← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Colombia Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Colombian resident covered by this Annex, and the Encargado de la Protección de Datos Personales designated under Decreto 1377 de 2013 Art 23 + SIC Circular Externa 02 de 2015. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Ley Estatutaria 1581 de 2012 (Por la cual se dictan disposiciones generales para la protección de datos personales — the principal PDPL — "LEPD"), (b) the enactment of any GDPR-aligned modernisation of the LEPD currently before the Congreso de la República (the family of proyectos de ley estatutaria that have been tabled and reworked in successive legislative sessions since 2022) — if enacted, the new statute will supersede the LEPD and this Annex's §§ 2, 4, 6, 7, 8, and 11 must be rewritten, (c) any Decreto of the Departamento Administrativo de la Función Pública or of the Ministerio de Comercio, Industria y Turismo that materially modifies Decreto 1377 de 2013 or its compiled version Decreto Único Reglamentario 1074 de 2015 (the "DUR"), (d) any Circular Externa of the Superintendencia de Industria y Comercio (the "SIC") — particularly Circular Externa 02 de 2015, Circular Externa 005 de 2017 (international transfers), Circular Externa 003 de 2018 (cross-border transfers), and any future SIC Circular Externa on children's data, breach notification, or transfer mechanisms — that materially alters the operational rules below, (e) any amendment to Ley 1098 de 2006 (Código de la Infancia y la Adolescencia), (f) any amendment to Ley 1480 de 2011 (Estatuto del Consumidor) or its implementing Decreto Reglamentario 1499 de 2014 / Decreto 587 de 2016 / Decreto 1369 de 2014 (e-commerce), (g) any amendment to Ley 1273 de 2009 (cybercrime statute, integrated into the Código Penal Title VII Bis) or to Ley 1336 de 2009 (strengthening the fight against the sexual exploitation of minors), (h) any Sentencia of the Corte Constitucional that materially changes the LEPD's constitutional interpretation under CN Art 15 (habeas data) or Art 44 (rights of children), (i) Colombia's accession to Convention 108+ (Colombia is invited under Council of Europe ETS 108 + CETS 223 but accession is pending at the Effective date), (j) the European Commission issuing an adequacy decision in respect of Colombia under GDPR Art 45 (none in force at the Effective date), or (k) any change to a sub-processor's Colombia data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Colombia-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Colombian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Colombian resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The authoritative Spanish-language version is republished at Colombia annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Colombian residents.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Colombia ("Colombia"), without distinction between the 32 departamentos and the Distrito Capital de Bogotá.

We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Colombia as the country of residence, this Annex applies, even if the other signals are non-Colombian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The LEPD has extraterritorial effect under its Art 2 read with Decreto 1377 de 2013 Art 4: the LEPD applies whenever the controller processes data of Colombian residents or in Colombian territory, including processing carried out outside Colombia where the controller targets Colombian residents (the SIC's interpretive practice — see SIC Concepto 17-243650 of 2017, Concepto 19-205274 of 2019, and Concepto 21-148732 of 2021). Balance squarely targets Colombian residents through Google Play and through publication of this Annex at balance.babayagaprogram.com.


2. Statutory framework — what applies

The Colombian data-protection and online-safety regime sits at the intersection of two constitutional provisions, the Ley Estatutaria 1581 de 2012 + its reglamentary decrees, the Habeas Data financiera statute (Ley Estatutaria 1266 de 2008) for credit-bureau data, the Código Penal as amended by Ley 1273 de 2009 (cybercrime) and Ley 1336 de 2009 (CSAE), Ley 1098 de 2006 (Código de la Infancia y la Adolescencia), Ley 1480 de 2011 (Estatuto del Consumidor), Ley 2300 de 2023 (Ley de Llamadas Inoportunas, aka the "Ley Mosquera"), and a body of Circulares Externas issued by the SIC.

Instrument Short cite What it does Balance's posture
Constitución Política de Colombia 1991 CN, as amended; Art 15 (right to good name, intimacy, habeas data, and the inviolability of correspondence and private communications); Art 20 (right to receive and disseminate truthful and impartial information); Art 44 (rights of children — fundamental and prevalent over the rights of others — life, physical integrity, health and social security, balanced food, name and nationality, family and not to be separated from it, care and love, education and culture, recreation, and the free expression of their opinion); Art 86 (acción de tutela — fast-track constitutional remedy for fundamental-rights violations); Art 87 (acción de cumplimiento). The constitutional anchor for the personal-data-protection regime and for the child-rights regime. The acción de tutela under Art 86 is the principal constitutional remedy available to a Colombian data subject; the Corte Constitucional has built a substantial body of jurisprudence (Sentencias T-260 de 2012, T-921 de 2014, T-022 de 2017, T-466 de 2017, T-552 de 2020, among others) interpreting Art 15 + Art 44 in the digital environment. Applies in full as the foundational constitutional layer. Treatment in §§ 3, 5, 6, 7, 13 below.
Ley Estatutaria 1581 de 2012 LEPD — Ley 1581 de 2012 of 17 October 2012; estatutaria status under CN Art 152(a) — reviewed and approved by the Corte Constitucional in Sentencia C-748 de 2011 prior to promulgation. The principal data-protection regime: definitions (Art 3); principles — legality, purpose, freedom, veracity, transparency, restricted access, security, confidentiality (Art 4); categories of personal data — public, semi-private, private, sensitive (Arts 3, 5, 6); special-category-data prohibition with exceptions (Art 6); processing of children's and adolescents' data (Art 7); rights of the data subject (Art 8); duty to obtain authorisation (Arts 9, 10, 12); the privacy-notice duty (Art 14); the rights catalogue including access / correction / deletion / revocation of consent / complaint (Art 8 + Art 14–18); international transfers (Art 26); supervisory authority — SIC (Arts 19–21); sanctions (Arts 23–24); criminal liability for circumvention (Art 18 + cross-reference to Código Penal). Applies in full. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Decreto 1377 de 2013 LEPD implementing decree of 27 June 2013 Operational rules for the LEPD, including: the privacy-notice template (Art 14); the contents and form of the authorisation (Arts 5, 7); the rights-exercise procedure and timelines (Arts 21–22); the right-to-erasure (supresión) procedure (Art 22); the security duties (Art 19); the international-transfer treatment (Arts 24–27); the children's-data treatment (Art 12); the Registro Nacional de Bases de Datos (RNBD) rules (Decreto 886 de 2014 + Decreto 090 de 2018 + Decreto 1074 de 2015 Title 1 Chapter 25). Applies as the implementing rules layer on top of Ley 1581.
Decreto Único Reglamentario 1074 de 2015 DUR — Decreto Único Reglamentario of 26 May 2015, consolidating the regulatory decrees of the Commerce, Industry, and Tourism sector (including Decreto 1377 de 2013 and Decreto 886 de 2014 in respect of the LEPD) The single compiled regulatory framework. The LEPD-relevant provisions are at Libro 2, Parte 2, Título 5, Capítulo 25 (Registro Nacional de Bases de Datos) and the Libro 2, Parte 2, Título 5, Capítulo 26 (rules on the LEPD compiled from Decreto 1377 de 2013). Applies as the consolidating regulatory layer.
SIC Circular Externa 02 de 2015 SIC instruction of 3 November 2015 The SIC's binding Circular on the security duties under the LEPD; sets the binding interpretive criteria on the Encargado de la Protección de Datos Personales (the LEPD-mandated DPO role); sets the binding criteria on the Registro Nacional de Bases de Datos (RNBD); sets the SIC's published practice on the rights-exercise timelines, the breach-notification expectation, and the Manual Interno de Políticas y Procedimientos (mandatory internal data-protection manual). Applies as the principal SIC instructional layer. Balance's Encargado de la Protección de Datos Personales is ; the internal Manual Interno is at our Records of Processing Activities (Article 30) § 7.
SIC Circular Externa 005 de 2017 SIC instruction of 10 August 2017 The SIC's binding Circular on international transfers. Sets the Concepto Vinculante on the meaning of "adequate level of protection" under LEPD Art 26. Establishes the SIC's published adequacy list (countries the SIC has found to provide an adequate level of protection) and the procedure for declaratory rulings on transfer mechanisms. Applies as the binding rule on international transfers. The SIC adequacy list does not include the United States as of the Effective date; accordingly, Balance's CO → US transfer relies on the LEPD Art 26 carve-outs (consent + contractual safeguards). See § 8 below.
SIC Circular Externa 003 de 2018 SIC instruction of 1 August 2018 The SIC's Circular updating the cross-border-transfer treatment, particularly in respect of the contractual-clause path and the Declaración de Conformidad (Declaration of Conformity) self-attestation mechanism for transfers to non-adequacy destinations. Applies as the principal layer for the CO → US contractual-clause path. The Declaración de Conformidad template + the EU-SCC-substance contractual clauses with each US sub-processor are in our international-transfer pack § 6.
SIC Circular Única — Título V The SIC's consolidated Circular Única — Title V on Protección de Datos Personales The SIC's compiled instructions on the LEPD. Applies as the consolidating SIC layer.
Ley Estatutaria 1266 de 2008 Ley 1266 de 2008Habeas Data financiera The credit-bureau / financial-data statute. Predates Ley 1581 and applies to credit-rating, financial, commercial, and similar databanks. Does not apply to Balance. Balance does not operate a financial / credit-rating databank. Listed here for completeness.
Ley 1273 de 2009 Ley 1273 de 2009 of 5 January 2009 — Ley de Delitos Informáticos Adds Title VII Bis to the Código Penal on cybercrime: Art 269A (illicit access to a computer system); Art 269B (illicit obstruction of a system or network); Art 269C (illicit interception of data); Art 269D (damage to data); Art 269E (use of malicious software); Art 269F (violation of personal data — violación de datos personales); Art 269G (impersonation of websites for fraud); Art 269H (aggravating circumstances); Art 269I (theft by computer means); Art 269J (computer fraud through ATM transfer of assets). Applies. Cross-reference in Child Safety Standards § 8 (Colombia CSAE routes — see § 14 below).
Ley 1336 de 2009 Ley 1336 de 2009 of 21 July 2009 — Por medio de la cual se adiciona y robustece la Ley 679 de 2001, de lucha contra la explotación, la pornografía y el turismo sexual con niños, niñas y adolescentes Strengthens the fight against the sexual exploitation of children. Imposes obligations on ISPs, hosts, and digital intermediaries to prevent the distribution of CSAM, to block reported CSAM, and to cooperate with authorities. Imposes a duty to publish Códigos de Conducta for the prevention of CSAE. Implementing decree: Decreto 1524 de 2002 (predating Ley 1336 but compatible). Applies. Balance's Código de Conducta for CSAE prevention is in Child Safety Standards §§ 4–10 + the global Child Safety Standards declaration in M6.
Ley 679 de 2001 Ley 679 de 2001 of 4 August 2001 — Por medio de la cual se expide un estatuto para prevenir y contrarrestar la explotación, la pornografía y el turismo sexual con menores The original CSAE-prevention statute. Predates Ley 1336 which strengthened it. Anchors the obligations of digital intermediaries to prevent CSAE. Applies in conjunction with Ley 1336.
Código Penal (Ley 599 de 2000) Código Penal of 24 July 2000, as amended; relevant articles: Art 217A (demanda de explotación sexual comercial de persona menor de 18 años); Art 218 (pornografía con personas menores de 18 años) — production, distribution, exhibition, sale, possession, or use of CSAM; Art 219A (utilización o facilitación de medios de comunicación para ofrecer actividades sexuales con personas menores de 18 años) — online grooming / sexual solicitation; Art 219B (omisión de denuncia) — failure to report CSAE; Art 188A (trata de personas) — trafficking in persons; Art 188D (uso de menores en la comisión de delitos); Art 269F (violación de datos personales — see Ley 1273). The Colombian criminal-law backbone for CSAM, online grooming, and child-sexual-exploitation offences. Applies. Cross-reference in Child Safety Standards § 8 (Colombia CSAE routes — see § 14 below).
Ley 1098 de 2006 Ley 1098 de 2006 of 8 November 2006 — Código de la Infancia y la Adolescencia (CIA) The principal child-protection statute. Codifies the interés superior de los niños, las niñas y los adolescentes (best-interest principle — Art 8); the prevalencia de los derechos de los niños (prevalence of children's rights — Art 9); the right to intimidad (Art 33); the right to information appropriate to age and maturity (Art 34); the right of children and adolescents to be heard (Art 26). Establishes the Sistema Nacional de Bienestar Familiar (SNBF) and the Instituto Colombiano de Bienestar Familiar (ICBF) as the principal cabinet-level child-welfare authority. Applies in full to every Colombian kid covered by this Annex. Treatment in §§ 5, 7, 14 below.
Ley 1480 de 2011 Ley 1480 de 2011 of 12 October 2011 — Estatuto del Consumidor The principal consumer-protection statute. Art 5 (definitions); Art 23 (right of information); Art 35 (publicidad); Art 37 (advertising directed at children); Art 47 (derecho de retracto — 5-business-day right of retraction for distance contracts); Art 51 (e-commerce information duties); Art 56 (collective actions). Implementing decree: Decreto 1499 de 2014 + Decreto 587 de 2016 + Decreto 1369 de 2014 (e-commerce). Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below.
Ley 2300 de 2023 Ley 2300 de 2023 of 11 July 2023 — Ley de Llamadas Inoportunas (the "Ley Mosquera") Restricts commercial calls, SMS, and electronic-marketing communications to consumers. Requires controllers to obtain prior, express, and revocable consent for commercial communications; requires a free, easy revocation channel; restricts call/SMS hours. Applies. Balance does not send electronic direct marketing to Colombian residents (cross-reference: § 12.3 below).
Decreto 1494 de 2024 (or successor) Decreto Reglamentario compiling the operational rules for Ley 2300 de 2023 (where promulgated by the Effective date) Sets the technical-operational rules for opt-in / opt-out registries, días y horarios prohibidos, and SIC oversight under Ley 2300. Applies operationally where relevant. Balance's no-marketing posture means the Decreto's restrictions do not bite.
Convention 108 + Convention 108+ Convenio para la Protección de las Personas con respecto al Tratamiento Automatizado de Datos de Carácter Personal (Council of Europe ETS 108 of 28 January 1981) and its Protocolo Modificativo (CETS 223 of 18 May 2018). Colombia is invited to accede under the Convention 108+ open-accession process. Accession is pending at the Effective date. Relevant as a context-setting instrument. Treatment in § 8 below.
EU adequacy None as of the Effective date — Colombia does not have an EU adequacy decision under GDPR Art 45. Distinct from Argentina (Decision 2003/490/EC) and Uruguay (Decision 2012/484/EU), Colombia does not yet hold an adequacy finding. Relevant only as context. Balance's transfer mechanism for the CO-to-US leg does not rely on adequacy. Treatment in § 8 below.
Corte Constitucional jurisprudence Principal SentenciasC-748 de 2011 (constitutional review of Ley 1581); C-1011 de 2008 (review of Ley 1266); T-260 de 2012 (data of minors in social networks); T-921 de 2014 (the Facebook case — minors and online privacy); T-022 de 2017 (online publication of images of minors); T-466 de 2017 (right to oblivion online); T-552 de 2020 (digital intimacy and minors). The Corte Constitucional's jurisprudence on Arts 15 and 44 establishes the constitutional ceiling on data-processing of minors and the acción de tutela as the principal fast-track remedy. Applies. Treatment in §§ 5, 7, 13 below.
Pending GDPR-aligned LEPD modernisation Successive proyectos de ley estatutaria tabled before the Congreso de la República since 2022 (most recently the bundle referenced in the master country-classification table as the "2025 framework") A comprehensive GDPR-aligned rewrite of the LEPD has been before the Congress in successive legislative sessions. If enacted, the new ley estatutaria would introduce GDPR-aligned definitions (controller / processor distinction), a fuller rights catalogue (portability, restriction, objection, automated-decision review), a DPIA obligation, an explicit breach-notification timeline, and an updated transfer regime. NOT in force as of the Effective date. If and when enacted, this Annex's §§ 2, 4, 6, 7, 8, and 11 will be rewritten and the rewrite will trigger an off-cycle update. Balance is already operationally GDPR-aligned (cross-reference: EU / EEA annex § 6 + § 8), so the substantive posture below already anticipates the modernisation; the regulatory cites are the only thing that will change.

(Any prospective Colombian Ley de Inteligencia Artificial and any SIC Circular Externa directed at automated-processing or algorithmic-decision rules are intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Colombian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. SIC — Supervisory authority

3.1 The SIC as supervisory authority

The supervisory authority for the LEPD is the Superintendencia de Industria y Comercio ("SIC"), through its specialised Delegatura para la Protección de Datos Personales (the personal-data delegation). The SIC was designated as the LEPD supervisory authority by Ley 1581 Art 19 read with Decreto 4886 de 2011 + Decreto 092 de 2022 (the Superintendencia's structure). The SIC also operates the Delegatura para la Protección del Consumidor (consumer-protection delegation) under Ley 1480, and a separate Delegatura para Asuntos Jurisdiccionales (with limited jurisdictional powers).

Field Value
Name Superintendencia de Industria y Comercio (SIC) — Delegatura para la Protección de Datos Personales
Headquarters Carrera 13 N° 27-00, pisos 1, 3, 4, 5, 6, 7, 9 y 10, Bogotá D.C., Colombia
General website https://www.sic.gov.co/
Personal-data section https://www.sic.gov.co/proteccion-de-datos-personales
Complaint / claim channel (Trámites y servicios — Reclamaciones de Protección de Datos) https://www.sic.gov.co/tramites-y-servicios/proteccion-de-datos-personales
Incident-notification channel The SIC's online incident-reporting form for novedades and security-incident notifications under Circular Externa 02 de 2015 — accessible from the Protección de Datos Personales portal
RNBD — Registro Nacional de Bases de Datos https://rnbd.sic.gov.co/ (the Registro Nacional de Bases de Datos, mandatory for in-scope controllers; foreign controllers without local establishment fall outside per SIC Concepto 19-205274)
Email contactenos@sic.gov.co (general); the SIC reception desk at notificacionesjudiciales@sic.gov.co for judicial communications
Phone +57 601 587-0000 (Bogotá); 018000-910165 (national toll-free)
Superintendente Delegado para la Protección de Datos Personales The head of the Delegatura is the supervisory officer for the LEPD; appointment is made by the Superintendente de Industria y Comercio under Decreto 092 de 2022

The SIC is the first-line forum for any LEPD-grounded complaint. A Colombian resident may petition the SIC without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the Encargado de la Protección de Datos Personales) and we will respond within the LEPD + Decreto 1377 timelines (see § 6 below).

A Colombian resident may also pursue private remedies against Balance via the acción de tutela (the constitutional remedy under CN Art 86 invoking the violation of Art 15 / Art 44 — Balance is a private party but the tutela against private parties is admissible under CN Art 86 + Decreto 2591 de 1991 Art 42 because Balance is the processor of fundamental-rights-implicating data of children, who are subordinados and indefensos within the meaning of the Decreto); or via the ordinary civil and criminal courts where appropriate (notably Art 269F Código Penalviolación de datos personales).

3.2 The Encargado de la Protección de Datos Personales

Decreto 1377 de 2013 Art 23 + SIC Circular Externa 02 de 2015 § II require the designation, by every controller subject to the LEPD, of a person or department responsible for personal-data protection (the Encargado de la Protección de Datos Personales — the LEPD-mandated DPO-equivalent). The designation is mandatory for every controller regardless of the size or category of the data processed; there is no de minimis carve-out (unlike GDPR Art 37 which only mandates a DPO for specific categories of controller).

The Balance Encargado de la Protección de Datos Personales is: - , Director, BabaYaga Program, TOO — .

The Encargado's functions are: (a) attend to the rights-exercise requests of data subjects; (b) implement and supervise compliance with the LEPD's principles and obligations; (c) maintain the internal Manual Interno de Políticas y Procedimientos; (d) cooperate with the SIC in any supervisory or investigation activity; (e) lead the security and confidentiality measures; (f) lead the children's-data treatment under Decreto 1377 Art 12.

3.3 Registro Nacional de Bases de Datos (RNBD) — non-registration position

Decreto 1074 de 2015 + Decreto 886 de 2014 + Decreto 090 de 2018 require certain controllers to register their personal-databanks in the Registro Nacional de Bases de Datos (RNBD) maintained by the SIC. The registration obligation applies to controllers that meet specified asset, employee, or processing-volume thresholds. The SIC's published practice — codified in SIC Concepto 19-205274 of 2019 and reiterated in SIC Concepto 21-148732 of 2021 — is that foreign controllers without a permanent establishment in Colombia are not required to register their databanks in the RNBD; the obligation applies to controllers having a permanent establishment in Colombia (which Balance does not).

Should the SIC's interpretive practice change, or should Balance ever establish a permanent presence in Colombia, the registration will be filed within the statutory window prescribed by the SIC's RNBD rules.


4. Lawful bases under the LEPD

Balance processes personal data of Colombian residents on the following LEPD lawful bases. The mapping below is the canonical Balance-side bridge between each processing purpose and the LEPD lawful basis. The full record is in our Records of Processing Activities (Article 30).

Processing purpose Lawful basis (LEPD + Decreto 1377) Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) LEPD Art 9 — prior, express, and informed authorisation of the data subject (here, the parent at sign-up); supplemented by Art 10(a) — data necessary for the satisfaction of a juridical or contractual obligation in which the data subject is a party H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data LEPD Art 7 — read with Decreto 1377 Art 12 — processing of children's and adolescents' data is admissible only where it (i) serves a higher interest, (ii) respects the kid's fundamental rights, and (iii) is authorised by the parent or legal guardian. Balance's VPC mechanism implements all three criteria. Supplemented by the constitutional best-interest and prevalencia principles under CN Art 44 + Ley 1098 Arts 8–9 § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts LEPD Art 9 + Art 10(a) — authorisation + contractual relationship; supplemented by the limited carve-out at Art 10(c) — information necessary for the recognition, exercise, or defence of a right in a judicial process H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access LEPD Art 17(d) — duty to ensure the security of the information; supplemented by Decreto 1377 Art 19 + SIC Circular Externa 02 de 2015 security obligations; legal-obligation basis under Art 10(b) — information required by a public entity in the discharge of its legal functions H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations (LEPD Art 14–18 DSAR responses; SIC Circular Externa 02 de 2015 breach notification; SIC information requests; Ley 1480 consumer-rights requests; Ley 1098 cooperation duties; CSAE-report obligations under Ley 679 + Ley 1336) LEPD Art 10(b) — information requested by a public entity in the discharge of its legal functions; supplemented by SIC Circular Externa rules § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data LEPD Art 7 + Art 9 — prior, express, and informed authorisation of the parent or legal guardian § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data LEPD Art 9 + Art 10(a) — authorisation + contractual relationship for the subscription H4; Ley 1480 overlay in § 16 below

Balance does not rely on the "public-data" carve-out (LEPD Art 10(d) — data of "naturaleza pública" admissible without authorisation) as a lawful basis for any kid-side processing.


5. Ley 1098 — children's rights overlay

Ley 1098 de 2006 (the Código de la Infancia y la Adolescencia, "CIA") is the principal Colombian child-protection statute. The principal Balance-side handshakes are:

5.1 Best-interest-of-the-child principle (CIA Art 8)

CIA Art 8 establishes the interés superior de los niños, las niñas y los adolescentes as the controlling principle for any decision that concerns a child. The constitutional anchor is CN Art 44 (los derechos de los niños prevalecen sobre los derechos de los demás) and the UN Convention on the Rights of the Child Art 3, internalised via Ley 12 de 1991. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.

5.2 Prevalence of children's rights (CIA Art 9)

CIA Art 9 codifies the constitutional principle that, in any conflict between the rights of a child and those of an adult, the rights of the child prevail. The Corte Constitucional has applied this principle in the digital environment (notably Sentencia T-921 de 2014 — the Facebook case) to require the controller to prefer the child's privacy and dignity over the adult interlocutor's interest. Balance's architectural posture preserves this prevalence: the parent's authorisation is the lawful basis for processing the kid's data, but the kid's substantive rights (dignity, intimacy, no behavioural-advertising profile, no third-party commercial data sharing) are not subject to override by the parent — even with the parent's affirmative consent, Balance does not enable behavioural advertising or third-party commercial data sharing of the kid's data.

5.3 Right to intimacy of the child and adolescent (CIA Art 33)

CIA Art 33 protects the intimidad of children and adolescents — their right to private life, family life, correspondence, communications, and image. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).

5.4 Right to information appropriate to age (CIA Art 34) + Right to be heard (CIA Art 26)

CIA Art 34 codifies the kid's right to information appropriate to their age and maturity. CIA Art 26 codifies the kid's right to be heard in any matter that concerns them. Balance's architectural posture preserves both principles: the kid app's UI is designed for the kid; the kid sees their own limits, schedules, tasks, and earned-time ledger in their own kid-app UI; the kid can request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision.

5.5 No advertising directed at children — Ley 1480 Art 37

Ley 1480 Art 37 prohibits advertising directed at children that induces consumption-related behaviours contrary to the child's interest. Read with CN Art 44, CIA Art 8 + Art 9 + Art 33, and SIC Circular Externa 02 de 2015 the substantive overlay is that advertising directed at children is a high-risk processing that requires the parent's specific authorisation and that must not be deceptive, must not exploit children's credulity, and must not encourage anti-social or unhealthy behaviours. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.6 Cooperation routes (Sistema Nacional de Bienestar Familiar)

The principal Colombian child-protection bodies are: (i) Instituto Colombiano de Bienestar Familiar (ICBF) — the cabinet-level child-welfare authority (CIA Arts 11, 16, 79; Decreto 4156 de 2011 + Decreto 987 de 2012); (ii) Sistema Nacional de Bienestar Familiar (SNBF) — the cross-government coordination system; (iii) Defensorías de Familia — district-level defenders within the ICBF; (iv) Procuraduría Delegada para la Defensa de los Derechos de la Infancia, la Adolescencia y la Familia — the Procuraduría General's child-protection delegation. Balance cooperates with each on incidents that involve Colombian kids — see § 14 below.


6. LEPD Article 8 + Decreto 1377 — the rights, the timeline, and how to exercise them

6.1 The rights catalogue

A Colombian resident has the following rights under the LEPD. The article-list mirrors LEPD Art 8 + Decreto 1377 Arts 21–22 as in force at the Effective date.

6.2 Timeline

Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to file a reclamo with the SIC and to seek constitutional tutela redress.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (Decreto 1377 Art 21). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of the Colombian cédula de ciudadanía or cédula de extranjería) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 Language

A request may be submitted in Spanish (preferred for Colombian residents) or in English.


7. Children's data — LEPD Art 7 + Decreto 1377 Art 12 + Corte Constitucional jurisprudence

LEPD Art 7 prohibits the processing of personal data of children and adolescents except where (i) it serves the higher interest (interés superior) of the child; (ii) it respects the kid's fundamental rights; and (iii) the parent or legal guardian has authorised it. Decreto 1377 Art 12 operationalises Art 7 with the same three-element test and adds that the parent's authorisation must be specific to the data and to the purposes for which they are processed.

The Corte Constitucional has built a body of jurisprudence on Art 7 in the digital environment — notably Sentencias T-260 de 2012, T-921 de 2014, T-022 de 2017, T-466 de 2017, and T-552 de 2020 — establishing that: - The constitutional best-interest principle (CN Art 44) operates as a substantive ceiling on what the parent may authorise on the kid's behalf. The parent cannot authorise a processing that would itself violate the kid's fundamental rights. - The kid's intimacy, dignity, and image (CIA Art 33) are constitutionally protected and cannot be waived by the parent for commercial advertising purposes. - Online platforms have a heightened duty of care in respect of minors and must implement architectural safeguards (the constitutional analogue to a "Children's Code" approach).

For Balance:

A parent may revoke authorisation at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Colombia

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Colombian resident's data leaves Colombia at the point of being uploaded to the Balance backend.

8.1 Transfer mechanism — LEPD Article 26

LEPD Art 26 prohibits the transfer of personal data to countries that do not provide an adequate level of protection, except where one of the carve-outs in Art 26 applies: (a) the data subject has expressly and unequivocally authorised the transfer; (b) the transfer is necessary for medical assistance or sanitary treatment; (c) the transfer involves bank or stock-exchange data and is necessary for processing the data subject's transactions; (d) the transfer is necessary for the performance of a contract between the data subject and the controller or for pre-contractual measures requested by the data subject; (e) the transfer is for the recognition, exercise, or defence of a right in a judicial process; (f) the transfer is necessary to satisfy a treaty obligation of Colombia; (g) the transfer is to a country that the SIC has declared to provide an adequate level of protection.

SIC Circular Externa 005 de 2017 + Circular Externa 003 de 2018 operationalise Art 26: the SIC publishes an adequacy list and a procedure for case-by-case declaratory rulings on transfer mechanisms; for transfers to non-adequacy destinations, the controller must rely on data-subject authorisation, the contract-performance carve-out, contractual clauses replicating the LEPD standards, or a Declaración de Conformidad (controller's self-attestation, with optional SIC verification).

The SIC adequacy list does NOT include the United States as of the Effective date.

Balance relies on the following stack to satisfy Art 26 for the CO → US transfer:

8.2 EU adequacy is not the transfer tool for CO-to-US

The European Commission has not issued an adequacy decision in respect of Colombia under GDPR Art 45. The EU position on Colombia is under assessment. The EU adequacy path is not available as a transfer tool for any Colombia-resident leg at the Effective date or in the short-to-medium term.

8.3 Transfer mechanism — the CO-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the SIC adequacy list, the CO-KZ axis is covered by contractual clauses replicating LEPD standards (SIC Circular Externa 003 de 2018) signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.4 Article 26(b)(c)(e)(f) carve-outs — not relied upon

Balance does not rely on the Art 26(b), (c), (e), or (f) carve-outs (medical assistance; bank/stock-exchange transfers; judicial-process right; treaty obligation) as the basis for routine transfers — those carve-outs are reserved for case-by-case scenarios, not for routine flows.


9. Data residency for Colombian residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Colombian resident's data held in Colombia? No. Every Colombian resident's data is held in the United States. The LEPD Art 26 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via LEPD-standards contractual clauses in the inverse arrangement in § 8.3.
Is there a Colombian establishment? No. Balance has no permanent establishment in Colombia.
Where is the supervisory authority? Colombia — Superintendencia de Industria y Comercio (SIC) — Delegatura para la Protección de Datos Personales, Carrera 13 N° 27-00, Bogotá D.C.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Colombia does not impose a comprehensive data-localisation mandate on parental-control services as of the Effective date.


10. Sub-processors touching Colombian resident data

Sub-processor Role Location of processing Colombian transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States Parent's express authorisation (LEPD Art 26(a)) + contract-performance carve-out (Art 26(d)) + LEPD-standards contractual clauses (SIC Circular Externa 003 de 2018) on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Parent's express authorisation + LEPD-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Parent's express authorisation + LEPD-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Colombian kid + parent devices United States Parent's express authorisation + LEPD-standards contractual clauses as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Parent's express authorisation + LEPD-standards contractual clauses as above.
Google LLC — Google Play Billing Processes subscription purchases United States Parent's express authorisation + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Colombian parent users United States Parent's express authorisation + LEPD-standards contractual clauses on file.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + SIC Circular Externa 02 de 2015 security duties. The full sub-processor list, with each row's DPA status and contractual-clause execution date, is at our sub-processor register.


11. Breach notification — SIC Circular Externa 02 de 2015

The LEPD does not contain an explicit breach-notification article (the gap is one of the principal motivators for the pending GDPR-aligned modernisation referenced in § 2). The SIC has filled the gap through Circular Externa 02 de 2015 § II.5, which sets the binding interpretive practice on the notification of novedades (incidents, including security incidents) affecting personal data: the controller must report to the SIC any novedad relating to a violation of the security duties under LEPD Art 17(d) + Decreto 1377 Art 19, and must notify affected data subjects where the breach is likely to result in harm.

Audience Trigger Deadline Channel
SIC A security incident affecting personal data that is reasonably likely to cause damage to data subjects. Within 15 working days of the controller becoming aware — SIC Circular Externa 02 de 2015 § II.5 anchors a 15-working-day benchmark for the notification of novedades. Balance's internal posture is to anchor to a 72-hour benchmark in line with the GDPR Art 33 / pending Colombian modernisation expectation, treating the SIC's 15-working-day window as a back-stop. The SIC's online incident-reporting form for novedades and security-incident notifications under Circular Externa 02 de 2015, filed in Spanish by the Encargado de la Protección de Datos Personales or by external Colombian counsel acting on the Encargado's instructions.
Affected data subjects A breach likely to cause significant harm to data subjects (the SIC's "harm-likelihood" overlay analogue). "Without undue delay" — the SIC's published guidance, with the controller's reasoned judgment as to the appropriate moment for the data-subject notification (which may legitimately be later than the SIC notification where the data-subject notification depends on the fuller forensic picture). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected).
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). Línea 141 ICBF + Te Protejo Colombia + Centro Cibernético Policial + Fiscalía General de la Nación CTI.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, SIC notification within the 15-working-day benchmark (with Balance's internal 72-hour target as the operational anchor), affected-data-subject notification per the Circular Externa 02 de 2015 harm-likelihood analysis.

11.1 Minimum content of the SIC notification

The SIC notification states: - the nature of the personal data affected; - the categories and approximate number of data subjects involved; - the technical and security measures in place at the time of the incident; - the risks for the data subjects; - the measures adopted or proposed to mitigate the effects of the incident; - the Encargado de la Protección de Datos Personales contact point (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering is produced by external Colombian counsel on filing.


12. Cookies and electronic direct marketing

Colombia does not have a specific ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) LEPD Art 9 authorisation as the lawful basis for any cookie that processes personal data; (ii) Ley 1480 Estatuto del Consumidor provisions on pre-contract information, deceptive advertising (Art 30), and abusive terms (Art 42); (iii) Ley 2300 de 2023 — the Ley de Llamadas Inoportunas (Ley Mosquera) — which restricts commercial calls, SMS, and electronic-marketing communications by requiring prior, express, and revocable consent, a free and easy revocation channel, and restricted call/SMS hours; (iv) the SIC's published practice on cookies in Concepto 18-066817 of 2018 and successor Conceptos, anchored on Art 9 authorisation.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up authorisation in the Spanish-language consent screen.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send electronic direct marketing to Colombian residents. The only email Balance sends to Colombian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 2300 de 2023 requires pre-existing express consent and a free, easy revocation channel for any commercial electronic communication; if Balance ever introduces a marketing channel, we will comply with the Ley 2300 rules + the SIC's interpretive guidance + the Ley 1480 prohibitions on misleading advertising.


13. Lawful-access requests and the encryption posture

Colombian authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Colombia

A Colombian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Colombian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Superintendencia de Industria y Comercio (SIC) — Delegatura para la Protección de Datos Personales LEPD + Decreto 1377 + SIC Circulares Externas Carrera 13 N° 27-00, Bogotá D.C.; https://www.sic.gov.co/proteccion-de-datos-personales/reclamaciones
Superintendencia de Industria y Comercio (SIC) — Delegatura para la Protección del Consumidor Ley 1480 Estatuto del Consumidor Carrera 13 N° 27-00, Bogotá D.C.; https://www.sic.gov.co/proteccion-del-consumidor
Procuraduría General de la Nación — Procuraduría Delegada para la Defensa de los Derechos de la Infancia, la Adolescencia y la Familia Child-rights matters (Ley 1098) https://www.procuraduria.gov.co/
Defensoría del Pueblo — Defensoría Delegada para los Derechos de la Niñez, la Juventud y la Mujer Human-rights-grounded child-rights complaints https://www.defensoria.gov.co/
Fiscalía General de la Nación Cybercrime + child-sexual-exploitation + collective LEPD-grounded prosecutions https://www.fiscalia.gov.co/; intake line 122
Jueces Civiles del Circuito / Jueces de Familia Ordinary civil and family-court actions Per jurisdiction
Corte Constitucional via acción de tutela Fundamental-rights protection (CN Arts 15 + 44 invoked via Art 86 tutela) First-instance to any juez de la República with jurisdiction; review by the Corte Constitucional on selection

A Colombian resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the Encargado de la Protección de Datos Personales). We will respond within the Decreto 1377 Art 21 ten-working-day window (for consultas) or the Art 22 fifteen-working-day window (for reclamos). Raising the matter with us first is not a precondition to complaining to the SIC, filing an acción de tutela, or seeking any other constitutional, civil, or criminal remedy; the SIC accepts complaints directly.


16. Consumer rights — the Ley 1480 overlay

Ley 1480 de 2011 (the Estatuto del Consumidor) is the principal Colombian consumer-protection statute. Where the parent is acting as a consumidor within the meaning of Ley 1480 Art 5, the following overlays apply to the subscription purchase flow and to the Terms of Service.

16.1 Pre-contract information (Ley 1480 Art 23 + Art 24 + Decreto 1369 de 2014)

The parent is entitled to información veraz, suficiente, oportuna, verificable, comprensible, precisa e idónea on the essential characteristics of the service. Decreto 1369 de 2014 (e-commerce) imposes specific pre-contract disclosure rules for distance contracts. Implemented in Subscription Terms § 5.

16.2 5-business-day right of retraction — derecho de retracto (Ley 1480 Art 47)

Ley 1480 Art 47 grants the consumer a 5-business-day right of retraction for distance contracts, computed from the date of the contract or from the delivery of the product / first delivery of the service, whichever is later. The right of retraction is the Colombian equivalent of the Argentine botón de arrepentimiento (AR Annex § 16.2) and the Chilean derecho de retracto (CL Annex § 16.2). Balance's subscription is concluded at a distance (in-app); the 5-business-day right of retraction applies and is implemented in Subscription Terms § 20. The right of retraction is honored regardless of whether the parent has used the service in the 5-business-day window — the parent is entitled to a full refund through the Google Play Billing refund route.

16.3 E-commerce disclosure (Decreto 1369 de 2014)

Decreto 1369 de 2014 imposes specific e-commerce disclosure obligations including: (a) prominent display of the supplier's identity and address; (b) clear pricing including all taxes and charges; (c) explicit confirmation of the purchase before the consumer is bound; (d) the right of retraction notice; (e) the cancellation flow. Balance's subscription flow is implemented to satisfy each Decreto 1369 obligation.

16.4 Abusive contract terms (Ley 1480 Art 42)

Ley 1480 Art 42 declares null any contract term that (i) limits the supplier's liability for damages contrary to public order; (ii) reverses the burden of proof to the consumer's detriment; (iii) imposes a unilateral right of termination on the supplier; (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 42 risk.

16.5 Advertising directed at children (Ley 1480 Art 37)

Ley 1480 Art 37 prohibits advertising directed at children that induces consumption-related behaviours contrary to the child's interest. Read with CN Art 44, CIA Arts 8 + 9 + 33, and LEPD Art 7, the prohibition operates as the substantive ceiling on any commercial communication that might be directed at a kid. Balance does not display any advertising — see § 5.5 above.

16.6 Forum and choice of law

Ley 1480 + Ley 1564 de 2012 (Código General del Proceso) Art 28 operate on a consumer-protective basis. The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace Colombian law to the prejudice of the Colombian consumer are presumptively null under Ley 1480 Art 42.

16.7 SIC acción de protección al consumidor

Ley 1480 Art 56 + Art 58 grant the consumer an acción de protección al consumidor before the SIC's Delegatura para Asuntos Jurisdiccionales (which has limited jurisdictional powers). The consumer may also seek collective action under Art 56 read with Ley 472 de 1998 (acciones populares + acciones de grupo).


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Colombia Country Annex.

← Back to Privacy Policy · Children's Privacy Notice