Privacy Policy

At Audty, protecting your personal data is our top priority. Learn how we collect, use, and safeguard your information.

Last updated: February 2026

Audty SpA (hereinafter "Audty") is committed to protecting the privacy and security of its users' personal data, in compliance with Chilean Law 19,628 on Protection of Private Life, Law 21,719 on Personal Data, the European Union's General Data Protection Regulation (GDPR), and all other applicable regulations. This policy describes how we collect, use, store, and protect your personal information.

1. Data We Collect

We collect only the data necessary to provide our legal compliance and complaint management services:

  • Identification data: name, email address, position, and company (for registered staff users)
  • Complaint data: information voluntarily provided by reporters, which may include narratives, evidence, and optional contact details
  • Usage data: platform activity logs, pages visited, and actions performed to improve the service
  • Technical data: IP address, browser type, operating system, and device used to access the platform

2. How We Use Your Data

Your personal data is used exclusively for the following purposes:

  • Managing and processing complaints in accordance with Ley Karin (Law 21,643) and Law 20,393 on criminal liability of legal entities
  • Providing automated legal assistance through artificial intelligence, without using data to train external models
  • Generating anonymous and aggregated statistical reports for organizational compliance analysis
  • Sending notifications related to the status of ongoing cases and investigations

3. Data Security

We implement enterprise-grade technical and organizational measures to protect your information:

  • Data encryption in transit (TLS 1.3) and at rest (AES-256) across the entire platform
  • Infrastructure hosted on Google Cloud Platform with SOC 2 and ISO 27001 certifications
  • Role-based access control (RBAC) with multi-factor authentication available
  • Regular security audits and continuous infrastructure monitoring

4. Your Rights

In accordance with applicable legislation, you have the following rights over your personal data:

  • Right of access: request a copy of the personal data we hold about you
  • Right of rectification: request correction of inaccurate or incomplete data
  • Right of erasure: request deletion of your personal data when no longer necessary
  • Right to object: oppose the processing of your data in certain circumstances

5. Whistleblower Protection

Reporter confidentiality is a fundamental pillar of our platform:

  • Reports can be filed completely anonymously, without registration or identification
  • Reporter data is logically separated from case information and protected with additional encryption
  • Access to the reporter's identity is restricted through strict access controls (blind administrator)
  • Full compliance with Ley Karin standards for the protection of the reporting person

6. Cookies and Tracking Technologies

We use strictly necessary cookies for the platform to function:

  • Session cookies: necessary to keep your session active and secure while using the platform
  • Preference cookies: to remember your language and display settings
  • We do not use third-party cookies for advertising or commercial tracking purposes

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with applicable legal obligations:

5 years

Case and investigation data

1 year

Activity logs

30 days

After account deletion

Privacy Questions?

If you have questions about this policy or wish to exercise your rights, contact us through our dedicated privacy channel.

privacidad@audty.com