Ir al contenido principal

Privacy Policy

Last updated: August 12, 2026 · Version 2.0.0

This policy describes how Sinapsis SpA ("Sinapsis", "we") processes personal data across all of its sites and services (the "Services"):

ServiceDomain / channel
Sinapsis corporate sitesinapsis.in
HumanOS — personal & family viewhumanos.eco, www.humanos.eco
HumanOS — business viewempresa.eco, www.empresa.eco
HumanOS — student viewestudiante.humanos.eco
QueBot (conversational assistant)inside HumanOS and via WhatsApp
Consulting and development servicesper each client agreement

A single policy governs all Services; Annexes A–D at the end describe the specifics of each one. Every version of this document is published frozen and verifiable through a SHA-256 fingerprint (section 19), so you can always prove which exact text was in force on a given date.

1. Data controller and contact

  • Controller: Sinapsis SpA — Chilean Tax ID (RUT) 78.327.684-4
  • Address: San Martín 924, Office 213, Temuco, Chile
  • General privacy channel: admin@sinapsis.in
  • Data Protection Officer (DPO): Felipe Mehr — fmehr@sinapsis.in

The DPO oversees compliance with this policy, handles data subjects' inquiries and channels the exercise of rights (section 14).

2. Legal framework

We process personal data in accordance with:

  • Chilean Law No. 19.628 on the Protection of Private Life (currently in force);
  • Chilean Law No. 21.719 on Personal Data Protection, fully effective December 1, 2026 — we adopt its standards today, including lawful bases, strengthened rights, breach notification and the DPO role;
  • Chilean Law No. 20.584 on Patients' Rights and Duties, for health data;
  • Law No. 21.096 (constitutional right to personal data protection, art. 19 No. 4);
  • as international best-practice references: the EU GDPR, California's CCPA/CPRA, and the ISO/IEC 27001 and ISO/IEC 27701 frameworks and the NIST Privacy Framework, whose requirements we incorporate where they exceed the local standard.

3. Principles we apply

  1. Lawfulness, fairness and transparency — we process data only on a legal basis and in an explainable way.
  2. Purpose limitation — specific, explicit and lawful purposes; no incompatible further use.
  3. Data minimization (proportionality) — only the data needed for each purpose.
  4. Accuracy — accurate, complete and up-to-date data.
  5. Storage limitation — retention periods defined per data type (section 13).
  6. Security (integrity and confidentiality) — technical and organizational measures (section 15).
  7. Accountability — we document and can demonstrate compliance: records of processing activities (RoPA), impact assessments (section 17) and verifiable policy versioning.
  8. Privacy by design and by default — new modules ship with the most protective settings on.

4. Data we process

Depending on the Service you use (per-service detail in the annexes):

CategoryExamplesMain purpose
Identification and contactName, email, profile photo (Google OAuth)User account, communication
Personal and family dataPhone, address, family members, dependentsPersonal/family organization features
Health data (sensitive)Medications, appointments, records in Care/Health modulesOnly with explicit consent; Annex A
Well-being dataMood, energy and stress check-insPersonal trends and insights; never shared
Financial dataRecorded payments, obligations, payablesPersonal/business financial control
Business dataOrganizations, roles, KPIs, risks, complianceBusiness management (Annex B)
Academic data (minors)Grades, subjects, assignments, goalsStudent module (Annex C)
Service contentAssistant queries, uploaded documents, notesProviding the requested service
Integration dataGoogle Calendar events (read/write)Only the agenda features you authorize
Technical and usage dataIP, browser, access logs, features usedSecurity, operation and improvement

We do not store card numbers or banking credentials. Biometric data (e.g., camera-based emotion detection) is not active; if ever offered, processing would run locally on your device and only with prior explicit consent.

5. Sources of data

  • Directly from you, when you sign up, fill in forms or use the Services.
  • From integrations you authorize (e.g., Google OAuth and Google Calendar).
  • Automatically, basic technical data when using the Services (IP, browser, logs).

We do not buy personal data from third parties nor enrich profiles from external sources.

6. Lawful bases

We process personal data only when at least one of these bases applies:

  • Performance of a contract — to provide the Service you request.
  • Consent — free, informed, specific and unambiguous; for optional integrations and for all sensitive data categories (express consent). You may withdraw it at any time without affecting prior lawful processing and without any detriment to your use of the rest of the Service.
  • Legal obligation — where a rule requires us to process or retain data.
  • Legitimate interest — only for purposes compatible with your rights and expectations (e.g., Service security and abuse prevention), after a balancing test.

7. Purposes

PurposeLawful basis
Provide, maintain and improve the ServicesContract
Process queries with AI assistants (with human oversight)Contract
Manage authorized integrations (Google Calendar, etc.)Consent
Process health data in Care/Health modulesExpress consent
Alerts, metrics and reports for the userContract
Service communications (updates, security)Contract / legitimate interest
Security, fraud and abuse preventionLegitimate interest
Compliance with legal obligations (tax, health)Legal obligation

We do not use your data for advertising. We do not profile you with legal effects nor make solely automated decisions that significantly affect you; AI assistants are guidance tools under human oversight.

8. Artificial intelligence

  • We use Anthropic (Claude) models to generate assistant responses (QueBot and HumanOS AI features).
  • Before sending text to the AI provider, a PII scrubber automatically removes direct identifiers (national ID, phone numbers, emails, addresses) when the feature does not require them.
  • Your data is not used to train our or third parties' AI models.
  • AI responses are for guidance only: they are not legal, financial, medical or other professional advice. See our Responsible AI Policy.

9. Google user data (Limited Use)

Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only access the Google data needed for the features you authorize.
  • We do not sell Google data and do not use it for advertising.
  • No humans read this data except with your express consent, for security, to comply with law, or for aggregated and anonymized internal operations.
  • You can revoke access at any time from your Google account settings.

10. Children and adolescents

The HumanOS Student module may be used by minors under 18 only under these conditions (detail in Annex C):

  • Sign-up and linking require the consent of a parent or responsible adult, who keeps visibility over academic progress.
  • We process the minimum data necessary for the educational purpose, guided by the best interests of the child.
  • We never use minors' data for advertising or commercial profiling, nor disclose it to third parties.
  • The responsible adult may revoke consent and request deletion of the minor's data at any time.

Outside the Student module, the Services are not directed at minors under 18 and we do not knowingly collect their data; if we detect a minor's data outside that framework, we delete it.

11. Processors, recipients and no sale of data

We do not sell or "share" personal data as defined by California law (CCPA/CPRA): no transfers for behavioral advertising and no commercialization of databases.

We share data only with processors acting on our behalf, under contract, confidentiality and use limitation:

ProcessorRoleLocation
Google Cloud PlatformApplication and database hosting (Cloud Run / Cloud SQL, us-central1 region)USA
AnthropicAI query processing (after PII scrubbing)USA
Google (OAuth / Calendar)Authentication and authorized agenda integrationUSA
RailwaySecondary services infrastructure in transition to Google CloudUSA
Meta / WhatsAppMessaging channel when you use QueBot via WhatsApp (Annex D)USA

We may also disclose information where required by law or by order of a competent authority, notifying you unless legally prohibited.

12. International transfers

The processors listed above process data outside Chile (mainly in the USA). Where this happens we apply adequate safeguards: contractual clauses with protection standards equivalent to this policy, prior minimization (PII scrubbing toward AI), encryption in transit and at rest, and vendor assessment. We keep the processor list in this policy up to date.

13. Retention

Data typePeriodGrounds
Health data15 yearsLaw 20.584, art. 13 (clinical record)
Financial/tax data6 yearsTax obligations (SII)
Audit logs5 yearsTraceability and security
AI interactions1 yearService operation and improvement
Account data and contentWhile the account is activeContract

If you delete your account, we erase your data within 30 days, except data we are legally required to retain for the periods above; that data is blocked (available only for the legal obligation that justifies it).

14. Your rights

You may exercise, free of charge, the rights of:

  • Access — know what data of yours we process and obtain a copy.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure (deletion) — delete your data and your account.
  • Objection — object to specific processing operations.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdrawal — withdraw any consent (including Google OAuth permissions), without retroactive effect.
  • Blocking — temporarily suspend a processing operation while a request is resolved.

How to exercise them: write to the DPO (fmehr@sinapsis.in) or to admin@sinapsis.in stating the right you are exercising. We may ask for reasonable evidence to verify your identity. We respond within the legal deadlines of Law 21.719; if we deny your request in whole or in part, we will state the grounds.

No retaliation: exercising your rights will never result in degraded service, different pricing or discrimination of any kind.

Complaint to the authority: if you believe your request was not properly handled, you may turn to the Chilean Personal Data Protection Agency (the authority created by Law 21.719) or to the competent courts.

15. Security

Current technical and organizational measures:

  • TLS/HTTPS encryption for all communications and encryption at rest in the database.
  • Additional field-level AES-256-GCM encryption for sensitive health data (national ID, diagnoses, allergies, clinical notes).
  • Tamper-evident clinical audit log for every access to health records.
  • Least-privilege access control and per-user, per-organization isolation (multi-tenant).
  • Google OAuth 2.0 authentication; secure secret and token management.
  • Parameterized queries (ORM) against injection; security headers and CSP.
  • Periodic security reviews and a phased continuous-improvement plan (2FA, GDPR-style export, SOC 2 readiness and external penetration testing on the roadmap).

We align our management system with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management) as reference frameworks; formal certifications, when adopted, will be announced on this page. See also the Information Security Policy.

16. Breach notification

In the event of a security incident affecting personal data: we assess and contain it, preserve evidence and, where it creates risk for data subjects, notify the Personal Data Protection Agency and affected individuals without undue delay, describing the nature of the incident, the data involved and the measures taken.

17. Impact assessments (DPIA)

Before starting processing that may pose high risk (sensitive data at scale, new AI uses, minors' data), we run a Data Protection Impact Assessment and proceed only if mitigation measures reduce the risk to an acceptable level — the same discipline as GDPR art. 35, applied across the ecosystem.

18. Cookies

We use essential cookies only (session, security, preferences such as language). We do not use advertising or third-party tracking cookies. Details in the Cookie Policy.

19. Changes to this policy and verifiable versioning

We will publish any modification on this page with a new date and version number. For substantial changes, we will additionally notify you through the platform or by email.

Each version is frozen in our repository with its SHA-256 fingerprint in an append-only manifest. This allows anyone to verify which exact text was in force on a given date and that it was not altered afterwards.

20. Contact


Annex A — HumanOS Personal & Family (humanos.eco)

Modules for personal life, family, health (Care/Health), well-being, personal finance, agenda and documents. Specifics: health data is processed only with express consent and field-level encryption (section 15); well-being check-ins generate trends for you only and are never shared; the Google Calendar integration is optional and revocable.

Annex B — HumanOS Business (empresa.eco)

When an organization uses HumanOS, the organization decides which business data it loads (KPIs, risks, compliance, teams). For the personal data of its members, the organization acts as controller and Sinapsis as processor under the service agreement; multi-tenant isolation prevents access across organizations.

Annex C — HumanOS Student (estudiante.humanos.eco)

Use by minors with the consent of the responsible adult (section 10): minimal academic data (grades, subjects, assignments, goals), parental visibility of progress, zero advertising and zero profiling. The exact consent text accepted is recorded through the verifiable versioning described in section 19.

Annex D — QueBot via WhatsApp

If you use QueBot through WhatsApp, Meta/WhatsApp processes the channel metadata (your number, message timing) under its own policies; the content QueBot processes follows this policy (AI with PII scrubbing, section 8). If you prefer not to expose metadata to WhatsApp, you can use QueBot inside the web platform.

Privacy Policy | HumanOS