PRIVACY POLICY

Personal Data Protection Policy and Data Processing

Personal Data Protection Policy and Data Processing

Website: happahub.com Version: 3.0

1. Legal basis and scope of application

This policy is developed in compliance with Articles 15 and 20 of the Political Constitution of Colombia, Statutory Law 1581 of 2012, Decree 1074 of 2015 (Chapters 25 and 26) consolidating Decree 1377 of 2013 and Decree 886 of 2014, Law 1266 of 2008, and administrative acts of the Superintendency of Industry and Commerce (SIC). When applicable to users from the European Economic Area, the Regulation (EU) 2016/679 (GDPR) is also observed.

Applies to all personal data (public, semiprivate, private, sensitive and data of children, adolescents) processed by happahub.com in its role as Controller and/or Processor, within the framework of accommodation search and reservations. The service has international reach, so processing may involve transfers and transmissions between countries (see section 17).

2. Identification of the Data Controller

The data controller is Happahub, through the website happahub.com. For any matter regarding personal data, the contact channel is manager@happahub.com.

3. Definitions

  • Authorization: prior, express, and informed consent of the Data Subject. It can be manifested in writing, orally, or through unequivocal actions; silence never equates to authorization.
  • Privacy Notice: communication directed to the Data Subject informing them of the existence of this policy, how to access it, and the purposes of data processing.
  • Database: organized set of personal data subject to processing.
  • Personal data: information linked or relatable to determined or determinable natural persons. It is classified as public, semiprivate, private, and sensitive.
  • Sensitive data: data that affects privacy or whose improper use can lead to discrimination (health, sexual life, biometric data, racial or ethnic origin, beliefs, affiliations, etc.).
  • Processor: the entity that processes data on behalf of the Controller.
  • Controller: the entity deciding on the database and/or data processing.
  • Data Subject: natural person whose data is subject to processing.
  • Transfer: sending data to a recipient who is also a Controller, within or outside the country.
  • Transmission: communication of data for processing by a Processor on behalf of the Controller, within or outside the country.
  • Processing: any operation on personal data (collection, storage, use, circulation, deletion, transfer, transmission).

4. Principles

All processing is governed by the principles of legality, purpose, freedom, truthfulness or quality, transparency, restricted access and circulation, security, confidentiality, and demonstrated responsibility (accountability), applied harmoniously to guarantee the right to habeas data.

5. Data we collect and purposes

5.1. Guests and customers

Data: first and last name; identity document or passport; email, phone, country/city; date of birth, nationality, and gender when required; reservation data (dates, nights, accommodation, number of guests, preferences, history); data of accompanying guests (name, document, and, when applicable, age); and payment data processed by external gateways (Stripe, PayU or others) -happahub.com does not store the full card number or CVV.

Purposes: manage and confirm reservations and register guests; verify identity; process payments and billing; address requests, inquiries, and complaints; communicate changes, cancellations, and incidents; fulfill legal, fiscal, and guest registration obligations; prevent fraud and ensure security; with consent, send promotions and offers; analyze preferences and use to improve the service; conduct satisfaction surveys; and process data directly or through a Processor in Colombia or another country, with necessary international transfer.

Third-party data (companions): whoever provides companion data declares they have their authorization and commits to informing them of this policy, being responsible for its truthfulness.

5.2. Suppliers and partners

Data: name, tax ID or identification, contact, position, and company data.

Purposes: manage contractual relationships, evaluate and supervise service, payments, and regulatory compliance.

5.3. Navigation and video surveillance

Navigation data (IP, browser, device, pages, cookies - section 12). If operating cameras in physical facilities, visible warnings will inform about surveillance, its security purpose, and access control, and channels to exercise rights; images are retained only as long as necessary.

5.4. Refusal to provide data

As certain identification data is required by lodging regulations, its non-provision may impede the service or reservation management.

6. Legal basis / Authorization

In Colombia, processing requires prior, express, and informed authorization, collected through means that allow future consultation (written, oral, or automated channels). When data is collected, information is provided about: processing and its purpose; the optional nature of responding regarding sensitive or minor data; the Data Subject's rights; and identification and contact of the Controller.

Under the GDPR, legal bases include contract execution (reservation), consent (marketing, non-essential cookies, companion data), legal obligation, and legitimate interest.

Authorization is not required when: a public/administrative entity requests in exercise of legal functions or by judicial order; public data is involved; medical or health emergency cases exist; processing is authorized by law for historical, statistical, or scientific purposes; or data pertains to Civil Registration.

7. Processing of minors' data

The processing of children's and adolescents' data is only carried out respecting their best interests and fundamental rights, with prior authorization from the legal representative and considering the minor's opinion depending on maturity. Accompanying minors' data is processed under the adult reservist's responsibility and solely for lodging purposes.

8. Recipients and partners

Data may be communicated (transmitted or transferred) to: accommodation providers and hotel sector partners (chains and operators with whom happahub.com has a business relationship, acting as controllers or processors under their own policies); payment gateways; technology providers (hosting, PMS/channel management, analytics, support) acting as Processors under contract; and competent authorities (including immigration, border control, and security purposes). Information is shared only when necessary to fulfill contractual commitments, protect legitimate interests, or comply with legal obligations.

9. Duties of happahub.com

As Controller: guarantee habeas data rights; retain a copy of the authorization; inform the purpose and rights; handle inquiries and complaints within legal deadlines; inform the data usage; maintain information with security measures; and observe all principles.

Towards the Processor: provide truthful and updated information, require security and confidentiality conditions, and ensure compliance with this policy.

As Processor (when applicable): process data according to principles; timely update, rectify, or suppress data; register legends "claim in progress" or "data in judicial discussion" as appropriate; permit access only to authorized personnel; and comply with instructions from the SIC.

10. Rights of Data Subjects

10.1. Under Law 1581 of 2012

Access, update, and rectify data; request proof of authorization; be informed of data usage; file complaints with the SIC; revoke authorization and/or request suppression; and free access to their data. Four claims are distinguished by law: correction, suppression, revocation, and infringement.

Data subjects can exercise these rights personally (with identity verification), their heirs, their representative/attorney, or by stipulation to someone else's favor. Minor's data rights are exercised by their representatives.

10.2. Under the GDPR

Access, rectification, suppression, limitation, portability, and objection, and immunity from automated decision-making; with the right to file a claim with the relevant control authority.

11. Data Subject assistance and procedure

Channels: email manager@happahub.com.

Request: must include full name and document of Data Subject (and their representative, with documentation accrediting representation); clear description of the petition and the right exercised; supporting documents when applicable; address for notifications; and date and signature (for physical requests).

Deadlines (Colombia): Consultation/access: maximum 10 business days; if not possible, notify and resolve within an additional 5 business days. Consultation is free at least once per calendar month. Claim: if incomplete, require amendment within 5 days (deemed abandoned with no response in 2 months). Once complete, "claim in process" legend is included within 2 business days and resolved within 15 business days, extendable up to 8 more business days. Once exhausted before happahub.com, the Data Subject may approach the SIC. Under GDPR, the term is up to 1 month extendable.

12. Cookies

We use first-party and third-party cookies across essential categories (necessary for functionality, non-disabling), functional, analytics/statistics, and marketing. Non-essential cookies require consent and can be managed or removed from browser settings (Chrome, Safari, Edge, Firefox, others). Disabling cookies may limit site functionality.

13. Security measures

We implement technical, human, and administrative measures to ensure confidentiality, integrity, and availability: encryption in transit and at rest, multifactor authentication for systems with sensitive data, network segregation, restricted access control to authorized personnel, backups, access logs, periodic audits, secure development, and staff training. Contracts with Processors include transmission clauses requiring equivalent measures. Since no system is entirely infallible, absolute security is not guaranteed.

14. Security incident management

happahub.com has procedures to detect, contain, assess, and mitigate incidents (unauthorized access, data loss or alteration, credential exposure, etc.). Includes risk evaluation for Data Subjects, authority notification when necessary, documenting lessons learned, and reporting to the SIC through the RNBD within 15 business days of detection, per regulations.

15. Artificial Intelligence (AI) data processing

When employing AI technologies, usage is restricted to authorized purposes and complies with Law 1581 of 2012 and 2024 SIC Circular 002, assessing suitability, necessity, reasonability, and proportionality. We refrain from AI usage posing significant risks to the Data Subject, applying principles of data protection and sufficient security measures.

16. Risk management

We identify risks associated with processing (crime, physical events, negligence or internal decisions), implementing controls and indicators to mitigate exposure, evaluating technology, human resources, infrastructure, and processes.

17. International transfers and transmissions

Transfers are conducted to countries with adequate protection levels as per SIC standards. Restrictions do not apply, among others, when: the Data Subject provides express and unequivocal authorization; exchanging medical data for health reasons; financial/stock transfers; based on reciprocal international treaties; necessary for contract execution (reservation) with Data Subject consent; or required to safeguard public interest or defend rights in legal proceedings. If the destination country is not listed as safe harbor, a compliance declaration with SIC will be managed.

Transmissions to a Processor do not require additional Data Subject consent, provided there is a transmission contract defining processing scope and obliging the Processor to process data according to principles, safeguard security, and maintain confidentiality. These conditions also apply to domestic transmissions. Under GDPR, transfers are safeguarded by standard contractual clauses or adequacy decisions.

18. National Database Registry (RNBD)

happahub.com registers and updates its databases in the RNBD managed by the SIC, in accordance with Article 25 of Law 1581 of 2012 and Decree 886 of 2014, within legally established deadlines.

19. Document management and retention

Documents with personal data are traceably retained on secure supports for the necessary time to fulfill purposes and legal deadlines (tax, accounting, fraud prevention). A custodian is designated, and when no longer required, documents are securely deleted or anonymized.

20. Validity and changes

This policy is effective from its publication date. happahub.com may modify it; non-substantial changes may be implemented without prior notification, while substantial changes will be communicated beforehand to Data Subjects. The current version is available at happahub.com.

21. Contact

For inquiries, requests, or complaints regarding personal data processing, Data Subjects can write to manager@happahub.com.