This is the personal-data processing policy of the Controller. The Spanish text is the official version under Colombian law; this English version is a convenience translation.
1. Controller
The Controller is Esteban Ruano, a natural person, domiciled in Bogotá D.C., Colombia. Email: contact@estebanruano.com. Phone: +57 322 294 5398.
The same person handles petitions, queries, and complaints about personal data. There is no separate data-protection team.
This policy covers the products and services I operate, including:
- estebanruano.com (personal site, blog, portfolio, contact form, and Ensemble)
- studies.estebanruano.com (interactive study material)
- Negodex
- Cuerpo Fit
- Oter (formerly Life Commander)
The current version is published at https://estebanruano.com/privacy and at https://estebanruano.com/privacidad.
2. Legal framework
Processing is governed mainly by the Colombian Constitution (article 15), Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015), guidance from the Superintendence of Industry and Commerce (SIC), and, where relevant, Law 2300 of 2023 on contact channels. This policy is not legal advice.
3. Definitions
- Personal data: any information linked or linkable to a determined or determinable natural person.
- Sensitive data: data that affects privacy or whose misuse could lead to discrimination (health, biometrics, and similar categories).
- Data subject: the natural person whose data is processed.
- Processing: any operation on personal data (collection, storage, use, circulation, deletion).
- Authorization: the data subject’s prior, express, and informed consent.
- Processor: a party that processes data on behalf of the Controller (for example a mail or hosting provider).
4. Scope
This policy applies to people who visit the sites, contact me, create an account, or use any of the listed applications. It also covers visitors and professional contacts.
5. Data processed
Depending on the product and what you choose to provide, I may process:
- Identity and contact: name, email, phone, message, and other data you send in forms or by email.
- Account and product use: user identifiers, credentials (stored appropriately, not in clear text), preferences, and content you create in the service (for example inventory in Negodex, logs in Cuerpo Fit, or personal-organization data in Oter).
- Health or physical-condition data in Cuerpo Fit, only when you enter it to use the app. This may be sensitive data.
- Technical data: IP address, device and browser type, access times, error logs, and metrics needed to run and protect the service.
- Ensemble session data: optional display name, room identifiers, and game state. Volume is stored on your device (local storage).
- Studies: material is viewed in the browser; that site does not run user accounts. Your device may keep local storage (progress or settings).
- Strictly necessary cookies: site language (the locale cookie). The personal site does not use advertising or third-party analytics cookies at the time this policy is published.
I do not seek data from people under eighteen (18). If a parent or legal guardian believes a minor sent us data, they can request deletion at the Controller’s email.
6. Purposes
Data is processed to:
- Reply to messages and work or contact requests.
- Provide, maintain, improve, and protect the products (accounts, sync, support, security, and abuse prevention).
- Meet legal duties, respond to authorities, and establish or defend rights.
- Send service-related notices for a product you use (for example security alerts or material changes to this policy). Data is not used for commercial spam. Under Law 2300 of 2023 you may say which channel you prefer for contact.
- Run the site (language, forms) and, in Ensemble, let several people share a room.
I do not sell personal data. I do not use it to build marketing profiles for third parties.
8. Data-subject rights
Under article 8 of Law 1581 of 2012, you may:
- Know, update, and rectify your personal data.
- Request proof of the authorization given, except where authorization is not required.
- Be informed of how your data has been used.
- File complaints with the Superintendence of Industry and Commerce.
- Revoke authorization and/or request deletion when constitutional and legal principles, rights, and guarantees are not respected.
- Access free of charge the personal data undergoing processing.
9. Queries and complaints
Send your request to contact@estebanruano.com from an address that identifies you, or use the phone number above, including: full name, a contact channel, a clear description of the request and, for a complaint, the facts and supporting documents. If you act for someone else, attach proof of representation.
Queries (article 14)
Answered within ten (10) business days from receipt. If that is not possible, you will be told before the deadline why, and the new date, which may not exceed five (5) additional business days.
Complaints (article 15)
If a complaint is incomplete, you will be asked to complete it within five (5) days. If two (2) months pass with no reply, it is treated as withdrawn. A complete complaint is answered in fifteen (15) business days; if that is not possible, you will be told before the deadline and it will be resolved in no more than eight (8) additional business days.
If you are not satisfied with the response, you may go to the Superintendence of Industry and Commerce (https://www.sic.gov.co).
10. Processors, transfers, and transmissions
To run the services I may use processors, including:
- Hosting and infrastructure providers (currently servers in Europe, e.g. Hetzner) and container or source hosting (e.g. GitHub / GHCR).
- EmailJS, to deliver contact-form messages to my inbox.
- Email, cloud storage, app stores and, when a product charges, payment gateways. Those processors handle only what they need for their role.
Some processors are outside Colombia. International transfers or transmissions are made to provide the service, with reasonable security measures and, where the law requires it, applicable safeguards or authorizations. Using the products authorizes those transfers needed for them to work.
11. Security and retention
I apply reasonable technical and organizational measures (restricted access, encryption in transit where the service allows it, backups, data minimization). No system is infallible; if an incident must be notified, I will do so as required.
Data is kept as long as needed for the purposes and for legal or defense duties. Contact messages are typically kept up to two (2) years unless they must be held longer. Product accounts are kept while active and for a reasonable period after closure for security and claims, then deleted or anonymized.
13. Term and changes
This policy takes effect on 2026-08-28. It remains in force while data is processed for the purposes described, or until a later version is published at the same URL. Material changes will be posted here; continued use of the services after the effective date means you are aware of the current version. If a change requires new authorization, I will ask for it.