Privacy and Personal Data Protection Policy
Last updated: May 25, 2026
This English translation is provided for convenience only. In the event of any discrepancy, the Spanish version prevails.
At Porteria SpA ("Porteria" or the "Company"), the protection of personal data is considered an essential part of our activities. We work permanently to offer a better service in compliance with the regulations in force regarding the protection of personal data (the persons concerned, the "Data Subjects"), especially Law No. 19.628 (the "Law").
Taking care of the personal data provided to us by Data Subjects is fundamental for us. Therefore, in this document (the "Privacy Policy") we explain how, and which, personal data Porteria processes with respect to Data Subjects, the purpose and lawful basis on which we process their data, to whom we may communicate or transfer it, how such information is stored and protected, and the processes and rights available to Data Subjects.
This Privacy Policy is incorporated into the Terms and Conditions of contracting with Porteria, and capitalized terms not defined in this instrument shall have the meaning given in said Terms and Conditions.
The Client, in its capacity as Data Controller, must obtain the consent of the Data Subjects or ensure the existence of other lawful bases in accordance with the Law for the processing of their personal data, with Porteria providing the support and technical means necessary for such purpose.
Porteria's Privacy Policy is set forth below.
1. Identification of the Personal Data Processor
- Name: Porteria SpA, Chilean taxpayer ID (RUT) No. 77.749.878-9.
- Address: Avenida Kennedy No. 5.600, office 507, Vitacura, Chile.
- Legal representative: Santiago Larroulet Irarrázaval.
- Email: [email protected]
2. Personal Data Controller
In accordance with this Privacy Policy, the controller of personal data processing shall be:
- The Client: the natural or legal person contracting Porteria's Services, being the Controller of the processing of data of Data Subjects registered through the Software at its facilities (residents, visitors, employees and suppliers).
- Porteria: with respect to the use of the Website and the processing inherent to contract management, billing, administrative communications and service improvement, in which it acts as an independent Controller.
3. Data We Collect and Process
Porteria will use personal data exclusively for security and access control purposes and, where necessary, to assist in the recovery of vehicles reported stolen. No automated analysis, profiling or use of the data for commercial purposes will be carried out.
This processing is always carried out in accordance with the personal data protection regulations in force and adopting reasonable security measures.
All data processing, including by third parties, shall comply with the duty of secrecy or confidentiality and the duty of security. For these purposes, Porteria may collect and process the following data:
- Identity information: first name, surname and national identification document number.
- Contact information: address, email, telephone and other means of communication expressly indicated by the Data Subject.
- Technical or usage information: IP address, device type, operating system, browser, browsing data, access logs and usage history of the Platforms. Geolocation only applies to Clients and Operators who use the Platforms, and its sole purpose is fraud prevention in the use of digital channels; under no circumstances does it apply to Data Subjects registered through identity document scanning.
In connection with the use of the Website, we collect data through cookies such as the type of device used, browser type, operating system, time of access to the Website, browsing time on the Website, web pages visited and information consulted. Device information is also collected, such as hardware model, unique device identifiers and mobile network information. Geolocation may be included to prevent fraud in the use of our digital channels.
The personal data collected by Porteria comes directly from the Data Subject, from third parties authorized by the Data Subject and/or from other sources authorized by the Law.
In particular, data collection may be carried out through the following means:
(i) User creation: when creating a user on one of the Platforms, data such as full name, email and, in certain cases, national identification document number or RUT may be recorded and stored.
(ii) Registration through the application: when using access control tools, data may be captured by scanning the Data Subject's identity document, storing information such as full name, national identification document number, RUT and gender.
All data requested by the Company is necessary for the provision of the Services.
Porteria shall not be liable for errors or damages arising from incorrect or incomplete information provided by the Data Subject.
Porteria does not collect biometric data or sensitive personal data under the legislation in force. The gender data captured from the identity document is processed as ordinary personal data and is used exclusively for statistical purposes and to generate service metrics. Should the Personal Data Protection Agency or applicable regulations classify gender data as sensitive personal data, the Client, in its capacity as Data Controller, must obtain the Data Subject's express consent in accordance with the law, and Porteria will provide the technical assistance necessary to implement such consent mechanism in the Software.
The identity document scan processes the following data: document type, country code, full name, document number, nationality code, date of birth, gender and personal number. However, not all of these data are stored in Porteria's database, such as date of birth and expiration date, among others that may not be stored.
The "gender" field extracted from the identity document is processed for statistical and internal metrics purposes. Should this data be classified as sensitive by the regulations or the competent authority, its processing shall be subject to the lawfulness rules required by law.
For the front-scan OCR mode, the text extracted from the document image is processed using third-party artificial intelligence tools. Said provider acts as a sub-processor, and is contractually barred from using the transmitted data to train its models.
4. Purposes of Data Processing
Porteria will process personal data for the following purposes, distinguishing by subject:
A. Essential service purposes (applicable to all Data Subjects; lawful basis: performance of the contract and/or legitimate interest of the Client):
- Access control and registration of entry/exit of people to the premises;
- Identity verification through identity document scanning;
- Security management of the condominium, company or facility;
- Handling of inquiries and technical support;
- Compliance with legal obligations and requirements of competent authorities;
- Cooperation with insurance companies and authorities in locating or recovering vehicles reported stolen, where applicable;
- Generation of statistical service metrics for the Client's dashboard.
B. Purposes inherent to the contractual relationship with the Client (applicable to data of the Client and its Operators; lawful basis: performance of the contract):
- Management of the contractual relationship, billing and payment management;
- Sending communications regarding the service, updates and changes to the Terms and Conditions;
- Generation of reports and statistics on Software usage.
C. Secondary purposes (applicable exclusively to Clients and Operators who have given specific consent; in no case applicable to visitors, residents or employees registered by document scanning):
- Sending commercial and promotional communications about Porteria services;
- Conducting satisfaction surveys and market research;
- Statistical analysis for Software improvement.
The Data Subject may revoke their consent for secondary purposes at any time, without affecting the lawfulness of prior processing or the provision of the essential service.
5. Lawful Bases for Data Processing
The processing of personal data by Porteria is based on one or more of the following lawful bases:
- When consent is given by the Data Subject freely, in an informed and specific manner as to its purpose or purposes;
- When the processing is necessary to satisfy legitimate interests of the user or of Porteria, as Controller, or of a third party, provided that the rights and freedoms of the Data Subjects are not affected. In any case, Data Subjects may always demand to be informed about the processing affecting them and the legitimate interest on which such processing is based.
The legitimate interests justifying this data processing focus on operational efficiency, risk prevention and continuous improvement of the service offering, and include:
- Security and fraud prevention: using usage information and geolocation data (IP address, device type, location) to prevent, detect and manage criminal, unlawful or fraudulent activities related to the use of our digital channels and the Platform.
- Profiling and commercial segmentation: processing Platform usage data of Clients and Operators to perform statistical analysis, evaluate service quality and offer services compatible with the contracted activity. This purpose applies exclusively to Clients and Operators and in no case to visitors, residents or employees whose data is obtained through identity document scanning. This automated processing is carried out using browsing and transaction patterns, and its intended consequence is the receipt of offers and recommendations adapted to the client or community profile. Data Subjects have the right to object to this processing at any time, requesting human intervention or review of the automated decision.
- Internal operational transfers: communicating or transferring personal data to companies of the same business group or affiliates, provided it is for the purpose of keeping the service available to Users, operating under the same internal standards and policies, and fulfilling the performance of contracts.
- Management and improvement of the contractual relationship: maintaining client records to ensure the proper provision and administration of the contracted Services, including information backup and management of the contractual relationship, provided that this processing does not require compliance with a specific legal or contractual obligation.
Data Subjects have the right to object to this processing based on legitimate interest at any time. If the right to object is exercised, Porteria must stop processing their personal data, unless the Company evidences compelling legitimate grounds for the processing that override their interests, rights and freedoms, or for the establishment, exercise or defense of claims.
6. Data Retention
Personal data is stored on servers located in Chile. It will be kept only for the time necessary to fulfill the purposes indicated above and while a contractual relationship exists between the Company and the User. After such period, it will be deleted or anonymized, unless it is necessary to keep it because the Company is under a legal obligation; it is necessary for compliance with the due diligence, disclosure and reporting obligations established in the applicable tax, administrative, financial, crime prevention and criminal prosecution regulations; or for the specific cases in which the data is necessary for compliance with legal obligations, such as those related to reports and forms associated with the prevention of money laundering and terrorism financing.
7. Transfer of Personal Data
The Company may communicate or transfer personal data to third parties, national or foreign, when necessary for the purposes described, and always in accordance with this Privacy Policy and applicable law. In particular, personal data may be transferred to insurance companies and similar institutions for the location and recovery of vehicles reported stolen, which shall follow the Company's instructions, adopting adequate security and confidentiality measures for the processing of personal data and compliance with the rules governing the protection of private life.
The Company may transfer data to companies in which it is a shareholder, or which are its controllers, subsidiaries or affiliates, or to a parent company or any company of the same group operating under the same internal processes and policies, including companies with current commercial agreements with the Company, provided it is for the purpose of keeping the service available to the client.
Data may also be transferred to third parties ("Providers") that render services associated with the contracts or the commercial relationship regarding the Services (such as, for example, client identification and authentication; marketing; logistics; and delivery of products and services). These Providers will perform their tasks as processors and may only process the data to fulfill the specific engagement entrusted to them.
Data will be transferred when the transfer is necessary or legally required to safeguard a public interest, or for the administration of justice; when the transfer is necessary for the recognition, exercise or defense of a right in judicial proceedings, or for the maintenance or fulfillment of a legal relationship between the corresponding Controller and the Data Subject.
If the Client or Operator itself, as the data subject of its usage data, has given specific consent for this, its data may be shared with data management platforms or marketing tools to carry out marketing, advertising and market research activities. This transfer does not apply in any case to the data of Data Subjects obtained through identity document scanning.
If personal data had been transmitted prior to the date of rectification or cancellation and continues to be processed by third parties, the Personal Data Controller will inform them of such rectification or cancellation request, so that they also proceed to carry it out.
8. Rights of Data Subjects
Data Subjects shall have, without any limitation, all the rights contemplated by the applicable law in force. In particular, the personal data subject may exercise the following rights established by law:
- Access their data and information about its processing by Porteria, as well as know the Privacy Policy to which the processing is subject.
- Request the rectification of incorrect, inaccurate or incomplete data.
- Request the deletion of data when its storage lacks legal basis or when it is outdated, unless a legal exception applies.
- Object to and/or block the processing, in the cases permitted by law where there is legitimate cause and their specific situation so requires in order to avoid harm, or when they do not wish their data to be processed for specific purposes.
- Revoke the consent given, in the manner and to the extent provided by law.
- Portability of personal data, to receive a copy of the personal data in a structured, commonly used format, to transfer it to another provider or service, or to have Porteria send it directly to another Controller when technically possible.
To exercise the rights of access, rectification, cancellation and objection, the Data Subject or their representative must submit a written request sent to the address or email of the corresponding Controller, with the following information: (i) their name and address, email or other means to communicate the response; (ii) documents evidencing their identity (simple copy of official identification) or, where applicable, representation (simple copy of a simple power of attorney); (iii) a clear and precise description of the data and the right to be exercised; (iv) any other element or document facilitating the location of the data; and (v) in the case of rectification, they must indicate the modifications and provide the supporting documentation.
The Company will respond to the Data Subject's request within 2 business days of receipt, in accordance with Article 16 of Law No. 19.628 currently in force. As of December 1, 2026, the response period will be 30 calendar days in accordance with Law No. 21.719. If the request is admissible, it will be implemented within 15 days following communication of the response. In case of denial, Porteria will state the grounds and indicate the Data Subject's right to file a claim with the Personal Data Protection Agency.
To revoke consent, the Data Subject may contact the Client directly in its capacity as Data Controller, or Porteria via [email protected]. It is recommended to also communicate the revocation to the site administration for operational purposes, but this is not a requirement for the revocation to produce its legal effects.
The Data Subject understands that revoking consent for data processing may result in the early termination of the Services, considering that the processing is necessary for the operation of Porteria's Software.
9. Security
The Company has implemented reasonable technical, organizational and administrative measures to protect personal data against unauthorized access, loss, destruction or alteration. These measures include access control, encryption, backups and incident response procedures.
Measures consisting of a combination of physical, technological and administrative security controls are used. In addition, the Company ensures that its staff are duly trained to protect personal data, and endeavors to ensure that the providers it works with meet its security standards. The Company's security procedures require that Data Subjects occasionally be asked for proof of identity before information about their personal data can be provided to them.
10. Cookies
The Platforms may use cookies, their own or third-party, to enable their proper functioning and the provision of the Services. It is the Data Subject's decision to allow the use of cookies or not, but if not allowed, access to certain sections or functionalities may be limited.
Cookies are small text files containing a unique identifier that is stored on the computer or mobile device through which websites or mobile applications are accessed. If the Data Subject has a registered account and logs in through it, the Company could identify them through the use of cookies, linking browsing data with their contact details.
11. Updates to this Privacy Policy
The Company may modify or update this Privacy Policy at any time, communicating its entry into force with reasonable notice and making it available to Clients, Users and Data Subjects through the Company's website and communicating it via the email registered in the application. Changes may also be communicated through different means, for example, a banner, a pop-up or a push notification. In the case of modifications and updates requiring the consent of Data Subjects, the Company will request such consent expressly, in accordance with the legal regulations in force. The date indicated as "last updated" will reflect the version in force.
12. Contact
If you have questions, comments or any communication or request to exercise your rights, you can contact us at: [email protected].