Effective August 1, 2026
1. Roles, scope and priority
This DPA forms part of the agreement between Emasmas and the customer for services processing personal data for the customer. The customer acts as controller or business and Emasmas as processor, service provider or contractor; where the customer is a processor, Emasmas is a subprocessor.
This DPA prevails for processing matters. A signed order may add product-specific categories or safeguards. Mandatory law always prevails.
2. Instructions and processing details
Emasmas processes data to provide, secure, maintain and support the contracted cloud service during the contract and limited export/deletion period. Processing follows documented instructions, including the contract and configured use, unless law requires otherwise; where lawful, we will notify the customer first. We will flag an instruction we reasonably believe violates applicable law and may pause affected processing.
Data may include identity, contact, employment, account, activity, technical records and operational content selected by the customer. Data subjects may include users, employees, candidates, customers, suppliers, attendees and contractors. High-risk, special-category or children's data may be entered only where the service expressly supports it and suitable legal bases and safeguards exist.
3. Emasmas obligations
Emasmas will limit access to authorized personnel under confidentiality; maintain risk-appropriate security; reasonably assist with rights, impact assessments, consultations and compliance; not sell data or use it for its own advertising or unrelated purposes; and retain information needed to demonstrate compliance.
Controls may include access management, least privilege, authentication, encryption in transit, logical separation, backups, logging, vulnerability management, continuity and incident response.
4. Incidents and subprocessors
Emasmas will notify the customer without undue delay after confirming a personal-data breach affecting customer data, with available facts on nature, scope, consequences and mitigation. Notice is not an admission of liability. The customer determines controller notifications, with reasonable Emasmas assistance.
The customer generally authorizes infrastructure, communication, support, payment and security subprocessors. Emasmas requires substantially equivalent protection and remains responsible as required by law and contract. We will provide notice of material changes where the product channel permits. The customer may object on reasonable data-protection grounds within 15 days; the parties will seek an alternative or may terminate the affected service if none exists.
5. International transfers and U.S. terms
For GDPR data transferred outside the EEA without adequacy, the parties incorporate, where applicable, the Standard Contractual Clauses under Decision (EU) 2021/914 using the module matching their roles and any necessary supplementary measures.
Chilean Law 19,628 applies and, from December 1, 2026, its amendments under Law 21,719. Applicable U.S. federal and state requirements also apply. Where CCPA/CPRA applies, Emasmas acts as service provider or contractor and will not sell or share personal information or retain, use or disclose it outside specified business purposes except as legally permitted.
6. Return, audit and customer duties
At termination, Emasmas enables export or deletes data according to the product and instructions unless legal retention applies. Backups expire on their normal protected cycle.
On reasonable request, we provide compliance information and answer questionnaires. Additional audits require notice, confidentiality and proportionate scope and must not compromise other customers; the customer bears cost unless a material Emasmas breach is found.
The customer determines purposes and essential means, informs individuals, establishes legal grounds, configures access and ensures lawful instructions. DPA requests: contacto@emasmas.cl.