Skip to content

Privacy and personal data protection policy

Last updated: [DATE]

This policy explains what personal data we collect when you buy the book on this site or leave us your details so we can tell you when the pre-order opens, what we use it for, and how you can exercise your rights. It is written in accordance with Colombia's Law 1581 of 2012 and Decree 1074 of 2015 (habeas data regime).

1. Data controller

[LEGAL NAME OF THE CONTROLLER], identified by [TAX ID], domiciled at [ADDRESS] and reachable at contact@srtsociety.com, is the controller of the personal data collected through this site.

2. Data we collect

To process your order we collect only: full name, email address, phone number, country, state, city and shipping address, plus any delivery notes you choose to add.

We never collect or store card details or banking credentials. Where payment is made through the gateway, that information is captured and processed directly by Wompi S.A.S. (Grupo Bancolombia) in its own secure environment, and from the transaction we keep only the reference, the amount and the payment status.

2c. If you place an order while online payment is not connected

Today the site does not charge: it records your order and the payment is agreed afterwards, away from this website. In that case we collect the same data as in section 2 — what is needed to prepare and ship the book — and we also use it to get in touch with you, at the email address or phone number you leave us, and settle the payment.

While payment is agreed that way, none of your data is shared with the payment gateway, because it is not involved. The rest of this policy applies unchanged: the same fulfilment processors, the same retention and the same rights.

2b. Data we collect if you only ask for the pre-order notice

While the pre-order is not open, this site does not charge: it offers a form so we can tell you when it is. If you use it, we collect only your email address, your mobile number and your country. Nothing else: we do not ask for your name or address, because they are not needed to notify you.

Those three items are used for one purpose only: to tell you that the pre-order has opened and which countries can order from. They are not used for any other communication, they are not shared with third parties and they are not combined with any other file.

We ask for the mobile number because the notice may also be sent by WhatsApp: an opening email stands a fair chance of landing in the promotions folder and never being read.

You can ask us to delete these details at any time by writing to contact@srtsociety.com, without giving any reason. We keep them until the pre-order opens and you decide whether to buy, and we delete them whenever you ask.

3. Purpose

We use your data to: (i) process and confirm payment; (ii) prepare and dispatch your order, which includes passing the shipping details to the distributing bookstore and the courier; (iii) communicate with you about the status of your order; and (iv) meet legal and accounting obligations.

We do not use your data for third-party advertising and we do not sell it.

4. Processors and transfers

We share strictly necessary data with: [DISTRIBUTING BOOKSTORE NAME] (fulfilment), the assigned courier, and our infrastructure provider, which may store the information on servers outside Colombia under contractual security and confidentiality terms. Where payment is made through the gateway, also with Wompi S.A.S. (payment processing).

5. Retention

We keep order data for [PERIOD — e.g. 5 years] for accounting and warranty purposes, then delete or anonymise it.

6. Your rights

You may access, update and correct your data; request proof of the authorisation you gave; be informed of how it has been used; file complaints with the Superintendency of Industry and Commerce; and withdraw your authorisation or request deletion where no legal or contractual duty prevents it.

To exercise any of these rights, write to contact@srtsociety.com. We answer queries within ten (10) business days and claims within fifteen (15) business days, as required by law.

7. Security

We apply reasonable technical and administrative measures to protect your data: encrypted transmission (HTTPS), restricted database access, and separation of payment-gateway credentials from the application code.

8. Changes

If this policy changes, we will publish the updated version on this page with its new date.