Gesto

Privacy & data-processing policy

How Gesto processes personal data of operators, console users and contacted debtors, under Colombia's Ley 1581 de 2012 and Ley 1266 de 2008.

Last updated: July 3, 2026. This document may be updated; the current version is the one published on this page.

01Data controller and processor

The Gesto platform is operated by T-Systems LLC, with its principal place of business at 1000 Brickell Ave, Suite 715, Miami, Florida, United States. For the debtor data managed through the platform, the data controller is the creditor entity (the operator) that entrusts its portfolio, and T-Systems LLC acts as the data processor, under the corresponding service agreement and its data-transmission clauses. For console users' data and the data of those who contact us through the website, T-Systems LLC acts as the controller. Contact channel for all personal-data matters: [email protected]. Requests concerning the data of a debt are handled in coordination with the responsible creditor entity.

02Data processed and purposes

Gesto processes identification data (name and national ID number), contact data (phone numbers), obligation data (balance, days past due, agreements and payment commitments) and the records of calls and messages (recordings, transcripts and delivery receipts). This data is used to verify the holder's identity before discussing any debt information, to manage and document the negotiation of payment agreements, to send authorized payment instructions, to handle disputes and requests, and to meet the creditor operator's legal and audit obligations. The data comes from the operator entrusting the portfolio and from what the holder provides during calls. Through the website, Gesto also processes the contact data that prospects submit in the demo form (name, company and email), for the sole purpose of handling their request.

03Text messages and mobile numbers

Gesto sends SMS or WhatsApp messages only to account holders who verbally authorize it during a recorded call, with a maximum of two to three messages per payment agreement. Message and data rates may apply depending on the holder's mobile plan. Mobile phone numbers and text-messaging opt-in consent data are not shared with third parties or affiliates for marketing or promotional purposes, and are never sold. Holders can reply HELP (AYUDA) for assistance or STOP to stop receiving messages. The messaging-program terms are available at www.gesto.com.co/legal/terminos.

04International data transfers

Data is processed and stored on infrastructure located in the United States, operated by T-Systems LLC and by its infrastructure, telephony and messaging providers acting under contract. The delivery of debtor data by the creditor entity in Colombia to T-Systems LLC constitutes an international data transmission, covered by the data-transmission clauses included in the service agreement between the creditor entity and T-Systems LLC, in accordance with Decreto 1377 de 2013. In all cases data travels and is stored encrypted, subject to the security measures described in this policy.

05Data-subject rights

Under Ley 1581 de 2012 and Ley 1266 de 2008, holders can know, update and rectify their data, request proof of authorization, be informed about how their data has been used, revoke authorization or request deletion where applicable, and file complaints with the Superintendencia de Industria y Comercio (SIC). Holders can also request at any time not to be contacted again. To exercise these rights, write to [email protected]; inquiries and claims are handled within the terms and deadlines established by law.

06Security and retention

Data is stored encrypted in transit and at rest. Sensitive identifiers, such as national ID and phone numbers, are additionally protected with blind indexes, and each operator's information is isolated from the others'. Every action on an account is recorded in immutable audit trails. Recordings, transcripts and records are retained for the duration of the service relationship and for the periods needed to handle disputes and legal obligations; once those periods expire they are securely deleted or anonymized.