ARTICLE ONE: DEFINITIONS
For purposes of the interpretation and application of this Policy, the following terms shall have the meaning indicated below:
- Authorization: The prior, express, informed, and unequivocal consent that the Data Subject must provide so that the Company may carry out the Processing of their personal data, except in the cases exempted by Law.
- Privacy Notice: A physical, electronic, or other format document generated by the Company and made available to the Data Subject prior to the Processing of their personal data, informing them of the existence of the applicable data processing policies, how to access them, and the purposes of the intended Processing of their data.
- Database: An organized set of personal data subject to Processing, regardless of the form or manner of its creation, storage, organization, or access, whether held in physical or electronic form.
- Consent: A free, express, specific, and informed manifestation of will by which the Data Subject authorizes the Processing of their personal data.
- Personal Data: Any information linked to, or that may be associated with, one or more identified or identifiable natural persons, such as name, identification number, address, email address, or telephone number, among others.
- Sensitive Data: Personal data relating to the physical or moral characteristics of individuals, or to facts or circumstances of their private life or activity, such as personal habits, racial origin, political ideology, religious or philosophical beliefs, physical or mental health status, and sexual life, among others.
- Data Processor: A natural or legal person, public or private, that alone or jointly with others carries out the Processing of personal data on behalf of the Data Controller.
- Public Access Source: A Database that may be consulted by any person, without restriction, by virtue of special provisions or the very origin of the data.
- Habeas Data: The fundamental right of every person to know the information about them held in Databases, and to demand its rectification, updating, confidentiality, or deletion when applicable, recognized in Article 24 of the Political Constitution of Costa Rica.
- Data Controller: A natural or legal person, public or private, that alone or in association with others decides on the Database and/or the Processing of personal data. For purposes of this Policy, the Company holds the status of Data Controller.
- Data Subject: The natural person to whom the information held in a Database refers, and to whom the rights and guarantees set forth in the Law and in this Policy apply.
- Processing: Any operation or set of operations carried out on personal data, such as collection, storage, use, circulation, transfer, transmission, updating, rectification, or deletion.
- Data Transfer: The sending of personal data by the Data Controller or Data Processor to a third-party recipient, located inside or outside Costa Rica, who in turn becomes a Data Controller.
- Data Transmission: The communication of personal data by the Data Controller to a Data Processor, inside or outside the territory of the Republic of Costa Rica, so that the latter carries out the Processing on behalf of the former.