COLEKTIA POLICIES

In compliance with the provisions of the Federal Law on the Protection of Personal Data Held by Private Parties (the “Law”), the Regulations of the Federal Law on the Protection of Personal Data Held by Private Parties (the “Regulations”), the Privacy Notice Guidelines published in the Official Gazette of the Federation on January 17, 2013 (the “Guidelines”), and other applicable regulations, COLEKTIA MÉXICO, S.A.P.I. DE C.V. (“the Company” or “COLEKTIA”) hereby provides this Privacy Notice to users of the website https://colektia.com/ (the “Users”), individuals or entities that engage COLEKTIA’s services (the “Clients”), individuals employed by COLEKTIA (the “Employees”), and individuals or legal entities that provide products or services to COLEKTIA (the “Suppliers”), regarding the processing and protection of personal data voluntarily provided through communications with COLEKTIA, including but not limited to communications via email, telephone, electronic means, oral or written communications, forms used to collect personal data, and access to the Website where such access involves the communication of personal data.

For all matters related to this Privacy Notice, the Company, acting as the data controller, designates its address at Bajío 360, 13th Floor, Hipódromo, Cuauhtémoc, Mexico City, Mexico, as the location for receiving notices and communications related to the processing of personal data. The Company hereby issues and makes available this Privacy Notice to Users, Clients, Employees, and Suppliers under the following terms.

I. PURPOSES OF PERSONAL DATA PROCESSING

a) Website Users

The personal information provided by Users will be used to provide information about the services offered by COLEKTIA and to establish communication with Users whenever necessary.

Additionally, personal data may be used for the following secondary purposes:

  • Advertising and marketing activities.
  • Record creation and administrative management.
  • Sending promotions, discounts, and exclusive offers.

If a User does not agree with the purposes described in the first paragraph of this section, they should refrain from using the Website. If a User does not agree with the secondary purposes, they may object by following the procedure described in Section VIII of this Privacy Notice.

Please note that, should the above situation occur, COLEKTIA may be unable to properly provide its services and shall not be liable for any resulting consequences.

b) Clients

The personal information provided by Clients will be used to provide information regarding COLEKTIA’s out-of-court collections services and advisory services, create customized debtor databases, understand the demand for services requested by Clients, establish communication when necessary, and create, analyze, evaluate, update, and maintain records relating to Clients and their debtors.

Based on this information, COLEKTIA may conduct internal studies, maintain records, generate statistics, and perform analyses for internal administrative and operational purposes.

In this context, COLEKTIA acts as a data processor in accordance with Article 49 of the Regulations, as a result of the legal relationship established between COLEKTIA and the Client. COLEKTIA shall comply with the obligations established under Article 50 of the Regulations.

COLEKTIA performs out-of-court collections activities related to credit products and services, whether independent, ancillary, or derived from such products and services. These activities include the collection and delivery of information and documentation, administrative, judicial, and out-of-court collections management, investigations, debtor tracing, and accounting services. Such activities are protected under this Privacy Notice and are carried out exclusively for the purposes described herein.

This information may be shared with third parties involved in the original obligation, as well as with collections personnel, employees, managers, and directors across COLEKTIA’s different offices, solely for the purposes described above.

Additionally, personal data may be used for the following secondary purposes:

  • Advertising and marketing activities.
  • Record creation and administrative management.
  • Sending promotions, discounts, and exclusive offers.

Furthermore, we may use the information provided for the following purposes, which are not strictly necessary for the primary services requested but enable us to provide a better customer experience and higher-quality service:

  • Identification of debtors.
  • Identification of Clients.
  • Facilitating communication between Clients and debtors.

If you do not agree with these secondary purposes, you may object by following the procedure described in Section VIII of this Privacy Notice.

Please note that, should the above situation occur, COLEKTIA may be unable to properly provide its services and shall not be liable for any resulting consequences.

c) Employees

The personal information provided by Employees will be used for the internal administration of employment relationships with COLEKTIA and to establish communication whenever necessary.

If an Employee does not agree with the purposes described in the first paragraph of this section, they should refrain from entering into an employment relationship with COLEKTIA. If an Employee does not agree with any secondary purposes, they may object by following the procedure described in Section VIII of this Privacy Notice.

d) Suppliers

Personal information voluntarily provided by Suppliers will primarily be used for record creation and maintenance. Such information is collected and stored for administrative purposes, facilitating future commercial activities and the provision of services between the parties.

If a Supplier does not agree with the purposes described in the first paragraph of this section, they should refrain from entering into a commercial relationship with COLEKTIA. If a Supplier does not agree with any secondary purposes, they may object by following the procedure described in Section VIII of this Privacy Notice.

II. PERSONAL DATA COLLECTED

For the purposes of this Privacy Notice, personal data shall mean any information collected relating to an individual or legal entity. A User shall mean any identified or identifiable individual or legal entity that provides personal data through the Website or any of the information collection methods described herein, including but not limited to:

  • The Website;
  • Forms used to collect personal data as part of COLEKTIA’s record management system;
  • Email communications;
  • SMS text messages;
  • WhatsApp communications; and
  • Any current or future COLEKTIA service that involves the communication of personal data.

The personal data collected by COLEKTIA from each category of data subject may include the following:

USERS

  • Name
  • Address
  • Age
  • Email address
  • Company affiliation

CLIENTS

  • Name
  • Address
  • Age
  • Marital status
  • Federal Taxpayer Registry (RFC)
  • Unique Population Registry Code (CURP)
  • Email address
  • Telephone number
  • General information
  • Outstanding balances
  • Payment history
  • Credit account number

All information listed in this section may correspond to debtors whose information is provided by the Client to COLEKTIA for collections purposes.

EMPLOYEES

  • Name
  • Address
  • Age
  • Marital status
  • Federal Taxpayer Registry (RFC)
  • Unique Population Registry Code (CURP)

SUPPLIERS

  • Name
  • Address
  • Federal Taxpayer Registry (RFC)

As part of its services, COLEKTIA receives information from various clients, including banks, financial institutions, and other individuals or legal entities that transfer information for the purpose of debt recovery or other services. Such information may contain personal data. Therefore, if a debtor receives any communication or notice from COLEKTIA, it is due to a legal relationship or agreement previously entered into with one of these entities, as described in this Privacy Notice.

In accordance with Article 10, Section IV, and Article 37, Sections VI and VII of the Federal Law on the Protection of Personal Data Held by Private Parties, any personal data obtained as an integral part of collections processes, including tracing and investigation activities, shall be used exclusively for the purpose of facilitating compliance with outstanding obligations. Under these circumstances, the data subject’s express consent is not required.

III. SOCIAL MEDIA

COLEKTIA informs Users, Clients, Employees, and Suppliers that it maintains a presence on social media platforms such as Facebook, Twitter (X), and Instagram.

The processing of personal data of any User, Client, Employee, or Supplier who follows or interacts with COLEKTIA’s official social media accounts shall be governed by the terms, conditions, and privacy policies of the relevant social media platform. Any personal data collected directly by such platforms is the sole responsibility of the platform and not of COLEKTIA.

Users are encouraged to review the privacy policies and terms of use of these platforms to better understand how their personal data is processed and the purposes for which such information may be used.

IV. PERSONAL DATA PROTECTION

The personal data of Users, Clients, Employees, and Suppliers shall be protected at all times in accordance with the principles of legality, consent, information, quality, purpose limitation, loyalty, proportionality, and accountability established under applicable law.

COLEKTIA is committed to safeguarding personal data and implementing appropriate measures to ensure that such information remains secure and protected against unauthorized access, misuse, loss, alteration, or disclosure.

V. TRANSFER OF PERSONAL DATA

The Company shall not disclose or transfer personal information collected from Users, Clients, Employees, or Suppliers, except to affiliated companies, subsidiaries, private entities, or governmental agencies that engage COLEKTIA’s services and require access to such information for the performance of the primary and secondary purposes described in this Privacy Notice.

The Company may also transfer personal data to competent authorities when necessary to comply with obligations established under the Federal Civil Code, the Commercial Code, and other applicable laws and regulations.

Users are further informed that COLEKTIA may transfer collected information to Clients who use the Website and/or COLEKTIA’s services, enabling them to access debtor information and, when deemed appropriate, use such information to initiate legal proceedings.

VI. CHANGES TO THIS PRIVACY NOTICE

The Company reserves the right to modify, expand, amend, or update this Privacy Notice at any time.

Users, Clients, Employees, and Suppliers are hereby informed that any modification to the content of this Privacy Notice will be communicated through the COLEKTIA Website and shall become effective upon publication.

VII. USE OF COOKIES

The Company informs Website Users that cookies and pixel tags may be used on the Website and on external links in order to provide a better user experience and improve the services offered through the Website.

COLEKTIA may collect information related to the User’s Facebook and/or Google account, preferred language, geographic region, browser type, and operating system for marketing, analytics, and tracking purposes.

Users may block or delete cookies and pixel tags installed on their devices by adjusting their browser settings. Most web browsers provide options to allow, block, or delete cookies.

Cookie Deletion Warning

Users may choose to delete or block all cookies associated with this Website. However, certain features of the Website may not function properly, and the overall user experience may be affected.

If you have any questions regarding our Cookie Policy, you may contact us using the email address provided in this Privacy Notice.

VIII. METHODS AND PROCEDURES FOR EXERCISING DATA SUBJECT RIGHTS

In accordance with applicable law, Users, Clients, Employees, and Suppliers may request that the Company cease processing their personal data at any time. They may access, rectify, cancel, or object to the processing of their personal data, as well as object to its disclosure or request limitations on its use through the procedures established by the Company.

Pursuant to the Federal Law on the Protection of Personal Data Held by Private Parties, Users, Clients, Employees, and Suppliers may exercise their rights of Access, Rectification, Cancellation, and Objection (ARCO Rights), object to the disclosure or use of their personal data, revoke any consent previously granted, or object to the processing of their personal data by:

Telephone

+52 15623969233

Email

datos@colektia.com

Attention: Luis Rojas

The request must include the following information:

  • The reason for the request to restrict, limit, or prohibit the use of personal data.
  • Full name of the data subject.
  • Physical address or email address where all communications related to the request may be sent.
  • A digital copy of an official identification document proving the identity of the applicant, including but not limited to a voter identification card, driver's license, passport, or any other document that facilitates the identification of the personal data concerned.
  • A clear and precise description of the personal data for which the data subject seeks to exercise any of their rights, or a detailed description of the processing activity for which the data subject wishes to restrict the use of their personal data.

Written Request

Requests may also be submitted in writing and sent by certified mail to COLEKTIA’s offices located at:

Bajío 360, 13th Floor
Hipódromo, Cuauhtémoc
Mexico City, Mexico

The Company shall have a period of twenty (20) business days to respond to the request through the communication channel specified by the User, Client, Employee, or Supplier.

If a User, Client, Employee, or Supplier believes that their rights regarding the protection of personal data have been violated, they have the right to seek recourse before the competent authority. In Mexico, the competent authority is the National Institute for Transparency, Access to Information and Personal Data Protection (INAI).

Users, Clients, Employees, and Suppliers may revoke any consent previously granted to COLEKTIA for the processing of their personal data. However, it is important to note that in certain cases COLEKTIA may not be able to comply with such request or immediately cease processing personal data due to legal obligations that require continued processing.

Likewise, data subjects should be aware that, for certain purposes, the revocation of consent may prevent COLEKTIA from continuing to provide the requested services or may result in the termination of the existing commercial, professional, or employment relationship, as applicable.

Pursuant to Article 8 of the Federal Law on the Protection of Personal Data Held by Private Parties, failure to expressly object after reading this Privacy Notice shall be deemed acceptance of its terms.

Colektia is a leading collections services provider in Latin America. We serve multiple banking and financial institutions and, as part of our operations, have access to sensitive business information, including the personal data of customers and end users. Any compromise of this information could adversely affect the business interests of Colektia, its employees, and its clients.

Our security vision is:

"To make Colektia trustworthy, resilient to today's volatile environment, adaptable to constant change, and capable of withstanding accidents, cyber threats, and operational failures."

This Security Policy reaffirms our commitment to protecting all information and assets owned by or entrusted to Colektia, ensuring a secure, efficient, and reliable operating environment for both our organization and our clients.

Colektia maintains a converged security model designed to ensure:

  • The protection of information and assets against unauthorized access through appropriate security controls covering physical security, logical security, and personnel security.
  • Compliance with all applicable legal, regulatory, and contractual requirements across our global operations.
  • Business continuity aligned with organizational requirements and stakeholder obligations.
  • Clearly defined security responsibilities across departments and individuals to ensure adherence to this policy.
  • Appropriate security awareness and competency across all levels of the organization to fulfill these responsibilities.
  • Established channels through which employees and stakeholders can report security weaknesses, breaches, incidents, or service disruptions.
  • A robust response framework for identifying, managing, and resolving security weaknesses, breaches, incidents, and service interruptions.
  • Governance and oversight of security performance against established objectives, enabling continuous improvement.

This policy is supported by standards, procedures, guidelines, and additional policies that together form Colektia’s Security Management System. These documents will be made available to relevant stakeholders, who are expected to contribute to their effective implementation and enforcement.

The Security Management System will be reviewed periodically to ensure its continued effectiveness, relevance, and alignment with business operations, regulatory requirements, and evolving stakeholder expectations.

This policy applies globally across Colektia and is binding on all employees, contractors, business partners, and third parties granted access to Colektia’s infrastructure, information systems, technology resources, or data assets.

Any violation or breach of the objectives and requirements established in this Security Policy may result in disciplinary, contractual, or legal consequences, as applicable, and shall apply equally across all Colektia operations worldwide.

OUR MISSION

Colektia’s mission is to reinvent the collections industry.

OUR VISION

To be a leading force in a new era of collections, where technology plays a fundamental role in making the industry more human, efficient, and effective.

WE ARE COMMITTED TO:

Innovation & Traceability

We conduct periodic reviews of our processes, providing feedback to recognize achievements and improve implemented strategies, with the goal of continuously enhancing the quality of our services.

Profitability

We recognize the importance of sustainable growth in both customer acquisition and revenue generation, while maintaining effective cost control to deliver strong financial results for our investors.

Fostering a Positive Work Environment

We promote a workplace built on respect, equality, and open communication. We are committed to maintaining an environment free from discrimination, sexual harassment, intolerance, and violence.

We actively support equity, diversity, and inclusion through inclusive leadership, meaningful change initiatives, and long-term business sustainability.

Compliance with Requirements

We are proactively committed to meeting the requirements and expectations of our stakeholders, continuously improving our Quality Management System, and complying with all applicable legal, regulatory, and contractual obligations.

Customer Satisfaction

Our approach is driven by a deep understanding of our customers. We provide personalized service tailored to each client's needs, anticipating challenges and supporting informed decision-making that positively impacts business outcomes.

Our Quality Policy is reviewed periodically to ensure its continued suitability and effectiveness and is communicated to all relevant stakeholders.