Legal
Privacy Policy
What personal data we process, why, who we share it with, how long we keep it, and how you ask us to delete it.
Version 1.0 · 28 July 2026
1. Who we are
This site and its associated services are operated by WEBIADOS SPA, a company incorporated in Chile, tax ID (RUT) 78.403.378-3, with registered address at Los Olivos N° 10958, Santiago, Chile. Its legal representative is Felipe Navarrete Navarrete.
For any personal data matter, including exercising your rights, write to us at contacto@webiados.com. That address is the official channel for these requests.
2. We act in two different roles, and it is worth knowing which one applies to you
The law distinguishes between whoever decides what is done with data (the controller) and whoever merely processes it under instructions from someone else (the processor). Webiados is one or the other depending on which data we are talking about:
- We are the controller of the data of our own clients and prospects: what you write to us through the contact form, what we use to issue you a quote, and the measurement of our advertising. There we decide, and you can bring your request straight to us.
- We are a processor when we operate the website, the chat or the WhatsApp of another business. If you wrote to a clinic, a shop or a restaurant that uses our platform, the controller of that data is that business, not Webiados: they decide what it is used for and we only process it on their instructions.
Why this matters to you: if your data reached us because you wrote to a business, address your request to that business. If you write to us anyway we will still help: we will put you in touch with the controller and support them in answering.
3. What data we process and why
This table is the full inventory. If a processing activity is not listed here, we do not do it.
| Data | Where it comes from | What for | Legal basis | How long |
|---|---|---|---|---|
| Name, email, subject and message from the contact form | You, by typing them on /contacto | Answering your enquiry and, where relevant, preparing a quote | Your consent when sending it, and pre-contractual steps | It stays in our mailbox. The website stores nothing |
| Contact name and email, and which quote option you chose | You give them to us when requesting a proposal | Issuing your quote, showing it online and recording what you accepted | Performance of the contract or pre-contractual steps | For the length of the commercial relationship and 90 days after |
| Name, email, phone, message and commercial interest (leads) | Forms and conversations on the sites we operate | So the business that owns the site can reply and follow up | Instructions of the controlling business; we only process it | For the length of the service and 90 days after |
| Your phone number and the full content of the conversation | When you message the business on WhatsApp or use its chat | Assisting you, booking, quoting or handing you to a person | Instructions of the controlling business; we only process it | 12 months |
| Pages you visit, a browser identifier and the _fbp cookie | Collected only if you interact with webiados.com | Measuring how our Facebook and Instagram ads perform | Legitimate interest in measuring our own advertising | The _fbp cookie lasts about 90 days |
One clarification about the contact form: it does not send anything to our servers. It opens your own email program with the message written out, and you are the one who sends it. This site keeps no copy.
Who is in our databases: people who contact us looking for our services, counterparties of our business clients, and people who write to the businesses whose systems we operate. We do not knowingly process data of children or adolescents; our services are aimed at adults.
Where the data comes from: always from you, when you type it, or from the business that engaged us to run its system. We do not buy databases, we do not hire lists and we do not scrape data from publicly accessible sources or social networks.
4. Sensitive data
Chilean law treats health-related data as sensitive, among other categories, and demands more care with it than with the rest. We work with clinics, medical practices and aesthetic centres: if you write to one of them describing a symptom, requesting an appointment or describing a treatment, that conversation contains sensitive data about you.
That is why conversations are kept for less time than other data, access is restricted to the owning business and whoever operates it, and we never use them for advertising nor sell them to anyone.
5. Who we share data with
We do not sell personal data nor hand it over for third-party advertising. We share it only with the providers that make the service work:
| Provider | What for | What it receives | Where it is |
|---|---|---|---|
| Meta Platforms (WhatsApp) | Delivering and receiving WhatsApp messages | Your number and the content of the messages | United States and Ireland |
| Meta Platforms (píxel) | Measuring how our ads perform | Pages visited and a browser identifier. Not your email | United States and Ireland |
| Google (Gemini) | Generating the assistant's reply when the business enabled AI | The text of the conversation. Your phone number is not sent | United States |
| Railway | Hosting the database and the servers | All stored data, on its infrastructure | United States |
| Cloudflare R2 | Storing images and files | The files uploaded to the sites | United States |
| Vercel | Serving this website | Technical connection data, such as the IP address | United States |
About the automated assistant: the business chooses how it works. In script mode the assistant only asks fixed questions and nothing is sent to any artificial intelligence provider. In the AI-enabled modes the text of the conversation is sent in order to generate the reply; your phone number is not sent. Today the provider we use is Google (Gemini). If we enable a different one for any client in the future, we will update this page before doing so.
All of these providers are outside Chile — mainly in the United States — so using them involves an international transfer of your data. None of those countries has yet been declared as offering an adequate level of protection by the Chilean authority, because that declaration does not exist yet. The transfer therefore relies on the contractual data protection clauses each provider signs, which oblige them to process the data only on our instructions and with equivalent security measures.
6. Automated decisions and profiling
There are two things our systems do on their own, without a person reviewing them one by one. Here is what they are and the logic behind them:
- Depending on how the business configured it, it follows a fixed script or generates the reply with an artificial intelligence model based on what you wrote. It can take down your contact details and hand you over to a person, but it does not decide whether you get served, what price you pay or whether you are accepted as a client.
- It is an internal number that helps the business decide who to answer first, based on how complete the information is and what interest you showed. It produces no legal effects on you: it only changes the order of a list that a person reviews anyway.
Even so, you have the right to object to being subject to automated decisions and to ask that a person review your case. Write to us and we will arrange it. We never use these systems to make decisions about your health, your financial situation or your access to a service.
6. How long we keep your data
- Chat and WhatsApp conversations: 12 months from the last message. It is the most sensitive data and the least useful once it ages.
- Leads, quotes and business data: while the service is active and 90 days after cancellation, so the client has time to export their information.
- Tax and accounting records: for as long as the law requires, which may be longer.
Once the period is up, the data is deleted. The principle we follow is simple: data we do not hold cannot leak.
7. Your rights
Regarding your personal data, you can ask us for:
- Access: that we confirm whether we process data about you and give you a copy.
- Rectification: that we correct anything wrong, incomplete or out of date.
- Erasure: that we delete it, in the cases the law allows.
- Objection: that we stop a particular processing activity.
- Blocking: that we suspend use while we resolve a request of yours.
- Portability: that we hand you your data in a standard file so you can take it to another provider.
- Not to be subject to automated decisions: that a person review your case instead of a system.
And if a processing activity is based on your consent, you can withdraw it whenever you want, without giving reasons and at no cost. Withdrawing it does not make what we did earlier with your permission unlawful: it only stops the processing from that point on.
Write to us at contacto@webiados.com identifying yourself and stating which right you are exercising and over what data. Exercising them is free of charge. If the data is among what we administer on behalf of another business, we will tell you and point you to the controller.
If we reject your request or fail to answer in time, you can complain to the Chilean Personal Data Protection Agency, the supervisory body the law creates.
9. How to ask us to delete your data
You can ask us to delete your data at any time, free of charge. This is how:
- Write to contacto@webiados.com with the subject “Data deletion request”.
- Tell us which channel you contacted us through — WhatsApp, a website chat, a form or this site — and with which number or email, so we can locate your data.
- We confirm receipt and verify that it is really you, so we do not delete someone else’s data by mistake.
- We delete what applies and tell you once it is done. If we must keep something because the law requires it — an invoice, for instance — we tell you what it is and why.
If your data reached us because you wrote to a business that uses our platform, the deletion is authorised by that business, which is the controller. We pass your request on, confirm it to you in writing, and carry out the deletion as soon as they instruct us.
8. Security and what happens if there is a breach
Passwords and access keys are stored encrypted, each business is isolated from the others in the database, access to the admin panel requires authentication, and connections are encrypted end to end.
If a breach nonetheless occurs posing a reasonable risk to your rights, we will report it to the Agency by the fastest means available and without undue delay, and we will keep a record of what happened. Where the breach affects sensitive data, we will also notify you directly, in plain language, telling you which data was affected, what consequences it may have and what we did about it.
9. Cookies and the Meta pixel
This site uses the Meta pixel to measure how many people arrive from our Facebook and Instagram ads. It loads only if you interact with the page, not the moment you arrive.
- _fbp: identifies your browser so you are not counted twice. It lasts about 90 days.
- _fbc: is only created if you arrive by clicking one of our ads, and records which ad you came from.
We do not send Meta your name, your email or your phone number. You can block these cookies from your browser settings, or use its private mode; the site works the same.
10. Changes to this policy
If we change anything material — a new provider, a different purpose, another retention period — we will update this page and its version number and date before the change takes effect. The version in force is always the one published here.
