Privacy policy

How we handle the personal data of people who visit this site or write to us.

This policy

This policy explains what personal data Gradiente processes when you visit this site or contact us, what we use it for, who we share it with, how long we keep it and how you can exercise your rights.

Today, Chilean Law 19.628, on the protection of private life, applies in its current text. The reform introduced by Law 21.719 will enter into force on 1 December 2026; if that date changes, we will update this policy. From here on, "the reformed law" means Law 19.628 (as amended by Law 21.719). We already apply its standard and, where today's rules and those of the reformed law differ, we tell you which applies at each point.

If you are in the European Economic Area (EEA: the European Union, Iceland, Liechtenstein and Norway) or in the United Kingdom, this policy also gives you the information required by the EU General Data Protection Regulation (GDPR) and by its UK version (UK GDPR). In this policy, "the GDPR" covers both.

Version
1.0
Publication date
to be confirmed on publication

Who the controller is

The controller of your data is Gradiente SpA. For any question about this policy or about your data, write to us at the email address below.

Legal name
Gradiente SpA
Chilean tax ID number (Rol Único Tributario, RUT)
76.166.435-2
Registered address
Santiago, Chile
Contact email
contacto@gradiente.cl

What data we process and where it comes from

We only process the data you give us when you write to us or book a conversation: your name, your email address, your company and job title if you share them, and what you tell us about what you need. When you book, the calendar also records the date and time you choose. If you want to work with us, also your résumé and the background you choose to send us.

This is data about the people who contact us, usually on behalf of a company, and about those who send us their application. It comes from you: we only receive it when you write to us or book a conversation.

When you visit the site, the provider that hosts it may log technical data about each visit, such as your device's internet address (IP address), the date and time, and the page requested. We do not use that data to identify you.

We also record each visit without data that identifies you and look at it only in aggregate figures, with PostHog, an analytics service that stores the data in the European Union (Frankfurt). For each visit we record the page visited, the date and time, the language of the page and of your browser, what your browser reports about itself (browser and operating system type and version, and device type), the screen and window size, the site you come from (its main address only and, if it is a search engine, which one) and the source, medium and campaign carried in the address (the parameters starting with "utm"); also clicks on the buttons to book, write to us or view services and guides, and language changes. We do not send your name, your email address or the address of the links you open. When it loads, PostHog's code also reads the page title and the rest of the address, which we discard before sending.

To count visits without leaving anything stored in your browser, when PostHog receives each visit it computes a code from the IP address and the browser, using a random value that changes every day and is then deleted. PostHog does not store the IP address.

Giving us your data is voluntary, but without a contact email we cannot reply to you. To talk about your project or to evaluate your application we do not need sensitive data, such as health data: please do not include it.

What we use it for

We use your data to reply to your message, to arrange and prepare the conversation you request and, if you ask for it, to prepare a proposal for our services. Technical data about visits is used to deliver the site and protect it from abuse.

Site usage measurement tells us, in aggregate figures, which pages and content are used, so we can improve the site.

If you want to work with us, we use your data to evaluate the applications and background you send us; we keep it only as long as needed for that and delete it if you ask us to.

Your data is used only for those purposes: no advertising or newsletters, no automated decisions and no profiling.

If we ever wanted to use it for another purpose, such as sending you news, we would first ask for your separate consent, and you could withdraw it at any time without affecting what was done until then.

The legal basis for the data you send us

We process your data because you ask us to: you are the one who writes to us, books the conversation or sends us your application.

  • Today, you give us your data in writing, informed by this policy, so that we can reply to you or evaluate your application. That is your authorization, as required by art. 4 of the current text of Law 19.628.
  • Under the reformed law, the basis will be the performance of pre-contractual measures you request (art. 13(c)), including when you send us your application. If you write on behalf of your company, also our legitimate interest in replying to a professional contact (art. 13(d)).
  • If you are in the EEA or the United Kingdom, the GDPR already applies: the basis is taking the steps you ask us to take before entering into a contract, including when you send us your application (art. 6(1)(b)) and, if you write on behalf of your company, our legitimate interest in replying to you (art. 6(1)(f)).

The legal basis for technical data about visits

Technical data about visits is used only to deliver the site and protect it from abuse, and is deleted within the period shown below. For people in the EEA or the United Kingdom, the basis is already our legitimate interest in delivering the site securely (GDPR, art. 6(1)(f)); under the reformed law, it will be the same (art. 13(d)). You can object to this processing by writing to us.

Site usage measurement tells us, in aggregate figures, how the site is used so we can improve it, and it leaves nothing stored in your browser. While the current text of Law 19.628 applies, the measurement does not require your authorization, because that law exempts processing by a private legal entity for its exclusive use for statistical purposes (art. 4, last paragraph). Under the reformed law, the basis will be our legitimate interest in understanding how the site is used (art. 13(d)). We do not measure visits from the European Union, the European Economic Area, the United Kingdom or Switzerland: if you connect from there, the site does not load the measurement.

To object, turn on the Do Not Track or Global Privacy Control signal in your browser: with either one, the site does not load the measurement. You can also write to us at the email address below; since the measurement does not let us tell which visits are yours, we cannot look them up, but we will tell you how to turn on those signals in your browser.

Contact email
contacto@gradiente.cl

Who we share it with

Your data is known only to Gradiente and to the providers that supply the services we need to reply to you, run the site and measure its use. Below we list who they are and whether they process the data on our behalf or under their own policy.

In addition, we will disclose data to an authority only when a law or a court orders it, or when it is necessary to exercise or defend a right before courts or public bodies.

Email and scheduling calendar
Google, through Google Workspace (email and a calendar with a booking page); processes the data on our behalf, under its Cloud Data Processing Addendum
Site hosting
Cloudflare, Inc., through Cloudflare Pages; processes the data on our behalf, under its Data Processing Addendum
Site usage measurement
PostHog Inc., through PostHog Cloud in its European Union region; processes the data on our behalf, under its Data Processing Agreement

International transfers

These providers may process the data outside Chile. Below we show, for each one, the country where it processes the data and the safeguard that protects it. If you are in the EEA or the United Kingdom, we also tell you whether the European Commission has issued an adequacy decision for that country; if it has not, the safeguard is the Commission's standard contractual clauses (GDPR, arts. 45 and 46(2)(c)). For data from the United Kingdom, we apply the equivalent rules of UK law.

Under the reformed law, Law 19.628 will allow data to be transferred to another country when that country has an adequate level of protection or when the transfer is covered by appropriate safeguards, such as contractual clauses (art. 27). The providers we use process your data on our behalf and under their data processing terms.

You can ask us for a copy of those safeguards at the email address above.

Email and scheduling calendar
Google · United States and other countries where Google or its subprocessors process data · For the United States, the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (and its UK Extension), in which Google LLC participates; for other countries, the Commission's standard contractual clauses, under its data processing addendum
Site hosting
Cloudflare · United States and other countries where Cloudflare or its subprocessors process data · For the United States, the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (and its UK Extension), in which Cloudflare, Inc. participates; for transfers that framework does not cover, the Commission's standard contractual clauses, under its data processing addendum
Site usage measurement
PostHog · Germany (PostHog Cloud's European Union region, in Frankfurt), and the United States and other countries where PostHog or its subprocessors process data · For the United States, the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (and its UK Extension), in which PostHog Inc. participates; in addition, the Commission's standard contractual clauses, under its data processing agreement

How long we keep it

If the conversation does not lead to a contract, we delete or anonymize your data within the period shown below, as the reformed law will require for data obtained for pre-contractual measures (art. 14(d)).

If you become a client, we keep the data for as long as the relationship lasts and, afterwards, for as long as legal, tax and accounting obligations require.

We keep applications only as long as needed to evaluate them, at most for the period shown below, and delete them sooner if you ask us to.

The hosting provider keeps technical data about visits under its own retention period, as shown below.

We keep site usage measurement data within the period shown below: once a year we keep only aggregate figures and delete all measurement data in PostHog.

Contacts that do not move forward
12 months from the last contact
Applications
12 months from when we receive them, or sooner if you ask us to
Technical data about visits
Under the retention period of Cloudflare, our hosting provider
Site usage measurement
Up to 13 months (once a year we keep only aggregate figures and delete all measurement data in PostHog)

Your rights

If you are in the EEA or the United Kingdom, the GDPR gives you the rights of access, rectification, erasure, restriction of processing, objection and portability (arts. 15 to 18, 20 and 21). Wherever you are, you can ask us at any time for:

Access

Confirmation of whether we process your data and a copy of it, with its source, its purpose, its recipients, how long we will keep it and, where applicable, the legitimate interest we rely on.

Rectification

Correction of data that is inaccurate, out of date or incomplete.

Erasure

Deletion of your data.

Objection

An end to the processing of your data for a specific purpose.

Portability

The data you gave us, in a commonly used electronic format.

Blocking

A temporary suspension of processing while we resolve a request for rectification, erasure or objection; we reply to that request within 2 business days. Under the GDPR, the closest right is restriction of processing.

How to exercise your rights

Write to us at the email address below with your name, the right you are exercising and the data it refers to. If needed, we will ask you to confirm your identity. Exercising these rights is free of charge. We will confirm that we received your request. Tell us the email or postal address where you want to receive the reply.

While the current text of Law 19.628 applies, we reply within 2 business days, as its art. 16 requires. Under the reformed law, we will reply within 30 calendar days, extendable once by up to another 30 (art. 11). If you are in the EEA or the United Kingdom, we reply within one month (GDPR, art. 12(3)).

Contact email
contacto@gradiente.cl

If you are not satisfied with our reply

While the current text of Law 19.628 applies, if we do not reply within 2 business days or we reject your request, you can go to the civil court of first instance (juez de letras en lo civil) of our domicile (art. 16). Under the reformed law, you will be able to file a complaint with the Personal Data Protection Agency within 30 business days of our reply or of the deadline for giving it (arts. 11 and 41).

If you are in the EEA or the United Kingdom, you can also lodge a complaint with a supervisory authority, in particular the one in the country where you live, where you work or where you believe the infringement took place (GDPR, art. 77(1)); in the United Kingdom, that is the Information Commissioner's Office (ICO).

How we protect your data

We apply technical and organizational measures appropriate to the processing to protect your data. The main ones are listed below.

This site has no forms and no user accounts.

Main measures
access to your data only for those who need it to reply to you, two-step verification on email and calendar, and the site served only over an encrypted connection (HTTPS)

What the site stores in your browser

We do not use cookies on this site. Site usage measurement leaves nothing stored in your browser: when it loads, PostHog's code checks whether the browser supports local storage, by writing and immediately deleting a test value that contains no data about you, and looks at what the browser has stored for this site, which is empty. Apart from that measurement, the site has no advertising pixels and no third-party content that tracks your visit. Its fonts and its measurement code are loaded from the site itself.

We do not measure visits from the European Union, the European Economic Area, the United Kingdom or Switzerland, and if your browser sends the Do Not Track or Global Privacy Control signal, the site does not load the measurement.

If you pause the animations, your browser remembers that preference only for the session, on your own device (session storage). That information is not sent to us.

To book a conversation, the booking link takes you to Google Calendar's booking page, on Google's calendar.app.google domain, shown below. That page is served by Google under its own privacy policy, which you can read at the link below. The details of your booking are stored in our calendar, with the provider listed under "Who we share it with".

Changes to this policy

When we change this policy, we will publish the new version on this page, with its number and its date.