Privacy Policy
1. Who We Are
This Privacy Policy describes how Acivem Solutions ("HWA", "we") processes personal data through the HWA platform. For data processed on behalf of educational centers, the center acts as data controller and HWA acts as data processor under the Operator DPA.
2. Data We Collect
- Account data: name, email, role, identity-provider subject (Auth0).
- Operational data: calendar entries, attendance records, center memberships.
- Media: photographs of educational materials (classroom boards, notebook and textbook pages) and voice recordings that you attach to in-app messages or replies.
- Technical data: IP address, device, browser, log timestamps, error traces.
- Device identifiers: push notification tokens (Firebase Cloud Messaging) and session identifiers.
- Communications: messages exchanged through in-app channels.
- Audit ledger: for each data-changing action performed in the Service (create, update, delete, access granted or revoked, report reviewed, and similar), we record: the acting user's identity (email in plaintext, Auth0 subject, roles at the time), the operation and the type and id of the affected record, a before/after snapshot of the changed record (which may include personal data from that record, such as names and emails of attendants, supervisors, students, and children), and request context (IP address, user-agent, device platform, timestamps, and request/trace correlation ids). Passwords, tokens, and other secrets are not stored in the ledger. Background system actions are recorded with no personal actor. Ledger entries use standardized English field labels and event descriptions regardless of your app language; data values remain as originally entered.
3. How We Use Personal Data
- Provide and maintain the Service.
- Authenticate users and prevent fraud or abuse.
- Send transactional notifications.
- Comply with legal obligations under Ley 1581 de 2012, Decreto 1377 de 2013, and related regulations.
- Improve security, reliability, and product quality.
- Maintain a security audit ledger for information security, accountability and non-repudiation, misuse and unauthorized-activity investigation, integrity of records, and the establishment, exercise, or defence of legal claims.
4. Legal Basis
We process personal data based on: (a) the data subject's authorization; (b) performance of a contract; (c) compliance with legal obligations; (d) legitimate interests, where not overridden by the data subject's rights.
For the audit ledger described in Section 2, we rely primarily on our legitimate interests in the information security, accountability, integrity, and misuse detection of the Service, and concurrently on compliance with legal-obligation retention requirements and on the establishment, exercise, or defence of legal claims. Our Legitimate Interests Assessment for this processing is available on request.
5. Minors
The Service may process data about minors when an educational center registers them. Such processing requires the prior, express authorization of the parent or legal guardian and is limited to purposes strictly necessary for the educational service.
The Service accepts uploaded media only for educational materials — classroom boards, notebook and textbook pages, and URL references. Photographs, videos, or other imagery of children, students, or any other identifiable person are prohibited by policy and blocked by automated enforcement.
6. Sharing
We share personal data only with:
- The educational center that controls your data.
- Sub-processors listed in the Operator DPA, including Auth0 (Okta) for identity and authentication, Google (Firebase Cloud Messaging) for push notification delivery, a cloud hosting and object storage provider for infrastructure and media storage, and a transactional email provider for system notifications.
- Authorities, when required by Colombian law or judicial order.
7. International Transfers
Some sub-processors operate outside Colombia. Transfers are made with appropriate safeguards and only to countries with adequate protection levels or under contractual guarantees that meet the standards set by the Superintendencia de Industria y Comercio (SIC).
8. Retention
We retain personal data for the duration of your account and for legally required periods thereafter. Operational records may be retained up to five (5) years for audit and compliance purposes; technical logs are typically retained for ninety (90) days.
Entries in the security audit ledger described in Section 2 are retained for five (5) years from the date of the recorded action, independently of your account status. See Section 10 for how this interacts with the right to erasure.
9. Your Rights
Under Ley 1581 de 2012 you may:
- Know, update, and rectify your personal data.
- Request proof of the authorization granted.
- Be informed about the use given to your personal data.
- File complaints with the SIC for violations.
- Revoke authorization and request deletion when appropriate.
- Access your personal data free of charge.
To exercise these rights, contact privacy@acivem-solutions.com. We will respond within fifteen (15) business days.
Limitations for the audit ledger: the right to erasure is limited for entries in the security audit ledger described in Section 2. Under Colombian data protection law, deletion is not required where the processing is necessary for the establishment, exercise, or defence of legal claims or for compliance with a legal obligation. The right of access still applies to your ledger entries. If you object to the underlying legitimate-interests processing, we will assess the balance of interests in accordance with applicable law and respond within the same fifteen (15) business days.
10. Account Deletion
You may delete your HWA account at any time. See the dedicated Account Deletion page for step-by-step instructions and the detailed deleted/retained split.
How to delete:
- In the mobile app: Settings → "Delete my account", then complete the slide-to-confirm.
- By email: privacy@acivem-solutions.com.
What we delete immediately when you delete your account:
- Your account credentials and identity-provider (Auth0) identity.
- Your name, email, phone number, profile settings, and preferences.
- Your device push tokens, session identifiers, and notification history.
- Direct in-app messages you sent, to the extent they are personal communications not part of an institutional record.
What we retain, and why:
- Attendance records, calendar entries, and classroom-board images that form part of an educational center's institutional record. The educational center is the data controller for these records and determines their retention under Ley 1581 de 2012.
- Records that must be kept to comply with legal, tax, accounting, or judicial obligations, for the periods those laws require.
- Server logs and security-related data, retained for up to ninety (90) days for fraud prevention and audit.
- Data that has been irreversibly anonymized and can no longer be linked to you.
- Backup copies, which continue to hold snapshots of prior state until they age out on their normal retention schedule of up to ninety (90) days.
- Entries in the security audit ledger described in Section 2. These may include your email address, Auth0 identifier, roles at the time of each recorded action, and details of the records you touched (which can themselves contain personal data of other users). We retain them for five (5) years from the date of each action for information security, accountability, misuse detection, and the establishment, exercise, or defence of legal claims. See Sections 4, 8, and 9 for the legal basis, retention, and rights limitations.
Records concerning minors: if you are a parent or legal guardian, deleting your account does not delete records about your child held by the educational center. Rights over your child's data are exercised against the educational center as data controller. HWA will support those requests when the center directs us to.
Limitation on erasure — audit ledger: the audit ledger is retained beyond your account deletion for the purposes described in Section 4 (Legal Basis). Colombian data protection law does not require deletion of personal data whose processing is necessary for the establishment, exercise, or defence of legal claims, or for compliance with a legal obligation. See Section 9 for how to exercise access and objection rights over your ledger entries.
Timeline: the personal data listed under "What we delete" is deleted immediately upon your request. Server logs and backup copies age out on their normal ninety (90) day retention cycles. Audit ledger entries are retained for five (5) years from the date of each recorded action.
11. Security
We implement administrative, technical, and physical safeguards proportionate to the risk, including encryption in transit, access controls, audit logs, and least-privilege access for staff.
12. Cookies and Similar Technologies
We use strictly necessary cookies to operate the Service (session, security, preferences). Analytics or marketing cookies require separate consent.
13. Changes
We will publish updates to this Policy with at least fifteen (15) days' notice before they become effective.
14. Contact
Data Protection Officer: dpo@acivem-solutions.com.