⚠️ INFORMATIVE TRANSLATION — NOT BINDING. The Spanish version at
../../legal/ is the authoritative text and the only one that may be signed,
published or presented to a third party. This English rendering exists so that non-Spanish readers
can review the content; where the two differ, Spanish governs. Like its original, it is an
unreviewed working draft — nothing here is legal advice, and nothing is final until a Chilean
data-protection lawyer has signed off.
- Purpose. The Processor will process personal data on behalf of the Controller solely to provide the Softcrum Suite services (contracted modules), in accordance with the Controller’s documented instructions expressed through the platform configuration and this annex.
- Data and data subjects. Categories: identification and contact data of the Controller’s end customers (including identity document where the Controller enables it), transactional and interaction behaviour data, preferences and consents. Data subjects: end customers, commercial contacts and users of the Controller.
- Duration. The term of the main contract; on termination, deletion or return per clause 10.
- Processor obligations. (a) process only under instructions; (b) confidentiality of personnel; (c) security measures of the Security Annex (TOMs); (d) assist the Controller in handling data subject rights (access, rectification, erasure, objection, portability) through platform features, execution within ≤30 days; (e) assist with impact assessments and consultations with the authority; (f) maintain a record of processing activities; (g) make available the information necessary to demonstrate compliance.
- Sub-processors. General authorisation for the sub-processors listed publicly at [trust center URL]; the Processor will notify additions [30] days in advance, and the Controller may object on reasoned grounds. The Processor is liable for its sub-processors.
- International transfers. Sub-processors may process data outside Chile; basis: contractual clauses and the guarantees stated in the sub-processor list, in accordance with the transfer regime of Ley 21.719.
- Security breaches. The Processor will notify the Controller without undue delay and at the latest within [48] hours of becoming aware, with the information available (scope, categories, measures). Notification to the authority and to data subjects is the Controller’s responsibility; the Processor will provide assistance.
- Audit. At most [1] time per year, with [15] days’ notice, by questionnaire and documentary evidence; on-site audit only upon demonstrated serious breach, at the Controller’s cost.
- Liability. In accordance with the liability regime of the main contract; each party is liable for the infringements attributable to it under its role.
- Termination. At the Controller’s election: export of data in a structured, commonly used format followed by deletion, or direct deletion; a deletion certificate is available. Accounting and ledger records are anonymized.