Legal document

Privacy Policy

How we collect, use and protect your personal data at WiseFollow.

Last updated: April 27, 2026 · Version 2.0 · Applicable globally

30-second summary: WiseFollow is an HSE SaaS platform operated by WiseSolutions SpA, a Chilean company. We collect only the minimum data necessary for the service to function (account details, company information, worker data you choose to manage in the system). We never sell personal data. We comply with the General Data Protection Regulation (GDPR) of the EU, Chilean Law 19.628, Brazilian LGPD, and equivalent regulations in all countries where we operate. You have rights of access, correction, deletion, portability, objection and limitation over your data, exercisable by writing to privacy@wisefollow.com.

1.Data Controller

The data controller for your personal data (hereinafter, the Controller) is:

Legal nameWiseSolutions SpA
Tax ID[WISESOLUTIONS TAX ID]
AddressAv. Nueva Providencia 1881, Of. 1912, Providencia, Santiago, Chile, ZIP 7500520
Emailprivacy@wisefollow.com
Phone+56 9 3860 1043
Websitewww.wisefollow.com

WiseSolutions SpA is the commercial operator of the WiseFollow platform. When a business customer contracts us to manage data of their workers, contractors or third parties, the customer acts as the Controller of processing and WiseFollow acts as the Data Processor in the terms of Article 28 GDPR. In those cases we sign a Data Processing Agreement (DPA) that governs processing.

Representative in the European Union (Article 27 GDPR). For processing the data of persons resident in the EU, we have designated a local representative as required by GDPR. Contact details for the representative: [NAME AND ADDRESS OF EU REPRESENTATIVE — TO BE COMPLETED BEFORE LAUNCH]. While this field is not completed, we do not process data of EU residents beyond the information strictly necessary to respond to commercial inquiries initiated by the individual themselves.

2.Data Protection Officer (DPO)

We have designated a Data Protection Officer (DPO) responsible for ensuring regulatory compliance, addressing data subject inquiries and serving as the point of contact with supervisory authorities:

DPO Name[DPO NAME]
Emaildpo@wisefollow.com
Contact languagesSpanish, English, Italian

You can contact the DPO directly for any matter relating to the processing of your personal data. We respond within a maximum of 30 calendar days as per Article 12 GDPR (extendable to 60 days if the request is complex, in which case we will inform you of the reason for the extension).

3.What data we collect

We collect only the data necessary to provide the service. We categorize data according to its source:

3.1. Data you provide directly to us

3.2. Data generated when using the service

3.3. Data of workers and contractors you manage

When you use WiseFollow to manage your workers and contractors, you upload third-party data: names, Tax ID, job title, certificates, trainings, medical examinations, PPE records, photos in inspections, digital signatures. In these cases you are the Controller and WiseFollow is the Processor. You are responsible for informing those third parties of processing, obtaining their consent where applicable, and ensuring the processing has a legitimate legal basis (typically the employment or contractual relationship you maintain with them, as per Article 6.1.b GDPR and equivalent local regulations).

Special categories of data. WiseFollow may process data relating to health when you manage medical examinations, workplace accidents or medical restrictions of your workers. These are special category data (Article 9 GDPR) and require strengthened legal basis. Your use of these modules requires explicit worker consent or that processing is covered by local labor legislation (Chilean Supreme Decree 109, Italian D.Lgs. 81/2008, Mexican NOM-035, etc.).

4.Purposes and legal basis for processing

Each processing of personal data has a specific purpose and legal basis as per Article 6 GDPR (and equivalent regulations):

PurposeLegal basis
Create and maintain your account · provide contracted servicePerformance of contract (Art. 6.1.b GDPR)
Process payments and issue invoicesPerformance of contract + tax obligation (Art. 6.1.b and 6.1.c)
Answer inquiries, provide technical support and handle claimsPerformance of contract and legitimate interest (Art. 6.1.b and 6.1.f)
Maintain platform security · prevent fraudLegitimate interest (Art. 6.1.f)
Comply with legal and tax obligationsLegal obligation (Art. 6.1.c)
Send commercial communications about WiseFollow (newsletter, product updates)Consent (Art. 6.1.a) — revocable at any time
Anonymized statistical analysis and product improvementLegitimate interest (Art. 6.1.f), always anonymized or aggregated
Analytics and marketing cookiesExplicit consent (Art. 6.1.a) — managed through the cookie banner

When the legal basis is consent, you can withdraw it at any time without affecting the lawfulness of prior processing. When the basis is legitimate interest, we have performed the corresponding balancing test and you can object on grounds derived from your particular situation (Article 21 GDPR).

5.Who we share data with

WiseFollow does not sell personal data. We share information only with the following third parties, all of them subject to data processing contracts (DPAs) that require them to process data solely according to our instructions:

Category of recipientProvider / purpose
Infrastructure provider (hosting)[AWS / GOOGLE CLOUD / AZURE — to be confirmed] · servers in LATAM and Europe
Transactional email provider[SENDGRID / RESEND / POSTMARK]
Payment processor[STRIPE / MERCADOPAGO / KHIPU]
Web analyticsGoogle Analytics 4 (data pseudonymized, truncated IP, only if you accept analytics cookies)
Customer support[INTERCOM / FRESHDESK / ZENDESK — if applicable]
AI services (AI modules)[ANTHROPIC / OPENAI / GOOGLE — LLM model providers] · data sent anonymized or pseudonymized
Legal and accounting advisorsUnder duty of professional confidentiality
Competent authoritiesWhen there is legal obligation (court order, administrative request)

The complete and updated list of sub-processors is available upon request by writing to dpo@wisefollow.com.

6.International data transfers

WiseFollow operates from Chile and provides services to customers in Chile, Peru, Colombia, Argentina, Guatemala, Mexico, Brazil and Italy. This involves international data transfers outside the European Economic Area (EEA), United Kingdom and other territories with enhanced protection regulations.

To ensure an adequate level of protection, we apply the following mechanisms:

You can obtain a copy of the safeguards applicable to each transfer by writing to dpo@wisefollow.com.

7.Retention periods

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Type of dataRetention period
Active user account dataWhile the account is active
Data after account cancellation30 days for download + suspension · then irreversible deletion
Billing data6 years from issuance (tax obligation, local tax regulations)
Security and audit logs12 months
Inspections, findings, action plans and HSE evidence5 years from generation (while account is active) · 30 days after cancellation
Marketing data (newsletter)Until you withdraw consent
Analytics cookiesMaximum 14 months (Google Analytics 4 with anonymization)

After these periods, data is deleted irreversibly or anonymized so it cannot be associated with an identified or identifiable person.

8.Your rights

As a data subject, you have the following rights guaranteed by GDPR (Articles 15-22), Chilean Law 19.628, Brazilian LGPD and equivalent regulations:

9.How to exercise your rights

You can exercise any of your rights by sending an email to privacy@wisefollow.com with:

  1. Clear identification (name, email associated with your WiseFollow account).
  2. Description of the right you wish to exercise.
  3. Data to which your request refers.
  4. Copy of your identity document (only if necessary to verify your identity — we process it only for this verification and delete it when the case closes).

We will respond within a maximum of 30 calendar days from receipt of your request, extendable to 60 days in complex cases (we will inform you of the reason for the extension). Exercise of rights is free of charge; we can only charge when requests are manifestly unfounded or excessive (Article 12.5 GDPR), always justifying this in advance.

If you believe we have not properly addressed your request, you can file a complaint with the competent supervisory authority (see section 15).

10.Automated decision-making and Artificial Intelligence

WiseFollow uses Artificial Intelligence in several product modules: deviation detection in inspections, action plan suggestions, risk assessment in work permits, data extraction from documents.

Important. AI suggestions are not binding automated decisions in the sense of Article 22 GDPR. AI assists the human user (supervisor, safety officer, administrator) who makes the final decision with full discretion. No action plan, finding, sanction or decision that significantly affects a worker is executed automatically without human review.

What AI does do:

If AI processing were to produce legal or significant effects on you, you have the right to obtain human intervention, express your point of view and contest the decision (Article 22.3 GDPR).

For technical questions about how AI models work and data sent to external providers, write to dpo@wisefollow.com.

11.Cookies and similar technologies

We use cookies and similar technologies (localStorage, sessionStorage, pixels) to make the site function, analyze its use and, where applicable, offer you relevant content. We categorize cookies by purpose:

11.1. Strictly necessary cookies

Essential for site operation. Do not require consent as per Article 5.3 of the ePrivacy Directive. Include: session cookie (authentication), CSRF token (form security), cookie preference banner (memory of your choice).

11.2. Functional cookies

Remember your preferences to improve your experience. Activated only with your consent. Include: selected language, chosen plan in price selector, closed language banner.

11.3. Analytics cookies

Help us understand how the site is used. Activated only with your consent. Provider: Google Analytics 4 with IP anonymization and reduced retention (14 months). We pseudonymize identifiers before sending.

11.4. Marketing cookies

Allow us to measure the effectiveness of our campaigns on other platforms and show relevant ads. Activated only with your consent. Possible providers: [META PIXEL / GOOGLE ADS / LINKEDIN INSIGHT — activate only those in use].

11.5. Managing your consent

When you first visit the site, we show a consent banner where you can:

You can change your choice at any time by clicking the "🍪 Cookies" button that appears at the bottom left of the screen.

12.Data security

We apply appropriate technical and organizational measures as per Article 32 GDPR to ensure a level of security appropriate to the risk:

13.Children

WiseFollow is a business tool intended exclusively for professionals over 18 years old. We do not knowingly collect data from minors. If you discover that a minor under 18 has provided us with personal data, contact us immediately at privacy@wisefollow.com and we will delete that data.

14.Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, legislation or service. Material changes will be notified by:

The date of last update appears at the beginning of the document. We recommend you review this policy periodically.

15.Complaints to supervisory authorities

If you believe that processing of your personal data violates applicable law, you have the right to file a complaint with the competent supervisory authority of the country where you habitually reside, where you work or where the alleged violation occurred (Article 77 GDPR):

CountrySupervisory authority
🇮🇹 ItalyGarante per la protezione dei dati personali · garanteprivacy.it
🇨🇱 ChileConsejo para la Transparencia / soon the Data Protection Agency · consejotransparencia.cl
🇧🇷 BrazilAutoridade Nacional de Proteção de Dados (ANPD) · gov.br/anpd
🇲🇽 MexicoINAI · home.inai.org.mx
🇨🇴 ColombiaSuperintendencia de Industria y Comercio · sic.gov.co
🇵🇪 PeruAutoridad Nacional de Protección de Datos Personales · gob.pe/anpdp
🇦🇷 ArgentinaAgencia de Acceso a la Información Pública · argentina.gob.ar/aaip
🇬🇹 GuatemalaProcuraduría de los Derechos Humanos · pdh.org.gt

Before contacting the supervisory authority, we appreciate if you try to resolve the matter by contacting us directly — most inquiries are resolved quickly with the DPO without the need for formal proceedings.

Final note. This policy is available in Spanish at this time. English, Italian and Portuguese versions will be available soon. In the meantime, if you need assistance in another language, write to privacy@wisefollow.com and we will address your inquiry in Spanish, English or Italian.