Privacy Policy

How we handle your data

This policy describes how Tecnologías Avanzadas y Seguridad Ledrium SpA — the company behind the Ledrium brand — processes the personal data it collects through this website and through the Ledrium ID access portal. It does not cover the processing carried out by the operational platforms our clients contract: in those deployments Ledrium acts as processor and the client is the controller (see section 12).

Last updated
August 25, 2026
Version
1.0

1. Who the controller is

The controller is Tecnologías Avanzadas y Seguridad Ledrium SpA, Chilean tax ID (RUT) 76.701.822-3, domiciled at Cerro El Plomo 5931, oficina 1213, Las Condes, Santiago, Chile, whose registered line of business is private security services provided by companies. It trades under the Ledrium brand.

For any matter concerning personal data — including the exercise of rights — the channel is administracion@goledrium.cl.

2. What data we process

We only process the data you give us or that is necessary for the site and the portal to work. We do not buy databases and we do not enrich your profile from third-party sources.

SourceDataIs it required?
Contact formName, email address, phone number, company, service of interest and whatever message you write.Name, email and message are needed to reply to you. The rest is optional.
Ledrium ID portal accountsEmail address, access credential in encrypted and irreversible form, and the platform and role authorizations attached to your account.Yes, for accounts created under a service contract.
Technical connection dataIP address, browser type and server request logs.Generated automatically as you browse.

This site does not process sensitive data. We neither request nor collect health, biometric, socio-economic, affiliation, or offence and sanction data.

3. Why we process it and on what grounds

PurposeLegal basis
Answering your commercial enquiry and maintaining the contact that follows from it.Your consent, given when you submit the form. You may withdraw it at any time.
Granting access to the Ledrium ID portal and to the platforms your organization has contracted.Performance of the contractual relationship between Ledrium and your organization.
Maintaining the security, availability and traceability of the service, and preventing unauthorized access.Ledrium's legitimate interest in protecting its own infrastructure (art. 13 d), weighed against your rights.

We do not use your data to build commercial profiles or for targeted advertising, and we do not share it with third parties for marketing purposes.

4. How long we keep it

We apply one retention period per data category rather than a single blanket period, and on expiry we delete or anonymize as appropriate.

CategoryPeriodOn expiry
Contact form data24 months from our last contact with you.Deletion.
Ledrium ID portal accountsDuration of the contractual relationship plus 2 years.Deletion.
Technical connection logs30 days.Deletion.

Where a legal obligation or the defence of a legal claim requires keeping a data point for longer, we keep it blocked — unused for any other purpose — until that obligation lapses.

5. Who else has access

We do not sell or transfer your data. We do work with providers that process it on our behalf, following our instructions and unable to use it for their own purposes:

ProviderPurpose
SupabaseDatabase and authentication service for the portal.
VercelHosting and delivery of the website.
ResendSending the internal notification when you write through the form.

Ledrium personnel strictly necessary to handle your enquiry or provide support may also access it, subject to the duty of secrecy imposed by law.

6. International transfers

The providers listed above operate infrastructure outside Chile, so the processing involves an international transfer of data.

The law allows three routes (art. 27). The first — transferring to a country with an adequate level of protection — is not available today, because the authority has not published any list of adequate countries. The third — a certified compliance model — is not available either. We therefore operate under the second: adequate safeguards assessed against the criteria of art. 28, carrying the burden of proof that its final paragraph places on whoever transfers.

You may ask us about the safeguards applied to a specific transfer by writing to the channel in section 9.

7. Your rights

Ley 21.719 grants you six rights over your personal data. They are not the classic «ARCO» set: blocking is a standalone right, specific to the Chilean regime.

RightWhat it lets you doArticle
AccessKnow what data of yours we process, for what purpose and to whom we disclose it.Art. 5
RectificationCorrect inaccurate, outdated or incomplete data.Art. 6
DeletionAsk us to erase your data when no grounds remain for processing it.Art. 7
ObjectionObject to a specific processing operation, including disclosure to third parties.Art. 8
PortabilityReceive your data in a structured, commonly used format, or ask us to transfer it.Art. 9
BlockingTemporarily suspend the processing without your data being deleted.Art. 8 ter

This site takes no automated decisions producing legal effects on you or significantly affecting you. Should that change, we would tell you, and you could request an explanation, human intervention and review of the decision (art. 8 bis).

8. Deadlines and cost

The general response deadline is thirty calendar days, extendable once by another thirty where the complexity of the request warrants it, notifying you before the first deadline expires (art. 11).

Blocking has its own, far shorter deadline: two business days (art. 8 ter).

Exercising the rights of rectification, deletion and objection is always free of charge. Access is free at least once per quarter.

9. How to exercise them

Write to administracion@goledrium.cl stating which right you wish to exercise, over which data, and an address where we can reply. To protect your information we may ask for additional details allowing us to verify your identity; we will not ask for more data than is necessary for that.

We will acknowledge your request and inform you of the outcome within the deadlines in the previous section. If we reject the request, we will explain why.

10. Complaints to the authority

If you believe we have not properly handled your request, or that we process your data in breach of the law, you may complain to the Agencia de Protección de Datos Personales once it is operating. That complaint is independent of the civil actions the law grants you.

11. Security

We apply technical and organizational measures appropriate to the risk of the processing:

  • Access control per user and per role, with centralized authentication.
  • Encryption of traffic in transit between your browser and our services.
  • Storage in private repositories, with no public access and no anonymous listing.
  • Time-limited signed links, generated server-side after validating the session, for any file that must be delivered.
  • Logging of the actions performed on the data.
  • Delivering to the browser only the data the view actually needs.

No measure removes risk entirely. In the event of a security breach entailing a reasonable risk to your rights, we will inform you without undue delay in accordance with art. 14 sexies.

12. The operational platforms: Ledrium as processor

The products Ledrium operates for its clients — access control and security in venues, plate reading on highways, digital twins of mine sites — process personal data under the responsibility of the contracting client, not of Ledrium. In those deployments the client is the controller: it defines the purpose, determines the legal basis, publishes its own policy and handles data subjects. Ledrium acts as processor.

If you attended a venue or drove on a road and wish to exercise rights over that processing, the request belongs to the operator of the venue or the road. If you write to us, we will point you to the right party and forward your request to the controller.

13. Changes to this policy

If we amend this policy we will publish the new version at this same address, with its version number and date. Where the change materially affects processing based on your consent, we will tell you before applying it.