Privacy policy
Last updated: 12 September 2026.
This policy covers the data this site collects. The records your organisation loads inside the PAIR product are not governed by this text but by the services agreement: there your organisation is the controller and we act as processor.
Who is responsible for your data
PAIR SERVICES CHILE SPA, Chilean tax ID 78.467.554-8, domiciled at Colocolo 379, oficina 306, Concepción, Chile, is the controller of the personal data collected at pair.cl.
For anything to do with personal data, including exercising your rights, write to contacto@pair.cl.
What this site collects, and what it does not
This site collects whatever you type into the demo form, and nothing else: your name, your work email, your company name and, if you want to tell us which form you use today, the message. That last field is optional and the form submits without it.
There are no tracking cookies, no analytics, no social pixels and not a single resource requested from a third-party server. The typefaces are hosted on our own domain, precisely so we do not leak the IP address of whoever visits us.
Whoever hosts this site — Netlify — logs the IP address and the browser of every request, as any web server does, and keeps the form submission in its own panel before forwarding it to us. We do not control that and we do not use it to profile anyone, but it happens, and it counts as one more processing operation if you are mapping where your data ends up.
- There are no advertising or measurement cookies.
- There is no profiling and no automated decision-making about visitors.
- We do not sell, transfer or exchange personal data with anyone.
What we use that data for
To contact you and arrange the demo you asked for. Nothing else.
The lawful basis is your own request: you write in the form because you want us to get in touch. If you would rather we stopped, say so and we delete the record.
Where it is stored and who processes it
The form is submitted to Netlify, which hosts this site and acts as our processor, and from there we receive it by email. Our product systems run on Google Cloud Platform. The servers of both are in the United States.
Both are infrastructure providers acting on our behalf and under contract. That involves an international data transfer, covered by contractual clauses with adequate safeguards. From 1 December 2026 that transfer is governed by articles 27 to 29 of the text set by Law 21.719.
If we add or change a provider that processes data on our behalf, we say so on this page before they start processing, and we update the date above. That date is how you can check whether the list of processors has changed since you last reviewed it.
Inside the product, and only for image and voice recognition, the content of those captures is processed with Google models. The content of a field marked as reserved is not part of that processing.
How long we keep it
Demo requests are kept for ninety days from the last contact, and then deleted automatically. The deletion is automated: it does not depend on anyone remembering.
If the process picks up again a year later — and in mining it does — by then the period has expired and that form no longer exists: you write to us again and a new record is opened, with its own period.
This is about the data from this site. If you become a customer, the data of the commercial relationship and the records you load inside the product are governed by the services agreement, which sets its own periods: those are not deleted after ninety days.
If you ask us to delete them sooner, they are deleted sooner.
What you can require of us, and from when
Chilean data protection law changes on 1 December 2026, and that changes what you can require of us. The two regimes are set out separately below: what you can exercise today is not the same as what you will be able to exercise from that date.
Until 30 November 2026, Law 19.628 applies: you have rights of access, rectification, cancellation and blocking. They are exercised by writing to contacto@pair.cl.
From 1 December 2026, Law 21.719 applies, adding rights of objection and portability, and enabling a complaint to the Personal Data Protection Agency.
In both cases we answer within the deadlines set by the law applicable at the time, and through the same address.
What protects that data, and what you can audit
Data travels encrypted in transit and is stored encrypted at rest. That encryption is provided by the infrastructure we run on, Google Cloud Platform, and is not an implementation of ours: if your audit asks for evidence of encryption, the evidence that applies is that provider’s.
Access to systems is restricted by role and is logged. We do not hold our own ISO 27001 certification; the certification belongs to the infrastructure.
If a breach affecting your personal data were to occur, we notify you at the address you gave us, without undue delay, with what we know and what we are doing.
The data your organisation loads into the product
This policy covers the website. It is separate from the data your organisation loads inside the PAIR product: there your organisation is the controller and we act as processor, with the obligations and limits set by the services agreement.
Inside the product, each organisation is isolated from every other by access rule, each person’s access is defined by you and not by us, and the personal data appearing in a photograph — national ID numbers, faces — can be redacted with the product’s redaction function.
Changes
If we change this policy, we change the date above too. Changes affecting what we do with data already collected are notified by email to those concerned before they take effect.