Personal Data Processing Policy
Protection, privacy and habeas data · HOUSINN.CO S.A.S. — NIT 901.937.358-1
Note on this translation
This English version is provided for information only, so that guests who do not read Spanish can understand what they accept. The binding text is the Spanish one, and this policy is governed by Colombian law. In the event of any discrepancy between the two versions, the Spanish version prevails.
1. Identification of the data controller
In accordance with article 17 of Law 1581 of 2012, the Controller of personal data collected through the www.housinn.co portal and in the course of tourist accommodation activities is:
- Company name
- HOUSINN.CO S.A.S.
- NIT (tax ID)
- 901.937.358-1
- RNT (tourism registry)
- 259832 y 256458
- Registered office
- Medellín, Antioquia, Colombia
- Contact email
- info@housinn.co
- Website
- www.housinn.co
To exercise data subject rights, the official channel is info@housinn.co, with the subject line: "SOLICITUD DATOS PERSONALES — [Data Subject Name]".
2. Legal framework
This Policy is based on:
- Statutory Law 1581 of 2012 — Protection of Personal Data.
- Implementing Decree 1377 of 2013.
- Single Regulatory Decree 1074 of 2015 (arts. 2.2.2.25.1.1 et seq.).
- Law 527 of 1999 — Electronic Commerce.
- External Circular 002 of 2015 of the Superintendency of Industry and Commerce (SIC).
- Law 1266 of 2008 — Financial Habeas Data (as applicable).
3. Personal data collected
3.1 Identification data
- Full name, identity document number (national ID, passport or equivalent), nationality and date of birth.
3.2 Contact data
- Email address, mobile and/or landline number, city and country of residence.
- When you write through the contact form: your name, your email address and the message you write, for the sole purpose of handling your enquiry and replying to you.
- When you write to us on WhatsApp, the conversation stays on that platform and is also governed by WhatsApp terms, which are outside the control of HOUSINN.CO S.A.S.
3.3 Booking and stay data
- Check-in and check-out dates, booked property or properties, number of companions, accommodation preferences and booking-related communications.
3.4 Financial and payment data
- Booking payments are completed in the payment gateway of our property management system (Stays), outside this portal. HOUSINN.CO S.A.S. does NOT store full credit or debit card data, and this portal never receives it at any point.
3.5 Browsing data
- Aggregate usage metrics: page views, approximate country, device and browser type, and whether a search or a quote was completed.
- These metrics are collected with Vercel Web Analytics, which sets no tracking cookies and builds no device fingerprint, and they do not allow any individual to be identified.
- The address of the visited page is cleaned before being sent: only a small set of previously approved parameters travels, and anything else is discarded, including the URL fragment.
3.6 Sensitive data
HOUSINN.CO S.A.S. does not systematically collect sensitive data (health, biometrics, political opinions, etc.). Where required by law (e.g. immigration reporting), the data subject will be expressly informed and specific authorisation will be requested.
4. Purposes of processing
Personal data will be processed for the following purposes.
4.1 Commercial and service delivery purposes
- Managing, confirming and administering accommodation bookings.
- Operational communications about the booking (confirmation, check-in instructions, check-out reminders).
- Payment, invoicing and collection management.
- Customer service and handling of requests, complaints and claims, including enquiries received through the contact form.
- Sending marketing communications, promotions, offers and newsletters — only where the data subject has given express authorisation for that purpose.
4.2 Legal and regulatory purposes
- Compliance with legal obligations before tourism authorities (National Tourism Registry).
- Reporting to immigration authorities where required by law (Migración Colombia).
- Prevention of fraud, money laundering and terrorist financing (SARLAFT).
- Compliance with judicial or administrative requirements of the competent authorities.
- Reporting to child protection bodies (ICBF, Police) under Law 679 of 2001.
4.3 Security purposes
- Verification of guest identity.
- Recording entry to and exit from the property (Accommodation Registration Card — TRA, art. 22 of Law 2068 of 2020).
- Detection and prevention of fraudulent use of the portal or the services.
5. Data subject authorisation
Personal data will be processed only with the free, express, informed and unequivocal prior authorisation of the data subject, in accordance with article 9 of Law 1581 of 2012. Authorisation may be:
- Written: through the portal forms or the accommodation contract.
- Oral: by call recording where applicable, with express indication of the purpose.
- By unequivocal conduct: where the data subject behaves in a way that unequivocally authorises processing, such as sending an enquiry through the contact form in order to receive a reply.
PARAGRAPH: Marketing communications require separate express authorisation from the data subject, which may be revoked at any time.
6. Rights of the data subject
Under article 8 of Law 1581 of 2012, the data subject has the following rights:
- To know, update and rectify their personal data held by HOUSINN.CO S.A.S.
- To request proof of the authorisation given for the processing of their data.
- To be informed about the use made of their personal data.
- To file complaints with the Superintendency of Industry and Commerce (SIC) for breaches of Law 1581 of 2012.
- To revoke authorisation and/or request deletion of their data, unless a legal or contractual obligation requires it to be retained.
- To access their processed personal data free of charge.
7. Procedure for exercising rights and filing claims
7.1 Enquiries
The data subject may consult the personal information held in the databases of HOUSINN.CO S.A.S. by emailing info@housinn.co with the subject "CONSULTA DATOS PERSONALES". HOUSINN.CO S.A.S. will respond within ten (10) business days of receipt. Where this is not possible, the data subject will be informed before that deadline of the reasons for the delay and of the date on which the enquiry will be answered, which may not exceed five (5) further business days.
7.2 Claims
Data subjects or their successors who consider that the information held must be corrected, updated or deleted, or who identify a possible breach of Law 1581 of 2012, may file a claim with HOUSINN.CO S.A.S., handled as follows:
- The claim must be submitted in writing to info@housinn.co, with the subject "RECLAMO DATOS PERSONALES", and must include: identification of the data subject, a description of the facts, supporting documents and a notification address.
- If the claim is incomplete, HOUSINN.CO S.A.S. will ask the claimant to complete it within five (5) days.
- Once the complete claim is received, a "claim in progress" note will be added to the database within the following two (2) business days, for as long as the claim is being handled.
- HOUSINN.CO S.A.S. will resolve the claim within fifteen (15) business days from the day after receipt. Where this is not possible, the claimant will be informed before that deadline of the reasons for the delay. The maximum additional period is eight (8) business days.
- Once this procedure is exhausted, the data subject may file a formal complaint with the Superintendency of Industry and Commerce (SIC).
8. Transfer and transmission of data to third parties
HOUSINN.CO S.A.S. may transfer or transmit personal data to third parties in the following cases:
- Data processors: suppliers that provide services on behalf of HOUSINN.CO S.A.S. and are contractually bound to guarantee the confidentiality and security of the data. As at the date of this policy there are two: Stays.net, the property management system that holds the catalogue, availability and bookings and where payment is completed; and Vercel Inc., which hosts the portal and provides the aggregate analytics described in section 3.5.
- Public authorities: where required by law, court order or administrative request (Migración Colombia, DIAN, National Police, ICBF, etc.).
- Authorised distribution channels: online travel agencies (OTAs) with which HOUSINN.CO S.A.S. has agreements, under confidentiality and data protection arrangements.
Some of these processors operate from outside Colombia. International transmissions are made under the transmission contracts provided for in article 25 of Law 1581 of 2012 and in Decree 1377 of 2013.
HOUSINN.CO S.A.S. will NOT sell or trade data subjects' personal data to third parties for advertising purposes without their express authorisation.
9. Security measures
HOUSINN.CO S.A.S. will implement the technical, human and administrative measures needed to guarantee the security of personal data and prevent its alteration, loss, unauthorised or fraudulent access, consultation or use, in accordance with article 17 of Law 1581 of 2012.
These measures include, among others: encryption of data in transit and at rest, role-based access control, audit logging, confidentiality agreements with staff and suppliers, and data retention and secure deletion policies.
10. Database validity and retention
HOUSINN.CO S.A.S. will retain personal data for as long as necessary to fulfil the purposes of processing and the applicable legal obligations, on the following criteria:
- Booking and stay data: up to five (5) years after the last booking, in line with tax and commercial obligations.
- Invoicing data: up to ten (10) years, under article 28 of the Colombian Commercial Code.
- Enquiries received through the contact form: for as long as needed to handle them and to evidence the reply.
- Data required by authorities (Accommodation Registration Card — TRA): for the periods set by applicable tourism regulations.
This portal offers no user registration or personal accounts, so it holds no access credentials of any kind. The list of saved apartments and the selected currency are stored only in the visitor’s own browser and are never sent to the server; clearing browser data removes them entirely, with no request needed.
PARAGRAPH: Once retention periods expire, data will be securely deleted or anonymised where possible.
11. Cookies and similar technologies
This portal sets no advertising or cross-site tracking cookies, and shares no browsing data with advertising networks.
Browser local storage is used to remember two visitor preferences — the currency prices are shown in, and the list of saved apartments. That information never travels to the server and disappears when browser data is cleared.
The usage metrics described in section 3.5 are collected without cookies. Visitors may also block them with any tracker-blocking extension, without affecting how the portal works or their ability to book.
12. Changes to this policy
HOUSINN.CO S.A.S. reserves the right to amend this Policy at any time to reflect legislative or case-law changes or new company practices. Amendments will be published on the portal at least ten (10) calendar days before they take effect, unless the change is required by law, in which case it takes effect immediately.
13. Contact and official channel
To exercise any right over personal data, or for questions or claims relating to this Policy, please contact:
- Official channel
- info@housinn.co
- Email subject
- DATOS PERSONALES — [Data Subject Name] — [Type of Request]
- Service hours
- Monday to Friday, 8:00 a.m. — 6:00 p.m. (Colombia time)
- Supervisory authority
- Superintendency of Industry and Commerce (SIC) — www.sic.gov.co
Published in accordance with Law 1581 of 2012 and Decree 1377 of 2013. Last updated: 2026-07-29. The Spanish version prevails.