Privacy Policy
Last updated: July 26, 2026
Encrypted in transit and at rest
TLS 1.3 in transit, AES-256 at rest
Full transparency
You know exactly what data we collect and what we use it for
User control
Access, export or delete your data at any time
1. General Information
This Privacy Policy describes how MIA Marketing & Intelligence Artificial SpA, RUT 78.199.687-4 (hereinafter, "WITHMIA", "we" or "the Company"), with registered address at Antonio Bellet 193, Of. 1210, Providencia, Santiago, Chile, collects, uses, stores and protects the personal information of users of the WITHMIA platform (hereinafter, the "Service").
This policy applies to all users of the Service, including website visitors, registered users and account administrators. By using the Service, you accept the practices described in this policy.
2. Data We Collect
We collect different types of information depending on how you interact with WITHMIA:
2.1 Registration data
- Full name and company name
- Corporate email address
- Phone number (optional)
- Country and time zone
2.2 Service usage data
- Conversations and messages sent/received through the platform
- Workspace settings, connected channels and automation rules
- Customer contact data managed on the platform
- Documents uploaded to the knowledge base (RAG)
- Team activity and audit logs
2.3 Technical data
- IP address and browser type
- Operating system and device type
- Pages visited, session duration and browsing patterns
- Session identifiers and authentication tokens
- When a payment cannot be completed because your country is not yet covered by our payment providers, we store your email address alongside that attempt for the sole purpose of letting you know when payment becomes available where you are. You may object by writing to [email protected]
2.4 Usage and browsing data (sign-up and payment funnel)
We record the steps of the path that runs from your first visit to the payment attempt, passing through sign-up and initial setup, so we can tell where people drop off and which markets we are reaching. Each event is stored with its date and the following data:
- Your IP address, the country —the one you declared or, if you did not declare it, the one we infer from your IP address— and which of those two sources it came from
- The language your browser requests and the language we actually serve you
- Your arrival at the public entry screens (home page, sign-in and sign-up), recorded once per session and not on every reload
- The sign-up and initial setup step you save, whether that step failed and for what reason, and payment attempts together with the plan, the billing cycle, the currency, the payment provider and the reason the charge could not be completed
- Your email address and the identifiers of your account and your company, only when you have already given them to us: when you sign up with Google, when you browse with an active session, or when you hit the payment wall. We never infer your email address from the IP address, nor do we obtain it from third parties
- A pseudonymous identifier derived from your session identifier through a hash function, which links those events to one another without creating a new cookie and expires with the session
What for: to understand at which step people drop off and from which countries and languages they reach us —so we can fix those points and decide where to enable payments— and to detect and stop abuse, such as the automated sign-ups blocked by our anti-bot filter. These events are consulted only from WITHMIA's admin panel: they do not feed advertising and are not sold to third parties.
Lawful basis: legitimate interest (Art. 6(1)(f) GDPR). Our interest is to know whether sign-up and payment work in each country and to protect sign-up against abuse; the processing is limited to the data listed above and involves no profiling and no advertising.
Retention: 12 months from the moment each event is recorded. A daily automated task deletes the events that exceed that period; we do not keep this history beyond it.
Objection: you can object to this processing by writing to [email protected]. We will delete the events we can link to you —those carrying your email address or your account identifier— and stop associating new events with you. Events that carry neither an email address nor an account could only be traced through the IP address, which changes over time, so we may not manage to locate all of them; in any case they are deleted after 12 months.
When the country does not already come resolved in the header supplied by the site's content delivery network (Cloudflare), we look your IP address up against an external IP geolocation service (ip-api.com), which returns the country and nothing else. Only the IP address is sent to that service: neither your email address nor any other data.
2.5 Web scheduling data
- Full name of the requester
- Email address
- Company name (optional)
- Meeting topic
- Selected date and time
- This data is used to create an event in Google Calendar with a Google Meet link, and to send a confirmation by email
2.6 Billing data
- Billing information that the account administrator may register for their receipts and tax documents: RUT, name or legal name, business activity, address and district
- This data is included in the payment receipts downloadable from the platform and, where applicable, in the electronic receipts or invoices issued in accordance with the regulations of the Chilean Internal Revenue Service (SII)
- Payment data (card number) is processed exclusively by our PCI-DSS certified payment processors, based on your country and currency: Flow.cl for payments in Chile (CLP), Paddle (Paddle.com Market Ltd, United Kingdom) for international payments —which acts as Merchant of Record (authorized reseller) and therefore processes your payment and billing data in accordance with its own terms and privacy policy— and dLocal for international payments in Latin America. WITHMIA neither sees nor stores credit card data
2.7 Data obtained from Google services
When you use Google to interact with WITHMIA, we may receive the following data:
- Google Sign-In: Full name and email address provided by your Google account to authenticate you on the platform
- Google Calendar: Calendar events, time availability and meeting data, used exclusively for the scheduling system within WITHMIA
- OAuth tokens: Encrypted credentials that allow WITHMIA to access Google services on your behalf. These tokens are stored securely and can be revoked at any time
WITHMIA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. WITHMIA does not use Google data for advertising, does not transfer it to third parties except as necessary to provide the Service, and does not use it for purposes unrelated to the functionality requested by the user.
3. Use of Information
We use the information collected for the following purposes:
- Provision of the Service: Operating, maintaining and improving the WITHMIA platform, including message processing, contact management and running automations
- Artificial intelligence: Generating the responses of the intelligent assistants. To do so, conversation messages and knowledge base content are sent to AI providers that act as data processors: Anthropic (Claude models, used on the Pro, Team and Max plans) and OpenAI (language model for the Inicial plan and embedding generation for semantic search). These providers process the text solely to produce the requested response and do not use it to train their models
- Scheduling: Processing meeting requests from the website, creating events in Google Calendar and sending email confirmations to the visitor and to the WITHMIA team
- Automated decisions: WITHMIA uses artificial intelligence models to generate automatic responses on support channels. These responses are AI-generated and may be supervised by the human team. No legal or significantly impactful decisions are made on a solely automated basis
- Communications: Sending notifications about the Service, updates, security alerts and support communications
- Analytics: Generating reports and performance metrics for users of the Service
- Sign-up and payment funnel analytics: Measuring at which step of sign-up, initial setup or payment people drop off, and from which countries and languages they reach us, in order to fix those points and decide where to enable payments. This measurement rests on our legitimate interest (Art. 6(1)(f) GDPR), includes the data described in section 2.4 —IP address, country, language and, once you have given it to us, your email address— and is kept for 12 months
- Security: Detecting, preventing and responding to security incidents, fraud or malicious activity
- Billing and tax obligations: Issuing payment receipts and, where applicable, electronic receipts or invoices for Service charges, and meeting WITHMIA's tax obligations before the Chilean Internal Revenue Service (SII). The processing of billing data is based on compliance with a legal obligation and on performance of the contract, and therefore does not require additional consent
- Legal: Complying with legal and regulatory obligations and with requirements from competent authorities
WITHMIA never sells personal data to third parties. The data in your conversations and contacts is exclusively yours.
4. Data Sharing
WITHMIA may share personal information only in the following circumstances:
- Service providers: Third parties that assist us in operating the Service (hosting, payment processing, email delivery), subject to confidentiality agreements
- Artificial intelligence providers: Conversation messages and knowledge base content are sent to Anthropic (Claude models, used on the Pro, Team and Max plans) and OpenAI (language model for the Inicial plan and embedding generation) for the sole purpose of generating the assistant's responses. Both act as data processors subject to data processing agreements (DPAs) and do not use this data to train their models
- Messaging platforms: Data necessary to deliver messages through WhatsApp Business API, Instagram, Facebook Messenger and other connected channels
- Issuance of tax documents: Billing data (RUT, name or legal name, business activity, address, district) is disclosed to the Chilean Internal Revenue Service (SII) in every electronic receipt or invoice issued, as required by law, and to the authorized electronic invoicing technology provider that acts as data processor for issuing the document
- Legal obligation: When required by law, court order or a competent authority of the Republic of Chile
- Protection of rights: To protect the rights, property or safety of WITHMIA, its users or the public
- Corporate transactions: In the event of a merger, acquisition or sale of assets, with prior notice to affected users
Main providers
| Provider | Purpose | Location |
|---|---|---|
| Railway / PostgreSQL | Infrastructure, hosting and database | United States |
| Flow.cl | Payment processing (Chile, CLP) | Chile |
| dLocal | International payment processing (Latin America) | Uruguay / Global |
| Paddle | International payment processing as Merchant of Record (payment and billing data) | United Kingdom / United States |
| SimpleAPI (Chilesystems) | Issuance of electronic receipts and invoices (DTE) before the SII, as data processor | Chile |
| Meta (WhatsApp/IG/Messenger) | Messaging API | United States |
| OpenAI | AI processing (language models) | United States |
| Anthropic | AI processing (language models) | United States |
| Authentication (Sign-In), Calendar API and Google Meet | United States | |
| Microsoft | Calendar integration (Outlook) | United States |
| Cloudflare | CDN, DNS and website security proxy | United States / Global |
| Google Analytics / Google Ads | Website measurement and advertising (with consent only) | United States |
| Meta Pixel | Website campaign measurement (with consent only) | United States |
Some components of the Service —the omnichannel inbox, the assistant's automations and the vector database that powers the knowledge base (RAG)— run self-hosted within WITHMIA's own infrastructure on Railway, so their operation does not involve transferring data to independent third parties.
La lista siempre vigente de subprocesadores, con el propósito y la ubicación de cada uno, vive en su propia página: withmia.com/subprocesadores.
5. Data Security
We implement technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure or destruction:
- Encryption in transit: All communications are protected with TLS 1.3
- Encryption at rest: Stored data is encrypted with AES-256
- Access control: Federated identity with Google (OAuth 2.0): WITHMIA neither creates nor stores passwords, so there are no credentials that could leak from our systems. Within each account, permissions are assigned by role and every company's data stays isolated from the rest; the WITHMIA team operates on a least-privilege basis
- Auditing: Data access and modification logs with 12-month retention
- Backups: Daily encrypted backups with 30-day retention
- Security testing: Periodic security assessments and audits of the code and infrastructure
- Incidents: Incident response plan with notification to affected users within 72 hours
- Google Verified App: WITHMIA is an app verified by the Google Auth Platform, which certifies the identity and legitimacy of our service to Google and its users
7. User Rights
In accordance with Chile's Law No. 19.628 on the Protection of Private Life, and in preparation for Law No. 21.719 on the Protection of Personal Data (in force since December 2026), you have the following rights:
- Access: Request a copy of the personal data we store about you
- Rectification: Correct inaccurate or incomplete personal data
- Deletion: Request the deletion of your personal data, subject to legal retention obligations
- Portability: Export your data in a structured, machine-readable format (JSON or CSV)
- Objection: Object to the processing of your data for marketing or analytics purposes
- Restriction: Request the restriction of the processing of your data in certain circumstances
- Not to be subject to automated decisions: The right not to be evaluated solely through automated processing that produces significant legal effects
- Revoking Google access: You can revoke WITHMIA's access to your Google account at any time from myaccount.google.com/permissions
To exercise these rights, send an email to [email protected]. We will respond within 15 business days of receiving your request.
8. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy:
- Account data: While the account is active + 30 days after cancellation
- Conversations and messages: According to the workspace's retention settings (configurable)
- AI documents (RAG): Until the user deletes them manually
- Audit logs: 12 months from the date they are recorded
- Billing data: 6 years in accordance with Chilean tax legislation (Tax Code). Data included in receipts and tax documents already issued (RUT, name or legal name, business activity, address) cannot be deleted or rectified retroactively during that period; its processing is limited to archiving and legal compliance purposes
- Technical data: 90 days for access logs, 30 days for sessions
- Funnel analytics (visits, sign-up and payment attempts): 12 months from the date the event was recorded, including the IP address and the email address attached to each event; a daily task automatically deletes anything past that period
- Payment-wall notification list: the email address we record when a payment cannot be completed because your country is not yet covered (section 2.3) is kept for as long as it remains necessary for that single purpose — letting you know when payment becomes available where you are — and is deleted sooner if you object or ask us to delete it. This list is separate from the funnel event log described above and is not removed by that automatic 12-month purge
Once the retention period has elapsed, data is securely and irreversibly deleted from all our systems, including backups.
9. International Transfers
Some of our service providers operate outside Chile, mainly in the United States. When we transfer data outside Chile:
- We make sure providers maintain adequate levels of protection, through European Commission Standard Contractual Clauses (SCCs) and/or the adequacy frameworks in force to which each provider adheres
- We sign data processing agreements (DPAs) with each provider
- We verify that they hold relevant certifications (SOC 2, ISO 27001, PCI-DSS as applicable)
- We implement additional technical measures such as encryption and pseudonymization where appropriate
In particular, artificial intelligence processing (Anthropic and OpenAI), platform hosting (Railway) and the website's content delivery network (Cloudflare) involve transferring data to the United States. These transfers are carried out under data processing agreements (DPAs) signed with each provider which, where applicable, incorporate European Commission Standard Contractual Clauses (SCCs) or rely on the adequacy frameworks in force to which those providers adhere.
10. Users in the European Economic Area and the United Kingdom (GDPR)
If you use the Service from the European Economic Area (EEA) or the United Kingdom, this section applies in addition to the rest of this policy, under the General Data Protection Regulation (GDPR) and its UK equivalent (UK GDPR). The data controller is MIA Marketing & Intelligence Artificial SpA ("WITHMIA"), a company incorporated in Chile, whose contact details appear in the Contact section of this policy.
Lawful bases (Art. 6(1) GDPR)
We process your personal data on the following bases:
- Performance of the contract (Art. 6(1)(b)): providing the platform and its features — processing your messages and conversations, running the AI assistants, scheduling and support
- Legitimate interest (Art. 6(1)(f)): security, fraud and abuse prevention, operational communications about your account, improvement of the Service, and the usage and browsing analytics described in section 2.4 —IP address, country, browser language, entry screens and sign-up and payment steps, and your email address once you have given it to us— which is kept for 12 months
- Consent (Art. 6(1)(a)): marketing communications and non-essential cookies; you can withdraw it at any time without affecting the lawfulness of processing carried out beforehand
- Legal obligation (Art. 6(1)(c)): billing, issuance of tax documents and other legal and tax obligations
Where processing rests on legitimate interest, you can object at any time by writing to [email protected], stating which processing you object to. In the case of the usage and browsing analytics in section 2.4, we will stop associating new events with you and delete those we can link to you through your email address or your account identifier.
Your rights under the GDPR
In addition to the rights described in section 7, if you are in the EEA or the United Kingdom you have the right to:
- Access: obtain confirmation of whether we process your data and a copy of it
- Rectification: correct inaccurate or incomplete data
- Erasure: obtain the erasure of your data, subject to legal retention obligations
- Restriction of processing: restrict processing in certain circumstances
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest or for marketing purposes
- Withdraw consent: at any time, where the processing is based on it
- Automated decisions: not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. WITHMIA's AI assistants generate conversational responses and do not make that type of decision
- Complaint: lodge a complaint with the data protection supervisory authority of your country of residence
To exercise these rights, write to [email protected]. We will respond within a maximum of 30 days from receipt of your request.
International transfers
Your data is processed in Chile and in the United States, where several of our providers operate (see the table in section 4). These transfers are covered by appropriate safeguards: European Commission Standard Contractual Clauses (SCCs) signed with the providers and/or the adequacy frameworks in force to which those providers adhere.
11. Minors
WITHMIA is not directed at persons under 18. We do not knowingly collect personal information from minors. If you become aware that a minor has provided personal data, please contact [email protected] so that we can proceed with its immediate deletion.
12. Modifications to this Policy
WITHMIA reserves the right to update this Privacy Policy to reflect changes in our practices, technology or legal requirements. When we make substantial changes:
- We will notify registered users by email at least 15 days in advance
- We will post a visible notice on the platform
- We will update the "last updated" date at the top of this document
Continued use of the Service after the changes take effect constitutes acceptance of the updated policy.
13. Contact
For questions about this Privacy Policy, to exercise your rights or to report security incidents, you can contact us through:
Data controller: MIA Marketing & Intelligence Artificial SpA
RUT: 78.199.687-4
Privacy email: [email protected]
General email: [email protected]
Website: withmia.com
Location: Antonio Bellet 193, Of. 1210, Providencia, Santiago, Chile