Version 3.0 — July 1, 2026
1.1. This Policy sets out the guidelines for the collection, storage, use, circulation, transmission, transfer, and deletion of personal data processed by NOVACODIFY S.A.S. ("NOVACODIFY") in the development of the Orbichain technological ecosystem, of which it is the owner and sole operator. Orbichain is a trademark and not a legal entity.
1.2. It is governed by the Political Constitution (arts. 15 and 20), Law 1581 of 2012, Decree 1074 of 2015 (which consolidates Decree 1377 of 2013), Law 1266 of 2008 where applicable, and the instructions of the Superintendencia de Industria y Comercio (SIC).
1.3. This Policy fully supersedes any prior version.
Authorization: prior, express, and informed consent of the Data Subject for the processing of their data.
Privacy notice: communication that informs the Data Subject of the existence of this Policy and the purposes of processing.
Database: organized set of personal data subject to processing.
Personal data: information linked or linkable to a determined or determinable natural person.
Sensitive data: data that affects the Data Subject’s privacy or whose improper use may lead to discrimination; includes biometric data.
Processor: who processes data on behalf of the Controller.
Controller: NOVACODIFY S.A.S.
Data Subject: natural person whose data are subject to processing (the Orbichain User).
Transfer: sending of data to a recipient who is also a Controller, within or outside Colombia.
Transmission: sending of data to a Processor so that they process them on behalf of the Controller.
NOVACODIFY applies the principles of legality, purpose, freedom, truthfulness, transparency, restricted access and circulation, security, and confidentiality (art. 4, Law 1581 of 2012). It collects only the data necessary and proportional to the declared purposes.
| Category | Data | Sensitive |
|---|---|---|
| Identification | First names, last names, type and number of document, date of birth, nationality, image of the document | No |
| Contact | Email, mobile phone, residential address, municipality | No |
| Biometric | Facial image, derived biometric template, liveness proof record | Yes |
| Compliance | Declaration of source of funds, economic activity, occupation, PEP status, results of screening against restrictive lists | No |
| Transactional | History of Exchanges, External Sends, OrbiTag transfers, wallet addresses, hashes, Position in Virtual Assets | No |
| Technical | IP address, device identifier and model, operating system, app version, access logs, approximate geolocation | No |
| Interaction | Content of support requests, PQR, and communications with the User | No |
4.1. Minors. Orbichain is not directed at persons under eighteen (18) years of age and does not deliberately collect their data. If a minor’s registration is detected, their data will be deleted, except for a legal conservation obligation, and the account will be closed.
4.2. Data not collected. NOVACODIFY does not process data on ethnic or racial origin, political orientation, religious or philosophical convictions, trade union membership, health data, or data on the Data Subject’s sexual life.
Data are processed exclusively for the following purposes. Any purpose not listed will require additional and specific authorization.
5.1. Service provision: create and administer the Orbichain Account; execute Exchanges, External Sends, and OrbiTag transfers; reflect the Position in Virtual Assets; transmit to the authorized third-party provider the User’s conversion instructions; issue invoices; administer Orbichain Levels and the Direct Referral Program.
5.2. Identification, security, and fraud prevention: verify identity through documentary and biometric validation; detect impersonation, multiple accounts, and self-referrals; detect unauthorized access and anomalous activity; administer authentication factors.
5.3. Regulatory compliance: carry out customer due diligence; consult restrictive lists and PEP status; perform transactional monitoring and chain analysis; prepare and submit to the UIAF the applicable reports, including suspicious transaction reports; respond to requests from competent authorities.
5.4. Tax and accounting compliance: fulfill invoicing, reporting, and conservation obligations before the DIAN.
5.5. Support and relationship with the Data Subject: handle inquiries, petitions, complaints, and claims; send transactional and security communications (confirmations, access alerts, notices of changes to the Terms), inherent to the service and not deactivatable while the account is active.
5.6. Service improvement: analyze in aggregated and dissociated form the use of the Platform to improve functionalities and correct errors.
5.7. Commercial communications — optional and revocable: send information on new functionalities, educational content, and benefits. Requires separate authorization, is optional, refusal does not affect the service, and is revocable at any time from the Platform or at legal@orbichain.com.
5.8. Expressly excluded purposes. NOVACODIFY will NOT process the Data Subject’s data to: prepare, sell, assign, or license credit profiles or behavior scores to third parties; commercialize databases; assign data to third parties for their own commercial purposes; or use biometric data for any purpose other than identity verification and fraud prevention.
6.1. The provision of sensitive data is optional (art. 6, Law 1581 of 2012).
6.2. Biometric validation is the means by which NOVACODIFY fulfills its identification duty. Without it, it cannot provide the service or enable operations. This is not a sanction, but the material impossibility of fulfilling a legal obligation.
6.3. Authorization for the processing of biometric data is obtained through an independent and specific checkbox, informing of its sensitive and optional nature.
6.4. Biometric data are used solely to verify identity and prevent impersonation. They are not used for advertising or segmentation, nor assigned to third parties for commercial purposes.
6.5. They are encrypted in transit and at rest, stored separately, and access is restricted to authorized personnel under audit logging.
NOVACODIFY relies on third parties that receive only the data necessary for their function, under a contract that imposes confidentiality, security, and limited use.
| Third-party category | Function | Role |
|---|---|---|
| Identity verification providers | Documentary and biometric validation | Processor |
| Restrictive list screening providers | List and PEP screening | Processor |
| Chain analysis providers | Address risk assessment | Processor |
| Conversion provider (authorized third party) | COP ⇄ Virtual Assets conversion service | Independent Controller |
| Infrastructure and cloud providers | Hosting and processing | Processor |
| Messaging and notification providers | Sending of emails and alerts | Processor |
| UIAF, DIAN, and competent authorities | Reports and legal requests | Authority |
7.1. Conversion provider. Upon using the Conversion Service, the Data Subject enters into a direct relationship with such provider, which acts as an independent Controller regarding the data it collects and whose privacy policy the Data Subject must accept. NOVACODIFY is not liable for the processing that provider performs under its own responsibility.
8.1. Some Processors are domiciled outside Colombia; consequently, the Data Subject’s data may be transmitted internationally.
8.2. Legal basis: (i) the Data Subject’s express and informed authorization; (ii) transmission contracts that impose on the Processor the duties of art. 25 of Decree 1074 of 2015; and (iii) where applicable, that the recipient country is considered to have an adequate level of protection by the SIC.
8.3. NOVACODIFY retains the status of Controller and is liable to the Data Subject for the processing that its Processors perform on its behalf.
The Data Subject has the right to: know and freely access their data; update and rectify inaccurate or incomplete data; request proof of the authorization; be informed of the use given to their data; file complaints with the SIC, after previously exhausting the procedure before NOVACODIFY; and revoke the authorization and request deletion, subject to the limitations of numeral 10.
10.1. Revocation and deletion do not apply while a legal or contractual duty to retain the information subsists, in particular that derived from money-laundering prevention regulations and from commercial and tax obligations.
10.2. During that term, the data are kept under blocking: they are retained for the exclusive disposal of competent authorities and are not used for any other purpose.
10.3. Once the legal term has elapsed, the data are deleted or anonymized irreversibly.
10.4. Revocation of the optional purposes of numeral 5.7 may be exercised at any time, is immediate, and does not affect the service.
11.1. Channel: request to legal@orbichain.com or from the Platform’s privacy section.
11.2. Content: full name, document number, registered email, clear description of the facts and of the right being exercised.
11.3. Time limits:
Inquiry — Response: 10 business days — Extension: Up to 5 additional business days, stating the reason
Claim — Response: 15 business days — Extension: Up to 8 additional business days, stating the reason
11.4. Incomplete claim: NOVACODIFY will require the Data Subject within the following five (5) days to cure; after two (2) months without response, it shall be deemed withdrawn.
11.5. Annotation: upon receipt of the claim, the legend "claim in process" will be included in the database within the following two (2) business days, until its decision.
12.1. Duty of confidentiality. NOVACODIFY, its personnel, its contractors, and its Processors are obligated to maintain the confidentiality of personal data and of all User information to which they gain access by reason of the service. This obligation subsists indefinitely, even after the relationship with the User or the employment or contractual relationship of the personnel involved has ended.
12.2. Scope. User information may only be disclosed: (a) to the User themselves; (b) to competent authorities that require it under the law; (c) to Processors, to the extent strictly necessary to provide the service; and (d) when the User expressly authorizes it. No other disclosure is permitted.
12.3. Security measures. NOVACODIFY implements reasonable technical, human, and administrative measures to protect the information against alteration, loss, consultation, use, or unauthorized or fraudulent access, including: encryption in transit and at rest; role-based access control under the principle of least privilege; multifactor authentication for administrative access; audit logs on sensitive data; confidentiality agreements with personnel and Processors; backups; and periodic personnel training.
12.4. Shared responsibility of the User. Information security also depends on the User, who is responsible for the custody of their credentials, for using secure devices, and for not sharing their access data, pursuant to the Terms and Conditions.
12.5. Incidents. Upon an incident affecting personal data, NOVACODIFY will report it to the SIC under the required terms and deadlines, and will inform affected Data Subjects when the incident may compromise their rights.
13.1. This Policy is effective as of July 1, 2026 and supersedes any prior version.
13.2. Databases will remain in effect for as long as necessary for the declared purposes and during the legal conservation periods.
13.3. NOVACODIFY may amend this Policy; material changes will be communicated with fifteen (15) calendar days’ prior notice through the Platform and the registered email. Any change that involves a new purpose will require new authorization.
DATA SUBJECT AUTHORIZATION By accepting this Policy, the Data Subject grants NOVACODIFY S.A.S. their prior, express, and informed consent to process their data pursuant to numeral 5, and declares that they have been informed of: the identity of the Controller; the purposes; their rights and their limits; the optional nature of biometric data; the possible international transmission to Processors; the optional nature of commercial communications; and the channel legal@orbichain.com to exercise their rights. NOVACODIFY S.A.S. — NIT 901.915.046-4 — Medellín, Colombia — orbichain.com