Legal

Privacy Policy

Last updated: April 9, 2026Jurisdiction: Law No. 19,628 — Chile

This Policy describes how SOTA SpA (hereinafter “SOTA”) collects, uses and protects personal data in the course of providing its services. It applies to the contact and access data of representatives of client companies, and to the technical data generated during use of the platform.

01

Data controller

The controller of personal data is SOTA SpA, domiciled in Santiago, Chile. For privacy enquiries, you may write to contacto@sotaops.com.


02

Data we collect

SOTA collects three categories of data:

Client company data

Trade name or legal name, tax ID and billing details required for the contractual relationship.

Platform user data

Name and email address of the people authorized by the client company to access the service. This data is used exclusively to manage access and service communications.

Technical and operational data

Data from the Client's management systems (sales, inventory, suppliers) that the Client itself integrates into the platform in order to receive the service. Session logs, IP address and platform usage data are also recorded for security and support purposes.

SOTA does not collect data about the Client's end consumers. The sales data the Client integrates corresponds to aggregated transactions or to its own system, not to personal data of its customers.


03

Purposes of processing

SOTA processes data for the following purposes:

  • Service delivery: Processing the Client's data to generate forecasts, recommendations and analytics. Legal basis: performance of the contract.
  • Service communications: Notifying the Client about updates, maintenance and relevant changes. Legal basis: performance of the contract.
  • Security and fraud prevention: Detecting unauthorized access and anomalous activity, and protecting the integrity of the platform. Legal basis: legitimate interest.
  • Service improvement: Analyzing anonymized usage patterns to improve the platform's functionality. Legal basis: legitimate interest.
  • Legal compliance: Retaining records where the law requires it. Legal basis: legal obligation.

SOTA will not use the Client's data for purposes other than those described here without obtaining prior consent.


04

Data and artificial intelligence

The Client's operational data (sales history, inventory levels, supplier information) is processed by SOTA's artificial intelligence models to generate demand forecasts and purchase order recommendations.

This processing is automated. Under Law No. 21,719, the Client has the right to:

  • Request an explanation of the factors that determined a specific recommendation.
  • Challenge a recommendation and request a review.
  • Not be subject to decisions producing significant effects based solely on automated processing, without human intervention.

SOTA does not use the Client's data to train models that serve other clients. Models are calibrated with each organization's own data.


05

International data transfers

To deliver the service, SOTA uses cloud provider infrastructure that may be located outside Chile, including servers in the United States. These transfers are made under contractual agreements requiring providers to maintain protection levels equivalent to those required by Chilean law.

Chile holds an adequacy recognition for data protection from the European Union, which facilitates data flows with European counterparties.


06

Data retention

SOTA retains data for the minimum time necessary to fulfil the purpose that gave rise to its processing:

Data typeRetention period
Client operational data (ERP, inventory)Term of the contract + 60 days
User access dataTerm of the contract + 60 days
Security and session logs12 months
Technical support records90 days after the case is closed
Billing dataAs required by applicable tax obligations

Once the period has elapsed, data is permanently deleted unless there is a legal obligation to retain it.


07

ARCO rights

Under Law No. 19,628 and the principles of Law No. 21,719, the data subject has the following rights:

A

Access

Know what personal data SOTA processes, for what purpose and for how long.

R

Rectification

Request correction of inaccurate, incomplete or outdated data.

C

Cancellation

Request deletion of personal data where there is no legal obligation to retain it.

O

Objection

Object to the processing of data for specific purposes, such as marketing communications.

P

Portability

Receive the data in a structured, commonly used format.

To exercise any of these rights, send your request to contacto@sotaops.com. SOTA will respond within a maximum of 20 business days.


08

Security

SOTA applies technical and organizational measures to protect data against unauthorized access, loss or disclosure, including encryption in transit and at rest, role-based access control and audit logging.

In the event of a security breach affecting personal data, SOTA will notify the Client and the competent authority within 72 hours of detection, as established in Law No. 21,719.


09

Changes to this policy

SOTA may update this Policy with 30 days prior notice to the registered contact email. If the changes involve new processing purposes, express consent will be requested. Continued use of the service after that period constitutes acceptance of the changes.


10

Contact

For privacy enquiries, exercising ARCO rights or any matter related to the processing of your data:

SOTA SpA

Santiago, Chile

contacto@sotaops.com