VHGValencia Holding Group
ESEN

Published: 1 October 2026

PERSONAL DATA PROCESSING AND PROTECTION POLICY

VALENCIA HOLDING GROUP
VHG Group Digital Legal Framework — Instrument MLD-04

Master policy on the governance, processing and protection of personal data of the VHG Group and its adhering entities

Version 2.0 — October 2026
Document subject to mandatory adoption and publication — Public access

Language notice. The governing language of this instrument is Spanish. This English version is published as a courtesy translation. In the event of any discrepancy, and in particular with respect to data subjects domiciled in Colombia, the Spanish version prevails.


DOCUMENT CONTROL

Identification

FieldDetail
DocumentMLD-04 — Personal Data Processing and Protection Policy
Master documentVHG Group Digital Legal Framework (MLD-VHG)
Issuing entityValencia Holding Group — Parent Company
Legal natureInformation Processing Policy (política de tratamiento de la información) under Article 2.2.2.25.3.1 of Colombian Decree 1074 of 2015
Related instrumentsMLD-01 (Terms), MLD-02 (Privacy Notice), MLD-03 (Cookie Notice)
Version2.0
Effective date1 October 2026
Material scopeAll personal databases of the VHG Group, digital and non-digital
Validity of databasesFor as long as the declared purposes and statutory retention periods subsist (Annex D)
Governing languageSpanish
StatusIn force

Version history

VersionDateDescriptionStatus
1.0 to 1.1July to September 2026Internal working versions. Not published.Superseded
2.01 October 2026First published version. Completion of controller identification, single contact channel, alignment of the governing law with the State of Delaware, trademark regime pending registration, and effectiveness with ordinary annual review.In force

Regulatory traceability convention

CategoryMeaningTreatment
Mandatory rulePublic-policy provision of compulsory applicationNo derogation permitted
Group standardRule adopted by VHG above the statutory minimumBinding on all adhering entities
Operational parameterTime limit, threshold or procedure defined by the GroupReviewable in the annual update
Deployment variableThe single field completed at the time of publicationMarked as 1 October 2026

Use notice

Document subject to mandatory adoption. This Policy is the instrument that Colombian law requires of every data controller and cannot be replaced by the Privacy Notice. Its formal adoption by each adhering entity, through a Deed of Adhesion, is a condition for the lawful operation of its databases. Non-compliance exposes the entity to the sanctions in Article 23 of Law 1581 of 2012.


CONTENTS

  1. Purpose, scope and group architecture
  2. Identification of the controller and governance structure
  3. Definitions
  4. Governing principles
  5. Data classification and special regimes
  6. Databases and purposes of processing
  7. Authorisation regime
  8. Data subject rights
  9. Duties of the VHG Group
  10. Procedure for handling enquiries and complaints
  11. Data processors and the supplier chain
  12. Data circulation within the VHG Group
  13. International transfers and transmissions
  14. Information security
  15. Security incident management
  16. National Database Register
  17. Retention, deletion and anonymisation
  18. Demonstrated accountability
  19. Special processing activities
  20. Sanctions regime and consequences of non-compliance
  21. Jurisdictional supplements
  22. Effectiveness, updating and regulatory monitoring
  23. Annexes and contact channels

1. Purpose, scope and group architecture

A processing policy is not a declaratory document but the instrument that legally organises the relationship between the Group and the persons whose data it administers. Its effectiveness depends on precisely delimiting what it covers, who applies it, and how it articulates with the Group's corporate structure.

1.1 Purpose

This Policy establishes the principles, criteria, procedures, safeguards and responsibilities governing the processing of personal data by Valencia Holding Group ("VHG" or the "Parent Company") and by the entities adhering to the VHG Group Digital Legal Framework (the "Adhering Entities" and, together, the "VHG Group").

It is adopted in compliance with Article 15 of the Political Constitution of Colombia, Law 1581 of 2012, Decree 1074 of 2015 — which consolidated Decree 1377 of 2013 — and concordant provisions, as well as the rules applicable in the other jurisdictions in which the Group operates.

1.2 Material scope

This Policy covers all personal databases of the VHG Group, irrespective of their medium, format or collection channel. It includes, without limitation:

● Databases fed by digital platforms, portals, applications and online forms.

● Databases arising from contracting with clients, investors, suppliers and contractors.

● Human resources databases, including candidates, employees and former employees.

● Due diligence and counterparty knowledge records.

● Physical, documentary and contractual files.

● Video surveillance and access control systems.

● Communications and customer service records.

This delimitation expressly corrects the exclusively digital scope of earlier instruments.

1.3 Subjective scope

Bound entities. VHG and every Adhering Entity. These include, among others, Valencia Capital Group (VCG) and Valencia Investment Group (VIG), as well as any other affiliate, subsidiary, company, brand or business unit that may in future join the Group, be incorporated by it or come under its direct or indirect control. This list is illustrative and not exhaustive: a new entity joins by executing the Deed of Adhesion under section 1.4, without any need to amend this Policy.

Data subjects covered. Any natural person whose data is processed by the VHG Group: platform users and visitors; current and prospective clients; investors and prospective investors; commercial counterparties; suppliers, contractors and their personnel; candidates and employees; and legal representatives, ultimate beneficial owners and contact persons of legal entities with which the Group deals.

Bound personnel. Directors, legal representatives, employees, contractors and third parties accessing personal data under the responsibility of the VHG Group, whose non-compliance shall give rise to the consequences set out in section 20.2.

1.4 Group architecture and adhesion

Valencia Holding Group is the Parent Company and the issuing unit of this Policy. It defines the mandatory minimum data protection standard for the entire Group and exercises coordination, verification and reporting functions through the Group Data Protection Office.

Each Adhering Entity is an autonomous Data Controller in respect of the databases whose purposes and means it determines. Adhesion creates no commingling of assets, no automatic joint controllership and no transfer of controller status to the Parent Company.

Adhesion is effected through a Deed of Adhesion in the form of Annex E, with the effects set out in section 2.2 of instrument MLD-01. As a condition of adhesion, each Adhering Entity must:

First. Complete and publish its Annex A — Identification Sheet.

Second. Formally designate its Data Protection Area and its contact point for the exercise of rights.

Third. Prepare and maintain its Annex D — Register of Databases, Purposes and Retention.

Fourth. Register its databases in the National Database Register where required under section 16.

Fifth. Execute Annex F — Intragroup Personal Data Transmission Master Agreement.

Power to supplement. Each Adhering Entity may issue its own supplements that raise the standard of this Policy, having regard to its activity, its regulated sector or its jurisdiction. No supplement may reduce, contradict or derogate from it.

1.5 Territorial scope and order of precedence

Under Article 2 of Law 1581 of 2012, the Colombian regime applies to processing carried out in Colombian territory and to controllers or processors not domiciled in Colombia to whom Colombian law applies by virtue of international rules and treaties.

The order of precedence, from which no derogation is permitted, is as follows:

OrderSource
1Mandatory and public-policy rules of the data subject's jurisdiction
2Applicable Jurisdictional Supplement (Annex B and section 21)
3Adhering Entity supplement, where it raises the standard
4This Policy (MLD-04)

2. Identification of the controller and governance structure

The law requires that data subjects know precisely against whom they exercise their rights. This section satisfies that requirement and also defines the internal structure that makes the Policy operational.

2.1 Identification of the controller

FieldDetail
Corporate nameValencia Holding Group LLC
NIT / RUC / EINWithheld from publication. Recorded in Annex A and disclosed to any authority so requiring
Principal domicileDelaware, United States of America
Physical address for serviceDelaware, United States of America. Designated formal channel for service: info@vhg.capital
Email address for the exercise of rightsinfo@vhg.capital
TelephoneNot published. Single contact channel: info@vhg.capital
Websitehttps://vhg.capital

The full identification of each Adhering Entity is set out in Annex A.

2.2 Area responsible for handling requests, enquiries and complaints

In compliance with Article 2.2.2.25.3.1(d) of Decree 1074 of 2015, the following area is designated as responsible for handling requests, enquiries and complaints before which data subjects may exercise their rights:

FieldDetail
Name of the areaVHG Group Data Protection Office
Email addressinfo@vhg.capital
Physical addressDelaware, United States of America
TelephoneNot published. Single contact channel: info@vhg.capital
Service hoursPermanent electronic intake. Response within the statutory periods, counted in business days

2.3 Group Data Protection Office

VHG designates a Group Data Protection Office (DPO) with the following functions:

● To maintain, interpret and update the Digital Legal Framework.

● To coordinate and verify implementation of this Policy across the Adhering Entities.

● To advise on impact assessments for high-risk processing.

● To consolidate incident reporting and act as interlocutor with supervisory authorities.

● To present an annual compliance report to the highest management body.

● To approve Adhering Entity supplements.

The DPO exercises its functions with functional independence and may not receive instructions that compromise its technical judgment. Its identification is set out in Annex A.

2.4 Data Protection and Information Governance Committee

A Committee is constituted with participation from the DPO, legal, technology, compliance and risk functions, meeting at least twice a year, responsible for reviewing the state of compliance, materialised incidents, identified gaps and the remediation plan.


3. Definitions

For the purposes of this Policy, the definitions in Article 3 of Law 1581 of 2012 and Article 2.2.2.25.1.3 of Decree 1074 of 2015 are adopted:

Authorisation. The data subject's prior, express and informed consent to the processing of their personal data.

Privacy notice. Verbal or written communication addressed to the data subject informing them of the existence of the processing policies, how to access them, and the purposes of processing.

Database. An organised set of personal data subject to processing.

Personal data. Any information linked to, or capable of being associated with, one or more identified or identifiable natural persons.

Public data. Data that is not semi-private, private or sensitive, such as data relating to civil status, profession or occupation and status as a merchant or public servant, and data contained in public documents, final judgments and public registers.

Semi-private data. Data that is neither intimate nor public in nature and whose knowledge is of interest to the data subject and to a specific group of persons.

Private data. Data of an intimate or restricted nature of interest only to its data subject.

Sensitive data. Data affecting the data subject's privacy or whose misuse may give rise to discrimination.

Data processor. A person who processes personal data on behalf of the controller.

Data controller. A person who decides on the database and on the processing of the data.

Data subject. The natural person whose personal data is processed.

Transfer. The sending of data to a recipient that is itself a controller, located inside or outside the country.

Transmission. The communication of data to a processor so that the latter may process it on behalf of the controller.

Processing. Any operation on personal data, such as collection, storage, use, circulation or deletion.

Security incident. An event compromising the confidentiality, integrity or availability of personal data.


4. Governing principles

The processing of personal data by the VHG Group is subject to the principles set out in Article 4 of Law 1581 of 2012, which operate as criteria for the interpretation of the entire Policy:

Lawfulness. Processing is a regulated activity that must comply with the law and its implementing provisions.

Purpose limitation. Processing serves a legitimate, specified purpose previously communicated to the data subject. No database is used for purposes other than those declared in Annex D.

Freedom. Processing is carried out only with the data subject's prior, express and informed consent. Data is neither obtained nor disclosed without authorisation, save under a legal or judicial mandate.

Accuracy or quality. Information is truthful, complete, exact, current, verifiable and comprehensible. The processing of partial, incomplete, fragmented or misleading data is prohibited.

Transparency. Data subjects are guaranteed the right to obtain, at any time and without restriction, information about the existence of data concerning them.

Restricted access and circulation. Processing is subject to the limits deriving from the nature of the data. Personal data other than public information may not be made available through mass dissemination media unless access is technically controllable.

Security. Information is handled with the technical, human and administrative measures necessary to secure records, preventing their alteration, loss, or unauthorised or fraudulent consultation, use or access.

Confidentiality. All persons involved in processing are obliged to maintain the confidentiality of the information, an obligation that subsists even after their relationship with the Group has ended.

Demonstrated accountability. As an additional Group standard, compliance is not declared: it is documented, measured and evidenced to the data subject and to the authority, in accordance with section 18.


5. Data classification and special regimes

Not all data admits the same treatment. Classification determines the level of authorisation required, the applicable security measures and the limits on circulation, and is therefore the operational starting point for every decision concerning data.

5.1 General classification

Under Law 1581 of 2012 and Constitutional Court Judgment C-748 of 2011, data is classified as public, semi-private, private and sensitive, with increasing levels of protection and restriction on circulation.

5.2 Sensitive data

Rule. The processing of sensitive data is prohibited, save in the cases set out in Article 6 of Law 1581 of 2012: where the data subject has given explicit authorisation, unless the law does not require it; where processing is necessary to safeguard the vital interest of a data subject who is physically or legally incapacitated; where processing is carried out in the course of legitimate activities by a foundation, NGO, association or other non-profit body with a political, philosophical, religious or trade union purpose, in respect of its members; where the data is necessary for the recognition, exercise or defence of a right in judicial proceedings; or where processing has a historical, statistical or scientific purpose and identity-suppression measures are adopted.

Additional safeguards. Where the VHG Group needs to process sensitive data, it shall:

● Inform the data subject that the data is sensitive and of the specific purpose.

● Obtain explicit authorisation, separate from the general authorisation.

● Expressly inform the data subject that they are not obliged to authorise the processing of sensitive data or to answer questions about it.

● Apply enhanced access controls, encryption and distinct audit logging.

● Refrain from conditioning any activity on the provision of sensitive data, save under a legal mandate.

5.3 Children's and adolescents' data

The processing of minors' data is prohibited, save where the data is of a public nature and the processing meets the parameters of Article 2.2.2.25.2.9 of Decree 1074 of 2015: responding to and respecting the best interests of the child, and ensuring respect for their fundamental rights.

The VHG Group:

● Does not direct its platforms or products to minors.

● Requires the authorisation of the legal representative, having taken account of the minor's views where their maturity permits.

● Immediately deletes minors' data collected inadvertently.

● Refrains from profiling or advertising directed at minors.

5.4 Financial and credit data

Where an Adhering Entity administers, reports or consults financial, credit, commercial or service information with information operators, such processing is additionally governed by Law 1266 of 2008 and its implementing rules, with the safeguards specific to that regime — prior notice before an adverse report, right of defence, information retention periods and lapse of adverse data.

Clarification. Law 1266 of 2008 governs financial and credit habeas data; the general personal data protection regime is that of Law 1581 of 2012. The two regimes are concurrent and do not replace one another. This clarification corrects the generic reference to the "Habeas Data Law" used in earlier versions of the Framework.

5.5 Data of legal entities

Data of legal entities is not personal data. However, data of their legal representatives, directors, ultimate beneficial owners, individual shareholders and contact personnel is personal data and is fully subject to this Policy.


6. Databases and purposes of processing

6.1 Register of databases

Each Adhering Entity prepares and keeps current Annex D — Register of Databases, Purposes and Retention, with the following minimum structure:

DatabaseCategories of data subjectsCategories of dataPurposesLawful basisProcessorsTransfersRetention periodSecurity measures
Web contacts and enquiriesVisitors and contactsIdentification, contact details and message contentHandling enquiries and relationship managementData subject authorisationHosting and email providerUnited StatesTwo (2) years from the last interactionEncryption in transit and at rest; access control
Suppliers and contractorsCounterparty personnelIdentification, contact and contractual dataContract performance and regulatory complianceAuthorisation and contract performanceLegal, accounting and audit advisersColombia and United StatesLimitation period for contractual actionsAccess control and audit logging
Talent managementEmployment candidatesIdentification, contact details and professional backgroundCandidate selection and assessmentData subject authorisationNot applicableColombiaTwelve (12) months from the close of the processRestricted access control

Annex D is updated at least annually and whenever a database is created, a purpose is modified or a new processor is engaged.

6.2 Declared purposes

The VHG Group processes personal data exclusively for the purposes declared in section 5 of instrument MLD-02, which are incorporated here in full: relationship management; contract performance; regulatory compliance, including anti-money-laundering and counter-terrorist-financing; risk management and security; corporate governance; platform improvement; institutional and commercial communications subject to specific authorisation; and talent management.

Prohibition on undeclared secondary purposes. No Group entity may use personal data for purposes other than, or incompatible with, those declared. Adding a new purpose requires updating Annex D, prior communication to the data subject and fresh authorisation.


7. Authorisation regime

Authorisation is the cornerstone of the Colombian data protection system and the point at which non-compliance most frequently materialises. This section sets out its regime without reference to foreign standards that Colombian law does not recognise.

7.1 Requirements

Authorisation must be prior to collection, express — manifested through unequivocal conduct — and informed, that is, preceded by communication to the data subject of the controller's identity, the purposes of processing, the optional nature of answering questions about sensitive data or minors' data, their rights, and how to access this Policy.

7.2 Absence of legitimate interest as an autonomous basis

Mandatory rule. Colombian law does not recognise "legitimate interest" as an autonomous lawful basis for processing. The only cases in which authorisation is not required are those exhaustively listed in Article 10 of Law 1581 of 2012: (i) information required by a public or administrative body in the exercise of its statutory functions or by court order; (ii) data of a public nature; (iii) medical or health emergencies; (iv) processing authorised by law for historical, statistical or scientific purposes; and (v) data relating to the Civil Registry of Persons. No Group entity may invoke legitimate interest as the basis for processing subject to Colombian law.

7.3 Manner of obtaining and evidence

Authorisation is obtained by means permitting subsequent consultation: a physical document, an electronic signature, an unchecked verification box, an acceptance button, a voice recording with prior warning, or unequivocal conduct of the data subject reasonably permitting the conclusion that authorisation was granted.

The VHG Group retains evidence of authorisation as required by Article 9 of Law 1581 of 2012, recording the date, time, channel, version of the text disclosed and technical traces. This record is retained throughout the processing and, at a minimum, for five (5) years after its termination.

The following do not constitute authorisation: silence, inactivity, pre-ticked boxes, continued browsing or continued use of a service.

7.4 Authorisation for data collected before this Policy took effect

In respect of previously collected data, the VHG Group shall conduct the authorisation request process set out in Article 2.2.2.25.2.4 of Decree 1074 of 2015, using efficient means of communication with the data subject. If, thirty (30) business days after the communication, the data subject has not objected and has continued using the services, authorisation shall be deemed to subsist; otherwise, the data shall be deleted.

7.5 Withdrawal and requests for deletion

Data subjects may withdraw authorisation and request deletion of their data at any time, free of charge, in whole or in part in respect of specific purposes.

Deletion does not proceed where the data subject is under a legal or contractual duty to remain in the database, or where deletion would obstruct judicial or administrative proceedings relating to tax obligations, the investigation of offences or the updating of administrative sanctions. In such cases, the refusal shall be communicated to the data subject with reasons within the time limits in section 10.


8. Data subject rights

Under Article 8 of Law 1581 of 2012, data subjects have the right to: know, update and rectify their data; request evidence of the authorisation granted; be informed of the use made of their data; lodge complaints with the Superintendency of Industry and Commerce once the procedure before the controller has been exhausted; withdraw authorisation and request deletion where applicable; and access their data free of charge.

Standing. These rights may be exercised by the data subject; by their successors, who must evidence that status; by the data subject's representative or attorney-in-fact; and under a stipulation in favour of a third party. Minors' rights shall be exercised by the person empowered to represent them.

Proof of identity. The VHG Group shall verify the applicant's identity through proportionate mechanisms, refraining from requesting excessive information or collecting additional data on the occasion of the request.


9. Duties of the VHG Group

9.1 As controller

Under Article 17 of Law 1581 of 2012, the VHG Group must: guarantee the data subject full exercise of habeas data; request and retain a copy of the authorisation; duly inform the data subject of the purpose and of their rights; keep the information under conditions of security; ensure the information is truthful, complete, exact, current, verifiable and comprehensible; update and rectify the information; supply the processor only with data whose processing has been authorised; require the processor to observe security and privacy conditions; handle enquiries and complaints; adopt an internal manual of policies and procedures; inform the processor where information is under dispute; inform the data subject, on request, of the use made of their data; and inform the data protection authority where breaches of security codes occur and risks arise in the administration of information.

9.2 As processor

Where a Group entity acts as processor on behalf of a third party, it shall observe the duties in Article 18 of Law 1581 of 2012, in particular processing data only in accordance with the controller's instructions and refraining from using it for its own purposes.


10. Procedure for handling enquiries and complaints

A right without a defined procedure is unenforceable. This section adopts the statutory procedure and time limits expressly and verifiably, and constitutes the mandatory minimum standard for every Adhering Entity.

10.1 Channels

Requests are submitted through the channels in section 23.2, stating: the data subject's name and identification; the capacity in which they act and evidence of standing where applicable; a precise description of the request; a physical or electronic address for service; and supporting documents.

10.2 Enquiries

Time limit: ten (10) business days from the date of receipt. Where the enquiry cannot be answered within that period, the interested party shall be informed before its expiry, stating the reasons and the date on which it will be answered, which may not exceed five (5) business days following expiry of the first period. (Article 14, Law 1581 of 2012.)

10.3 Complaints

Time limit: fifteen (15) business days from the day following receipt. Where the complaint cannot be handled within that period, the interested party shall be informed of the reasons for the delay and of the response date, which may not exceed eight (8) business days following expiry of the first period. (Article 15, Law 1581 of 2012.)

SituationActionTime limit
Incomplete complaintRequest to the interested party to remedy5 days from receipt
Interested party fails to remedyComplaint deemed withdrawn2 months from the request
Entity not competentReferral to the competent party and notice to the interested party2 business days
Complaint pendingInclusion of the legend "complaint pending" and its subject matter in the database2 business days

10.4 Procedural prerequisite

Under Article 16 of Law 1581 of 2012, a data subject may lodge a complaint with the Superintendency of Industry and Commerce only once the enquiry or complaint procedure before the controller or processor has been exhausted.

10.5 Record and traceability

Each Adhering Entity maintains a register of requests with a unique reference, date and time of receipt, intake channel, type of request, response date, the substance of the decision and evidence of notification. This register feeds the DPO's annual report and serves as evidence before the authority.

Special rule arising from the single channel. The VHG Group operates a single contact mailbox (info@vhg.capital). Traceability is therefore provided not by the email address but by the procedure: every incoming communication is classified upon receipt as an enquiry, a complaint, a withdrawal request, legal service, an incident report or general correspondence, and those constituting an exercise of rights are immediately entered in the register, triggering the running of statutory periods. Incorrect or late classification of a request neither suspends nor interrupts the periods in sections 10.2 and 10.3.

10.6 No charge

The exercise of rights is free of charge. No payment shall be required and handling shall not be conditioned on any consideration. Information may be supplied by any means, including electronic means, requested by the data subject.


11. Data processors and the supplier chain

The risk of a processing activity does not stop at the boundaries of the organisation: it extends to the entire supplier chain that accesses the data. Its contractual governance is therefore an integral part of the security duty.

11.1 Prior due diligence

Before engaging a processor, the Adhering Entity assesses its technical and organisational security conditions, its location and that of its subcontractors, its certifications, its incident history and its mechanisms for handling data subject rights. The assessment is documented.

11.2 Transmission agreement

Every transmission to a processor is documented in an agreement which, under Article 2.2.2.25.5.2 of Decree 1074 of 2015, must contain at least: the scope and purposes of the processing; the activities the processor will carry out on behalf of the controller; the processor's obligations to the data subject and to the controller; the duty to process data in accordance with the authorised purpose and applicable law; the duty to safeguard the security of the databases; the duty of confidentiality; and the return or deletion of data at the end of the relationship.

11.3 Sub-processors

The processor may not subcontract processing without the controller's prior written authorisation. Authorisation is conditioned on the sub-processor assuming equivalent obligations and on the processor retaining responsibility towards the controller.

11.4 Audit

The controller reserves the right to audit the processor, directly or through an independent third party, on reasonable notice and without disrupting operations.


12. Data circulation within the VHG Group

Membership of the same corporate group does not, on its own, permit the free flow of data between its entities. Each flow requires legal characterisation and its own basis.

12.1 Characterisation of the flow

Transmission. Where a Group entity processes data on behalf of another, following its instructions and without determining its own purposes, it acts as a processor. The flow is governed by the agreement in section 11.2 and requires no additional authorisation from the data subject, provided the purpose has been declared.

Transfer. Where the receiving entity determines its own purposes, it acts as an independent controller. The flow constitutes a transfer and requires the data subject's authorisation, disclosed at the time of collection or requested subsequently.

12.2 Intragroup Master Agreement

VHG and the Adhering Entities execute Annex F — Intragroup Personal Data Transmission Master Agreement, which documents the flows, characterises each entity's position, defines the permissible purposes, establishes common security measures and governs the handling of rights requests where a data subject approaches an entity other than the controller.

12.3 Single point of entry

Data subjects may exercise their rights before any VHG Group entity. The entity receiving the request shall refer it to the controller within two (2) business days and inform the data subject accordingly, without the internal referral affecting the statutory response periods owed to the data subject.


13. International transfers and transmissions

13.1 Applicable regime

Mandatory rule. Article 26 of Law 1581 of 2012 prohibits the transfer of personal data to countries that do not provide adequate levels of protection, meaning those meeting the standards set by the Superintendency of Industry and Commerce. The prohibition does not apply where: the data subject has given express and unequivocal authorisation; the transfer concerns the exchange of medical data required for the data subject's treatment on grounds of health or public hygiene; the transfer concerns banking or stock-exchange transfers under the applicable legislation; the transfer has been agreed in an international treaty to which Colombia is a party; the transfer is necessary for the performance of a contract between the data subject and the controller or for pre-contractual measures, provided authorisation exists; or the transfer is legally required to safeguard the public interest or for the recognition, exercise or defence of a right in judicial proceedings.

13.2 Countries with an adequate level of protection

Under External Circular 005 of 2017 of the Superintendency of Industry and Commerce, the following countries, among others, are declared to provide an adequate level of protection: Germany, Austria, Belgium, Bulgaria, Cyprus, Costa Rica, Croatia, Denmark, Slovakia, Slovenia, Spain, the United States of America, Estonia, Finland, France, Greece, Hungary, Ireland, Iceland, Italy, Latvia, Lithuania, Luxembourg, Malta, Mexico, Norway, the Netherlands, Peru, Poland, Portugal, the United Kingdom, the Czech Republic, the Republic of Korea, Romania, Serbia and Sweden, as well as countries declared adequate by the European Commission.

Current processing destinations. As at the publication date of this Policy, the VHG Group's only processing destinations are Colombia and the United States of America, the latter declared to provide an adequate level of protection by External Circular 005 of 2017. The Group carries out no transfers or transmissions to jurisdictions not declared adequate, including Panama, which does not appear on that list.

Activation rule. Before enabling any flow to a destination not declared adequate, the Group Data Protection Office must verify and document its basis, which may only be: (i) the data subject's express and unequivocal authorisation, specifically informed as to the destination; (ii) a declaration of conformity issued by the Superintendency of Industry and Commerce; or (iii) one of the exceptions in Article 26 of Law 1581 of 2012. No such flow may commence without that prior verification.

13.3 Periodic verification

The list of countries with an adequate level of protection is dynamic. The DPO verifies its currency at least annually and upon any pronouncement by the authority, updating Annex D accordingly.

13.4 Contractual safeguards

Irrespective of the adequacy status of the destination, every international transfer or transmission is documented with clauses imposing on the recipient obligations equivalent to those in this Policy as regards purpose, security, confidentiality, handling of rights, incident notification and return or deletion.

13.5 Declaration of conformity

Where a flow cannot rely on a statutory exception or on the data subject's authorisation, the Adhering Entity shall obtain a declaration of conformity from the Superintendency of Industry and Commerce before commencing the transfer.


14. Information security

The security principle is evidenced not by a statement of intent but by verifiable controls proportionate to the risk. The VHG Group adopts the following minimum standard, binding on every Adhering Entity.

14.1 Administrative measures

● An internal manual of policies and procedures, of which this Policy forms part.

● Formal allocation of roles and responsibilities for each database.

● Confidentiality agreements executed by all personnel and contractors.

● An annual training programme with attendance records and assessment.

● A documented procedure for granting, modifying and revoking access.

14.2 Technical measures

● Access control under the principles of least privilege and need to know.

● Enhanced authentication for access to databases containing sensitive or high-volume information.

● Encryption of information in transit and at rest, in line with the state of the art.

● Audit logging of accesses and operations, retained for a minimum of twelve (12) months and protected against alteration.

● Periodic backups and documented restoration testing.

● Environment segregation and a prohibition on using real personal data in development and testing environments without prior pseudonymisation.

● Vulnerability management and timely patching.

14.3 Physical measures

● Access control to premises, data centres and documentary archives.

● Secure custody and destruction of physical media.

● Clear desk and clear screen protocols.

14.4 Duty of confidentiality

All persons involved in processing are obliged to maintain the confidentiality of the information. This obligation subsists even after their relationship with the VHG Group has ended.


15. Security incident management

15.1 Definition and detection

A security incident is any event that compromises or may compromise the confidentiality, integrity or availability of personal data, including unauthorised access, loss or destruction of information, improper disclosure, cyberattacks and human error affecting data.

15.2 Protocol

PhaseActionMaximum time
Detection and internal reportingImmediate communication to the Data Protection Area and the DPOWithout delay, upon becoming aware
ContainmentMeasures to halt the incident and limit its scopeImmediate
AssessmentDetermination of scope, categories of data and data subjects affected, and risk to their rights72 hours
Reporting to the authorityReport to the Superintendency of Industry and Commerce through the National Database RegisterWithin 15 business days of detection
Communication to data subjectsWhere the incident entails a risk to data subjects' rightsWithout undue delay
Remediation and closureCorrective actions and lessons learned30 calendar days

Reporting to the authority is made in compliance with Article 17(n) of Law 1581 of 2012 and the instructions issued by the Superintendency of Industry and Commerce through the National Database Register. Where an incident affects additional jurisdictions, the notification duties of each shall be discharged in parallel.

15.3 Incident register

Each Adhering Entity maintains an incident register recording the description, date of detection, categories and volume of data affected, measures adopted, reports made and closure status. The DPO consolidates the Group register.


16. National Database Register

Private legal entities are required to register their databases containing personal data in the National Database Register (RNBD) administered by the Superintendency of Industry and Commerce, under Article 25 of Law 1581 of 2012 and its implementing rules.

Applicability threshold. Decree 090 of 2018 limited the registration obligation to companies and non-profit entities with total assets exceeding 100,000 UVT.

Current position of the Group. As at the publication date of this Policy, no VHG Group entity reaches the 100,000 UVT threshold in total assets, so RNBD registration is not required of it. This position is not permanent: the threshold is assessed against each financial year's statements and the UVT value in force for that year. Accordingly, the Group Data Protection Office shall verify the threshold annually, within one month of approval of each Adhering Entity's financial statements, and shall document that verification whether or not the threshold is exceeded. Once exceeded, registration must be effected within the period set by the authority.

Associated obligations. Registered entities must keep the information on their databases current and report, through the RNBD, complaints submitted by data subjects and security incidents, within the time limits set by the authority.

Verification. The DPO verifies annually the registration status of each Adhering Entity and documents that verification, whether or not the entity exceeds the threshold.


17. Retention, deletion and anonymisation

17.1 Retention criteria

Personal data is retained only for as long as necessary to: fulfil the declared purpose; meet legal, accounting, tax, employment and regulatory obligations; and exercise or defend rights during the applicable limitation and lapse periods.

Specific periods by database are set out in Annex D. In the absence of a special rule, the default period is the general limitation period for ordinary actions applicable in the relevant jurisdiction.

17.2 Secure deletion

Once the retention period expires, data is deleted through procedures preventing its recovery, in both production systems and backups, with documentary evidence of the deletion. Where immediate deletion from backups is not technically feasible, the data shall be blocked until backup rotation.

17.3 Anonymisation

As an alternative to deletion, the VHG Group may subject data to irreversible anonymisation, after which it ceases to be personal data. Anonymisation must prevent re-identification by reasonably available means; mere pseudonymisation is not equivalent to anonymisation and does not exempt from compliance with this Policy.


18. Demonstrated accountability

Compliance is not declared: it is evidenced. The principle of demonstrated accountability, incorporated in Article 2.2.2.25.6.1 of Decree 1074 of 2015 and developed by the Superintendency of Industry and Commerce, requires the controller to adopt appropriate, effective and verifiable measures and to demonstrate their implementation.

18.1 Comprehensive Personal Data Management Programme

Each Adhering Entity implements a programme comprising, at a minimum: this Policy and its derived procedures; a current Annex D; the register of authorisations; the register of data subject requests; the incident register; contracts with processors; the international transfer matrix; the annual training plan; and the annual compliance report.

18.2 Privacy by design and by default

Every new product, platform, feature or process involving the processing of personal data incorporates data protection considerations from the design phase, applying by default the most protective configuration, data minimisation and purpose limitation.

18.3 Impact assessment

High-risk processing — large-scale processing of sensitive data, systematic profiling, automated decisions with legal effects, extensive video surveillance, use of biometric data or the incorporation of artificial intelligence systems — requires a prior impact assessment, documented and approved by the DPO.

18.4 Training

Personnel receive training on joining and at least annually, with content differentiated according to their level of access to data. Attendance and assessment records are retained.

18.5 Audit and review

The DPO conducts an annual compliance review of each Adhering Entity, the results of which are presented to the Committee and to the highest management body, together with a remediation plan and assigned owners.


19. Special processing activities

19.1 Video surveillance

The installation of video surveillance systems is limited to the security of persons and property, with visible signage at capture points, a prohibition on capture in areas of reasonable expectation of privacy, restricted access to recordings and a retention period not exceeding thirty (30) calendar days, unless the images document an incident under investigation.

19.2 Commercial communications

Sending commercial communications requires specific and separate authorisation, revocable at any time. In Colombia, Law 2300 of 2023 additionally applies: contact only through channels authorised by the consumer, within permitted hours — Monday to Friday from 7:00 to 19:00 and Saturdays from 8:00 to 15:00, prohibited on Sundays and public holidays — respecting frequency limits and immediately honouring any request not to be contacted.

19.3 Biometric data

Biometric data is sensitive data. Its processing requires explicit and separate authorisation, a prior impact assessment, encrypted storage, a prohibition on use for purposes other than the declared authentication or access control, and the availability of a non-biometric alternative for data subjects who do not authorise it.

19.4 Automated decisions, profiling and artificial intelligence

The VHG Group does not take decisions based solely on automated processing that produce legal effects on, or significantly affect, a data subject, without qualified human intervention and without prior disclosure.

Any artificial intelligence system processing personal data is subject to: a prior impact assessment; documentation of the processing logic and the categories of data used; a prohibition on using personal data for model training without the data subject's specific and informed authorisation; and periodic review of outputs to detect discriminatory bias.

19.5 Employment and candidate data

Candidate data is retained for a maximum of twelve (12) months from the conclusion of the process, unless express authorisation is given for retention in a talent pool. It is prohibited to request information on pregnancy status, sexual orientation, political or trade union affiliation, or any sensitive data unrelated to suitability for the role.

19.6 Anti-money-laundering compliance

The processing of data for due diligence, counterparty knowledge, restrictive list screening and reporting to authorities is carried out on the basis of compliance with legal obligations. Where applicable, the regimes of External Circular 100-000016 of 2020 of the Superintendency of Companies (SAGRILAFT), the Business Transparency and Ethics Programme and the rules of the Financial Information and Analysis Unit shall be observed. The statutory confidentiality of suspicious transaction reports prevails over the data subject's right of access, as provided by law.


20. Sanctions regime and consequences of non-compliance

20.1 Administrative sanctions

Non-compliance with the data protection regime exposes the controller to the sanctions in Article 23 of Law 1581 of 2012, imposed by the Superintendency of Industry and Commerce:

● Personal and institutional fines of up to the equivalent of two thousand (2,000) current statutory monthly minimum wages.

● Suspension of processing-related activities for up to six (6) months.

● Temporary closure of processing-related operations where the suspension period elapses without corrective measures being adopted.

● Immediate and permanent closure of operations involving the processing of sensitive data.

In Panama, the sanctions under Law 81 of 2019 imposed by the competent authority apply; in other jurisdictions, those provided by the relevant regime.

20.2 Internal consequences

Breach of this Policy by directors, employees or contractors constitutes serious misconduct and gives rise to the applicable disciplinary and contractual measures, without prejudice to applicable civil and criminal actions, including those arising from Article 269F of the Criminal Code — breach of personal data, added by Law 1273 of 2009.


21. Jurisdictional supplements

This Policy constitutes the Group's minimum standard. In each jurisdiction, the local regime applies in addition and prevails where more protective.

21.1 Colombia

Principal regime: Article 15 of the Political Constitution; Law 1581 of 2012; Decree 1074 of 2015; Law 1266 of 2008 on financial habeas data; Law 1273 of 2009 on criminal matters; Law 1480 of 2011 on consumer protection; Law 2300 of 2023 on contact with consumers; Law 527 of 1999 on data messages. Supervisory authority: Superintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data.

21.2 Other jurisdictions — contingency regime

The VHG Group does not currently operate databases in jurisdictions other than Colombia and the United States. Should an Adhering Entity become established in, or process data in, another territory, its adhesion shall trigger the issuance of the corresponding jurisdictional supplement before processing begins.

By way of provision, it is recorded that in Panama — a jurisdiction referenced in earlier versions of the Framework — Law 81 of 26 March 2019 on Personal Data Protection applies, as implemented by Executive Decree 285 of 28 May 2021, under the supervision of the National Authority for Transparency and Access to Information (ANTAI), with a regime likewise structured around the data subject's consent.

21.3 United States

Valencia Holding Group LLC is incorporated in the State of Delaware. There is no general federal data protection regime in the United States. The following apply as relevant: Section 5 of the Federal Trade Commission Act on unfair or deceptive practices; state consumer privacy laws where their applicability thresholds are met — which the Group does not currently reach; and any applicable sector-specific regulation. The Group Data Protection Office shall review annually whether any state law becomes applicable by reason of revenue or data-subject volume thresholds being exceeded, and shall document that determination.

21.4 European Economic Area and United Kingdom

The VHG Group does not declare general subjection to Regulation (EU) 2016/679. Where an Adhering Entity offers goods or services to persons in the European Economic Area or monitors their behaviour, within the meaning of Article 3 of the Regulation, it must carry out a formal applicability determination and, where appropriate, adopt the additional measures the Regulation requires, including the possible designation of a representative under its Article 27.

References to "GDPR-aligned standards" in Group documents are voluntary best practice and do not constitute a declaration of applicability.


22. Effectiveness, updating and regulatory monitoring

22.1 Effectiveness

This Policy takes effect upon publication at https://vhg.capital, on the date stated in the Document Control block, and remains in force until superseded by a later version. The publication date is displayed prominently on the site, in compliance with Article 2.2.2.25.3.1(f) of Decree 1074 of 2015.

22.2 Validity of the databases

In compliance with Article 2.2.2.25.3.1(f) of Decree 1074 of 2015, the VHG Group's databases shall remain in force for as long as the declared purposes and the statutory retention periods set out in Annex D subsist, after which the data shall be deleted or anonymised in accordance with section 17.

22.3 Updating

The DPO subjects this Policy to ordinary review on 1 January each year and to extraordinary review in the event of regulatory changes, corporate reorganisations, the addition of new Adhering Entities, the enabling of new platform functionality or material incidents. Each review is documented, whether or not it results in an amendment.

Substantial amendments are communicated to data subjects in advance of taking effect. Where an amendment entails a change in the purpose of processing, fresh authorisation from the data subject is required; silence shall not be construed as acceptance.

22.4 Regulatory monitoring

Monitoring alert. In August 2025 the National Government filed a bill to update the Colombian personal data protection regime, contemplating, among other matters, an expansion of the lawful bases, strengthened autonomy for the supervisory authority, mandatory designation of a data protection officer in certain cases, reinforced protections for minors, new rights in relation to automated decisions and incident notification duties. As at the issuance date of this Policy, Law 1581 of 2012 remains in force and constitutes the applicable regime. The DPO shall monitor the legislative process and shall present to the Committee, within sixty (60) days of any enactment of the new law, a plan to bring the Framework into line with it.


23. Annexes and contact channels

23.1 Annexes

AnnexTitleResponsible for completion
AAdhering Entity Identification SheetIssued and published
BJurisdictional SupplementsIncorporated in section 21 of this Policy
CInventory of Cookies and Similar TechnologiesIncorporated in section 6 of MLD-03
DRegister of Databases, Purposes and RetentionIssued — internal document
EModel Deed of Adhesion to the MLD-VHGIssued — pending execution by VCG and VIG
FIntragroup Personal Data Transmission Master AgreementActivated upon the first formal adhesion
GContact Form AuthorisationIssued — texts and implementation specification
HSecurity Incident Management ProcedureIncorporated in section 15 of this Policy

23.2 Contact channels

SubjectChannel
Exercise of rights (enquiries and complaints)info@vhg.capital
Area responsible for handling requestsVHG Group Data Protection Office — info@vhg.capital
Group Data Protection Officeinfo@vhg.capital
Security incident reportinginfo@vhg.capital
Physical serviceDelaware, United States of America — formal channel: info@vhg.capital

23.3 Supervisory authorities

JurisdictionAuthority
ColombiaSuperintendency of Industry and Commerce — Delegate Office for the Protection of Personal Data
Other jurisdictionsThe competent supervisory authority in the territory, under the supplement issued when operations are enabled
United StatesFederal Trade Commission and competent state authorities

END OF INSTRUMENT MLD-04

Valencia Holding Group — VHG Group Digital Legal Framework
MLD-04 — Personal Data Processing and Protection Policy | Version 2.0 | Governing language: Spanish

  • Terms and Conditions
  • Privacy Notice
  • Cookie Notice
  • Data Protection Policy
  • Entity Identification Sheet

vhg.capital · © 2026 Valencia Holding Group LLC