Hey Santi
Privacy Policy
Hey Santi is an app that helps families and support teams look after neurodivergent children and adolescents. To do that we handle very sensitive information: health data about people under eighteen. This policy explains exactly what data we handle, for what purpose, on what legal basis, who we share it with and how you can control it.
It is written to be understood. If anything is unclear, write to us at privacidad@heysanti.app and we will explain.
1. Who is responsible
The controller of your personal data is:
| Legal name | Servicios Informáticos Development CL Ltda. |
|---|---|
| RUT | 76.424.424-9 |
| Address | Nueva San Martín 1520, oficina 117, Santiago Centro, Región Metropolitana, Chile |
| Privacy email | privacidad@heysanti.app |
| Service | Hey Santi (mobile app and web portal at heysanti.app) |
That address is the official channel for exercising rights and for communications from the Chilean Data Protection Agency. We keep it working and monitored.
We are a company registered in Chile, so we are subject to the jurisdiction of the Chilean courts and Agency, and you can reach us at the address above.
2. Applicable legal framework
This policy is governed by Chilean law:
- Law No. 21,719, which governs the protection and processing of personal data and creates the Data Protection Agency. It takes effect on 1 December 2026.
- Law No. 19,628 on the protection of private life, in force until then.
- Law No. 19,496 on consumer rights, as regards signing up for the service.
We have written this policy to the standard of Law 21,719 already, even though it is not yet in force. Where health data about children is concerned, we think the stricter standard should apply from day one rather than waiting until the obligation becomes enforceable.
3. What data we handle
3.1 Data about adult users
About mothers, fathers, legal guardians, therapists and organisation staff:
| Data | Source | Required |
|---|---|---|
| Email address | Sign-up or Google account | Yes |
| Name | Sign-up or Google account | Yes |
| Role (parent, guardian, therapist, teacher, administrator) | Sign-up | Yes |
| Gender, date of birth, country, time zone | Profile | No |
| Link to the organisation and job title | Organisation invitation | Organisation profiles only |
| Profile photo, if you choose to upload one | Personal data |
3.2 Data about the child or adolescent
This is the most sensitive data we handle. The responsible adult enters it:
| Data | Category |
|---|---|
| Name, sex and date of birth | Personal data of a minor |
| Photo of the child: stored encrypted and seen only by whoever the responsible adult expressly authorises | Personal data of a minor |
| Daily observation log: notes, milestones, alerts, medical entries, intensity, category | Sensitive data (health) |
| Therapy session records: type, goals and homework | Sensitive data (health) |
| Medication: name, active ingredient, dose, route of administration and record of each dose | Sensitive data (health) |
| Activities, routines and scheduled appointments | Personal data of a minor |
| Links to educational or clinical organisations | Personal data of a minor |
3.3 Technical data
Generated by the service as it runs:
- Audit logs: user identifier, action taken, IP address and date and time. They exist so we can tell who accessed what.
- Image access logs: who viewed, uploaded or deleted a child’s photo, with IP address, user agent and time of access. This is a deliberate safeguard: photos of children are the highest-risk data in the system and we want to be able to reconstruct every access to them.
- Device identifier for notifications (Firebase Cloud Messaging token).
- The child’s time zone, so a medication reminder goes off at the time where the child is and not where the person who set it up is.
- Web server logs, with IP address and request details.
4. Data about children and adolescents
Almost everything that happens in Hey Santi revolves around data about people under eighteen, which the law protects more strictly. Our rules:
- Only an adult with parental responsibility or legal guardianship can create a child’s profile. Sign-up does not complete without that express declaration, and we keep a record of the exact wording accepted, the date, the IP address and the device it was made from.
- You declare in what capacity you act — mother, father, legal guardian — and whether you are the only person with day-to-day care or there is another. This is not an administrative field: it determines who must authorise decisions about your child’s data. If you declare that another person exists, the decisions you take while they have not joined are recorded as settled in their absence.
- The child does not create their own account or use the app directly.
- No professional or organisation accesses the child’s information without consent given by the responsible adult, specific to that person or organisation and limited to the sections the adult authorises.
- An organisation cannot create a child’s profile, even if it pays for the service. If a school or therapy centre invited you to use Hey Santi, you create the profile: the contract that organisation has with us does not replace your authorisation, because you are the one who can consent to your child’s data being used.
- Consent can be withdrawn at any time from the app or the portal, with no need to justify it and at no cost. It is enough for one of the responsible adults to ask.
About verifying parental responsibility. We do not ask for documents proving it, and we would rather say so plainly than imply a check we do not carry out. What we do instead:
- We require an express declaration without which the profile is not created, and we keep a record of the wording accepted, the date, the IP and the device.
- We ask you to declare in what capacity you act, whether another person holds parental responsibility, and who has day-to-day care, and we keep that declaration too.
- We detect duplicate registrations: if someone else registers a child matching yours by name and date of birth, we email you so you can recognise it or report it.
- If we learn that someone registered a child without having day-to-day care of them, we suspend the profile immediately and delete the data.
We deliberately do not ask for identity documents or family court orders: storing them would create a bigger risk than it would solve.
When there is more than one responsible adult
When you register a child you declare who has day-to-day care: you, both of you, or the other person. That declaration determines who decides and who is informed. Here is how it works:
- All responsible adults are always informed, whether they decide or not. This is not configurable and does not depend on who has day-to-day care.
- Whoever has day-to-day care decides. If it is shared, granting access needs both to agree, and a single refusal stops the request.
- Whoever does not have it can place an objection on record. It does not block the decision, but it is recorded with a date and a reason, and it is never deleted.
- Anyone can revoke an access on their own. Requiring both to agree in order to stop sharing would keep the access alive for as long as the other person did not reply, which is the opposite of what revoking is for.
- Permanently removing the child does need everyone to agree, whether or not they have day-to-day care: deleting the history takes away something the other person already had, and it cannot be undone.
Why we do not require both signatures for everything. We considered it and ruled it out. The Chilean Civil Code provides that, where the parents live apart, parental responsibility is exercised by whoever has day-to-day care (article 245). Requiring the signature of the one who does not would give them a power of veto the law does not grant, and would paralyse the person who can in fact decide.
But article 224 establishes that both parents, living together or apart, take part in raising the child actively, equally and continuously — and the law does not say how. Informing everyone always, and allowing an objection to be recorded, is how we give that substance.
You can see who the responsible adults are for each child, invite the other one, and sign or reject pending decisions from both the app and the web portal. Having it in both is not a detail: if it were only in the app, anyone unwilling to install it could not take part in decisions about their own child.
For every signature we keep the exact wording that was accepted, the role declared, the date and the address it was signed from. That chain is never deleted, not even when the child’s data is erased: it is the only thing that lets us answer afterwards who authorised what.
5. Limits in the education setting
Law 21,719 prohibits processing and disclosing health data collected in an education setting. This is not a formality: it changes what the app allows.
- Profiles belonging to schools and their teachers do not access the child’s health data. They do not see medication, medical entries in the log, therapy session records or diagnoses.
- This restriction applies even if the responsible adult wanted to authorise it. It is not a configurable option.
- Education profiles only access expressly authorised teaching and behavioural information.
6. What we use the data for
We use the data solely to:
- Provide the service: create and maintain profiles, keep the log, manage medication, activities and appointments.
- Enable authorised collaboration between the family and its support team.
- Send notifications about reminders and relevant updates, according to the preferences you set.
- Authenticate access and protect account security.
- Keep audit logs that make it possible to tell who accessed the child’s information.
- Manage the subscription and billing.
- Meet legal obligations.
We do not use the data for any other purpose without first asking for fresh, specific consent.
7. Legal basis
| Processing | Basis |
|---|---|
| The child’s health data | Express consent of the adult with parental responsibility, given in writing in the app for a specific purpose |
| The child’s identifying data | Consent of the responsible adult |
| Adult user’s data | Performance of the service contract |
| Access by professionals and organisations | Specific, revocable consent of the responsible adult |
| Audit and security logs | Compliance with the security duty the law imposes |
| Billing and accounting | Legal obligation |
Where the basis is consent, you can withdraw it whenever you like. Withdrawing does not affect the lawfulness of earlier processing, but it does stop processing from then on.
8. Who we share it with
We do not sell personal data. We do not disclose it for advertising. We do no commercial profiling and make no automated decisions about people.
We rely on the following suppliers, which act as processors and may only handle the data on our instructions:
| Supplier | What for | Where |
|---|---|---|
| Akamai Technologies (Linode) | Application and database servers | Miami, United States |
| Google (Firebase) | Account authentication and push notifications | United States and global infrastructure |
| Zoho Corporation | Transactional email | Outside Chile |
| Google Play and the App Store | App distribution and subscription billing | Outside Chile |
Inside the app, the child’s information is shared only with the people and organisations the responsible adult has expressly authorised, and only in the sections authorised.
We will also hand over data when a competent authority requires it by reasoned decision and in accordance with the law.
When a school or therapy centre pays for Hey Santi
An organisation can pay for the service to support its students or patients. That contract does not authorise it to process your child’s data. You are the one who can authorise that, and it is not something a contract you are not party to can delegate.
So this is how it works:
- The organisation invites you; it does not create the child’s profile. The invitation holds your email address and an internal code of the organisation itself, no data about the child: before you authorise anything, there is nothing of theirs to process.
- The sections the organisation asks to see are a proposal. You can authorise less than it asks for.
- While the child is linked, the organisation processes their data on your behalf and only for what you authorised.
- If you unlink the child from the organisation, it keeps only the clinical or school record the law obliges it to keep — for example Law 20,584 as regards the clinical record — and must delete the rest. We notify it of the unlinking with that warning. For that record, the organisation answers for itself and not through us.
- Nothing obtained through Hey Santi may be used for the organisation’s own purposes — statistics, student selection, publicity — without fresh, specific consent from you.
What applies today. The mechanism described above is already built and working, but as of this version no organisation has access to any child’s data in Hey Santi: we will not enable one until we have signed the corresponding data processing agreement with it. If that changes, we will update this policy first.
9. International transfers
Your data is stored outside Chile. Hey Santi’s servers are in Miami, United States. We think you should know that plainly, not buried in a clause.
The United States has no adequacy decision issued by the Chilean Data Protection Agency. The transfer relies on:
- The contractual data protection obligations assumed by our infrastructure suppliers, and
- Your informed consent, which you give by accepting this policy knowing where the data is hosted.
We encrypt all communications in transit and apply identity-based access control to the information stored.
10. How long we keep it
| Data | Period |
|---|---|
| Account and child data | While the account is active |
| After a deletion request | Permanent deletion within 30 calendar days |
| After cancelling the subscription without asking for deletion | 12 months read-only, then deletion |
| Audit and image access logs | 24 months, because of their oversight role |
| Tax records | Whatever period the law requires |
The right to deletion is not conditional on keeping an active subscription. You can cancel the service and still ask us to erase everything.
Before deleting, we give you a copy
When you ask for deletion, we first build a file with the child’s entire history — log, medication, activities, sessions — and only then erase. The order matters: erasing before confirming delivery would turn your right to take the data with you into a permanent loss.
We do not send that file as an email attachment. Doing so would leave a child’s health history in inboxes we do not control, with no guaranteed encryption along the way and the chance of being forwarded by accident. Instead we send you a code, and the download happens on the platform with your session signed in. If more than one responsible adult is registered, each gets their own code, and it is recorded who collected their copy.
If the download window closes without someone collecting theirs, the deletion goes ahead — we cannot hold the data indefinitely — and it is recorded that the copy was not collected.
Of the deletion itself we keep only a record with the count of items erased and the organisations notified. It contains no data about the child. It exists so we can show the deletion happened.
11. Your rights
As a data subject, or as the child’s legal representative, you can exercise:
| Right | What it means | Response time |
|---|---|---|
| Access | Find out what data we hold and get a copy | 30 calendar days |
| Rectification | Correct inaccurate or incomplete data | 30 calendar days |
| Erasure | Have us delete your data | 30 calendar days |
| Objection | Object to a particular processing | 30 calendar days |
| Portability | Receive your data in a structured, commonly used format, or ask us to send it to another controller | 30 calendar days |
| Restriction | Temporarily suspend processing while we resolve a rectification, erasure or objection request | 2 working days |
The 30 calendar days can be extended once by a further 30 where the request is complex; if that happens we will tell you before the first period runs out.
How to exercise them
From the app or the portal, under “Your rights”. This is the route we recommend, for two concrete reasons:
- You do not have to prove your identity with documents. Your session already proves who you are. Asking for an ID to exercise a right is a barrier, and it would force us to store copies of identity documents that we do not have today and do not want to have.
- You can see the deadline. Every request is recorded with its due date and the days remaining. It does not depend on someone remembering.
Or by writing to privacidad@heysanti.app, saying which right you are exercising and enclosing something that lets us verify your identity. This channel stays open and always will: not everyone uses the app, and anyone who has closed their account keeps these rights just the same.
If you are acting for a child, tell us your relationship. Exercising these rights is free by either route.
What we do with your request. It is recorded with a date and a due date, and that deadline watches itself: the system alerts whoever has to answer you before it runs out. Access and portability are resolved on the spot — we build the file and send you a code to download it; the rest is reviewed by a person.
If we needed the extension the law allows, we will tell you before the first period runs out and say why.
12. Security
Measures we apply:
- TLS encryption in transit for all communications.
- Encryption at rest of the clinical history. The child’s name, the whole log, medication with its dosing and the notes on each dose are stored encrypted with AES-256, using a key the database does not hold. Anyone obtaining a copy of the database, or credentials to it, would find no readable text.
- Photos are encrypted too, including the child’s, which is stored as a file outside the database with the same encryption. Each image is cryptographically bound to the record it belongs to: an image moved elsewhere cannot be opened.
- Encryption of the database files and their transaction logs, so that a discarded or stolen disk reveals nothing.
- Authentication with signed tokens and validation at a security layer in front of the application.
- Access control by role and by consent: every request is checked against the permissions the responsible adult granted.
- Audit logging of access, with reinforced traceability over children’s images.
- Isolation of the server process with least privilege.
- Daily backups encrypted with AES-256 under a separate passphrase, verified after they are made and with restricted access.
- Strict separation between the test and production environments.
No system is invulnerable. If you find a security flaw, write to us at privacidad@heysanti.app: we will look into it and will take no action against anyone reporting in good faith.
13. Security breaches
If a breach affecting personal data occurs:
- We will notify the Data Protection Agency without undue delay.
- We will notify each affected person directly, since we process sensitive data and data about children under fourteen, where the law requires direct communication.
- The notice will say what happened, what data was affected, what we did about it and what you can do.
14. What we do not do
- We do not sell or rent personal data.
- We show no advertising in the app.
- We do not use children’s data to train artificial intelligence models.
- We do no tracking across third-party apps or sites.
- We make no automated decisions with legal effects on people.
- We do not ask for data we do not need to provide the service.
15. Changes to this policy
If we change it, we will update the date and version in the header. Where the change is substantial — new purposes, new recipients or a change of legal basis — we will tell you by email and inside the app before it takes effect. If the change requires fresh consent, we will ask for it; we will not assume it.
16. Contact and complaints
For any privacy matter: privacidad@heysanti.app
If you are not satisfied with our answer, you can complain to the Chilean Data Protection Agency, the body created by Law 21,719 and competent from the date it takes effect. Before then, complaints are handled under Law 19,628 before the ordinary courts.
If you are somewhere else, you may also be able to go to the data protection authority of your own country. We say so because the law that protects you is usually the law of where you are, and we do not want anyone to assume they must complain in a country they do not live in.