1. Controller identity
This policy describes personal data processing carried out by EasyComp, the commercial brand of AMADEA SPA, a digital solutions and applied AI company operating in Chile.
- Legal entity: AMADEA SPA
- Commercial brand: EasyComp
- Country: Chile
- Business address: Calle Los Rabones #898, Colbún, Chile
- General contact email: contacto@easycomp.cl
- Privacy email: contacto@easycomp.cl
2. Scope of this policy
This policy applies to personal data processing related to:
- visitors of the easycomp.cl website;
- people who submit inquiries via the contact form, email, phone, or WhatsApp;
- clients and prospects of professional services (websites, marketing, software, apps, applied AI, and support);
- business users who contract or use EasyComp products, in particular Chat Bot Manager;
- administrators, collaborators, and agents authorized by a client company;
- people who communicate with a client company through channels connected to Chat Bot Manager (for example, WhatsApp);
- people who use Meta login or connection flows to link WhatsApp Business accounts.
Roles in processing. In general:
- EasyComp acts as the data controller for data needed to operate the website, answer inquiries, manage the commercial relationship, create and administer product accounts, authenticate users, maintain security and technical logs, provide support, and invoice.
- For conversations between a client company and its own consumers or contacts in Chat Bot Manager, the client company is normally the controller and EasyComp normally acts as a processor, handling data according to the client's instructions and configuration.
This allocation of roles may change if a specific contract or operation provides otherwise. Client companies must keep their own privacy policies for their consumers and disclose the use of tools such as Chat Bot Manager when applicable.
3. Data that may be processed
Depending on the contact channel, the contracted service, and enabled integrations, EasyComp may receive, temporarily process, or retain the following categories. Not every listed item is stored in every case.
| Category | Examples | Source | Main purpose |
|---|---|---|---|
| Website and contact data |
| The individual, via the form, email, phone, or WhatsApp | Respond to inquiries, schedule meetings, and manage the commercial relationship |
| Product account data |
| The individual; the client company; authentication systems | Create and administer accounts, authenticate, assign permissions, and provide the service |
| Data obtained through Meta |
| Meta / WhatsApp Business Platform; user or business authorization | Connect accounts, send and receive messages, manage templates, and maintain the integration |
| Conversation data |
| Meta / WhatsApp; the client company; human agents; configured automations | Manage conversations, history, assignment, assisted replies, and service continuity |
| Technical data |
| Website or product systems; the user's browser | Security, diagnostics, fraud prevention, and operational improvement |
| Commercial data |
| The client company; payment providers; support interactions | Manage the contractual relationship, billing, and support |
If payment is processed entirely by an external provider, EasyComp may receive only confirmations or payment metadata, without storing full card details.
4. Data sources
Personal data may come from:
- the data subject;
- the client company that contracts services or uses Chat Bot Manager;
- Meta and the WhatsApp Business Platform;
- integrations authorized by the client;
- webhooks and technical events from connected third parties;
- EasyComp technical systems (logs, audit, security);
- providers contracted to deliver services to EasyComp;
- public sources, only when there is a valid legal basis for their use.
5. Purposes
EasyComp processes personal data for specific purposes, including:
- operating the website and answering commercial inquiries;
- providing, configuring, and maintaining contracted services and products;
- authenticating users and controlling access;
- connecting Meta and WhatsApp Business accounts in Chat Bot Manager;
- receiving, sending, and managing messages and conversations;
- generating AI-assisted replies;
- classifying intents or conversations according to configured rules;
- sending Meta-approved templates;
- assigning conversations to human agents;
- keeping history and operational continuity;
- preventing fraud, abuse, and unauthorized access;
- diagnosing and fixing errors;
- providing technical and commercial support;
- performing contracts with business clients;
- complying with applicable legal obligations;
- improving the service through aggregated or anonymized information, when permitted.
6. Legal bases
Depending on the nature of the processing and EasyComp's role, the legal basis may include:
- Consent, when the person gives it freely, specifically, and in an informed way (for example, when authorizing an integration or submitting the contact form).
- Performance of a contract or pre-contractual steps, to provide the contracted service or administer an account.
- Compliance with legal obligations applicable to EasyComp or the client company, as the case may be.
- Legitimate interest, subject to assessment and respect for the data subject's rights (for example, security, fraud prevention, or operational improvement with safeguards).
- Documented instructions from the client controller, when EasyComp acts as a processor for end-contact data.
Consent is not the only legal basis applicable to all processing carried out by EasyComp.
7. Meta and WhatsApp data
The Meta application associated with Chat Bot Manager has the technical name Agent-Chatbot-AI. To connect and operate WhatsApp Business, authorization may be requested for permissions such as:
- public_profile: access to basic authorized profile information (for example, name and identifier) needed to identify the account making the connection.
- business_management: manage Meta business assets, such as accounts and settings required for the integration.
- whatsapp_business_management: manage the WhatsApp Business account, numbers, templates, and related settings.
- whatsapp_business_messaging: send and receive messages through the WhatsApp Business Platform in accordance with Meta rules.
The user or business must expressly authorize the connection. Authorization can be revoked from Meta or by disconnecting the integration in Chat Bot Manager. Revoking permissions or disconnecting an integration does not necessarily mean immediate deletion of all data already processed, when legal, contractual, security, or backup obligations require retention for a defined period.
Meta and WhatsApp policies, terms, and rules also apply to the use of those services.
8. Artificial intelligence and automation
EasyComp may use automation and artificial intelligence, both in professional services and in products such as Chat Bot Manager, to:
- analyze messages or documents;
- detect intent or classify requests;
- search business information configured by the client (for example, FAQ or RAG);
- suggest or generate replies;
- summarize conversations;
- trigger flows configured by the client company.
AI-generated replies may contain errors or inaccuracies. The client company is responsible for reviewing configurations, content, and replies relevant to its operation. A conversation may be handed off to a human agent when the client configures it or when the situation requires it.
Automated decisions with legal or similarly significant effects on people should not be adopted without the corresponding assessment, information, and safeguards. Where applicable, the person may request human intervention.
EasyComp may use language-model providers to deliver these features. Content is sent to operate the service; EasyComp does not use that data to train its own models. The corresponding provider terms also apply.
9. Sensitive data
Neither the website nor Chat Bot Manager is designed to request sensitive data unnecessarily. However, a person might include it voluntarily in a form or conversation (for example, health, biometric, or financial information).
The client company must avoid collecting sensitive data unless it is strictly necessary, have a valid legal basis, and apply enhanced protection measures. EasyComp may apply additional restrictions depending on service configuration and client instructions.
11. Providers and subprocessors
EasyComp may rely on providers that process data on behalf of EasyComp or the client company, as applicable:
| Provider | Service | Data categories | Location / region | Purpose | Policy |
|---|---|---|---|---|---|
| Meta / WhatsApp | WhatsApp Business Platform | Profile, messaging, templates, and business identifiers | United States and other regions according to Meta | Sending, receiving, and managing messages | WhatsApp Privacy Policy |
| Vercel | Hosting and serverless functions | Technical data and request logs; website content | Vercel regions according to deployment | Deploying and running the website and web applications | Vercel Privacy Policy |
| Resend | Transactional email for the contact form | Name, email, company, and message submitted through the form | According to Resend infrastructure | Deliver website inquiries to the EasyComp team | Resend Privacy Policy |
| Supabase | Product authentication, database, and realtime | Account data, conversations, and technical logs | sa-east-1 (São Paulo) | Authentication, storage, and sync for Chat Bot Manager | Supabase Privacy Policy |
| Amazon Web Services (AWS) | Product backend infrastructure | Data processed by the API and related components | sa-east-1 (São Paulo) | Business-logic processing and backend services | AWS Privacy Policy |
| Upstash | Redis (cache and queues) | Temporary processing and queue data | sa-east-1 (São Paulo) | Cache, queues, and temporary processing | Upstash Privacy Policy |
12. International transfers
Some providers may process information outside Chile, even when core product components are deployed in region sa-east-1 (São Paulo).
Where applicable, EasyComp will assess the protection level of the destination country or region and apply available contractual, technical, or organizational safeguards, including provider clauses and reasonable security measures.
Transfers are made to provide the contracted service and to operate the website and required integrations (for example, Meta, cloud infrastructure, transactional email, and AI services).
13. Retention
Data is retained for as long as needed to fulfill the described purposes, client instructions, and applicable legal obligations. When the purpose ends, data is deleted or anonymized, except for legitimate exceptions (security, backups, legal defense, or legal obligations).
| Category | Period | Notes |
|---|---|---|
| Website inquiries | As long as needed to respond and follow up commercially | Contact form, email, and WhatsApp messages. |
| Product user accounts | While the account is active and for an additional period after closure | Needed to provide the service and handle later requests. |
| Organizations | Tied to the contract and billing or support obligations | Includes settings and operational data of the client company. |
| Messages, conversations, files, and media | According to client configuration and operational needs | May be retained while the service is active, unless a deletion request is made. |
| Technical logs, webhooks, and tokens | As long as needed for security, diagnostics, and audit | Tokens are kept until revocation or expiration. |
| Backups | According to scheduled rotation cycles | Final deletion may complete after the next backup cycle. |
| Support and billing | According to tax and contractual obligations in Chile | Tickets, emails, support records, and accounting documents. |
| Privacy requests | As long as needed for compliance and traceability | Record of requests and responses. |
14. Security
EasyComp adopts security measures that are reasonable and proportionate to the risk. Implemented measures include, as applicable:
- role- and permission-based access control;
- multi-tenant isolation by organization or business in products;
- user authentication in products;
- encryption in transit via HTTPS;
- encryption at rest when provided by the contracted infrastructure;
- management of secrets and API credentials;
- activity, error, and technical audit logs;
- backups and recovery procedures;
- token and session revocation;
- least-privilege principle for internal access.
No system is completely invulnerable. EasyComp does not guarantee absolute security, but works to reduce the risk of unauthorized access, loss, or alteration of data.
15. Individual rights
Under applicable Chilean law, including Law No. 19.628 and, as of December 1, 2026, the applicable provisions of Law No. 21.719, data subjects may exercise, among others, the following rights:
- access;
- rectification;
- erasure (deletion);
- objection;
- blocking;
- portability, where applicable;
- withdrawal of consent, when processing is based on it.
To exercise these rights, you may write to contacto@easycomp.cl. The request should at least identify:
- the requester's name;
- a contact method for the reply;
- the relationship with EasyComp, the website, a service, or a product such as Chat Bot Manager;
- the related account, company, or number, if known;
- the right you wish to exercise;
- a description of the data or processing concerned.
By default, copies of identity documents will not be requested. Identity verification will be proportionate and will use the least invasive method possible.
EasyComp will respond within a maximum of 30 calendar days, extendable once when legally permitted and needed due to the complexity of the request.
When EasyComp acts as a processor for end-contact data, the request may be forwarded or coordinated with the client company that is the controller.
16. Data deletion
You may request deletion of personal data associated with website inquiries, your account, organization, integrations, or conversations, as described on the dedicated page: Data deletion.
Requests may be made, as applicable, through:
- account or organization settings, when a product function exists;
- disconnecting a Meta or WhatsApp integration;
- email to contacto@easycomp.cl;
- mechanisms provided by Meta, when they apply.
Important: disconnecting Meta, revoking permissions, or closing an account does not always mean automatic and immediate deletion of all data. Some records may be retained for legal, contractual, security, or backup obligations, as described in this policy.
17. Children and adolescents
EasyComp services and products are aimed at businesses and are not directed at children or adolescents as contracting clients.
If a client company uses an EasyComp product to serve minors, that company must have a valid legal basis, provide adequate information, and adopt special protection measures under applicable law.
18. Business client responsibilities
The client company that uses EasyComp products or services, in particular Chat Bot Manager, is responsible for:
- informing its contacts about the processing of their data;
- keeping its own privacy policy up to date;
- having authorization or a legal basis to send messages;
- respecting opt-in and opt-out mechanisms;
- not sending spam or unsolicited communications;
- using Meta-approved templates;
- correctly configuring bots, flows, and human handoff;
- restricting internal access by role;
- not loading unnecessary data into the platform;
- handling rights requests when it acts as controller with respect to its contacts.
19. Changes to this policy
This policy may be updated due to legal, technical, or functional changes to the website, services, or products. The current version shows the last-updated date and version number on this page.
Material changes may be communicated by email, a notice on the website or in the product, or another reasonable channel.
