Privacy policy

This policy has two parts, and the difference between them decides who you should write to.

In force since 2026-09-03.

Part A · The data GRATOX answers for

Your account, your visit to this site and what you write to us. Here the contact is GRATOX.

What this part covers

The data GRATOX decides to keep on its own account: your platform account, your visit to this site, and whatever you write to us. Here GRATOX is the controller, and answers directly.

What is kept, and what for

  • Your account: name, email, when you last signed in and from which trusted devices. It exists so you can sign in and so the company knows who did what.
  • Technical records: errors, slow responses and failed sign-in attempts. They keep the platform running and reveal improper access.
  • Site visits, in aggregate. They identify no one and are not linked to your account.
  • Whatever you write to our contact address, so we can reply.

What is not done

Data is not sold. It is not disclosed to third parties other than the providers that keep the platform running, all of which are published. It is not used for advertising or to train artificial intelligence models.

What you can ask for, and from whom

About this data, and only this, you can ask GRATOX what it holds, to correct it, to delete it, or to hand it over in a file. We answer within 30 days.

There is a limit. While your company keeps your account active, GRATOX cannot delete it. That decision is theirs, and the request is passed on to them.

Part B · Project data, which belongs to your company

Reports, photographs, hours and documents. Here the contact is NOT GRATOX: it is your company.

What this part covers

Everything inside a project: site reports, photographs, hours worked, personnel ID numbers, documents. A client company uploads it and decides about it. GRATOX only processes it on their instructions.

What that means in practice

  • GRATOX does not use that data for its own purposes, does not sell it and does not disclose it.
  • If you ask for something there to be corrected or deleted, the request goes to your company. GRATOX cannot resolve it alone: its contract expressly forbids it.
  • When a company stops being a client, its data is deleted or returned to them, as they choose. The time frames are below.

How long it is kept afterwards

GRATOX does not process this data on its own behalf, so these time frames are its default offer: if your company asks for something else in its contract, its instruction prevails.

  • For the first 30 days after the service ends, the company can ask GRATOX for a complete export of its data, delivered as a file. After that period there is nothing left to export.
  • At 90 days, everything is deleted from the database: projects, reports, photographs, hours and personnel. That period covers the 30-day rescue window plus the time needed for the deletion to reach the providers that host the information.
  • Backups are kept for seven days, so they disappear within the week following that deletion.
  • If your company wants it deleted sooner, it can ask and it will be done without waiting for the deadline.
  • These time frames are set by GRATOX: no Chilean law imposes them. If they change, it will be announced here.

Who to write to instead

To the address your company has published for personal data matters. You will find it inside the platform, in your menu, under \u201cYour data\u201d. If your company has not declared one yet, ask internally who to contact: GRATOX cannot answer for data that is not its own.

Contact

For part A, or any question about this policy: contacto@gratox.net

The providers involved and the measures protecting all of this are in Subprocessors · Security