policies.acivem-solutions.com · HWA · CO · v1.0 · EN

Privacy Policy

v1.0COEN Effective 12 June 2026

1. Who We Are

This Privacy Policy describes how Acivem Solutions ("HWA", "we") processes personal data through the HWA platform. For data processed on behalf of educational centers, the center acts as data controller and HWA acts as data processor under the Operator DPA.

2. Data We Collect

3. How We Use Personal Data

4. Legal Basis

We process personal data based on: (a) the data subject's authorization; (b) performance of a contract; (c) compliance with legal obligations; (d) legitimate interests, where not overridden by the data subject's rights.

For the audit ledger described in Section 2, we rely primarily on our legitimate interests in the information security, accountability, integrity, and misuse detection of the Service, and concurrently on compliance with legal-obligation retention requirements and on the establishment, exercise, or defence of legal claims. Our Legitimate Interests Assessment for this processing is available on request.

5. Minors

The Service may process data about minors when an educational center registers them. Such processing requires the prior, express authorization of the parent or legal guardian and is limited to purposes strictly necessary for the educational service.

The Service accepts uploaded media only for educational materials — classroom boards, notebook and textbook pages, and URL references. Photographs, videos, or other imagery of children, students, or any other identifiable person are prohibited by policy and blocked by automated enforcement.

6. Sharing

We share personal data only with:

7. International Transfers

Some sub-processors operate outside Colombia. Transfers are made with appropriate safeguards and only to countries with adequate protection levels or under contractual guarantees that meet the standards set by the Superintendencia de Industria y Comercio (SIC).

8. Retention

We retain personal data for the duration of your account and for legally required periods thereafter. Operational records may be retained up to five (5) years for audit and compliance purposes; technical logs are typically retained for ninety (90) days.

Entries in the security audit ledger described in Section 2 are retained for five (5) years from the date of the recorded action, independently of your account status. See Section 10 for how this interacts with the right to erasure.

9. Your Rights

Under Ley 1581 de 2012 you may:

To exercise these rights, contact privacy@acivem-solutions.com. We will respond within fifteen (15) business days.

Limitations for the audit ledger: the right to erasure is limited for entries in the security audit ledger described in Section 2. Under Colombian data protection law, deletion is not required where the processing is necessary for the establishment, exercise, or defence of legal claims or for compliance with a legal obligation. The right of access still applies to your ledger entries. If you object to the underlying legitimate-interests processing, we will assess the balance of interests in accordance with applicable law and respond within the same fifteen (15) business days.

10. Account Deletion

You may delete your HWA account at any time. See the dedicated Account Deletion page for step-by-step instructions and the detailed deleted/retained split.

How to delete:

What we delete immediately when you delete your account:

What we retain, and why:

Records concerning minors: if you are a parent or legal guardian, deleting your account does not delete records about your child held by the educational center. Rights over your child's data are exercised against the educational center as data controller. HWA will support those requests when the center directs us to.

Limitation on erasure — audit ledger: the audit ledger is retained beyond your account deletion for the purposes described in Section 4 (Legal Basis). Colombian data protection law does not require deletion of personal data whose processing is necessary for the establishment, exercise, or defence of legal claims, or for compliance with a legal obligation. See Section 9 for how to exercise access and objection rights over your ledger entries.

Timeline: the personal data listed under "What we delete" is deleted immediately upon your request. Server logs and backup copies age out on their normal ninety (90) day retention cycles. Audit ledger entries are retained for five (5) years from the date of each recorded action.

11. Security

We implement administrative, technical, and physical safeguards proportionate to the risk, including encryption in transit, access controls, audit logs, and least-privilege access for staff.

12. Cookies and Similar Technologies

We use strictly necessary cookies to operate the Service (session, security, preferences). Analytics or marketing cookies require separate consent.

13. Changes

We will publish updates to this Policy with at least fifteen (15) days' notice before they become effective.

14. Contact

Data Protection Officer: dpo@acivem-solutions.com.