Privacy Policy
Draft prepared September 2026
This draft is structured to address Colombia's Law 1581 of 2012 and common United States privacy practices. It must be reviewed and completed by qualified counsel before publication.
1. Data controller
Gryfa, 30N South Gould Street, Sheridan, WY 82801, United States, [registration number/EIN or NIT] will be identified as the data controller. Privacy inquiries and requests may be sent to ceo@gryfa.tech.
2. Information collected
We may collect information you submit, such as your name, business email, company information and message, plus limited technical and usage information such as device, browser, IP address and page activity.
3. Purposes and legal bases
Information may be used to answer inquiries, assess service needs, operate and secure the website, maintain business records, comply with law and, with required authorization, send relevant communications.
4. Colombian data-subject rights
Under Law 1581 of 2012 and applicable regulations, data subjects may know, update and correct their personal data; request proof of authorization; learn how data is used; submit complaints to the Superintendence of Industry and Commerce after completing the applicable internal process; revoke authorization or request deletion when legally available; and access their data free of charge.
5. Requests and complaints
Submit requests to ceo@gryfa.tech with sufficient information to verify identity and locate the data. The final policy must state the legally applicable response periods, escalation procedure and complete controller contact details.
6. Service providers and international transfers
Personal data may be handled by vetted technology, hosting, communications and professional service providers under appropriate contractual safeguards. Cross-border transfers or transmissions will follow applicable authorization and data-protection requirements.
7. U.S. privacy practices
Where applicable, the final policy will describe relevant state-specific rights, including access, correction, deletion, portability and opt-out rights, and how authorized agents may submit requests. Gryfa does not state that personal information is sold or shared for targeted advertising unless its actual practices have been verified.
8. Retention, security, cookies and children
Data should be retained only as long as necessary for stated purposes or legal duties. Reasonable administrative, technical and organizational safeguards will be used. The final policy must identify actual cookies and analytics tools. The website is intended for business users and not directed to children.
9. Changes
The finalized policy will show an effective date and explain how material changes are communicated.