1. Who is responsible for your data
| Legal name | HERIHE DIGITAL LTDA. |
|---|---|
| Tax ID (RUT) | 78.389.881-0 |
| Registered address | Cochrane 639, of. 54, Valparaíso, 2361806, Chile open discrepancy |
| Data protection contact | datos@herihe.digital |
| Phone | +56 9 4043 5095 |
| Website | https://herihe.digital/ |
| Business | Digital marketing and automation agency. Services: paid media (Google Ads, Meta Ads), CRM and email marketing (Mautic), automation (n8n, Chatwoot), landing pages, B2B prospecting and AI agents. |
| Markets we operate in | Chile, Brazil, United States, Spain, Peru and Mexico. |
All personal data requests are handled at datos@herihe.digital. It is the single, monitored channel to exercise your rights, request deletion of your data, report an issue or file a complaint.
2. Our dual role: controller and processor
HERIHE DIGITAL LTDA. processes personal data in two distinct capacities, and that distinction determines who you should address:
| Role | When it applies | What it means for you |
|---|---|---|
| Controller | Data about our own staff and contractors, B2B prospects in our commercial database, visitors to our websites, and people who contact or hire us. | We decide the purposes and means. You exercise your rights directly with us at datos@herihe.digital. |
| Processor | Data we operate on behalf of our clients: their CRM and email marketing databases, their stores, their advertising campaigns, their support conversations. | The controller is our client, not us. If you contact us, we forward your request to the controller and assist them in responding within the legal deadline. We can also tell you which company to address. |
When we act as a processor, we process data solely according to the client controller's documented instructions, we do not use it for our own purposes, and we do not combine it across different clients.
3. What data we process
3.1 Data you give us directly
- Full name, email address and phone number.
- Company name and job title.
- Any information you send through contact forms, WhatsApp, website chat or social media messaging.
- Billing details, where a commercial relationship exists.
- Credentials and authorizations you voluntarily connect (for example, OAuth access to Google Ads, Google Analytics, Search Console or Meta Business Manager). These are stored encrypted with restricted access.
3.2 Data from publicly available sources
- Business information published in directories and maps (for example, Google Maps) and in commercial registries.
- Information from public professional and business profiles.
- Information published on corporate websites.
This is professional contact data (corporate email, business phone, job title, company). We do not collect sensitive data from public sources.
3.3 Data collected automatically
- IP address and user agent.
- Browsing data: pages visited, traffic source, campaign parameters (UTM), cookies and similar identifiers.
- Interaction with our emails: delivery, opens and clicks.
- Consent and confirmation timestamps.
3.4 Data received from third-party platforms
When you interact with us through Meta (Facebook, Instagram, WhatsApp), Google, Apple or other platforms, we receive data from those platforms. The exact detail — what we receive, what for and how it is deleted — is in section 11.
4. Purposes and legal bases
| Purpose | Legal basis | Data used |
|---|---|---|
| Delivering contracted services | Performance of a contract | Name, email, phone, company, connected credentials |
| Answering enquiries via form, chat, WhatsApp or social messaging | Contract / pre-contractual steps | Contact details and message content |
| Commercial communications and B2B prospecting | Legitimate interest (see section 5) | Name, corporate email, job title, company |
| Newsletter and content delivery | Consent | Email, name, preferences |
| Analytics, campaign measurement and service improvement | Legitimate interest / consent for non-essential cookies | Browsing and interaction data |
| Running advertising campaigns on behalf of clients | Data processing agreement with the client controller | Audiences, metrics, campaign identifiers |
| Invoicing and tax compliance | Legal obligation | Billing and identification data |
| Security, fraud prevention and traceability | Legitimate interest / legal obligation | Technical records, IP, access logs |
| Handling rights requests and demonstrating compliance | Legal obligation | The minimum needed to evidence how the request was handled |
5. Legitimate interest and B2B prospecting
For commercial communications addressed to professional business contacts we carry out a documented balancing test under Article 16 quinquies of Law 21.719. It is available on request at datos@herihe.digital.
The limits we impose on ourselves in this activity:
- Only professional contact data — never sensitive data or consumer data.
- Sends are segmented by industry and criteria, never indiscriminate blasts.
- One-click unsubscribe link in every send, and immediate cessation on any objection.
- Traceability of every contact's origin and a centralized suppression list, so an opt-out is never undone by a later import.
- Data received through Meta platform direct messaging is excluded from this activity (see section 11.1).
You may object to the use of your data for commercial communications at any time and without giving a reason. Just click the unsubscribe link in any email, reply “STOP” or “I DO NOT WISH TO RECEIVE COMMUNICATIONS”, or write to datos@herihe.digital. We stop processing immediately.
6. Who we share data with: processors and sub-processors
We share data with providers acting as processors or sub-processors, under our instructions and solely to deliver the service. We do not sell, license or transfer personal data to third parties for their own purposes.
| Provider | Function | Data location |
|---|---|---|
| DigitalOcean | Compute infrastructure and hosting | USA |
| cPanel/WHM hosting | Website hosting | USA |
| Mautic (self-hosted instances) | Email marketing and CRM | On our own infrastructure |
| SendGrid | Transactional email delivery | USA |
| Chatwoot (self-hosted) | Conversational support | On our own infrastructure |
| Google (Ads, Analytics, Search Console, Tag Manager, Workspace, Merchant Center) | Advertising, analytics and corporate email | USA |
| Meta Platforms | Advertising, audiences and messaging | USA |
| Salesforce Marketing Cloud | Email and audiences (for clients who use it) | USA |
| Klaviyo | Email marketing (for clients who use it) | USA |
| Apify | Public data collection | EU / USA |
| Hunter · Apollo | Professional email verification and enrichment | EU / USA |
| Anthropic · OpenAI | AI models (drafting, analysis, transcription) | USA |
| Fathom | Meeting recording and transcription | USA |
| Transbank · MercadoPago · Flow | Payment processing | Chile / regional |
| Bsale | Electronic invoicing | Chile |
This list is updated whenever our provider chain changes. The current detail per service is available on request.
7. International transfers
A significant part of our infrastructure and of the providers we use has servers outside Chile, primarily in the United States. In those cases we apply the safeguards required by Law 21.719 (Arts. 27–28) to ensure an adequate level of protection, and the equivalent safeguards required by the LGPD (Ch. V) and the GDPR (Ch. V), including standard contractual clauses where applicable.
If you are a data subject in the European Union or the European Economic Area, you may request a copy of the applicable transfer mechanism by writing to datos@herihe.digital.
8. Retention periods
| Data type | Retention period |
|---|---|
| Active client data | Duration of the relationship + 5 years |
| Prospect data with no reply | 12 months from last contact |
| Prospect data with an objection on file | Deleted; we keep only the strict minimum in the suppression list (email and its hash) so we never contact you again |
| Browsing and analytics data | 12 months |
| Technical records and access logs | 90 days |
| Billing data | Statutory tax period (6 years in Chile) |
| Proof of consent and of rights-request handling | For as long as needed to demonstrate compliance |
| Google user data obtained through Google APIs | For the duration of the contract; deleted within 30 days of its termination or of access revocation commitment to confirm |
| Data received from Meta platforms | For as long as the purpose described in this policy subsists; deleted when the relationship ends, when authorization is withdrawn, or on request (see section 12) |
| Data processed on behalf of clients | According to the client controller's instructions; on service termination it is returned or securely deleted, unless a legal retention obligation applies |
Where the law requires us to keep data despite a deletion request, we document the specific legal obligation grounding that retention and tell you about it in our response.
9. Security
- Encryption in transit: HTTPS/TLS across sites and services; SSH for infrastructure operations.
- Credential encryption: tokens and secrets are stored encrypted, never in source code. Enforced by automated secret-detection tooling on every change.
- Access control: restricted to the technical staff assigned to each account, by role.
- Client isolation: each client has its own instance or database. One client's data is never combined with another's.
- Backups: encrypted backups of the central commercial database.
- Traceability: origin recorded for every contact, plus a centralized suppression list.
- Incident response: a formal breach notification plan, notifying the controller without undue delay and the authority within the applicable statutory deadlines.
10. Cookies and similar technologies
Our sites use cookies and similar identifiers for site functionality, analytics and advertising measurement.
Parties that may collect, receive or use data through these technologies: HERIHE DIGITAL LTDA., Google LLC (Google Analytics, Google Ads, Google Tag Manager) and Meta Platforms, Inc. (Meta pixel).
We use Google Analytics. You can read how Google collects and processes this data at “How Google uses information from sites or apps that use our services”. We do not pass information to Google that could be used or recognized as personally identifiable, hashed or otherwise.
Other than strictly necessary cookies, we only set cookies with your consent, requested via the banner on our site. We keep a record of the consent given. You can withdraw it at any time from the “Cookie preferences” link in the footer of each site, or by writing to datos@herihe.digital.
11. Third-party platform data
This section describes, platform by platform, what data we receive, what we use it for, where we store it, who we share it with and how it is deleted. We only process platform data for the purposes described here.
11.1 Meta — Facebook, Instagram and WhatsApp Business
What data we receive
- Profile: public name, profile picture and the user identifier scoped to our app (app-scoped user ID) or to the page (page-scoped ID); email address only if you expressly authorize it.
- Messaging: the content of messages you send us via Messenger, Instagram Direct or WhatsApp Business, and the thread metadata (date, time, channel).
- Public interactions: comments and mentions on posts of the pages and accounts we manage.
- Advertising and measurement: identifiers, metrics and campaign results obtained through the Marketing API; aggregated audience data; Meta pixel and Conversions API events.
- Pages and assets: identifiers and metadata of pages, ad accounts and catalogs we manage on behalf of clients.
What we use it for
- Replying to your conversation and supporting you on the same channel you wrote from.
- Publishing, moderating and managing content on our own or our clients' pages and accounts.
- Planning, running, measuring and reporting advertising campaigns on behalf of the relevant advertiser.
Limits we observe
- Messaging purpose limitation: we do not use any data obtained about the people we reach in Messenger or Instagram Messaging — other than the content of the message thread or call itself — for any purpose other than as reasonably necessary to support the messaging types we use. Concretely: if you write to us by direct message, that contact is not added to our B2B prospecting database and is not enriched with third-party data.
- No sale of Platform Data: we do not sell, license or purchase data obtained from Meta platforms.
- Advertiser segregation: a client's advertising data is used only to assess the performance and effectiveness of that same advertiser's campaigns. It is never combined with another client's data or added to our own databases.
- Only what is disclosed: we process platform data solely for the purposes described in this policy.
How it is deleted
We delete data obtained from Meta platforms as soon as reasonably possible when: (a) it is no longer needed for the purpose described; (b) we discontinue the service or app; (c) Meta asks us to, in order to protect a person; (d) you ask us to, or you close your account; or (e) the law requires it.
To request deletion: write to datos@herihe.digital with the subject “Data deletion — Meta”, stating the channel (Facebook, Instagram or WhatsApp) and the username or number you wrote from. The full procedure, deadlines and what happens next are in section 12.
You can also remove our access from your own Meta account, under Settings & Privacy → Settings → Apps and Websites, and submit a deletion request from “View Removed Apps and Websites”.
11.2 Google — Ads, Analytics, Search Console, Tag Manager and Merchant Center
When a client authorizes us through Google OAuth, we access data in their Google account (“Google user data”) for the sole purpose of delivering the contracted services of advertising and search management, audit and analysis.
What we access and why
| API and scope | Data we access | Purpose |
|---|---|---|
Google Ads APIauth/adwords | Campaign metrics, keywords, ads, budgets, conversions and account identifiers | Audit, optimization and reporting of the client's campaigns |
Google Analyticsauth/analytics.readonly | Aggregated reports on sessions, conversions and behaviour | Results measurement and reporting |
Search Consoleauth/webmasters.readonly | Queries, pages, impressions and organic positions | SEO/AEO diagnosis and planning |
Tag Managerauth/tagmanager.readonly | Inventory of tags, triggers and variables | Measurement audit |
Merchant Centerauth/content | Feed and product status | Catalog diagnosis |
Where it is stored
OAuth tokens are stored encrypted on infrastructure under our control, with access restricted to the technical staff assigned to that account. Extracted data is retained for the duration of the contract and deleted within 30 days of its termination or of access revocation.
Who it is shared with
We do not share Google user data with third parties, except with the infrastructure processors listed in section 6, under contract and solely to host or process the information on our behalf. We do not sell or transfer Google user data, we do not use it for targeted advertising, we do not use it to train generalized artificial intelligence models, and we do not use it for creditworthiness assessment.
Revocation
You can revoke our access at any time at myaccount.google.com/permissions or by writing to datos@herihe.digital. Once revoked, we stop accessing immediately and delete the extracted data within 30 days.
Scope changes
If we ever need to access a type of data not described here, we will update this policy and ask for your consent before accessing it.
“HERIHE DIGITAL LTDA.’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.”
11.3 Apple — App Store and Sign in with Apple
Current status: HERIHE DIGITAL LTDA. does not currently publish its own apps on the App Store. This section governs any app we publish or operate on behalf of a client, and states the commitments we apply from the first review submission onwards.
- Accessible policy: the link to this policy is declared in the App Store Connect metadata and kept accessible within the app.
- What data, how and why: this policy identifies what data the app collects, how it collects it, and all the uses we make of it.
- Third parties: we confirm that any third party with whom the app shares user data — analytics tools, advertising networks, third-party SDKs and any related entities with access to that data — provides the same or equal protection of user data as stated here.
- In-app account deletion: if the app allows account creation, it also offers a way to initiate deletion of that account from within the app itself. Deleting the account deletes the associated data, except what we must retain by legal obligation, which is disclosed to the user.
- Withdrawing consent: we explain how to withdraw consent and how to request deletion of your data (section 12).
- Sign in with Apple: where offered, we honour the Hide My Email option and treat the private relay address like any other email; we do not require additional data as a condition of using it.
- Consistency with the privacy label: the information declared in App Store Connect's App Privacy (the “nutrition label”) matches what is described in this policy.
11.4 Other platforms
This table is extended whenever we add a new platform, without rewriting the rest of the document.
| Platform | What we receive | Purpose | How to delete or revoke |
|---|---|---|---|
| WhatsApp Business | Phone number, profile name, conversation content and metadata | Support and continuity of the conversation you started | Write to datos@herihe.digital from the same number, or request deletion in the chat itself |
| TikTok (Business / Ads) | Aggregated campaign metrics and audiences; public interactions | Campaign management and measurement on behalf of the advertiser | By removing our access in the advertiser's TikTok Business Center |
| Public professional contact data; campaign metrics | B2B prospecting and campaign management | Unsubscribe link in the message, or datos@herihe.digital | |
| Shopify · WooCommerce | Order and customer data from the client's store | Operating the store and its automations, as a processor | Address the store as controller; we assist and forward your request |
| Stripe · MercadoPago · Transbank · Flow | Payment confirmation and transaction identifiers. We do not store card numbers | Payment collection and reconciliation | Tax data is retained by legal obligation; see section 8 |
| Fathom | Meeting recordings, transcripts and participants | Recording agreements and service continuity | You can request deletion of a recording at datos@herihe.digital |
12. How to delete your data
Data deletion request
Single channel: datos@herihe.digital — subject: “Data deletion”.
Please tell us: (1) your name; (2) the email, phone number or username associated with your data; (3) the platform you interacted with us through (email, website, Facebook, Instagram, WhatsApp, Google, other); and (4) whether you are asking for full deletion or only to stop commercial communications.
Step-by-step instructions, platform by platform: Data deletion instructions.
You can also, without writing to us: click the unsubscribe link included in every email, or remove our app's access from your account settings on the relevant platform.
What happens next
- Acknowledgement within 48 hours, with a reference number for your request.
- Identity verification. If you write from the same email address or number we have on file, that is enough. If not, we will ask for the minimum details needed to confirm it is you, without demanding unnecessary documents.
- Execution. We delete your data from our central database and from any instance where it is held, keeping only the strict minimum in the suppression list (email and its hash) so we never contact you again.
- Written response stating what was deleted, what was retained and why. If a legal obligation prevents us from deleting an item, we tell you which one.
Deadlines
| If you are in | Maximum response time |
|---|---|
| Chile (Law 21.719) | 15 business days |
| Brazil (LGPD) | 15 days |
| European Union / EEA (GDPR) | 1 month, extendable by up to 2 further months for complex requests, with notice of the reason |
| California (CCPA/CPRA) | Acknowledgement within 10 business days; response within 45 calendar days, extendable by a further 45 |
An objection to direct marketing waits for no deadline: it is executed immediately (operationally, within 48 hours at most).
What we cannot delete
We retain data the law requires us to keep — chiefly billing records, for the statutory tax period — and the minimum needed to evidence that we handled your request. In those cases we tell you the specific obligation grounding the retention, and the data is blocked: it is not used for any other purpose.
Data we process on behalf of a client
If your data sits in a database we operate as a processor, the controller is our client. We forward your request without delay, assist them in responding within the legal deadline and, if they authorize us to, tell you which company it is so you can approach them directly.
13. Your rights by jurisdiction
Wherever you are, you can exercise your rights through the same channel: datos@herihe.digital. Exercising your rights is free of charge and we will not treat you worse for doing so.
13.1 Chile — Law 21.719
You have the rights of access, rectification, cancellation (erasure), objection, portability and blocking. The right to object to direct marketing is absolute and requires no justification.
- Response time: 15 business days from receipt of the request.
- Authority: Agencia de Protección de Datos Personales, where you may complain if you consider your request was not handled properly.
- Effective date: Law 21.719 takes effect around December 2026. We apply these standards already.
13.2 Brazil — LGPD (Law 13.709/2018)
You have the right to: confirmation that processing exists; access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law; portability; deletion of data processed on the basis of your consent; information about the entities we share data with; information about the option not to consent and its consequences; withdrawal of consent; and review of automated decisions.
- Response time: immediately in simplified format, or up to 15 days for the full statement.
- Authority: ANPD — Autoridade Nacional de Proteção de Dados.
- Data protection officer channel: datos@herihe.digital.
13.3 European Union and EEA — GDPR
You have the rights of access (Art. 15), rectification (Art. 16), erasure or “to be forgotten” (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects (Art. 22). Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Response time: 1 month from receipt, extendable by up to 2 further months for complex requests, with notice of the reason within the first month.
- Authority: you may lodge a complaint with the supervisory authority of your Member State of residence, place of work or of the alleged infringement.
- Transfers: see section 7.
13.4 California — CCPA / CPRA
If you are a California resident, you have the right to: know what personal information we collect, use, disclose and from which sources; access a copy of it; correct inaccurate information; delete your personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information; and not be discriminated against for exercising any of these rights.
- We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not disclose it for cross-context behavioural advertising. That is why we do not publish a “Do Not Sell or Share My Personal Information” link: there is no sale or sharing to opt out of.
- Deadlines: we acknowledge receipt within 10 business days and respond within 45 calendar days, extendable by a further 45 days with notice of the reason.
- Authorized agent: you may designate an agent to exercise your rights; we will ask for proof of authorization and may ask you to verify your identity.
14. Artificial intelligence and automated decisions
We use third-party artificial intelligence systems — chiefly Anthropic and OpenAI — as supporting tools to draft content, analyse campaign data, transcribe meetings and run conversational agents. They act as our processors, under enterprise API terms that exclude the use of submitted content to train their models.
- Client meeting audio and video, and voice notes, are transcribed on our own infrastructure, without being sent to third-party transcription services.
- We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Every decision with material impact goes through human review.
- If we ever implement such a decision, we will disclose it in this policy, explain the logic involved and guarantee your right to obtain human intervention, express your point of view and contest the decision.
15. Minors
Our services are aimed at people over 18 and at professional business contacts. We do not knowingly collect data from minors. If you believe a minor has provided us with data, write to datos@herihe.digital and we will delete it.
16. Changes to this policy
We may update this policy to reflect legal, technical or business changes. The date of the last update appears at the top of the document. Material changes will be announced with reasonable notice through a prominent notice on the site and, where appropriate, by email.
If we need to process a type of platform data not described here, we will update this policy before accessing that data and, where the legal basis is consent, we will ask you for it again.
17. Contact and complaints
- Personal data: datos@herihe.digital
- Phone: +56 9 4043 5095
- Address: Cochrane 639, of. 54, Valparaíso, 2361806, Chile
- Website: https://herihe.digital/
If you consider that your request was not handled properly, you may complain to the authority in your jurisdiction: the Agencia de Protección de Datos Personales in Chile, the ANPD in Brazil, the supervisory authority of your Member State in the EU/EEA, or the California Attorney General.
18. Pending human decision
This block is part of the draft and is removed before final publication. It lists what only HERIHE DIGITAL LTDA.'s management and the reviewing attorney (MisAbogados, case 25762) can close.
Blockers — must be resolved before publishing
- Registered address. The current address is Cochrane 639, Of. 54, Valparaíso, per the articles of incorporation and the compliance file. The Meta Business Manager record contains a typo (“630”); HERIHE DIGITAL LTDA. decided on 2026-09-06 not to correct it, to avoid reopening the already completed business verification. This page uses the correct address.
- Responsible entity — resolved. The data controller is HERIHE DIGITAL LTDA. (RUT 78.389.881-0, Valparaíso), confirmed by management on 2026-09-06. The earlier version of this page, which attributed the site to “Converclick, based in Santiago”, is superseded.
- Contact email. The live version uses
privacy@herihe.digital(and mentionslegal@); the compliance file and this draft usedatos@herihe.digital. Confirm the official channel, keep the other forwarding for at least 12 months, and leave no dead addresses in a public legal document. - Response deadline. The live version promises “20 business days”; Law 21.719 and our internal procedure set 15 business days. This draft uses 15. Confirm, and do not republish the 20.
- Public phone number. This draft uses +56 9 4043 5095. The WhatsApp button on the current site points to +56 9 4043 5095. Decide which is the public contact number and unify it.
Operational commitments that create real obligations
- The 30 days to delete Google API data after contract termination or access revocation: confirm the process exists and is executable, or change the number. A stated deadline that is not met is worse than stating none.
- “We do not use Google user data to train generalized models” and “we do not combine advertising data across clients”: verify that no automated flow contradicts these before signing off on the statement.
- Excluding direct-message contacts from B2B prospecting. Meta's Developer Policies require it and this policy states it. Today it is a written rule: it must become a technical control in the Chatwoot → commercial database flow, not a paper promise.
- Data processing agreements with AI providers (Anthropic, OpenAI and similar): the internal inventory flags this as an open gap. This policy states they act as our processors; the contractual instrument must exist.
- Cookie consent records and a “Cookie preferences” link in every site footer: declared here, this requires the banner to actually record consent and allow withdrawal.
Platform decisions
- Meta — data deletion route. One of two must be chosen: declare as the Data Deletion Instructions URL in the App Dashboard either the dedicated page (Data deletion instructions) or this section 12 — one URL, not both —, or implement a Data Deletion Callback URL (signed endpoint, confirmation code and status page). They are alternatives, not cumulative. If the callback is chosen, this policy must describe the confirmation code and the status page.
- Terms of Service. It is a required field to switch a Meta app to Live mode. The current terms at
/terms.html,/pt/terms.htmland/en/terms.htmlmust be reviewed and aligned with the entity and address decided here. - URL declared on the Google OAuth consent screen. It must be exactly the same URL linked from the
herihe.digitalhomepage, hosted on that same domain, and the domain must be verified in Search Console by an account that owns or edits the Google Cloud project. Do not host this page on the deliverables portal. - Google scope classification. Confirm in the Google Cloud console that
adwords,analytics.readonlyandwebmasters.readonlyare listed as sensitive and not restricted. Adding a Gmail or Drive scope to the same project would trigger an annual third-party security assessment designated by Google. - Apple. This policy states we publish no apps of our own today. If one is published — ours or a client's — verify beforehand: account deletion that can be initiated from inside the app, consistency with the App Privacy label, and a link to this policy within the app.
- Tags and analytics on legal pages. This draft loads no tag container, no analytics and no remote fonts: it is self-contained. The live version loads GTM. Decide whether legal pages carry measurement and, if so, that it does not fire before consent.
- Typefaces. To avoid calling third-party servers from a legal page before consent, Playfair Display and Space Grotesk should be self-hosted. In the meantime, this page falls back to the system font stack.
Open questions for the attorney
- Whether the 12-month retention period for non-responding prospects is sufficient.
- Final wording of the international transfers section, based on the specific safeguards adopted (Arts. 27–28 of Law 21.719).
- Whether the volume and nature of the data processed require a Data Protection Impact Assessment and the formal appointment of a data protection officer.
- Whether anonymization is acceptable as an alternative to full erasure where referential integrity requires it.
- The transitional regime applicable to the existing commercial database until Law 21.719 takes effect.
- Whether this policy must formally distinguish HERIHE DIGITAL LTDA. from the group's other entities, and in what wording.