These Data Privacy Terms and Policies describe the commitment of CSK Technologies SpA (RUT: 77.862.964-K, domiciled at Los Militares No 5620, oficina No 905, hereinafter “the Data Controller”), through the chask™ platform, to protect and respect the privacy of its Clients and Users in accordance with the General Data Protection Regulation (GDPR) and Chilean Law No. 19,628 on the Protection of Private Life. By using the Platform, you acknowledge and accept the collection, storage and processing of your personal data as described in this Policy.
Definitions
For the purposes of this Privacy Policy:
- Country: Refers to Chile.
- Service: Refers to chask™.
- Website: Refers to chask™, accessible at https://www.chask.io.
- Company: (also referred to as “The Company”, “chask” or “Our” in this document) refers to CSK Technologies SpA, the company that owns and operates the chask™ platform.
- Account: Refers to the account/user created for you to access our Services or parts of them.
- User: Refers to the “Person” or “Client” who accesses and/or uses the service, or the company or other legal entity on behalf of which such person accesses or uses the service, as applicable.
- Device: Refers to any device that can access the Service, such as a computer, phone or tablet, among others.
- Usage Data: Refers to data collected automatically, either from the use of the Service or from the infrastructure of the Service itself (for example, the duration of a page visit).
- Personal data: Refers to any information that relates to an identified or identifiable individual, natural person or legal entity, or a representative thereof.
- AI Algorithms: Refers to the third-party artificial intelligence models, specifically OpenAI and Anthropic, that chask™ uses through their APIs to process the User’s requests and provide real-time responses. The Company does not train its own AI models with the data of its Clients and Users.
- Third-party AI assistant: Refers to an artificial intelligence application that the User chooses to connect to chask™ through the Model Context Protocol (MCP), such as Anthropic’s Claude or OpenAI’s ChatGPT.
- Service Provider: Refers to any natural person or legal entity that processes data on behalf of the Company. It refers to third-party companies or individuals engaged by the Company to facilitate the Service, provide the Service on behalf of the Company, perform services related to the Service or assist the Company in analyzing how the Service is used.
Data Controller
CSK Technologies SpA is the Data Controller, responsible for determining the purposes and means of processing the personal data collected from Clients and their Users through the chask™ platform.
Data Controller contact details:
- Legal Name: CSK Technologies SpA
- RUT: 77.862.964-K
- Address: Los Militares No 5620, oficina No 905
- Email: contact@chask.io
Data protection inquiries:
- Email: contact@chask.io
Data Collected and Purposes
Your data will be used exclusively to provide information to the request system and to improve the operation of the system. By using the service, you agree to the collection and use of information as set forth in this Privacy Policy. chask™ collects (without being limited to) standard and private user information, such as first name, last name, phone number, home address, email address and other data necessary for account creation, administration, payment management and communication purposes. Payment card data is processed directly by our payment providers and is not stored by chask™. In addition, chask™ stores and processes the data related to each of the requests provided by and owned by the User for the sole purpose of providing the Service. This data is collected automatically when the Service is used. It may include information such as the Internet Protocol Address (for example: IP Address), the Browser used, the Browser Version, the pages of our Service that you visit, the Date and Time of the visit, the time spent on our Pages, unique Device identifiers and other diagnostic data. When you access the service through a mobile device, We may collect certain information automatically, including (but not limited to): the type of Mobile Device you use, the unique device ID, the IP address of the mobile device, the Operating System of the Mobile Device, the type of Internet Browser you use, unique device identifiers and other diagnostic data. We may also collect information that is sent each time your Browser visits our Website or when you access the service through a mobile device.
Legal Basis for Data Processing (GDPR)
In accordance with Article 6 of the GDPR, the processing of your personal data is based on the following legal bases:
| Purpose of Processing | GDPR Legal Basis | Retention Period |
|---|---|---|
| Account registration and management | Article 6(1)(b) - Performance of a contract | For the term of the contract + 5 years |
| Payment processing | Article 6(1)(b) - Performance of a contract | 10 years (tax obligations) |
| MCP server request logs | Article 6(1)(f) - Legitimate interest | 30 days |
| History of actions on the organization’s map | Article 6(1)(b) - Performance of a contract | For as long as the organization exists in chask™ |
| Marketing and communications | Article 6(1)(a) - Consent | Until consent is withdrawn |
| Security and fraud prevention | Article 6(1)(f) - Legitimate interest | 3 years from the last activity |
| Legal compliance | Article 6(1)(c) - Legal obligation | As required by applicable law |
| Service analysis and improvement | Article 6(1)(f) - Legitimate interest | 2 years from collection |
Use of the User's Personal Data
The Company may use your personal data for the following purposes:
- To provide and maintain our Service, including monitoring how the Service is used.
- To manage your Account: To manage your registration as a User of the Service. The Personal Data that the User provides will give the User access to different features of the Service that are available to registered Users. For authentication and account management we use Clerk, whose privacy policy is available at https://clerk.com/legal/privacy.
- For the performance of a Contract: The development, fulfillment and execution of the purchase agreement for the products, items and/or services that the User has acquired, or of any other contract with the Company through the Service or the selected subscription plan.
- To contact you: To contact you by email, telephone calls, text messages (SMS) or other equivalent forms of digital communication, such as PUSH notifications in the mobile application, regarding updates or information related to the features, products or services acquired, including security updates, when necessary or reasonable for their implementation.
- To provide You with news, special offers and general information about other products, services and events that we offer and that are similar to those You have already acquired and/or inquired about. You may opt out of receiving such information.
- To manage your requests: To manage and respond to your requests to us.
- For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of promotional campaigns, and evaluating and improving our Service, products, services, marketing and your experience as a User.
Use of Third-Party AI Algorithms
The Company may share and analyze User information in order to strengthen the details of the Service, and develop new programs and updates according to the requirements that may arise in chask™, with the AI Algorithms of OpenAI and Anthropic.
Specific information about the AI models:
AI Models Used: We use the AI models of OpenAI and Anthropic (Claude).
- Data shared: We share the user’s personal and usage data, including but not limited to name, email address, details of interaction with the service and request data, and documents uploaded to the platform.
- OpenAI Privacy Standards: User information shared with OpenAI is processed in accordance with OpenAI’s privacy standards for API integrations. Data shared through the API is not used to train OpenAI’s models.
- Anthropic Privacy Standards: User information shared with Anthropic is processed in accordance with Anthropic’s privacy standards for API integrations. Data shared through the API is not used to train Anthropic’s models.
- Purpose of Data Sharing: Data is shared solely to provide the Service and process the User’s requests. The Company does not train its own AI models with the data of its Clients and Users.
- Use of Data by the AI Models: The AI models use the data to recognize patterns and provide real-time responses, improving the personalized assistance we offer to users.
- Responsible and Ethical Use: We ensure that data is used responsibly and ethically, in compliance with all applicable regulations and guaranteeing the privacy and security of the user’s data.
Situations in which we may share user information:
- With Service Providers: We may share the User’s personal information with Service Providers to monitor and analyze the use of our Service and/or to contact the User.
- With Affiliates: We may share the User’s information with affiliates of the Company, in those cases in which the affiliates comply with this Privacy Policy. Affiliates include the parent Company and any other subsidiaries, joint venture partners or other companies that we control or that are under common control with CSK Technologies SpA.
- With Other Users: When You share personal information or interact in public areas with other Users, such information may be viewed by all Users and may be publicly distributed outside these areas due to the use of unprotected networks. In this regard, CSK Technologies SpA is not responsible for the User’s own care and compliance in handling their data.
- Compliance with the Law: Under certain circumstances, the Company may be required to share Your personal data if required by Law or in response to public requests from valid authorities (for example: courts or government agencies).
- Other Legal Requirements: Compliance with a legal obligation, protecting and defending the rights or property of the Company, preventing or investigating possible wrongdoing in connection with the Services, protecting the personal safety of Users of the Service and of the general public.
- With the User’s Consent: We may share and make use of the User’s personal information data for any other purpose specified in this clause, with utmost diligence and if, and only if, the User consents.
- Prohibition of Sale: The Company does not sell Your information.
These policies are designed to ensure the maximum protection and privacy of User data, in line with the highest security and ethical standards. The Company undertakes to review and update these policies periodically to ensure their effectiveness and compliance with applicable regulations. The User is entirely free to request the total or partial deletion of their data at any time while subscribed to any of the chask™ plans.
Storage and Encryption of User Data
chask™ uses Amazon Web Services (AWS) for the secure storage and encryption of the User’s request data, and Polar and Transbank for payment processing and the collection of subscription fees for the provision of the service. By using the Platform, you acknowledge and accept that your personal data will be stored and encrypted using AWS services, and that your payment data will be processed by Polar or Transbank. Stored information that allows us to provide the Service, as well as to improve and personalize it, may be uploaded to the Company’s servers and/or to AWS Servers. The User is responsible for accurately entering and/or deleting the personal data of their payment card for the billing of each chask™ Service according to the selected subscription plan.
Retention of User Data
chask™ will retain your personal data for the specific periods set out in the legal bases table (section THIRD (BIS)). The retention periods have been defined taking into account the purpose of the processing, legal obligations and regulatory requirements. Once the data is no longer necessary or the applicable retention period expires, it will be securely deleted or irreversibly anonymized.
Deletion procedures:
- Automatic deletion upon expiration of the retention period
- Secure deletion using multiple-overwrite techniques
- Irreversible anonymization for data used for statistical purposes
- Certificates of destruction for physical data where applicable
Use of Cookies and Tracking Technologies
chask™ uses cookies and similar technologies to improve the user experience, analyze website traffic and provide personalized content. Cookies are small text files that are stored on your device when you visit our website.
Types of cookies we use:
- Essential cookies: Necessary for the basic operation of the website, including authentication and security (CSRF token).
- Functional cookies: Allow us to remember your preferences and personalize your experience.
- Analytics cookies: Help us understand how users interact with our website and our application through PostHog and Vercel Analytics. You can review their privacy policies at https://posthog.com/privacy and https://vercel.com/legal/privacy-policy.
Transfer of User Data
Information provided by the User may be transferred to and processed outside the European Economic Area (EEA) and Chile. International transfers of personal data are carried out under the following protection mechanisms:
International Transfer Mechanisms:
- Amazon Web Services (AWS - United States): Transfer based on Standard Contractual Clauses (SCCs) and SOC 2 Type II security certifications.
- OpenAI (United States): Transfer based on Standard Contractual Clauses (SCCs) and SOC 2 Type II security certifications.
- Anthropic (United States): Transfer based on Standard Contractual Clauses (SCCs) and SOC 2 Type II security certifications.
- Clerk (United States): Transfer based on Standard Contractual Clauses (SCCs) and technical and organizational security measures.
- Vercel (United States): Hosting of the web applications and the MCP server. Transfer based on Standard Contractual Clauses (SCCs).
- PostHog (United States): Product analytics. Transfer based on Standard Contractual Clauses (SCCs) where applicable.
- Polar (United States): Payment and subscription processing. Transfer based on Standard Contractual Clauses (SCCs) where applicable.
Destination countries of the transfers:
- United States (AWS, OpenAI, Anthropic, Clerk, Vercel, PostHog, Polar)
All international transfers comply with the requirements of Chapter V of the GDPR and include appropriate safeguards to protect your personal data. You may request a copy of the specific safeguards by contacting contact@chask.io.
User Rights
Under the GDPR, you have several rights regarding your personal data, including:
- The right to access your data.
- The right to rectify inaccurate or incomplete data.
- The right to erasure (right to be forgotten).
- The right to restrict processing.
- The right to data portability.
- The right to object to processing.
- The right to withdraw consent.
To exercise any of these rights, please contact chask™ at contact@chask.io.
Opt-Out and Deletion of User Data
Clients may choose to delete their data from the Platform. To do so, please contact chask™ at contact@chask.io. Please note that, following the deletion of data, certain personalized features of the Platform may not be available to you as agreed in the subscription plan. In addition, chask™ will inform the User if the deletion of the data prevents the provision of the contracted services and/or could affect other potential third-party services. Please note that it will be necessary to verify your identity before processing this type of request, and that the Company may retain basic User information if it has a legal obligation or a legal basis to do so. Likewise, the User may update, modify or delete their information at any time by logging in to their Account, if they have one, and visiting the Account settings section, which allows them to manage their personal information. The User may also contact the Company to request access to, correction of or deletion of any personal information that the User has provided to us.
Changes to the Data Privacy Terms and Policies
chask™ reserves the right to update or modify these Data Privacy Terms and Policies at any time. Any change will be notified to Users and published on this page, the Website, or the User’s email.
In addition to the changes included in this privacy policy, chask™ undertakes the following:
- chask™ will use its best technical and organizational efforts to provide reasonable cooperation or assistance requested by the Client in connection with the steps the Client takes to comply with the Data Privacy Laws set forth in this document, to the extent they relate to the agreement regarding security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
- chask™ will notify the Client without undue delay upon becoming aware of a personal data breach;
- At the Client’s written direction, delete or return the personal data and copies thereof to the Client upon termination of the agreement, unless Applicable Law requires the personal data to be stored;
- Maintain complete and accurate records and information to demonstrate its compliance with this clause.
- Restrict access to Client Data to its personnel who need to access Client Data to provide the services to Clients or their affiliates. chask™ will ensure that any chask™ personnel who process Client Data: (i) are bound by appropriate contractual obligations of confidentiality, data protection and data security that are at least as restrictive as this clause; and (ii) will only process Personal Data in accordance with the Client’s instructions unless required by law.
- Provide the Client with a point of contact regarding the activities covered by this clause.
- Make its personal information available to the Client, upon request of the Client, to demonstrate the Client’s compliance with the obligations set forth in this clause.
- Obtain the prior specific written consent of the Client before engaging a subcontractor, or before the User wishes to outsource their personal requirements to process Client Data on behalf of the Client. chask™ will ensure that any subcontractor or third party is bound by the same data protection obligations set forth in this clause.
Security of User Data
The security of the User’s personal data is important to us. We implement appropriate technical and organizational security measures, including:
- Encryption of data in transit and at rest (AES-256)
- Multi-factor authentication for administrative access
- Continuous security monitoring and intrusion detection
- Regular security audits and penetration testing
- Access controls based on the principle of least privilege
- Encrypted data backup and recovery
Data Breach Notification
In the event of a security breach affecting your personal data, we will comply with the obligations of the GDPR:
Notification to the authorities:
- Notification to the competent supervisory authority within 72 hours of becoming aware of the breach
- Complete documentation of the incident, its impact and the measures taken
Notification to affected users:
- Direct communication without undue delay when the breach poses a high risk to your rights and freedoms
- Clear description of the nature of the breach and the data affected
- Measures taken to mitigate the adverse effects
- Recommendations for the user to reduce possible negative effects
- Contact details of the Data Protection Officer for inquiries
Children's Privacy
The Services provided by the Company are not directed at persons under 18 years of age, the minimum age to create an Account under the Terms and Conditions of Use. As a Company, we do not intentionally and knowingly collect personal information from persons under 18 years of age. If the User is a parent or guardian and becomes aware that the minor in their custody has provided us with personal data, please contact us. If we identify information of a person under 18 years of age in our database without the prior consent of their parents or guardians, we will take the appropriate measures to delete this information from our servers. If we need to rely on consent as the legal basis for processing the User’s information, and their region requires the consent of parents or guardians, we may request such consent before collecting and using that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Our Company. If the User decides to access these links by clicking on them, they will be directed to that third party’s website. We recommend that the User review the Privacy Policy of each site the User visits. CSK Technologies SpA and chask™ assume no responsibility for the content, privacy policies or practices of third-party websites.
Google API Services Limited Use Policies
CHASK™’s use and transfer of any information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements set forth at the following link, visible and subject to the User’s full consent: https://developers.google.com/terms/api-services-user-data-policy
Email delegation for sending on behalf of the User
The Platform may offer the User the optional feature of delegating access to their email account, so that chask™ can send messages on their behalf (for example, marketing campaigns, service confirmations or other communications previously authorized by the User). Use of this feature will always require the express and informed consent of the User and will be governed by the guidelines set out below:
- Limited scope of access: chask™ will request only the permissions strictly necessary to draft and send emails, without accessing personal messages that are not related to the authorized purposes.
- Use exclusively for authorized purposes: Emails will be sent only when the User expressly requests or approves them, and will be limited to the defined purposes (e.g., targeted marketing campaigns, request confirmations or service reminders).
- Revocation and control: The User may revoke the delegation of their email at any time from the account settings or by writing to contact@chask.io. Once access is revoked, the stored authentication tokens will be deleted and all sending on behalf of the User will cease.
- Logging and auditing: chask™ will keep a log of the messages sent on behalf of the User (sender, recipient, subject, date and time), which will be available for audit at the request of the User.
- Regulatory compliance: All sending will comply with applicable regulations on spam, commercial advertising and data protection (including Chilean Law No. 19,628 on the Protection of Private Life and, where applicable, the GDPR). Each email will include clear mechanisms to unsubscribe.
- Providers and third parties: Where third-party services are used for email delivery (e.g., SMTP providers, the Gmail API or others), they must offer equivalent guarantees of security and confidentiality. When Google services are used, the use and transfer of data will comply with the Google API Services User Data Policy (Limited Use).
By enabling this feature, the User declares that they understand and accept the conditions described above. If the User does not want chask™ to send emails on their behalf, they may simply not enable this option.
WhatsApp messaging delegation for sending on behalf of the User
The Platform may offer the User the optional feature of sending messages through the WhatsApp Business API on their behalf (for example, service notifications, payment reminders, request confirmations or other communications previously authorized by the User). Use of this feature will always require the express and informed consent of the User and will be governed by the guidelines set out below:
- Limited scope of access: chask™ will use only the WhatsApp Business API integration to send messages on the channels and to the recipients authorized by the User, without accessing personal conversations or data not related to the authorized purposes.
- Use exclusively for authorized purposes: Messages will be sent only when the User expressly requests or approves them through the configuration of pipelines or automated flows on the platform, and will be limited to the defined purposes (e.g., operational notifications, reminders, service confirmations).
- Revocation and control: The User may revoke the WhatsApp messaging delegation at any time from the account settings or by writing to contact@chask.io. Once access is revoked, all sending on behalf of the User through this channel will cease.
- Logging and auditing: chask™ will keep a log of the messages sent on behalf of the User (sender, recipient, content, date and time), which will be available for audit at the request of the User.
- Regulatory compliance: All sending will comply with the WhatsApp Business API usage policies and applicable regulations on spam, commercial advertising and data protection (including Chilean Law No. 19,628 on the Protection of Private Life and, where applicable, the GDPR). Messages will include mechanisms that allow recipients to opt out of receiving future communications.
- Providers and third parties: The integration with the WhatsApp Business API is provided through Meta Platforms, Inc. The use and transfer of data will comply with the WhatsApp Business Policy and the Meta Privacy Policy.
By enabling this feature, the User declares that they understand and accept the conditions described above. If the User does not want chask™ to send WhatsApp messages on their behalf, they may simply not enable this option in their channel settings.
Integration with Fintoc for access to banking data
The Platform may offer the User the optional feature of connecting their bank accounts through Fintoc SpA (RUT: 77.143.385-5), a regulated financial data intermediary in Chile, for the purpose of accessing financial information relevant to the management of requests and the automation of tasks within chask™. This integration is entirely voluntary and will only be activated when the User expressly decides to enable it.
- Data accessed: Through Fintoc, chask™ may access the following banking data of the User: account types, transaction history, account holder names and available balances. chask™ will not access banking data other than that strictly necessary for the purposes authorized by the User.
- Consent and scope: Access to banking data requires the express and informed consent of the User through the Fintoc connection widget. The consent extends strictly to the purposes defined by the User within the chask™ platform.
- Handling of credentials: Fintoc acts solely as an intermediary in the bank connection process. The User’s banking credentials are managed exclusively by Fintoc and are not stored on chask™ servers. Fintoc does not retain bank access credentials on its servers, in accordance with its terms of service.
- Security: Fintoc holds ISO 27001 certification in information security management and complies with the PCI SAQ D standard. All data communication is carried out using TLS 1.2 encryption or higher to ensure the protection of data in transit.
- Revocation and control: The User may revoke access to their banking data at any time from the account settings in chask™ or by writing to contact@chask.io. Once access is revoked, chask™ will stop receiving the User’s banking data through Fintoc.
- Use exclusively for authorized purposes: Banking data obtained through Fintoc will be used exclusively for the purposes defined by the User within the platform (e.g., payment reconciliation, generation of financial reports, transaction validation). chask™ will not sell or share this data with unauthorized third parties.
- Fintoc’s responsibility: Fintoc SpA acts as an independent controller of the personal data it collects directly from the User through its widget. The processing of data carried out by Fintoc is governed by its own Privacy Policy and its Terms and Conditions.
- Regulatory compliance: The integration with Fintoc complies with Chilean Law No. 19,628 on the Protection of Private Life and, where applicable, with the GDPR. Fintoc operates under current Chilean financial regulation.
By enabling this feature, the User declares that they understand and accept the conditions described above. If the User does not wish to connect their bank accounts through Fintoc, they may simply not enable this option in the integration settings.
Connection with third-party AI assistants (MCP server)
chask™ offers a Model Context Protocol (MCP) server that allows the User to connect a Third-party AI assistant, such as Claude or ChatGPT, to their organization’s map. The connection is optional and is only activated when the User expressly authorizes it from that assistant.
- Authorization: The User signs in with their chask™ Account (through Clerk) and approves read permissions and, if they wish, edit permissions for the map. The assistant always acts with the User’s permissions: it only accesses the organizations the User belongs to and respects the access settings of each floor.
- Data received by chask™: The identity of the authenticated User and the actions that the assistant requests on the map, with their parameters (for example, the name of a person or a process to be created). chask™ does not receive or store the User’s conversations with the assistant, their history, their memory or the files they have shared with it.
- Data received by the assistant: The map data that the assistant itself requests on behalf of the User (floors, people, platforms, connections and processes). Its subsequent processing is governed by the privacy policy of the assistant’s provider (Anthropic, OpenAI or another), with whom the User maintains an independent relationship.
- Logs and retention: The technical logs of each request to the MCP server are kept for 30 days and are then deleted automatically. The actions that modify the map remain in the organization’s action history for as long as the organization exists, in the same way as changes made from the application.
- Actions with external effects: Actions that send emails (such as inviting a person) are executed only when the User requests them through the assistant, and compatible clients ask the User for confirmation.
- Revocation: The User may disconnect the connector at any time from their assistant’s settings, or write to contact@chask.io to revoke access. Once revoked, the assistant can no longer act on the map.
Contact Information
If you have any questions or concerns about this Data Privacy Policy or your personal data, please contact the chask™ team at contact@chask.io.
