RAPITRA, in compliance with Law 1581 of 2012, Decree 1377 of 2013, and other related regulations on personal data protection in Colombia, adopts this Personal Data Processing Policy, which governs the collection, storage, use, circulation, and deletion of information provided by data subjects.
1. What RAPITRA processes, and in what capacity
This policy covers two distinct sets of information. RAPITRA does not act in the same capacity with respect to each:
- Data belonging to platform customers —hosts, owners and accommodation managers—: RAPITRA acts as data controller, determines the purposes described in this policy and answers directly to the data subject.
- Data belonging to guests registered through the platform: RAPITRA acts as data processor. The controller is the accommodation provider that collects the data and is required to report it to Colombia's Ministry of Trade, Industry and Tourism and to the Special Administrative Unit Migración Colombia. RAPITRA processes it solely on that controller's instructions: it does not use the data for its own purposes, does not sell it and does not transfer it to third parties other than those authorities.
2. Purpose of Processing
The personal data collected will be used to:
- Manage contractual, commercial, and employment relationships.
- Provide information about products, services, promotions, and events.
- Handle requests, complaints, and claims.
- Comply with legal and regulatory obligations.
- Conduct internal market analysis and customer satisfaction studies.
3. Rights of Data Subjects
In accordance with current regulations, personal data subjects have the right to:
- Know, update, and rectify their data.
- Request proof of the authorization granted.
- Be informed about how their data is used.
- File complaints with the Superintendence of Industry and Commerce (SIC).
- Revoke authorization and/or request the deletion of their data when applicable.
4. Duties of the Data Controller
RAPITRA commits to:
- Guarantee the security and confidentiality of information.
- Implement technical, human, and administrative measures to prevent alteration, loss, consultation, or unauthorized access.
- Respect the principles of legality, purpose, freedom, truthfulness, transparency, and confidentiality in data processing.
5. Retention and deletion
Processing does not extend beyond the reasonable period necessary for the purposes that justified it. Once the purpose is fulfilled, information is deleted or anonymised by an automated daily process, without the data subject having to request it:
- Identity document images: deleted 30 calendar days after check-out.
- Guest identifying data —names, document number, date of birth, email and phone—: anonymised 6 months after check-out.
- Records of transmissions to the authorities —report codes and dates—: retained dissociated from the data subject's identity. As they no longer allow a person to be identified, they cease to constitute personal data.
- Customer account data: for the duration of the contractual relationship and, thereafter, for the period required by applicable legal, accounting and tax obligations.
Deletion is carried out on the platform's production systems. Backups are overwritten according to their own rotation cycle.
6. Assisted document reading
When the accommodation provider enables identity document capture, the platform offers assisted reading that extracts the document's fields so the data subject does not have to type them. To do so, the image is transmitted to an external technology provider that processes it on the spot and returns the extracted fields. That provider acts as a processor and handles the image solely on RAPITRA's instructions, without using it for its own purposes. RAPITRA does not store the image as a result of that operation: all that remains is a technical usage record containing no personal data. Use of this feature is optional and the data subject may type the fields manually.
7. Procedure for Exercising Rights
Data subjects may exercise their rights by sending a written communication to the email info@rapitra.app, clearly stating the request.
8. Validity
This policy becomes effective on August 31, 2026, and will remain in force as long as the relationship with the data subjects is maintained or as long as necessary to fulfill the purposes described.