Legal
Personal data processing policy
Last updated: August 30, 2026
1. Data controller
Mercury is an application developed and operated by CHL Group. Article 13 of Colombian Decree 1377 of 2013 requires the data controller to be fully identified, and Google Play requires the policy to name the correct developer entity.
[PENDING] State the exact legal name, tax ID (NIT), physical address, city, country, contact email address and telephone number of the data controller.
2. Scope and who this applies to
This policy applies to personal data processed through the Mercury mobile application, identified as com.chlgroup.mercury on Android and under the same bundle identifier on iOS.
Mercury is an internal work tool for field operators. It is not aimed at the general public and does not allow self-registration: credentials are issued by the employing organization to each worker. Data subjects are therefore employees or contractors of the organizations that use Mercury.
The application is not directed at children and does not knowingly collect data from minors.
3. What data is collected, and how
3.1 Identification data
First name, last name and email address. The email address is the sign-in credential. Operators do not type these in: they arrive with the account their organization creates, and cannot be modified from within the application.
3.2 Location data
Precise device location, travel speed and the phone battery level. These are collected through the operating system location services, after the operator grants the corresponding permission.
Mercury collects location data even when the app is closed or not in use. Battery level is transmitted alongside location to flag a device that may run out of charge during a shift.
3.3 Content generated during work
- Photographs captured as task evidence, taken with the camera or selected from the device gallery.
- Signatures, text notes and barcodes recorded as evidence.
- Comments written inside a task to coordinate with the dispatch team.
Evidence is mandatory when the task requires it: without it, the task cannot be completed. Comments are voluntary.
3.4 Notification identifier
If the operator accepts notifications, the application obtains a push token associated with their device. If notifications are declined, no such identifier is generated.
3.5 What Mercury does NOT collect
Mercury does not collect sensitive data as defined by article 5 of Colombian Law 1581 of 2012, does not access the contact book, does not collect advertising identifiers, does not track users across applications, and does not build profiles for advertising or behavioural analytics.
4. Purposes of processing
The data described above is processed exclusively for the following purposes, all of them tied to the performance of the employment or contractual relationship and to the employing organization’s field operation:
| Data | Purpose |
|---|---|
| Name, surname and email | Authenticate the user and attribute each action to the person who performed it |
| Location and speed | Show dispatchers which operators are available and where; track the progress of a task in flight; verify that a stop was serviced at the correct place |
| Battery level | Warn dispatchers that a device may run out of charge during a shift |
| Photos, signatures, notes and codes | Evidence the completion of a task under the requirements defined by the organization |
| Comments | Operational coordination between the operator and the dispatch team |
| Notification identifier | Deliver task assignment and task change alerts |
The data is not used for advertising, is not sold, and is not transferred to third parties for their own commercial purposes.
5. Background location
This section details the processing of location data, given its particular sensitivity and in compliance with the specific requirements of Google Play and App Store Review Guideline 5.1.5.
Mercury collects location data to show the operator’s position to the dispatch team and to track tasks in progress, even when the app is closed or not in use.
This feature is essential to the application. Without it, dispatchers cannot assign work by proximity, monitor the progress of a route, or confirm that a stop was serviced at the correct place.
5.1 Operator control
- Tracking is switched on and off from the profile inside the application, at any time and without intermediaries.
- While tracking is off, no location is recorded, and the application remains fully functional in every other respect.
- While tracking is on, the operating system displays a persistent notice in the notification bar.
- Before requesting the permission, the application shows a prominent disclosure explaining the background use.
5.2 Technical boundary
The map provider that renders a task’s stops does not receive the operator’s location: the application does not hand it over.
6. Device permissions
| Permission | Purpose |
|---|---|
| Precise location, including in the background | Track the operator during their shift |
| Notifications | Alert when a task is assigned or modified |
| Camera | Capture evidence photographs |
| Photo library | Attach existing photographs as evidence |
All permissions are requested at runtime and can be revoked from the operating system settings. Revoking the location permission prevents tracking but does not prevent signing in or reviewing assigned tasks.
7. Who the data is shared with
All information is transmitted to the server of the organization operating Mercury, which is where the dispatch team consults it. Beyond that destination, the application shares data with only two providers, in the narrow scope described below:
| Provider | What it receives |
|---|---|
| Push notification service | Only the device identifier, required to deliver the alert. It receives no location, evidence or comments. |
| Map service | Only the coordinates of a task’s stops, in order to draw the map. It does not receive the operator’s location. |
These providers act as data processors and are contractually bound to afford the data a level of protection equivalent to the one described in this policy, and to process it solely under the controller’s instructions.
[PENDING] Confirm whether the organization’s server shares information with any additional third party (hosting, analytics, backup, subcontractors) and identify it here together with the purpose. App Store Review Guideline 5.1.1 requires identifying every third party that receives user data.
[PENDING] State whether data is stored or processed outside Colombia. If so, describe the international transfer and its legal basis under article 26 of Law 1581 of 2012.
8. Information security
All communication between the application and the server is encrypted. The device operating system blocks cleartext connections by default, and the application declares no exception to that rule.
Only the operator’s session is stored on the device, and it is erased on sign-out. Authentication uses session tokens; the application does not store the user’s password on the device.
9. Retention and deletion
App Store Review Guideline 5.1.1 requires the retention and deletion policy to be explained, and item 6 of article 13 of Decree 1377 of 2013 requires stating the database validity period.
[PENDING] Define the retention period for location records, evidence photographs, notes and comments; whether automatic deletion occurs once that period elapses; and the validity period of the database.
[PENDING] Define what happens to an operator’s data when their relationship with the organization ends, and describe the procedure by which they may request erasure of their personal data.
10. Data subject rights
Under article 8 of Colombian Law 1581 of 2012, the data subject has the right to:
- Access, update and rectify their personal data held by the controller or processor.
- Request proof of the authorization granted to the controller, except where the law waives that requirement.
- Be informed, upon request, of the use made of their personal data.
- File complaints with the Superintendency of Industry and Commerce for breaches of Law 1581 of 2012 and its implementing regulations.
- Revoke the authorization and request erasure of the data where the processing does not respect constitutional and statutory principles, rights and guarantees.
- Access, free of charge, their personal data that has been processed.
11. How to exercise these rights
11.1 Enquiries
Data subjects may consult their personal data by addressing a request to the channel indicated in section 12. Under article 14 of Law 1581 of 2012, the enquiry will be answered within a maximum of ten (10) business days from receipt. Where that is not possible, the requester will be told the reasons for the delay and the date of response, which may not exceed five (5) business days beyond the expiry of the first term.
11.2 Complaints
A data subject who believes their information should be corrected, updated or erased, or who identifies an apparent breach of the law, may file a complaint stating their identity, a description of the facts, a contact address and any supporting documents.
Under article 15 of Law 1581 of 2012, if the complaint is incomplete the requester will be asked within five (5) days of receipt to remedy it; if two (2) months elapse without the requested information, the complaint is deemed withdrawn. The maximum term to answer a complaint is fifteen (15) business days from the day after receipt, extendable by eight (8) further business days, with prior notice of the reasons for the delay.
11.3 Prerequisite before approaching the authority
Under article 16 of Law 1581 of 2012, a data subject may only file a complaint with the Superintendency of Industry and Commerce after exhausting the enquiry or complaint procedure with the data controller.
12. Area responsible for requests
Item 4 of article 13 of Decree 1377 of 2013 requires identifying the area or person in charge of handling data subject petitions, enquiries and complaints.
[PENDING] Designate the responsible area or role, and state the email address, physical address and telephone number to which data subjects should direct their requests.
13. Employee geolocation
Mercury records the operator’s location during their shift, including with the device pocketed and the application closed. Processing employee geolocation data is subject to specific obligations under Law 1581 of 2012 and the doctrine of the Superintendency of Industry and Commerce, distinct from those applying to a consumer application.
In particular, the data subject’s authorization must be prior, express and informed, and cannot be inferred from merely accepting the operating system permission. Processing must further be limited to working hours and to the purposes declared in section 4.
[PENDING] Record that workers were informed in writing about geolocation during working hours, its purposes and its temporal scope, and that they granted prior, express and informed authorization. State the mechanism by which that evidence is retained. Without documented authorization, the processing has no legal basis.
14. Changes to this policy
Any substantial change to this policy will be communicated to data subjects before it takes effect, through the organization’s channels and within the application itself. Where the change affects the purpose of processing, a new authorization will be requested, under the proviso to article 13 of Decree 1377 of 2013.
15. Effective date
This policy takes effect on its date of publication.
[PENDING] State the exact effective date of the policy and the validity period of the database, under item 6 of article 13 of Decree 1377 of 2013.