← Back to home

Personal Data Processing Policy

Controller: Fidy

Version: policy-2026-08-03

Effective: August 2, 2026

This English translation is provided for convenience. The Spanish policy is the authoritative version.

1. Scope

This policy explains how Fidy, as the data controller, collects, uses, retains, accesses, updates, and deletes the personal data of users in Colombia. It applies to Fidy’s personal finance service, including its chat, API, and web channels.

2. Data we process

Fidy does not request sensitive data to provide the service. If a person incidentally sends sensitive data, Fidy will limit its processing to what is strictly necessary to address the request or comply with a legal obligation.

3. Purposes

Fidy processes personal data to:

Fidy will request additional authorization before using data for a new purpose that is not compatible with these purposes.

4. Authorization

Before creating an account or processing financial information, Fidy presents a privacy notice and requests a prior, express, and informed decision. Fidy retains evidence of the version presented, the decision, the date, and the message identifiers needed to demonstrate authorization. The person may decline; in that case, Fidy does not create the account or retain financial content sent before the decision.

5. Processors, transmissions, and transfers

Fidy may engage infrastructure, storage, messaging, security, and language-processing providers as data processors. In particular, Fidy uses OpenAI to process instructions and content through cloud services operated in the United States. These providers receive only the data necessary for their function and are subject to confidentiality, security, and processing-on-instruction obligations. When processing occurs outside Colombia, Fidy will apply Colombian requirements for international transmission or transfer of personal data.

6. Retention

Data is retained while the person uses Fidy or until they revoke authorization, unless a legal, contractual, accounting, security, or claims-defense obligation requires specific information to be retained longer. At the end of the applicable period, Fidy securely deletes the data. Minimal evidence of authorization or revocation may be retained for the period needed to demonstrate legal compliance.

7. Data-subject rights

The data subject may:

8. Inquiries, complaints, and revocation

Requests are received at obarboza@fidyapp.com. The request must identify the person, describe the facts, and provide an address for the response. Fidy may request reasonable information to verify identity and protect data against unauthorized disclosure.

9. Security

Fidy applies reasonable technical, human, and administrative safeguards to reduce the risk of unauthorized access, use, alteration, loss, or disclosure. No system is infallible; Fidy will manage incidents and notify people or authorities where required.

10. Changes to this policy

Fidy will publish each version at this address. If a change affects purposes or conditions that require new authorization, Fidy will request it before applying the change to that processing.