New York view

LEGAL DISCLAIMERS

Hoyos & Associates P.C. (“Hoyos & Associates” or “H&A”) is a law firm structured as a New York State Professional Corporation that operates through several professional firms and constituent entities (the “Related Firms”) located worldwide to provide legal and other client-related professional services. The Related Firms are constituted and regulated under relevant local regulatory and legal requirements. Hoyos & Associates is for description purposes only and does not imply that the Related Firms are in a partnership. The responsibility for providing services to the client is defined in writing, whether in a digital or physical format, which outlines terms of engagement between the Related Firm and the client.

In accordance with the customary terminology used in professional services organizations, references to "partner" or "shareholder," as is common, means a person who is a partner, shareholder, or equivalent in a Related Firm, and reference to a “location” means the location of the office of any such Related Firm.

The Hoyos & Associates Web Site(s) and the Information Feed (As defined in the End-User Agreement, which requires prior consent) on the Web App, as well as any Web Site operated for or on behalf of H&A or any Related Firm, are intended for information purposes only. Nothing on the H&A Web Sites is to be considered as creating an attorney-client relationship, any contractual relationship, or rendering legal or professional advice for any specific matter. Readers are responsible for obtaining such advice from their own legal counsel. No client or reader should act or refrain from acting based on any H&A Web Site(s) content without first obtaining matter-specific legal and/or professional advice. H&A and any Related Firm accept no responsibility for any loss or damage, howsoever incurred, which may result from accessing or reliance on content on the H&A Web Site(s) and disclaim, to the fullest extent permitted by applicable law, any or all liability concerning acts or omissions made by clients or readers based on content on the H&A Web Site(s).

If you have any questions about the content on the H&A Web Site, please contact:

Mateo Hoyos, Chief Executive Officer, at mateo@hoyos.law.

The H&A Web Site(s) or Web App may contain links to external Web Sites, and external Web Sites may link to the H&A Web Site(s) or Web App. H&A and the Related Firms are not responsible for the content or operation of any such external sites and disclaims all liability, howsoever occurring, regarding the content or operation of any such external Web Sites.

Some of the H&A Web Site(s) and the Web App content may constitute attorney advertising within the meaning of the applicable bar rules. As applicable, the following statement is made in accordance with those rules:

ATTORNEY ADVERTISING. PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME.

Anti-corruption and anti-bribery

H&A must comply with various anti-corruption and anti-bribery laws across many jurisdictions, including, but without limitation, the US Foreign Corrupt Practices Act. The Firm, its lawyers, employees, clients, and suppliers have various obligations under these laws. We comply with these obligations and advise our clients on how to comply. As a Firm, we have robust policies, training, and procedures to ensure compliance with anti-corruption and anti-bribery laws globally, where applicable.

E-mail Communications

NOTICE: If you have received an e-mail from H&A, the e-mail message and all attachments transmitted with it are intended solely for the use of the addressee and may contain legally privileged and confidential information. If the reader of the message is not the intended recipient or an employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, copying, or other use of the message or its attachments is strictly prohibited. If you have received a message in error, please notify the sender immediately by replying to the message and delete it from your computer.

PLEASE NOTE that we and an external service provider will automatically scan all incoming emails to eliminate unsolicited promotional emails (“spam”). This could result in the deletion of a legitimate email before its intended recipient at our firm reads it. Please let us know if you have concerns about this automatic filtering.

Information About Fraudulent Emails and Phone Calls Referencing H&A

H&A is a law firm that operates directly in three (3) jurisdictions and indirectly in various locations, employing lawyers and support staff in these jurisdictions. Our Firm may sometimes attract the attention of unscrupulous individuals who falsely claim to work for H&A and/or use our Firm’s name to advance fraudulent schemes against innocent people.

These sorts of scams and other security risks are rampant on the Internet, and we recommend you take steps to protect yourself and the security of your information. While we routinely report such abuses to law enforcement agencies, the nature, and volume of these scams and frauds make it impossible for our Firm to prevent the misuse of H&A's name and the names of our lawyers.

Among the various recent misrepresentations referencing H&A are:

  1. individuals falsely claiming to be from H&A and making offers of employment or soliciting personal information or job application fees via email (often purporting to conduct “interviews” online via virtual meeting platforms with no in-person or even telephonic interviews) or supposedly on behalf of a company using H&A as a legal reference or point of contact for such purposes; individuals falsely claiming to be from H&A or sending fake invoices seeking payment, including wire transfer instructions;
  2. individuals falsely claiming to be H&A lawyers handling consumer debt collection cases and threatening wage garnishment or arrest if funds are not provided immediately;
  3. individuals falsely claiming to be H&A lawyers requesting to facilitate payment of money urgently for the benefit of a family member who has been in an automobile accident or other emergency;
  4. individuals falsely claiming to be from H&A and forwarding supposed court notices that require an immediate response.

PLEASE NOTE THIS IS NOT AN EXHAUSTIVE LIST OF SCAMS; NEW ONES ARE BEING DEVISED BY CRIMINALS ALL THE TIME.

What should you do? To report a potential e-mail, telephone, or other scam, we recommend you contact the relevant police or government authorities in your jurisdiction. For example, you can file reports in the US with the following government authorities:

If you receive an email or threatening telephone call from someone claiming to be from H&A and offering employment or seeking payment of money or personal information, we suggest:

  • Communicate with such person using only the contact information provided on our Web Site or Web App, www.hoyos.law. Do not communicate via other email addresses, telephone numbers, or text messaging. For example, if the sender is using a non-H&A email address and/or justifies this on the basis that an H&A account is not working, you should insist on contacting the sender only via the contact information on our Web Site.
  • Attempt to independently verify, including by telephone, the legitimacy of the caller’s identity, for example, by contacting the Firm’s General Counsel.
  • Do not send any money to the email sender or caller.
  • Do not provide the email sender or caller with personal or financial information about yourself, such as your bank accounts or credit card numbers.
  • Report the fraudulent email or call to the police or other relevant authorities.

In addition, if you receive a suspicious email referencing our Firm or appearing to be from our Firm (e.g., from a "spoofed" H&A email address, which does not end in “@hoyos.law” ), we suggest the following:

  • Do not open or click on any links contained in the email.
  • Do not open or download any attachments to the email.
  • Do not respond to the email in any way or provide any personal or confidential information in reply to the email.
  • Do not send any money in response to the email.
  • If applicable, forward the suspicious email to your organization’s IT Department and ask that they inspect the message to determine legitimacy.
  • Delete (permanently) the message from your email account.

If you have questions about your computer’s security or suspect it has been compromised, we recommend you contact your information technology support team, computer manufacturer, or Internet service provider.

H&A is not involved in the scams listed above or any other scams. Note that we do not conduct Firm business via web-based email accounts such as gmail.com, hotmail.com, yahoo.com, or personal email addresses. We generally do not conduct firm business through text messages or instant messaging. Neither H&A nor its lawyers or employees can accept any responsibility for the criminal conduct of a third party claiming to use the Firm's name. If you have any concerns or receive suspicious communications referencing H&A, please contact our General Counsel at the telephone number or email address shown on this web page.

Notice of Copyright and Reproduction

Copyright 2024 H&A. All rights reserved.

The content of the H&A Web Sites is protected, the reproduction of reasonable portions of the content of the Web Sites is permitted provided that (i) such reproductions are made available free of charge and for non-commercial purposes, (ii) such reproductions are appropriately attributed to H&A, (iii) the portion of the Web Site being reproduced is not altered or made available in a manner that modifies the content of the web site or presents the portion of the web site being reproduced in a false light and (iv) notice is made to the disclaimers included on the Web Site. The permission to re-copy does not allow for incorporation of any substantial portion of the Web Sites in any work or publication, whether in hard copy, electronic, or any other form or for commercial purposes.

1. LEGAL NOTICES

1.1 The Firm and the Related Firms

Hoyos & Associates P.C. (“Hoyos & Associates” or “H&A”) is a law firm structured as a Professional Corporation organized under the laws of the State of New York that operates through several professional firms and constituent entities (the “Related Firms”) located in various jurisdictions to provide legal and other client-related professional services. The Related Firms are constituted and regulated under the local regulatory and legal requirements applicable to them. The name “Hoyos & Associates” is used for descriptive purposes only and does not imply that the Related Firms are in a partnership with one another. Responsibility for providing services to the client is defined in writing, whether in digital or physical format, through the terms of engagement agreed between the relevant Related Firm and the client.

In accordance with the customary terminology used in professional services organizations, references to a “partner” or “shareholder” mean a person who is a partner, shareholder, or equivalent in a Related Firm, and references to a “location” or “office” mean the office of any such Related Firm.

1.2 No Attorney-Client Relationship

The Hoyos & Associates Web Site(s) and the Information Feed on the Web App (as defined in the End-User Agreement, which requires prior consent), as well as any Web Site operated by or on behalf of H&A or any Related Firm, are intended for information purposes only. Nothing on the H&A Web Sites is to be considered as creating an attorney-client relationship or any contractual relationship, or as rendering legal or professional advice for any specific matter. Readers are responsible for obtaining such advice from their own legal counsel. No client or reader should act, or refrain from acting, on the basis of any content on the H&A Web Site(s) without first obtaining matter-specific legal and/or professional advice. H&A and the Related Firms accept no responsibility for any loss or damage, howsoever incurred, that may result from accessing or relying on content on the H&A Web Site(s), and disclaim, to the fullest extent permitted by applicable law, any and all liability with respect to acts or omissions made by clients or readers on the basis of such content.

If you have any questions about the content on the H&A Web Site, please contact: Mateo Hoyos, Chief Executive Officer, at mateo@hoyos.law.

The H&A Web Site(s) or Web App may contain links to external Web Sites, and external Web Sites may link to the H&A Web Site(s) or Web App. H&A and the Related Firms are not responsible for the content or operation of any such external sites and disclaim all liability, howsoever occurring, regarding the content or operation of any such external Web Sites.

1.3 Attorney Advertising

Some of the content on the H&A Web Site(s) and the Web App may constitute attorney advertising within the meaning of the applicable bar rules, including the New York Rules of Professional Conduct (22 NYCRR Part 1200, Rule 7.1). As applicable, the following statement is made in accordance with those rules:

ATTORNEY ADVERTISING.

PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME.

1.4 Anti-Corruption and Anti-Bribery

H&A must comply with various anti-corruption and anti-bribery laws across many jurisdictions, including, without limitation, the U.S. Foreign Corrupt Practices Act and, in Colombia, the regime of administrative liability of legal entities for transnational bribery under Law 1778 of 2016, as well as other applicable criminal and administrative provisions. The Firm, its lawyers, employees, clients, and suppliers have various obligations under these laws. We comply with these obligations and advise our clients on how to comply. As a Firm, we maintain robust policies, training, and procedures to ensure compliance with anti-corruption and anti-bribery laws globally, where applicable.

1.5 E-mail Communications

NOTICE: If you have received an e-mail from H&A, the e-mail message and all attachments transmitted with it are intended solely for the use of the addressee and may contain legally privileged and confidential information. If the reader of the message is not the intended recipient, or an employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, copying, or other use of the message or its attachments is strictly prohibited. If you have received a message in error, please notify the sender immediately by replying to the message, and delete it from your computer.

PLEASE NOTE that we and an external service provider automatically scan all incoming e-mails to eliminate unsolicited promotional e-mails (“spam”). This could result in the deletion of a legitimate e-mail before its intended recipient at our Firm reads it. Please let us know if you have any concerns about this automatic filtering.

1.6 Information About Fraudulent E-mails and Phone Calls Referencing H&A

H&A is a law firm that operates directly in three (3) jurisdictions and indirectly in various locations, employing lawyers and support staff in those jurisdictions. Our Firm may sometimes attract the attention of unscrupulous individuals who falsely claim to work for H&A and/or use our Firm’s name to advance fraudulent schemes against innocent people.

These sorts of scams and other security risks are rampant on the Internet, and we recommend that you take steps to protect yourself and the security of your information. While we routinely report such abuses to law enforcement agencies, the nature and volume of these scams and frauds make it impossible for our Firm to prevent the misuse of H&A’s name and the names of our lawyers.

Among the various recent misrepresentations referencing H&A are:

  1. Individuals falsely claiming to be from H&A and making offers of employment or soliciting personal information or job application fees via e-mail (often purporting to conduct “interviews” online via virtual meeting platforms, with no in-person or even telephonic interviews), or supposedly acting on behalf of a company using H&A as a legal reference or point of contact for such purposes; as well as individuals falsely claiming to be from H&A or sending fake invoices seeking payment, including wire transfer instructions;
  2. Individuals falsely claiming to be H&A lawyers handling consumer debt collection cases and threatening wage garnishment or arrest if funds are not provided immediately;
  3. Individuals falsely claiming to be H&A lawyers requesting the urgent facilitation of payments for the benefit of a family member who has purportedly been in an automobile accident or other emergency;
  4. Individuals falsely claiming to be from H&A and forwarding supposed court notices that require an immediate response.

PLEASE NOTE THAT THIS IS NOT AN EXHAUSTIVE LIST OF SCAMS; NEW ONES ARE BEING DEVISED BY CRIMINALS ALL THE TIME.

What should you do? To report a potential e-mail, telephone, or other scam, we recommend that you contact the relevant police or government authorities in your jurisdiction. For example, in the United States you can file reports with the Federal Bureau of Investigation, through the Internet Crime Complaint Center (www.ic3.gov), and with the Federal Trade Commission (reportfraud.ftc.gov). In Colombia, you may file criminal complaints with the Fiscalía General de la Nación and through the National Police’s CAI Virtual.

If you receive an e-mail or a threatening telephone call from someone claiming to be from H&A and offering employment or seeking payment of money or personal information, we suggest that you:

  • Communicate with such person using only the contact information provided on our Web Site or Web App, www.hoyos.law. Do not communicate via other e-mail addresses, telephone numbers, or text messaging. For example, if the sender is using a non-H&A e-mail address and/or justifies this on the basis that an H&A account is not working, you should insist on contacting the sender only via the contact information on our Web Site.
  • Attempt to independently verify, including by telephone, the legitimacy of the caller’s identity, for example by contacting the Firm’s General Counsel.
  • Do not send any money to the e-mail sender or caller.
  • Do not provide the e-mail sender or caller with personal or financial information about yourself, such as your bank account or credit card numbers.
  • Report the fraudulent e-mail or call to the police or other relevant authorities.

In addition, if you receive a suspicious e-mail referencing our Firm or appearing to be from our Firm (e.g., from a “spoofed” H&A e-mail address that does not end in “@hoyos.law”), we suggest the following:

  • Do not open or click on any links contained in the e-mail.
  • Do not open or download any attachments to the e-mail.
  • Do not respond to the e-mail in any way or provide any personal or confidential information in reply.
  • Do not send any money in response to the e-mail.
  • If applicable, forward the suspicious e-mail to your organization’s IT department and ask that they inspect the message to determine its legitimacy.
  • Delete (permanently) the message from your e-mail account.

If you have questions about your computer’s security or suspect it has been compromised, we recommend that you contact your information technology support team, computer manufacturer, or Internet service provider.

H&A is not involved in the scams listed above or any other scams. Note that we do not conduct Firm business via web-based e-mail accounts such as gmail.com, hotmail.com, or yahoo.com, or via personal e-mail addresses. We generally do not conduct Firm business through text messages or instant messaging. Neither H&A nor its lawyers or employees can accept any responsibility for the criminal conduct of a third party claiming to use the Firm’s name. If you have any concerns or receive suspicious communications referencing H&A, please contact our General Counsel at the telephone number or e-mail address shown in the Contact section of this document.

1.7 Notice of Copyright and Reproduction

Copyright © 2024–2026 H&A. All rights reserved.

The content of the H&A Web Sites is protected. The reproduction of reasonable portions of the content of the Web Sites is permitted provided that: (i) such reproductions are made available free of charge and for non-commercial purposes; (ii) such reproductions are appropriately attributed to H&A; (iii) the portion of the Web Site being reproduced is not altered or made available in a manner that modifies the content of the Web Site or presents it in a false light; and (iv) notice is made of the disclaimers included on the Web Site. This permission to re-copy does not allow for the incorporation of any substantial portion of the Web Sites in any work or publication, whether in hard copy, electronic, or any other form, or for commercial purposes.

2. WHO WE ARE AND SCOPE OF THIS STATEMENT

2.1 Nature of This Document

This document integrates into a single body: (i) the Privacy Statement applicable to the Firm’s websites, applications, and other communication platforms; and (ii) the Personal Data Processing Policy (Política de Tratamiento de Datos Personales) required by Colombian Statutory Law 1581 of 2012 and Article 2.2.2.25.3.1 of Decree 1074 of 2015, applicable to the processing of Personal Data carried out in Colombia or concerning data subjects (Titulares) located in Colombia. The sections of this document apply jointly; where a rule is specific to one jurisdiction, this is expressly indicated. In the event of any discrepancy concerning data subject to Colombian law, the provisions implementing the Colombian regime shall prevail; in the event of any discrepancy concerning data subject to U.S. law, the provisions implementing the U.S. regime shall prevail. In case of doubt, we will apply the more protective standard.

2.2 Data Controllers

This Privacy Statement describes how Hoyos & Associates P.C. and other Related Firms (defined on the Legal Disclaimers page available at www.hoyos.law/legaldisclaimers) and affiliates of H&A collect, use, share, and otherwise process Personal Data (as defined below). The controller of your Personal Data is the H&A entity with which you engage (in each case, the “Firm”). For processing subject to Colombian law, the data controller (Responsable del Tratamiento) is:

  • Hoyos & Associates S.A.S., a simplified stock company (sociedad por acciones simplificada) organized under the laws of Colombia, Tax ID (NIT) 901.003.912-4, domiciled at Carrera 6ª No.48ª-10, Piso 1, Bogotá D.C., Colombia; e-mail: mateo@hoyos.law; telephone: +57 312 888 4092   and +57 304 376 1740

For processing subject to U.S. law, the controller is:

  • Hoyos & Associates P.C., a Professional Corporation organized under the laws of the State of New York, with offices at 15 MetroTech Center, 7th Floor, Brooklyn, New York 11201, United States of America; e-mail: mateo@hoyos.law.

Either entity may act as controller (Responsable) or processor (Encargado) with respect to specific processing operations, depending on the relationship at issue, as described in this document.

2.3 Individuals Covered

The Firm processes Personal Data about:

  • Visitors to our websites, web applications, mobile applications, and other communication platforms (each, a “Site”).
  • Contact persons for our clients and/or prospective clients.
  • Contact persons for suppliers of goods and services to the Firm.
  • Any other individuals about whom the Firm obtains Personal Data.

If you provide us with Personal Data relating to other persons (such as family members, work colleagues, or employees), you are responsible for ensuring that the relevant individuals are made aware of the terms of this Privacy Statement, that you are legally entitled or authorized to provide us with their Personal Data, and that such Personal Data is accurate and up to date.

Unless we expressly state otherwise, the Firm is the controller of the Personal Data we process and is therefore responsible for ensuring that the systems and methods we use comply with the data protection laws applicable to us. Firm personnel are required to comply with this Privacy Statement and associated internal policies when dealing with Personal Data, and must complete data protection training appropriate to their role.

3. DEFINITIONS

For purposes of this document, and consistently with Article 3 of Law 1581 of 2012 and Article 2.2.2.25.1.3 of Decree 1074 of 2015, the following definitions apply:

  • Personal Data: any information linked to, or that can be associated with, an identified or identifiable natural person; that is, information that (either in isolation or in combination with other information held by the Firm) enables you to be identified or recognized, directly or indirectly, as an individual.
  • Data Subject (Titular): the natural person whose Personal Data is processed.
  • Processing (Tratamiento): any operation or set of operations performed on Personal Data, such as collection, storage, use, circulation, or deletion.
  • Controller (Responsable del Tratamiento): the person who, alone or jointly with others, decides on the database and/or the processing of the data.
  • Processor (Encargado del Tratamiento): the person who processes Personal Data on behalf of the controller.
  • Sensitive Data: data affecting the data subject’s privacy or whose misuse may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions or social or human rights organizations, as well as data concerning health, sex life, and biometric data (Article 5, Law 1581 of 2012). Other regimes refer to these as “special categories of data.”
  • Transfer (Transferencia): the sending of Personal Data to a recipient that is itself a controller, located within or outside the country.
  • Transmission (Transmisión): the communication of Personal Data, within or outside Colombia, for a processor to carry out processing on behalf of the controller.
  • Privacy Notice (Aviso de Privacidad): the verbal or written communication addressed to the data subject informing them of the existence of the applicable processing policies, how to access them, and the purposes of the processing.

4. PERSONAL DATA WE COLLECT

We collect the following categories of Personal Data about Site visitors, clients, prospective clients, suppliers, and other third parties:

  • Primary data: name, gender, title, organization, job responsibilities, phone number, mailing address, e-mail address, contact details, and information about family life (excluding Sensitive Data), including family, children, hobbies, and interests.
  • Sensitive Data (special categories of data): in limited circumstances, where you have provided us with such information because it is necessary for a specific service we are providing to you: religious or other beliefs, racial or ethnic origin, sexual orientation, health data, and details of trade union membership.
  • Registration data: newsletter requests, event/seminar registrations, dietary preferences (excluding Sensitive Data), subscriptions, downloads, and usernames/passwords.
  • Client service data: Personal Data received from clients regarding their employees, customers, or other individuals known to them, invoicing details and payment history, and client feedback.
  • Marketing data: individual participation in conferences and in-person seminars, credentials, associations, service interests, and preferences.
  • Transaction data: Personal Data contained in documents, correspondence, or other materials provided in connection with, or relating to, transactions, proceedings, or other legal matters on which we advise our clients.
  • Interaction data: Personal Data such as contact data, e-mail metadata, and other technical data relating to your interactions with us.
  • Compliance data: government identifiers, passports or other identification documents, dates of birth, beneficial ownership information, and due diligence data.
  • Job applicant data: data provided by job applicants or others, on our Sites or through offline means, in connection with employment opportunities, which may also be subject to an additional local recruitment privacy policy.
  • Device data: computer Internet Protocol (IP) address, unique device identifier (UDID), cookies and other data linked to a device, and data about the usage of our Sites (Usage Data).

5. SOURCES OF THE DATA

We collect Personal Data from several sources: directly from data subjects, from our clients, from colleagues, and from publicly available sources. Where the Firm receives data about employees, customers, or other individuals from its clients, the client is responsible for ensuring that any such data is transferred or transmitted to us in compliance with applicable data protection laws, including obtaining any required authorizations.

6. PURPOSES OF PROCESSING AND LEGAL BASES

6.1 General Framework by Jurisdiction

For data subjects covered by Colombian law, processing is based on the data subject’s prior, express, and informed authorization (Article 9, Law 1581 of 2012), obtained through any means that can be subject to subsequent consultation, or on the statutory exceptions of Article 10 of that law (including information required by a public authority in the exercise of its legal functions or by court order, and data of a public nature). For individuals covered by the European Union General Data Protection Regulation (“GDPR”), processing relies on the legal bases of Article 6 GDPR (performance of a contract, compliance with legal obligations, legitimate interests, or consent). For individuals in the United States, processing is carried out in accordance with notice-and-choice principles and the duties established by applicable federal and state laws. Where this section invokes “legitimate interests,” that basis operates under the GDPR or other regimes that recognize it; for data subjects covered by Colombian law, the corresponding processing rests on the authorization granted or on the statutory exceptions.

6.2 Purposes

The purposes for which we use Personal Data, and the bases supporting each processing activity, are as follows:

  • To provide legal advice and respond to inquiries. We use primary, registration, client service, and device data. We need to process your information in this way in order to perform our obligations under our client contracts.
  • To manage our business operations and administer our relationships with clients and suppliers. We use primary data, Sensitive Data, registration data, marketing data, and client service data. This processing is necessary to perform our obligations under our contracts with clients (e.g., issuing and processing invoices) and suppliers (e.g., managing the supply of goods and services to the Firm).
  • To make our Sites more intuitive and easy to use. We use device data. It is in our legitimate interests to monitor how our Sites are used in order to improve their layout and the information available, and to provide a better service to our Site users.
  • To protect the security and effective functioning of our Sites and information technology systems. We use primary, registration, transaction, and device data. It is in our legitimate interests to monitor how our Sites are used in order to detect and prevent fraud, other crimes, and misuse. This helps us ensure that you can safely use our Sites.
  • To expand and maintain our contacts list and strengthen our relationships. We use primary, interaction, and device data to better understand how people use our services and to improve our relationships with clients and other third parties. It is in our legitimate interests to keep your information accurate and up to date in order to improve the client experience and our relationship with you.
  • To provide relevant marketing. To inform you about events or services that may be of interest to you - including legal services, legal updates, client conferences, networking events, and groups of specific interest - we use marketing, primary, Sensitive, registration, client service, and device data. It is in our legitimate interests to process this information in order to provide you with tailored and relevant marketing updates and invitations; where applicable law requires your prior consent or authorization, we will obtain it.
  • To address compliance and legal obligations. To comply with the Firm’s tax and reporting obligations, verify the identity of new clients, and prevent money laundering, terrorist financing, and fraud, we use compliance, primary, registration, transaction, and device data. This processing is necessary to comply with legal requirements to which we are subject.
  • To evaluate candidates and manage onboarding. We use job applicant data and compliance data to consider individuals for employment and contractor opportunities and to manage onboarding procedures. This processing is necessary for recruitment and onboarding and to comply with legal obligations to which we are subject, and may also be subject to a relevant local recruitment privacy policy.
  • To exercise and defend the Firm’s rights. We may process the categories of data described above where necessary for the recognition, exercise, or defense of a right in judicial or administrative proceedings, or to protect our rights, property, or safety, or those of others.

7. USE OF GENERATIVE ARTIFICIAL INTELLIGENCE (genAI)

The Firm may use generative artificial intelligence (“genAI”) technology to support the processing of Personal Data for the purposes described in this Privacy Statement. All genAI technology we use is subject to robust prior screening to ensure that it meets applicable ethical, legal, and contractual requirements, including data privacy and information security. The Firm has adopted appropriate business practices and training for attorneys and business professionals governing the responsible use of genAI technology, so that Personal Data remains adequately protected and subject, in all cases, to professional secrecy where applicable.

8. SHARING OF PERSONAL DATA

We may share Personal Data with the following categories of recipients:

  • Affiliates and Related Firms: Hoyos & Associates S.A.S., our Colombian Related Firm, operates as a member firm of the network led by Hoyos & Associates P.C., a Professional Corporation organized under the laws of the State of New York, with member firms and affiliates in various jurisdictions. Each member firm may share Personal Data with other member firms and affiliates in order to provide you with legal services and administer our relationship with you (e.g., invoicing and marketing), or otherwise as necessary for the purposes described in Section 6.
  • Suppliers and service providers: we share Personal Data with suppliers and service providers to enable them to perform functions on our behalf and under our instructions, in furtherance of the purposes described above. These include infrastructure and IT service providers (for example, the providers of our client intake system, our finance systems, and our customer relationship management databases); third-party consultants who support us with business analytics and marketing campaigns; and the providers of external venues where we host conferences and events. We contractually require such parties to provide reasonable security for Personal Data and to use and process it on our behalf only. Where a provider processes data subject to Colombian law on the Firm’s behalf, the operation constitutes a transmission and is implemented through a transmission agreement containing the safeguards of Article 2.2.2.25.5.2 of Decree 1074 of 2015.
  • Financial institutions: we share Personal Data concerning invoices and payments with financial institutions.
  • Corporate purchasers: we may share Personal Data with any actual or prospective corporate purchaser, to the extent permitted by law, as part of any merger, acquisition, sale of Firm assets, or transition of services to another provider, as well as in the event of insolvency, bankruptcy, or receivership in which Personal Data would be transferred as an asset of the Firm.
  • Mandatory disclosures and legal claims: we share Personal Data to comply with the Firm’s tax and reporting obligations; to comply with any subpoena, court order, or other legal process; and to respond to requests from our regulators, governmental requests, or any other legally enforceable demand. We also share Personal Data to establish or protect our legal rights, property, or safety, or the rights, property, or safety of others, and to defend against legal claims.

We do not sell Personal Data for monetary consideration. To the extent that the use of advertising cookies could be deemed a “sale” or “sharing” of data under certain U.S. state laws, you may opt out of such use through the cookie consent management tool described in Section 10. If you have questions about the parties with which we share Personal Data, please contact us as specified in Section 20.

9. MARKETING CHOICES

You have control over our use of your Personal Data for direct marketing. In markets where the law so requires, we will obtain your express consent or authorization before sending you marketing communications. In all markets, you can choose to stop receiving such communications at any time and free of charge, by following the unsubscribe link included in the relevant communication or by contacting us as indicated in Section 20.

Our commercial e-mail communications comply with the U.S. CAN-SPAM Act (15 U.S.C. §§ 7701 et seq.): we do not use false or misleading header information or deceptive subject lines, we identify the sender, and we honor opt-out requests promptly. Where we conduct text message or telephone marketing directed at the United States, we will do so in accordance with the Telephone Consumer Protection Act (47 U.S.C. § 227). Commercial or advertising communications directed at consumers in Colombia will observe, where applicable, the channels authorized by the consumer and the time and frequency restrictions established by Law 2300 of 2023.

We do not authorize the automated harvesting of e-mail addresses published on our Sites for the purpose of sending unsolicited commercial communications.

10. COOKIES

We engage certain providers to use cookies, web beacons, and similar tracking technologies (collectively, “cookies”) on our Sites.

What are cookies? Cookies are small amounts of data stored on your browser, device, or viewing page. Some cookies are deleted once you close your browser, while others are retained even after you close your browser so that you can be recognized when you return to a website.

How do we use cookies? We use cookies, and allow certain third parties to place cookies on our Sites, to provide the Sites and services, gather information about your usage patterns when you navigate the Sites, enhance your personalized experience, and understand usage patterns in order to improve our Sites, products, and services.

Cookies on our Sites are generally divided into the following categories:

  • Necessary Cookies: these cookies are essential for the website to function and cannot be switched off in our systems. They are usually set only in response to actions made by you that amount to a request for services, such as setting your privacy preferences, logging in, or filling in forms. You can set your browser to block these cookies or alert you about them, but some parts of the site will not work. These cookies do not store any personally identifiable information.
  • Functional Cookies: these cookies enhance the website’s functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, some or all of these services may not function properly.
  • Performance Cookies: these cookies allow us to count visits and traffic sources so that we can measure and improve our site’s performance. They help us know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies, we will not know when you visited our site and will be unable to monitor its performance.
  • Targeting Cookies: these cookies may be set through our site by our advertising partners. These companies may use the information collected to build a profile of your interests and show you relevant advertisements on other sites. They do not store personal information directly, but rely on uniquely identifying your browser and Internet device. If you do not allow these cookies, you will experience less targeted advertising.
  • Social Media Cookies: these cookies are set by a range of social media services we have added to the site to enable you to share our content with your friends and networks. They can track your browser across other sites and build a profile of your interests, which may affect the content and messages you see on other websites you visit. If you do not allow these cookies, you may not be able to use or see these sharing tools.

What are your options if you do not want cookies on your computer? When you first visit our Sites, you will be asked for your consent to the use of any cookies that are not strictly necessary. You can manage your choices using the consent management tool provided. If you change your mind, you can adjust your preferences at any time using the “Manage cookies” link in the footer of our Sites.

11. DATA SUBJECT RIGHTS

11.1 Rights We Recognize for Everyone

Regardless of your location, and as the Firm’s minimum standard, we recognize that every person whose Personal Data we process has the right to know and access their data, to request its updating or rectification, to request its deletion where no legal, contractual, or professional duty requires its retention, and to object to direct marketing uses. The following subsections detail the rights and procedures specific to each regime; where more than one regime applies, we will apply the more protective one.

11.2 Data Subjects Covered by Colombian Law (Law 1581 of 2012)

Pursuant to Article 8 of Law 1581 of 2012, the data subject (Titular) has the right to:

  • Know, update, and rectify their Personal Data vis-à-vis the controller or the processor, particularly with respect to data that is partial, inaccurate, incomplete, fragmented, or misleading, or whose processing is expressly prohibited or has not been authorized.
  • Request proof of the authorization granted to the controller, except where expressly excepted under Article 10 of Law 1581 of 2012.
  • Be informed by the controller or the processor, upon request, of the use that has been made of their Personal Data.
  • File complaints with the Superintendence of Industry and Commerce (Superintendencia de Industria y Comercio, “SIC”) for violations of the data protection regime, once the consultation or claim procedure before the controller or processor has been exhausted (Article 16, Law 1581 of 2012).
  • Revoke the authorization and/or request the deletion of the data where no legal or contractual duty requires its retention and the constitutional and legal principles, rights, and guarantees are not respected.
  • Access their Personal Data that has been processed, free of charge.

Consultations (Article 14, Law 1581 of 2012). The data subject or their successors may consult the data subject’s information held in our databases through the channels indicated in Section 20, provided that proof of the consultation can be maintained. Consultations will be answered within a maximum of ten (10) business days from the date of receipt. Where it is not possible to respond within that term, we will inform the interested party of the reasons for the delay and the date on which the consultation will be answered, which in no case will exceed five (5) business days following the expiration of the first term.

Claims (Article 15, Law 1581 of 2012). Data subjects or their successors who consider that their information should be corrected, updated, or deleted, or who identify an alleged breach of any of the duties established by the law, may file a claim through the channels indicated in Section 20, including: (i) the identification of the data subject; (ii) a description of the facts giving rise to the claim; (iii) a contact address; and (iv) any supporting documents. If the claim is incomplete, we will require the interested party to cure the deficiencies within five (5) days following its receipt; if two (2) months elapse from the date of the request without the required information being submitted, the claim will be deemed withdrawn. Once the complete claim is received, a legend stating “claim in process” (reclamo en trámite) and its grounds will be added to the database within no more than two (2) business days and maintained until the claim is decided. The maximum term to decide the claim is fifteen (15) business days from the day following its receipt; where it is not possible to decide within that term, we will inform the interested party of the reasons for the delay and the date of decision, which in no case will exceed eight (8) business days following the expiration of the first term.

Revocation and deletion. The data subject may revoke their authorization or request the deletion of their data at any time and free of charge, unless a legal or contractual duty requires that the data remain in the database (for example, record-keeping duties inherent to the practice of law, tax obligations, or anti-money laundering requirements).

Data protection authority. The competent authority is the Superintendence of Industry and Commerce - Deputy Superintendence for Personal Data Protection (Delegatura para la Protección de Datos Personales, www.sic.gov.co). Complaints before the SIC are admissible once the consultation or claim procedure before the controller or processor has been exhausted.

11.3 Individuals in the European Economic Area (EEA) or the United Kingdom

If you are in the EEA or the United Kingdom, you have the following rights under the GDPR (or its UK equivalent):

  • Access. Subject to certain exceptions, you have the right to request a copy of the Personal Data we are processing about you, which we will provide to you in electronic form. We may require you to verify your identity before providing the requested information, and we may charge a reasonable administration fee if you request multiple copies of your Personal Data.
  • Rectification. You have the right to require that we amend any incomplete or inaccurate Personal Data that we process about you.
  • Erasure. You have the right to request that we delete Personal Data that we process about you, unless we are required to retain such data to comply with a legal obligation or to establish, exercise, or defend legal claims.
  • Restriction. You have the right to request that we restrict our processing of your Personal Data where you believe such data to be inaccurate, where our processing is unlawful, or where we no longer need to process such data for a particular purpose but cannot delete it due to a legal or other obligation, or because you do not want us to delete it.
  • Portability. You have the right to request that we transmit to another controller the Personal Data that you have provided to us, where we process that data on the basis of your consent or in order to perform our obligations under a contract with you (such as the provision of legal services).
  • Objection. Where our legal justification for processing your Personal Data is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate grounds for the processing that override your interests and rights, or unless we need to continue processing the data to establish, exercise, or defend a legal claim.
  • Withdrawing consent. If you have consented to our processing of your Personal Data, you have the right to withdraw your consent at any time, free of charge. This includes cases where you wish to opt out of marketing messages that you receive from us.

If you are in the EEA or the United Kingdom, you also have the right to complain to your local data protection authority if you believe that we have not complied with applicable data protection laws.

11.4 Residents of U.S. States

Various U.S. state privacy laws (such as those of California, Virginia, Colorado, Connecticut, and Texas) grant rights of access, correction, deletion, portability, and opt-out from targeted advertising, subject to applicability thresholds and exceptions  - including those for information protected by the attorney-client privilege and attorney work product. To the extent that any such law applies to the Firm, we will honor the rights it confers; in any event, we voluntarily extend to all individuals the rights described in Section 11.1. We do not discriminate against any person for exercising their privacy rights. You can manage cookie-based advertising through the consent tool described in Section 10.

11.5 Identity Verification and Channels

We may request reasonable information to verify your identity (or your capacity as successor or representative, where applicable) before acting on a request. Requests are submitted through the channels indicated in Section 20. The contact information of the area responsible for handling petitions, consultations, and claims is set out in that same section.

12. SENSITIVE DATA AND CHILDREN’S DATA

The provision of Sensitive Data is optional: the data subject is not obliged to authorize its processing, and no activity will be conditioned on its provision, unless there is a legal or professional reason requiring it (Articles 5 and 6, Law 1581 of 2012). Where we process Sensitive Data subject to Colombian law, we will obtain the data subject’s explicit authorization, except in the cases excepted by law (for example, where processing is necessary for the recognition, exercise, or defense of a right in judicial proceedings).

The processing of data concerning children and adolescents will be carried out only where legally permissible, respecting their prevailing rights and best interests (Article 7, Law 1581 of 2012). Our Sites and services are not directed to children under thirteen (13) years of age, and we do not knowingly collect Personal Data online from children under that age; if you are a parent or legal guardian and believe that a child has provided us with Personal Data, please contact us as indicated in Section 20 so that we can delete it, in accordance with the U.S. Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501 et seq., and 16 C.F.R. Part 312) and applicable Colombian rules.

13. AUTHORIZATION, PROOF, AND PRIVACY NOTICE

Except as otherwise permitted by law, for processing subject to Colombian law the Firm obtains the data subject’s prior, express, and informed authorization, through any means that can be subject to subsequent consultation (Article 9, Law 1581 of 2012), and retains proof of it in accordance with Decree 1074 of 2015. The data subject may revoke their authorization as described in Section 11.2. The Firm may inform data subjects of the applicable processing policies and the purposes of processing through Privacy Notices (Avisos de Privacidad), which will indicate how to access this document.

14. DATA SECURITY

We have implemented reasonable technical, human, and administrative measures to safeguard the Personal Data in our custody and control, consistent with the security principle of Article 4(g) of Law 1581 of 2012 and the reasonable safeguards standard of the New York SHIELD Act (N.Y. General Business Law § 899-bb). Such measures include, among others and as appropriate to the nature of the data, as detailed below:

  • Administrative safeguards: designating personnel responsible for coordinating the security program; periodically identifying and assessing reasonably foreseeable internal and external risks; annual training of personnel in information security and data protection; selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract; and adjusting the security program in light of business changes or new circumstances.
  • Technical safeguards: restricting access to Personal Data to staff and service providers on a need-to-know basis; authentication and credential management, including the use of password managers and periodic rotation; information encryption tools; backup copies; and monitoring, detecting, preventing, and responding to attacks, intrusions, or system failures, with periodic testing of the effectiveness of key controls.
  • Physical safeguards: controlling access to equipment, networks, and facilities; protecting information during its collection, transportation, storage, and final disposal; and securely disposing of media containing Personal Data within a reasonable time after it is no longer needed, so that the information cannot be read or reconstructed.

While we endeavor to protect our systems, Sites, operations, and information against unauthorized access, use, modification, and disclosure at all times, due to the inherent nature of the Internet as an open global communications vehicle and other risk factors, we cannot guarantee that any information, during transmission or while stored on our systems, will be entirely safe from intrusion by others.

You also have an essential role in protecting Personal Data. Do not share any username, password, or other authentication data provided to you with anyone, and we recommend that you not reuse passwords across more than one website or application. If you have any reason to believe that your username or password has been compromised, please contact us as indicated in Section 20.

15. SECURITY INCIDENT NOTIFICATION

If a violation of security codes or measures occurs, or risks arise in the management of the information of data subjects covered by Colombian law, we will inform the Superintendence of Industry and Commerce in accordance with Articles 17(n) and 18(k) of Law 1581 of 2012, and the data subject where appropriate. With respect to New York State residents, we will notify security breaches involving private information in accordance with N.Y. General Business Law § 899-aa, including the required notifications to the competent state authorities. We will also comply with any other incident notification laws applicable based on the residence of the affected individuals.

16. CROSS-BORDER TRANSFERS AND TRANSMISSIONS OF DATA

We transfer Personal Data to other jurisdictions as necessary for the purposes described in Section 6, including to jurisdictions that may provide a different level of data protection than your home country. In particular, our Sites are hosted on servers located in the United States; if you are in a non-U.S. jurisdiction, the transfer of your Personal Data is necessary to provide you with the requested information and to perform any requested transaction, and when you submit personal information to us, you transfer your data across borders.

From Colombia. International transfers of Personal Data of data subjects covered by Colombian law are carried out in accordance with Article 26 of Law 1581 of 2012 and the SIC’s instructions contained in Title V of its Circular Única. The United States of America is included in the list of countries offering an adequate level of personal data protection established by the SIC (External Circular 005 of 2017, incorporated into Title V of the Circular Única, as amended). In addition, where required, we will obtain the data subject’s express and unequivocal authorization for the transfer, or rely on the other exceptions of Article 26 (including transfers necessary for the performance of a contract between the data subject and the controller, and transfers legally required for the recognition, exercise, or defense of a right in judicial proceedings). Transmissions to processors outside Colombia are implemented through transmission agreements in accordance with Article 2.2.2.25.5.2 of Decree 1074 of 2015. If the recipient country does not offer an adequate level of protection, we will adopt the appropriate safeguards or request a declaration of conformity from the SIC’s Deputy Superintendence for Personal Data Protection.

From the EEA and Switzerland. Concerning transfers originating from the European Economic Area and Switzerland (together, the “EEA”) to the United States and other non-EEA jurisdictions, we implement standard contractual clauses approved by the European Commission and other appropriate solutions to address cross-border transfers, as required or permitted by Articles 46 and 49 of the GDPR or other applicable laws. Where required by such laws, you may request a copy of the mechanisms we have in place by contacting us as indicated in Section 20.

17. DATA RETENTION

We retain Personal Data for as long as necessary to fulfill the purposes described in this Statement and for as long as the relationship giving rise to the processing subsists, and thereafter for the periods required by: (i) the record-keeping and file-retention duties inherent to the professional practice of law; (ii) tax, accounting, regulatory compliance, and anti-money laundering and counter-terrorist financing obligations; and (iii) the statutes of limitations applicable to actions that may arise from the relevant relationship. Once those periods expire, the data will be securely deleted or anonymized. The Firm’s databases will remain in force for the period corresponding to the purposes for which their processing was authorized and to the special rules governing the matter.

18. OTHER MATTERS

  • Consequences of not providing Personal Data. You are not obliged to provide us with your Personal Data; however, if you do not, we may be unable to provide our services, respond to your inquiries, process your engagement as a client or supplier, or allow you to use certain features of the Sites.
  • Automated decision-making. We do not make decisions based solely on automated processing that produce substantial legal effects on individuals.
  • Do-Not-Track (DNT) signals. Unless otherwise required by applicable law, our Sites do not currently respond to browser “Do Not Track” signals. You can manage cookies through the tool described in Section 10.
  • Links to third-party sites. Our Sites may contain links to third-party websites. This Statement does not apply to those sites, whose privacy practices are governed by their own policies, which we encourage you to review.
  • Employees and contractors. The processing of Personal Data of employees, contractors, and candidates is additionally governed by the Firm’s internal policies. This policy is deemed incorporated, as relevant, into the employment and services agreements and the Internal Work Regulations (Reglamento Interno de Trabajo) of Hoyos & Associates S.A.S.
  • National Database Registry (RNBD). H&A will register and keep its databases updated in the National Database Registry administered by the SIC to the extent that such obligation applies to it under Article 25 of Law 1581 of 2012 and Articles 2.2.2.26.1.2 and 2.2.2.26.3.1 of Decree 1074 of 2015, as amended by Decree 090 of 2018 (an obligation applicable to companies and non-profit entities with total assets exceeding 100,000 UVT and to public legal entities).

19. CHANGES TO THIS STATEMENT

We may update this Privacy Statement and Processing Policy to reflect legal, technological, or practice changes. We will publish the current version on our Sites with its effective date and, where changes are material with respect to processing subject to Colombian law, we will communicate them through notices on the Sites or other effective means before their implementation. Use of the Sites after publication of the updated version is subject to that version.

20. CONTACT, SERVICE CHANNELS, AND AUTHORITIES

If you have questions or comments regarding this Privacy Statement or our privacy practices, or wish to exercise your rights, please contact us:

  • Privacy contact: Mateo Hoyos, Esq.  - Chief Executive Officer, e-mail mateo@hoyos.law.
  • United States: 15 MetroTech Center, 7th Floor, Brooklyn, New York 11201, U.S.A.
  • Colombia: Carrera 6ª No.48ª-10, Piso 1, Bogotá D.C.Telephone: +57 312 888 4092  and +57 304 376 1740. Petitions, consultations, and claims from data subjects will be received and processed by the client service area of Hoyos & Associates S.A.S., within the terms and time limits of Section 11.2.
  • Colombian authority: Superintendence of Industry and Commerce  - Deputy Superintendence for Personal Data Protection (www.sic.gov.co).
  • EEA / United Kingdom: you may contact your local data protection authority.

Effective date: [●  - TO BE CONFIRMED]. This version supersedes the Privacy Statement with an effective date of May 2024 and, as relevant, the July 2024 Personal Data Processing Policy of Hoyos & Associates S.A.S.