<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1632434933919128&amp;ev=PageView&amp;noscript=1">
Privacidad y seguridad en cada proceso. Consulta nuestra polĂ­tica de datos personales.
29 July 2026

RENTING COLOMBIA S.A.S. (the “Company”), a business establishment identified with NIT No. 811.011.779-8, with principal domicile at Carrera 52 # 14 – 30 Etapa 2, Office 340, Medellín, Colombia, national toll-free line 01 8000 524 444, PBX (604) 514 44 44, email address servicio@rentingcolombia.com, recognizes the importance of the security, privacy, and confidentiality of the personal data of its customers, users, employees, suppliers, shareholders, business partners, and, in general, all of its stakeholders with respect to whom it processes personal information. Therefore, in compliance with constitutional and legal provisions, it has adopted this PERSONAL DATA PROCESSING POLICY.

29 July 2026

1. Applicable Regulations

The main regulations currently in force in Colombia regarding personal data protection are listed below. The Company is fully committed to complying with such regulations, which have been taken into account for the purposes of developing this Policy and the Comprehensive Personal Data Management System of Grupo Cibest.

  • Article 15 of the Political Constitution of Colombia

  • Statutory Law 1266 of 2008

  • Law 1273 of 2009

  • Statutory Law 1581 of 2012

  • Decree 1377 of 2013

  • Decree 886 of 2014

  • Decree 1074 of 2015

  • Title V of the Single Circular of the Superintendence of Industry and Commerce (SIC)

29 July 2026

2. Context and Scope

In accordance with Article 15 of the Political Constitution of Colombia, all persons have the right to know, update, and rectify the information held about them in data banks. Law 1581 of 2012 established the general personal data protection regime in Colombia, developing the constitutional principles under which every person has the right to know, update, and rectify personal information stored in databases or files (manual or automated), and to receive truthful and verifiable information.

At the Company, as data controllers or processors, as applicable, we have special regulations concerning the protection of the data of our stakeholders, and we define processes and policies intended to ensure trust, security, and quality in the use of information. The Company receives, records, preserves, modifies, reports, consults, delivers, shares, and deletes information with the authorization of its data subject.

The data allow us to offer and provide information on products and services; to consult, report, and update information before information and risk operators; to update the status of contractual relationships; to comply with agreed obligations; and to prevent the risks of money laundering and terrorist financing, among others. Renting Colombia S.A.S. obtains the data subject’s authorization through different means, such as written or verbal authorization, or through various virtual means, for the purposes described in this Policy.

Likewise, in the development of its activities and management, and in order to provide business collaboration among the companies of the group, the Company may, during the performance of its activities, process personal data jointly with the entities that belong or may come to belong to Grupo Cibest, or with any person who represents its rights or may in the future hold the status of creditor, assignee, or any other capacity vis-Ă -vis the data subjects. The Company, the entities that belong or may come to belong to the Group in accordance with the law, their affiliates and/or subsidiaries, or the entities in which they directly or indirectly hold equity interests or are associates, domiciled in Colombia and/or abroad, shall be understood to be part of Grupo Cibest.

29 July 2026

3. Addressees

This Policy is addressed to our customers, users, employees, suppliers, business partners, and, in general, our stakeholders whose personal information is processed by the Company.

29 July 2026

4. Definitions

The following definitions shall be taken into account for the purposes of this Policy:

  • Authorization: the prior, express, and informed consent of the Data Subject to carry out the Processing of personal data.

  • Privacy Notice: the verbal or written communication whose purpose is to inform the data subject about the Company’s data protection policy.

  • Database: an organized set of personal data subject to processing.

  • Successor in Interest: a person who has succeeded another due to the latter’s death (also understood as heirs or legatees).

  • Personal Data: any information linked or that may be associated with one or more identified or identifiable natural persons.

  • Public Data: data that the law or the Constitution determines to be public, as well as all data that is not semi-private or private.

  • Private Data: data that, by its intimate or reserved nature, is only relevant to the data subject.

  • Semi-Private Data: data that is not intimate, reserved, or public in nature and whose knowledge or disclosure may be of interest not only to its data subject but also to a certain sector or group of persons.

  • Sensitive Data: data that affects the privacy of the data subject or whose improper use may give rise to discrimination.

  • Data Processor: a natural or legal person, public or private, who, by itself or in association with others, processes personal data on behalf of the data controller.

  • Data Controller: a natural or legal person, public or private, who, by itself or in association with others, performs the processing of personal data.

  • Data Subject: a natural person whose personal data are subject to processing. For the Company, the Data Subjects shall be customers, users, employees, suppliers, business partners, shareholders, visitors, our stakeholders, and any other natural person whose data are processed by the Company, whether directly or indirectly.

  • Data Transfer: occurs when the controller and/or processor of personal data, located in Colombia, sends information or personal data to a recipient who is, in turn, a data controller and is located within or outside the country.

  • Data Transmission: the processing of personal data that entails the communication thereof within or outside the territory of the Republic of Colombia when its purpose is the performance of processing by the processor on behalf of the controller.

  • Processing: any operation or set of operations performed on personal data, such as collection, storage, use, circulation, or deletion.

29 July 2026

5. Guiding Principles for the Processing of Personal Data

The Company undertakes to process the personal data of Data Subjects in accordance with the following principles:

  • Principle of legality in data processing matters: the Company is aware that the processing referred to in Law 1581 of 2012 is a regulated activity that must be subject to the provisions established therein and in the other provisions that develop it.

  • Principle of purpose: the Company shall process the data for a legitimate purpose in accordance with the Constitution and the law, which must be communicated to the data subject.

  • Principle of freedom: the Company shall process data only with the data subject’s prior, express, and informed consent. Personal data may not be obtained or disclosed without prior authorization or in the absence of a legal or judicial mandate.

  • Principle of truthfulness or quality: the information subject to processing must be truthful, complete, up to date, verifiable, and understandable. The processing of fragmented data or data that may lead to error is prohibited within the Company.

  • Principle of transparency: the Company acknowledges that Data Subjects have the right to obtain, at any time and without restriction, information regarding the existence of data concerning them.

  • Principle of restricted access and circulation: processing is subject to the limits arising from the nature of personal data and from Law 1581 of 2012 and the Constitution. Accordingly, processing may be carried out only by persons authorized by the data subject and/or by the persons provided for by law. Except for public information, the Company shall not make personal data available on the Internet or other means of mass dissemination or communication, unless access is technically controllable so as to provide restricted knowledge only to data subjects or third parties authorized under Law 1581 of 2012.

  • Principle of security: the Company shall handle the information subject to processing referred to in Law 1581 of 2012 with the technical, human, and administrative measures necessary to provide security to the records, preventing their alteration, loss, consultation, use, or unauthorized or fraudulent access.

  • Principle of confidentiality: all persons involved in the processing of personal data that is not public in nature are required to guarantee the confidentiality of the information, including after the end of their relationship with any of the activities comprising the processing, and may only provide or communicate personal data when this corresponds to the development of activities authorized under Law 1581 of 2012 and under the terms thereof.

29 July 2026

6. Authorizations

The Company shall request authorization in such a manner that the Data Subject grants prior, express, and informed consent for the processing to which his or her personal data are subject.

Authorization may also be obtained from unequivocal conduct by the data subject that reasonably allows the conclusion that the data subject granted consent for the processing of his or her information. Such conduct must clearly manifest the intention to authorize the processing.

The data subject’s consent may be obtained by any means that may be subject to subsequent consultation, such as written, verbal, or virtual communication, or by unequivocal conduct.

By virtue of its nature and corporate purpose, the Company receives, collects, records, preserves, stores, modifies, reports, consults, delivers, transmits, transfers, shares, and deletes personal information, for which it obtains the data subject’s prior authorization.

The Company, as operator of the LOCALIZA RENT A CAR franchise, shall request authorization from customers linked through the franchise to transfer the data subject’s personal data, nationally and internationally, to Localiza Rent a Car Brasil as franchisor.

The authorization granted by the Data Subjects to the Company allows, among other things, the fulfillment of the following purposes: offering and providing information on products and services, as well as consulting, reporting, and updating their data before information and risk operators; updating current contractual relationships and complying with agreed obligations, among others (see Section 7, Purposes). The Company shall appropriately preserve evidence of such authorizations, safeguarding and respecting the principles of privacy and confidentiality of information.

Likewise, in the Company, when dealing with information related to the following types of data, the following special considerations shall apply:

a. Sensitive Data

For the processing of sensitive data, the Company shall inform the data subject of the following:

  • For the processing of this type of information, the data subject is not required to give authorization or consent.

  • The type of sensitive data to be requested shall be explicitly and previously disclosed.

  • The processing and the purpose to be given to the sensitive data shall be communicated.

  • Authorization for sensitive data shall be prior, express, and clear.

 

b. Data of Children and Adolescents.

The Company shall ensure that the processing of this type of data is carried out in accordance with the rights of children and adolescents. In this regard, it shall protect their special status and ensure respect for their fundamental rights, pursuant to Articles 5, 6, and 7 of Law 1581 of 2012, and Articles 6 and 12 of Decree 1377 of 2013, and any other regulations that amend or supplement them.

For purposes of complying with the foregoing, the Company shall act in accordance with the following:

Authorization shall be requested from the legal representative of the child or adolescent after the minor has exercised his or her right to be heard, whose opinion shall be assessed taking into account maturity, autonomy, and ability to understand the matter, for purposes of processing his or her personal data.

The optional nature of answering questions regarding the data of children or adolescents shall be disclosed.

The data subject to processing and the purpose thereof shall be explicitly and previously disclosed.

The Company informs all its stakeholders that, pursuant to Article 10 of Law 1581 of 2012, the data subject’s authorization shall not be necessary in the following cases:

1. Information required by a public or administrative entity in the exercise of its legal functions or by court order.

2. Data of a public nature.

3. Cases of medical or health emergency.

4. Processing of information authorized by law for historical, statistical, or scientific purposes.

5. Data related to the Civil Registry of Persons.

29 July 2026

7. Purposes

The following are the main purposes for which the Company processes personal information:

Customers and/or Users

  • To establish, maintain, and terminate the contractual relationship.

  • To comply with and enforce the obligations arising from commercial agreements between the Company and the customer.

  • To know their financial, commercial, and credit behavior and compliance with their legal obligations.

  • To carry out all necessary actions aimed at confirming and updating the customer’s information.

  • To validate and verify the customer’s identity for the offer and administration of products and services, as well as to share the information with various market participants.

  • To offer and provide products or services through any means or channel according to the customer’s profile and technological developments.

  • To provide information to the entities of Grupo Cibest for the offer of current and future commercial campaigns, promotion of products and services, whether proprietary or third-party, and other communications necessary to keep the customer informed and updated by means of telephone calls, text messages, email, Facebook, Twitter, Instagram, or any integrated social network or instant messaging service, among others.

  • To carry out collection management and portfolio recovery, whether directly or through a third party hired for that purpose.

  • To provide commercial, legal, product, security, service, or any other type of information.

  • To share customer information with the Company’s business partners in order to access or redeem benefits granted for the acquisition of goods and services.

  • To know the customer’s location, geolocation, and contact details for notification purposes related to security, monitoring, offering of benefits, and commercial offers.

  • To perform commercial, statistical, risk, market, and financial analyses and research, including contacting the customer for these purposes.

  • To know the status of transactions (active, passive, or of any nature), or those that the customer may enter into in the future with any entity of Grupo Cibest, with other financial or commercial entities, with any agent or participant in the financial market, information operator, database administrator, or any other similar entity that may be established in the future and whose purpose is any of the foregoing activities.

  • To prevent money laundering and terrorist financing, as well as to detect fraud, corruption, and other illegal activities.

  • To perform, validate, authorize, or verify transactions, including, when required, the consultation and reproduction of sensitive data such as fingerprint, image, or voice, among others.

  • To conduct satisfaction surveys regarding the services provided or products sold.

  • To consult fines and sanctions before the different administrative and judicial authorities or public databases whose function is the administration of data of this nature.


Suppliers and Business Partners

  • The information requested from the supplier or business partner may include information of the natural or legal person, as applicable. Likewise, information may be requested from the employees of the supplier or business partner who are engaged in performing any function or relationship with the Company and who, due to the work performed, require access to the organization’s facilities, applications and/or systems, or others.

  • To carry out the onboarding process of the supplier or business partner with the Organization, developing internal procedures, including relationship, accounting, financial, commercial, logistics, and other procedures.

  • To manage and verify commercial and reputational background and the risks of money laundering and terrorist financing, as well as to detect and/or prevent fraud, corruption, and other illegal activities by the supplier or its employees in relation to the Company’s operation.

  • To manage and strengthen contractual relationships with the supplier or business partner, allowing greater control over the obligations assumed by the parties.

  • To review and evaluate the results of the supplier or business partner, in order to strengthen contracting processes within the Company.

  • To offer and provide products or services through any means or channel according to the profile of the supplier or business partner and according to technological developments.

  • To perform commercial, statistical, risk, market, and financial analyses and research based on the results of the supplier or business partner.


Applicants

  • To conduct the entry evaluation and onboarding process of the applicant.

  • To verify the personal, family, employment, professional, and historical information of candidates participating in the Company’s different processes, and compliance with constitutional, legal, and regulatory standards.

  • To prepare demographic, social, and economic statistics and update personal data.

  • To invite applicants to other selection processes.

  • To enter into agreements with third parties that facilitate fulfillment of these purposes and any other legitimate purpose that enables fulfillment of the purposes defined in this Policy.


Employees

  • The processing of the personal information of our employees is intended to manage the existing employment relationships with them, as well as to develop the different activities established by the organization. Among these, the following are highlighted:

  • To comply with the obligations and rights arising from its activity as employer, and with the activities inherent to its main and related corporate purpose, which may be performed directly or with the support of third parties with whom the information shall be shared for purposes related to the subject matter of the contract.

  • To share personal data with national or foreign authorities (judicial or administrative) when the request is based on legal, procedural, and/or tax reasons.

  • Access and authorization of the benefits established by the employer, according to the requirements defined in each case.

  • Consultation of their data in internal control lists, in compliance with national regulations and internal policies associated with the System for the Prevention of Money Laundering and Terrorist Financing Risk, as well as compliance with the ethics and integrity standards established by the Company.

  • To process THE EMPLOYEE’s information in connection with his or her relationship with employee funds, mutual investment funds, banks, insurance brokers, entities related to Grupo Cibest and family compensation funds, or other third parties performing functions similar to those of such entities, or that may offer products of interest to THE EMPLOYEE and to which THE EMPLOYEE has previously authorized access to his or her information.

  • In the case of former employees, the Company shall store, even after termination of the employment contract, the information necessary to comply with obligations that may arise pursuant to the employment relationship that existed under Colombian law, as well as to provide employment certificates requested by the former employee or by third parties before whom he or she is undergoing a selection process.


Shareholders

  • The information and personal data of shareholders, including personal and contact information, as well as the information and documentation provided through virtual channels, telephone channel, email, and information updates, shall be collected, consulted, updated, modified, and processed directly by the Company and/or by the third parties designated by it, for the following purposes:

  • To comply with the obligations and rights arising from its capacity as Issuer and Depositor, respectively.

  • To carry out the comprehensive administration activities of the shareholders’ registry book.

  • To provide information related to procedures, complaints, and requests of shareholders.

  • To provide access to information to judicial or administrative authorities that request such data in the exercise of their functions.

  • To manage the risk of money laundering and terrorist financing and corruption.

  • To comply with the activities and purposes necessary for the issuer–shareholder relationship.


Access to Buildings, Surveillance, and Security of Facilities

  • To have information on each of the employees, external personnel, and outsourcing personnel working for the Company and on visitors entering the organization’s facilities.

  • To control and identify access to agencies, administrative offices, and other operational facilities.

  • To maintain security and access control to facilities and agencies.

  • The Company informs all data subjects that data collected directly at security points of administrative offices, buildings, branches, and other facilities, which are provided in security personnel documents, and data obtained from video recordings made inside or outside the Company’s facilities, are used for the security of persons, property, and facilities.

29 July 2026

8. Information Storage

Information is stored physically and/or digitally in media and environments that have adequate controls for the protection of personal data. These include physical and information security, technological, and environmental controls in restricted areas within Company-owned facilities and/or document centers managed by third parties.

29 July 2026

9. Duration of Processing and Validity of Databases

Personal data shall be subject to processing by the Company during the contractual term in which the Data Subject has the product, service, contract, or relationship, plus the term established by law.

29 July 2026

10. Rights of the Data Subject

The Data Subjects whose information is subject to processing by the Company may:

  • Know, update, rectify, delete, or revoke their personal data and be informed of the processing that the Company performs on the personal data.

  • Request proof of the authorization granted to the Company, except where it is expressly exempted as a requirement for the Processing.

  • Be informed by the Company, upon request, regarding the use it has made of their personal data.

  • Submit requests and claims related to the regulations in force on Personal Data Protection.

  • Request revocation of the authorization and/or deletion of personal data if it is determined that the Company has engaged in conduct contrary to current regulations. The deletion or revocation request shall not proceed when data subjects have a legal or contractual duty to remain in the Company’s database.

  • Access, free of charge, their personal data that have been subject to Processing.

In accordance with Article 20 of Decree 1377 of 2013, the aforementioned rights may be exercised by the following persons:

  • By the data subject, who must sufficiently prove his or her identity through the different means made available by the controller.

  • By their successors in interest, who must prove such capacity.

  • By the representative and/or attorney-in-fact of the data subject, upon proof of representation or power of attorney.

  • By stipulation in favor of another or for another.

  • The rights of children or adolescents shall be exercised by the persons authorized to represent them.

29 July 2026

11. Duties of RENTING COLOMBIA S.A.S.

The Company, as controller of the personal data stored in its databases, undertakes to:

  • Guarantee the data subject the full and effective exercise of his or her rights.

  • Request and keep a copy of the authorization granted by the data subject or evidence thereof.

  • Inform the data subject about the purposes of the collection, the uses of his or her personal data, and his or her rights by reason of the authorization granted.

  • Preserve the information under secure conditions to prevent its alteration, loss, consultation, use, or unauthorized access.

  • Ensure that the information provided to third parties or data processors is truthful, complete, accurate, up to date, verifiable, and understandable.

  • Update the information held by any third party or processor with respect to all developments related to the data supplied and adopt the measures necessary for the information to be up to date.

  • Rectify the information when it becomes aware that it is incorrect.

  • Ensure that the third parties and/or processors of the personal information for which the Company is responsible have effective measures and policies to guarantee the proper processing of such information. Likewise, it shall require them to adhere to and apply the provisions of this Personal Data Processing Policy and the other guidelines established by the Company, or to certify that their internal policies contain at least the provisions set forth herein. If it is not possible to issue such certification, the Company must verify that the internal policies of the third parties and/or processors include security and/or privacy criteria equivalent or superior to those provided herein. In this regard, the third parties and/or processors must adopt security and privacy measures and conditions for personal data shared with them, at least at the same level of protection adopted by the Company.

  • Process the inquiries and claims filed in accordance with the provisions of this Policy and the law.

  • Inform the data protection authority when security breaches occur and there are risks in the management of the information of data subjects.

29 July 2026

12. Handling of Inquiries, Complaints, and Claims

Data Subjects who need to make an inquiry, complaint, or claim may use the following mechanisms, which shall be handled by the Company’s Comprehensive Service Center:

a. Inquiries

Data subjects, their successors in interest, or any other person who may have a legitimate interest may request to be informed about the data subject’s personal data stored in any of the Company’s databases.

In accordance with the foregoing, the Company shall guarantee the right of inquiry by disclosing the personal information linked to the data subject.

Inquiries concerning access to information, evidence of the authorization granted by the data subject, uses and purposes of personal information, or any other inquiry related to personal information provided by the data subject, must be submitted through the channels enabled by the Company.

The inquiry shall be answered within a maximum term of ten (10) business days counted from the date of receipt thereof.

When it is not possible to answer the inquiry within the term provided, the interested party shall be informed of the reasons for the delay and the date on which the inquiry will be answered, which shall not exceed five (5) business days following the expiration of the first term, in accordance with Article 14 of Law 1581 of 2012.


b. Claims

Correction, Update, Deletion, and Revocation

Data subjects, their successors in interest, or any other person with a legitimate interest who considers that the information contained in any of the Company’s databases should be corrected, updated, or deleted, or who notices a possible breach of the duties established in Law 1581 of 2012 and its regulatory decrees, may submit a claim following the requirements of Article 15 of the same law.

Requirements to submit a claim:

  • Identification of the data subject or of the person filing the claim, indicating his or her name and identification number.

  • Clearly and expressly describe the reason for the claim, setting forth the facts that gave rise to it and submitting the documents intended to be relied upon.

  • Evidence the legitimate interest under which the person filing the claim is acting and attach the relevant supporting documents, if necessary.

  • Indicate the telephone number and physical or electronic address to which notice must be given and the response to the request must be sent.

In any case, if the claim is incomplete, the interested party shall be required, within five (5) days following receipt thereof, to remedy the deficiencies. If two (2) months have elapsed from the date of the request without the applicant submitting the required information, the Company shall understand that the claim has been withdrawn.

When the Company is not the competent entity to resolve the claim submitted, it shall transfer the claim to the appropriate party within a maximum term of two (2) business days and inform the interested party of such situation.

If the claim is received complete, a note stating "in progress" and the reason for it shall be included in the database within a term not exceeding two (2) business days. This note shall remain until the claim is resolved and shall be adjusted in accordance with internal procedures.

The maximum term to address the claim shall be fifteen (15) business days counted from the day following the date of receipt. When it is not possible to address it within such term, the interested party shall be informed of the reasons for the delay and the date on which his or her claim will be resolved, which in no case may exceed eight (8) business days following the expiration of the first term.

Data subjects, their successors in interest, or any other person with a legitimate interest may file a complaint with the Superintendence of Industry and Commerce, but only after exhausting the inquiry or claim procedure before the Company as controller and/or any processor, in accordance with Article 16 of Law 1581 of 2012.

Deletion of Information

If requesting deletion of all or part of his or her personal information, the data subject should bear in mind that the Company shall analyze the request made. However, deletion of the information shall not proceed if the data subject has any legal or contractual duty to remain in the database managed by the Company.


Revocation of Authorization

If requesting revocation of the authorization for his or her personal data, the Company shall analyze the request made and inform the data subject whether such revocation proceeds.

However, revocation of the authorization shall not proceed if the data subject has any legal or contractual duty to remain in the database managed by the Company.

The inquiries and claims submitted shall be processed in accordance with internal processes and procedures.


Service Channels for Inquiries, Complaints, and Claims

Petitions, inquiries, and claims submitted by Data Subjects whose personal data are processed by the Company for the purpose of exercising their rights to know, update, rectify, and delete their data, or to revoke authorization, must be addressed to:

  • The email address servicio@rentingcolombia.com

  • The Risk Area of Renting Colombia at the following address: Carrera 52 # 14-30 Etapa 2, Office 340, MedellĂ­n, Colombia.

29 July 2026

13. Transfer and Transmission of Personal Data

The Company may, from time to time, as controller of the personal information stored in its databases and in furtherance of the purposes described in this document, carry out national or international transfers or transmissions of data.

The Company is committed to verifying the level of protection and security standards of the country receiving the personal information, making the declaration of conformity (when applicable), and entering into a transfer agreement or other legal instrument that guarantees the protection of the personal data subject to transfer.

By virtue of this exchange relationship, the Company has adopted various guidelines for relationships with third parties in order to protect the information subject to this activity.
In order to protect the information, the Company shall verify whether the Superintendence of Industry and Commerce has included the respective country in the list of countries that offer an adequate level of data protection, or shall review the regulations in force in the country receiving the information, to determine whether suitable conditions exist to guarantee adequate levels of security for the information subject to transmission or transfer.

Relationships with Third Parties and/or Processors

In furtherance of this Policy and the internal provisions for the proper handling of personal data, the Company shall ensure that the third parties with which it engages or with which it establishes commercial or employment relationships or alliances adapt their conduct to the personal data protection regime in Colombia.

In view of the foregoing, the Company, without prejudice to all documentation, forms, and means provided for requesting authorization for processing, privacy notices, records, and contractual and/or legal protections, may request suitable and relevant information from third parties and/or processors to verify and observe compliance with the provisions contained in this Policy and in the personal data protection regime in Colombia.

In this regard, the Company may require third parties and/or processors to evidence, before, during, or after the relationship that binds them, compliance with the requirements of the personal data protection regime. Accordingly, an occasional or periodic review and supervision of compliance with legal and/or contractual requirements may be requested, through evidence or supporting documents of the management performed, visits to the third party’s facilities, among other activities that may be coordinated to validate compliance.

29 July 2026

14. Cookies

The Company, in order to improve its service on websites and digital applications, uses first-party and third-party cookies to optimize the experience of customers and users, monitor statistical information, and present content and advertising related to users’ preferences when they browse our website, platforms, and/or technological and/or digital applications.

The information collected through cookies is encrypted and shall not be used to identify and/or disclose the user’s information. Likewise, users’ data such as debit or credit card numbers, or other financial or credit information, are not collected.

29 July 2026

15. Supplementary Policies and Guidelines and Amendments to this Policy

By virtue of this Policy, the Company may develop policies on specific matters (for example, a cookie policy), as well as guidelines, directives, and circulars aimed at its implementation, provided that they are consistent with the regulatory framework and this Policy.

This Policy may be amended at any time in order to adapt it to new practices that are developed or to legislative or case-law developments in the matter. Any update shall be made available to the Data Subjects on the website www.rentingcolombia.com , in the Data Processing Policy section, or through any other means deemed relevant, indicating the effective date of the corresponding amendment or update, as applicable.

29 July 2026

16. Effective Date

This Personal Data Processing Policy shall become effective as of the date of its approval (June 25, 2024).