Personal Data Processing Policy
Last updated: August 14, 2026 · Version 2.0.0
This document is the general framework under which Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services, in accordance with Chilean data protection law. The full detail — data categories per service, purposes, lawful bases, processors, retention periods and per-product annexes — is in the Privacy Policy, which is the binding document in case of any difference. Both are published with frozen, SHA-256-verifiable versioning (section 8).
1. Data controller and DPO
- Controller: Sinapsis SpA — Chilean Tax ID (RUT) 78.327.684-4
- Address: San Martín 924, Office 213, Temuco, Chile
- Privacy and rights channel: admin@sinapsis.in
- Data Protection Officer (DPO): Felipe Mehr — fmehr@sinapsis.in
2. Legal framework
We process personal data in accordance with Chilean Law No. 19.628 (currently in force) and we already adopt the standards of Chilean Law No. 21.719 on Personal Data Protection — fully effective December 1, 2026 — including lawful bases, strengthened rights, breach notification and the DPO role. Law No. 20.584 additionally applies to health data. As best-practice references we consider the EU GDPR, California's CCPA/CPRA and the ISO/IEC 27001 and 27701 frameworks (see the Compliance Notice).
3. Principles we apply
- Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
- Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
- Data minimization (proportionality) — only the data needed for each purpose.
- Accuracy — accurate, complete and up-to-date data.
- Storage limitation — retention periods defined per data type.
- Security (integrity and confidentiality) — technical and organizational measures.
- Proactive accountability — we document and can demonstrate compliance: record of processing activities (RoPA), impact assessments (DPIA) and verifiable versioning of our policies.
- Privacy by design and by default — new modules launch with the most protective settings enabled.
4. What data we process
In summary (full per-service table in the Privacy Policy, section 4):
| Category | Examples | Main purpose |
|---|---|---|
| Identification and contact | Name, email (Google OAuth) | User account, communication |
| Service content | Assistant queries, uploaded documents | Providing the requested service |
| Authorized integrations | Google Calendar events | Only features you expressly authorize |
| Technical and usage data | IP, browser, access logs | Security, operation and improvement |
The corporate site sinapsis.in does not collect sensitive personal data. Some modules of the HumanOS platform do process sensitive categories (for example, health data in Care/Health): always with express consent, reinforced encryption and the conditions described in the annexes of the Privacy Policy. We do not buy data from third parties and we do not use your data for advertising.
5. Data subjects' rights
You can exercise, free of charge, the rights of access, rectification, erasure (deletion), objection, portability, withdrawal of any consent, and temporary restriction (blocking) of processing.
How to exercise them:
- Write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in, stating the right you are exercising and, where applicable, the data or processing involved.
- We may request reasonable information to verify your identity.
- We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.
No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind. If you consider your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency or the competent courts.
6. Processors, third parties and international transfers
We share data only with processors acting on our behalf — under contract, confidentiality and use limitation — and where the law requires it. We do not sell personal data or hand it over for advertising. International transfers are carried out with adequate safeguards (contractual clauses, prior minimization, encryption). The current list of processors and applied safeguards is in the Privacy Policy, sections 11 and 12.
7. Security and incidents
We apply the technical and organizational measures described in the Information Security Policy: encryption in transit and at rest, additional field-level encryption for sensitive health data, least-privilege access control and audit logging. If an incident affecting personal data creates risk for data subjects, we notify the Personal Data Protection Agency and those affected without undue delay.
8. Validity, changes and verifiable versioning
This policy is effective upon publication. Every modification is published on this page with a new date and version number; each version is frozen with its SHA-256 fingerprint in an append-only manifest, so it can always be proven which exact text was in force on a given date.
9. Contact
- Privacy channel: admin@sinapsis.in
- DPO: Felipe Mehr — fmehr@sinapsis.in
- Company: Sinapsis SpA (RUT 78.327.684-4), San Martín 924, Office 213, Temuco, Chile