerning our privacy policies can be found at www.crossriver.com or call 1-877-55CRB55.
Welcome, and thank you for using Cobre services (hereinafter, the "Services") and the Cobre platform (hereinafter, the "Platform").
The Platform is operated by Pexto Colombia S.A.S., which includes the companies Pexto Colombia S.A.S., Pexto Pagos S.A.S., Pexto México S.A. de C.V., Novupeso S.A. de C.V. and Tesored S.A. de C.V., hereinafter collectively referred to as Cobre (hereinafter, "Pexto" or "Cobre"), which, for purposes of this Privacy and Personal Data Processing Policy and Privacy Notice, is responsible for collecting and processing your Personal Data.
For purposes of this Privacy and Personal Data Processing Policy and Privacy Notice, Cobre shall mean:
Use of the Services is governed by the laws of the country in which they are contracted (Colombia or Mexico), and their scope is primarily limited to such places of contracting, which are the countries where Cobre offers its services.
Accordingly, Cobre makes the following Privacy and Personal Data Processing Policies available to you, according to the country in which the Services are contracted (Colombia or Mexico).
This Information Processing Policy or Personal Data Protection Policy shall apply to all Databases and/or files containing Personal Data that are Processed by PEXTO COLOMBIA S.A.S. and PEXTO PAGOS S.A.S. (hereinafter, "PEXTO" or the "Company").
In order to duly comply with applicable law, whenever Pexto Processes Personal Data, it shall be governed by the following principles:
a) Principle of legality. The Processing of Personal Data is an activity that must comply with the rules governing the matter.
b) Principle of purpose limitation. Processing must serve a legitimate purpose in accordance with the Constitution and the law, and such purpose must be communicated to the Data Subject through the means provided by applicable regulations.
c) Principle of freedom. Processing may only be carried out with the Data Subject's prior, express, and informed consent. Personal Data may not be obtained or disclosed without prior Authorization, except where a legal or judicial mandate removes the requirement for consent.
d) Principle of truthfulness or quality. Information subject to Processing must be truthful, complete, accurate, up to date, verifiable, and understandable. Pexto must refrain from Processing partial, incomplete, fragmented, or misleading data.
e) Principle of transparency. Processing must guarantee the Data Subject's right to obtain from the Data Controller or Data Processor, at any time and without restriction, information regarding the existence of data concerning them, in accordance with the rules governing such access.
f) Principle of restricted access and circulation. Processing may only be carried out by persons authorized by the Data Subject and/or by persons provided for under applicable law. Accordingly, the Company must take the necessary actions to obtain the corresponding Authorization from the Data Subject whenever required.
g) Principle of security. Information Processed by Pexto in its capacity as Data Controller or Data Processor must be handled using the technical, human, and administrative measures necessary to safeguard the data against alteration, loss, consultation, use, or unauthorized or fraudulent access.
h) Principle of confidentiality. All Company personnel and any other persons involved in the Processing of Personal Data on behalf of and representing the Company are required to preserve the confidentiality of the information.
i) Principle of accountability. When collecting and Processing Personal Data, Pexto shall implement appropriate and effective measures to comply with the obligations established by applicable law.
PEXTO, acting as Data Controller, for the proper conduct of its business activities and to strengthen its relationships with third parties, collects, stores, uses, Processes, circulates, and deletes Personal Data relating to the stakeholder groups identified below for the following purposes:
A. General Purposes
The purposes described below shall apply to all Data Subjects who have given prior, express, and informed Authorization for the Processing of their Personal Data:
B. Customers, Users and/or Consumers of PEXTO Platforms
The purposes applicable to the Personal Data of customers (when they are natural persons), users and/or consumers of PEXTO's platforms and applications, in addition to those applicable under other sections, are as follows:
C. Shareholders
The purposes applicable to the Personal Data of PEXTO shareholders, in addition to those applicable under other sections, are as follows:
D. Employees and Other Collaborators
The purposes applicable to the Personal Data of PEXTO employees and other collaborators include carrying out recruitment and selection processes, which may include health examinations and scheduling interviews, and:
E. Suppliers and/or Contractors
The purposes applicable to the Personal Data of PEXTO's Suppliers and/or Contractors (or the personnel of such Suppliers and/or Contractors, as applicable), in addition to those applicable under other sections, are as follows:
PEXTO understands that the Personal Data of the supplier or contractor and of those third parties whose data the supplier or contractor provides, such as workers authorized to perform the assigned management or service, references and commercial certifications, have been authorized by the respective Data Subjects to be provided and Processed in accordance with the purposes set forth in this Policy.
Natural persons whose Personal Data is Processed by PEXTO have the following rights, which they may exercise at any time:
PEXTO's Cybersecurity Department is responsible for the development, implementation, training, and compliance with this Policy. This Department has also been designated by PEXTO as the area responsible for handling requests, inquiries, complaints, and claims before which the Data Subject may exercise their rights to know, update, rectify, and delete data and revoke Authorization.
Data Subjects whose Personal Data is being collected, stored, used, or circulated by PEXTO may, at any time, exercise their rights to know, update, rectify, and delete information and revoke Authorization.
For such purpose, the following procedure shall be followed in accordance with the Personal Data Protection Law:
a. Handling and Response to Requests and Inquiries
Inquiry Procedure: Data Subjects wishing to make inquiries should note that the Data Controller shall provide them with all information contained in the individual record or linked to the identification of the Data Subject. The inquiry shall be submitted through the channels enabled by the Data Controller and shall be answered within a maximum period of ten (10) business days from the date the request is received. Where it is not possible to answer the inquiry within such period, the interested party shall be informed of the reasons for the delay and the date on which the inquiry will be answered, which in no case may exceed five (5) business days following expiration of the initial period, without prejudice to the provisions of special laws or regulations issued by the National Government that may establish shorter periods depending on the nature of the Personal Data.
Claim Procedure: A Data Subject who considers that information contained in a Database of the Data Controller should be corrected, updated, or deleted, or who becomes aware of an alleged breach of any of the duties contained in Law 1581 of 2012, may file a claim, which shall be processed under the following rules:
i. The claim shall be submitted by means of a request addressed to the Data Controller or Data Processor, identifying the Data Subject, describing the facts giving rise to the claim, and providing an address, together with any documents the claimant wishes to rely upon.ii. If the claim is incomplete, the interested party shall be required, within five (5) days following receipt of the claim, to remedy the deficiencies. If two (2) months elapse from the date of the request for additional information without the applicant providing the required information, the claim shall be deemed withdrawn.iii. If the person receiving the claim is not competent to resolve it, the claim shall be forwarded to the appropriate person within a maximum of two (2) business days, and the interested party shall be informed of the situation.iv. Once the complete claim has been received, a notation stating "claim in process" and the reasons giving rise to it shall be entered in the Database within no more than two (2) business days. Such notation shall remain until the claim has been finally resolved.v. The maximum period for responding to the claim shall be fifteen (15) business days counted from the day following the date of receipt. Where it is not possible to respond to the claim within such period, the interested party shall be informed of the reasons for the delay and the date on which the claim will be answered, which in no case may exceed eight (8) business days following expiration of the initial period.
Channels enabled for the submission of requests and inquiries:
PEXTO has made the following channels available for the receipt and handling of requests and inquiries, all of which allow evidence thereof to be retained. Communication addressed to PEXTO – Cybersecurity Department at the following addresses:
Pursuant to the security principle set forth in Law 1581 of 2012, PEXTO has adopted and incorporated into its various processes the technical, human, and administrative measures necessary and appropriate to safeguard records containing Personal Data against alteration, loss, consultation, use, or unauthorized or fraudulent access. Personnel who Process Personal Data shall follow the protocols established by PEXTO in order to ensure information security. The foregoing shall be implemented taking into account the state of technology, the type and nature of the data contained in the Databases, and the risks to which such data is exposed.
Personal Data obtained by PEXTO through any form, contract, physical or electronic communication shall be Processed with strict confidentiality, with PEXTO undertaking to maintain due secrecy regarding such data and to store it using the necessary measures to prevent alteration, loss, unauthorized Processing, or unauthorized access, in accordance with applicable law.
Pexto may Process Personal Data only for such time as is reasonable and necessary, in accordance with the purposes that justified the Processing, taking into account the provisions applicable to the relevant matter and the administrative, accounting, tax, legal, and historical aspects of the information. Once the purpose of the Processing has been fulfilled, the Personal Data shall be deleted from the Company's files, unless a legal or contractual duty requires that it be retained in its Databases.
This Information Processing Policy is governed by the applicable legislation on protection of Personal Data referred to in Article 15 of the Political Constitution of Colombia, Law 1581 of 2012, Decree 1074 of 2015 (which compiles Decree 1377 of 2013), and any other rules that amend, repeal, or replace them.
This Policy became effective on May 1, 2025.
In compliance with the Federal Law on Protection of Personal Data Held by Private Parties and all other applicable regulations, we hereby make this Privacy Notice available to you. In this regard, we inform you as follows:
Pexto México, S.A. de C.V. (hereinafter, "COBRE"), with address at Avenida Paseo de la Reforma 333, Alcaldía Cuauhtémoc, Mexico City, Postal Code 06500 - Cobre Company, is responsible for the Processing and protection of your Personal Data and/or the use made thereof, as applicable (hereinafter, the "Personal Data").
For the purposes stated in this Privacy Notice, we may collect your Personal Data in different ways: when you provide it directly to us; when you visit our Website at https://www.cobre.co/mexico or use our online services or social networks; and when we obtain information through other sources permitted by law.
Personal Data we collect directly. We collect your Personal Data directly when you provide it to us through various means, such as when you participate in our promotions or provide information for the purpose of contracting the services offered on the website https://www.cobre.co/mexico. The data we obtain through this means is:
The Personal Data we collect when you visit and interact with our website https://www.cobre.co/mexico or use our online services, or through any other source, follows the same list above.
2.1. Sensitive Personal Data. COBRE does not at any time request or require Sensitive Personal Data. If a user were to provide such data at any time, it will receive the same security treatment as any information requested by the website https://www.cobre.co/mexico. The security and confidentiality of the data provided by users when contracting an online service will be protected by a secure server, so that the data sent will be transmitted in encrypted form to safeguard it. However, it is clear that no data communication over the Internet is completely secure, and therefore COBRE cannot guarantee that your Personal Data will be free from any damage, loss, alteration, destruction, or unauthorized use, access, or Processing.
2.2. Personal Data of minors and persons under legal incapacity. We inform you that we take special care to protect the personal information of minors and persons under legal incapacity. Personal Data that we obtain from minors must, without exception, be provided by the father, mother, or legal guardian and shall be Processed and protected under strict security and confidentiality measures.
2.3. Personal Data of Third Parties. For Personal Data of third parties that you provide to us, you must first obtain the consent of the Data Subject and inform them of the website where they may find and review this comprehensive Privacy Notice.
a) Primary. Purposes that give rise to and are necessary for the legal relationship between you and COBRE:
b) Secondary. Purposes other than those giving rise to the legal relationship between you and COBRE, but which are nevertheless of great importance and usefulness to us for:
In all cases, once the purposes for Processing your Personal Data have been fulfilled, and provided there is no legal provision establishing otherwise, COBRE shall proceed with the cancellation, deletion and/or destruction of the Personal Data received, under the terms established by law.
If you do not wish your Personal Data to be Processed for the secondary purposes mentioned above, or any of them, you may withhold your consent from this time by sending your request to our Privacy Department, which will inform you of the procedure to follow to exercise your right. Your refusal in this regard may not be grounds for denying you the services and products that you request or contract with us.
When we obtain Personal Data indirectly, you will have a period of five (5) business days to express, where applicable, your refusal to the Processing of Personal Data for secondary purposes. If you do not do so, you will be deemed to consent to the Processing of Personal Data for such purposes, without prejudice to your later decision to exercise your rights of revocation or objection in the manner indicated in Sections 6 and 7 of this Privacy Notice.
For the fulfillment of the primary purposes stated in this Privacy Notice, Personal Data may be transferred to the following natural or legal persons without your consent being legally required pursuant to Article 36 of the Federal Law on Protection of Personal Data Held by Private Parties:
Likewise, Personal Data may be transferred to the following legal persons, in which cases we do require your consent:
If you do not express your refusal to allow us to make such transfer(s), we will understand that you have granted us your consent. You may express your refusal from this time by sending an e-mail to our Privacy Officer, who will inform you of the procedure to follow to exercise your right.
Under applicable regulations, you have the right to know what Personal Data we hold about you, what we use it for, and the conditions under which we use it (Access). You also have the right to request correction of your personal information if it is outdated, inaccurate, or incomplete (Rectification); to request that we delete it from our records or Databases when you consider that it is not being used appropriately (Cancellation); and to object to the use of your Personal Data for specific purposes (Objection). These rights are known as ARCO Rights.
To exercise any of the ARCO Rights, you must submit the corresponding request by e-mail to our Privacy Department, which will inform you of the procedure and requirements for exercising such rights, response periods, how we will give effect to your right, and will address any questions, complaints, or comments you may have in this regard.
Under applicable regulations, you may revoke any consent you may have granted to us. However, it is important to note that your request may not be granted in all cases, nor may we be able to cease use immediately, because we may be required by a legal obligation to continue Processing your Personal Data.
To revoke your consent, you must submit your request by e-mail to our Privacy Department, which will inform you of the procedure and requirements for exercising this right, response periods, how we will give effect to your right, and will address any questions, complaints, or comments you may have in this regard.
In addition to the procedure and exercise of the rights set forth in Sections 4 and 7 of this Privacy Notice, you may limit the use or disclosure of Personal Data in the following ways:
We reserve the right to make amendments or updates to this Privacy Notice at any time in response to legislative developments, internal policies, or new requirements for the provision or offering of our services or products. Such amendments will be made available to the public through the following means:
Cookies are text files that are automatically downloaded and stored on the hard drive of a user's computer when browsing a specific Internet page, and allow the Internet server to remember certain data about the user, including preferences for displaying pages on that server, username, and password. Web beacons, on the other hand, are images inserted into an Internet page or e-mail that may be used to monitor a visitor's behavior, such as storing information about the user's IP address, the duration of interaction with the page, and the type of browser used.
We inform you that we use cookies and web beacons to obtain personal information about you, such as the following:
These cookies and other technologies may be disabled. There are various areas on our COBRE website that may connect to other websites that do not operate under COBRE's privacy policies. When you connect to other websites, the privacy practices of our COBRE website and this Privacy Notice no longer apply. We encourage users to review the privacy policies and corresponding notice of each website before disclosing any personally identifiable information, since those entities are responsible for Processing their Personal Data. The Processing of your Personal Data by such entities or websites may be subject to the laws of other jurisdictions.
Our Cybersecurity Department includes the individual within COBRE who, in compliance with Article 29 of the Federal Law on Protection of Personal Data Held by Private Parties, has been formally designated to:
For all matters relating to the Processing and protection of Personal Data, you may contact our Cybersecurity Department by sending an e-mail to soporte@cobre.co.
By entering into a commercial relationship with COBRE, you acknowledge that this Privacy Notice has been made available to you and you consent to the Processing of your Personal Data, including your property and financial Personal Data, authorizing the Transfer thereof under the terms described in this Privacy Notice.
Last updated: March 30, 2026.