Effective August 1, 2026
1. Controller and scope
Empresas de Servicios Integrales de Informática Mauricio Díaz Acevedo EIRL, trading as Emasmas EIRL, Chilean Tax ID 76.033.045-0, Berta Fernández 1982, Santiago, Chile ("Emasmas"), is controller for data used to manage its websites, business relationships, accounts, billing, communications and support.
This Policy covers Emasmas's current and future cloud-based digital products. Product notices supplement it. For content a customer enters into a cloud-based digital product, the customer is generally controller and Emasmas acts as processor under the DPA.
2. Data, sources and purposes
We may process identity, organization and contact details; account, authentication and permissions; plan, billing, payment status and transaction references; communications and support; device, browser, IP address, logs, cookies, usage and diagnostics; and product content selected by the customer. We do not retain full card details unless expressly disclosed.
Data comes from you, your organization, service use, enabled integrations and authorized providers. We use it to contract and deliver services, administer accounts, process payments, provide support, secure systems, prevent abuse, meet legal duties, communicate changes and improve products using aggregated data or consent where required.
Legal grounds may include contract, pre-contract steps, legal obligation, consent and balanced legitimate interests. Where GDPR applies, we rely on a valid Article 6 basis and an Article 9 condition for special-category data. Consent may be withdrawn prospectively.
3. Cookies, recipients and sale
Necessary cookies support security, sessions and preferences. Non-essential cookies or consent-based measurement activate only after consent where required.
We may disclose data to infrastructure, security, payment, email, support, analytics and professional providers; authorities under valid legal process; and parties to a corporate transaction under safeguards. Access is limited and appropriate confidentiality, security and processing terms apply.
Emasmas does not sell personal data. If applicable U.S. law treats a future activity as a "sale" or "sharing" for cross-context behavioral advertising, we will provide required notices and opt-out mechanisms.
4. International transfers and retention
We operate from Chile and providers may process data elsewhere. We use legally required safeguards, including those under Law 19,628 as amended by Law 21,719, and, where applicable, adequacy decisions, Standard Contractual Clauses or another valid GDPR Articles 44–49 mechanism.
We retain data only as needed for the stated purposes, contract, security, backups and legal periods, considering sensitivity and risk. We then delete or reasonably anonymize it; protected backups expire on their normal cycle.
5. Security and incidents
Risk-appropriate measures include access control, least privilege, encryption in transit, logical isolation, backups, logging, vulnerability management and incident response. No system is infallible. We notify customers, individuals or authorities where law or the DPA requires. Report concerns to contacto@emasmas.cl.
6. Your rights
In Chile, you may exercise access, correction, deletion/cancellation, objection and other rights under Law 19,628. Law 21,719, published December 13, 2024 and effective December 1, 2026, strengthens those rights and adds portability, blocking, accountability duties and a supervisory authority; we will apply it from its effective date.
Where GDPR applies, rights may include access, correction, erasure, restriction, objection, portability, safeguards for automated decisions and complaint to a supervisory authority. Where U.S. law applies, including CCPA/CPRA if its thresholds are met, you receive its rights without discrimination.
Email contacto@emasmas.cl with your request and jurisdiction. We will proportionately verify identity and authority, respond within the legal period and explain any denial. Authorized agents may act where law permits.
7. Children and automated decisions
Services are directed to organizations and adults, not children. We do not knowingly collect data directly from children under 13 through accounts subject to COPPA. Customers entering children's data must have a lawful basis and safeguards; Emasmas processes it only under instructions and the DPA.
We do not make solely automated decisions producing legal or similarly significant effects unless expressly disclosed with a valid basis and required safeguards.
8. Changes and contact
We will give reasonable advance notice of material changes. Controller: Emasmas EIRL. Privacy and rights requests: contacto@emasmas.cl. Website: https://emasmas.cl.