Privacy Policy

Privacy Policy

πŸ“… Last updated: 1 de enero de 2025
πŸ“„ Version: 2.0
βš–οΈ Legal framework: Ley 19.628 Chile
6 key points
Your financial data belongs to you. We never sell it.
We only use your data to provide the service you subscribed to.
You can request deletion of all your information at any time.
We apply AES-256 encryption at rest and TLS 1.3 in transit.
We do not share your data with advertisers or data brokers.
We comply with Chilean Law NΒ° 19.628 on the protection of private life.
This is a reference translation. In case of discrepancy, the Spanish version prevails, as it is the official and legally binding language of this Privacy Policy.

01 Data controller

The controller of your personal data is:

Costrol SpA
Address: Santiago, Chile
Privacy email: privacidad@costrol.cl
Support email: soporte@costrol.cl

This Privacy Policy applies to the costrol.cl website, the Costrol SaaS platform and all related services.

πŸ›‘οΈ

Costrol acts as data controller for registration, usage and navigation data. For financial and banking data uploaded by the user, it acts as data processor, with the user being the controller of such data.

02 Data we collect

We collect different types of information depending on your interaction with the Service:

2.1 Data you provide directly

CategorySpecific dataWhen collected
Identity dataName, surname, tax ID (optional)At registration
Contact dataEmail, phone (optional)At registration or profile update
Company dataCompany name, tax ID, business type, addressWhen completing profile or billing
CredentialsPassword (stored as bcrypt hash, never in plain text)At registration
Billing dataCard information (processed by certified gateway, not stored by Costrol)When subscribing to a paid plan
Project financial dataBank statements, transactions, categories, budgets, project namesDuring Service use
CommunicationsMessages sent to support, contact formsWhen contacting us

2.2 Data we collect automatically

DataPurpose
IP addressSecurity, fraud detection, approximate geolocation
User agent (browser & OS)Technical compatibility and support
Pages visited & session timeUsage analysis for product improvement
Access date & timeActivity logging and security audit
Session identifierAuthentication and active session maintenance
Platform actions (events)Usage analysis, UX improvement, technical support
ℹ️

Costrol never collects special category or sensitive data such as racial origin, health, political affiliation, religion or sexual orientation.

03 Processing purposes & legal bases

We process your personal data only for the following purposes, each with its corresponding legal basis under Chilean Law NΒ° 19.628:

PurposeLegal basis
Provision of the contracted Service (account creation, statement processing, dashboard display)Contract performance (Terms of Use)
Subscription management, billing and tax document issuanceContract performance + legal obligation (SII Law)
Transactional communications (confirmations, alerts, support)Contract performance
Service security, fraud and abuse preventionLegitimate interest of Costrol
Product improvement through anonymized statistical analysisLegitimate interest of Costrol
Newsletter and marketing communicationsConsent (explicit opt-in)
Compliance with legal obligations and authority requirementsLegal obligation
πŸ“§

Marketing communications are always opt-in. You can unsubscribe at any time by clicking "Unsubscribe" at the bottom of any commercial email.

04 Sharing data with third parties

Costrol does not sell, rent or commercialize your personal data under any circumstances. We only share information in the following limited cases:

4.1 Data processors (sub-processors)

We use external providers acting as data processors under our instructions and contractually obligated to protect your data:

☁️ Cloud infrastructure (AWS)
Data storage and computing. Data stored with encryption at rest. AWS Privacy Policy
πŸ’³ Payment gateway (WebPay / Transbank)
Card payment processing. Costrol never stores card data. Transbank is PCI-DSS certified. Transbank Policy
πŸ“§ Transactional email service
Sending confirmation emails, alerts and support messages. They only receive your email and the specific message content.
πŸ“Š Product analytics (anonymized)
Platform usage analysis tool. Data is transmitted without personally identifiable information.

4.2 Mandatory legal disclosure

We may disclose personal information when required by law, court order or competent Chilean authority (SII, PDI, Public Prosecutor), strictly to the extent necessary.

4.3 Transfer in case of corporate change

In the event of a merger, acquisition or sale of Costrol assets, user data may be transferred to the new owner, who will be bound by this Policy. We will notify users at least 30 days in advance.

05 Financial & banking data β€” special protection

The financial data you upload to Costrol (bank statements, transactions, budgets, project costs) receives special protection:

  • Exclusively the user's property: This data belongs to you. Costrol is only the technical custodian processing it under your instructions.
  • Access restricted to the minimum necessary: Only the strictly necessary technical staff can access the data, under confidentiality agreements.
  • No commercial analysis: Costrol does not analyze, aggregate or use your financial data for its own commercial purposes or to offer to third parties.
  • No use for external AI training: Financial data is not used to train third-party artificial intelligence models.
  • Tenant isolation: Each company's/account's data is logically isolated from other accounts.
πŸ”’

Processed bank statements are stored encrypted with AES-256. Access to decrypted data requires multi-factor authentication and is logged in audit logs.

06 Data retention periods

We retain personal data only for the time necessary to fulfil the purposes for which it was collected:

Data typeRetention periodReason
Active account data (profile, settings)While the account is activeService provision
Financial data (active account)According to plan limit (6β€“βˆž months)Service provision
Financial data (post-cancellation)90 calendar daysExport and portability
Billing data and SII documents6 yearsLegal tax obligation
Security and audit logs12 monthsSecurity and investigation
Support communications (emails)3 yearsService record
Anonymized analytics dataIndefinite (not personal data)Product improvement
Backup copies90 additional days post-active retentionDisaster recovery

Upon expiry of the retention period, data is securely deleted through overwriting or certified destruction of storage media.

πŸ’Ύ

After cancelling your account you have 90 days to export all your data from the settings panel before it is permanently deleted.

07 Security measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction or disclosure:

7.1 Technical measures

  • Encryption in transit: TLS 1.3 on all communications. Strict HTTP (HSTS).
  • Encryption at rest: AES-256 for all stored data.
  • Passwords: Stored as bcrypt hash (cost factor 12). Never in plain text.
  • 2FA available: Optional two-factor authentication for all users (mandatory for Enterprise accounts).
  • Security testing: Periodic audits, vulnerability scans and penetration tests.
  • Continuous monitoring: Intrusion detection systems and automatic alerts.

7.2 Organizational measures

  • Production data access restricted to minimum necessary staff, under the principle of least privilege.
  • Confidentiality agreements with all staff and contractors with data access.
  • Regular security and data privacy training for the team.
  • Documented procedure for responding to security breaches.

7.3 Breach notification

In the event of a security breach affecting personal data, Costrol will notify affected users within 72 hours of becoming aware of it.

08 Cookies & tracking technologies

Costrol uses cookies and similar technologies for technical operation and Service improvement:

πŸͺ

Costrol does not use advertising cookies or share behavioral data with ad networks. We do not show ads.

You can manage cookies through Settings β†’ Privacy, or through your browser settings.

09 Your data rights

Under Chilean Law NΒ° 19.628 and applicable legislation, you have the following rights regarding your personal data:

πŸ‘οΈ
Right of access
You can request a copy of all personal data Costrol holds about you.
✏️
Right of rectification
You can correct inaccurate or incomplete personal data from Settings β†’ Profile.
πŸ—‘οΈ
Right of erasure
You can request deletion of your personal data. Some data must be retained due to legal obligations (e.g. SII documents).
πŸ“¦
Right of portability
You can export all your data in CSV or JSON format from Settings β†’ Export data.
🚫
Right to object
You can object to the processing of your data for marketing or analytics purposes.
⏸️
Right to restriction
You can request that we suspend processing of your data while a claim about its accuracy or lawfulness is resolved.

How to exercise your rights

To exercise any of these rights, write to privacidad@costrol.cl indicating:

  1. Your full name and email associated with the account.
  2. The right you wish to exercise.
  3. Specific description of your request.

We will respond within 30 business days of receiving your request.

πŸ“‹

If you believe your request was not handled correctly, you can appeal to the Council for Transparency or the competent courts of Chile.

10 Minors

The Costrol Service is directed exclusively at persons over 18 years of age. We do not intentionally collect personal data from minors.

If you become aware that a minor under 18 has created an account, notify us at privacidad@costrol.cl and we will delete that account and its associated data.

11 International data transfers

Some of our infrastructure providers (such as AWS) operate from servers located outside Chile, primarily in the United States. These transfers are made with the following safeguards:

  • Providers are subject to standard contractual clauses guaranteeing a level of protection equivalent to Chilean standards.
  • AWS holds international security certifications (ISO 27001, SOC 2 Type II) equivalent to the standards required by Law 19.628.
  • Project financial data is stored in the us-east-1 region (Virginia, USA) under the security standards described in section 7.

By accepting these terms and using the Service, you consent to the transfer of your data to these countries under the described safeguards.

12 Changes to this policy

We may update this Privacy Policy occasionally to reflect changes in our practices, the Service or applicable law.

  • Material changes will be notified by email at least 30 days in advance.
  • Non-material changes (wording corrections, clarifications) will be published without prior notice.
  • The "Last updated" date at the top of the document always reflects the current version.
  • Continued use of the Service after changes take effect constitutes acceptance of the new policy.

The history of previous versions of this policy is available on request by emailing privacidad@costrol.cl.

13 Privacy contact

For any inquiry, request or complaint related to this Privacy Policy:

πŸ“§ Privacy email
privacidad@costrol.cl β€” Response time: up to 5 business days for acknowledgment, up to 30 business days for resolution.
πŸ“§ Legal email
legal@costrol.cl β€” For formal legal requests, authority requirements and legal communications.
🌐 Contact form
costrol.cl/contacto β€” For general privacy and data protection inquiries.
βš–οΈ Supervisory authority
If you are not satisfied with our response, you may appeal to the Council for Transparency of Chile or to the competent civil courts of Santiago.

Privacy questions?

We respond to privacy requests within 30 business days.

πŸ‡¨πŸ‡± ES πŸ‡ΊπŸ‡Έ EN