Privacy Policy
Last updated: September 9, 2026 · Version 2.1.4
This policy describes how Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services (the "Services"):
| Service | Domain / channel |
|---|---|
| Sinapsis corporate site | sinapsis.in |
| HumanOS — personal & family view | humanos.eco, www.humanos.eco |
| HumanOS — business view | empresa.eco, www.empresa.eco |
| HumanOS — student view | estudiante.humanos.eco |
| QueBot (conversational assistant) | inside HumanOS and via WhatsApp |
| Consulting and development services | per each client agreement |
A single policy governs all Services; Annexes A–D at the end describe the specifics of each one. Every version of this document is published frozen and verifiable through a SHA-256 fingerprint (section 19), so you can always prove which exact text was in force on a given date.
1. Data controller and contact
- Controller: Sinapsis SpA — Chilean Tax ID (RUT) 78.327.684-4
- Address: San Martín 924, Office 213, Temuco, Chile
- General privacy channel: admin@sinapsis.in
- Data Protection Officer (DPO): Felipe Mehr — fmehr@sinapsis.in
The DPO oversees compliance with this policy, handles data subjects' inquiries and channels the exercise of rights (section 14).
2. Legal framework
We process personal data in accordance with:
- Chilean Law No. 19.628 on the Protection of Private Life (currently in force);
- Chilean Law No. 21.719 on Personal Data Protection, fully effective December 1, 2026 — we adopt its standards today, including lawful bases, strengthened rights, breach notification and the DPO role;
- Chilean Law No. 20.584 on Patients' Rights and Duties, for health data;
- Law No. 21.096 (constitutional right to personal data protection, art. 19 No. 4);
- as international best-practice references: the EU GDPR, California's CCPA/CPRA, and the ISO/IEC 27001 and ISO/IEC 27701 frameworks and the NIST Privacy Framework, whose requirements we incorporate where they exceed the local standard.
3. Principles we apply
- Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
- Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
- Data minimization (proportionality) — only the data needed for each purpose.
- Accuracy — accurate, complete and up-to-date data.
- Storage limitation — retention periods defined per data type (section 13).
- Security (integrity and confidentiality) — technical and organizational measures (section 15).
- Accountability — we document and can demonstrate compliance: records of processing activities (RoPA), impact assessments (section 17) and verifiable policy versioning.
- Privacy by design and by default — new modules ship with the most protective settings on.
4. Data we process
Depending on the Service you use (per-service detail in the annexes):
| Category | Examples | Main purpose |
|---|---|---|
| Identification and contact | Name, email, profile photo (Google OAuth) | User account, communication |
| Personal and family data | Phone, address, family members, dependents | Personal/family organization features |
| Health data (sensitive) | Medications, appointments, records in Care/Health modules | Only with explicit consent; Annex A |
| Well-being data | Mood, energy and stress check-ins | Personal trends and insights; not handed to third parties, but they may travel in the assistant's context |
| Financial data | Recorded payments, obligations, payables | Personal/business financial control |
| Business data | Organizations, roles, KPIs, risks, compliance | Business management (Annex B) |
| Academic data (minors) | Grades, subjects, assignments, goals | Student module (Annex C) |
| Service content | Assistant queries, uploaded documents, notes | Providing the requested service |
| Integration data | Google Calendar events (read/write) | Only the agenda features you authorize |
| Technical and usage data | IP, browser, access logs, features used | Security, operation and improvement |
We do not store card numbers or banking credentials. Biometric data (e.g., camera-based emotion detection) is not active; if ever offered, processing would run locally on your device and only with prior explicit consent.
5. Sources of data
- Directly from you, when you sign up, fill in forms or use the Services.
- From integrations you authorize (e.g., Google OAuth and Google Calendar).
- Automatically, basic technical data when using the Services (IP, browser, logs).
We do not buy personal data from third parties nor enrich profiles from external sources.
6. Lawful bases
We process personal data only when at least one of these bases applies:
- Performance of a contract — to provide the Service you request.
- Consent — free, informed, specific and unambiguous; for optional integrations and for all sensitive data categories (express consent). You may withdraw it at any time without affecting prior lawful processing and without any detriment to your use of the rest of the Service.
- Legal obligation — where a rule requires us to process or retain data.
- Legitimate interest — only for purposes compatible with your rights and expectations (e.g., Service security and abuse prevention), after a balancing test.
7. Purposes
| Purpose | Lawful basis |
|---|---|
| Provide, maintain and improve the Services | Contract |
| Process queries with AI assistants (with human oversight) | Contract |
| Manage authorized integrations (Google Calendar, etc.) | Consent |
| Process health data in Care/Health modules | Express consent |
| Alerts, metrics and reports for the user | Contract |
| Service communications (updates, security) | Contract / legitimate interest |
| Security, fraud and abuse prevention | Legitimate interest |
| Compliance with legal obligations (tax, health) | Legal obligation |
We do not use your data for advertising. We do not profile you with legal effects nor make solely automated decisions that significantly affect you; AI assistants are guidance tools under human oversight.
8. Artificial intelligence
- We use Anthropic (Claude) models to generate assistant responses (QueBot and HumanOS AI features).
- In the conversational chat, before sending the text messages you write to the AI provider, a PII scrubber replaces the identifiers it recognizes: the Chilean RUT, tax identifiers from other countries, phone numbers, email addresses, payment card numbers, IBANs and IP addresses. It recognizes formats, not intentions: an identifier written in an unusual way may go undetected.
- That scrubbing does not cover every path, and you should know it before you type. It does not apply when you attach a file — neither to the file nor to the message that accompanies it, because reading it whole is precisely what you need — and it does not apply when your text goes to the agent features that plan or carry out tasks for you: there it travels exactly as you wrote it. The practical rule, and the only one that does not go stale as we add features, is this: assume anything you write may reach the provider as it is.
- Your own identity does travel in the assistant's context. So that QueBot can fill in a form, draft a document or cite you correctly without you having to dictate your details in every conversation, its context includes your name and your RUT (Chilean national ID) and — when you work at a company — that company's RUT and legal name. This is your data, in a session already authenticated as yours.
- The assistant's context does not include the RUT field of another person whose file you are viewing. If you are a guardian reviewing your student, that field does not travel. This does not mean no identifier of theirs can appear: a RUT written inside free text — in that person's biography, for instance — travels along with that text. Nor does it extend to what you ask the assistant to do: if you request work involving a third party's data — drafting a rental agreement, for example — it receives the data needed to carry it out, including that person's identifier.
- Your data is not used to train our or third parties' AI models.
- AI responses are for guidance only: they are not legal, financial, medical or other professional advice. See our Responsible AI Policy.
9. Google user data (Limited Use)
Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
- We only access the Google data needed for the features you authorize.
- We do not sell Google data and do not use it for advertising.
- No humans read this data except with your express consent, for security, to comply with law, or for aggregated and anonymized internal operations.
- You can revoke access at any time from your Google account settings.
10. Children and adolescents
The HumanOS Student module may be used by minors under 18 only under these conditions (detail in Annex C):
- Sign-up and linking require the consent of a parent or responsible adult, who keeps visibility over academic progress.
- We process the minimum data necessary for the educational purpose, guided by the best interests of the child.
- We never use minors' data for advertising or commercial profiling, nor disclose it to third parties.
- The responsible adult may revoke consent and request deletion of the minor's data at any time.
Outside the Student module, the Services are not directed at minors under 18 and we do not knowingly collect their data; if we detect a minor's data outside that framework, we delete it.
11. Processors, recipients and no sale of data
We do not sell or "share" personal data as defined by California law (CCPA/CPRA): no transfers for behavioral advertising and no commercialization of databases.
We share data only with processors acting on our behalf, under contract, confidentiality and use limitation:
| Processor | Role | Location |
|---|---|---|
| Google Cloud Platform | Application and database hosting (Cloud Run / Cloud SQL, us-central1 region) | USA |
| Anthropic | AI query processing (with the scrubbing and its limits described in section 8) | USA |
| Google (OAuth / Calendar) | Authentication and authorized agenda integration | USA |
| Railway | Secondary services infrastructure in transition to Google Cloud | USA |
| Meta / WhatsApp | Messaging channel when you use QueBot via WhatsApp (Annex D) | USA |
We may also disclose information where required by law or by order of a competent authority, notifying you unless legally prohibited.
12. International transfers
The processors listed above process data outside Chile (mainly in the USA). Where this happens we apply adequate safeguards: contractual clauses with protection standards equivalent to this policy, prior minimization toward the AI — with the scope and limits described in section 8, which does not cover every path —, encryption in transit and at rest, and vendor assessment. We keep the processor list in this policy up to date.
13. Retention
| Data type | Period | Grounds |
|---|---|---|
| Health data | 15 years | Law 20.584, art. 13 (clinical record) |
| Financial/tax data | 6 years | Tax obligations (SII) |
| Audit logs | 5 years | Traceability and security |
| AI interactions | 1 year | Service operation and improvement |
| Account data and content | While the account is active | Contract |
If you delete your account, we erase your data within 30 days, except data we are legally required to retain for the periods above; that data is blocked (available only for the legal obligation that justifies it).
14. Your rights
You may exercise, free of charge, the rights of:
- Access — know what data of yours we process and obtain a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure (deletion) — delete your data and your account.
- Objection — object to specific processing operations.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdrawal — withdraw any consent (including Google OAuth permissions), without retroactive effect.
- Blocking — temporarily suspend a processing operation while a request is resolved.
How to exercise them: write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in stating the right you are exercising. We may ask for reasonable evidence to verify your identity. We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.
No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind.
Complaint to the authority: if you believe your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency (the authority created by Law 21.719) or to the competent courts.
15. Security
Current technical and organizational measures:
- TLS/HTTPS encryption for all communications and encryption at rest in the database.
- Additional field-level AES-256-GCM encryption for sensitive health data (national ID, diagnoses, allergies, clinical notes).
- Tamper-evident clinical audit log for every access to health records: if someone altered an entry, the log reveals it; that is not the same as physically preventing the change.
- Least-privilege access control and per-user, per-organization isolation (multi-tenant).
- Google OAuth 2.0 authentication; secure secret and token management.
- Parameterized queries (ORM) against injection; security headers and CSP.
- Periodic security reviews and a phased continuous-improvement plan (2FA, GDPR-style export, SOC 2 readiness and external penetration testing on the roadmap).
We align our management system with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management) as reference frameworks; formal certifications, when adopted, will be announced on this page. See also the Information Security Policy.
16. Breach notification
In the event of a security incident affecting personal data: we assess and contain it, preserve evidence and, where it creates risk for data subjects, notify the Personal Data Protection Agency and affected individuals without undue delay, describing the nature of the incident, the data involved and the measures taken.
17. Impact assessments (DPIA)
Before starting processing that may pose high risk (sensitive data at scale, new AI uses, minors' data), we run a Data Protection Impact Assessment and proceed only if mitigation measures reduce the risk to an acceptable level — the same discipline as GDPR art. 35, applied across the ecosystem.
18. Cookies
We use essential cookies only (session, security, preferences such as language). We do not use advertising or third-party tracking cookies. Details in the Cookie Policy.
19. Changes to this policy and verifiable versioning
We will publish any modification on this page with a new date and version number. For substantial changes, we will additionally notify you through the platform or by email.
Each version is frozen in our repository with its SHA-256 fingerprint in an append-only manifest. This allows anyone to verify which exact text was in force on a given date and that it was not altered afterwards.
20. Contact
- Privacy channel: admin@sinapsis.in
- DPO: Felipe Mehr — fmehr@sinapsis.in
- Company: Sinapsis SpA (RUT 78.327.684-4), San Martín 924, Office 213, Temuco, Chile
Annex A — HumanOS Personal & Family (humanos.eco)
Modules for personal life, family, health (Care/Health), well-being, personal finance, agenda and documents. Specifics: health data is processed only with express consent and field-level encryption (section 15); well-being check-ins generate trends for you only and are not handed to third parties — though they may travel in the assistant's context, like the rest of your data; the Google Calendar integration is optional and revocable.
Annex B — HumanOS Business (empresa.eco)
When an organization uses HumanOS, the organization decides which business data it loads (KPIs, risks, compliance, teams). For the personal data of its members, the organization acts as controller and Sinapsis as processor under the service agreement; multi-tenant isolation prevents access across organizations.
Annex C — HumanOS Student (estudiante.humanos.eco)
Use by minors with the consent of the responsible adult (section 10): minimal academic data (grades, subjects, assignments, goals), parental visibility of progress, zero advertising and zero profiling. The exact consent text accepted is recorded through the verifiable versioning described in section 19.
Annex D — QueBot via WhatsApp
If you use QueBot through WhatsApp, Meta/WhatsApp processes the channel metadata (your number, message timing) under its own policies; the content QueBot processes follows this policy (AI with the scrubbing and its limits described in section 8). If you prefer not to expose metadata to WhatsApp, you can use QueBot inside the web platform.