1. Who processes your data
Data controller: GEP SOLUTIONS SPA, Chilean tax ID 78.473.733-0, located at LOS MILITARES 5620 OF 905 PS 9 DEPTO. #905 COMUNA LAS CONDES, Chile.
Privacy and data-subject rights contact: contacto@gepsolutions.cl.
2. Scope of this policy
This policy provides a single source of privacy information for GEP Solutions' digital services.
Covers www.gepsolutions.cl, its commercial forms, GEPbot, and GEP Platform. It applies to visitors, commercial contacts, demonstration users, and clients.
Covers GEP Standards, used to document and publish work standards, and GEP Confirmaciones, used to verify work in the field and record results.
GEP Standards and GEP Confirmaciones share one account, workspace, and server. Each organization's workspace data is kept separate.
3. Data we process and why
Corporate website, forms, and GEP Platform
- Identification, contact, role, and organization data that you provide so we can respond to inquiries, arrange demonstrations, and manage commercial relationships.
- Questions and conversations with GEPbot so we can respond and improve service through aggregate analysis.
- Account data, content, and technical information required to operate GEP Platform, manage authorized access, and protect the service.
- Website usage data, only when you accept non-essential cookies, to measure usage and improve the experience.
The contact form uses Cloudflare Turnstile to silently check that submissions come from people rather than automated systems.
When you create a GEP Lean Apps account
| Data | Purpose | Legal basis |
|---|---|---|
| Name and email address | Identify you, verify your email, and invite you to a workspace. | Performance of a contract |
| Password | Authenticate you. It is never stored in plain text; a bcrypt cryptographic hash is stored. | Performance of a contract |
| Optional profile photo | Display your avatar. | Consent |
| Site or facility name | Separate one organization's documents from another's. | Performance of a contract |
When you document work in GEP Standards
- Standard content: titles, steps, key points, reasons, checklists, and decision trees.
- Step photographs.
- Optional asset or equipment location for display on a map.
When you perform a field confirmation
- Confirmation templates and the items to be checked.
- Each item's status—compliant, non-compliant, or not observed—plus comments and optional evidence photographs.
- The identity of the person performing the confirmation, and its date and time.
- Findings and aggregate adherence metrics by area, standard, and dimension.
Offline work, location, and QR codes
When there is no signal, GEP Confirmaciones stores records on the phone and synchronizes them when connectivity returns. Repeating synchronization does not duplicate a confirmation.
The apps may request approximate location only while in use. GEP Standards uses it to show nearby equipment, and GEP Confirmaciones uses it to sort equipment with pending checks. The user's position is used to calculate distance and is not retained on GEP Solutions' servers; in GEP Confirmaciones, the calculation takes place on the phone. The location that may be saved belongs to the equipment, not the user.
The public QR viewer records an anonymous view count: no account is required and the viewer's identity is not stored.
GEP Solutions does not sell personal data or use it for purposes incompatible with those disclosed.
4. Artificial intelligence assistant
When you use the GEP Standards assistant to structure a standard, the text you dictate or type is sent to OpenAI for processing. Your account information is not sent.
Any workspace member may enable the AI opt-out. While it is active, no content from that workspace is sent to the provider. The assistant is designed to turn technical information that the user did not supply into questions instead of filling it in.
GEP Confirmaciones does not use this assistant. Its templates come from human-authored key points or are written manually, and confirmation content is not sent to an AI provider.
5. Who we share data with
We do not sell personal data or disclose it for advertising. Depending on the service used, our technology providers act as data processors:
| Provider | Purpose | Location |
|---|---|---|
| Render | Application servers. | United States |
| Neon | Database. | United States |
| Cloudflare | Website security, Turnstile, and storage and delivery of published standards, photographs, and evidence. | Global network |
| Brevo | Email confirmation, password recovery, and invitations. | European Union |
| OpenAI | Standards creation assistant, only when used and not disabled. | United States |
| Website measurement when cookies are accepted, and maps on Android. | United States | |
| Apple | Maps on iPhone. Apple does not receive data from our servers for this feature. | According to its service |
| Sentry | Error detection using technical messages and traces; it does not receive request content or account data. | United States |
Some providers process data outside Chile. These transfers are made subject to the applicable contractual safeguards.
6. Published standards are publicly accessible
Publishing a standard creates a QR code so it can be viewed without an account or app. The standard and its photographs therefore become available online through a web address.
- The address contains a random 12-character identifier designed to be impractical to guess.
- It is not password protected: anyone with the link can view it.
- Only content that you choose to publish is exposed; drafts remain in your workspace.
Confirmations, their results, findings, comments, and evidence photographs are not public. They are visible only to workspace members; images are delivered through signed links that expire after one hour.
7. How long we retain data
| Data | Retention period |
|---|---|
| Account, standards, and templates | While the account exists. |
| Confirmations, responses, findings, and checklist runs | 90 days, then automatically deleted. |
| Previous versions of a standard | The latest three are retained on the free plan. |
| Password recovery links | 30 minutes and one use. |
| Email confirmation links | 48 hours. |
The purge runs daily. Only a cryptographic hash of recovery and confirmation links is stored in the database, never the link itself.
8. Your rights
You may request access, rectification, erasure, objection, blocking, and portability where applicable under the relevant regulations. Send requests to contacto@gepsolutions.cl; we will respond within the statutory time limits.
Deleting an account also deletes its associated data. Account deletion is currently handled by email request; the apps do not yet include an account-deletion button.
contacto@gepsolutions.cl
9. Security
- Traffic is encrypted with TLS.
- Passwords are stored with bcrypt, never in plain text.
- Recovery and confirmation links are stored as cryptographic hashes.
- Workspaces are isolated and their identity is verified on every request.
- A resource from another workspace returns as nonexistent so its existence is not disclosed.
No system is infallible. If a breach presents a reasonable risk to people's rights and freedoms, it will be reported to the authority by the most expeditious means and without undue delay. Affected people will be informed where there is a high risk, in accordance with applicable law.
10. Children
GEP Standards and GEP Confirmaciones are workplace tools and are not directed at children under 14.
11. Changes to this policy
When this policy changes, we will publish the new version and its date. Material changes affecting GEP Standards or GEP Confirmaciones will also be communicated within the applications.
Last updated: September 2, 2026.