
Verify Before You Meet
Stay safer by confirming who you are meeting before the first encounter.
Privacy Policy / Política de Tratamiento de Datos Personales
Version 2.0. Date of issue: 13 August 2026. Versión 2.0. Fecha de expedición: 13 de agosto de 2026.
Welcome to VeraID. We built this platform to help keep travelers safe in Colombia. We take your privacy seriously and want to be transparent about how we handle your data. This policy covers both our English-speaking visitors and our Spanish-speaking providers.
Bienvenido a VeraID. Esta política cubre tanto a visitantes de habla inglesa como a proveedores de habla hispana.
This policy is the Personal Data Processing Policy (Política de Tratamiento de Datos Personales) referred to in our Terms and Conditions for Providers and Terms and Conditions for Visitors.
1. Who We Are / Quiénes Somos
VeraID is a voluntary identity verification and personal safety platform operating in Colombia. The data controller (responsable del tratamiento) is:
Foti Enterprise S.A.S. NIT 900.884.199-4 Commercial registration No. 21-544668-12, Chamber of Commerce of Medellín for Antioquia Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellín, Antioquia, Colombia
- Judicial notification email: [email protected]
- User support email: [email protected]
- Personal data protection email: [email protected]
- Website: veraid.org
We operate under applicable laws including Colombian Ley 1581 de 2012 and its implementing Decree 1074 de 2015 (Personal Data Protection), Ley 1480 de 2011 (Consumer Protection), and applicable United States privacy regulations for our US-based visitors.
2. Where This Policy Applies
This Privacy Policy applies to the VeraID mobile application, the veraid.org website and any related services we operate. It applies to all users regardless of location, with specific provisions for Colombian residents under Ley 1581 de 2012 and for California residents under the California Consumer Privacy Act (CCPA).
3. Data We Collect / Datos que Recopilamos
Data you give us:
For visitors we collect: full name, email address, WhatsApp phone number, passport number (optional), emergency contact name and phone number (optional), and a referral code if provided by a provider.
For service providers we collect: full legal name, cédula number, date of birth, WhatsApp phone number, face photo, cédula front and back photos, profession, RNT registration number and certificate where applicable, bank account details for commission payouts (optional), and biometric identity verification data (facial photograph, liveness check, and any technical representation derived from them) processed through our verification partner to confirm the person is real and matches their identity document.
For all users we collect: safety reports you submit including descriptions and photos, and check-in records including timestamps and provider codes.
Data generated automatically:
When you use VeraID we keep basic technical and security logs, such as account login events, needed to operate and protect the service. We do not run advertising or analytics tracking, and we do not collect precise geolocation data.
4. How We Use Your Data / Cómo Usamos sus Datos
We use your data to operate the VeraID platform including verifying provider identities, issuing and maintaining TRU codes, enabling visitor check-ins, processing safety reports, sending WhatsApp notifications, managing subscriptions, and processing referral commissions.
We use your data to keep the platform safe including reviewing safety reports, investigating flagged providers, and suspending accounts that violate our terms.
We do not use your data for advertising, for commercial profiling, for recognition of third parties unconnected with a user’s own verification process, or to train artificial intelligence models. We do not sell your data to any third party under any circumstances.
No usamos sus datos para publicidad, perfilamiento comercial, reconocimiento de terceros ajenos al proceso de verificación, ni para entrenar modelos de inteligencia artificial. No vendemos sus datos a terceros bajo ninguna circunstancia.
5. Sensitive Data / Datos Sensibles
Biometric data (facial photograph, liveness check, and any template or technical representation derived from them) is sensitive data under article 5 of Ley 1581 de 2012. Only providers supply biometric data. Visitors do not.
You are not legally obliged to supply sensitive data. However, without biometric verification we cannot complete the identity verification process that is the object of the provider service. We collect biometric data only with prior, express and informed authorisation, granted through a separate checkbox at registration, independent from acceptance of the Terms and Conditions.
Los datos biométricos (fotografía facial, prueba de vida y cualquier plantilla o representación técnica derivada de ellas) son datos sensibles conforme al artículo 5 de la Ley 1581 de 2012. Solo los Proveedores suministran datos biométricos; los Visitantes no.
Usted no está legalmente obligado a suministrar datos sensibles. Sin embargo, sin la verificación biométrica no podemos completar el proceso de verificación de identidad que constituye el objeto del servicio para Proveedores. Solo tratamos datos biométricos con autorización previa, expresa e informada, otorgada mediante una casilla de verificación separada e independiente de la aceptación de los Términos y Condiciones.
6. How We Share Your Data / Cómo Compartimos sus Datos
Provider face photos and first names are visible to verified visitors who look up their TRU code. No other personal data is shared publicly. Cédula numbers, identity document images and the biometric photograph are never shown to visitors.
We use the following service providers (encargados del tratamiento), who process your data solely to operate our platform and are bound by their own privacy and security obligations:
- Didit (identity and biometric verification). Didit is the Verification Partner referred to in our Terms and Conditions for Providers.
- Supabase (data storage, database and hosting)
- RevenueCat and Apple (subscription management and payment processing)
- Ultramsg (WhatsApp notifications)
Some of these providers process data outside Colombia, for example Didit in the European Union. This international transmission is carried out under adequate security standards and is covered by the authorisation you grant at registration, in accordance with Ley 1581 de 2012 and Decree 1074 de 2015.
We may disclose your data to law enforcement or courts if required by Colombian law, US law, or a valid court order.
We will never share your cédula number, passport number, bank account details, or emergency contact information with any third party except as required by law or as needed to perform the verification described above.
7. Data Security / Seguridad de Datos
All data is stored securely using Supabase with encrypted databases. Photos and documents are kept in private storage and are accessible only through short-lived signed links to authorized roles. Sensitive operations run server-side only. Access to provider data is restricted to authorised VeraID personnel and to the processors listed above. We apply industry standard technical, administrative and physical security measures in accordance with article 4, subparagraph g), of Ley 1581 de 2012.
While we take security seriously, no system is completely secure. If you believe your account has been compromised please contact us immediately at [email protected]
8. WhatsApp Communications
By providing your WhatsApp number you consent to receiving safety notifications, account updates, and referral commission alerts from VeraID via WhatsApp. You may opt out at any time by contacting [email protected]
Al proporcionar su número de WhatsApp, acepta recibir notificaciones de seguridad, actualizaciones de cuenta y alertas de comisiones de VeraID por WhatsApp. Puede cancelar en cualquier momento contactando [email protected]
9. Your Rights / Sus Derechos
For all users: You have the right to access, correct, update, and request deletion of your personal data at any time, and to revoke any authorisation you have granted. You can delete your account directly in the app or by contacting [email protected]
For Colombian residents (Ley 1581 de 2012): Usted tiene derecho a conocer, actualizar, rectificar y suprimir sus datos personales, solicitar prueba de la autorización otorgada, ser informado sobre su uso, y revocar la autorización. Para ejercer estos derechos escriba a [email protected]. Atenderemos consultas en un máximo de diez (10) días hábiles y reclamos en un máximo de quince (15) días hábiles, conforme a la ley.
For California residents (CCPA): California residents have the right to know what personal data we collect, the right to delete personal data, and the right to opt out of the sale of personal data. VeraID does not sell personal data. To exercise your rights contact [email protected]
For all US residents: You have the right to access and delete your personal data. VeraID does not engage in targeted advertising or data sales. Contact [email protected] to exercise your rights.
10. Data Retention / Retención de Datos
We retain your data for as long as your account is active and thereafter only for the time necessary to fulfil the purposes described in this policy and any applicable legal, accounting or evidentiary obligations. When you delete your account your personal data is removed within 30 days, except where retention is legally required. Check-in logs and safety reports are anonymized rather than deleted, as they serve as safety records.
For safety, when a provider is suspended or terminated we retain a one-way, irreversible technical identifier (hash) derived from their cédula, together with a history flag. This record contains no readable ID number, name, photo, or contact details. Its sole purpose is to prevent a person from evading a suspension by deleting their account and re-registering.
This identifier is retained only for the time strictly necessary to fulfil that purpose and is subject to periodic review of whether continued retention remains justified. We do not claim that this identifier ceases to be personal data merely because it is derived from a hash function. The rights described in Section 9 apply to it, and you may submit requests relating to this processing at [email protected]
We may retain certain data longer if required by Colombian or US law or if needed to resolve an ongoing safety investigation or legal matter.
11. Children / Menores de Edad
VeraID is not intended for users under 18 years of age. We do not knowingly collect data from minors. Age verification is required during registration. If you believe a minor has registered please contact us at [email protected]
12. Changes to This Policy / Cambios a esta Política
We may update this policy from time to time. We will notify registered users of substantial changes through the application or the registered email address with reasonable advance notice, before they take effect.
Where a change requires a new authorisation for the processing of your personal data, we will request that authorisation expressly. Continued use of the app is not treated as acceptance of a change that requires express authorisation.
Podremos actualizar esta política. Los cambios sustanciales se informarán con antelación razonable a través de la aplicación o del correo electrónico registrado. Cuando un cambio requiera una nueva autorización, esta se solicitará expresamente. El uso continuado de la aplicación no se entiende como aceptación de un cambio que requiera autorización expresa.
13. Contact / Contacto
For any privacy questions, data requests, or complaints:
Foti Enterprise S.A.S. (VeraID) NIT 900.884.199-4 Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellín, Antioquia, Colombia
- Personal data protection: [email protected]
- General support: [email protected]
- Website: veraid.org
Consumer protection / Protección al consumidor. If you have a complaint or claim relating to the Service, you can write to us at [email protected]. You may also contact the Superintendencia de Industria y Comercio (SIC) at https://www.sic.gov.co
Si tienes una queja o reclamo relacionado con el Servicio, puedes escribirnos a [email protected]. También puedes acudir a la Superintendencia de Industria y Comercio: https://www.sic.gov.co
For California residents with unresolved complaints you may contact the California Privacy Protection Agency at https://cppa.ca.gov
VeraID · Foti Enterprise S.A.S. · Medellín, Colombia · Version 2.0 · 13 August 2026
VERA ID
Términos y Condiciones para Proveedores
Versión 2.0. Fecha de expedición: 13 de agosto de 2026. Vigente a partir de su publicación en la aplicación VeraID y en veraid.org.
Lea cuidadosamente estos Términos y Condiciones antes de registrarse como Proveedor en la aplicación móvil VeraID, el sitio web y los servicios relacionados (el "Servicio"). Al seleccionar la opción "Acepto los Términos y Condiciones", crear una cuenta o utilizar el Servicio como Proveedor, usted manifiesta que ha leído, comprendido y aceptado estos Términos. La autorización para el tratamiento de sus datos sensibles y biométricos es independiente de esta aceptación y debe otorgarse por separado, conforme al Capítulo 12 y al Anexo 1 de este documento. Si usted no está de acuerdo con estos Términos, no debe registrarse ni utilizar el Servicio como Proveedor.
1. Identificación del Operador de VeraID
El Servicio VeraID es operado por Foti Enterprise S.A.S., sociedad comercial por acciones simplificada constituida bajo las leyes de la República de Colombia, identificada con NIT 900.884.199-4, inscrita bajo la matrícula mercantil No. 21-544668-12 de la Cámara de Comercio de Medellín para Antioquia, con domicilio principal y dirección de notificación judicial en la Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellín, Antioquia, Colombia, correo electrónico de notificación judicial [email protected], correo electrónico de atención al usuario [email protected] y correo para protección de datos personales [email protected]. Para efectos de estos Términos, Foti Enterprise S.A.S. podrá denominarse "VeraID", "nosotros" o "la Plataforma". VeraID es una marca y plataforma digital operada por Foti Enterprise S.A.S.
Estos Términos y Condiciones para Proveedores (los "Términos") regulan exclusivamente la relación entre VeraID y las personas naturales que se registran como prestadores de servicios para solicitar un proceso de verificación de identidad y un código TRU (los "Proveedores"). La relación con quienes consultan dicho código o interactúan con la Plataforma como Visitantes se rige por un documento independiente, los Términos y Condiciones para Visitantes.
2. Naturaleza del Servicio
VeraID presta al Proveedor un servicio de verificación de identidad: confirma, mediante los procedimientos descritos en el Capítulo 5, que la identidad declarada por el Proveedor corresponde razonablemente a la persona que se registra, y le asigna un código TRU que refleja el resultado de esa verificación.
VeraID NO certifica, garantiza ni avala la buena conducta del Proveedor, su seguridad personal, la ausencia de antecedentes de cualquier naturaleza, su idoneidad profesional, la calidad del servicio que preste a un Visitante, su solvencia económica, ni su comportamiento futuro. El código TRU no es una licencia, permiso o autorización estatal para ejercer una actividad, ni sustituye ningún registro, licencia o habilitación que la ley exija para la actividad concreta que el Proveedor desarrolle.
Por lo anterior, VeraID evita en su comunicación, publicidad e interfaz expresiones como "proveedor seguro", "proveedor confiable" o "proveedor certificado", y utiliza en su lugar expresiones técnicamente delimitadas como "identidad verificada" o "estado de verificación", cuyo alcance exacto es el descrito en estos Términos.
3. Elegibilidad y Mayoría de Edad
El registro como Proveedor está reservado a personas naturales mayores de dieciocho (18) años. Al registrarse, el Proveedor declara que tiene al menos dieciocho (18) años, que la información que suministra es propia, veraz, completa y verificable, y que cuenta con capacidad legal para prestar los servicios que ofrece por su propia cuenta y riesgo.
VeraID no permite conscientemente el registro de menores de edad como Proveedores. Si se identifica razonablemente que una cuenta pertenece a un menor de edad, VeraID podrá suspenderla, restringir su acceso y eliminar los datos personales asociados, salvo que exista una obligación legal de conservación.
4. Registro del Proveedor
Para registrarse, el Proveedor debe crear una cuenta y suministrar la información que la Plataforma solicite con carácter obligatorio para adelantar el proceso de verificación descrito en el Capítulo 5. El Proveedor es responsable de mantener la confidencialidad de sus credenciales, de no compartir su cuenta, de informar de inmediato cualquier uso no autorizado, de mantener actualizada su información y de no crear cuentas duplicadas para evadir una suspensión o terminación.
VeraID podrá solicitar verificaciones adicionales cuando sean razonablemente necesarias para prevenir suplantaciones, fraude, duplicidad de cuentas o uso abusivo del Servicio, respetando en todo caso los principios de finalidad, necesidad y proporcionalidad aplicables al tratamiento de datos personales conforme al artículo 4 de la Ley 1581 de 2012.
El registro como Proveedor constituye una solicitud dirigida a VeraID y no genera, por sí solo, derecho a obtener una cuenta ni un código TRU. VeraID podrá abstenerse de aceptar cualquier solicitud de registro, de forma discrecional y sin obligación de expresar los motivos de su decisión, dado que en esta etapa no se ha perfeccionado vínculo contractual alguno entre el solicitante y VeraID. La no aceptación de una solicitud no genera responsabilidad para VeraID ni derecho a indemnización, y no impide que el solicitante presente una nueva solicitud en el futuro. Cuando una solicitud no sea aceptada, los datos suministrados serán suprimidos o conservados únicamente en los términos previstos en los Capítulos 11 y 13.
5. Proceso de Verificación de Identidad (KYC)
El proceso de verificación de identidad del Proveedor comprende, como mínimo, la presentación de un documento de identidad vigente, la captura de una fotografía del rostro del Proveedor ("selfie"), una prueba de vida destinada a confirmar que quien se registra es una persona real presente al momento del registro, y una comparación facial uno a uno (1:1) entre esa captura y la fotografía del documento de identidad presentado.
Estos procedimientos técnicos son ejecutados con la intervención de un proveedor tecnológico externo especializado en verificación de identidad (el "Aliado de verificación"), cuya identidad y calidad serán informadas en el Capítulo 11 y en la Política de Tratamiento de Datos Personales de VeraID.
El resultado técnico entregado por el Aliado de verificación está sujeto a una revisión humana final por parte de VeraID antes de la emisión, denegación o revocación de un código TRU. En consecuencia, ninguna decisión que afecte de manera definitiva el estado de verificación de un Proveedor se adopta exclusivamente mediante un proceso automatizado, sin intervención humana.
6. El Código TRU
El código TRU es un identificador digital único que VeraID asigna al Proveedor cuando este supera satisfactoriamente el proceso de verificación descrito en el Capítulo 5. El código TRU tiene como única finalidad reflejar el resultado de dicha verificación de identidad; no es una calificación de reputación, no es un puntaje de riesgo y no es una recomendación comercial.
El código TRU es personal e intransferible: está vinculado exclusivamente a la identidad verificada del Proveedor y no puede cederse, prestarse, venderse ni compartirse con un tercero para que este se presente bajo dicho código. Queda expresamente prohibido que el Proveedor comparta, ceda o permita el uso de su código TRU por otra persona, así como que utilice el código TRU de un tercero.
El uso indebido del código TRU —incluida su transferencia fraudulenta a un tercero o su utilización para hacer aparecer como verificada a una persona distinta del Proveedor original— constituye un incumplimiento grave de estos Términos y dará lugar a la suspensión o revocación del código y, cuando corresponda, a la terminación de la cuenta conforme al Capítulo 10, sin perjuicio de las acciones legales a que haya lugar.
El código TRU permanece vigente mientras la información verificada del Proveedor no cambie de manera sustancial y mientras no se presenten las irregularidades descritas en el Capítulo 8. VeraID podrá requerir una reverificación periódica u ocasional cuando existan razones objetivas para ello.
7. Información Visible para los Visitantes
VeraID limita estrictamente los datos del Proveedor que resultan visibles para un Visitante que consulta su código TRU. En ningún caso se muestra el número de cédula, pasaporte u otro documento de identificación del Proveedor, ni se muestra la fotografía biométrica ("selfie") capturada para la verificación, ni las imágenes del documento de identidad cargadas durante el proceso KYC.
La fotografía pública de perfil que el Proveedor decide mostrar en su cuenta se trata de forma independiente y separada de la imagen biométrica utilizada exclusivamente para la verificación de identidad descrita en el Capítulo 5; la primera es una imagen que el Proveedor autoriza mostrar públicamente, mientras que la segunda es un dato biométrico sujeto al régimen reforzado de protección descrito en el Capítulo 12.
Según la configuración de la cuenta y la información que el Proveedor decida hacer pública, el Visitante podrá consultar únicamente el primer nombre o nombre abreviado del Proveedor, su fotografía pública de perfil y el estado general de su código TRU.
8. Reportes de Seguridad
Los Visitantes pueden presentar ante VeraID reportes relacionados con una interacción real con un Proveedor. Este Capítulo regula dos figuras jurídicas distintas aplicables frente a dichos reportes: la suspensión preventiva temporal y la suspensión o terminación definitiva.
Suspensión preventiva temporal. VeraID podrá suspender provisionalmente la cuenta o el estado de verificación de un Proveedor cuando exista un reporte serio, un riesgo razonable para otros usuarios, evidencia prima facie que lo justifique, o cuando ello sea necesario para preservar la integridad de una investigación en curso. Esta suspensión preventiva no constituye una declaración de culpabilidad ni implica que VeraID haya determinado la veracidad definitiva del reporte; se trata de una medida cautelar sometida a revisión humana inmediata, que debe ser proporcional a la gravedad de lo reportado y que solo puede mantenerse mientras resulte estrictamente necesaria. VeraID revisará la medida dentro de los tres (3) días hábiles siguientes a su adopción y la levantará o modificará tan pronto desaparezcan las razones que la motivaron.
Suspensión o terminación definitiva. La suspensión definitiva del código TRU o la terminación de la cuenta con fundamento en un reporte solo podrá imponerse después de un procedimiento contradictorio que garantice el derecho de defensa del Proveedor, conforme al artículo 29 de la Constitución Política. Dicho procedimiento comprende la notificación al Proveedor del contenido sustancial del reporte dentro de los tres (3) días hábiles siguientes a su recepción, un plazo de cinco (5) días hábiles para que el Proveedor presente sus descargos y aporte las pruebas que considere pertinentes, la revisión humana e imparcial de la información disponible, la adopción de una decisión motivada dentro de los diez (10) días hábiles siguientes al vencimiento del plazo de descargos, y la posibilidad de solicitar una apelación ante una instancia interna de revisión de VeraID dentro de los cinco (5) días hábiles siguientes a la notificación de la decisión. VeraID podrá ajustar estos plazos cuando la complejidad del caso lo justifique razonablemente, informando al Proveedor el nuevo término.
La información sustancial del reporte podrá reservarse parcialmente cuando ello sea estrictamente necesario para proteger a la persona que lo presentó, evitar represalias o no afectar una investigación en curso, sin que dicha reserva pueda utilizarse para impedir de manera absoluta el derecho de defensa del Proveedor.
9. Reportes Falsos y Abuso del Sistema
Los reportes deben presentarse de buena fe, describir hechos concretos y evitar información deliberadamente falsa. Cuando VeraID determine, después del procedimiento aplicable, que un reporte fue presentado a sabiendas de su falsedad o con fines maliciosos, podrá adoptar medidas frente a la cuenta del Visitante que lo presentó, incluida su suspensión, sin perjuicio de la responsabilidad civil o penal a que dicha conducta pueda dar lugar conforme a la legislación colombiana.
El Proveedor podrá informar a VeraID sobre reportes que considere falsos, abusivos o presentados con ánimo de perjudicarlo, aportando la evidencia que tenga disponible, la cual será valorada dentro del procedimiento descrito en el Capítulo 8.
10. Eliminación, Suspensión y Terminación de Cuentas
El Proveedor podrá eliminar su cuenta en cualquier momento mediante la funcionalidad disponible en la aplicación o contactando a VeraID a través de los canales indicados en el Capítulo 1.
Además de los supuestos descritos en el Capítulo 8, VeraID podrá suspender o terminar la cuenta de un Proveedor cuando exista incumplimiento de estos Términos, suplantación, fraude, información falsa, uso indebido del código TRU conforme al Capítulo 6, o incumplimiento de una medida de seguridad. Cuando la medida no responda a una situación urgente, VeraID informará al Proveedor la razón principal y le permitirá presentar explicaciones o solicitar revisión, en los términos del Capítulo 8.
La terminación de la cuenta no elimina automáticamente los datos cuya conservación sea necesaria para cumplir una obligación legal, atender una reclamación, prevenir fraude o ejercer derechos; dicha conservación estará limitada a la finalidad y al período estrictamente necesarios, conforme al Capítulo 11.
11. Protección de Datos Personales del Proveedor
VeraID, a través de Foti Enterprise S.A.S., es responsable del tratamiento de los datos personales del Proveedor, conforme al artículo 15 de la Constitución Política y a la Ley 1581 de 2012 y su decreto reglamentario, el Decreto 1074 de 2015, Título 2, Capítulo 25.
Los datos personales que VeraID recolecta del Proveedor incluyen, según
VERAID
Términos y Condiciones para Visitantes
Versión 2.0. Fecha de expedición: 13 de agosto de 2026. Vigente a partir de su publicación en la aplicación VeraID y en veraid.org.
Lea cuidadosamente estos Términos y Condiciones antes de crear una cuenta, acceder o utilizar la aplicación móvil VeraID, el sitio web y los servicios relacionados (el "Servicio") como Visitante. Al seleccionar la opción "Acepto los Términos y Condiciones", crear una cuenta o utilizar el Servicio, usted manifiesta que ha leído, comprendido y aceptado estos Términos. Si usted no está de acuerdo con estos Términos, no debe crear una cuenta ni utilizar el Servicio.
1. Identificación de VeraID
El Servicio VeraID es operado por Foti Enterprise S.A.S., sociedad comercial por acciones simplificada constituida bajo las leyes de la República de Colombia, identificada con NIT 900.884.199-4, inscrita bajo la matrícula mercantil No. 21-544668-12 de la Cámara de Comercio de Medellín para Antioquia, con domicilio principal y dirección de notificación judicial en la Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellín, Antioquia, Colombia, correo electrónico de notificación judicial [email protected], correo electrónico de atención al usuario [email protected] y correo para protección de datos personales [email protected]. Para efectos de estos Términos, Foti Enterprise S.A.S. podrá denominarse "VeraID", "nosotros" o "la Plataforma". VeraID es una marca y plataforma digital operada por Foti Enterprise S.A.S.
Estos Términos y Condiciones para Visitantes (los "Términos") regulan exclusivamente la relación entre VeraID y las personas que utilizan la Plataforma para consultar el código TRU de un Proveedor u otras funciones dirigidas a este perfil de usuario (los "Visitantes"). La relación con quienes se registran como Proveedores se rige por un documento independiente, los Términos y Condiciones para Proveedores.
2. Naturaleza del Servicio
VeraID permite al Visitante consultar el estado de verificación de identidad de un Proveedor, expresado a través de un código TRU, con el fin de reducir la asimetría de información propia de un primer contacto entre personas que no se conocen. VeraID no organiza, contrata, supervisa ni participa en los servicios que el Proveedor ofrezca directamente al Visitante.
3. Elegibilidad
El Servicio está dirigido exclusivamente a personas mayores de dieciocho (18) años. Al crear una cuenta o utilizar el Servicio, el Visitante declara que cumple este requisito y que la información que suministra es propia, veraz y actualizada. VeraID no permite conscientemente el registro de menores de edad; si identifica razonablemente que una cuenta pertenece a un menor de edad, podrá suspenderla y eliminar los datos personales asociados, salvo obligación legal de conservación.
4. Cuenta del Visitante
Para utilizar determinadas funciones, el Visitante deberá crear una cuenta y suministrar información veraz, completa y actualizada. Es responsable de mantener la confidencialidad de sus credenciales, de no compartir su cuenta, de informar de inmediato cualquier uso no autorizado y de utilizar la Plataforma conforme a la ley y a estos Términos.
La creación de una cuenta constituye una solicitud dirigida a VeraID y no genera, por sí sola, derecho a obtener acceso al Servicio. VeraID podrá abstenerse de aceptar cualquier solicitud de registro, de forma discrecional y sin obligación de expresar los motivos de su decisión, dado que en esta etapa no se ha perfeccionado vínculo contractual alguno. La no aceptación de una solicitud no genera responsabilidad para VeraID ni derecho a indemnización. Cuando una solicitud no sea aceptada, no se cobrará suma alguna al solicitante y, si se hubiere efectuado algún pago, este será reembolsado en su totalidad.
5. Consulta del Código TRU
El Visitante podrá consultar el código TRU de un Proveedor para conocer su estado general de verificación, así como la información pública que el Proveedor haya autorizado mostrar, conforme al Capítulo 7 de los Términos y Condiciones para Proveedores. Esta consulta no otorga al Visitante acceso a los documentos de identificación, a la fotografía biométrica ni a ningún otro dato reservado del Proveedor.
6. Alcance de la Verificación
Visualizar que un Proveedor cuenta con "identidad verificada" o un código TRU activo significa únicamente que dicho Proveedor superó el proceso de verificación de identidad descrito en los Términos y Condiciones para Proveedores. Esto NO significa, ni debe interpretarse como, una garantía de seguridad personal, una certificación de la conducta del Proveedor, una recomendación de VeraID sobre la contratación de sus servicios, ni la ausencia de cualquier riesgo derivado del contacto o la interacción con dicho Proveedor. El Visitante conserva en todo momento la responsabilidad de evaluar por sí mismo si contrata o se relaciona con un Proveedor determinado.
7. Check-ins
Cuando la Plataforma ofrezca la función de check-in, esta consiste en un registro que el Visitante decide crear, por ejemplo antes o durante un encuentro con un Proveedor. Los check-ins son registros informativos y no constituyen un servicio de monitoreo en tiempo real de la ubicación o situación del Visitante. VeraID no despacha automáticamente autoridades, servicios de emergencia ni ningún tercero como consecuencia de un check-in, y no presta servicios de emergencia de ningún tipo. El Visitante que se encuentre en una situación de riesgo o emergencia debe contactar directamente a las autoridades o a los servicios de emergencia correspondientes, y no debe depender de la función de check-in para dicho fin.
8. Reportes de Seguridad
El Visitante que presente un reporte de seguridad sobre un Proveedor debe hacerlo de buena fe, con base en hechos concretos relacionados con una interacción real, y aportando la evidencia disponible que resulte razonable. Quedan prohibidos los reportes maliciosos o presentados a sabiendas de su falsedad.
Cuando VeraID determine, después del procedimiento aplicable conforme a los Términos y Condiciones para Proveedores, que un reporte fue presentado con información deliberadamente falsa, podrá adoptar medidas frente a la cuenta del Visitante que lo presentó, incluida su suspensión, sin perjuicio de la responsabilidad civil o penal a que dicha conducta pueda dar lugar conforme a la legislación colombiana.
9. Privacidad del Proveedor
El Visitante se obliga a respetar la privacidad de los Proveedores cuya información consulte a través de la Plataforma. En consecuencia, queda expresamente prohibido: realizar scraping o extracción automatizada de información de la Plataforma; copiar de forma masiva perfiles de Proveedores; crear bases de datos propias a partir de la información consultada; utilizar las imágenes de un Proveedor para procesos de reconocimiento facial ajenos a VeraID; suplantar a un Proveedor o hacerse pasar por él; y publicar, redistribuir o divulgar de manera indebida la información de un Proveedor obtenida a través de la Plataforma.
10. Capturas de Pantalla y Reproducción
Salvo para los usos estrictamente personales y razonables que resulten inherentes al propósito del Servicio —como conservar temporalmente el resultado de una consulta antes de un encuentro—, el Visitante no podrá reproducir, almacenar de forma permanente, redistribuir ni divulgar sin autorización la información de un Proveedor obtenida a través de la Plataforma, incluidas las capturas de pantalla.
VeraID podrá implementar medidas técnicas orientadas a limitar capturas de pantalla o descargas de contenido cuando ello sea técnicamente posible, sin que dichas medidas garanticen la imposibilidad absoluta de copiar contenidos de la Plataforma. La prohibición contractual descrita en este Capítulo rige con independencia de la efectividad de dichas medidas técnicas.
11. Suscripciones y Pagos
Cuando el Servicio ofrezca al Visitante suscripciones u otras funciones pagas, VeraID informará antes de la compra la descripción del servicio, el precio total, la periodicidad del cobro, la existencia de renovación automática, la forma de cancelación, las condiciones de retracto y de reembolso, y los canales de atención disponibles.
Las compras podrán procesarse a través de la Apple App Store, Google Play u otro proveedor de pagos como RevenueCat, cuyas condiciones operativas de facturación, renovación y cancelación se aplican adicionalmente a estos Términos, sin que ello elimine las obligaciones legales de VeraID frente al consumidor ni los derechos reconocidos por normas colombianas imperativas.
El Visitante tiene derecho de retracto conforme al artículo 47 de la Ley 1480 de 2011. La excepción prevista en el numeral 1 de dicho artículo —según la cual el retracto no aplica una vez ha comenzado la prestación del servicio— solo opera cuando el Visitante ha otorgado, de forma expresa y específica al momento de la compra, su acuerdo para que la prestación del servicio pagado comience antes de vencer el término de retracto. La sola activación técnica de una suscripción, sin que medie esa autorización expresa y específica del consumidor, no es suficiente por sí sola para entender configurada dicha excepción. Cuando la excepción no resulte aplicable, el Visitante conserva su derecho a retractarse dentro de los términos legales, y en todo caso conserva los derechos de reversión del pago reconocidos en el artículo 51 de la Ley 1480 de 2011 frente a fraude, cobros no solicitados o incumplimiento de las condiciones ofrecidas.
12. Protección de Datos Personales del Visitante
VeraID, a través de Foti Enterprise S.A.S., es responsable del tratamiento de los datos personales del Visitante, conforme al artículo 15 de la Constitución Política y a la Ley 1581 de 2012 y su Decreto reglamentario 1074 de 2015.
Los datos personales que VeraID recolecta del Visitante incluyen, según el caso: datos de la cuenta (nombre, correo electrónico, número de teléfono); los registros de check-ins que el Visitante decida crear; el contenido de los reportes de seguridad que presente, incluida la evidencia que aporte; las notificaciones y comunicaciones que se generen dentro de la Plataforma; y los datos necesarios para procesar pagos de suscripciones, sin que VeraID almacene directamente los datos completos de la tarjeta cuando el pago sea procesado por un tercero.
Las finalidades del tratamiento son: permitir el registro y funcionamiento de la cuenta del Visitante; habilitar la consulta de códigos TRU; procesar y dar seguimiento a los check-ins y reportes de seguridad; gestionar suscripciones y pagos; atender solicitudes, peticiones y reclamos; prevenir fraude y usos indebidos de la Plataforma; y cumplir las obligaciones legales aplicables a VeraID.
Los datos se conservan durante el tiempo necesario para cumplir las finalidades informadas y las obligaciones legales, contables o probatorias aplicables, con medidas de seguridad razonables conforme al artículo 4, literal g), de la Ley 1581 de 2012. Cuando VeraID transmita datos a un tercero encargado del tratamiento —incluidos los procesadores de pago descritos en el Capítulo 11— ello se informará en la Política de Tratamiento de Datos Personales, junto con las garantías aplicables.
El Visitante, en su calidad de titular, podrá ejercer en cualquier momento los derechos de conocer, actualizar, rectificar y suprimir sus datos personales, así como revocar la autorización otorgada, conforme al artículo 8 de la Ley 1581 de 2012, a través de los canales indicados en el Capítulo 1.
13. Autorización para el Tratamiento de Datos
La autorización del Visitante para el tratamiento de sus datos personales cubre el funcionamiento de su cuenta, la creación y gestión de check-ins, la presentación y trámite de reportes de seguridad, las comunicaciones de contacto necesarias para prestar el Servicio, y la transmisión de los datos estrictamente necesarios a los terceros tecnológicos que intervienen en dichas funciones, incluidos los procesadores de pago cuando aplique.
A diferencia de los Proveedores, el Visitante no suministra datos biométricos a VeraID como parte del funcionamiento actual de la Plataforma. En consecuencia, esta autorización no incluye ni requiere el tratamiento de datos biométricos del Visitante; si en el futuro se incorporara una funcionalidad que lo requiera, VeraID solicitará una autorización separada y específica para ese tratamiento, en los mismos términos exigentes previstos para los Proveedores.
El modelo de autorización correspondiente se incluye como Anexo 1 a este documento.
14. Propiedad Intelectual
El nombre VeraID, sus signos distintivos, logotipos, diseños, interfaces, software y demás elementos de la Plataforma son propiedad de Foti Enterprise S.A.S. o se utilizan legítimamente bajo licencia, y están protegidos por la normativa colombiana e internacional de propiedad intelectual, incluidas la Decisión Andina 351 de 1993 y la Ley 23 de 1982. El Visitante podrá utilizar el Servicio únicamente para las finalidades permitidas por estos Términos.
15. Responsabilidad del Visitante
El Visitante es responsable de la veracidad de la información que suministra, de los reportes que presenta, del cumplimiento de las prohibiciones descritas en los Capítulos 9 y 10, y de las decisiones que adopte respecto de su interacción con un Proveedor. VeraID no sustituye el juicio personal del Visitante ni asume las consecuencias de las decisiones que este adopte con base en la información consultada en la Plataforma.
16. Limitación de Responsabilidad de VeraID
VeraID no controla, celebra, ejecuta ni supervisa los encuentros, negocios o servicios que el Visitante acuerde con un Proveedor. Dentro de los límites que permite la ley, VeraID no será responsable por los daños derivados de dichos encuentros, negocios o servicios, en la medida en que actúa exclusivamente como un intermediario voluntario de verificación de identidad.
Esta limitación no exonera a VeraID de responder por los daño
VERA ID
Terms and Conditions for Providers
Version 2.0. Date of issue: 13 August 2026. Effective upon publication in the VeraID application and at veraid.org.
Please read these Terms and Conditions carefully before registering as a Provider on the VeraID mobile application, the website and related services (the "Service"). By selecting the option "I accept the Terms and Conditions", creating an account or using the Service as a Provider, you state that you have read, understood and accepted these Terms. The authorisation for the processing of your sensitive and biometric data is independent of this acceptance and must be granted separately, in accordance with Chapter 12 and Annex 1 of this document. If you do not agree with these Terms, you must not register or use the Service as a Provider.
1. Identification of the Operator of VeraID
The VeraID Service is operated by Foti Enterprise S.A.S., a simplified joint stock company incorporated under the laws of the Republic of Colombia, identified with NIT 900.884.199-4, registered under commercial registration No. 21-544668-12 of the Chamber of Commerce of Medellin for Antioquia, with principal domicile and address for judicial notification at Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellin, Antioquia, Colombia, judicial notification email [email protected], user support email [email protected] and personal data protection email [email protected]. For the purposes of these Terms, Foti Enterprise S.A.S. may be referred to as "VeraID", "we" or "the Platform". VeraID is a trademark and digital platform operated by Foti Enterprise S.A.S.
These Terms and Conditions for Providers (the "Terms") govern exclusively the relationship between VeraID and the natural persons who register as service providers in order to request an identity verification process and a TRU code (the "Providers"). The relationship with those who look up that code or interact with the Platform as Visitors is governed by a separate document, the Terms and Conditions for Visitors.
2. Nature of the Service
VeraID provides the Provider with an identity verification service: it confirms, through the procedures described in Chapter 5, that the identity declared by the Provider reasonably corresponds to the person registering, and assigns them a TRU code reflecting the result of that verification.
VeraID does NOT certify, guarantee or endorse the Provider's good conduct, their personal safety, the absence of any kind of criminal or other record, their professional suitability, the quality of the service they provide to a Visitor, their financial solvency, or their future behaviour. The TRU code is not a state licence, permit or authorisation to carry out an activity, and does not replace any registration, licence or qualification required by law for the specific activity the Provider carries out.
For this reason, VeraID avoids in its communications, advertising and interface expressions such as "safe provider", "trusted provider" or "certified provider", and instead uses technically delimited expressions such as "verified identity" or "verification status", whose exact scope is that described in these Terms.
3. Eligibility and Age of Majority
Registration as a Provider is reserved for natural persons over eighteen (18) years of age. On registering, the Provider declares that they are at least eighteen (18) years old, that the information they supply is their own, truthful, complete and verifiable, and that they have the legal capacity to provide the services they offer at their own account and risk.
VeraID does not knowingly permit the registration of minors as Providers. If it is reasonably identified that an account belongs to a minor, VeraID may suspend it, restrict its access and delete the associated personal data, unless there is a legal obligation to retain it.
4. Provider Registration
In order to register, the Provider must create an account and supply the information that the Platform requests on a mandatory basis in order to carry out the verification process described in Chapter 5. The Provider is responsible for keeping their credentials confidential, for not sharing their account, for immediately reporting any unauthorised use, for keeping their information up to date, and for not creating duplicate accounts in order to evade a suspension or termination.
VeraID may request additional verifications where these are reasonably necessary to prevent impersonation, fraud, duplicate accounts or abusive use of the Service, respecting in all cases the principles of purpose, necessity and proportionality applicable to the processing of personal data under article 4 of Law 1581 of 2012.
Registration as a Provider constitutes a request addressed to VeraID and does not, in itself, give rise to a right to obtain an account or a TRU code. VeraID may decline to accept any registration request, at its discretion and without any obligation to state the reasons for its decision, given that at this stage no contractual relationship has been formed between the applicant and VeraID. The non acceptance of a request does not give rise to liability for VeraID or to any right to compensation, and does not prevent the applicant from submitting a new request in the future. Where a request is not accepted, the data supplied shall be deleted or retained only on the terms provided in Chapters 11 and 13.
5. Identity Verification Process (KYC)
The Provider's identity verification process comprises, as a minimum, the presentation of a valid identity document, the capture of a photograph of the Provider's face ("selfie"), a liveness check intended to confirm that the person registering is a real person present at the time of registration, and a one to one (1:1) facial comparison between that capture and the photograph on the identity document presented.
These technical procedures are carried out with the involvement of an external technology provider specialised in identity verification (the "Verification Partner"), whose identity and capacity will be disclosed in Chapter 11 and in VeraID's Personal Data Processing Policy.
The technical result delivered by the Verification Partner is subject to a final human review by VeraID before the issuance, refusal or revocation of a TRU code. Accordingly, no decision that definitively affects a Provider's verification status is taken exclusively by an automated process, without human intervention.
6. The TRU Code
The TRU code is a unique digital identifier that VeraID assigns to the Provider when they successfully pass the verification process described in Chapter 5. The sole purpose of the TRU code is to reflect the result of that identity verification; it is not a reputation rating, it is not a risk score and it is not a commercial recommendation.
The TRU code is personal and non transferable: it is linked exclusively to the Provider's verified identity and may not be assigned, lent, sold or shared with a third party so that the third party may present themselves under that code. The Provider is expressly prohibited from sharing, assigning or allowing the use of their TRU code by another person, and from using a third party's TRU code.
Improper use of the TRU code, including its fraudulent transfer to a third party or its use to make a person other than the original Provider appear as verified, constitutes a serious breach of these Terms and shall give rise to the suspension or revocation of the code and, where applicable, to termination of the account under Chapter 10, without prejudice to any legal action that may be appropriate.
The TRU code remains in force for as long as the Provider's verified information does not change substantially and for as long as the irregularities described in Chapter 8 do not arise. VeraID may require periodic or occasional reverification where there are objective reasons to do so.
7. Information Visible to Visitors
VeraID strictly limits the Provider's data that is visible to a Visitor who looks up their TRU code. Under no circumstances is the Provider's national identity card number, passport number or other identification document number displayed, nor is the biometric photograph ("selfie") captured for verification displayed, nor the images of the identity document uploaded during the KYC process.
The public profile photograph that the Provider chooses to display on their account is handled independently and separately from the biometric image used exclusively for the identity verification described in Chapter 5; the former is an image that the Provider authorises to be shown publicly, while the latter is biometric data subject to the reinforced protection regime described in Chapter 12.
Depending on the account settings and the information the Provider chooses to make public, the Visitor may see only the Provider's first name or abbreviated name, their public profile photograph and the general status of their TRU code.
8. Safety Reports
Visitors may submit reports to VeraID relating to a real interaction with a Provider. This Chapter governs two distinct legal mechanisms applicable to such reports: temporary precautionary suspension, and definitive suspension or termination.
Temporary precautionary suspension. VeraID may provisionally suspend a Provider's account or verification status where there is a serious report, a reasonable risk to other users, prima facie evidence justifying it, or where this is necessary to preserve the integrity of an ongoing investigation. This precautionary suspension does not constitute a finding of guilt and does not imply that VeraID has determined the definitive truth of the report; it is a precautionary measure subject to immediate human review, which must be proportionate to the seriousness of what has been reported and which may only be maintained for as long as it remains strictly necessary. VeraID will review the measure within the three (3) business days following its adoption and will lift or modify it as soon as the reasons that gave rise to it cease to exist.
Definitive suspension or termination. Definitive suspension of the TRU code or termination of the account on the basis of a report may only be imposed following an adversarial procedure guaranteeing the Provider's right of defence, in accordance with article 29 of the Political Constitution. That procedure comprises notification to the Provider of the substantial content of the report within the three (3) business days following its receipt, a period of five (5) business days for the Provider to submit their response and provide such evidence as they consider relevant, human and impartial review of the available information, the adoption of a reasoned decision within the ten (10) business days following expiry of the response period, and the possibility of requesting an appeal before an internal review body of VeraID within the five (5) business days following notification of the decision. VeraID may adjust these time limits where the complexity of the case reasonably justifies it, informing the Provider of the new period.
The substantial information in the report may be partially withheld where this is strictly necessary to protect the person who submitted it, to prevent retaliation or to avoid affecting an ongoing investigation, provided that such withholding may not be used to prevent the Provider's right of defence absolutely.
9. False Reports and Abuse of the System
Reports must be submitted in good faith, must describe concrete facts and must avoid deliberately false information. Where VeraID determines, following the applicable procedure, that a report was submitted in the knowledge that it was false or for malicious purposes, it may take measures against the account of the Visitor who submitted it, including suspension, without prejudice to any civil or criminal liability that such conduct may give rise to under Colombian law.
The Provider may inform VeraID of reports that they consider false, abusive or submitted with the intention of causing them harm, providing such evidence as they have available, which will be assessed within the procedure described in Chapter 8.
10. Deletion, Suspension and Termination of Accounts
The Provider may delete their account at any time using the functionality available in the application or by contacting VeraID through the channels indicated in Chapter 1.
In addition to the situations described in Chapter 8, VeraID may suspend or terminate a Provider's account where there is breach of these Terms, impersonation, fraud, false information, improper use of the TRU code under Chapter 6, or breach of a security measure. Where the measure does not respond to an urgent situation, VeraID will inform the Provider of the principal reason and will allow them to submit explanations or request review, on the terms of Chapter 8.
Termination of the account does not automatically delete data whose retention is necessary in order to comply with a legal obligation, address a claim, prevent fraud or exercise rights; such retention shall be limited to the purpose and to the period strictly necessary, in accordance with Chapter 11.
11. Protection of the Provider's Personal Data
VeraID, through Foti Enterprise S.A.S., is the data controller responsible for the processing of the Provider's personal data, in accordance with article 15 of the Political Constitution and with Law 1581 of 2012 and its implementing decree, Decree 1074 of 2015, Title 2, Chapter 25.
The personal data that VeraID collects from the Provider includes, as applicable: identification data (full name, identity document, date of birth), contact data (email address, telephone or WhatsApp number), account and Platform usage data, the public profile photograph, and the biometric data described in Chapter 12. For the purposes of their processing, this data is classified as general personal data and sensitive data, the latter being subject to the reinforced regime described in Chapter 12.
The purposes of the processing are: to carry out the identity verificat
VERAID
Terms and Conditions for Visitors
Version 2.0. Date of issue: 13 August 2026. Effective upon publication in the VeraID application and at veraid.org.
Please read these Terms and Conditions carefully before creating an account, accessing or using the VeraID mobile application, the website and related services (the "Service") as a Visitor. By selecting the option "I accept the Terms and Conditions", creating an account or using the Service, you state that you have read, understood and accepted these Terms. If you do not agree with these Terms, you must not create an account or use the Service.
1. Identification of VeraID
The VeraID Service is operated by Foti Enterprise S.A.S., a simplified joint stock company incorporated under the laws of the Republic of Colombia, identified with NIT 900.884.199-4, registered under commercial registration No. 21-544668-12 of the Chamber of Commerce of Medellin for Antioquia, with principal domicile and address for judicial notification at Carrera 42 # 5 Sur - 145, Edificio OFI 7, Barrio La Francia, Medellin, Antioquia, Colombia, judicial notification email [email protected], user support email [email protected] and personal data protection email [email protected]. For the purposes of these Terms, Foti Enterprise S.A.S. may be referred to as "VeraID", "we" or "the Platform". VeraID is a trademark and digital platform operated by Foti Enterprise S.A.S.
These Terms and Conditions for Visitors (the "Terms") govern exclusively the relationship between VeraID and the persons who use the Platform to look up a Provider's TRU code or other functions directed at this user profile (the "Visitors"). The relationship with those who register as Providers is governed by a separate document, the Terms and Conditions for Providers.
2. Nature of the Service
VeraID allows the Visitor to look up the identity verification status of a Provider, expressed through a TRU code, in order to reduce the information asymmetry inherent in a first contact between people who do not know each other. VeraID does not organise, contract, supervise or participate in the services that the Provider offers directly to the Visitor.
3. Eligibility
The Service is directed exclusively at persons over eighteen (18) years of age. By creating an account or using the Service, the Visitor declares that they meet this requirement and that the information they supply is their own, truthful and up to date. VeraID does not knowingly permit the registration of minors; if it reasonably identifies that an account belongs to a minor, it may suspend the account and delete the associated personal data, except where there is a legal obligation to retain it.
4. Visitor Account
In order to use certain functions, the Visitor must create an account and supply truthful, complete and up to date information. The Visitor is responsible for keeping their credentials confidential, for not sharing their account, for immediately reporting any unauthorised use, and for using the Platform in accordance with the law and with these Terms.
The creation of an account constitutes a request addressed to VeraID and does not, in itself, give rise to a right to obtain access to the Service. VeraID may decline to accept any registration request, at its discretion and without any obligation to state the reasons for its decision, given that at this stage no contractual relationship has been formed. The non acceptance of a request does not give rise to liability for VeraID or to any right to compensation. Where a request is not accepted, no amount shall be charged to the applicant and, if any payment has been made, it shall be refunded in full.
5. Looking Up the TRU Code
The Visitor may look up a Provider's TRU code in order to learn their general verification status, as well as the public information that the Provider has authorised to be displayed, in accordance with Chapter 7 of the Terms and Conditions for Providers. This look up does not give the Visitor access to identification documents, to the biometric photograph, or to any other restricted data of the Provider.
6. Scope of the Verification
Seeing that a Provider has "verified identity" or an active TRU code means only that the Provider passed the identity verification process described in the Terms and Conditions for Providers. This does NOT mean, and must not be interpreted as, a guarantee of personal safety, a certification of the Provider's conduct, a recommendation by VeraID regarding the engagement of their services, or the absence of any risk arising from contact or interaction with that Provider. The Visitor retains at all times the responsibility to assess for themselves whether to engage with or relate to a given Provider.
7. Check-ins
Where the Platform offers the check-in function, this consists of a record that the Visitor chooses to create, for example before or during a meeting with a Provider. Check-ins are informational records and do not constitute a real time monitoring service of the Visitor's location or situation. VeraID does not automatically dispatch authorities, emergency services or any third party as a result of a check-in, and does not provide emergency services of any kind. A Visitor who finds themselves in a situation of risk or emergency must contact the relevant authorities or emergency services directly, and must not rely on the check-in function for that purpose.
8. Safety Reports
A Visitor who submits a safety report about a Provider must do so in good faith, on the basis of concrete facts relating to a real interaction, and providing such available evidence as is reasonable. Malicious reports, or reports submitted in the knowledge that they are false, are prohibited.
Where VeraID determines, following the applicable procedure under the Terms and Conditions for Providers, that a report was submitted with deliberately false information, it may take measures against the account of the Visitor who submitted it, including suspension, without prejudice to any civil or criminal liability that such conduct may give rise to under Colombian law.
9. Provider Privacy
The Visitor undertakes to respect the privacy of the Providers whose information they look up through the Platform. Accordingly, the following are expressly prohibited: carrying out scraping or automated extraction of information from the Platform; copying Provider profiles on a mass scale; creating one's own databases from the information looked up; using a Provider's images for facial recognition processes unrelated to VeraID; impersonating a Provider or passing oneself off as one; and improperly publishing, redistributing or disclosing a Provider's information obtained through the Platform.
10. Screenshots and Reproduction
Except for the strictly personal and reasonable uses that are inherent to the purpose of the Service, such as temporarily retaining the result of a look up before a meeting, the Visitor may not reproduce, permanently store, redistribute or disclose without authorisation a Provider's information obtained through the Platform, including screenshots.
VeraID may implement technical measures aimed at limiting screenshots or content downloads where this is technically possible, without such measures guaranteeing the absolute impossibility of copying content from the Platform. The contractual prohibition described in this Chapter applies regardless of the effectiveness of those technical measures.
11. Subscriptions and Payments
Where the Service offers the Visitor subscriptions or other paid functions, VeraID will inform them before purchase of the description of the service, the total price, the billing frequency, the existence of automatic renewal, the method of cancellation, the withdrawal and refund conditions, and the support channels available.
Purchases may be processed through the Apple App Store, Google Play or another payment provider such as RevenueCat, whose operating conditions for billing, renewal and cancellation apply in addition to these Terms, without this eliminating VeraID's legal obligations towards the consumer or the rights recognised by mandatory Colombian law.
The Visitor has the right of withdrawal (retracto) under article 47 of Law 1480 of 2011. The exception provided in paragraph 1 of that article, under which withdrawal does not apply once performance of the service has begun, operates only where the Visitor has given, expressly and specifically at the time of purchase, their agreement for performance of the paid service to begin before the withdrawal period expires. The mere technical activation of a subscription, without that express and specific authorisation from the consumer, is not in itself sufficient for that exception to be considered established. Where the exception does not apply, the Visitor retains their right to withdraw within the legal time limits, and in any event retains the payment reversal rights recognised in article 51 of Law 1480 of 2011 in cases of fraud, unrequested charges or failure to comply with the conditions offered.
12. Protection of the Visitor's Personal Data
VeraID, through Foti Enterprise S.A.S., is the data controller responsible for the processing of the Visitor's personal data, in accordance with article 15 of the Political Constitution and with Law 1581 of 2012 and its implementing Decree 1074 of 2015.
The personal data that VeraID collects from the Visitor includes, as applicable: account data (name, email address, telephone number); the check-in records that the Visitor chooses to create; the content of the safety reports they submit, including any evidence they provide; the notifications and communications generated within the Platform; and the data necessary to process subscription payments, without VeraID directly storing full card details where payment is processed by a third party.
The purposes of the processing are: to enable the registration and operation of the Visitor's account; to enable the look up of TRU codes; to process and follow up on check-ins and safety reports; to manage subscriptions and payments; to handle requests, petitions and complaints; to prevent fraud and improper use of the Platform; and to comply with the legal obligations applicable to VeraID.
Data is retained for the time necessary to fulfil the purposes stated and the applicable legal, accounting or evidentiary obligations, with reasonable security measures in accordance with article 4, subparagraph g), of Law 1581 of 2012. Where VeraID transmits data to a third party data processor, including the payment processors described in Chapter 11, this will be disclosed in the Personal Data Processing Policy, together with the applicable safeguards.
The Visitor, in their capacity as data subject, may at any time exercise the rights to know, update, rectify and delete their personal data, as well as to revoke the authorisation granted, in accordance with article 8 of Law 1581 of 2012, through the channels indicated in Chapter 1.
13. Authorisation for Data Processing
The Visitor's authorisation for the processing of their personal data covers the operation of their account, the creation and management of check-ins, the submission and handling of safety reports, the contact communications necessary to provide the Service, and the transmission of the strictly necessary data to the technology third parties involved in those functions, including payment processors where applicable.
Unlike Providers, the Visitor does not supply biometric data to VeraID as part of the current operation of the Platform. Accordingly, this authorisation does not include or require the processing of the Visitor's biometric data; if in the future a functionality requiring it were introduced, VeraID will request a separate and specific authorisation for that processing, on the same demanding terms provided for Providers.
The corresponding model authorisation is included as Annex 1 to this document.
14. Intellectual Property
The VeraID name, its distinctive signs, logos, designs, interfaces, software and other elements of the Platform are the property of Foti Enterprise S.A.S. or are legitimately used under licence, and are protected by Colombian and international intellectual property law, including Andean Decision 351 of 1993 and Law 23 of 1982. The Visitor may use the Service only for the purposes permitted by these Terms.
15. Visitor Responsibility
The Visitor is responsible for the truthfulness of the information they supply, for the reports they submit, for compliance with the prohibitions described in Chapters 9 and 10, and for the decisions they take regarding their interaction with a Provider. VeraID does not replace the Visitor's personal judgement and does not assume the consequences of the decisions the Visitor takes on the basis of the information looked up on the Platform.
16. Limitation of VeraID's Liability
VeraID does not control, enter into, perform or supervise the meetings, dealings or services that the Visitor agrees with a Provider. Within the limits permitted by law, VeraID shall not be liable for damages arising from those meetings, dealings or services, to the extent that it acts exclusively as a voluntary identity verification intermediary.
This limitation does not release VeraID from liability for damages legally attributable to it through its own wilful misconduct or gross negligence, for unlawful processing of personal data, for the absence of reasonable security measures, or for breach of non waivable rights recognised to the Visitor by Colombian law. Under article 1522 of the Civil Code, the waiver of future wilful misconduct is void, and under article 16 of the same Code, laws of public order may not be derogated from by private agreement.
17. Consumer Protection
These Terms are subject to Colombian consumer protection law. Any clause that produces an unjustified imbalance to the detriment of the Visitor, or that undu
