This translation is provided for convenience. In case of discrepancy, the Spanish version prevails.
Current version: 2026-07-27. Effective date: July 27, 2026.
This Privacy Policy and Personal Data Processing document sets out the guidelines applicable to the collection, storage, use, circulation, retention, updating and deletion of information processed through JoinComu.
Its purpose is to clearly inform data subjects about the use of their personal data, the purposes of processing, the measures adopted to protect information and the mechanisms available to exercise their rights.
This policy is adopted in compliance with the Constitución Política de Colombia, Ley 1581 de 2012, Decreto 1074 de 2015 and all other provisions that modify, complement or regulate the Colombian personal data protection regime.
1. Scope
This policy applies to the processing of information carried out through JoinComu, including directory browsing, community submission, opening external links through the exit route, reports and communications sent through contact channels.
2. Identification of the responsible person
José Hernández
Data controller
Colombia
Privacy email: privacidad@joincomu.com
Website: joincomu.com
Queries, requests and complaints relating to personal data are handled exclusively through electronic means via privacidad@joincomu.com.
3. Essential definitions
For purposes of this policy, personal data means any information associated or associable with a natural person. Processing means any operation on that data, such as collection, storage, use, retention, updating or deletion. Data subject means the person to whom the information refers.
4. Information subject to processing
A community's public information may include name, description, platform, type, category, country, language, content classification, status and slug.
Private or technical information may include the real invitation link, the terms and privacy version and acceptance date, the anti-abuse identifiers stored as hashes, the publisher's email, report reason and comment, and technical metric information when stored.
The real invitation link is kept private on the server. There are no user accounts. The publisher's email is requested but is not displayed publicly: it is used to associate publications and send the temporary management link only when requested. No email is sent when a publication is submitted, expires or is renewed. Age, identification document and date of birth are not stored.
When a community limits access by country, JoinComu may temporarily use the approximate country associated with the connection to decide whether to show the exit link. This check does not use GPS location or create a separate location history.
For new reports, the server temporarily processes an infrastructure- validated network address and a random first-party identifier, transforms the network signal through HMAC and retains only pseudonymous hashes. IP and user-agent values are not stored in the report. Infrastructure providers may process technical logs needed for security and operation. There is no active behavioral advertising.
First-party metrics are optional and operate only after choosing “Accept analytics” and while the configuration is active. To measure views and link openings and deduplicate views, the server uses a random first-party identifier created when analytics are accepted and temporarily processes the public network address validated by Vercel. The two limits remain separate and their values are transformed with HMAC.
Only the pseudonymous result, its version, the community and the event date are retained. IP addresses and user-agent values are not stored; the analytics cookie is first-party, random and deleted on withdrawal; visitors are not tracked across sites and the identity is not shared with advertisers. This pseudonymization reduces exposure, but it is not a promise of complete anonymization. The same approximate identity can add only one view per community during a 24-hour period. Link openings are recorded per event and are not subject to that 24-hour window.
5. Processing purposes
- Publish, classify and display communities.
- Prevent abuse, spam and duplicates.
- Protect private links and measure link openings.
- Optionally measure views and openings when prior analytics consent exists.
- Process reports and maintain operational security.
- Associate publications with the publisher's private email and send the requested temporary management link.
- Answer inquiries, comply with legal obligations and retain evidence of acceptance.
6. Applicable principles
Processing is guided by the principles of legality, purpose, freedom, truthfulness, transparency, restricted access, security and confidentiality, according to the Colombian data protection regime.
7. Authorization and proof of consent
Data must be provided freely and on an informed basis. JoinComu does not request sensitive data as an ordinary condition of service. For new publications, versioned evidence of acceptance of the terms and privacy policy is retained and linked to the submitted community.
The cookie choice is independent: no choice or rejection means necessary cookies only. Withdrawing consent stops future events and deletes the analytics visitor cookie without changing historical metrics already recorded.
8. Rights of data subjects
As a data subject, you may know, access, update, rectify, request proof of authorization, know the use given to your data, revoke authorization when appropriate, request deletion when appropriate, file inquiries and complaints, and go before the Superintendencia de Industria y Comercio after exhausting the internal process.
9. Handling inquiries and complaints
The privacy channel is privacidad@joincomu.com. Include reasonable identification of the requester, a description of the request, contact details for the response and elements that make it possible to locate the information. JoinComu may carry out reasonable identity verification without requiring unnecessary documents.
Inquiries will be answered within a maximum of 10 business days, with a legal extension of up to 5 business days. Complaints will be answered within a maximum of 15 business days from the day after complete receipt, with a legal extension of up to 8 business days.
10. Retention and deletion
No automatic periods that the code does not implement are invented. Data is retained for the reasonable time needed for its purposes. Publications and links may remain while they are active; reports and technical records may be retained for security, fraud prevention, disputes and legal obligations.
The publisher's email is retained while needed to associate and manage their publications. Deleting a publication does not guarantee immediate deletion of the technical contact because the system may retain a contact without publications until cleanup or a valid deletion request is completed.
When information is no longer necessary, it will be deleted, anonymized or blocked as appropriate and in accordance with applicable technical and legal possibilities.
The analytics visitor cookie lasts up to 180 days while consent remains. Pseudonymized metric events are retained for approximately 90 days, and a daily automated task deletes events older than that period. Deleting these event rows does not change the accumulated metric totals.
11. Processors and technology providers
Confirmed providers are Supabase for database and authentication, Vercel for application hosting and execution, Resend for requested transactional access email, Cloudflare for domain, DNS and security, and Google Workspace for general email and communication channels.
12. International transfers or transmissions
Some providers may process information outside Colombia according to their services, configurations and applicable obligations. Exact server locations are not asserted without available evidence.
13. Information security
JoinComu uses access controls, separation of private links, RLS, sensitive server-side operations, link validation, email authentication and anti-abuse controls. No measure guarantees absolute security.
14. Information of minors
JoinComu is not designed to deliberately collect personal data from children. Data from minors must not be submitted without authorization and an appropriate legal basis. This is not equivalent to restricting the viewing of general content when the law permits access.
15. Modifications and effectiveness
Substantial changes to this policy will be communicated before they are implemented when appropriate. Before enabling new providers, advertising or additional collection, this policy must be updated when necessary.