Legal

Privacy
Policy

Legal framework: Law 21.719 · Chile Scope: horaciogaray.com
Contents
  1. Data Controller
  2. Data We Collect
  3. Purpose and Legal Basis
  4. Cookies and Tracking Technologies
  5. Retention Period
  6. Recipients and Transfers
  7. Your Rights
  8. Security
  9. Minors
  10. Changes to This Policy
  11. Contact

This policy describes how Horacio Garay processes personal data recopilados a través de horaciogaray.com, in accordance with Law N° 21.719 which Regulates the Protection and Processing of Personal Data, published on December 13, 2024, whose full enforcement begins on December 1, 2026.

1. Data Controller

The data controller for personal data collected on this website is:

Name: Horacio Garay

Role: Go-To-Market Architect & Fractional CMO

Website: horaciogaray.com

Contact: Contact form available on this site

Country: Chile

The controller also acts as compliance officer within the terms of Article 49 of Law 21.719, given the size and nature of the activity.

2. Data We Collect

We only collect data voluntarily provided by the user through the contact form on this website:

Field Required Purpose
Nombre Identify the requester and personalize the response
Correo electrónico Response and communication channel
Empresa No Provide context for the inquiry
Servicio de interés No Direct the response to the appropriate service area
Mensaje No Understand the context of the inquiry

Additionally, through Google Analytics and Google Tag Manager, technical browsing data is collected in an anonymous or pseudonymized form (truncated IP address, browser type, pages visited, session duration). This data does not allow direct identification of a person.

3. Purpose and Legal Basis del tratamiento

Data collected through the contact form is processed for the following purposes and legal bases:

Purpose Legal basis (Law 21.719)
Respond to the inquiry or request submitted Explicit consent of the data subject (Art. 12)
Manage the pre-contractual or contractual commercial relationship Execution of pre-contractual measures at the request of the data subject (Art. 13 letter c)
Internal record of prospects and clients in proprietary CRM Legitimate interest of the controller (Art. 13 letter d), compatible with the declared purpose
Web traffic analysis (anonymous data) Legitimate interest — anonymized or pseudonymized data (Art. 13 letter d)

Data will not be used for unsolicited commercial communications (spam), nor shared with third parties for marketing purposes.

4. Cookies and Tracking Technologies

This website uses cookies and similar technologies. We classify them by purpose:

Type Tool Purpose Consent
Strictly necessary Site session Basic website operation Not required
Analytics Google Analytics 4 (G-354108467) Measure traffic and browsing behavior Required
Marketing / Tracking Google Tag Manager (GTM-KSR6VZ) Tag management and conversion tracking Required

Users can manage cookie preferences through the consent panel available on the site, or by configuring their browser to block or delete cookies. Withdrawal of consent does not affect the lawfulness of processing based on prior consent.

5. Retention Period

Personal data will be retained for the strictly necessary time to fulfill the purpose for which it was collected, in accordance with the proportionality principle of Art. 3 letter c of Law 21.719:

Data type Retention Period Rationale
Prospect data (no commercial relationship) 24 months from last contact Reasonable period to assess commercial interest
Active client data Duration of relationship + 5 years Tax and legal obligations (Tax Code)
Web analytics data (GA4) 14 months (GA4 configuration) Google Analytics retention standard
Consent records 5 years from grant Controller accountability obligation (Art. 12)

After these periods, data will be deleted or irreversibly anonymized.

6. Recipients and Transfers

Personal data collected through the form is processed by the following technology services acting as data processors (third-party processors per Art. 15 bis):

Provider Country Function Safeguards
Resend EE.UU. Sends form notification to the controller Standard contractual clauses
Netlify EE.UU. Website hosting and serverless function execution DPA available / Privacy Shield successor
Google (Analytics / GTM) EE.UU. Anonymous web traffic analysis Standard contractual clauses (GDPR)
CRM propio (Lovable) Chile / cloud Prospect and client record management Direct controller — no transfer to third parties

As some providers are located outside Chile, the international data transfer regime of Art. 27 of Law 21.719 applies. Adequate contractual safeguards are used in all cases.

Data will not be transferred, sold, or shared with third parties for purposes other than those declared in this policy.

7. Your Rights

In accordance with Title I of Law 21.719 (Arts. 4–11), the data subject has the following rights:

Access
Request confirmation of whether their data is being processed and obtain access to it.
Rectification
Request correction of inaccurate, outdated, or incomplete data.
Erasure
Request deletion of their data when it is no longer necessary or consent is withdrawn.
Objection
Object to the processing of their data based on legitimate interest.
Portability
Receive their data in a structured, commonly used format to transfer it to another controller.
Temporary Blocking
Request suspension of processing while a rectification, erasure, or objection request is resolved.

Cómo ejercer sus derechos: Use the form below indicating your full name, the right you wish to exercise, and the specific data to which your request refers.

The controller will respond within 30 calendar days of receiving the request, in accordance with Art. 11 of Law 21.719.

8. Security

The controller adopts appropriate technical and organizational measures to protect personal data against unauthorized processing, loss, accidental destruction or damage, in accordance with the security principle of Art. 3 letter f and Art. 14 quinquies of Law 21.719. These measures include:

— Form communications are transmitted via HTTPS with TLS encryption.
— Notifications are sent via the Resend API with private key authentication stored as an environment variable.
— The site is hosted on Netlify with industry-standard infrastructure protections.
— Access to the proprietary CRM is protected by authentication and restricted to the controller.

In the event of a security breach that generates reasonable risk to the rights and freedoms of data subjects, the controller will notify affected parties in accordance with Art. 14 sexies of the law.

9. Minors

The services offered on this website are directed exclusively at persons over 18 years of age. We do not intentionally collect personal data from minors. If you are a parent or guardian and are aware that a minor has submitted data through this site, you may request its deletion using the contact form in the Contact section of this page.

10. Changes to This Policy

This policy may be updated to reflect changes in data processing practices, services offered, or applicable regulations. Any modifications will be published on this page.

We recommend reviewing this policy periodically. Continued use of the site after changes are published implies acceptance of the updated version.

11. Contact

To exercise your rights or inquire about the processing of your personal data, complete the form below. We will respond within 30 calendar days.