Privacy Policy

Privacy Policy

DAPP Colombia S.A.S., a simplified stock corporation identified with Tax ID (NIT) 901,644,165, domiciled at Cl 104 #18A-52 in the city of Bogotá D.C. (hereinafter the "Company" or the "Corporation"), in its capacity as Data Controller for personal data, and in compliance with Statutory Law 1266 of 2008, Statutory Law 1581 of 2012, Sole Regulatory Decree 1074 of 2015, and other regulations that amend, supplement, or replace them, makes available to its users, employees, suppliers, and other data subjects this Personal Data Processing Policy, for the purpose of guaranteeing the full exercise of the fundamental right to habeas data, ensuring the privacy, confidentiality, and security of personal information collected, and establishing the guidelines under which the Company collects, stores, uses, circulates, deletes, and generally processes personal data in the course of its corporate purpose and business activities.

To this end, the Company discloses the following:

For anything related to the processing and protection of your Personal Data, you may contact us by sending an email to privacy@arqfinance.com.

1. Definitions

  • Personal Data: any information associated with a natural person that allows their identification. E.g.: Name.

  • Private Personal Data: knowledge of it is restricted to the public and is known or should only be known by the Data Subject.

  • Sensitive Data: affects the Data Subject's privacy and improper use may lead to discrimination. E.g.: Political party or fingerprints.

  • Public Data: may be processed by anyone without requiring authorization.

  • Data Subject: the natural person whose personal data is subject to Processing.

  • Database: a set of personal data subject to processing.

  • Data Processing: any action carried out with personal data. E.g.: collection, storage, use, modification, or deletion.

  • Data Controller: the party who makes decisions regarding the database and/or data processing.

  • Data Processor: the party who carries out personal data processing under the Data Controller's instructions.

  • Authorization: the Data Subject's prior, express, and informed consent to carry out the Processing of personal data. It may be written, oral, or implied.

  • Privacy Notice: a document that informs the Data Subject about how their personal data is collected, used, stored, and protected, as well as their rights regarding it.

  • Transmission: the sending of personal information, within or outside the country, whereby the Data Controller shares it with a Data Processor for processing, following agreed-upon conditions.

  • Privacy Officer: the person who oversees, controls, and promotes the application of the Privacy Policies.

2. What is the purpose of the processing and what data do we collect?

The Company will collect personal information to comply with personal data processing regulations in Colombia, prevent fraud, and ensure a reliable experience in our transactions within the ARQ Application. The purpose of our data processing is as follows:

Purpose of processing / Data collected

Browsing on the web and/or app. We may collect user information while accessing the website or the ARQ Application, even if the user is not registered or logged in. Data collected: assigned IP address; location (approximate); device geolocation data; login information; date and time of access to the ARQ Application and other traffic-related data; APIs; pages visited; unique device identifiers; browser type used; operating system and/or platform used; search engine and keywords used to find the ARQ Application; other similar identifying information to communicate with the ARQ Application.

Registration in the App. We may collect data during use of or registration in the ARQ Application. Data collected: name; physical address; email address; phone number; date of birth; nationality; identity document or passport; tax identification number and/or any other government-issued identification number; employment or business activity details; financial information, including salary, income, and employer details; source of income; device geolocation; cryptocurrency wallet address; biometric data; electronic signature; any public key shared with us; communications; 2FA recovery codes; names of family beneficiaries; information about how users use our site or any other information required by applicable law; proof of identity, requesting a copy of a Passport, Proof of Residence or Income, or any relevant identification document.

Provision of services and management. User registration in the ARQ application. Confirmation of the user's identity. Provision of requested information, products, and services. Completion of transactions carried out with us. Collection of outstanding debts. Compliance with contractual obligations. Fraud prevention and account security assurance.

Management and Operation of Cards and Financial Services. Processing and administration of applications for the issuance, activation, and shipment of Cards. Management of collections and communications, using various channels such as email, phone calls, instant messaging, and other electronic and physical means. Verification and resolution of inquiries about charges, transactions, and billing related to the Cards. Monitoring and analysis of users' financial and transactional behavior for risk and fraud prevention. Validation and authentication of data through home visits when necessary for Card delivery or application processing. Creation of consumption profiles and spending patterns, facilitating the personalization of financial services.

Service improvements. Optimization of the presentation of ARQ Application content to ensure maximum efficiency. Management of the ARQ Application and internal business administration, including troubleshooting, data analysis, testing, research, and statistical purposes. Contacting the user for customer service or any other reason we deem necessary. Notification of changes to our services. Maintaining the security of the ARQ Application as part of our protection efforts.

Targeted marketing. Providing information about other services we offer. Distribution of marketing materials. Sending marketing communications, including promotions and campaigns.

Identification and prevention of fraud, abuse, and crime. Compliance with applicable regulations. ARQ Application of Anti-Money Laundering and Counter-Terrorist Financing rules, through identity validation, "Know Your Customer" (KYC) processes, screening against Politically Exposed Persons lists, and profile and history analysis. Compliance with tax reporting regimes related to collection, registration, auditing, and billing at the governmental level. Responding to requests from competent administrative or judicial authorities.

Administrative and accounting management. Management of employment contracts, payments, benefits, and internal reporting. Management of onboarding suppliers and third parties for the execution of the Company's accounting and financial procedures. Recording and support of financial and accounting information in the Company's software to track transactions carried out. Management of billing processes to support payments within internal accounting and for internal and external audits. Control and monitoring of risk reports within the Company to identify unsafe areas and develop action plans to mitigate risks. Administration of the occupational health and safety management system, including tracking of employees' entry and exit medical exams.

Types of data collected

This section describes the types of personal data that may be collected, in accordance with current Colombian regulations, including but not limited to identification, contact, sensitive, financial data, and any other information necessary for the provision of our services, pursuant to Law 1581 of 2012 and its implementing decrees.

Biometric data: Facial photograph, for device unlocking (fingerprint, Touch ID, and Face ID), and facial recognition for authentication purposes.

Financial data: Banking information, transactions, payment history, payment account number, account balance, prepaid card information, transaction history (date, amount, transaction type, merchant or destination), transaction frequency and volume.

Security data: Authentication information (such as passwords, PIN, two-factor authentication), suspicious activity or fraud attempts.

3. Processing of sensitive data

In the event that, due to the nature of the service, we require sensitive data, such as fingerprint and/or facial biometrics, its processing will be subject to express and separate authorization from the Data Subject.

You, as the Data Subject, are not required to provide sensitive data. If you choose to share it voluntarily, we guarantee its protection through enhanced security measures and in compliance with Colombian personal data protection regulations.

4. Consent

We recognize our responsibility when collecting and processing your data, which is why we make sure to obtain your consent beforehand. Consent is granted through notices in emails, statements in forms, upon entering the App, and through any legally valid mechanism we implement.

Consent must be informed, which is why this Policy contains complete and clear information about the privacy of your data.

For the processing of personal information, we will request your prior, express, and informed authorization as the data subject; this may be written, verbal, or through unequivocal conduct, and we will keep proof of the authorizations obtained for data processing.

5. What are your rights as a data subject?

a) To know, update, and correct your Personal Data. b) To request proof of the authorization granted. c) To be informed about the use of your Data. d) To file complaints with the Superintendence of Industry and Commerce for violations of Law 1581 of 2012 and applicable regulations. e) To revoke the authorization and/or request deletion of the Data when the Processing fails to respect constitutional and legal principles, rights, and guarantees. f) To access, free of charge, the Personal Data subject to Processing. g) To authorize third parties to be given your Data. h) To review your personal information held in our Database.

6. What are our obligations as Data Controller?

a) Request and retain a copy of the authorization you granted. b) Inform you of the purpose of the collection and your rights when authorizing the processing. c) Keep the information under security standards. d) Process your inquiries and complaints. e) Adopt an internal manual of policies and procedures to ensure proper legal compliance in handling inquiries and complaints. f) Inform the Data Subject, upon request, about the use given to their Data. g) Notify the data protection authority when security breaches occur and there are risks in the administration of your data. h) Comply with instructions and requirements from the Superintendence of Industry and Commerce.

7. Age requirement.

You must be at least 18 years old to accept this Policy on your own behalf.

8. How long will we retain your information?

We retain your Personal Data for as long as necessary to fulfill the intended purpose. You may revoke the consent you have given us for the processing of your Personal Data at any time.

However, please note that we reserve the right to retain your Data for as long as a contractual relationship is maintained and the intended purposes are being fulfilled.

Generally, Personal Data collected in compliance with our legal obligations is retained for 5 years. However, we may retain your personal data for a longer period when necessary to comply with a legal obligation to which we are subject, or when we have a legitimate purpose for its processing.

9. Who do we share your information with?

We may share your information with:

  • Companies belonging to the ARQ group of companies (formerly DolarApp). That is, any affiliate, subsidiary, or holding company.

  • Other companies that provide services to us for the maintenance or fulfillment of our services.

  • Risk management providers, information security providers, specialized software providers necessary for fulfilling the contractual relationship with our Users, software providers specialized in fraud prevention, and similar entities.

  • Our employees who have a business reason to know the information.

10. Data transfer

We may transfer personal data domestically and internationally, ensuring at all times compliance with Law 1581 of 2012 and other applicable personal data protection regulations.

Efforts will be made to ensure that international transfers are always made to countries that provide adequate levels of data protection; if this is not the case, the necessary contractual and security measures will be adopted to guarantee the integrity, confidentiality, and legality of the information processing, in accordance with the provisions established by the Superintendence of Industry and Commerce (SIC) and the law.

Likewise, the transfer of personal data may be carried out when there is express authorization from the Data Subject, except for exceptions provided by law, and when necessary for the performance of a contract between the Data Subject and the Company.

In all cases, the Company will strive to ensure that third-party recipients of personal data comply with adequate protection standards and adopt the necessary measures for proper processing, in line with the principles of legality, security, and confidentiality established under current legislation.

Accordingly, through this Privacy Policy, you consent and agree that your Personal Data may be transferred to other countries. Withdrawal of your consent will have effect only prospectively, without affecting the validity or legality of processing, actions, or decisions carried out prior to such revocation, which will remain in the same terms in which they were carried out.

11. How to make requests regarding data processing?

If you have any inquiry or request regarding the processing of your data, contact us at: privacy@arqfinance.com

We will respond to your request within a maximum of 15 business days. The inquiry must include:

  • Your name, identification, and contact number or email;

  • Description of the Data you wish to review;

  • Description of the inquiry you are making; and

  • Supporting documents, if applicable.

If the inquiry does not include these requirements, we will notify you within 5 days of receiving it. You will have 2 months to correct it; if you do not, we will consider that you have withdrawn the request.

12. Amendments to the Policy

We may amend this Policy at any time. To do so, we will notify changes by publishing them on our website. If you continue using our services after the amendments have been published, we will understand that you have accepted them.

If you disagree with the new Policy, you may request the withdrawal of your information via the email indicated above. However, you may not request withdrawal of your Data while you maintain a relationship with us.

This version of the Policy will take effect as of May 20, 2026.