Legal

Terms of Service and Privacy Policy

Privacy Policy

Last updated: March 20, 2026

Carteras Colectivas Profesional ("CCP", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, MCP server, REST API, and related services (collectively, the "Services").

1. Information We Collect

1.1 Information You Provide

  • Account registration information (name, email address)
  • Payment information (processed by Stripe; we do not store card details)
  • Communications you send us (support requests, feedback)

1.2 Information Collected Automatically

  • Log data: IP address, browser type, access times, pages viewed
  • API usage: endpoints called, request timestamps, response times
  • MCP tool usage: tool names invoked, request timestamps (query content is not logged)

1.3 Information We Do Not Collect

  • We do not read, store, or process the content of your AI conversations
  • We do not collect personal financial data or investment positions
  • We do not use tracking cookies for advertising purposes
  • Our MCP server does not access your local filesystem or any data outside the fund database

2. How We Use Your Information

  • To provide and maintain the Services
  • To authenticate API and MCP requests
  • To process payments and manage subscriptions
  • To monitor service performance and prevent abuse
  • To respond to your inquiries and provide support
  • To comply with legal obligations

3. Data Sharing

We do not sell your personal information. We may share information with:

  • Service providers: Stripe (payments), AWS (hosting infrastructure), Vercel (website hosting)
  • Legal requirements: When required by law, regulation, or legal process
  • Business transfers: In connection with a merger, acquisition, or sale of assets

4. Data Retention

  • Account data: retained while your account is active, deleted within 30 days of account closure
  • API/MCP usage logs: retained for 90 days for operational monitoring, then deleted
  • Payment records: retained as required by tax and financial regulations (typically 5 years)

5. Data Security

We implement industry-standard security measures including encryption in transit (TLS), encrypted storage, VPC network isolation, and API key authentication. However, no method of electronic transmission or storage is 100% secure.

6. Your Rights

You may:

  • Request access to your personal data
  • Request correction or deletion of your data
  • Opt out of marketing communications
  • Request data portability

To exercise these rights, contact us at privacy@carterascolectivas.co

7. Cookies

We use essential cookies for authentication and session management. We do not use third-party advertising cookies. Analytics cookies are used only in aggregate form to improve the service.

8. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of changes by updating the "Last updated" date and, for material changes, by email or prominent notice on the website.

MCP Server & API Data Handling

Specific to the Carteras Colectivas MCP Server and REST API

What Our MCP Server Does

The Carteras Colectivas MCP server provides read-only access to publicly available Colombian mutual fund data. It connects to a regulated financial database containing fund performance, risk metrics, fees, and market segmentation data published by fund administrators under Superintendencia Financiera de Colombia oversight.

Data Collection by the MCP Server

All 26 MCP tools are read-only.

The MCP server performs only SELECT queries against the database. It cannot create, modify, or delete any data. The database user has read-only permissions enforced at the database level.

  • Queries are not logged: The content of SQL queries and tool arguments sent via MCP or API is not stored or logged beyond operational request metadata (timestamp, tool name, response time).
  • No conversation data: The MCP server has no access to your AI conversations, prompts, or responses. It only receives structured tool calls and returns structured data.
  • No filesystem access: The MCP server does not read, write, or access any files on your computer. It operates exclusively as a database query interface.
  • No external requests: The MCP server does not make outbound requests to third-party services. All data comes from our own database.
  • Authentication: API keys are validated per request. Keys are stored encrypted in AWS Secrets Manager. Failed authentication attempts are logged for security monitoring.

Data Returned by the MCP Server

All data returned is publicly available financial data about Colombian mutual funds (FICs), including:

  • Fund names, categories, and classifications
  • Assets under management (AUM) and investor counts
  • Historical returns, risk metrics, and fee structures
  • Market segmentation and benchmark comparisons

No personal financial data, individual investor information, or proprietary trading data is accessible through the MCP server or API.

Third-Party Data Sharing

The MCP server does not share any user data with third parties. Infrastructure providers (AWS) process requests as part of hosting but do not have access to application-level data.

Terms of Service

Last updated: March 20, 2026

1. Acceptance of Terms

By accessing or using the Carteras Colectivas Profesional website, MCP server, REST API, or any related services (the "Services"), you agree to be bound by these Terms of Service. If you do not agree, do not use the Services.

2. Service Description

CCP provides data analysis tools for the Colombian mutual fund market, including a web platform, MCP server for AI integration, and REST API for programmatic access. All data is sourced from public regulatory filings and fund administrator reports.

3. Account and API Keys

  • You are responsible for maintaining the confidentiality of your account credentials and API keys
  • Each API key is for use by a single user or application
  • You must not share, publish, or embed API keys in client-side code
  • We reserve the right to revoke keys that violate these terms or usage limits

4. Permitted Use

  • The Services are for informational and analytical purposes only
  • Data provided does not constitute investment advice or recommendation
  • You may use the data for personal analysis, research, and internal business purposes
  • Redistribution, resale, or systematic reproduction of the data requires written authorization

5. Rate Limits and Usage

API and MCP usage is subject to rate limits based on your subscription tier. Exceeding rate limits may result in temporary throttling. Persistent abuse may result in key revocation.

6. Data Accuracy

While we strive for accuracy, data is provided "as is" without warranty. CCP is not responsible for errors in source data from fund administrators or regulatory filings. Historical data may be revised by source providers.

7. Intellectual Property

The CCP platform, indices, analytical methodologies, and proprietary classifications are the intellectual property of Carteras Colectivas Profesional. Underlying fund data is sourced from public regulatory filings.

8. Limitation of Liability

CCP shall not be liable for any direct, indirect, incidental, or consequential damages arising from the use of the Services, including but not limited to investment decisions made based on data provided by the Services.

9. Subscription and Payment

  • Paid subscriptions are billed monthly or annually as selected
  • Payments are processed by Stripe. Prices do not include applicable taxes (IVA 19%)
  • You may cancel your subscription at any time; access continues until the end of the billing period
  • Refunds are handled on a case-by-case basis

10. Termination

We reserve the right to suspend or terminate access to the Services at our discretion, including for violation of these terms, non-payment, or abusive usage patterns.

11. Governing Law

These terms are governed by the laws of the Republic of Colombia. Any disputes shall be resolved in the courts of Bogota, Colombia.

12. Contact

For questions about these terms, contact us at info@carterascolectivas.co

RNAMV · Resolucion 0485 de 2017 · Superintendencia Financiera de Colombia

Miembro AmCham Colombia · Colombia Fintech

© 2026 Carteras Colectivas Profesional · Todos los derechos reservados