Privacy policy
PERSONAL DATA PROCESSING POLICY OF NMZ DISEÑOS S.A.S.
1. Introduction
This personal data processing policy of NMZ DISEÑOS S.A.S. or (Simplified Stock Company) is from now on referred to as “NMZ” or the “COMPANY” or “WE.” NMZ is responsible for the processing of personal data when performing the activities contained in the corporate purpose of the COMPANY. Herein are described the Holder’s privacy rights.
NMZ handles the processing of personal data, with the prior express authorization of the Holder which, is granted at different times and through various channels. The Holder agrees to the processing when he purchases goods or services in the authorized stores, through the Company’s websites, mobile applications, when entering into contracts or agreements, or in any other way that the Company has implemented for the marketing of its products and services. NMZ uses the collected personal data exclusively for the purposes indicated and specified in this personal data processing policy.
NMZ will handle the management of the data through the appointed Data Processing Officer, who may also contract third parties to process it under the terms of the law (from now on, Data Processors). The Data Processors will be obliged to protect the personal data following the Colombian legal system and this personal data protection policy as well.
The COMPANY may make modifications to this personal data processing policy.
2. Definitions.
For clarity, the following terms are defined relating to the fundamental right of habeas data or protection of personal data, which are essential for the understanding of this personal data processing policy:
“Habeas data or protection of personal data” is a fundamental right that grants the Holder the power to determine who and how his personal information is managed. In a sense, it gives the ability to know, update, rectify, authorize, include, and exclude information that is considered personal, and that is being managed in the database of a public or private entity.
“Authorization”: Prior, express, and informed consent of the Holder to carry out the processing of personal data.
“Database”: The organized set of personal data that is subject to processing.
“Personal data”: It is any information of any kind related, or that may be associated with one or more specific or definable legal persons or legal entities.
“Data Processor”: the natural person, or legal entity, public or private, who, by itself or in association with others, carries out the processing of personal data on behalf of the data controller.
“Data Controller”: the natural person, or legal entity, public or private, who, by itself or in association with others, decides on the database or the processing of the data.
“Holder”: A natural person whose personal data is processed.
“Processing of personal data”: Any operation or set of operations on personal data, such as collection, storage, use, circulation, or deletion.
“Sales channels”: Any NMZ’s sales channel.
3. REGULATION OF THE RIGHT OF HABEAS DATA.
The fundamental right of habeas data, or protection of personal data, is primarily regulated by the following legislation:
- • Political Constitution, Article 15.
- • Law 1266 of 2008.
- • Law 1581 of 2012.
- • Regulatory Decree No. 1727/ 2009.
- • Regulatory Decree No. 2952/2010.
- • Partial Regulatory Decree No. 1377/2013.
- • Rulings of the Constitutional Court: C – 1011/2008, and C – 748/2011.
4. DATA CONTROLLER.
NMZ DISEÑOS S.A.S, or (Simplified Stock Company), legally constituted by the laws of the Republic of Colombia, is responsible for the processing of personal data, and informs for all legal purposes, its identification data:
- Registered office: Capital District of Bogotá.
- - Address for legal notices: CL 57A # 45 - 21.
- - E-mail address: info@shopnmz.com
5. HOLDERS’ INFORMATION THAT IS BEING PROCESSED.
NMZ, handles the processing of personal data, of different types of data, and for different purposes; thus, this personal data processing policy applies to:
- • Personal data of NMZ’s Customers.
- • Personal data of NMZ’s Suppliers.
- • Personal data of NMZ’s Collaborators.
6. INFORMATION THAT IS COLLECTED.
WE collect personal information that allows us to contact the Holder in authorized establishments, hotlines, websites, mobile applications, in communications submitted directly by him to NMZ, and in any other means devised by the COMPANY to handle the processing of the Holder’s data, subject to prior authorization.
NMZ handles the administration and processing of the databases listed below; in other words, it has the control and decision-making power over their management.
7. CUSTOMERS’ DATABASES.
7.1.1. Description. Customers’ databases are the personal data of NMZ’s customers, who purchase goods marketed by the COMPANY through its various sales channels.
7.1.2. Content. These databases contain the following personal information:
7.1.2.1. Names and surnames, type of identification, identification number, nationality, sex, address, contact telephone number, email, age, date of birth, marital status, and family and health information.
7.1.2.2. Data stored by third parties, as long as WE have the authorization to access and process the data.
NMZ collects its Customers’ personal information when:
- • They register on NMZ’s website www.shopnmz.com
- • They sign up in NMZ’s mobile applications.
- • They register to participate in sweepstakes, surveys, or contests, developed by the COMPANY.
- • They let the COMPANY know that they are interested in receiving information about our products or services, such as email alerts, newsletters, and other notifications.
- • They request goods to be sent to their home address.
- • They interact with the COMPANY’s websites, mobile applications, and other online services.
7.1.4. Purpose of Processing. The information contained in our databases enables the COMPANY to:
- • Develop, fulfill, and execute the contract of sale and purchase of products or services that the Holder has acquired in any of the channels provided by our COMPANY.
- • Contact the Holder through email, phone calls, Short Messages Service (SMS), or other equivalent electronic means of communication, such as Facebook, WhatsApp, Instagram, or other similar platforms to the cellular number provided, concerning updates or informative communications and notifications related to NMA’s products or services purchased through the channels supplied by the COMPANY, or whenever necessary or authorized.
- • Send the Holder information about new products or related to the goods or services marketed by the COMPANY.
- • Send the Holder advertising and commercial communications for sale purposes or other business-related nature.
- • Carry out the processes of invoicing, portfolio, collection, and payments for the services rendered.
- • Respond to requests, complaints, or claims of the Holder.
- • Provide the Holder’s information to the data processors, such as the service providers, data processing centers or data centers, payment processing companies, transport companies that deliver orders, companies that provide information technology infrastructure services, customer service, emailing, auditing, and other services.
- • Attend judicial requests from authorities of the Republic of Colombia.
- • Fulfill the obligations undertaken by the COMPANY
- • Control the access to NMZ’s retail establishments as well as to its headquarters and establish security measures, which may include video surveillance.
- • Develop the area of marketing to provide the Holder a better service and advice and keep him updated on financial and legal issues that may be of interest.
- • Comply with the legal mandates established in the Colombian legal system.
7.2. SUPPLIERS’ DATABASE
7.2.1. Description. NMZ collects personal data of the persons who are linked to companies or to the suppliers that carry out economic activities as natural or legal entities.
7.2.2. Content. This database refers to the content of the following personal information:
- • Names and surnames, type of identification, identification number, address, contact telephone number, email, job title, financial, tax, and commercial information of the natural persons who are NMZ’s suppliers.
- • Registered name, tax identification number, names and surnames, type of identification and identification number of the legal representative, names, surnames and job title of the contact person, address, contact telephone number, email, job title, and financial, business, and commercial information of the legal entities that are NMZ’s suppliers.
7.2.3. How NMZ collects this data NMZ collects the personal information of the natural persons who are suppliers of goods and services and the personal data of the persons designated by the companies that supply products and services when:
- • They are registered as suppliers of goods and services of the COMPANY.
- • They are appointed by the suppliers to be the contact persons at the time of signing a contractual or a pre-contractual document that governs NMZ’s business relationship.
7.2.4. Purpose of the processing. The information contained in this database enables the COMPANY to:
- • Inform the supplier about the relationship status, information about the contract negotiations, and about the different issues that may impact on the contractual relationship.
- • Comply with the obligations acquired.
- • Comply with judicial decisions and administrative and legal, tax, and regulatory provisions.
- • Comply with the legal mandates established in the Colombian legal system.
8. COLLABORATORS’ DATABASE.
8.1. Description. These are the personal data of 1) the candidates for a position in the COMPANY, 2) NMZ’s workers, and 3) former workers, that is, those who expect to have, have, or had employment contracts with our COMPANY.
8.2. Content. This database contains the following personal information:
8.2.1. Names and surnames, type and number of identification, date, and place of issue of the identification document, date, and place of birth, age, sex, marital status, place of residence, address, contact telephone number, city, military passbook, email, pension fund, Subsidized Health Promoting Entity (EPS), severance fund, family data including children and adolescents in the first degree of consanguinity, photographic and biometric records, job title, formal and certified academic information, level of education, degree obtained, date of entry, date of completion, languages, work experience, job position, name of the company where the employee worked, salary earned, emergency contact, payroll, bank account number, bank account, medical data, and blood group.
8.3. How NMZ collects this data. NMZ collects personal information from its candidates, employees, and former employees when they:
- • Apply or aspire to get an employment contract for a specific position.
- • Enter into employment contracts.
- • Enter into apprenticeship and training contracts.
8.4. Purpose of processing. The information contained in this database enables the COMPANY to:
- • Select its personnel.
- • Issue labor certificates.
- • Give job references to those who are interested.
- • Manage directly or through third parties the processes of selection and recruitment of personnel, including the evaluation and qualification of the participants, the verification of work, personal references, and the completion of safety studies
- • Execute the activities of the COMPANY’s Human Resources Management, related to payroll, affiliations to entities of the social security system, activities of welfare and occupational health, and the legal authority to impose sanctions on employees.
- • Comply with the legal mandates established in the Colombian legal system.
The specific rule will apply in the case of administrative, commercial, and working arrangements of contracts or pre-contracts or when it is necessary to process personal data for the maintenance or fulfillment of the legal, contractual relationship.
9. SENSITIVE PERSONAL DATA AND PERSONAL DATA OF BOYS, GIRLS, AND ADOLESCENTS.
9.1. Sensitive personal data. NMZ currently performs the processes of sensitive personal data, such as biometric and medical data of its workers, only for the purposes related to health and safety policies at work, and expressly adhering to the procedures with the exceptions enshrined in the Article 6 of Law 1581 of 2012. The COMPANY reports that, in addition to complying with the requirements established for the authorization as set forth below, the Holder has the free right not to authorize the processing of sensitive data.
NMZ will process sensitive data under high security and confidentiality standards. For this purpose, the COMPANY has implemented administrative, technical, and legal measures, of mandatory compliance to those involved and, as applicable as the case may be, to its suppliers, affiliated companies, and commercial partners.
9.2. Personal data of boys, girls, and adolescents. NMZ does not process personal data of children and adolescents that are not public.
10. AUTHORIZATION.
The Holder authorizes NMZ the processing of his data for the purposes specified with prior, free, and informed consent. WE obtain the authorization, enabled by the regulations in force in the Colombian legal system, by mechanisms that ensure the Holder’s consultation, and these are:
- In writing.
- Orally or by telephone.
- Data message.
- Through explicit conduct of the Holder, that allows the COMPANY to conclude that he granted the authorization.
At NMZ, we will not process the collected personal data for purposes other than those authorized by the Holder. However, when the data is collected, the Holder will be expressly and unequivocally informed of the use of the processing. Also, the Holder can exercise his right of habeas data for access, rectification, cancellation, and opposition to the information that is collected.
11. RIGHTS OF THE HOLDER.
Every personal data Holder has the following rights:
11.1. Know, update, and rectify his data. This right may also be exercised if the data is partial, inaccurate, incomplete, fractioned, misleading, or if the processing is expressly prohibited or has not been authorized.
11.2. Request proof of the authorization given by NMZ for the processing of his data.
11.3. Be informed of the use and processing given to personal data, upon request through the service channels.
11.4. Submit complaints to the Superintendence of Industry and Commerce for infringements pursuant to the law and to other regulations that modify, add, or supplement it.
11.5. Revoke the authorization or request the erasing of one or more data when the processing does not respect the legal and constitutional principles, rights, and guarantees. The revocation or suppression will proceed when the Superintendence of Industry and Commerce has determined that the data processing has been incurred in conduct contrary to the law and the Constitution.
11.6. Access free of charge to data that has been processed.
12. DEPARTMENT RESPONSIBLE FOR ATTENTION AND PROCEDURE OF THE HOLDER’S RIGHTS.
The COMPANY’s website uses Comodo, a Secure Socket Layer (SSL). The Comodo digital certificate protects against malicious websites, and it is one of the world’s largest certifiers that enables real-time vulnerability assessments. This cryptographic protocol guarantees that the Holder’s data, such as mailing address, credit card information, or order history, will not be disclosed. This technology also prevents access to information by unauthorized third parties.
12.1. Responsible department. NMZ, as the party responsible for the processing of the Holder’s data, undertakes to respect the confidentiality of data and to guarantee the exercise of the right to habeas data.
The COMPANY has a Personal Data Officer, who is in charge of receiving, processing, and resolving requests, complaints, or claims. For matters related to personal data collected, his contact details are the following.
- Name of Responsible Party: Data Protection Officer
- E-mail: info@shopnmz.com
The Holder, whose personal information was collected by NMZ for processing, may contact the Data Protection Officer, through the channels provided to:
12.1.1. Request the correction, updating, or suppression of collected data.
12.1.2. Submit a request, complaint, or claim regarding the Holder’s data processing policy.
12.1.3. Consult the personal information that has been collected.
12.2. Procedure for the exercise of the Holder’s rights. For this purpose, the Holder must:
12.2.1. Write an e-mail to info@shopnmz.com
12.2.2. Once the respective communication has been received, the Responsible Department will have fifteen (15) business days to resolve the requests, complaints, or claims and respond to the Holder. If it is not possible to determine the requests, complaints, or claims, within that period, the Holder will be informed of the reasons for the delay and the date on which his claim will be addressed, which may not exceed eight (8) business days after the expiration of the first period.
12.2.3. The Responsible Area will send the respective response to the email from which the concern or complaint was sent, or to the address indicated in the communication.
12.2.4. Any communication that lacks a physical or electronic address will not be analyzed and will be discarded.
13. NATIONAL AND INTERNATIONAL TRANSFER AND TRANSMISSION OF PERSONAL DATA.
NMZ may transfer and transmit personal data collected in compliance with the standards of personal data protection required by the Colombian legal system and the Superintendence of Industry and Commerce.
14. MODIFICATIONS TO THE PERSONAL DATA PROCESSING POLICY OF NMZ DISEÑOS S.A.S.
NMZ may, at its discretion, modify its data processing policy.
15. VALIDITY.
This NMZ’s personal data processing policy is updated and shall become effective on June first (1), two thousand twenty (2020).




