PRIVACY AND PERSONAL DATA PROTECTION POLICY
This Privacy Policy (hereinafter, the "Policy") governs the processing of personal and operational data collected by DRUPPIFY (hereinafter, the "Platform" or "Druppify"), owned by Sistemas Tecnológicos Osystems SpA, tax ID 76.967.436-5, in its capacity as Data Controller.
By registering and using the Platform, the User (hereinafter, the "User" or "Drupper") expressly authorises Druppify to collect, store, process and use their personal and operational data in accordance with this Policy and the Terms and Conditions of Use.
1. INTRODUCTION AND SCOPE
1.1. Data Controller: Sistemas Tecnológicos Osystems SpA (tax ID 76.967.436-5), as owner of the Druppify Platform, acts as the Controller of Users' personal and operational data.
1.2. Territorial Scope: This Policy applies to the processing of data of Users located in Chile and is governed by Chilean legislation in force on the protection of personal data, including Law No. 19,628 on the Protection of Private Life and complementary regulations.
1.3. Nature of the Service: Druppify is a technology platform for operational coordination connecting Logistics Operators, Commercial Principals and Users (Druppers). Druppify is NOT an employer of the User, does NOT process payments nor set rates, and does NOT intervene in the contractual relationship between the User and the Logistics Operator. Druppify acts exclusively as a technology intermediary.
2. DRUPPIFY'S ROLE AS DATA CONTROLLER
2.1. Druppify's Responsibilities: As Data Controller, Druppify is responsible for:
- Ensuring the lawful, fair and transparent processing of personal data
- Implementing technical and organisational security measures to protect the data
- Processing data solely for the purposes stated in this Policy
- Respecting Users' privacy rights in accordance with applicable law
- Retaining the operational data required for system integrity and legal compliance
2.2. Limitations: Druppify is NOT responsible for:
- Data processing carried out by Logistics Operators or Commercial Principals outside the Platform
- Employment, contractual or commercial relationships between the User and third parties
- The User's payments or tax obligations
- Misuse of data by third parties unconnected with Druppify
3. TYPES OF DATA COLLECTED
Druppify collects and processes the following categories of data:
3.1. Identifiable Personal Data (Registration and Profile)
- Full name: required to identify the User
- Email address: used for communications, notifications and account recovery
- Mobile phone: required for SMS verification, notifications and operational contact
- Password: stored with bcrypt encryption (irreversible hash) for secure authentication
- Profile photograph: optional, for visual identification on the Platform
- Home address: optional, to calculate distances and optimise coordination
- Date of birth: to verify the User is of legal age (under-18s prohibited)
- Identity document: required for identity validation and legal compliance
- Driving licence: only for Operational Roles that involve driving
- Certificates and skills: documentation of relevant training, permits or certifications
3.2. Verification and Authentication Data
-
SMS verification code: sent to the User's phone during registration via the endpoint
/auth/send-sms-verification-signup - Session token: generated after successful authentication to keep the session active
- Login history: date, time, IP address and device used
- Failed authentication attempts: to prevent unauthorised access
3.3. Operational Data (Activity on the Platform)
- Service start/end records: date and time when operational activities are started and finished
- Geolocation at critical events: GPS coordinates captured while entering an address (where applicable), delivering orders, during incidents or whenever required for operational traceability.
- Photographic evidence: photos of products, digital signatures, proof of delivery, vehicle or facility condition, or any evidence required by the operational process
- Digital signatures: captured on a touchscreen to record deliveries or acceptance of services
- Performance metrics: punctuality, adherence to protocol, completion rate, average rating and indicators calculated automatically by the Platform
- Service history: a list of services assigned, accepted, completed, declined or cancelled, including reasons for declining or cancelling
- Incidents and claims: records of operational anomalies, problem reports, claims made by the User or reported against them
3.4. Technical and Device Data
- Device information: model, manufacturer, operating system (iOS/Android), OS version
- Mobile app version: for compatibility and to detect when updates are required
- Unique device identifier (Device ID): to prevent fraud and control multiple sessions
- Permissions granted: a record of the permissions granted by the User (camera, location, notifications)
- Error and crash logs: technical information about application failures, to improve the service
3.5. Data Generated by Algorithms and Automated Processes
- NON-binding payment estimates: indicative calculations based on rates configured by the Logistics Operator; they do NOT constitute a payment commitment on Druppify's part
- Scores and rankings: ordering of Users based on performance metrics, generated automatically to facilitate coordination (NOT for employment decisions)
- Priority assignment: an algorithm that suggests the order in which services are assigned according to availability, proximity, history and the Operator's configuration
- Automated flags and statuses: markers for active/inactive, blocked, under review or suspended accounts
- Anomaly alerts: automated detection of unusual behaviour
4. PURPOSE OF DATA PROCESSING
Druppify processes the User's personal and operational data exclusively for the following purposes:
4.1. Platform Functionality and Operation
- Registration, authentication and management of User accounts
- Operational coordination between Users and Logistics Operators
- Notifications about available, assigned or modified services
- Recording and traceability of the start and end of services, operational evidence and digital signatures
- Calculation and display of NON-binding payment estimates (configured by the Operator)
- Management of incidents, claims and technical support
4.2. Validation, Security and Fraud Prevention
- Identity verification through validation of the national ID, documents and SMS
- Detection and prevention of record manipulation, impersonation or fraudulent use
- Auditing of critical events (logins, profile changes, suspicious actions)
- Access and permission control according to roles and account statuses
4.3. Traceability, Audit and System Integrity
- Retention of historical operational records for the integrity of metrics and calculations
- Auditing of operational processes for Logistics Operators and Commercial Principals
- Generation of aggregated operational reports, statistics and analysis
- Compliance with applicable accounting, tax and legal obligations
4.4. Service Improvement and Technology Development
- Analysis of Platform usage to improve features
- Detection and correction of technical errors (logs, crashes)
- Optimisation of coordination and dispatch algorithms
- Development of new features based on User feedback
4.5. Service-Related Communications
- Operational notifications (services, changes, alerts)
- Technical support and customer service communications
- Notices about changes to the Terms and Conditions or Privacy Policy
- Legal, administrative or regulatory compliance communications
5. LEGAL BASES FOR PROCESSING
The processing of the User's personal data is based on the following legal grounds:
5.1. The User's Express Consent: By registering and accepting these Terms and Conditions and Privacy Policy, the User gives their free, informed and unambiguous consent to the processing of their data in accordance with this Policy.
5.2. Performance of the Service: Processing is necessary to provide the operational coordination service requested by the User when registering on the Platform.
5.3. Compliance with Legal Obligations: Retention of operational data to comply with accounting, tax, audit and other applicable regulations in Chile.
5.4. Druppify's Legitimate Interest: Fraud prevention, Platform security, system integrity, service improvement and protection of the rights of Druppify, Operators and other Users.
6. USE OF GEOLOCATION, CAMERA AND OPERATIONAL EVIDENCE
6.1. Geolocation (GPS)
The Platform requires access to the GPS location of the User's mobile device only at specific events:
- Start of service: when starting a service, to validate presence at the correct location
- End of service: when finishing a service, to record completion
- Order deliveries: when completing deliveries, for traceability and evidence
- Operational incidents: when it is necessary to record the location of an abnormal event
6.2. Camera and Photographic Evidence
The Platform requires access to the device camera in order to capture:
- Profile photograph: optional, for visual identification of the User
- Identity documents: capture of the national ID card, driving licence and certificates
- Delivery evidence: photos of delivered products, packaging condition, digital signatures
- Incident records: photographic evidence of damage, anomalies or exceptional situations
6.3. Storage of Evidence
Photographic evidence and digital signatures are stored securely on cloud servers (Microsoft Azure) with encryption at rest and in transit, and are retained in accordance with the retention periods set out in Section 9.
7. AUTOMATED PROCESSES AND ALGORITHMS
The Platform uses algorithms and automated processes for operational coordination, NOT for employment decisions or for defining the terms on which services are provided.
7.1. Priority Assignment Algorithm
It orders Users according to configurable criteria (availability, proximity, performance history, Operator preferences) to facilitate coordination. It does NOT determine who must provide services.
7.2. Calculation of Payment Estimates (NON-Binding)
Based on rates configured by the Logistics Operator, the Platform may display indicative estimates of financial compensation. These estimates:
- Are exclusively informative and indicative in nature, in accordance with the Terms and Conditions of Use
- do NOT constitute any payment commitment on Druppify's part
- are NOT binding on either the Operator or the User
- Serve only as informative reference
- The actual payment is the exclusive responsibility of the Logistics Operator
7.3. Automated Performance Metrics
The Platform automatically calculates metrics such as:
- Punctuality (difference between the expected time and the actual start, for roles where this applies)
- Completion rate (services completed versus assigned)
- Adherence to protocol (compliance with operational steps)
- Average rating (if the Operator enables a rating system)
These metrics are used for coordination and ordering, NOT for employment decisions or disciplinary action.
7.4. Automated Anomaly Detection
The Platform can automatically detect:
- Services started outside the expected geographical area
- Unusual patterns of declined services
- Manipulation of records
- Simultaneous access from multiple devices
These detections generate alerts for manual review; they do NOT apply automatic penalties.
8. AUTHORISATION OF USE AND NON-TRANSFER OF DATA
8.1. Nature of the Authorisation: The User declares and accepts that the authorisation granted to Druppify to process their personal and operational data does NOT constitute an assignment, transfer or sale of data, but rather a limited and revocable permission for strictly operational, functional and security purposes of the Platform.
8.2. Ownership of the Data: The User does NOT transfer ownership of their personal data to Druppify. They retain all their rights over the data in accordance with applicable law.
8.3. Revocability: The User may revoke their authorisation and request the deletion of their identifiable personal data, subject to the limitations set out in Section 9 (retention of operational data for system integrity).
9. DATA RETENTION, DELETION AND ANONYMISATION
9.1. Erasable Personal Data
The User may request the deletion of the following identifiable personal data:
- Name, surname, email, telephone (to be replaced by a pseudonymous identifier)
- Profile photograph
- Home address and its GPS coordinates
- Images of identity documents, licences and certificates (subject to the minimum legal retention period)
9.2. NON-Erasable Operational Data (Mandatory Retention)
For reasons of system integrity, traceability, audit and legal compliance, Druppify will retain for the legally required periods and/or in anonymised form the following operational data:
- History of services assigned, completed or cancelled
- Service start/end records with timestamp and GPS coordinates
- Performance metrics (punctuality, adherence, completion rates)
- Operational evidence (delivery photos, digital signatures, receipts)
- Records of incidents, claims or operational anomalies
- Payment estimate calculations and rates applied
- Historical relationships with Operators and Commercial Principals
- Logs of critical events (authentication, configuration changes)
9.3. Reasons for Retaining Operational Data
- System integrity: deleting operational data would break historical metrics, calculations and reports
- Operational audit: Operators require full traceability of past services
- Legal compliance: accounting, tax and audit obligations require operational records to be retained
- Fraud prevention: historical pattern analysis to detect anomalous behaviour
- Dispute resolution: operational evidence may be needed for mediation or legal proceedings
9.4. Account Deletion Mechanism
When account deletion is requested:
- Identifiable personal data (name, email, telephone) will be anonymised (replaced by a pseudonymous identifier such as "User-XXXXX")
- Operational data will be retained linked to the pseudonymous identifier to preserve the integrity of historical records
- The User You will NOT be able to access the Platform again with the same account
- Photographic evidence will remain stored securely for the legal retention period (minimum 6 years)
- The anonymisation process is irreversible
9.5. Retention Period
- Identifiable personal data (with no deletion request): while the account is active and for up to 2 years after the last activity
- Anonymised operational data: minimum 6 years from the creation of the record, in accordance with Chilean accounting and tax obligations
- Operational evidence (photos, signatures): minimum 6 years in secure storage
- Security and audit logs: minimum 2 years
10. USER RIGHTS
The User has the following rights over their personal data:
10.1. Right of Rectification
To correct inaccurate or out-of-date personal data. This can be done directly from the profile settings or by contacting support.
10.2. Right of Erasure (with limitations)
To request the deletion or anonymisation of identifiable personal data, subject to the operational data retention limitations set out in Section 9.
10.3. Right to Object to Processing
To object to specific processing that is not essential to the service. Objecting to essential processing means it will not be possible to continue using the Platform.
10.4. Right Not to Be Subject to Automated Decisions with Legal or Employment Effects
The Platform's algorithms and automated processes (priority assignment, metric calculation, rankings, anomaly detection) have NO legal or employment effects on the User. They are tools for operational coordination and traceability, NOT for selection, hiring, employment appraisal or determining the terms on which services are provided. The User retains at all times the absolute and unrestricted right to accept or decline the services offered, with no consequences or penalties.
10.5. How to Exercise These Rights
To exercise any of these rights, the User must get in touch through the official support channels (see Section 15), identifying themselves appropriately.
11. SHARING DATA WITH THIRD PARTIES
Druppify does NOT sell or trade Users' personal data. Data may be shared only in the following cases:
11.1. With Logistics Operators
Name, profile photograph, performance metrics, operational history and the data required to coordinate specific services. The Operator acts as Data Processor and must comply with this Privacy Policy.
11.2. With Technology Providers
- Microsoft Azure: cloud storage of data and evidence (with encryption at rest)
- MongoDB Atlas: operational database (with encryption at rest and in transit)
- SMS providers: to send verification codes (phone number + temporary code only)
- Push notification services: Firebase/APNs for mobile notifications (device token + message)
All technology providers are subject to confidentiality and data processing agreements.
11.3. Upon Legal Requirement
Druppify may disclose personal data if required by:
- A court order
- A requirement from a competent authority (public prosecutor, tax authority, etc.)
- Compliance with mandatory legal obligations
- Protection of the rights of Druppify, Operators or third parties in legal proceedings
11.4. NOT Shared with Third Parties for Marketing
Druppify does NOT share, sell or assign personal data to third parties for advertising, direct marketing or the commercialisation of databases.
12. INFORMATION SECURITY
Druppify implements technical and organisational security measures to protect the User's personal and operational data:
12.1. Technical Security Measures
- Password encryption: bcrypt algorithm with irreversible hashing (passwords are never stored in plain text)
- HTTPS/TLS communication: all communication between the mobile/web application and the servers uses TLS 1.2+ encryption
- Encryption at rest: data stored in Azure and MongoDB Atlas with AES-256 encryption
- Session tokens: JWT token-based authentication with automatic expiry
- Access control: granular permissions by role (User, Operator, Administrator)
- Auditing of critical events: logging of logins, profile changes and suspicious actions
12.2. Organisational Measures
- Access to personal data restricted to authorised staff bound by confidentiality obligations
- Regular team training in data protection and information security
- Internal policies for managing security incidents and notifying breaches
- Confidentiality agreements with technology providers and Data Processors
12.3. Security Limitations
Despite the measures in place, no system is 100% secure. Druppify cannot guarantee absolute security against unauthorised access, cyberattacks or security breaches. The User accepts these risks inherent in the use of digital services.
12.4. Notification of Security Breaches
In the event of a security breach affecting sensitive personal data, Druppify will notify the affected Users within a maximum of 72 hours from becoming aware of the incident, in line with international best practice.
13. PROHIBITION OF USE BY MINORS
The Platform is PROHIBITED for anyone under 18 years of age.
Druppify does NOT knowingly collect data from minors. On registering, the User declares that they are over 18. If Druppify detects that a User is a minor, it will proceed to immediately delete their account and personal data.
13.1. User Responsibility
The User is responsible for the accuracy of the age information provided. Any falsehood in this regard constitutes a serious breach of the Terms and Conditions.
13.2. Procedure if a Minor Is Detected
- Immediate suspension of the account
- Complete deletion of personal data (total deletion, not anonymisation)
14. AMENDMENTS TO THIS PRIVACY POLICY
14.1. Right to Amend: Druppify reserves the right to amend this Privacy Policy at any time, publishing the new version on the Platform and/or on the website www.druppify.com.
14.2. Notification of Substantial Changes: Substantial amendments affecting the User's fundamental rights will be notified at least 10 days in advance by:
- Email to the registered address
- Push notification in the mobile app
- An information banner in the User's panel
14.3. Acceptance of Changes: Continued use of the Platform after the changes come into force constitutes tacit acceptance of the new Privacy Policy.
14.4. Right Not to Accept: If the User does not agree with the amendments, they must stop using the Platform and request the deletion of their account before the changes come into force.
15. CONTACT AND EXERCISING PRIVACY RIGHTS
For queries, complaints, the exercise of privacy rights (access, rectification, deletion of data) or any request relating to the processing of personal data, the User may contact Druppify through:
Official Support Channels:
- Email: soporte@druppify.com (please write "PRIVACY" in the subject line)
- In-app form: "Support" section > "Privacy and Personal Data"
- Support chat: available during business hours (Mon-Fri 9:00-18:00 Chile time)
Data Controller Details:
- Registered name: Sistemas Tecnológicos Osystems SpA
- Tax ID: 76.967.436-5
Response Times:
- General information requests: 5 business days
- Exercise of ARCO rights (access, rectification, cancellation, objection): 10 business days
- Complaints about infringement of rights: 15 business days
16. ACCEPTANCE AND CONSENT
By ticking the "I accept the Privacy Policy" box and/or by clicking "Register" or "Continue", the User expressly declares that:
- They have read, understood and fully accept this Privacy Policy
- They give their free, informed and unambiguous consent for the processing of their personal and operational data in accordance with this Policy
- They authorise the use of GPS geolocation at specific events (start and end of services, deliveries)
- They authorise the use of the camera to capture documents and operational evidence
- They understand and accept that operational data will be retained in anonymised form even if they request account deletion
- They accept that Druppify is NOT their employer and that this authorisation does NOT constitute an assignment or sale of data
- They are over 18 years of age and have the legal capacity to give this consent
- They have read and accept the Terms and Conditions of Use of Druppify
17. APPLICABLE LAW AND JURISDICTION
This Privacy Policy is governed by the laws of the Republic of Chile, in particular:
- Law No. 19,628 on the Protection of Private Life
- Law No. 19,496 on the Protection of Consumer Rights
- The Civil Code and Commercial Code of Chile
- Complementary regulations in force on data protection