Privacy Policy
Last updated: August 12, 2026 · Version 2.0.0
This policy describes how Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services (the "Services"):
| Service | Domain / channel |
|---|---|
| Sinapsis corporate site | sinapsis.in |
| HumanOS — personal & family view | humanos.eco, www.humanos.eco |
| HumanOS — business view | empresa.eco, www.empresa.eco |
| HumanOS — student view | estudiante.humanos.eco |
| QueBot (conversational assistant) | inside HumanOS and via WhatsApp |
| Consulting and development services | per each client agreement |
A single policy governs all Services; Annexes A–D at the end describe the specifics of each one. Every version of this document is published frozen and verifiable through a SHA-256 fingerprint (section 19), so you can always prove which exact text was in force on a given date.
1. Data controller and contact
- Controller: Sinapsis SpA — Chilean Tax ID (RUT) 78.327.684-4
- Address: San Martín 924, Office 213, Temuco, Chile
- General privacy channel: admin@sinapsis.in
- Data Protection Officer (DPO): Felipe Mehr — fmehr@sinapsis.in
The DPO oversees compliance with this policy, handles data subjects' inquiries and channels the exercise of rights (section 14).
2. Legal framework
We process personal data in accordance with:
- Chilean Law No. 19.628 on the Protection of Private Life (currently in force);
- Chilean Law No. 21.719 on Personal Data Protection, fully effective December 1, 2026 — we adopt its standards today, including lawful bases, strengthened rights, breach notification and the DPO role;
- Chilean Law No. 20.584 on Patients' Rights and Duties, for health data;
- Law No. 21.096 (constitutional right to personal data protection, art. 19 No. 4);
- as international best-practice references: the EU GDPR, California's CCPA/CPRA, and the ISO/IEC 27001 and ISO/IEC 27701 frameworks and the NIST Privacy Framework, whose requirements we incorporate where they exceed the local standard.
3. Principles we apply
- Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
- Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
- Data minimization (proportionality) — only the data needed for each purpose.
- Accuracy — accurate, complete and up-to-date data.
- Storage limitation — retention periods defined per data type (section 13).
- Security (integrity and confidentiality) — technical and organizational measures (section 15).
- Accountability — we document and can demonstrate compliance: records of processing activities (RoPA), impact assessments (section 17) and verifiable policy versioning.
- Privacy by design and by default — new modules ship with the most protective settings on.
4. Data we process
Depending on the Service you use (per-service detail in the annexes):
| Category | Examples | Main purpose |
|---|---|---|
| Identification and contact | Name, email, profile photo (Google OAuth) | User account, communication |
| Personal and family data | Phone, address, family members, dependents | Personal/family organization features |
| Health data (sensitive) | Medications, appointments, records in Care/Health modules | Only with explicit consent; Annex A |
| Well-being data | Mood, energy and stress check-ins | Personal trends and insights; never shared |
| Financial data | Recorded payments, obligations, payables | Personal/business financial control |
| Business data | Organizations, roles, KPIs, risks, compliance | Business management (Annex B) |
| Academic data (minors) | Grades, subjects, assignments, goals | Student module (Annex C) |
| Service content | Assistant queries, uploaded documents, notes | Providing the requested service |
| Integration data | Google Calendar events (read/write) | Only the agenda features you authorize |
| Technical and usage data | IP, browser, access logs, features used | Security, operation and improvement |
We do not store card numbers or banking credentials. Biometric data (e.g., camera-based emotion detection) is not active; if ever offered, processing would run locally on your device and only with prior explicit consent.
5. Sources of data
- Directly from you, when you sign up, fill in forms or use the Services.
- From integrations you authorize (e.g., Google OAuth and Google Calendar).
- Automatically, basic technical data when using the Services (IP, browser, logs).
We do not buy personal data from third parties nor enrich profiles from external sources.
6. Lawful bases
We process personal data only when at least one of these bases applies:
- Performance of a contract — to provide the Service you request.
- Consent — free, informed, specific and unambiguous; for optional integrations and for all sensitive data categories (express consent). You may withdraw it at any time without affecting prior lawful processing and without any detriment to your use of the rest of the Service.
- Legal obligation — where a rule requires us to process or retain data.
- Legitimate interest — only for purposes compatible with your rights and expectations (e.g., Service security and abuse prevention), after a balancing test.
7. Purposes
| Purpose | Lawful basis |
|---|---|
| Provide, maintain and improve the Services | Contract |
| Process queries with AI assistants (with human oversight) | Contract |
| Manage authorized integrations (Google Calendar, etc.) | Consent |
| Process health data in Care/Health modules | Express consent |
| Alerts, metrics and reports for the user | Contract |
| Service communications (updates, security) | Contract / legitimate interest |
| Security, fraud and abuse prevention | Legitimate interest |
| Compliance with legal obligations (tax, health) | Legal obligation |
We do not use your data for advertising. We do not profile you with legal effects nor make solely automated decisions that significantly affect you; AI assistants are guidance tools under human oversight.
8. Artificial intelligence
- We use Anthropic (Claude) models to generate assistant responses (QueBot and HumanOS AI features).
- Before sending text to the AI provider, a PII scrubber automatically removes direct identifiers (national ID, phone numbers, emails, addresses) when the feature does not require them.
- Your data is not used to train our or third parties' AI models.
- AI responses are for guidance only: they are not legal, financial, medical or other professional advice. See our Responsible AI Policy.
9. Google user data (Limited Use)
Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
- We only access the Google data needed for the features you authorize.
- We do not sell Google data and do not use it for advertising.
- No humans read this data except with your express consent, for security, to comply with law, or for aggregated and anonymized internal operations.
- You can revoke access at any time from your Google account settings.
10. Children and adolescents
The HumanOS Student module may be used by minors under 18 only under these conditions (detail in Annex C):
- Sign-up and linking require the consent of a parent or responsible adult, who keeps visibility over academic progress.
- We process the minimum data necessary for the educational purpose, guided by the best interests of the child.
- We never use minors' data for advertising or commercial profiling, nor disclose it to third parties.
- The responsible adult may revoke consent and request deletion of the minor's data at any time.
Outside the Student module, the Services are not directed at minors under 18 and we do not knowingly collect their data; if we detect a minor's data outside that framework, we delete it.
11. Processors, recipients and no sale of data
We do not sell or "share" personal data as defined by California law (CCPA/CPRA): no transfers for behavioral advertising and no commercialization of databases.
We share data only with processors acting on our behalf, under contract, confidentiality and use limitation:
| Processor | Role | Location |
|---|---|---|
| Google Cloud Platform | Application and database hosting (Cloud Run / Cloud SQL, us-central1 region) | USA |
| Anthropic | AI query processing (after PII scrubbing) | USA |
| Google (OAuth / Calendar) | Authentication and authorized agenda integration | USA |
| Railway | Secondary services infrastructure in transition to Google Cloud | USA |
| Meta / WhatsApp | Messaging channel when you use QueBot via WhatsApp (Annex D) | USA |
We may also disclose information where required by law or by order of a competent authority, notifying you unless legally prohibited.
12. International transfers
The processors listed above process data outside Chile (mainly in the USA). Where this happens we apply adequate safeguards: contractual clauses with protection standards equivalent to this policy, prior minimization (PII scrubbing toward AI), encryption in transit and at rest, and vendor assessment. We keep the processor list in this policy up to date.
13. Retention
| Data type | Period | Grounds |
|---|---|---|
| Health data | 15 years | Law 20.584, art. 13 (clinical record) |
| Financial/tax data | 6 years | Tax obligations (SII) |
| Audit logs | 5 years | Traceability and security |
| AI interactions | 1 year | Service operation and improvement |
| Account data and content | While the account is active | Contract |
If you delete your account, we erase your data within 30 days, except data we are legally required to retain for the periods above; that data is blocked (available only for the legal obligation that justifies it).
14. Your rights
You may exercise, free of charge, the rights of:
- Access — know what data of yours we process and obtain a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure (deletion) — delete your data and your account.
- Objection — object to specific processing operations.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdrawal — withdraw any consent (including Google OAuth permissions), without retroactive effect.
- Blocking — temporarily suspend a processing operation while a request is resolved.
How to exercise them: write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in stating the right you are exercising. We may ask for reasonable evidence to verify your identity. We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.
No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind.
Complaint to the authority: if you believe your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency (the authority created by Law 21.719) or to the competent courts.
15. Security
Current technical and organizational measures:
- TLS/HTTPS encryption for all communications and encryption at rest in the database.
- Additional field-level AES-256-GCM encryption for sensitive health data (national ID, diagnoses, allergies, clinical notes).
- Tamper-evident clinical audit log for every access to health records.
- Least-privilege access control and per-user, per-organization isolation (multi-tenant).
- Google OAuth 2.0 authentication; secure secret and token management.
- Parameterized queries (ORM) against injection; security headers and CSP.
- Periodic security reviews and a phased continuous-improvement plan (2FA, GDPR-style export, SOC 2 readiness and external penetration testing on the roadmap).
We align our management system with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management) as reference frameworks; formal certifications, when adopted, will be announced on this page. See also the Information Security Policy.
16. Breach notification
In the event of a security incident affecting personal data: we assess and contain it, preserve evidence and, where it creates risk for data subjects, notify the Personal Data Protection Agency and affected individuals without undue delay, describing the nature of the incident, the data involved and the measures taken.
17. Impact assessments (DPIA)
Before starting processing that may pose high risk (sensitive data at scale, new AI uses, minors' data), we run a Data Protection Impact Assessment and proceed only if mitigation measures reduce the risk to an acceptable level — the same discipline as GDPR art. 35, applied across the ecosystem.
18. Cookies
We use essential cookies only (session, security, preferences such as language). We do not use advertising or third-party tracking cookies. Details in the Cookie Policy.
19. Changes to this policy and verifiable versioning
We will publish any modification on this page with a new date and version number. For substantial changes, we will additionally notify you through the platform or by email.
Each version is frozen in our repository with its SHA-256 fingerprint in an append-only manifest. This allows anyone to verify which exact text was in force on a given date and that it was not altered afterwards.
20. Contact
- Privacy channel: admin@sinapsis.in
- DPO: Felipe Mehr — fmehr@sinapsis.in
- Company: Sinapsis SpA (RUT 78.327.684-4), San Martín 924, Office 213, Temuco, Chile
Annex A — HumanOS Personal & Family (humanos.eco)
Modules for personal life, family, health (Care/Health), well-being, personal finance, agenda and documents. Specifics: health data is processed only with express consent and field-level encryption (section 15); well-being check-ins generate trends for you only and are never shared; the Google Calendar integration is optional and revocable.
Annex B — HumanOS Business (empresa.eco)
When an organization uses HumanOS, the organization decides which business data it loads (KPIs, risks, compliance, teams). For the personal data of its members, the organization acts as controller and Sinapsis as processor under the service agreement; multi-tenant isolation prevents access across organizations.
Annex C — HumanOS Student (estudiante.humanos.eco)
Use by minors with the consent of the responsible adult (section 10): minimal academic data (grades, subjects, assignments, goals), parental visibility of progress, zero advertising and zero profiling. The exact consent text accepted is recorded through the verifiable versioning described in section 19.
Annex D — QueBot via WhatsApp
If you use QueBot through WhatsApp, Meta/WhatsApp processes the channel metadata (your number, message timing) under its own policies; the content QueBot processes follows this policy (AI with PII scrubbing, section 8). If you prefer not to expose metadata to WhatsApp, you can use QueBot inside the web platform.