MongiCore
  • Home
  • Services
  • Products
  • About
  • Contact
Get Started
Home › Privacy Policy

Privacy Policy

Last updated: July 10, 2026

MongiCore SAS is committed to protecting your privacy. This policy explains how we collect, use, store, and safeguard your personal data in compliance with the EU General Data Protection Regulation (GDPR), Colombian Law 1581/2012 (Habeas Data), and other applicable privacy legislation.

Table of Contents
1. Data Controller 2. Data We Collect 3. Legal Basis 4. How We Use Data 5. Data Retention 6. Data Sharing 7. Int'l Transfers 8. Cookies 9. Your Rights 10. Children 11. Security 12. Policy Changes 13. Contact

1. Data Controller

The entity responsible for processing your personal data is:

MongiCore SAS

NIT 902049660-0

Cll 49 #3C – 20 1101, Bogotá D.C., Colombia

Email: admin@mongicore.com

Phone: +57 318 974 1737

2. Data We Collect

a) Data You Provide Directly

  • Full name and email address submitted via our contact form
  • Subject and message content of your enquiry
  • Account credentials (username, hashed password) when registering for a service
  • Billing name and billing address — processed by PCI-DSS compliant payment providers; we never store raw card data

b) Technical & Usage Data

  • IP address, browser type and version, operating system, device type
  • Pages visited, time on site, referring URLs and click paths — via standard server logs
  • Language preference stored in your browser’s localStorage — never transmitted to our servers

3. Legal Basis for Processing (GDPR Art. 6)

Under GDPR Art. 6 and Colombian Law 1581/2012 we process your data on the following lawful bases:

Purpose Legal Basis
Responding to contact form enquiriesArt. 6(1)(b) — Pre-contractual / contract performance
Providing purchased services & billingArt. 6(1)(b) — Contract performance
Security monitoring & fraud preventionArt. 6(1)(f) — Legitimate interests
Compliance with legal obligations (invoicing, tax)Art. 6(1)(c) — Legal obligation
Marketing communicationsArt. 6(1)(a) — Explicit consent (opt-in only)

4. How We Use Your Data

  • Respond to enquiries and provide customer support
  • Deliver, maintain, and improve our software products and platforms
  • Process payments and issue invoices for purchased services
  • Send service notifications (account creation, password resets, billing receipts)
  • Detect and prevent fraudulent, abusive, or unlawful activity
  • Comply with legal and regulatory obligations

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

5. Data Retention

We retain your personal data only as long as necessary for the purposes described:

Data Type Retention Period
Contact form submissions24 months from last interaction
User account dataDuration of account + 12 months after deletion request
Billing & invoice records10 years (Colombian tax law — Art. 46 C.Co.)
Server access logs90 days
Support tickets36 months from ticket closure

6. Data Sharing & Sub-Processors

We share the minimum necessary data with the following trusted sub-processors under binding Data Processing Agreements:

Brevo (Sendinblue)

Transactional email delivery. GDPR-compliant, data processed in the EU. Privacy Policy →

Google Fonts

Font rendering. Your browser requests font files from Google servers; Google may log the request. Google Privacy Policy →

Stripe / Wompi

Payment processing. PCI-DSS compliant. We never store raw payment card data — all card handling is performed by the payment processor.

Cloud Hosting Providers

Infrastructure hosting. Providers have no direct access to personal data stored in our applications.

We may disclose data when required by law, court order, or governmental authority, or to protect the rights and safety of MongiCore SAS, our users, or the public.

7. International Data Transfers

MongiCore SAS is based in Colombia. Some sub-processors operate in the EEA or the United States. For cross-border transfers we rely on:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers to countries declared adequate by the Colombian SIC (Superintendencia de Industria y Comercio)
  • Data Processing Agreements (DPAs) with all sub-processors covering security and confidentiality obligations

8. Cookies & Local Storage

Our marketing website (mongicore.com) uses no tracking cookies, advertising cookies, or third-party analytics. The only client-side storage we use is:

mongicore-lang — localStorage

Stores your language preference (en/es). Session-persistent, no expiry. Never transmitted to our servers. Clear it via your browser’s developer tools at any time.

Our platform portals may use strictly necessary session cookies for authentication. These are exempt from consent requirements under applicable law.

9. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you (GDPR Art. 15 / Ley 1581 Art. 8a).

Rectification

Request correction of inaccurate or incomplete data (GDPR Art. 16 / Ley 1581 Art. 8b).

Erasure

Request deletion of your data, subject to legal retention obligations (GDPR Art. 17 / Ley 1581 Art. 8c).

Restriction

Request we limit processing in certain circumstances (GDPR Art. 18).

Portability

Receive your data in a structured machine-readable format (JSON / CSV) (GDPR Art. 20).

Objection

Object to processing based on legitimate interests or for direct marketing (GDPR Art. 21).

To exercise any right, email admin@mongicore.com with subject Data Rights Request. We respond within 30 calendar days. EU/EEA residents may also lodge a complaint with their national supervisory authority.

Colombian residents (Habeas Data — Ley 1581/2012): You may file a complaint with the SIC at www.sic.gov.co.

10. Children’s Privacy

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, please email admin@mongicore.com and we will delete it promptly.

11. Data Security

We apply appropriate technical and organisational measures to protect your data:

  • HTTPS / TLS encryption for all data in transit
  • Bcrypt hashing for all stored passwords
  • Role-based access controls and principle of least privilege
  • Two-factor authentication (2FA) for platform access
  • Regular dependency updates and security reviews

In the event of a data breach likely to result in high risk to your rights, we will notify you and the relevant supervisory authority as required by law (within 72 hours under GDPR).

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, the “Last updated” date will be revised. Continued use of our services after a change constitutes acceptance of the updated policy.

13. Contact Us

For any questions or requests relating to this Privacy Policy or your personal data:

MongiCore SAS — Data Privacy

NIT 902049660-0

Cll 49 #3C – 20 1101, Bogotá D.C., Colombia

Email: admin@mongicore.com

Phone: +57 318 974 1737

We aim to respond to all privacy-related requests within 30 calendar days.

Also see our Terms of Service for information on your rights and obligations when using our services.

MongiCore

Empowering businesses through innovative technology solutions worldwide.

Services

  • Software Development
  • Mobile Applications
  • Web Hosting
  • Artificial Intelligence

Products

  • ViscoelasticsApp
  • YukuHost
  • ABC-TAMS

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© MongiCore SAS. NIT 902049660. All rights reserved.

Privacy Policy • Terms of Service

Cll 49 #3C - 20 1101, Bogotá, Colombia • +57 318 974 1737