Privacy Policy and Personal Data Processing
Coral System — SOS Asistencia
Last updated: [fill in date] · Version 0.1
1. Purpose and scope
This Privacy Policy and Personal Data Processing notice (the "Policy") informs end customers, corporate customers, technicians and field partners, advisors, and other users (collectively, the "Data Subjects") about how SOS Asistencia (and, where applicable, AYA Constructores) collects, uses, stores, shares, and protects personal data processed through the Coral system.
Coral is the technology platform that manages the entire lifecycle of assistance services end-to-end: from the customer's request, the advisor's intake, the search, notification, and assignment of technicians, travel and on-site arrival, execution and follow-up of the service, management of products and spare parts, through to closing, collection, and invoicing.
This Policy applies to every component of the Coral ecosystem: the mobile app for technicians (CoralApp), the web administration dashboard, the corporate customer portal, the AI chat widget, and the associated backend services, regardless of the country in which the service is delivered.
2. Data controller
The controller responsible for the personal data collected through Coral is:
- Legal name: SOS Asistencia [fill in legal name and tax ID]
- Registered address: [fill in address]
- Privacy contact email: [fill in email, e.g. privacy@sosasistencia.com]
Where a service is provided under a corporate customer that acts as controller of its own end customers' data (for example, an insurer or transportation company using Coral to manage its field staff), that corporate customer may be the controller for that data, and SOS Asistencia will act as processor under the terms defined contractually.
3. Applicable legal framework
In Chile, personal data processing is currently governed by Law No. 19,628 on the Protection of Private Life. That law will be replaced, where relevant, by Law No. 21,719, published on December 13, 2024, which comes into full force on December 1, 2026. Law 21,719 creates the Personal Data Protection Agency (APDP), grants full ARCO rights (access, rectification, cancellation, and objection) plus the right to portability, requires security-breach notification within 72 hours, and raises fines up to 20,000 UTM (or up to 4% of annual revenue for repeat offenses).
SOS Asistencia also operates in other LATAM countries. In each of them, Coral must operate in accordance with the local data protection law in force (for example, Law 1581 of 2012 in Colombia, the LFPDPPP in Mexico, or Law 29733 in Peru, among others that may apply).
4. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Sensitive data: data revealing ethnic origin, political opinions, health, sex life, biometric data, or union membership, among other categories with reinforced protection.
- Processing: any operation performed on personal data, such as its collection, storage, use, disclosure, or deletion.
- Data subject: the natural person to whom the personal data relates.
- Controller: the party that decides on the purpose and means of processing.
- Processor: the party that processes personal data on behalf of, and under the instructions of, the controller (e.g., technology providers).
- ARCO rights: access, rectification, cancellation (deletion), and objection.
- International data transfer: sending personal data to a recipient located outside the country where it was collected.
5. Categories of data subjects
Coral processes personal data belonging to the following categories of people:
- End customers: people who request and receive the assistance service.
- Corporate customers and their users: companies that contract services, and the people who administer or view the portal on their behalf.
- Technicians and field partners: people who carry out the services, whether employed by SOS Asistencia or by third-party partners.
- Advisors and internal staff: SOS Asistencia users who register, assign, and follow up on services.
- Suppliers and commercial partners: contact people for suppliers of products and spare parts.
6. Personal data we collect
The table below summarizes, on a non-exhaustive basis, the personal data Coral collects by category of Data Subject:
| Data subject category | Personal data collected | Source / means of collection |
|---|---|---|
| End customer | Name, service address, phone number, email, photos and videos of the site, voice notes, service history and status, complaints/claims (NQR), confirmation or sign-off, billing and payment data where applicable. | Support channels, the advisor's intake form, the Coral App (technician), email, corporate customer portal. |
| Corporate customer and its users | Company details (legal name, tax ID, contact), portal login credentials, information about the services and end customers linked to their account. | Corporate customer onboarding, Coral portal, integrations with the customer's third-party systems. |
| Technician / field partner | Name, ID, phone, email, real-time geolocation during travel and active shifts, evidence photos and videos, voice notes, schedule and availability, service history, performance evaluations, device identifier and push-notification token. | CoralApp (technician), engagement/contract form with SOS Asistencia or the partner, mobile device geolocation sensors. |
| Advisor / internal staff | Name, user credentials, assigned role and permissions, audit logs of their activity in the system. | Internal user provisioning in the Coral dashboard. |
| Supplier / commercial partner (purchasing) | Company name, business contact details and, where applicable, banking details for paying purchase orders. | Coral purchasing module, purchase order emails. |
7. Purposes of processing
The personal data described above is processed for the following purposes:
- Managing the entire service lifecycle end-to-end: intake, search and notification of technicians, assignment, travel, on-site arrival, execution, closing, collection, and invoicing.
- Sending operational notifications and communications (push, email, SMS, WhatsApp, or other channels).
- Verifying appointment compliance, monitoring travel, and detecting the technician's arrival at the service site.
- Managing the request, purchase, and delivery of products and spare parts required for the service.
- Recording and following up on complaints and claims (NQR).
- Generating reports, summaries, and operational performance analytics, including generative AI features.
- Preventing fraud, ensuring platform security, and maintaining an audit trail of activities.
- Complying with applicable legal, accounting, tax, and regulatory obligations.
8. Legal basis for processing
- Contract performance: when processing is necessary to deliver the service or to manage the relationship with the technician, partner, or corporate customer.
- Consent: for non-essential purposes, such as marketing communications.
- Legitimate interest: for security, fraud prevention, compliance monitoring, and continuous service improvement.
- Legal obligation: for invoicing, accounting, and reporting to authorities.
9. Technician geolocation
CoralApp captures the technician's real-time location while traveling to a service or during an active shift, for the following purposes: calculating estimated arrival times, optimizing routes, automatically detecting arrival at the site (geofencing), enabling proximity-based service assignment, and allowing advisors to view on a map the location of available or already-assigned technicians.
Geolocation is collected only during periods when the technician is on an active shift or traveling in connection with a service, and is not intended to track the technician's private life outside that context. The basis and scope of this collection must also be reflected expressly in the technician's or partner's employment/commercial agreement with SOS Asistencia, not only in the app's terms of use.
10. Photos, videos and voice notes
During service delivery, the technician, the advisor, and the customer themselves may record photos, videos, and voice notes as evidence of site conditions, the work performed, or issues related to the service. This content is processed solely for operational, service-quality, dispute-resolution, and service-history purposes, and is stored with the security measures described in Section 15.
11. Communications through third parties
Coral sends push notifications, emails, text messages (SMS), and WhatsApp messages, among other channels, to keep customers, technicians, and advisors informed. These communications may involve external messaging and email providers, who act as processors and are contractually required to protect the information.
13. International data transfers
When any of the technology providers used by Coral (for example, cloud or AI services) store or process personal data on servers located outside the country where it was collected, such transfer will be carried out adopting the safeguards required by applicable law.
14. Data retention
Personal data will be retained for as long as the commercial or contractual relationship with the Data Subject lasts and, afterward, for any additional period required by applicable legal, accounting, and tax obligations. Geolocation data will be retained only for the period strictly necessary for the operational and compliance purposes described above, in line with the data-minimization principle.
15. Security measures
SOS Asistencia implements reasonable technical and organizational measures, including:
- Role, module, and permission-based access control, with two-factor authentication (TOTP or email) for internal users.
- Encryption of information in transit and, where applicable, at rest.
- Rate limiting against unauthorized access attempts.
- Audit logs of actions performed on services and data.
- Segregation of information between different corporate customers (multi-tenant architecture).
- Internal incident-response protocols.
In the event of a security breach affecting personal data, SOS Asistencia will notify the competent authority and affected Data Subjects within the timeframes required by applicable law (in Chile, within 72 hours under Law 21,719 once it is in force).
16. Data subject rights
- Access: to know what data is processed and for what purpose.
- Rectification: to request correction of inaccurate or incomplete data.
- Cancellation or deletion: to request deletion of data that is no longer necessary, without prejudice to legal retention obligations.
- Objection: to object to processing for specific purposes, such as marketing communications.
- Portability: to request data in a structured, commonly used format, where applicable law provides for it.
To exercise these rights, Data Subjects may contact SOS Asistencia through [fill in contact channel]. Requests will be handled within the timeframes set by applicable law.
17. Minors
Coral's services are directed at adults. SOS Asistencia does not intentionally collect personal data from minors through the platform. Should information about a minor be incidentally recorded in connection with a service (for example, in a photo of the site), it will be treated under the same protection and minimization standard set out in this Policy.
19. Data processors and providers
SOS Asistencia enters into data processing agreements or clauses with its technology providers (cloud, messaging, AI, geolocation and maps, among others), to ensure levels of security and confidentiality equivalent to those required by this Policy.
20. Data Protection Officer
In line with the requirements of Law 21,719 in Chile, SOS Asistencia [will designate / has designated] a Data Protection Officer (DPO), responsible for overseeing compliance with this Policy. Contact details: [fill in DPO name and email].
21. Changes to this Policy
SOS Asistencia may update this Policy to reflect regulatory, operational, or technological changes. Any material change will be communicated to Data Subjects with reasonable notice before it takes effect.
22. Governing law and jurisdiction
This Policy is governed primarily by Chilean data protection law (Law 19,628 and, from December 1, 2026, Law 21,719). For Coral's operations in other LATAM countries, the local law of each jurisdiction will additionally apply.
23. Contact
For questions related to this Policy, Data Subjects may contact SOS Asistencia at: [fill in email / address / contact form].