Last updated: September 15, 2026
At GLYNNE S.A.S. we recognize that information is one of the most important assets of an organization.
For this reason, we design our solutions under principles of security, access control, data minimization, and responsible data processing.
This Privacy Policy explains how GLYNNE collects, uses, stores, protects, and, where applicable, shares personal information.
The party responsible for the processing of personal data shall be:
This Policy applies to information collected through:
When GLYNNE processes information exclusively on behalf of a Client, the processing may be additionally regulated by the contract executed between both parties.
Depending on the relationship with GLYNNE, we may collect:
We may receive information that the user voluntarily chooses to provide via:
In the development of enterprise solutions, GLYNNE may have access to information provided by its Clients.
This information may include:
The processing of this information will be carried out in accordance with the scope of the contracted service and the applicable instructions of the Client.
The information may be used to:
GLYNNE will not use personal information for purposes incompatible with those informed to the data subject, unless there is a legal basis that allows such processing.
GLYNNE seeks to limit the processed information to that which is strictly necessary to execute a specific function or service.
In architectures that allow it, systems can be designed to prevent a component from having indiscriminate access to all available information.
Some of GLYNNE's services may incorporate artificial intelligence technologies.
Depending on the architecture, the data may be processed by:
GLYNNE will endeavor to implement technical mechanisms that allow controlling the information each component can receive.
When a project requires the use of an external artificial intelligence provider, the processing of information will be subject to the contractual and technical conditions applicable to the service.
GLYNNE shall not interpret technical access to Client information as automatic authorization to use such information to train general-purpose artificial intelligence models.
When processing of this nature is necessary, there must be a legal basis, authorization, or contractual provision that allows it.
[VALIDATE THIS SECTION WITH THE LAWYER AND ADAPT IT TO GLYNNE'S ACTUAL TECHNICAL POLICY.]
GLYNNE may use technological providers to deliver its services.
These providers may render services related to:
GLYNNE will seek to select appropriate providers for the nature of the service and establish the corresponding contractual and technical measures.
Some technological providers used by GLYNNE may operate infrastructure located outside of Colombia.
When it is appropriate to carry out international transfers or transmissions of personal data, GLYNNE will apply the requirements established by Colombian legislation and the corresponding legal and contractual mechanisms.
GLYNNE adopts reasonable technical and organizational measures aimed at protecting information against:
Security measures may include:
The exact nature of the measures will depend on the service and the information processed.
In projects where GLYNNE integrates artificial intelligence, security can be applied not only to the model but to the entire architecture.
A model does not necessarily need direct access to all of an organization's information.
Depending on the system, GLYNNE can design mechanisms through which:
Information → permissions → software → tools → model → result
This allows controlling what information can be queried, what tools an agent can use, and what actions it can execute.
The specific implementation will depend on the contracted project.
GLYNNE will retain the information for the time necessary to fulfill the purpose for which it was collected, fulfill contractual obligations, address legal obligations, or protect its rights.
Specific periods may vary depending on:
When it is no longer necessary, the information may be deleted, anonymized, or subjected to retention mechanisms when a legal obligation requires it.
In accordance with applicable Colombian legislation, data subjects may exercise their corresponding rights, including, when applicable:
Data subjects may submit requests to the email:
alexglynne7@gmail.com
The request must contain, at a minimum:
When the request is submitted by a representative, the corresponding authorizations must be accredited.
GLYNNE will address the requests within the terms established by applicable legislation.
GLYNNE's enterprise services are not specifically designed for minors.
GLYNNE does not seek to deliberately collect personal information from minors without the corresponding authorization or applicable legal basis.
When GLYNNE participates in an enterprise project involving minors' information, the processing must comply with the special rules applicable to this type of information.
GLYNNE may send communications related to services, news, products, events, or commercial information when there is a legal basis or authorization that allows it.
Users may request to stop receiving certain commercial communications through the mechanisms available in each communication or by contacting GLYNNE.
GLYNNE's websites may contain links to external sites.
GLYNNE does not control the privacy policies of such sites and recommends reviewing their respective policies before providing personal information.
GLYNNE has internal procedures aimed at identifying and managing security incidents.
When an incident may generate legal notification obligations, GLYNNE will carry out the corresponding communications in accordance with applicable legislation and current contractual obligations.
GLYNNE may update this Privacy Policy to reflect technological, operational, legal, or regulatory changes.
The current version will be published indicating the date of update.
For inquiries related to privacy and data protection: