Privacy Policy

Last updated: August 12, 2026 · Version 2.0.0

This policy describes how Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services (the "Services"):

A single policy governs all Services; Annexes A–D at the end describe the specifics of each one. Every version of this document is published frozen and verifiable through a SHA-256 fingerprint (section 19), so you can always prove which exact text was in force on a given date.

1. Data controller and contact

The DPO oversees compliance with this policy, handles data subjects' inquiries and channels the exercise of rights (section 14).

2. Legal framework

We process personal data in accordance with:

3. Principles we apply

  1. Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
  2. Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
  3. Data minimization (proportionality) — only the data needed for each purpose.
  4. Accuracy — accurate, complete and up-to-date data.
  5. Storage limitation — retention periods defined per data type (section 13).
  6. Security (integrity and confidentiality) — technical and organizational measures (section 15).
  7. Accountability — we document and can demonstrate compliance: records of processing activities (RoPA), impact assessments (section 17) and verifiable policy versioning.
  8. Privacy by design and by default — new modules ship with the most protective settings on.

4. Data we process

Depending on the Service you use (per-service detail in the annexes):

We do not store card numbers or banking credentials. Biometric data (e.g., camera-based emotion detection) is not active; if ever offered, processing would run locally on your device and only with prior explicit consent.

5. Sources of data

We do not buy personal data from third parties nor enrich profiles from external sources.

6. Lawful bases

We process personal data only when at least one of these bases applies:

7. Purposes

We do not use your data for advertising. We do not profile you with legal effects nor make solely automated decisions that significantly affect you; AI assistants are guidance tools under human oversight.

8. Artificial intelligence

9. Google user data (Limited Use)

Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

10. Children and adolescents

The HumanOS Student module may be used by minors under 18 only under these conditions (detail in Annex C):

Outside the Student module, the Services are not directed at minors under 18 and we do not knowingly collect their data; if we detect a minor's data outside that framework, we delete it.

11. Processors, recipients and no sale of data

We do not sell or "share" personal data as defined by California law (CCPA/CPRA): no transfers for behavioral advertising and no commercialization of databases.

We share data only with processors acting on our behalf, under contract, confidentiality and use limitation:

We may also disclose information where required by law or by order of a competent authority, notifying you unless legally prohibited.

12. International transfers

The processors listed above process data outside Chile (mainly in the USA). Where this happens we apply adequate safeguards: contractual clauses with protection standards equivalent to this policy, prior minimization (PII scrubbing toward AI), encryption in transit and at rest, and vendor assessment. We keep the processor list in this policy up to date.

13. Retention

If you delete your account, we erase your data within 30 days, except data we are legally required to retain for the periods above; that data is blocked (available only for the legal obligation that justifies it).

14. Your rights

You may exercise, free of charge, the rights of:

How to exercise them: write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in stating the right you are exercising. We may ask for reasonable evidence to verify your identity. We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.

No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind.

Complaint to the authority: if you believe your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency (the authority created by Law 21.719) or to the competent courts.

15. Security

Current technical and organizational measures:

We align our management system with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management) as reference frameworks; formal certifications, when adopted, will be announced on this page. See also the Information Security Policy.

16. Breach notification

In the event of a security incident affecting personal data: we assess and contain it, preserve evidence and, where it creates risk for data subjects, notify the Personal Data Protection Agency and affected individuals without undue delay, describing the nature of the incident, the data involved and the measures taken.

17. Impact assessments (DPIA)

Before starting processing that may pose high risk (sensitive data at scale, new AI uses, minors' data), we run a Data Protection Impact Assessment and proceed only if mitigation measures reduce the risk to an acceptable level — the same discipline as GDPR art. 35, applied across the ecosystem.

18. Cookies

We use essential cookies only (session, security, preferences such as language). We do not use advertising or third-party tracking cookies. Details in the Cookie Policy.

19. Changes to this policy and verifiable versioning

We will publish any modification on this page with a new date and version number. For substantial changes, we will additionally notify you through the platform or by email.

Each version is frozen in our repository with its SHA-256 fingerprint in an append-only manifest. This allows anyone to verify which exact text was in force on a given date and that it was not altered afterwards.

20. Contact


Annex A — HumanOS Personal & Family (humanos.eco)

Modules for personal life, family, health (Care/Health), well-being, personal finance, agenda and documents. Specifics: health data is processed only with express consent and field-level encryption (section 15); well-being check-ins generate trends for you only and are never shared; the Google Calendar integration is optional and revocable.

Annex B — HumanOS Business (empresa.eco)

When an organization uses HumanOS, the organization decides which business data it loads (KPIs, risks, compliance, teams). For the personal data of its members, the organization acts as controller and Sinapsis as processor under the service agreement; multi-tenant isolation prevents access across organizations.

Annex C — HumanOS Student (estudiante.humanos.eco)

Use by minors with the consent of the responsible adult (section 10): minimal academic data (grades, subjects, assignments, goals), parental visibility of progress, zero advertising and zero profiling. The exact consent text accepted is recorded through the verifiable versioning described in section 19.

Annex D — QueBot via WhatsApp

If you use QueBot through WhatsApp, Meta/WhatsApp processes the channel metadata (your number, message timing) under its own policies; the content QueBot processes follows this policy (AI with PII scrubbing, section 8). If you prefer not to expose metadata to WhatsApp, you can use QueBot inside the web platform.