Legal

Privacy policy

Corporate policy effective July 2026 · web version published August 2026

This page describes how Dexon Software S.A.S. BIC ("Dexon") processes personal data — on this website, in its corporate operations and in its SaaS services. It is the web version of Dexon's Corporate Privacy and Personal Data Protection Policy, drafted to be reviewed by privacy officers, legal teams and vendor risk teams as much as by the person filling in a form.

Who is responsible

The data controller for this website and Dexon's corporate processing is Dexon Software S.A.S. BIC, Cra 16A #79-95, Piso 6, Bogotá D.C., Colombia (postal code 110221). Privacy contact: [email protected]. General contact: [email protected]. Where a customer agreement designates a different notice channel, requests related to that customer's data should follow the contractual channel.

What this website collects

This site is static: browsing it creates no account and requires no login. Personal data enters in exactly three ways:

  • The contact form: name, job title, organization, sector, work email, phone (optional) and your message. It is sent by email to the Dexon team so a person can reply — that is its only purpose.
  • Bot verification: the form is protected by Cloudflare Turnstile, which processes technical data (IP address, browser signals) to distinguish people from bots. It may set strictly necessary cookies for that verification.
  • Hosting logs: the site is served by Cloudflare Pages, whose infrastructure processes IP addresses and request metadata to deliver pages and protect against abuse.

What this website does not do

This site sets no analytics or advertising cookies and runs no third-party trackers. Fonts are served from our own origin, so your visit is not reported to a fonts provider. If we ever add measurement, it will be a cookieless, privacy-preserving tool, and this policy will say so before it happens.

Purposes and legal bases

Where GDPR applies and Dexon acts as controller, processing relies on the following bases:

  • Performance of a contract — providing services, support, user access and contract administration, and answering the enquiry you send us.
  • Legitimate interests — security monitoring, service improvement, business relationship management, fraud prevention and business-to-business communications.
  • Consent — optional marketing communications and any cookies that require it. You may withdraw consent at any time without affecting prior processing.
  • Legal obligation — tax, accounting, corporate, labor, regulatory, judicial or administrative requirements.

When your data lives in a customer's Dexon platform

Dexon's customers configure Dexon BPM and Dexon ServiceDesk to run their own business processes. For that Customer Data, the customer is the controller and Dexon acts as processor: we process it only to provide the contracted services and under the customer's documented instructions, governed by a Data Processing Agreement.

Two commitments from the corporate policy are worth quoting plainly: Dexon does not sell Customer Data, and Dexon does not use Customer Data for unrelated advertising purposes. Dexon support personnel access Customer Data only when necessary to provide support, troubleshoot, maintain security or follow authorized instructions.

If you want to exercise rights over data a Dexon customer holds about you — your employer, a service provider, a public entity — the controller is that organization. We will direct your request to them and assist them as their processor.

Recipients and subprocessors

Dexon shares personal data only for legitimate purposes: with its personnel and authorized contractors under confidentiality obligations, with cloud and infrastructure providers, with professional advisors, and with public authorities where the law requires it. For this website specifically, the processors involved are Cloudflare (hosting and bot verification), Resend (delivery of contact form email) and Microsoft Azure for the SaaS platform. Subprocessors for SaaS services are governed contractually and detailed in the Data Processing Agreement and the International Data Transfer Statement, available to customers under review.

International transfers

Personal data may be processed or hosted in Colombia, the United States and other approved jurisdictions, depending on the service and contract. Dexon-managed SaaS deployments run on Microsoft Azure. Where GDPR applies to a transfer, Dexon implements the required safeguards — contractual protections, Standard Contractual Clauses where applicable, subprocessor due diligence and security controls. The detail lives in the International Data Transfer Statement, provided during customer evaluations.

Security

Dexon maintains administrative, technical and organizational measures designed to protect personal data: role-based access under least privilege, TLS encryption in transit and encryption mechanisms for sensitive data, logging and audit trails, secure development practices, cloud infrastructure controls, backup and recovery, confidentiality obligations for anyone with access, and an incident response procedure. No method of transmission or storage is completely secure; Dexon applies risk-based controls and improves them continuously.

Retention

Dexon keeps personal data only as long as necessary for the purpose it was collected: contract and account records for the relationship plus applicable legal limitation periods; Customer Data according to the customer's configuration and instructions; support and security records as needed for audit and service history; marketing records until you opt out. When data is no longer required it is deleted, anonymized or securely disposed of; deletion from backups follows the backup lifecycle.

Your rights

Under GDPR and Colombian law (Law 1581 of 2012 and Decree 1377 of 2013) you may, depending on the case:

  • Know whether we process your data, and access it.
  • Request correction of inaccurate or incomplete data, or deletion where legally applicable.
  • Request restriction of processing, portability of certain data, or object to processing — including direct marketing, always.
  • Withdraw consent where processing rests on it, and request proof of authorization under Colombian law.
  • Request safeguards regarding solely automated decisions with legal or similarly significant effects.

How to exercise them

Write to [email protected]. We may need to verify your identity, and your authority if you act for someone else. If the request concerns Customer Data processed for a customer, we will refer it to that customer and assist them. We respond within the timeframes the applicable law sets, and keep a record of the request and the response. If you believe your rights were not respected, you may also complain to the competent data protection authority.

Minors, automated decisions and changes

Dexon's services are for business and institutional use and are not directed at children; data collected from a child without proper authorization will be deleted or handled as the law requires.

Dexon as a company does not make solely automated decisions with legal effects about you through this website. Where a customer uses platform automation to decide about individuals, that customer is responsible for its legal basis, transparency and human review — and the platform is built to support those safeguards.

This policy may be updated to reflect changes in law, services or security practice. The current version is always at this address, and material changes are communicated to customers as their contracts require.