At StreamData SpA, we design our Snap platform with a Privacy by Design approach (Law 21.663). The processing of personal data of our users and clients is governed by Law No. 19,628, the new Law No. 21,719, and international enterprise security standards.
1. Privacy by Design (Architecture)
Data Separation: The LLM only processes structural metadata (table schemas, data types) and never sees your raw database rows. Code generated for data analysis is executed locally inside a secure, locked-down virtual sandbox with zero external internet access.
2. Record of Processing Activities (RAT)
We map all data flows under the legal basis of contract execution: corporate account authentication, optional integrations (Slack), and AI processing (Vertex / Anthropic). Your query contexts and data are never used to train public AI models.
3. Data Retention & Minimization
We enforce automatic purge cycles: AI agent traces and query histories are deleted after 30 days, and operational or email logs after 90 days. Inactive accounts for 5 years are permanently anonymized and disabled.
4. Authorized Subprocessors
We partner with leading infrastructure providers (Google Vertex AI, Anthropic, Slack) under strict Data Processing Agreements (DPA). They are legally prohibited from using customer data for model training or their own purposes.
5. Transfers & Safeguards
All international data flows are backed by Standard Model Contractual Clauses (SCC) approved by the Chilean Ministry of Economy. Data in transit is secured with TLS 1.3, and connection credentials are encrypted at rest using Fernet AES-128.
6. ARCO+ Rights & Erasure
We guarantee the full exercise of your Access, Rectification, Deletion, Opposition, Portability, and Blocking rights. Upon deletion, we execute an atomic sequence: disabling logins, removing integrations, and purging all cognitive AI memory tiers.
Ley 21.719 Compliance
Addendum: Operational Metrics Ledger & Report Creation History (Ley 21.719 Compliance)
1. Purpose of the Ledger
To maintain precise platform usage metrics and ensure operational traceability for organization subscription plans, StreamData maintains an immutable technical log of created reports ("SnapMails" or "Snaps").
2. Principle of Proportionality & Data Minimization (Art. 3 item c & Art. 14 quáter of Chilean Ley 21.719)
This metric log stores strictly minimal technical references:
- Technical report ID (
snapmail_id). - User account reference (
user_id). - Organization identifier (
organization_id). - Creation timestamp (
created_at).
Privacy Guarantee: This usage ledger does NOT store or process user prompts, message content, underlying dataset values, executed SQL queries, or recipient email addresses.
3. Right to Erasure & Automatic Anonymization (Art. 2 item k & Art. 7 of Ley 21.719)
In compliance with the Right to Erasure (ARCO rights):
- Upon account deletion or user removal from an organization, the link between the natural person and the creation record is irreversibly decoupled (
user_id set to NULL). - Through this anonymization process (pursuant to Art. 2 item k of Ley 21.719), the record ceases to be personal data, preserving the organization's aggregated metric count without retaining any personal identifiers.