DraftThis document is a technical draft under legal review. It is being reviewed by MisAbogados (attorney Ricardo Cantero, case 25762) and does not constitute legal advice. Chile's Law 21.719 takes effect around December 2026. The final version will be published with its corresponding effective date.

Registered address. The current address is Cochrane 639, Of. 54, Valparaíso, per the articles of incorporation and the compliance file. The Meta Business Manager record contains a typo (“630”); HERIHE DIGITAL LTDA. decided on 2026-09-06 not to correct it, to avoid reopening the already completed business verification. This page uses the correct address.

1. Who is responsible for your data

Legal nameHERIHE DIGITAL LTDA.
Tax ID (RUT)78.389.881-0
Registered addressCochrane 639, of. 54, Valparaíso, 2361806, Chile open discrepancy
Data protection contactdatos@herihe.digital
Phone+56 9 4043 5095
Websitehttps://herihe.digital/
BusinessDigital marketing and automation agency. Services: paid media (Google Ads, Meta Ads), CRM and email marketing (Mautic), automation (n8n, Chatwoot), landing pages, B2B prospecting and AI agents.
Markets we operate inChile, Brazil, United States, Spain, Peru and Mexico.

All personal data requests are handled at datos@herihe.digital. It is the single, monitored channel to exercise your rights, request deletion of your data, report an issue or file a complaint.

2. Our dual role: controller and processor

HERIHE DIGITAL LTDA. processes personal data in two distinct capacities, and that distinction determines who you should address:

RoleWhen it appliesWhat it means for you
Controller Data about our own staff and contractors, B2B prospects in our commercial database, visitors to our websites, and people who contact or hire us. We decide the purposes and means. You exercise your rights directly with us at datos@herihe.digital.
Processor Data we operate on behalf of our clients: their CRM and email marketing databases, their stores, their advertising campaigns, their support conversations. The controller is our client, not us. If you contact us, we forward your request to the controller and assist them in responding within the legal deadline. We can also tell you which company to address.

When we act as a processor, we process data solely according to the client controller's documented instructions, we do not use it for our own purposes, and we do not combine it across different clients.

3. What data we process

3.1 Data you give us directly

3.2 Data from publicly available sources

This is professional contact data (corporate email, business phone, job title, company). We do not collect sensitive data from public sources.

3.3 Data collected automatically

3.4 Data received from third-party platforms

When you interact with us through Meta (Facebook, Instagram, WhatsApp), Google, Apple or other platforms, we receive data from those platforms. The exact detail — what we receive, what for and how it is deleted — is in section 11.

4. Purposes and legal bases

PurposeLegal basisData used
Delivering contracted servicesPerformance of a contractName, email, phone, company, connected credentials
Answering enquiries via form, chat, WhatsApp or social messagingContract / pre-contractual stepsContact details and message content
Commercial communications and B2B prospectingLegitimate interest (see section 5)Name, corporate email, job title, company
Newsletter and content deliveryConsentEmail, name, preferences
Analytics, campaign measurement and service improvementLegitimate interest / consent for non-essential cookiesBrowsing and interaction data
Running advertising campaigns on behalf of clientsData processing agreement with the client controllerAudiences, metrics, campaign identifiers
Invoicing and tax complianceLegal obligationBilling and identification data
Security, fraud prevention and traceabilityLegitimate interest / legal obligationTechnical records, IP, access logs
Handling rights requests and demonstrating complianceLegal obligationThe minimum needed to evidence how the request was handled

5. Legitimate interest and B2B prospecting

For commercial communications addressed to professional business contacts we carry out a documented balancing test under Article 16 quinquies of Law 21.719. It is available on request at datos@herihe.digital.

The limits we impose on ourselves in this activity:

6. Who we share data with: processors and sub-processors

We share data with providers acting as processors or sub-processors, under our instructions and solely to deliver the service. We do not sell, license or transfer personal data to third parties for their own purposes.

ProviderFunctionData location
DigitalOceanCompute infrastructure and hostingUSA
cPanel/WHM hostingWebsite hostingUSA
Mautic (self-hosted instances)Email marketing and CRMOn our own infrastructure
SendGridTransactional email deliveryUSA
Chatwoot (self-hosted)Conversational supportOn our own infrastructure
Google (Ads, Analytics, Search Console, Tag Manager, Workspace, Merchant Center)Advertising, analytics and corporate emailUSA
Meta PlatformsAdvertising, audiences and messagingUSA
Salesforce Marketing CloudEmail and audiences (for clients who use it)USA
KlaviyoEmail marketing (for clients who use it)USA
ApifyPublic data collectionEU / USA
Hunter · ApolloProfessional email verification and enrichmentEU / USA
Anthropic · OpenAIAI models (drafting, analysis, transcription)USA
FathomMeeting recording and transcriptionUSA
Transbank · MercadoPago · FlowPayment processingChile / regional
BsaleElectronic invoicingChile

This list is updated whenever our provider chain changes. The current detail per service is available on request.

7. International transfers

A significant part of our infrastructure and of the providers we use has servers outside Chile, primarily in the United States. In those cases we apply the safeguards required by Law 21.719 (Arts. 27–28) to ensure an adequate level of protection, and the equivalent safeguards required by the LGPD (Ch. V) and the GDPR (Ch. V), including standard contractual clauses where applicable.

If you are a data subject in the European Union or the European Economic Area, you may request a copy of the applicable transfer mechanism by writing to datos@herihe.digital.

8. Retention periods

Data typeRetention period
Active client dataDuration of the relationship + 5 years
Prospect data with no reply12 months from last contact
Prospect data with an objection on fileDeleted; we keep only the strict minimum in the suppression list (email and its hash) so we never contact you again
Browsing and analytics data12 months
Technical records and access logs90 days
Billing dataStatutory tax period (6 years in Chile)
Proof of consent and of rights-request handlingFor as long as needed to demonstrate compliance
Google user data obtained through Google APIsFor the duration of the contract; deleted within 30 days of its termination or of access revocation commitment to confirm
Data received from Meta platformsFor as long as the purpose described in this policy subsists; deleted when the relationship ends, when authorization is withdrawn, or on request (see section 12)
Data processed on behalf of clientsAccording to the client controller's instructions; on service termination it is returned or securely deleted, unless a legal retention obligation applies

Where the law requires us to keep data despite a deletion request, we document the specific legal obligation grounding that retention and tell you about it in our response.

9. Security

10. Cookies and similar technologies

Our sites use cookies and similar identifiers for site functionality, analytics and advertising measurement.

Parties that may collect, receive or use data through these technologies: HERIHE DIGITAL LTDA., Google LLC (Google Analytics, Google Ads, Google Tag Manager) and Meta Platforms, Inc. (Meta pixel).

We use Google Analytics. You can read how Google collects and processes this data at “How Google uses information from sites or apps that use our services”. We do not pass information to Google that could be used or recognized as personally identifiable, hashed or otherwise.

Other than strictly necessary cookies, we only set cookies with your consent, requested via the banner on our site. We keep a record of the consent given. You can withdraw it at any time from the “Cookie preferences” link in the footer of each site, or by writing to datos@herihe.digital.

11. Third-party platform data

This section describes, platform by platform, what data we receive, what we use it for, where we store it, who we share it with and how it is deleted. We only process platform data for the purposes described here.

11.1 Meta — Facebook, Instagram and WhatsApp Business

What data we receive

What we use it for

Limits we observe

How it is deleted

We delete data obtained from Meta platforms as soon as reasonably possible when: (a) it is no longer needed for the purpose described; (b) we discontinue the service or app; (c) Meta asks us to, in order to protect a person; (d) you ask us to, or you close your account; or (e) the law requires it.

To request deletion: write to datos@herihe.digital with the subject “Data deletion — Meta”, stating the channel (Facebook, Instagram or WhatsApp) and the username or number you wrote from. The full procedure, deadlines and what happens next are in section 12.

You can also remove our access from your own Meta account, under Settings & Privacy → Settings → Apps and Websites, and submit a deletion request from “View Removed Apps and Websites”.

11.2 Google — Ads, Analytics, Search Console, Tag Manager and Merchant Center

When a client authorizes us through Google OAuth, we access data in their Google account (“Google user data”) for the sole purpose of delivering the contracted services of advertising and search management, audit and analysis.

What we access and why

API and scopeData we accessPurpose
Google Ads API
auth/adwords
Campaign metrics, keywords, ads, budgets, conversions and account identifiersAudit, optimization and reporting of the client's campaigns
Google Analytics
auth/analytics.readonly
Aggregated reports on sessions, conversions and behaviourResults measurement and reporting
Search Console
auth/webmasters.readonly
Queries, pages, impressions and organic positionsSEO/AEO diagnosis and planning
Tag Manager
auth/tagmanager.readonly
Inventory of tags, triggers and variablesMeasurement audit
Merchant Center
auth/content
Feed and product statusCatalog diagnosis

Where it is stored

OAuth tokens are stored encrypted on infrastructure under our control, with access restricted to the technical staff assigned to that account. Extracted data is retained for the duration of the contract and deleted within 30 days of its termination or of access revocation.

Who it is shared with

We do not share Google user data with third parties, except with the infrastructure processors listed in section 6, under contract and solely to host or process the information on our behalf. We do not sell or transfer Google user data, we do not use it for targeted advertising, we do not use it to train generalized artificial intelligence models, and we do not use it for creditworthiness assessment.

Revocation

You can revoke our access at any time at myaccount.google.com/permissions or by writing to datos@herihe.digital. Once revoked, we stop accessing immediately and delete the extracted data within 30 days.

Scope changes

If we ever need to access a type of data not described here, we will update this policy and ask for your consent before accessing it.

11.3 Apple — App Store and Sign in with Apple

Current status: HERIHE DIGITAL LTDA. does not currently publish its own apps on the App Store. This section governs any app we publish or operate on behalf of a client, and states the commitments we apply from the first review submission onwards.

11.4 Other platforms

This table is extended whenever we add a new platform, without rewriting the rest of the document.

PlatformWhat we receivePurposeHow to delete or revoke
WhatsApp BusinessPhone number, profile name, conversation content and metadataSupport and continuity of the conversation you startedWrite to datos@herihe.digital from the same number, or request deletion in the chat itself
TikTok (Business / Ads)Aggregated campaign metrics and audiences; public interactionsCampaign management and measurement on behalf of the advertiserBy removing our access in the advertiser's TikTok Business Center
LinkedInPublic professional contact data; campaign metricsB2B prospecting and campaign managementUnsubscribe link in the message, or datos@herihe.digital
Shopify · WooCommerceOrder and customer data from the client's storeOperating the store and its automations, as a processorAddress the store as controller; we assist and forward your request
Stripe · MercadoPago · Transbank · FlowPayment confirmation and transaction identifiers. We do not store card numbersPayment collection and reconciliationTax data is retained by legal obligation; see section 8
FathomMeeting recordings, transcripts and participantsRecording agreements and service continuityYou can request deletion of a recording at datos@herihe.digital

12. How to delete your data

Data deletion request

Single channel: datos@herihe.digital — subject: “Data deletion”.

Please tell us: (1) your name; (2) the email, phone number or username associated with your data; (3) the platform you interacted with us through (email, website, Facebook, Instagram, WhatsApp, Google, other); and (4) whether you are asking for full deletion or only to stop commercial communications.

Step-by-step instructions, platform by platform: Data deletion instructions.

You can also, without writing to us: click the unsubscribe link included in every email, or remove our app's access from your account settings on the relevant platform.

What happens next

  1. Acknowledgement within 48 hours, with a reference number for your request.
  2. Identity verification. If you write from the same email address or number we have on file, that is enough. If not, we will ask for the minimum details needed to confirm it is you, without demanding unnecessary documents.
  3. Execution. We delete your data from our central database and from any instance where it is held, keeping only the strict minimum in the suppression list (email and its hash) so we never contact you again.
  4. Written response stating what was deleted, what was retained and why. If a legal obligation prevents us from deleting an item, we tell you which one.

Deadlines

If you are inMaximum response time
Chile (Law 21.719)15 business days
Brazil (LGPD)15 days
European Union / EEA (GDPR)1 month, extendable by up to 2 further months for complex requests, with notice of the reason
California (CCPA/CPRA)Acknowledgement within 10 business days; response within 45 calendar days, extendable by a further 45

An objection to direct marketing waits for no deadline: it is executed immediately (operationally, within 48 hours at most).

What we cannot delete

We retain data the law requires us to keep — chiefly billing records, for the statutory tax period — and the minimum needed to evidence that we handled your request. In those cases we tell you the specific obligation grounding the retention, and the data is blocked: it is not used for any other purpose.

Data we process on behalf of a client

If your data sits in a database we operate as a processor, the controller is our client. We forward your request without delay, assist them in responding within the legal deadline and, if they authorize us to, tell you which company it is so you can approach them directly.

13. Your rights by jurisdiction

Wherever you are, you can exercise your rights through the same channel: datos@herihe.digital. Exercising your rights is free of charge and we will not treat you worse for doing so.

13.1 Chile — Law 21.719

You have the rights of access, rectification, cancellation (erasure), objection, portability and blocking. The right to object to direct marketing is absolute and requires no justification.

13.2 Brazil — LGPD (Law 13.709/2018)

You have the right to: confirmation that processing exists; access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law; portability; deletion of data processed on the basis of your consent; information about the entities we share data with; information about the option not to consent and its consequences; withdrawal of consent; and review of automated decisions.

13.3 European Union and EEA — GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure or “to be forgotten” (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects (Art. 22). Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

13.4 California — CCPA / CPRA

If you are a California resident, you have the right to: know what personal information we collect, use, disclose and from which sources; access a copy of it; correct inaccurate information; delete your personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information; and not be discriminated against for exercising any of these rights.

14. Artificial intelligence and automated decisions

We use third-party artificial intelligence systems — chiefly Anthropic and OpenAI — as supporting tools to draft content, analyse campaign data, transcribe meetings and run conversational agents. They act as our processors, under enterprise API terms that exclude the use of submitted content to train their models.

15. Minors

Our services are aimed at people over 18 and at professional business contacts. We do not knowingly collect data from minors. If you believe a minor has provided us with data, write to datos@herihe.digital and we will delete it.

16. Changes to this policy

We may update this policy to reflect legal, technical or business changes. The date of the last update appears at the top of the document. Material changes will be announced with reasonable notice through a prominent notice on the site and, where appropriate, by email.

If we need to process a type of platform data not described here, we will update this policy before accessing that data and, where the legal basis is consent, we will ask you for it again.

17. Contact and complaints

If you consider that your request was not handled properly, you may complain to the authority in your jurisdiction: the Agencia de Protección de Datos Personales in Chile, the ANPD in Brazil, the supervisory authority of your Member State in the EU/EEA, or the California Attorney General.

18. Pending human decision

This block is part of the draft and is removed before final publication. It lists what only HERIHE DIGITAL LTDA.'s management and the reviewing attorney (MisAbogados, case 25762) can close.

Blockers — must be resolved before publishing

  1. Registered address. The current address is Cochrane 639, Of. 54, Valparaíso, per the articles of incorporation and the compliance file. The Meta Business Manager record contains a typo (“630”); HERIHE DIGITAL LTDA. decided on 2026-09-06 not to correct it, to avoid reopening the already completed business verification. This page uses the correct address.
  2. Responsible entity — resolved. The data controller is HERIHE DIGITAL LTDA. (RUT 78.389.881-0, Valparaíso), confirmed by management on 2026-09-06. The earlier version of this page, which attributed the site to “Converclick, based in Santiago”, is superseded.
  3. Contact email. The live version uses privacy@herihe.digital (and mentions legal@); the compliance file and this draft use datos@herihe.digital. Confirm the official channel, keep the other forwarding for at least 12 months, and leave no dead addresses in a public legal document.
  4. Response deadline. The live version promises “20 business days”; Law 21.719 and our internal procedure set 15 business days. This draft uses 15. Confirm, and do not republish the 20.
  5. Public phone number. This draft uses +56 9 4043 5095. The WhatsApp button on the current site points to +56 9 4043 5095. Decide which is the public contact number and unify it.

Operational commitments that create real obligations

  1. The 30 days to delete Google API data after contract termination or access revocation: confirm the process exists and is executable, or change the number. A stated deadline that is not met is worse than stating none.
  2. “We do not use Google user data to train generalized models” and “we do not combine advertising data across clients”: verify that no automated flow contradicts these before signing off on the statement.
  3. Excluding direct-message contacts from B2B prospecting. Meta's Developer Policies require it and this policy states it. Today it is a written rule: it must become a technical control in the Chatwoot → commercial database flow, not a paper promise.
  4. Data processing agreements with AI providers (Anthropic, OpenAI and similar): the internal inventory flags this as an open gap. This policy states they act as our processors; the contractual instrument must exist.
  5. Cookie consent records and a “Cookie preferences” link in every site footer: declared here, this requires the banner to actually record consent and allow withdrawal.

Platform decisions

  1. Meta — data deletion route. One of two must be chosen: declare as the Data Deletion Instructions URL in the App Dashboard either the dedicated page (Data deletion instructions) or this section 12 — one URL, not both —, or implement a Data Deletion Callback URL (signed endpoint, confirmation code and status page). They are alternatives, not cumulative. If the callback is chosen, this policy must describe the confirmation code and the status page.
  2. Terms of Service. It is a required field to switch a Meta app to Live mode. The current terms at /terms.html, /pt/terms.html and /en/terms.html must be reviewed and aligned with the entity and address decided here.
  3. URL declared on the Google OAuth consent screen. It must be exactly the same URL linked from the herihe.digital homepage, hosted on that same domain, and the domain must be verified in Search Console by an account that owns or edits the Google Cloud project. Do not host this page on the deliverables portal.
  4. Google scope classification. Confirm in the Google Cloud console that adwords, analytics.readonly and webmasters.readonly are listed as sensitive and not restricted. Adding a Gmail or Drive scope to the same project would trigger an annual third-party security assessment designated by Google.
  5. Apple. This policy states we publish no apps of our own today. If one is published — ours or a client's — verify beforehand: account deletion that can be initiated from inside the app, consistency with the App Privacy label, and a link to this policy within the app.
  6. Tags and analytics on legal pages. This draft loads no tag container, no analytics and no remote fonts: it is self-contained. The live version loads GTM. Decide whether legal pages carry measurement and, if so, that it does not fire before consent.
  7. Typefaces. To avoid calling third-party servers from a legal page before consent, Playfair Display and Space Grotesk should be self-hosted. In the meantime, this page falls back to the system font stack.

Open questions for the attorney

  1. Whether the 12-month retention period for non-responding prospects is sufficient.
  2. Final wording of the international transfers section, based on the specific safeguards adopted (Arts. 27–28 of Law 21.719).
  3. Whether the volume and nature of the data processed require a Data Protection Impact Assessment and the formal appointment of a data protection officer.
  4. Whether anonymization is acceptable as an alternative to full erasure where referential integrity requires it.
  5. The transitional regime applicable to the existing commercial database until Law 21.719 takes effect.
  6. Whether this policy must formally distinguish HERIHE DIGITAL LTDA. from the group's other entities, and in what wording.