1. Who receives your request

Legal entityHERIHE DIGITAL LTDA.
Tax ID (RUT)78.389.881-0
Registered addressCochrane 639, of. 54, Valparaíso, 2361806, Chile (see Notice 2 above)
Data privacy channeldatos@herihe.digital
Phone+56 9 4043 5095
Websitehttps://herihe.digital/
BusinessDigital marketing and automation agency. We operate from Chile and serve clients in Chile, Brazil, the United States, Spain, Peru and Mexico.

We act in two distinct roles, and which one applies determines who decides on deletion:

2. What "delete my data" means

When you request deletion, we look for your data and erase it across every system where we might hold it, not just the one that contacted you:

What we cannot delete for you: your Instagram, Facebook, WhatsApp, Google or Apple account; the messages stored on your own phone; or the data those platforms keep on their own behalf. Those deletions are requested from each platform. Section 12 tells you exactly where.

3. How to request deletion — step by step

There is no charge, no special form, and no need to justify your decision. We will not ask you why.

  1. Email datos@herihe.digital with the subject "Delete my personal data". This is the official channel and the one that creates a record.
  2. Tell us how to find you. The email address or phone number we used to contact you is enough. If you remember where the contact happened (an email, a WhatsApp message, a form), mention it — it speeds up the search.
  3. Tell us what you want. You can ask for full deletion, or only to stop receiving commercial communications (objection), which is faster and does not erase your contract history if you are a client.
  4. You will receive an acknowledgement within 48 hours with a reference number in the format ARCO-YYYY-NNN. Keep it: with that number you can ask for the status of your request at any time by replying to the same email.
  5. We confirm in writing once it is done, within the legal deadline that applies to your country (section 6), stating what was deleted and what — if anything — was retained under a legal obligation, and on what grounds.

If you would rather copy and paste, this message is enough:

To: datos@herihe.digital Subject: Delete my personal data Hello, I am requesting the deletion of my personal data from your systems. Name: Email address you contacted me on: Phone number (if applicable): Where I remember being contacted (email / WhatsApp / form / phone call): Please also send me written confirmation once it has been carried out. Thank you.

4. Every available channel

ChannelHow to use itWhat it does
Email (official)datos@herihe.digitalAny right: deletion, access, rectification, objection, portability, blocking
Unsubscribe linkAt the bottom of every email we sendImmediate opt-out from commercial communications (one click). Does not erase the rest of the data
Direct replyReply to any of our emails with "STOP SENDING ME COMMUNICATIONS"Counts as an objection and is recorded exactly like an unsubscribe
WhatsApp or chatWrite "I want my data deleted" in your open conversation with usWe record it and ask you to confirm by email so there is a written record
Phone+56 9 4043 5095We write it down and confirm by email before executing
Postal mailCochrane 639, of. 54, Valparaíso, ChileSame process; the clock starts on receipt
From your Meta accountSettings → Apps and Websites (section 12.1)Specific to data we receive from Meta platforms
From your Google accountmyaccount.google.com/permissions (section 12.2)Revokes our access to your Google data immediately

5. What happens after your request

  1. Day 0 — Receipt. We log the request with its reference number and send you the acknowledgement within 48 hours.
  2. Days 1 to 5 — Search and verification. We verify your identity (section 7) and locate your data in the central database, in each Mautic instance, in the conversation system and in internal reports.
  3. Days 5 to 10 — Execution. We delete the record; where referential integrity prevents that, we irreversibly anonymise it. We add your minimum identifier to the suppression list (section 9) so you are not re-imported. All commercial communication stops immediately.
  4. Day 10 through the legal deadline — Response. We confirm the outcome in writing, stating what was deleted, what was kept, and on what legal ground.

6. Response times by jurisdiction

The deadline that applies to you is the one from your own jurisdiction. Where a person could be covered by more than one law, we apply the shortest deadline.

Where you areApplicable lawResponse deadlineAuthority you can complain to
ChileLaw 21.719 15 business days from receipt. Acknowledgement within 48 h. Objection to marketing: immediate (max. 48 h) Agencia de Protección de Datos Personales (once constituted)
BrazilLGPD — Law 13.709/2018 Confirmation of processing and access in simplified format: immediate; full statement and execution: 15 days (art. 19). Withdrawal of consent: immediate (art. 8 §5) ANPD — Autoridade Nacional de Proteção de Dados
European Union / EEA and United KingdomGDPR / UK GDPR 1 month from receipt (art. 12.3), extendable by up to 2 further months for complex requests, with notice to you inside the first month The supervisory authority of your country of residence
California (USA)CCPA / CPRA Acknowledgement within 10 business days; response within 45 calendar days, extendable by 45 more (90 total) with notice California Privacy Protection Agency (CPPA) and the California Attorney General
Rest of the world We apply the Chilean standard by default: 15 business days Your country's data protection authority, where one exists

About the platforms: Meta requires developers to act "promptly" but sets no number of days. That is why the deadline we give you always comes from the law that protects you, not from the platform.

7. How we verify it is really you

We verify identity so that we never hand over or erase one person's data at another person's request. It protects you; it is not a delaying tactic.

SituationWhat we ask for
You write from the same email address we have on fileNothing further. That is enough
You write from a different addressFull name, the registered email address and, if you remember it, the subject line of the last message we sent you
You request it by phone or chatWe confirm by email before executing
You act as someone else's representativeA power of attorney or mandate evidencing the representation

Anything you send us to verify your identity is used only for that purpose and is deleted when the request is closed, except for the minimum record we are legally required to keep as evidence that we handled it.

8. What gets deleted and what we must keep

Deletion is the rule. Retention is the exception, and only applies where there is a legal obligation or a right to exercise or defend. When we keep something, we tell you exactly what and why.

Type of dataWhat happens when you request deletionGround
B2B prospecting data (name, work email, job title, company)Deleted. Only the minimum stays on the suppression listNo legal obligation to retain
Campaign history and email interaction historyDeleted along with the contact record
Chat, WhatsApp, Messenger and Instagram Direct conversationsDeleted from our support system
Browsing and analytics dataDeleted or anonymised. Ordinary retention: 12 months
Tax and invoicing recordsRetained for the statutory period (6 years in Chile), and used for nothing elseStatutory tax obligation
Data from a current or recent contractRetained for the duration of the relationship plus the subsequent limitation period (5 years)Performance of the contract and defence of legal claims
Evidence of your own requestRetained as a minimal record: date, channel, right exercised and outcomeDuty to demonstrate that we handled it
Suppression listRetained at the strict minimum (see next section)Honouring your own objection

9. The suppression list (why we keep a minimum)

This one tends to surprise people, so here it is without euphemism.

If we erase absolutely every trace of you, nothing stops you from entering our database again tomorrow from a public source — a business directory, a corporate website, a list handed to us by a client — and receiving another email from us. The only way to guarantee that does not happen is to keep a marker saying "this person must not be contacted".

So when we carry out your deletion, we keep on a suppression list:

That list is never used to send you anything. It does the exact opposite: every new batch of contacts is checked against it and matches are discarded before import.

If you still want us to erase even that minimum, ask and we will. But you should know the consequence: we lose the ability to recognise you, and you could be contacted again if your details reappear in a public source. We will warn you of this in writing before executing it.

10. What happens with backups

Backups exist so systems can be recovered after an incident. They are encrypted and are not consulted in day-to-day operations.

The maximum length of the backup rotation cycle still has to be fixed and published: see the corresponding item under Pending human decision.

11. If we handle your data on a client's behalf

A large part of our work consists of operating other companies' data infrastructure: their CRM, their online store, their ad account, their support channel. In those cases the client company is the controller and we act on their instructions.

If your request falls into that category:

  1. We tell you within the same 48-hour acknowledgement window, rather than leaving you waiting.
  2. We identify which company is the controller and give you their contact channel, so you can go to them directly if you prefer.
  3. We forward your request to them anyway and assist them in executing it within the legal deadline. We do not use the handover as an excuse to do nothing.
  4. If that company instructs us to carry out the deletion, we execute it in the systems we operate and confirm it to you.

When a client contract ends, their data is returned or deleted as agreed in the data processing agreement, and we do not reuse it for any purpose of our own.

12. Platforms: where the data comes from and how to erase it

This section exists because data does not always arrive through a form. Sometimes it arrives from a platform, and each platform has its own deletion route alongside ours.

12.1 Meta — Facebook, Instagram, Messenger and WhatsApp

What data we may receive from Meta platforms:

DataWhat we use it for
App-scoped and page-scoped user IDsRecognising the same conversation across messages; it does not identify you outside that context
Public name, profile picture and email address, where the person authorises them at loginKnowing who we are talking to
The content of Messenger, Instagram Direct and WhatsApp messages that reach our support systemSolely to answer and follow up on that same conversation
Public comments and mentions on pages and accounts we manageModeration and community response
Advertising metrics and campaign data from our client's ad accountRunning, optimising and reporting on those campaigns, for that advertiser and no one else

Limits we expressly accept for this data:

How to request deletion of this data — two routes, either one works:

  1. Write to us directly at datos@herihe.digital, telling us the Instagram handle, Facebook page or WhatsApp number we spoke through. This is the fastest route: it enters the flow described in section 5.
  2. From your own Meta account, if you ever logged into an application of ours: Settings & Privacy → Settings → Apps and Websites → remove the app → View Removed Apps and Websites → select the app → Send Request. Meta delivers those requests to us in batches on a periodic basis, so if you want us to act right away, email us as well.

Remember that erasing your data from our systems does not delete your account or your messages on Facebook, Instagram or WhatsApp: that copy lives on the platform and on your phone, and is deleted from within the app itself.

12.2 Google — Ads, Analytics, Search Console, Tag Manager and Merchant Center

Here the data almost always belongs to a client company that granted us access to its own accounts through Google OAuth. We do not access anyone's personal Google account.

Service and scopeWhat we accessPurpose
Google Ads API (auth/adwords)Campaign metrics, keywords, ads, budgets, conversions and account identifiersAuditing, optimising and reporting on the client's campaigns
Google Analytics (auth/analytics.readonly)Aggregated reports on sessions, conversions and behaviourMeasuring results
Search Console (auth/webmasters.readonly)Queries, pages, impressions and organic positionsSEO diagnosis and planning
Tag Manager (auth/tagmanager.readonly)Inventory of tags, triggers and variablesMeasurement audit
Merchant Center (auth/content)Feed and product statusCatalogue diagnosis

How to cut off access and request deletion:

  1. Revoke the access yourself at myaccount.google.com/permissions. It is immediate and does not depend on us: from that moment we can no longer access anything.
  2. Email datos@herihe.digital so we also delete the data already extracted (reports, metric tables, exports) and the stored credentials.

When access is revoked or the contract ends, authorisation tokens are deleted immediately. Data already extracted is deleted or anonymised at the end of the relationship, within the term set in the data processing agreement with each client (see pending item 6). We do not use Google user data for our own advertising, to train general-purpose artificial intelligence models, or for creditworthiness assessment, and we do not sell it.

12.3 Apple — App Store and Sign in with Apple

Current status: HERIHE DIGITAL LTDA. does not currently publish any app of its own on the App Store. This section applies when we build or operate an iOS app on a client's behalf, and states what we guarantee in that case.

12.4 Other platforms

This table grows as we add channels. In every case, the general route remains datos@herihe.digital.

PlatformWhat we may holdAdditional deletion route
WhatsApp BusinessPhone number, profile name and the content of messages you sent usEmail us; deleting the chat on your phone does not delete our copy, and vice versa
TikTokAdvertising campaign data and public comments on accounts we manageEmail us; your own profile content is managed in your TikTok account
LinkedInPublic professional data used for B2B prospectingEmail us; you go on the suppression list
Shopify / WooCommerceOrder data from stores we operate on a client's behalfProcessor role: see section 11
Stripe, MercadoPago, Transbank, FlowWe do not store card numbers. Payment references tied to an orderSubject to tax retention; see section 8
Google Maps and public directoriesPublicly published business contact dataEmail us; you go on the suppression list so it is not re-imported
Fathom (meeting recording)Voice, image and transcript of meetings you took part inEmail us with the date of the meeting
TelegramIdentifier and messages in support channelsEmail us

13. Your rights by jurisdiction

Deletion is one of several rights. They are all exercised through the same channel and all free of charge.

Chile — Law 21.719

Access, rectification, cancellation (erasure), objection, portability and blocking. Objection to direct marketing is absolute: you do not need to justify it and we cannot refuse it. Deadline: 15 business days. Complaints go to the Agencia de Protección de Datos Personales.

Brazil — LGPD

Confirmation that processing exists, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, deletion of data processed on the basis of consent, information about who we share data with, information about the option not to consent, withdrawal of consent, and review of automated decisions. Deadline: immediate in simplified format, 15 days for the full response. Complaints go to the ANPD.

European Union / EEA and United Kingdom — GDPR

Access, rectification, erasure ("right to be forgotten"), restriction of processing, portability, objection — including the absolute right to object to direct marketing — and the right not to be subject to solely automated decisions producing legal effects. Deadline: 1 month, extendable by 2 further months. Complaints go to your national supervisory authority, and you also have the right to an effective judicial remedy.

California — CCPA / CPRA

The right to know what personal information we collect, use and share; the right to delete it; the right to correct it; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising any of these rights — we will not charge you more or give you a worse service.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. Deadline: acknowledgement within 10 business days and a response within 45 calendar days, extendable by 45 more. You may appoint an authorised agent to exercise your rights; we will ask them for proof of that authorisation.

14. Vendors and international transfers

To deliver our services we work with vendors that process data on our instructions. When we carry out a deletion, we propagate it to those concerned.

VendorFunctionWhere the data sits
DigitalOceanCompute infrastructure and hostingUSA
cPanel hosting (converclick.com)Websites and formsUSA
Mautic (self-hosted instances)Email marketingOn our own infrastructure
SendGridEmail deliveryUSA
Google (Ads, Analytics, Search Console, Tag Manager, Workspace)Advertising, analytics and corporate emailUSA / EU
MetaAdvertising and messaging channelsUSA
Salesforce Marketing CloudA client's audiencesUSA
KlaviyoA client's email marketingUSA
ApifyPublic data collectionEU / USA
Hunter, ApolloB2B email verification and enrichmentEU / USA
OpenAI, AnthropicTranscription and artificial intelligence agentsUSA
FathomMeeting transcriptionUSA
Transbank, MercadoPago, Flow, BsalePayments and invoicingChile and region

Part of this infrastructure sits outside Chile, mainly in the United States. For those transfers we adopt the safeguards required by articles 27 and 28 of Law 21.719 and, where applicable, the GDPR standard contractual clauses. An up-to-date vendor list is available on request.

15. If we cannot delete your data

Some of your data may have to be retained. If that happens we will not go silent or answer with boilerplate. We send you, in writing:

If you disagree with our answer, you can complain to the authority for your country listed in section 6. You can also reply to the same email asking for a review, and we will carry one out.

16. Contact and related documents

The other two documents in this same package (also under review):

Until this package is published, the versions in force on the site are the current privacy policy and terms.

17. Pending human decision

This block is deliberately visible. It lists what cannot be settled in the drafting and requires a decision from HERIHE DIGITAL LTDA.'s management, its accountant or its attorney.

  1. Registered address. The current address is Cochrane 639, Of. 54, Valparaíso, per the articles of incorporation and the compliance file. The Meta Business Manager record contains a typo (“630”); HERIHE DIGITAL LTDA. decided on 2026-09-06 not to correct it, to avoid reopening the already completed business verification. This page uses the correct address.
  2. Responsible entity — resolved. The controller is HERIHE DIGITAL LTDA. (RUT 78.389.881-0, Valparaíso), confirmed by management on 2026-09-06. The earlier attribution to “Converclick, based in Santiago” is superseded.
  3. Response deadline discrepancy. The live page promises 20 business days; the internal procedure and this page use 15 business days, which is the Law 21.719 deadline. This must be unified on the shorter figure.
  4. Contact phone number. The website shows a WhatsApp number, +56 9 4043 5095; the operational record lists +56 9 4043 5095, which is the one shown here. Decide which is the official channel for data protection matters.
  5. Backup rotation cycle. A maximum number of days after which every backup copy containing deleted data has been overwritten still needs to be fixed and published.
  6. Deletion deadline for data extracted from Google APIs. The technical proposal is 30 days from the end of the relationship or from revocation. It needs operational confirmation (is it achievable?) and legal sign-off before being published as a commitment.
  7. Meta deletion route. Meta lets you choose between a data deletion instructions URL (which is what this page is) and a callback URL that receives signed requests and returns a confirmation code. Today we cover the first. The second requires development: endpoint, signature verification, deletion queue and status page. Decide which one gets declared.
  8. Publication and URL declaration. Decide the final URL for this page and declare it in Meta's App Dashboard and, where applicable, in App Store Connect. Remember that Google requires the privacy policy to be hosted on the same domain as the declared home page and linked from it, and the domain to be verified in Search Console by the same identity that owns the Google Cloud project.
  9. Appointment of a data protection officer. Still not appointed. Its mandatory nature must be assessed given the volume processed and the presence of clients' sensitive data.
  10. Anonymisation as an alternative to erasure. Confirm whether it is legally acceptable where referential integrity prevents physical deletion, and with what irreversibility guarantees.
  11. Twelve-month retention for unresponsive prospects. Confirm whether the period is sufficient and defensible under Law 21.719.
  12. Contractual chain with sub-processors. Formal data processing agreements with the foreign vendors listed in section 14 are still missing. Without them, what this page promises about propagating deletion downstream rests only on each vendor's generic terms.
  13. Residual data in decommissioned instances. There are Mautic instances belonging to former clients that no longer run but still hold data. A decision is needed between secure erasure, return to the former client, or retention on an express legal basis — and it must be reflected here.
  14. Publish the package together. This page, the privacy policy and the terms form a single package and link to each other by filename (privacy.{es|pt|en}.html, terms.{es|pt|en}.html, data-deletion.{es|pt|en}.html). They must be published together and in the same directory; if any of them is renamed or moved on upload, the links must be adjusted before declaring any URL to Meta or Google. To Meta, a broken link on a legal page is a violation, not a detail.

Drafted as version 1.0 on September 6, 2026 for review by MisAbogados (case 25762). It does not constitute legal advice. If you are the professional reviewing it, write to datos@herihe.digital.