ACL Tecnología SpA · PSI-09 · Version 2.0 · Approved on September 24, 2026
The fundamental purpose of this policy is to establish the strategic guidelines and mandatory directives to ensure the privacy, confidentiality, integrity, availability and resilience of the Personal Data processed by ACL Tecnología SpA (hereinafter "ACL"). This policy applies in full to all employees, contractors, suppliers, agents (mandatarios) and authorized third parties who access, process, store, transmit or delete personal data in the course of the company's operations, regardless of the electronic medium or physical format used. This directive brings together the operational and technical requirements of the Information Security Management System under the international standard ISO/IEC 27001:2022 and the Chilean legal framework on the protection of individuals' private life. Detailed operational management, the day-to-day collection of background information and the specific processing of records and general information are governed, on a complementary basis, by the internal rules and procedures defined by the relevant areas.
ACL ensures that all processing of personal data is strictly grounded in the principles of legality, fairness, transparency, proportionality, purpose limitation and data minimization. In accordance with Article 13 of Ley N° 19.628, no personal data is processed within the company's platforms or services without a valid enabling lawful basis1. These legal bases include the prior, free, informed and specific consent of the data subject; the need to perform commercial or employment contracts and to take pre-contractual measures; compliance with mandatory legal obligations imposed by current legislation; and the pursuit of legitimate corporate interests, such as safeguarding information security, protecting the company's technology infrastructure and preventing potential fraud.
As a general rule, ACL does not disclose or transfer personal data to third parties, except where there is an enabling lawful basis expressly provided for by current legislation. Where the organization uses technology providers, hosting companies, agents (mandatarios) or external service providers that must process personal data on ACL's behalf, the contractual and organizational agreements required by Article 15 bis of Ley N° 19.628 will be formalized. These instruments formally require third parties to apply confidentiality standards and security measures of the same level as those required internally by ACL, restricting the use of the information exclusively to the authorized purposes.
Personal data in ACL's custody is retained only for as long as strictly necessary to fulfill the purposes for which it was collected, with retention and safekeeping periods kept in accordance with the provisions of the Dirección del Trabajo (Chilean Labor Directorate) and applicable law. Once the legally required periods have elapsed or the corresponding obligations have been extinguished, the company proceeds with the deletion, secure destruction or irreversible anonymization2 of the information, in accordance with the data sanitization standards defined within the Information Security Management System.
In compliance with the requirements of the ISO/IEC 27001:2022 standard and Article 14 quinquies of Ley N° 19.628, ACL implements layered technical and organizational security safeguards to protect personal data against unauthorized access, loss, alteration, leakage or any other form of unlawful processing. These measures include rigorous access control management based on the principle of least privilege and mandatory multi-factor authentication for corporate users. The company also applies cryptographic encryption to data both in transit and at rest, as well as masking, pseudonymization3 and anonymization in test environments, complemented by periodic audits to evaluate the effectiveness of technical controls.
ACL guarantees data subjects the timely and barrier-free exercise of the rights recognized by applicable regulations. Data subjects have the right to request information about the origin, purpose and recipients of their data; to demand the rectification of inaccurate, outdated or incomplete information; to request the deletion or cancellation of their data when there is no legal basis for its processing; to object to specific processing based on legitimate interest; to request the blocking or temporary suspension of processing while a dispute is being resolved; to receive a copy of their data in a structured format under the right to data portability; and to withdraw previously granted consent at any time. To submit these requests, data subjects may formally contact the Personal Data Protection Officer through the corporate email address designated for that purpose.
The personal data processed by the company is obtained directly from data subjects when they interact with the company, automatically through the audit logs of ACL's protected systems, or from publicly accessible professional sources (fuentes de acceso público) within the limits provided by law. In its recruitment process, ACL uses a proprietary Artificial Intelligence platform developed in-house, whose design and operation comply with the principles of governance, risk management, non-discrimination and transparency set out in the international standard ISO/IEC 42001:2023 and in personal data protection legislation. This system acts exclusively as a tool to support and optimize analysis, guaranteeing substantial human oversight and intervention (human-in-the-loop) in final hiring or rejection decisions. All specifications regarding the operation, technical scope, algorithmic logic and operating parameters of this Artificial Intelligence solution are formally defined and regulated in the organization's Recruitment Procedure.
Any information security event or breach that compromises the confidentiality, availability or integrity of the personal data processed by the organization will immediately trigger the Incident Response Plan of the Information Security Management System. In compliance with Article 14 sexies of Ley N° 19.628, ACL will carry out the corresponding containment and remediation actions and will promptly notify the competent authority and the affected data subjects when the breach poses a risk to their rights and freedoms.
This policy is formally reviewed at least once a year, or on an extraordinary basis in the event of significant technological changes, operational restructuring or applicable legislative amendments. Each updated version of the document will be officially published indicating its version number and effective date.
Jorge Portus
General Manager
Approved on September 24, 2026
Prepared on September 23, 2026 by Karen Olivares Cornejo, Head of Quality, Security and Compliance
PSI-09 · Version 2.0