Ir al contenido principal

Privacy Policy

Last updated: September 9, 2026 · Version 2.1.4

This policy describes how Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services (the "Services"):

ServiceDomain / channel
Sinapsis corporate sitesinapsis.in
HumanOS — personal & family viewhumanos.eco, www.humanos.eco
HumanOS — business viewempresa.eco, www.empresa.eco
HumanOS — student viewestudiante.humanos.eco
QueBot (conversational assistant)inside HumanOS and via WhatsApp
Consulting and development servicesper each client agreement

A single policy governs all Services; Annexes A–D at the end describe the specifics of each one. Every version of this document is published frozen and verifiable through a SHA-256 fingerprint (section 19), so you can always prove which exact text was in force on a given date.

1. Data controller and contact

  • Controller: Sinapsis SpA — Chilean Tax ID (RUT) 78.327.684-4
  • Address: San Martín 924, Office 213, Temuco, Chile
  • General privacy channel: admin@sinapsis.in
  • Data Protection Officer (DPO): Felipe Mehr — fmehr@sinapsis.in

The DPO oversees compliance with this policy, handles data subjects' inquiries and channels the exercise of rights (section 14).

2. Legal framework

We process personal data in accordance with:

  • Chilean Law No. 19.628 on the Protection of Private Life (currently in force);
  • Chilean Law No. 21.719 on Personal Data Protection, fully effective December 1, 2026 — we adopt its standards today, including lawful bases, strengthened rights, breach notification and the DPO role;
  • Chilean Law No. 20.584 on Patients' Rights and Duties, for health data;
  • Law No. 21.096 (constitutional right to personal data protection, art. 19 No. 4);
  • as international best-practice references: the EU GDPR, California's CCPA/CPRA, and the ISO/IEC 27001 and ISO/IEC 27701 frameworks and the NIST Privacy Framework, whose requirements we incorporate where they exceed the local standard.

3. Principles we apply

  1. Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
  2. Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
  3. Data minimization (proportionality) — only the data needed for each purpose.
  4. Accuracy — accurate, complete and up-to-date data.
  5. Storage limitation — retention periods defined per data type (section 13).
  6. Security (integrity and confidentiality) — technical and organizational measures (section 15).
  7. Accountability — we document and can demonstrate compliance: records of processing activities (RoPA), impact assessments (section 17) and verifiable policy versioning.
  8. Privacy by design and by default — new modules ship with the most protective settings on.

4. Data we process

Depending on the Service you use (per-service detail in the annexes):

CategoryExamplesMain purpose
Identification and contactName, email, profile photo (Google OAuth)User account, communication
Personal and family dataPhone, address, family members, dependentsPersonal/family organization features
Health data (sensitive)Medications, appointments, records in Care/Health modulesOnly with explicit consent; Annex A
Well-being dataMood, energy and stress check-insPersonal trends and insights; not handed to third parties, but they may travel in the assistant's context
Financial dataRecorded payments, obligations, payablesPersonal/business financial control
Business dataOrganizations, roles, KPIs, risks, complianceBusiness management (Annex B)
Academic data (minors)Grades, subjects, assignments, goalsStudent module (Annex C)
Service contentAssistant queries, uploaded documents, notesProviding the requested service
Integration dataGoogle Calendar events (read/write)Only the agenda features you authorize
Technical and usage dataIP, browser, access logs, features usedSecurity, operation and improvement

We do not store card numbers or banking credentials. Biometric data (e.g., camera-based emotion detection) is not active; if ever offered, processing would run locally on your device and only with prior explicit consent.

5. Sources of data

  • Directly from you, when you sign up, fill in forms or use the Services.
  • From integrations you authorize (e.g., Google OAuth and Google Calendar).
  • Automatically, basic technical data when using the Services (IP, browser, logs).

We do not buy personal data from third parties nor enrich profiles from external sources.

6. Lawful bases

We process personal data only when at least one of these bases applies:

  • Performance of a contract — to provide the Service you request.
  • Consent — free, informed, specific and unambiguous; for optional integrations and for all sensitive data categories (express consent). You may withdraw it at any time without affecting prior lawful processing and without any detriment to your use of the rest of the Service.
  • Legal obligation — where a rule requires us to process or retain data.
  • Legitimate interest — only for purposes compatible with your rights and expectations (e.g., Service security and abuse prevention), after a balancing test.

7. Purposes

PurposeLawful basis
Provide, maintain and improve the ServicesContract
Process queries with AI assistants (with human oversight)Contract
Manage authorized integrations (Google Calendar, etc.)Consent
Process health data in Care/Health modulesExpress consent
Alerts, metrics and reports for the userContract
Service communications (updates, security)Contract / legitimate interest
Security, fraud and abuse preventionLegitimate interest
Compliance with legal obligations (tax, health)Legal obligation

We do not use your data for advertising. We do not profile you with legal effects nor make solely automated decisions that significantly affect you; AI assistants are guidance tools under human oversight.

8. Artificial intelligence

  • We use Anthropic (Claude) models to generate assistant responses (QueBot and HumanOS AI features).
  • In the conversational chat, before sending the text messages you write to the AI provider, a PII scrubber replaces the identifiers it recognizes: the Chilean RUT, tax identifiers from other countries, phone numbers, email addresses, payment card numbers, IBANs and IP addresses. It recognizes formats, not intentions: an identifier written in an unusual way may go undetected.
  • That scrubbing does not cover every path, and you should know it before you type. It does not apply when you attach a file — neither to the file nor to the message that accompanies it, because reading it whole is precisely what you need — and it does not apply when your text goes to the agent features that plan or carry out tasks for you: there it travels exactly as you wrote it. The practical rule, and the only one that does not go stale as we add features, is this: assume anything you write may reach the provider as it is.
  • Your own identity does travel in the assistant's context. So that QueBot can fill in a form, draft a document or cite you correctly without you having to dictate your details in every conversation, its context includes your name and your RUT (Chilean national ID) and — when you work at a company — that company's RUT and legal name. This is your data, in a session already authenticated as yours.
  • The assistant's context does not include the RUT field of another person whose file you are viewing. If you are a guardian reviewing your student, that field does not travel. This does not mean no identifier of theirs can appear: a RUT written inside free text — in that person's biography, for instance — travels along with that text. Nor does it extend to what you ask the assistant to do: if you request work involving a third party's data — drafting a rental agreement, for example — it receives the data needed to carry it out, including that person's identifier.
  • Your data is not used to train our or third parties' AI models.
  • AI responses are for guidance only: they are not legal, financial, medical or other professional advice. See our Responsible AI Policy.

9. Google user data (Limited Use)

Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only access the Google data needed for the features you authorize.
  • We do not sell Google data and do not use it for advertising.
  • No humans read this data except with your express consent, for security, to comply with law, or for aggregated and anonymized internal operations.
  • You can revoke access at any time from your Google account settings.

10. Children and adolescents

The HumanOS Student module may be used by minors under 18 only under these conditions (detail in Annex C):

  • Sign-up and linking require the consent of a parent or responsible adult, who keeps visibility over academic progress.
  • We process the minimum data necessary for the educational purpose, guided by the best interests of the child.
  • We never use minors' data for advertising or commercial profiling, nor disclose it to third parties.
  • The responsible adult may revoke consent and request deletion of the minor's data at any time.

Outside the Student module, the Services are not directed at minors under 18 and we do not knowingly collect their data; if we detect a minor's data outside that framework, we delete it.

11. Processors, recipients and no sale of data

We do not sell or "share" personal data as defined by California law (CCPA/CPRA): no transfers for behavioral advertising and no commercialization of databases.

We share data only with processors acting on our behalf, under contract, confidentiality and use limitation:

ProcessorRoleLocation
Google Cloud PlatformApplication and database hosting (Cloud Run / Cloud SQL, us-central1 region)USA
AnthropicAI query processing (with the scrubbing and its limits described in section 8)USA
Google (OAuth / Calendar)Authentication and authorized agenda integrationUSA
RailwaySecondary services infrastructure in transition to Google CloudUSA
Meta / WhatsAppMessaging channel when you use QueBot via WhatsApp (Annex D)USA

We may also disclose information where required by law or by order of a competent authority, notifying you unless legally prohibited.

12. International transfers

The processors listed above process data outside Chile (mainly in the USA). Where this happens we apply adequate safeguards: contractual clauses with protection standards equivalent to this policy, prior minimization toward the AI — with the scope and limits described in section 8, which does not cover every path —, encryption in transit and at rest, and vendor assessment. We keep the processor list in this policy up to date.

13. Retention

Data typePeriodGrounds
Health data15 yearsLaw 20.584, art. 13 (clinical record)
Financial/tax data6 yearsTax obligations (SII)
Audit logs5 yearsTraceability and security
AI interactions1 yearService operation and improvement
Account data and contentWhile the account is activeContract

If you delete your account, we erase your data within 30 days, except data we are legally required to retain for the periods above; that data is blocked (available only for the legal obligation that justifies it).

14. Your rights

You may exercise, free of charge, the rights of:

  • Access — know what data of yours we process and obtain a copy.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure (deletion) — delete your data and your account.
  • Objection — object to specific processing operations.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdrawal — withdraw any consent (including Google OAuth permissions), without retroactive effect.
  • Blocking — temporarily suspend a processing operation while a request is resolved.

How to exercise them: write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in stating the right you are exercising. We may ask for reasonable evidence to verify your identity. We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.

No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind.

Complaint to the authority: if you believe your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency (the authority created by Law 21.719) or to the competent courts.

15. Security

Current technical and organizational measures:

  • TLS/HTTPS encryption for all communications and encryption at rest in the database.
  • Additional field-level AES-256-GCM encryption for sensitive health data (national ID, diagnoses, allergies, clinical notes).
  • Tamper-evident clinical audit log for every access to health records: if someone altered an entry, the log reveals it; that is not the same as physically preventing the change.
  • Least-privilege access control and per-user, per-organization isolation (multi-tenant).
  • Google OAuth 2.0 authentication; secure secret and token management.
  • Parameterized queries (ORM) against injection; security headers and CSP.
  • Periodic security reviews and a phased continuous-improvement plan (2FA, GDPR-style export, SOC 2 readiness and external penetration testing on the roadmap).

We align our management system with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management) as reference frameworks; formal certifications, when adopted, will be announced on this page. See also the Information Security Policy.

16. Breach notification

In the event of a security incident affecting personal data: we assess and contain it, preserve evidence and, where it creates risk for data subjects, notify the Personal Data Protection Agency and affected individuals without undue delay, describing the nature of the incident, the data involved and the measures taken.

17. Impact assessments (DPIA)

Before starting processing that may pose high risk (sensitive data at scale, new AI uses, minors' data), we run a Data Protection Impact Assessment and proceed only if mitigation measures reduce the risk to an acceptable level — the same discipline as GDPR art. 35, applied across the ecosystem.

18. Cookies

We use essential cookies only (session, security, preferences such as language). We do not use advertising or third-party tracking cookies. Details in the Cookie Policy.

19. Changes to this policy and verifiable versioning

We will publish any modification on this page with a new date and version number. For substantial changes, we will additionally notify you through the platform or by email.

Each version is frozen in our repository with its SHA-256 fingerprint in an append-only manifest. This allows anyone to verify which exact text was in force on a given date and that it was not altered afterwards.

20. Contact


Annex A — HumanOS Personal & Family (humanos.eco)

Modules for personal life, family, health (Care/Health), well-being, personal finance, agenda and documents. Specifics: health data is processed only with express consent and field-level encryption (section 15); well-being check-ins generate trends for you only and are not handed to third parties — though they may travel in the assistant's context, like the rest of your data; the Google Calendar integration is optional and revocable.

Annex B — HumanOS Business (empresa.eco)

When an organization uses HumanOS, the organization decides which business data it loads (KPIs, risks, compliance, teams). For the personal data of its members, the organization acts as controller and Sinapsis as processor under the service agreement; multi-tenant isolation prevents access across organizations.

Annex C — HumanOS Student (estudiante.humanos.eco)

Use by minors with the consent of the responsible adult (section 10): minimal academic data (grades, subjects, assignments, goals), parental visibility of progress, zero advertising and zero profiling. The exact consent text accepted is recorded through the verifiable versioning described in section 19.

Annex D — QueBot via WhatsApp

If you use QueBot through WhatsApp, Meta/WhatsApp processes the channel metadata (your number, message timing) under its own policies; the content QueBot processes follows this policy (AI with the scrubbing and its limits described in section 8). If you prefer not to expose metadata to WhatsApp, you can use QueBot inside the web platform.

Privacy Policy | HumanOS