Effective Date: October 6, 2026
Masnet SpA, a corporation by shares incorporated under Chilean law.
1. Data Controller
Masnet SpA (Chile) is the data controller responsible for the processing of personal data through the Platform. Contact information for the controller and/or privacy contact:
- Privacy: [email protected]
- Legal: [email protected]
2. Scope
This Policy applies to the personal data of registered users and Client representatives who use the Masnet Platform and APIs.
2.1. International Scope and Principles
Although Masnet is a Chilean company and the service is primarily oriented toward the domestic market, we voluntarily and reasonably apply principles of privacy by design, data minimization, purpose limitation, and transparency consistent with international standards (GDPR/EU) and EDPB best practices when interacting with data subjects located outside Chile, without altering the applicable law stated in this Policy.
3. Data We Process
We may process the following categories:
- Identification and contact information: full name, RUT (Rol Único Tributario - Chilean Tax ID), telephone, email address; where applicable, business name and RUT of the company.
- Platform activity: search history for tenders, agile purchases, purchase orders, interests, tracked items and configured notifications; technical metadata (e.g., IP addresses and access logs).
- Internal operations data: workflows, assignments, internal comments, strategic discussions, drafts, preliminary versions, and Client configurations. This data is treated as confidential information of the Client.
- Data the user adds: documents and files, notes, messages, emails drafted or sent from the Platform, and voice recordings the user submits for transcription.
- Integrations the user enables: in Telegram, the username and the identifier of the linked chat; in Masnet Gateway, the extension for Chromium browsers, the identity of the Mercado Público session (name, company, and RUT) and the data of the operations the user performs with it. Masnet Gateway does not request or store the Mercado Público password.
- Billing and payment: business name, RUT, and tax data for electronic invoicing; if the Client registers a card, its brand and last four digits. The full card number is processed by the payment processor, not by Masnet.
- Authentication: the password, which we keep only as an irreversible hash; verification codes sent by email for passwordless sign-in and account validation; the second factor (TOTP) and passkeys the user enables; and the related security events.
- Device signals for access security: when you sign in, we process limited technical information from your browser and device in order to protect your account, detect anomalous access, and apply additional verifications when necessary. This information may include: browser family and major version, operating system, timezone, language, device type (desktop, mobile, or tablet), screen resolution category, touch capability, and a first-party device identifier issued by our server. These signals are supplemented with data derived from the IP address (country, network provider). We do not collect detailed hardware attributes (GPU, memory, processors), battery data, storage, multimedia devices, or browser fingerprints. We do not use these signals for advertising, cross-site tracking, or commercial profiling.
- Cookies and browser storage: The Platform uses only essential cookies for session, authentication, and trusted device identification purposes. The `Auth-Token` session cookie uses Secure, HttpOnly, and SameSite=Strict; the `__mdt` device identification cookie uses Secure, HttpOnly, and SameSite=Lax. These cookies are strictly necessary for the service to function and account security, and do not require prior consent. We do not use third-party cookies or third-party web analytics tools, neither on the Platform nor on the masnet.com site. The Platform keeps preferences, drafts, and local working copies in the browser (IndexedDB and localStorage) to recover what was written and to load faster; signing out deletes the drafts and the local working copies. The masnet.com site stores theme, language, and animation preferences in the browser and, if a session is active, queries it to show the user's avatar. Should it become necessary to employ non-essential cookies in the future, we will update this Policy and request prior consent through appropriate mechanisms.
- Email delivery and reading: the email provider records delivery, opens, and link clicks for the emails the Platform sends, including those the user sends from it.
Important regarding bid documents: Documents, prices, and information that the Client formally submits in the official system of Mercado Público will become public in accordance with Law No. 20.285 on Transparency after the tender closes. This publication is performed by the official public procurement system and is not Masnet's responsibility. Masnet processes such data only while it remains as drafts or internal preparation within the Platform.
4. Data Sources
- Data provided by the User/Client when registering, configuring their account, or using the Platform.
- Data generated by the Platform during its use (logs, security and audit events), automatically.
- Public data sourced from the Mercado Público system and State transparency sources: tenders, awards, purchase orders, and other processes published by public agencies, of a public and reusable nature in accordance with transparency regulations (Law 20.285) and ChileCompra's open data policy.
Corrections of source data. When a data subject detects inaccuracies in data sourced from Mercado Público, Masnet will manage its update from the source (without prejudice to the rights of access, rectification, cancellation, and objection that the data subject holds vis-à-vis Masnet) and will propagate the changes after the next synchronization with the public source.
5. Processing Purposes
We process data for:
- Authentication and security (sign-in with or without a password, second factor, passkeys, account verifications, and fraud prevention).
- Provision of contracted SaaS services and APIs (search, tracking, analytics, performance reports, KPIs, and market participation).
- Artificial intelligence functionalities the user requests: analysis of tenders and documents, drafting of emails and templates, voice transcription, description of catalog products, and prioritization of opportunities.
- Billing and collection of the subscription.
- Transactional notifications (alerts for new tenders, awards, purchase orders, process tracking, and user activity).
- Operational metrics, maintenance, and Platform improvement.
- Technical support and handling of Client requests.
- Legal compliance and responding to requests from competent authorities.
- Optional marketing (only if there is contractual authorization or express consent from the data subject).
6. Legal Bases (Law No. 19.628 in force)
In accordance with Law No. 19.628, we process data under the following bases:
- Contractual performance: provision of service to the Client/registered User pursuant to the subscription agreement.
- Consent: where required, for example for optional commercial communications or account creation when applicable.
- Legal obligation: when regulations require us to process or retain certain data (e.g., tax, accounting obligations, or authority requirements).
- Processing of data from publicly accessible sources (art. 4 Law 19.628): when we process data from tenders, awards, purchase orders, and other information published by public agencies in compliance with Law 20.285 and transparency regulations.
Regulatory transition (Law No. 21.719). Law 21.719 (published on December 13, 2024) which amends Law No. 19.628 and establishes a new personal data protection framework, will enter into force after a transitional period of 24 months. Masnet will adapt this Policy and its compliance program (including new legal bases, expanded rights, notification obligations, and supervision by the future Data Protection Agency) before its full enforceability.
6.1. Legal Bases for Data Subjects in Other Jurisdictions
When we process data of data subjects located in jurisdictions with specific data protection frameworks, we will apply the following bases and safeguards:
- Data subjects in the EEA/United Kingdom: Masnet will act as a data processor with respect to Client data, and will make available a Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses (SCCs 2021/914) of the European Commission.
- Data subjects in Brazil: Masnet will observe the principles and rights established in the LGPD (Lei Geral de Proteção de Dados) when processing data of data subjects located in Brazil.
- California consumers (USA): Masnet will respect rights under CCPA/CPRA when applicable, including requests for access, deletion, and limitation of use of sensitive personal information.
7. Disclosures, Processors, and Sub-processors
We do not share personal data with third parties for their own purposes or commercial use.
Data processors. Masnet may engage vendors as data processors (e.g., cloud infrastructure services, delivery and protection network, email delivery, artificial intelligence models, payment processing, electronic invoicing, messaging, security monitoring, anti-abuse protection, backups), under contract and with reasonable security measures. Masnet remains responsible for compliance with its data protection obligations.
Information on sub-processors. Information regarding the categories of sub-processors used will be available upon request via [email protected] or [email protected]. For enterprise clients with specific requirements, Masnet may offer notification of material changes under contractually agreed terms. Masnet will respond to requests for information on sub-processors within 10 business days of receipt.
8. International Transfers
To provide the service, the following vendors process personal data outside Chile:
- Cloudflare (United States, with a global network): all traffic to the Platform and to the masnet.com site passes through its delivery and protection network. It also stores the files in companies' document vault; companies with a contractual residency requirement can store them on infrastructure operated by Masnet.
- Postmark (United States): sending and receiving the Platform's emails, with their recipients, content, and attachments.
- Artificial intelligence model providers (mainly in the United States; depending on the provider, other countries as well): they receive the content the requested functionality requires, such as the question, the retrieved document excerpts, the text to be drafted, or, if Masnet's own transcription service is unavailable, the audio to be transcribed. Masnet's model plane chooses the provider for each functionality; the current list is available upon request under Section 7.
- Telegram, when the user links their account: the alerts and messages the Platform sends to that chat.
- Browser notification services (for example, Google, Mozilla, Apple, or Microsoft), when the user enables notifications: the content of each alert.
Text extraction and OCR of documents, search indexes, and voice transcription run mainly on infrastructure operated by Masnet.
These transfers are necessary to perform the contract with the Client and are governed by each vendor's data processing terms. Each vendor receives only the data its function requires. For data subjects in the EEA/United Kingdom, the Standard Contractual Clauses (SCCs 2021/914) may be incorporated through the DPA in Annex F. If we add a new destination, we will update this Section stating the data categories, the countries or regions, and the protective measures.
9. Retention Periods
We retain data by categories, in accordance with the following rules:
- Account, contract, and billing data: up to 6 years from account closure, to comply with accounting, tax obligations (Chilean Internal Revenue Service), and defense of legitimate interests in case of litigation (general statute of limitations for ordinary actions: 5 years; tax audit period: 3 to 6 years).
- Access logs, security logs, and audit records: between 12 and 24 months, depending on the nature of the record and security requirements.
- Device signals and login risk events: risk assessment events are retained for 90 days; trusted device records are retained for 180 days from last use; associated IP addresses are nullified after 30 days, retaining only country and network provider for security analysis.
- Technical support and incident data: up to 24 months after ticket or incident resolution, for service improvement and trend analysis purposes.
- Backups: retention in rotating cycles of 30 to 90 days, according to technical backup policy.
Once the indicated periods are met, we will delete or anonymize the data in accordance with the law and our internal policies, unless there is a legal obligation to retain for a longer period.
10. Information Security
We apply reasonable technical and organizational measures proportionate to the risk, including:
- Encryption of data in transit (TLS) and at rest where appropriate.
- Access control through passwords, verification codes, second factor, or passkeys, and role-based permission management.
- Security monitoring, threat detection, and incident response.
- Periodic backups with rotating retention.
- Internal security policies, staff training, and auditing.
However, no security measure is infallible. The User understands and accepts the inherent risks of all electronic transmission and storage of information.
Incident notification. In case of security incidents affecting personal data, we will assess the risk to data subjects and notify the Client and/or affected data subjects within 72 hours following confirmation of the incident, providing available information on the nature, scope, and measures adopted. This timeframe is established in preparation for the mandatory notification requirements that Law 21.719 will establish upon entry into force.
10.1. Responsible Vulnerability Disclosure (VDP)
Masnet maintains a vulnerability channel at [email protected] and a Responsible Vulnerability Disclosure Policy based on the CISA template and ISO/IEC 29147 standards. We evaluate and manage reports under principles of Coordinated Vulnerability Disclosure, and will not pursue legal action against researchers who report in good faith in accordance with our policy.
10.2. Analytics and Artificial Intelligence Use
Masnet does not use Client Data (including content, metadata, and usage signals) to train, fine-tune, or improve proprietary or third-party artificial intelligence models, unless there is express opt-in consent documented. Artificial intelligence is used by KIM's analysis of tenders and documents, the drafting of emails and templates, voice transcription, the description of catalog products, and the prioritization of opportunities. Each request sends the model provider only the context the functionality requires; Section 8 identifies those providers and their location. Results are kept on the Platform in accordance with Section 9.
11. Data Subject Rights
The personal data subject may exercise the following rights, in accordance with Law No. 19.628:
- Access: know what personal data of theirs is being processed, the purpose, and the source.
- Rectification: request correction of inaccurate or incomplete data.
- Cancellation/Deletion: request deletion of their data when there is no legal obligation to retain it.
- Objection: object to the processing of their data in specific cases permitted by law.
- Blocking: request temporary blocking of their data.
Portability (contractual benefit). Masnet voluntarily offers portability of Client data in standard formats (e.g., CSV, JSON) when technically feasible. When Law 21.719 enters into force, this right will become a mandatory legal entitlement and Masnet will adjust the scope and procedures in accordance with the regulations.
Exercise of rights. To exercise any of these rights, the data subject may send a request to [email protected] or [email protected]. We will respond within the timeframes established by applicable regulations, and may request additional documentation to verify the identity of the requester and prevent unauthorized access.
12. Minors
The Platform is intended for persons of legal age. We do not intentionally register data of persons under 18 years of age. If we detect that data of minors has been collected without consent from their legal representatives, we will proceed to delete it.
13. Changes to this Policy
We may update this Policy to reflect regulatory (including the entry into force of Law 21.719), functional, or contractual changes. We will publish the current version and indicate the update date.
Notification of material changes. When changes are material and significantly affect the rights of data subjects, we will notify by email or through the Platform with reasonable advance notice.
14. Contact and Vulnerability Reporting Channel
Privacy and data protection inquiries:
Security vulnerability reporting:
Note: This Policy is governed by applicable Chilean legislation, particularly Law No. 19.628 (and its amendment by Law No. 21.719 when it enters into force), Law No. 20.285 on transparency, and other applicable regulations.