• Products
  • Help
  • Fees and rates
  • Security
  • Blog
  • About

PRODUCTS

Business
Account
Card
Security

HELP

Contact
FAQs
Help center
Terms & Conditions

LEGAL

Privacy Policy
Account Terms & Conditions
Card Terms & Conditions
Cookies

FEES & RATES

Product pricing

ABOUT VIIO

Our story

Available on the App Store and Google Play

App StoreGoogle Play

Follow us

InstagramTikTokYouTubeSpotifyLinkedIn

Follow us

InstagramTikTokYouTubeSpotifyLinkedIn

Persimon (VIIO) does not provide or offer regulated financial services and does not perform activities reserved for licensed financial institutions.

By using VIIO, users acknowledge they understand the product's features and the associated risks, as described in the terms and conditions available on this website.

© 2026 viio.me

  1. Home
  2. Privacy policy

Privacy policy

VIIO

VIIO

Publish date: 9/29/2026

Last updated: 9/29/2026

legal

VIIO values user trust and recognizes the importance of personal data protection in the digital environment, particularly concerning payments, purchases, and international transfers. Our platform allows individuals and companies to carry out operations such as making online purchases in dollars, making international purchases from Colombia, sending money internationally, and transferring money abroad, which involves the responsible handling of personal, financial and transactional information.

For this reason, VIIO adopts strict security, confidentiality, and regulatory compliance standards to ensure that personal data is processed lawfully, securely, and transparently. This Privacy Policy explains how we collect, store, use, share, and protect the personal information of users who interact with our digital services, and describes the rights available to them as data subjects.

This Privacy Policy details how VIIO collects, stores, uses, and protects the information of all users and clients who interact with its digital services

Effective Date: September 4, 2024

1. INTRODUCTION

The Privacy Policy or Personal Data Processing Policy complies with the provisions of Law 1581 of 2012 and the rules that modify, repeal or replace it, compiled in the Single Regulatory Decree 1074 of 2015, Commerce, Industry and Tourism Sector; in development of the constitutional right to know, update and rectify all information that has been collected in databases or files, and other constitutional rights, freedoms and guarantees related in articles 15 and 20 of the Political Constitution; personal data that are Treated by PERSIMON S.A.S. (VIIO), legal entity that guarantees the security, confidentiality and availability of the data, in all its processes and procedures regarding the Processing, that is, collection, storage, use, circulation and suppression of the personal data.

I) PERSIMON S.A.S. (VIIO), is recognized as RESPONSIBLE for the Personal Data Processing.

II) PERSIMON S.A.S. (VIIO), informs the data subjects of personal data, (clients, suppliers, employees, independent professionals, work contractors, temporary employees, security, among others, of the purposes of the personal Data Processing.

III) PERSIMON S.A.S. (VIIO), informs the data subjects, the means so they can exercise their rights: know, update, rectify, suppress information and revoke the authorization of personal Data Processing in cases allowed by law.

2. IDENTIFICATION OF THE DATA CONTROLLER

• Name: PERSIMON S.A.S. (VIIO)

• Address: Carrera 15#93ª-84

• NIT. 901682358-5

3. SCOPE

This Policy applies and is of mandatory and strict compliance for employees (direct and temporary), contractors, suppliers and who hereinafter have or come to have any type of technical or service contractual relationship with PERSIMON S.A.S. (VIIO), related to all personal data registered in the files or databases (physical and digital) held by PERSIMON S.A.S. (VIIO), who acts as RESPONSIBLE, when treating directly, and as in charge when performing said Processing on behalf of a Responsible, of the Personal Data Processing.

For customer personal data, this present policy is applicable solely to personal data collected directly by PERSIMON S.A.S. (VIIO), by virtue of commercial and legal relationship generated from direct request of its clients.

4. DEFINITIONS

For this policy, definitions described in Law 1581 of 2012, Title I, Article 3 will be taken:

1. Authorization: Prior, express and informed consent of Data Subject to carry out Personal Data Processing

2. Database: Organized set of personal data that is object of Processing;

3. Personal data: Any information linked or that can be associated to one or several determined or determinable natural persons;

4. Person in Charge of Processing: Natural or legal person, public or private, who by themselves or in association with others, performs Personal Data Processing on behalf of Data Controller

5. Data Controller: Natural or legal person, public or private, who by themselves or in association with others, decides on database and/or Data Processing;

6. Data Subject: Natural person whose personal data are object of Processing;

7. Processing: Any operation or set of operations on personal data, such as collection, storage, use, circulation or suppression.

8. Public data: Data that is not semi-private, private or sensitive. Considered public data are, among others, data relative to civil status of persons, their profession or trade and their quality of merchant or public servant. By its nature, public data may be contained, among others, in public records, public documents, official gazettes and bulletins and duly executed judicial sentences that are not subject to reserve.

9. Sensitive data: Understood by sensitive data are those that affect privacy of Data Subject or whose improper use can generate their discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership to unions, social organizations, human rights or that promotes interests of any political party or that guarantee rights and guarantees of opposition political parties, as well as data relative to health, sexual life, and biometric data.

5. PRINCIPLES

For personal Data Processing principles defined in Law 1581 of 2012, Article 4 will apply:

1. Principle of legality in matters of Data Processing: It is a regulated activity that must be subject to what is established in law and other provisions that develop it;

2. Principle of finality: Processing must obey a legitimate purpose in accordance with Constitution and Law, which must be informed to Data Subject;

3. Principle of freedom: Processing can only be exercised with prior, express and informed consent of Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in absence of legal or judicial mandate that relieves consent;

4. Principle of truthfulness or quality: Information subject to Processing must be truthful, complete, exact, updated, verifiable and understandable. Processing of partial, incomplete, fractioned or misleading data is prohibited;

5. Principle of transparency: In Processing right of Data Subject to obtain from Data Controller or Person in Charge of Processing, at any time and without restrictions, information about existence of data concerning them must be guaranteed;

6. Principle of access and restricted circulation: Processing is subject to limits derived from nature of personal data, provisions of this law and Constitution. In this sense, Processing may only be done by persons authorized by Data Subject and/or by persons provided for in law. Personal data, except public information, cannot be available on Internet or other mass disclosure or communication media, unless access is technically controllable to provide restricted knowledge only to Data Subjects or authorized third parties in accordance with law;

7. Principle of security: Information subject to Processing by Data Controller or Person in Charge of Processing referred to in this policy, must be handled with technical, human and administrative measures necessary to grant security to records avoiding their adulteration, loss, consultation, use or unauthorized or fraudulent access;

8. Principle of confidentiality: All persons intervening in Personal Data Processing that do not have nature of public are obliged to guarantee reservation of information, inclusive after their relationship with any of tasks comprising Processing has ended, being able only to supply or communicate personal data when corresponds to development of activities authorized in law and in terms thereof.

6. PURPOSE AND CHANNELS OF PROCESSING

1. Without prejudice to exceptions provided in Law, for Personal Data Processing prior and informed authorization of Data Subject is required, which must be obtained by any means that can be object of subsequent consultation.

2. Data Subject authorization will not be necessary when referring to: Information required by a public or administrative entity in exercise of its legal functions or by judicial order; Data of public nature; Cases of medical or sanitary urgency; Information Processing authorized by law for historical, statistical or scientific purposes; Data related to Civil Registry of Persons.

3. Purposes of Personal Data Processing supplied in your quality of Data Subject are:

A) For proper purposes of credit contracts celebrated or to be celebrated between PERSIMON S.A.S. (VIIO) and its users and clients, in accordance with what is provided in commerce code, Single Decree 1074 of 2015 and other rules regulating specifically the matter as regarding services offered and provided by PERSIMON S.A.S. (VIIO) through its page and/or its applications and those activities derived from its corporate purpose

B) Publicize services offered by PERSIMON S.A.S. (VIIO)

C) Develop processes required for adequate provision of products and/or services contracted by users and/or clients of PERSIMON S.A.S. (VIIO)

D) Evaluate, maintain, improve and deepen contractual relationship, in its different phases, including acts related to pre-contractual stage such as offering of new products and/or services and/or information on events, news, promotions, advertising and loyalty programs, through use of:

• email,

• Cell phone,

• SMS,

E) Update supplied data with information found available in Information Operators or any other person, entity or organization handling or administering databases with legally defined purposes for this type of entities

F) Analyze, develop and implement tools for fraud prevention and/or impersonations and/or risks of PERSIMON S.A.S. (VIIO) computer system

G) Share data relative to client information, which includes use and update of contact data, with firms specialized in collection tasks so they advance collection management of contracted obligations, and other services considered necessary or complementary; as well as, management of overdue portfolio, using for it both judicial mechanisms as well as extra-procedural ways allowed by legal system

H) Evaluation of solvency, suitability, debtor risks, their payment behavior, collection of corresponding quotas, rates and charges, both prejudicially and judicially, as appropriate

I) Remit answers of consultations and petition rights to petitioners

J) Advance procedures and services requested to Company

K) Carry out campaigns and dissemination activities and offers of Company services and/or products

L) Update Databases, including cases where transmitting or transferring to a third party is required, information for validation, debugging, enrichment and homogenization of data, prior compliance with legal requirements

M) Elaborate studies, statistics, surveys, trend analysis, related to services provided by Company

N) Manage necessary information for fulfillment of tax, contractual, commercial and commercial, corporate and accounting registration obligations

O) Transmit information to national or international agents with whom there is an operational relationship providing necessary services for due operation of Company

P) Carry out all necessary activities for fulfillment of different contractual stages in relationships with current and potential clients

Q) Maintain a digital archive allowing to have information corresponding to each contract.

R) PERSIMON S.A.S. (VIIO), subscribes presently and in near future, alliances and/or agreements with Risk Centrals, Guarantors and/or Certifiers, to transfer, transmit, receive, process, circulate, store, supply and classify financial personal information of Data Subjects, among them, Financial Information Central and/or CIFIN, Datacrédito Experian, dematerialized promissory notes with Deceval; and/or whoever represents or holds their rights; Insurance Companies, Insurance Intermediaries; Telemarketing Companies, Companies and/or natural persons specialized in portfolio collection management; Third party logistics and strategic service providers including all those helping to fulfill social and commercial purpose of PERSIMON S.A.S. (VIIO)

4. Purposes of Processing provided of candidate, employee, supplier and share data subject data.

A) For all purposes related to object of selection processes, contractual or related to them

B) Carry out all internal procedures and fulfillment of accounting, tax and legal obligations

C) Manage Company budget

D) Carry out all necessary activities for fulfillment of different contractual stages in relationships with suppliers and contractors

E) Issue contractual certifications requested by Company contractors

F) Maintain a digital archive allowing to have information corresponding to each contract

7. USER RIGHTS

Users having registered personal information in PERSIMON S.A.S. (VIIO) databases or their successors have right to what is described in Law 1581 of 2012, Title IV, Article 8, which states following rights:

1. Know, update, rectify, oppose and cancel their personal data before Responsibles for Processing or Persons in Charge of Processing. This right may be exercised, among others, regarding partial, inaccurate, incomplete, fractioned data, that induce to error, or those whose Processing is expressly prohibited or has not been authorized; therefore; user will be sole and exclusive responsible for truthfulness and accuracy of their personal data.

2. Request proof of authorization granted to Data Controller except when expressly excepted as requirement for Processing, in accordance with provided in article 10 of law 1581 of 2012.

3. Be informed by Data Controller or Person in Charge of Processing, upon request, regarding use given to their personal data;

4. Present before Superintendence of Industry and Commerce complaints for infractions to provisions in this law and other rules modifying, adding or complementing it;

5. Revoke authorization and/or request suppression of data when in Processing principles, rights and constitutional and legal guarantees are not respected. Revocation and/or suppression will proceed when Superintendence of Industry and Commerce has determined that in Processing Responsible or Person in Charge have incurred in conducts contrary to this law and Constitution;

6. Access free of charge their personal data that have been object of Processing.

8. DUTIES OF PERSIMON S.A.S. (VIIO) AS DATA CONTROLLER AND/OR PROCESSOR

1. Duties as data controller

A) Guarantee Data Subject, at all times, full and effective exercise of right of Personal Data Data Subjects.

B) Request and keep, under conditions provided in this law, copy of respective authorization granted by Data Subject.

C) Inform duly Data Subject about purpose of collection and rights assisting them by virtue of authorization granted.

D) Keep information under necessary security conditions to prevent its adulteration, loss, consultation, use or unauthorized or fraudulent access.

E) Guarantee that information supplied to Person in Charge of Processing is truthful, complete, exact, updated, verifiable and understandable.

F) Update information, communicating timely to Person in Charge of Processing, all novelties regarding data previously supplied and adopt other necessary measures so information supplied to them is kept updated.

G) Rectify information when incorrect and communicate pertinent to Person in Charge of Processing.

H) Supply to Person in Charge of Processing, according to case, only data whose Processing is previously authorized in accordance with provided in Applicable Laws.

I) Demand from Person in Charge of Processing at all times, respect for security and privacy conditions of Data Subject information.

J) Process consultations and claims formulated in terms indicated in Chapter VI of this Policy.

K) Inform Person in Charge of Processing when determined information is under discussion by Data Subject, once claim has been presented and respective procedure has not finished.

L) Inform at request of Data Subject about use given to their Personal Data.

M) Inform data protection authority when violations to security codes occur and risks exist in administration of Data Subjects information.

N) Comply with instructions and requirements imparted by Superintendence of Industry and Commerce.

2. Duties as Data Processor

A) Update information reported by Responsibles for Processing within five (5) business days counted from receipt of communication.

B) Process consultations and claims formulated by Personal Data Subjects in terms indicated in Applicable Laws.

C) Register in Database legend 'claim in process' in form regulated in Applicable Laws.

D) Abstain from circulating information being controverted by Data Subject and whose blocking has been ordered by Superintendence of Industry and Commerce.

E) Allow access to information solely to persons who can have access to it.

F) Inform Superintendence of Industry and Commerce when violations to security codes occur and risks exist in administration of Data Subjects information.

G) Comply with instructions and requirements imparted by Superintendence of Industry and Commerce

9. AREA, MEANS AND PROCEDURES FOR EXERCISE OF RIGHTS OF INFORMATION PROCESSING

Pursuant to Title V of Law 1581 of 2012 legitimized persons for exercise of Data Subject rights may make consultations and claims before Data Controller as follows:

1. Consultations. Legitimized persons may consult personal information of Data Subject held by PERSIMON S.A.S. (VIIO), who in its condition of Data Controller must supply information linked to Data Subject found stored. Consultation will be formulated by means enabled by Responsible, as long as proof of date of receipt of consultation and identity of applicant can be maintained to accredit their legitimacy and remit response.

Consultation will be attended in a maximum term of ten (10) business days counted from date of receipt thereof. When not possible to attend consultation within said term, interested party will be informed expressing motives of delay and signaling date in which consultation will be attended, which in no case may exceed five (5) business days following expiration of first term.

2. Claims. Legitimized persons considering that information found held by Responsible should be object of update, correction or suppression, or when noticing alleged breach of any duties contained in Law 1581 of 2012, may present a claim before PERSIMON S.A.S. (VIIO) in its quality of Data Controller.

Claim will be formulated via request directed to PERSIMON S.A.S. (VIIO) with identification of Data Subject, description of facts giving rise to claim, physical or electronic address to remit response and inform about state of procedure, and accompanying pertinent documents or proofs wanted to be asserted. If claim turns out incomplete, interested party will be required within five (5) business days following its receipt to correct failures. After two (2) months since date of requirement without applicant presenting required information, it will be understood they have desisted from claim.

Maximum term to attend claim will be fifteen (15) business days counted from day following date of its receipt. When not possible to attend claim within said term, interested party will be informed motives of delay and date in which claim will be attended, which in no case may exceed eight (8) business days following expiration of first term.

3. Legitimized persons may only raise complaint before Superintendence of Industry and Commerce once consultation or claim procedure before PERSIMON S.A.S. (VIIO) as Data Controller has been exhausted.

10. VALIDITY

This Policy is in effect since February 23, 2023 and applies to all personal data collected, stored, used, transmitted and transferred until date of its publication, and hereinafter. This Policy may be modified from time to time by VIIO and will be part of contracts celebrated by VIIO implying personal Data Processing. Any substantial modification of this Policy will have to be communicated previously to data subjects via efficient mechanisms, such as VIIO website and/or emails. Understood by substantial modification is, among others, modification in identification of area, dependency or person in charge of attending consultations and claims.

On this page

  1. 1. INTRODUCTION
  2. 2. IDENTIFICATION OF THE DATA CONTROLLER
  3. 3. SCOPE
  4. 4. DEFINITIONS
  5. 5. PRINCIPLES
  6. 6. PURPOSE AND CHANNELS OF PROCESSING
  7. 7. USER RIGHTS
  8. 8. DUTIES OF PERSIMON S.A.S. (VIIO) AS DATA CONTROLLER AND/OR PROCESSOR
  9. 9. AREA, MEANS AND PROCEDURES FOR EXERCISE OF RIGHTS OF INFORMATION PROCESSING
  10. 10. VALIDITY

You might be interested in

Terms and conditions

Terms and conditions

9/29/2026

legal

Card terms and conditions

Card terms and conditions

9/29/2026

legal

Cookies

Cookies

9/29/2026

legal