Privacy policy
How Bolder handles your personal data.
Privacy Policy and Data Processing Addendum (DPA) — Bolder
PART I — Privacy Policy
(Bolder as Data Controller)
1. Purpose and data controller
1.1. This Privacy Policy describes how Bolder SpA, RUT 76.066.308-5, domiciled in Santiago, Chile (“Bolder”), processes the personal data of its own Users (Account Holders), of the personnel they authorize to access the platform, and of its business contacts, in its capacity as Data Controller.
1.2. Bolder’s legal representative is Mr. Tomás Pollak Williamson.
1.3. This Policy does not govern the processing that Bolder carries out on behalf of its Users with respect to the data of their End Users — that processing is governed by the Data Processing Addendum (Part II of this document).
2. Personal data that Bolder processes as Controller
2.1. Bolder collects and processes, among others, the following data: name or corporate name, RUT, email address, contact telephone number, billing address, data of the Account’s authorized users, platform usage information, and contact data of persons who interact commercially with Bolder (for example, in a sales or support process).
3. Purposes and lawful bases
3.1. Bolder processes this data in order to: (a) manage the contractual relationship and the provision of the Services; (b) invoice and collect payment for the contracted Plans; (c) provide technical and commercial support; (d) comply with legal and tax obligations; and (e) improve and secure the platform.
3.2. The lawful basis for this processing varies depending on the category of data subject: (a) with respect to the Account Holder, it is the performance of the contract entered into with Bolder (the Terms) and compliance with legal obligations applicable to Bolder; (b) with respect to personnel that the User authorizes to access the platform, who are not a direct party to the contract, it is the legitimate interest of Bolder and of the User itself in allowing such operational access, to the extent necessary for the provision of the Services; and (c) with respect to business contacts (for example, in a sales process), it is Bolder’s legitimate interest in managing that business relationship, or the contact’s own consent where applicable.
3.3. Bolder processes personal data only where there is a lawful basis that justifies it and for specified, explicit and lawful purposes, which are set out in this Policy. Bolder will not use the data for purposes incompatible with those for which it was collected.
3.4. Where the lawful basis is the data subject’s consent, it will be prior, free, informed and specific, will be given through an affirmative act (not through pre-ticked boxes or silence), may be withdrawn at any time as easily as it was given, and Bolder will keep a record of it. In particular, Bolder will not send commercial communications unrelated to the provision of the Services without first having such consent.
4. Processors used by Bolder
4.1. To provide the Services, Bolder relies on external providers that process personal data on its behalf, as Bolder’s processors, including:
- Infrastructure, hosting and database: Linode (Akamai), in the United States.
- Backups: Amazon Web Services (Amazon S3), in the United States.
- Content delivery network (CDN) and network security: Cloudflare.
- Email delivery: Mailgun.
- Payment processing for Bolder’s Plans: Stripe.
- Customer support: HelpScout and Slack.
4.2. Bolder enters into written contracts with its processors that oblige them to process data only on its instructions, to keep it confidential and to apply appropriate security measures, and Bolder maintains an updated inventory of them.
4.3. Bolder will report in this Policy, with reasonable advance notice, the addition or replacement of processors that process the personal data of the data subjects referred to in this Part I, as well as any relevant change in the country or location where such data is hosted.
5. International data transfers
5.1. Part of the infrastructure Bolder uses to provide the Services hosts personal data outside Chile, including in the United States. Bolder informs data subjects of this fact and will communicate in this Policy any relevant change in the destination countries or in the providers involved.
5.2. Bolder will adopt the safeguards required by applicable law for this type of transfer and will formalize them in writing with the providers involved.
6. Retention period
6.1. In general, Bolder will retain personal data for the duration of the contractual relationship and for the additional period necessary to comply with legal obligations (including tax obligations) or to handle potential claims. Tax supporting documentation (for example, invoices) will be retained for six (6) years. Once those periods have elapsed, or when the data subject validly exercises their right to erasure, Bolder will delete or anonymize the data.
6.2. Bolder keeps an internal record of erasure requests and of the deletions carried out (without retaining the erased data), so that it can demonstrate to the data subject and to the Personal Data Protection Agency that the erasure took place. After an Account is closed, data is deleted from active systems within thirty (30) days following the end of the export period. Data contained in backups is deleted through rotation within a maximum of ninety (90) days, and in the meantime is not used for any other purpose.
7. Security measures
7.1. Bolder implements reasonable technical and organizational measures to protect the personal data it processes, in line with the state of the art and the nature of the data processed. These include: encryption of communications in transit (TLS); role-based internal access control; logical separation of the data of each Store; storage of passwords using secure hashing; authentication of buyers by one-time code; a firewall with rules blocking malicious requests and request rate limits; and periodic, redundant backups.
8. Rights of data subjects
8.1. Under Law No. 21.719, data subjects have the right to: access their personal data; request its rectification where it is inaccurate or outdated; request its erasure (also known as cancellation); object to its processing; request its portability; and request the temporary blocking of their data while any of the foregoing requests is being resolved (together, the “ARSOP Rights”, which include the rights traditionally known as ARCO rights: access, rectification, cancellation and objection). Bolder handles these requests free of charge to the data subject.
8.2. These rights may be exercised by sending a request to info@onbolder.com, indicating the right to be exercised and attaching the information necessary to verify the requester’s identity.
8.3. Bolder will respond to ARSOP Rights requests within thirty (30) calendar days of receipt, extendable once for up to thirty (30) additional calendar days in justified cases, informing the data subject of the extension before the original period expires. Where the request includes a temporary blocking of the data, Bolder will resolve that blocking request within two (2) business days, and until it is resolved, will not continue processing the affected data for the challenged purpose.
8.4. If the data subject considers that their request was not handled correctly or on time, they may file a complaint directly with the Personal Data Protection Agency.
9. Duty of transparency — minimum content of this Policy
9.1. Under Law No. 21.719, this Policy must inform, clearly and accessibly, among other things: the date of its last update; the identity of Bolder’s legal representative; the categories of personal data and of data subjects processed; the recipients or categories of recipients of such data; the purposes and legal basis of each processing activity; where applicable, the legitimate interest invoked; the data subject’s right to file a complaint with the Personal Data Protection Agency; the origin of the data when not collected directly from the data subject; the existence of international transfers; and the existence of automated decisions, where applicable.
10. Notification of security breaches
10.1. In the event of a security breach affecting personal data under its responsibility and creating a reasonable risk to the rights and freedoms of data subjects, Bolder will notify the Personal Data Protection Agency by the most expeditious means possible and without undue delay, and will also notify affected data subjects where the breach entails a high risk to their rights.
11. Data Protection Officer
11.1. Queries, requests and complaints regarding personal data protection may be sent to info@onbolder.com, the channel Bolder uses to handle these matters.
12. Changes to this Policy
Bolder may update this Policy from time to time, in accordance with the amendment mechanism described in Section 22 of the Terms.
PART II — Data Processing Addendum (DPA)
(Bolder as Data Processor on behalf of the User)
1. Purpose
1.1. This Addendum governs the processing that Bolder carries out, on behalf of and on the instructions of the User, with respect to the personal data of the User’s End Users that is processed through the Store (for example, End User data such as name, address, email, telephone, and order data).
1.2. For the purposes of this Addendum, the User is the Data Controller of that data, and Bolder acts as its Data Processor, in accordance with the documented instructions set out in the Terms and in this Addendum.
2. Instructions and scope of processing
2.1. Bolder will process the personal data of the User’s End Users solely for the purpose of providing the Services (for example, processing orders, enabling shipping and payment integrations, generating reports for the User), and in accordance with the User’s instructions as reflected in the configuration and use of the platform. If Bolder considers that an instruction infringes personal data protection legislation, it will inform the User.
2.2. Bolder will not use this data for its own purposes unrelated to the provision of the Services, unless it has an independent lawful basis to do so. In particular, Bolder may use aggregated and anonymized data — in such a way that it does not allow any data subject to be identified, directly or indirectly, nor allow specific Stores to be distinguished — to generate statistics, improve its Services, and train or develop its own models, including artificial intelligence models, without prejudice to anything agreed otherwise in a specific contract with the User.
2.3. The User, as Controller, declares and warrants that it has a valid lawful basis for each processing activity it instructs Bolder to carry out, and that it has informed its End Users of the purposes and conditions of the processing. Where that basis is the data subject’s consent, the User is responsible for obtaining it in a prior, free, informed and specific manner, through an affirmative act of the data subject, for keeping proof of such consent and for managing its withdrawal.
3. Categories of data and data subjects
3.1. Depending on the User’s line of business and the integrations it enables, the data processed may include: identification and contact details of the End User (name, email, telephone, address), purchase order data, and data necessary for shipping (shared with integrated couriers).
3.2. If the User processes sensitive personal data through the Store (for example, health data or data of children and adolescents), it must inform Bolder in advance, have the enhanced lawful basis required by law, and comply with the applicable security measures and other requirements. Bolder may require additional measures or the signing of a specific addendum for such processing.
4. Bolder’s sub-processors and Third-Party Services chosen by the User
4.1. Bolder’s sub-processors proper
The User authorizes Bolder to use the following sub-processors, engaged and controlled by Bolder, for the provision of the Services:
- Infrastructure, hosting and database: Linode (Akamai), United States.
- Backups and SMS messaging: Amazon Web Services (Amazon S3 for backups; Amazon SNS for sending SMS), United States.
- Content delivery network (CDN) and network security: Cloudflare (global reach); Store and checkout traffic passes through its network.
- Transactional emails to End Users: Mailgun, United States.
- Geocoding and delivery distance calculation: Google (Maps, Geocoding and Distance APIs), United States.
- Error monitoring: Bugsnag, United States, whose reports may include request context.
- Generation of Chilexpress shipping labels: Heroku (Salesforce), United States.
4.2. Third-Party Services chosen directly by the User
The payment gateways (Webpay Plus, Webpay OneClick, Mercado Pago, Flow, Khipu, Getnet, Stripe, Klap, Kushki, MachBank, TUU, PayPal, Servipag, VirtualPos) and the logistics and shipping providers (Bluexpress, Chilexpress, PedidosYa, UberDirect, Correos de Chile, Cabify) that the User decides to enable in its Store are not Bolder’s sub-processors. The User contracts directly with those third parties (or uses the terms of service they offer to the public), and is responsible for the corresponding data processing relationship with each of them. Bolder’s role with respect to these third parties is limited to enabling the technical integration and transmitting the information strictly necessary for that integration to work, in accordance with Section 10 of the Terms.
4.3. Addition and replacement of sub-processors
Bolder will keep the list in Section 4.1 updated and may add or replace sub-processors under Section 4.1 (that is, providers that Bolder itself engages and controls), by notifying the User in writing (including by email) with a description of the provider and of the processing it will carry out, with reasonable advance notice before it begins operating. The same notice will be given for any relevant change in the country or location where the User’s data is hosted. If the User does not state a well-founded objection within ten (10) business days of the notice, it will be deemed to have given its specific written authorization for that addition. This is without prejudice to a specific contract with the User requiring its express acceptance. If the User raises a well-founded objection within that period on grounds of a relevant risk, Bolder will assess the objection, without prejudice to the fact that this may make it impossible to provide the functionality associated with that sub-processor.
4.4. Bolder maintains with each sub-processor a written contract (including each provider’s standard data processing terms, accepted by Bolder) that imposes data protection obligations no less demanding than those of this Addendum, and will be liable to the User for compliance with those obligations.
4.5. Regarding the tokenization of payment methods: Bolder informs that OneClick and Stripe are the only integrations that allow card tokenization for recurring purchases; in those cases, the card data remains in the custody of the respective payment provider, not of Bolder.
5. International transfers
5.1. The User authorizes Bolder to host and process the personal data entrusted to it in the countries where the sub-processors listed in Section 4.1 operate, principally the United States (and, in the case of Cloudflare’s network, globally). Bolder will notify the User of any relevant change in those countries, in accordance with the mechanism in Section 4.3, and will adopt the safeguards required by applicable law for these transfers.
6. Security measures
6.1. Bolder will implement reasonable technical and organizational measures to protect the personal data processed as Processor, in line with Section 7 of Part I of this document.
7. Confidentiality of Bolder’s personnel
7.1. Bolder undertakes to ensure that the persons authorized to process the User’s personal data commit to maintaining due confidentiality, or are subject to a statutory or contractual duty of confidentiality.
8. Assistance to the User in the exercise of data subjects’ rights
8.1. Where an End User exercises any of the rights recognized by law (access, rectification, erasure or cancellation, objection, portability or temporary blocking) directly with Bolder with respect to data processed as Processor, Bolder will redirect the request to the corresponding User without undue delay and will not respond to it itself, since the User is the Controller of that processing.
8.2. Bolder will assist the User, through appropriate technical and organizational measures and with the lead time necessary for the User to meet the legal response deadlines, to access, rectify, delete, export or block a data subject’s data when the User so instructs.
9. Notification of security incidents to the User
9.1. If Bolder becomes aware of a security breach affecting personal data processed on behalf of the User, it will notify the User without undue delay, with the information available on the nature of the incident, so that the User can comply with its own notification obligations as Controller.
10. Return or deletion of data upon termination
10.1. Upon termination of the Services, Bolder will keep available to the User read-only access and export of its data for the 30-day period indicated in Section 20.2 of the Terms. After that period, Bolder will delete or return that data, as appropriate, from its active systems within the following thirty (30) days, unless a legal obligation requires its retention for a longer period.
10.2. Bolder will keep a record of the deletions carried out and, at the User’s request, will confirm in writing that the deletion took place, so that the User can demonstrate it. Data contained in backups will be deleted through rotation within a maximum of ninety (90) days and will not be used for any other purpose.
11. Audits
11.1. The User may request from Bolder reasonable information to verify compliance with this Addendum, without prejudice to Bolder being able to satisfy that request by providing relevant documentation (for example, this policy itself, or certifications of its infrastructure providers), instead of on-site audits, unless otherwise agreed in an Enterprise contract.
12. Liability
12.1. The parties’ liability under this Addendum is governed by Section 16 of the Terms.
This document is drafted in Spanish and may be provided in English as a courtesy translation. In the event of any discrepancy between the two versions, the Spanish version will prevail.