Legal Notice & Privacy Policy
How we handle personal data, the terms of use for this site, and the legal framework that applies
Language note: This is an English translation provided for convenience. The authoritative version of this notice is the Spanish original. In case of any discrepancy between the two, the Spanish version prevails.
1. Legal Notice and Identification of the Controller
1.1 Identifying Details of the Owner
In compliance with the disclosure obligations set out in Colombian Law 1581 of and, where applicable to users located in the European Union, Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), the following identifying details of the owner of this website are provided:
Legal Name: Gopenux Lab S.A.S.
Trade Name: Gopenux Lab - Top Tech Lab
Registered Address: Gramalote, Norte de Santander, Colombia
Country of Incorporation: Republic of Colombia
Principal Activity: B2B software development and technology services
Email: [email protected]
Phone: +57 310 214 1792
Website: https://gopenux.com
1.2 Purpose and Scope
This Legal Notice governs access to and use of the website gopenux.com (the "Website"), owned by Gopenux Lab S.A.S. The Website exists to:
- Provide information about the software development services offered by Gopenux Lab
- Enable contact with prospective clients, particularly in the United States and Canada
- Provide corporate and contact information
1.3 Acceptance and Terms of Use
Accessing and browsing the Website makes you a User and implies full and unreserved acceptance of every provision in this Legal Notice. The User undertakes to:
- Use the Website lawfully, in accordance with applicable law and this Legal Notice
- Not carry out activities that may damage, disable, overload or impair the Website
- Not introduce viruses, worms, trojans or any other malicious code
- Not attempt to access, use or manipulate data belonging to Gopenux Lab, its third-party providers or other users
- Not reproduce, copy, distribute or modify the content without express authorization
- Not remove, circumvent or tamper with protection devices or security systems
1.4 Disclaimer of Liability
Gopenux Lab is not liable for:
- Damages arising from interference, omissions, interruptions or telecommunications failures
- The presence of viruses or harmful elements in content that may alter computer systems
- Improper use of the Website by users
- Third-party content and services reachable through links
1.5 Governing Law and Jurisdiction
This Legal Notice is governed by the laws of Colombia. For users located in the United States, Canada or the European Union, the mandatory consumer protection rules of their place of residence apply. For any dispute, the parties submit to the Courts of Cúcuta, Norte de Santander (Colombia), without prejudice to any forum that may correspond to the consumer under applicable law.
2. Privacy Policy and Data Protection
2.1 Data Controller
In accordance with Colombian Law 1581 of , the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Regulation (EU) 2016/679 (GDPR) where applicable, the controller of your personal data is:
Controller: Gopenux Lab S.A.S.
Address: Gramalote, Norte de Santander, Colombia
Data Protection Email: [email protected]
Phone: +57 310 214 1792
2.2 Data Protection Officer (DPO)
Given its size and the nature of the processing it carries out, Gopenux Lab is not required to appoint a Data Protection Officer under Article 37 of the GDPR. Any data protection question can nevertheless be directed to the email address above.
2.3 Personal Data We Collect
The personal data we may collect through this Website includes:
| Data Category | Types of Data | Source |
|---|---|---|
| Identifying data | First name, last name, job title | Contact form, email |
| Contact data | Work email, phone number | Contact form, email |
| Professional data | Company, industry, project requirements | Direct communications |
| Browsing data | IP address, browser type | Automatic (server logs) |
| Usage and analytics data | Cookie identifier, pages visited, traffic source, device type | Analytics cookies (only with your consent — see section 7) |
2.4 Processing Principles
Gopenux Lab guarantees that personal data processing follows these principles:
- Lawfulness, fairness and transparency: Data is processed lawfully, fairly and transparently
- Purpose limitation: Data is collected for specified, explicit and legitimate purposes
- Data minimization: We collect only the data necessary for the stated purposes
- Accuracy: Data is kept accurate and up to date
- Storage limitation: Data is retained only for as long as necessary
- Integrity and confidentiality: Appropriate security of the data is guaranteed
3. Purposes of Data Processing
Your personal data will be processed for the following purposes:
3.1 Primary Purposes
- Responding to inquiries: Answering your requests for information about our services
- Pre-contractual management: Preparing proposals and estimates
- Contract management: Performing and maintaining the commercial relationship
- Billing: Issuing invoices and managing collections
3.2 Secondary Purposes (with consent)
- Commercial communications: Sending information about services, news and events (only with express consent)
- Satisfaction surveys: Assessing the quality of the service delivered
- Website analytics: Aggregate statistical measurement of Website use to improve its content, via analytics cookies and only if you consent (see section 7)
3.3 Retention Periods
| Purpose | Retention Period | Basis |
|---|---|---|
| Inquiries without a contract | 1 year from the last communication | Legitimate interest |
| Contractual relationship | Duration of the contract + 5 years | Legal obligation (limitation period) |
| Tax and accounting data | 6 years from the last entry | Legal obligation (Commercial Code) |
| Commercial communications | Until consent is withdrawn | Consent |
| Website analytics | Maximum 2 years, or until consent is withdrawn | Consent |
| Proof of cookie consent | 1 year | Legal obligation (Art. 7.1 GDPR) |
4. Legal Basis for Processing
Processing of your personal data rests on the following legal grounds, under Article 6 of the GDPR, Article 6 of Colombian Law 1581 of 2012, and the notice-and-consent principles of PIPEDA:
4.1 Consent
For sending commercial communications and newsletters, and for setting analytics cookies. This consent can be withdrawn at any time without retroactive effect; for cookies, through the settings panel described in section 7.6.
4.2 Performance of a Contract or Pre-contractual Steps
For handling information requests, preparing commercial proposals and performing service contracts.
4.3 Compliance With a Legal Obligation
For meeting tax, accounting and invoicing obligations under Colombian law and, where applicable, the law of the client's jurisdiction.
4.4 Legitimate Interest
For the following purposes, having carried out the corresponding balancing test:
- Fraud prevention: Legitimate interest in protecting our systems and detecting fraudulent activity
- Security and availability: Legitimate interest in recording server access logs to guarantee the security and correct operation of the Website
- Legal claims: Legitimate interest in retaining data to defend potential claims
Website analytics does not rely on legitimate interest: because it is carried out through cookies, it requires your prior consent as described in section 4.1.
In every case we have verified that the legitimate interest does not override the rights and freedoms of data subjects, given the B2B context of our activity and the reasonable expectations of professional users.
5. International Data Transfers
Important: Gopenux Lab is a company incorporated in Colombia serving clients in the United States, Canada and Europe. This necessarily involves international data transfers.
5.1 Destination Countries
Personal data may be transferred to:
- Colombia: Where Gopenux Lab is established and where data is processed
- United States: Google LLC, as parent of Google Ireland Limited, provider of the analytics service described in section 7. This transfer only occurs if you consent to analytics cookies
- European Union (Denmark): Usercentrics A/S (Cookiebot), provider of the consent management platform
5.2 Safeguards Applied
For clients and users in the United States and Canada, data processed in Colombia is protected by contractual safeguards equivalent to those required under PIPEDA, which holds an organization accountable for personal information transferred to a third party for processing. Every client engagement is covered by a data processing agreement setting out the security obligations described in section 6.
For users in the European Union, Colombia does not currently benefit from a European Commission adequacy decision under Article 45 of the GDPR. Transfers therefore rely on the safeguards in Article 46:
- Standard Contractual Clauses (SCCs): We adopt the standard contractual clauses approved by the European Commission (Decision 2021/914) to guarantee a level of protection equivalent to the GDPR
- Supplementary measures: We implement additional technical and organizational measures in line with the recommendations of the European Data Protection Board (EDPB)
For transfers to the United States arising from the analytics service, Google LLC is certified under the EU-U.S. Data Privacy Framework, for which the European Commission adopted an adequacy decision on , supplemented by the Standard Contractual Clauses signed with Google Ireland Limited.
5.3 Applicable Colombian Legislation
In Colombia, personal data processing is governed by:
- Statutory Law 1581 of 2012 (Personal Data Protection Law)
- Decree 1377 of 2013 (implementing Law 1581)
- Decree 1074 of 2015 (Single Regulatory Decree for the Commerce Sector)
5.4 Service Providers
We may use service providers located outside Colombia acting as data processors. In those cases we require equivalent contractual guarantees and verify that they hold valid transfer instruments: a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework), Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).
6. Security Measures
In line with Article 32 of the GDPR, Article 4(g) of Colombian Law 1581 of 2012, and the safeguards principle of PIPEDA, Gopenux Lab implements the following technical and organizational security measures:
6.1 Technical Measures
- Encryption: HTTPS/TLS for all communications
- Access control: Authentication and authorization systems governing access to data
- Backups: Regular backup and recovery procedures
- Updates: Ongoing maintenance and patching of systems and software
- Monitoring: Access supervision and anomaly detection
6.2 Organizational Measures
- Internal policies: Documented data processing procedures
- Training: Staff training on data protection
- Confidentiality: Confidentiality undertakings signed by all personnel
- Incident management: A defined breach notification procedure
6.3 Breach Notification
If a security breach affecting personal data occurs, Gopenux Lab will notify the competent supervisory authority within a maximum of 72 hours, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms. For Canadian users, breaches posing a real risk of significant harm are reported to the Office of the Privacy Commissioner of Canada as required by PIPEDA.
8. Your Rights
8.1 Rights of California Residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes and any third parties involved
- Delete: Request deletion of personal information we collected from you, subject to statutory exceptions
- Correct: Request correction of inaccurate personal information
- Opt out of sale or sharing: Direct us not to sell or share your personal information. As stated in section 7.4, we do not sell or share personal information, so there is nothing to opt out of
- Limit use of sensitive personal information: We do not collect sensitive personal information as defined by the CPRA
- Non-discrimination: Receive equal service and pricing regardless of exercising any of these rights
8.2 Rights Under PIPEDA (Canada)
If you are located in Canada, you have the right to:
- Access: Be informed of the existence, use and disclosure of your personal information, and be given access to it
- Correction: Challenge the accuracy and completeness of your information and have it amended as appropriate
- Withdraw consent: Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice
- Challenge compliance: Challenge our compliance with PIPEDA principles, first with us and then with the Office of the Privacy Commissioner of Canada
8.3 Rights Under GDPR (EU Users)
If you are located in the European Union, you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), not to be subject to solely automated decisions (Art. 22), and to withdraw consent at any time.
8.4 Rights Under Colombian Law 1581 of 2012
Data subjects have the right to know, update and rectify their personal data, request deletion when the data is no longer required for the purpose, revoke the authorization given for processing, and file complaints with the Superintendency of Industry and Commerce (SIC).
8.5 How to Exercise Your Rights
To exercise any of these rights, contact us through:
Email: [email protected]
Subject line: "Privacy Rights Request - [state the right]"
To process your request, you will need to:
- Identify yourself reliably (full name and identification document)
- State clearly which right you wish to exercise
- Provide an email address for our response
- Attach a copy of an identity document or power of attorney if you are acting on behalf of someone else
We respond within a maximum of 45 days for requests under the CCPA (extendable by a further 45 days where necessary), within 30 days for requests under PIPEDA, and within one month for requests under the GDPR (extendable by two further months in particularly complex cases, with notice to you).
8.6 Right to Complain to a Supervisory Authority
If you believe the processing of your data breaches applicable law, you have the right to lodge a complaint with:
- California: California Privacy Protection Agency (CPPA) or the California Attorney General
- Canada: Office of the Privacy Commissioner of Canada (OPC)
- Spain / EU: Spanish Data Protection Agency (AEPD) — C/ Jorge Juan, 6, 28001 Madrid
- Colombia: Superintendency of Industry and Commerce (SIC) — Carrera 13 No. 27-00, Bogotá D.C.
9. Intellectual and Industrial Property
9.1 Ownership of Rights
All Website content — including but not limited to text, photographs, graphics, images, icons, logos, technology, software, links, audiovisual content, graphic design and source code — is the intellectual property of Gopenux Lab or of third parties who have authorized its use, and is protected by:
- International law: Berne Convention, WIPO Treaties, TRIPS Agreement
- Colombian law: Law 23 of 1982 on Copyright, Andean Decision 351 of 1993, Law 1915 of 2018
- United States law: Title 17 of the U.S. Code (Copyright Act), including the DMCA
- Canadian law: Copyright Act (R.S.C. 1985, c. C-42)
9.2 Prohibited Actions
The following are expressly prohibited without written authorization from Gopenux Lab:
- Reproduction, distribution, public communication or transformation of the content
- Decompilation, reverse engineering or disassembly of the software or systems
- Extraction or reuse of all or a substantial part of the content
- Use of the content for commercial purposes without authorization
- Removal, concealment or manipulation of copyright notices
9.3 Trademarks and Distinctive Signs
The trade names, trademarks and logos appearing on the Website belong to Gopenux Lab or to third parties. Accessing the Website grants no rights over those distinctive signs. Any use without express authorization is prohibited.
9.4 Limited Use License
Gopenux Lab grants the User a non-exclusive, non-transferable, revocable license limited to viewing the Website content for personal, non-commercial purposes. Any other use requires prior written authorization.
10. Minors
This Website and the services of Gopenux Lab are directed exclusively at companies and professionals (B2B). We do not knowingly collect data from minors.
10.1 Minimum Age
- United States: Under the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13
- Canada: Consent from a parent or guardian is required for the processing of a minor's personal information
- European Union / Spain: Under Article 8 of the GDPR and Article 7 of the Spanish LOPDGDD, the minimum age to give consent in Spain is 14
- Colombia: Under Law 1581 of 2012, processing a minor's data requires authorization from their legal representative
10.2 Inadvertent Processing
If we discover that we have collected data from a minor without the consent of their legal representative, we will delete it immediately. If you become aware that a minor has provided personal data, contact us so we can remove it.
11. Changes to This Policy
Gopenux Lab reserves the right to modify this Privacy Policy and Legal Notice to reflect changes in legislation, case law or business practice.
11.1 Notification of Changes
Any substantial change will be communicated to users through:
- Publication of the new version on this page with its update date
- A prominent notice on the Website for a reasonable period
- Direct email communication to registered users where appropriate
11.2 Applicable Version
The version in force is always the one published at this URL. We recommend reviewing this page periodically to stay informed of any changes.
12. Contact and Complaints
For any question, inquiry or complaint relating to this Legal Notice, the Privacy Policy or the processing of your personal data:
Gopenux Lab S.A.S.
Address: Gramalote, Norte de Santander, Colombia
Email: [email protected]
Phone / WhatsApp: +57 310 214 1792
LinkedIn: Gopenux Lab
12.1 Internal Complaints Procedure
Before approaching a supervisory authority, we invite you to contact us so we can try to resolve the matter directly. We undertake to:
- Acknowledge receipt of your complaint within 5 business days
- Investigate the reported facts diligently
- Provide you with a reasoned response within 15 business days
12.2 Supervisory Authorities
If you are not satisfied with our response, you may contact:
- California Privacy Protection Agency (CPPA): cppa.ca.gov
- Office of the Privacy Commissioner of Canada (OPC): priv.gc.ca
- Spanish Data Protection Agency (AEPD): www.aepd.es
- Superintendency of Industry and Commerce of Colombia (SIC): www.sic.gov.co
Last updated:
Version: 2.1