Data Protection Policy
This Privacy Policy describes how Gauss Control collects, processes, stores, discloses, and protects personal data processed in connection with the provision of its services and the use of its technology platforms.
This document contains relevant information regarding the categories of personal data processed by Gauss Control, the purposes for which such data is used, the applicable legal bases for processing, the recipients of personal data, the security measures implemented, the rights of data subjects, and the mechanisms available to exercise those rights.
Gauss Control makes this Privacy Policy permanently available to data subjects in order to ensure transparent and informed processing, in accordance with applicable personal data protection laws.
Title I. Nature and Scope of Application
Article 1. General Considerations
Desert Point SpA (“Gauss Control”), Tax ID No. 76.274.794-4, with registered address at Rosario Norte 532, Office 202, Las Condes, Santiago, legally represented by Lorena Oliver.
For inquiries related to this Privacy Policy or to the processing of personal data carried out by Gauss Control, data subjects may contact us at pd@gausscontrol.com.
Gauss Control is a company dedicated to the development and provision of technology solutions, Software as a Service (SaaS) platforms, monitoring systems, and predictive models focused on operational risk management, fatigue prevention, and the promotion of safety for workers and other users of its clients.
This Personal Data Protection Policy is intended to establish the principles, guidelines, and procedures applicable to the processing of personal data carried out by Gauss Control, as well as the measures designed to ensure the protection of the rights and freedoms of data subjects, in accordance with Article 19 No. 4 of the Political Constitution of the Republic of Chile, Law No. 19,628 on the Protection of Personal Data, as amended by Law No. 21,719, and all other applicable regulations (hereinafter, the “Data Protection Law”).
Article 2. Territorial Scope of Application.
The provisions of this Policy shall apply to the processing of personal data where the data controller or authorized processor is established or incorporated within Chilean territory. They shall also apply where the data controller is not located in Chile, but its operations are intended to provide services to data subjects in the country or to monitor, track, and make predictions regarding their behavior.
For these purposes, it shall be sufficient for the data controller or the third party acting as an authorized processor or data processor to be established or incorporated in Chile for the Data Protection Law to apply, regardless of the location of the personal data subject or the place of establishment of the respective data controller. Accordingly, any processing of personal data carried out by Gauss Control in Chile in its capacity as a third-party authorized processor or data processor shall be subject to the provisions of this Policy and the Data Protection Law, even where the data subjects are located outside Chilean territory, without prejudice to any personal data protection regulations that may also apply in the jurisdiction in which such data subjects are located.
Article 3. Definitions.
For the proper application of this Policy, the following terms shall have the meanings set forth below:
“Personal Data”: Any information linked or relating to an identified or identifiable natural person. A person shall be considered identifiable when their identity can be determined, directly or indirectly, through one or more identifiers, such as their name, national identity card number, or through the analysis of elements specific to their physical, physiological, genetic, psychological, economic, cultural, or social identity.
“Sensitive Personal Data”: Personal data relating to the physical or personal characteristics of individuals, or to facts or circumstances concerning their private or intimate life, which reveal their ethnic or racial origin, political affiliation, trade union or professional association membership, socioeconomic status, ideological or philosophical beliefs, religious beliefs, health-related data, human biological profile, biometric data, and information concerning a natural person’s sex life, sexual orientation, or gender identity.
“Consent”: Any freely given, specific, unambiguous, and informed indication of will, provided through a statement or clear affirmative action, by which the data subject, their legal representative, or authorized agent, as applicable, authorizes the processing of personal data concerning them.
“Data Controller”: Any natural or legal person, whether public or private, that determines the purposes and means of the processing of personal data, regardless of whether such data is processed directly by that person or through a third-party agent or processor.
“Third-Party Agent or Processor”: Any natural or legal person that processes personal data on behalf of and under the instructions of the Data Controller.
“Anonymization”: An irreversible process whereby personal data can no longer be linked or associated with a specific individual, nor allow that individual to be identified, because the connection with the information that links, associates, or identifies that person has been destroyed or removed. Anonymized data shall no longer be considered personal data.
“Pseudonymization”: The processing of personal data in such a manner that the data can no longer be attributed to a data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures designed to ensure that the personal data is not attributed to an identified or identifiable natural person.
“Data Subject”: An identified or identifiable natural person to whom the personal data relates or refers.
“Data Processing”: Any operation or set of operations or technical procedures, whether automated or not, that enable the collection, processing, storage, communication, transmission, or use of personal data or sets of personal data in any manner.
Article 4. Categories of Data Processed.
In the course of its activities and the provision of its technology services, Gauss Control may collect and process the following categories of data:
(a) Identification and contact data, such as name, national identity card number, job title, company affiliation, email address, telephone number, and any other information necessary for the provision of the services.
(b) Biometric data.
(c) Data relating to the human biological profile.
(d) Derived or inferred data, including alerts, reports, metrics, profiles, and indicators generated through the automated processing of information using analytical tools, predictive models, or artificial intelligence systems.
(e) Technical and platform usage data, including IP addresses, device identifiers, access records, security events, activity logs, browsing information, and any other technical information generated through the use of Gauss Control’s platforms and technology solutions.
The collection and processing of these categories of data shall be limited to information that is adequate, relevant, and strictly necessary for the purposes that justify such processing.
Article 5. Purposes of Processing
The purposes described in this Article correspond to the processing activities carried out by Gauss Control in its capacity as Data Controller, including the following:
(a) To develop, operate, maintain, and provide the technology solutions, platforms, and services offered by Gauss Control to its clients.
(b) To manage its commercial, contractual, and employment relationships with its clients, suppliers, and employees.
(c) To comply with legal, regulatory, contractual, or other obligations applicable to Gauss Control.
(d) Geolocation data
When Gauss Control acts as a third-party agent or Data Processor on behalf of its clients, the purposes of the processing shall be those defined by the respective Data Controller. By way of illustration, such purposes commonly include monitoring and assessing variables associated with alertness, fatigue, drowsiness, distraction, and other operational risk factors through the capture and processing of driver images and/or the performance of psychomotor tests, with the aim of contributing to accident prevention and promoting safe working conditions, as well as generating alerts, reports, indicators, and analyses intended to support such clients’ risk management, operational safety, and decision-making processes.
Article 6. Personal Data Subjects and Recipients.
The following identifies the data subjects whose personal data may be processed by Gauss Control and the third-party recipients to whom such data may be disclosed.
(a) Personal Data Subjects. In the course of its activities and the provision of its services, Gauss Control may process personal data relating to the following categories of data subjects: (i) natural persons and representatives, employees, contractors, and other individuals associated with corporate clients; (ii) authorized users of the platforms and technology solutions developed by Gauss Control; (iii) drivers, operators, and other individuals subject to monitoring through the solutions and services provided by Gauss Control on behalf of its clients; and (iv) third parties, pedestrians, and external drivers incidentally captured through front-facing cameras (dashcams) and ADAS (Advanced Driver Assistance Systems). Gauss Alert records the vehicle’s surroundings and detects events such as “forward collision risk” and even “pedestrian collision.” Accordingly, the system inevitably processes images of third parties in public spaces who have no contractual relationship with Gauss Control or its clients.
(b) (v) Unidentified or Unauthorized Individuals Behind the Wheel: The Driver Identification System (IDC), using facial recognition technology, captures images each time a vehicle is started (ignitionOn). If the detected face does not match the company’s database, the system generates a record or registers an “anonymous deviation.” The data subject associated with this biometric data is therefore present within the platform, even if their identity is unknown.
(c) (vi) Technical Contacts, Installers, and Field Support Personnel: Operational databases maintain records of interventions performed on physical devices, including the full name, telephone number, and email address of individuals providing field support or installation services.
(d) Recipients of Personal Data. Personal data processed by Gauss Control may be disclosed or made available to third parties only where there is a sufficient lawful basis and where such disclosure is necessary to fulfill the purposes that justify the processing. In particular, personal data may be disclosed to: (i) Gauss Control’s clients, when Gauss Control acts as a third-party agent or Data Processor; (ii) related companies and subsidiaries, where necessary for the provision of services or for legitimate internal administrative purposes; (iii) administrative or judicial authorities, or any other competent public authority, where required by law, regulation, or a valid legal order; and (iv) any other person or entity where the data subject has provided authorization or where another lawful basis exists under the Data Protection Law.
Under no circumstances shall personal data be sold, commercially exploited, or disclosed to third parties for purposes incompatible with those that justified its collection.
The foregoing is without prejudice to the possibility that, in the context of a merger, acquisition, consolidation, divestiture, or other corporate reorganization involving Gauss Control, personal data may be disclosed or transferred to the resulting entity or to advisors participating in such process, subject to the applicable confidentiality and security measures, and provided that such entity continues to comply with the purposes and conditions communicated to data subjects under this Policy.
Article 7. International Transfers of Personal Data.
For the provision of its services, Gauss Control may engage technology providers, storage services, cloud infrastructure, support, monitoring, security, and analytics tools, as well as other third parties that may be located outside Chile or that may enable remote access to personal data from abroad.
In this context, certain personal data processing activities may involve international transfers of personal data, including its storage, processing, remote access, disclosure, or making such data available from or to jurisdictions other than Chile.
For the purposes of this Policy, international transfers include both the disclosure or storage of personal data abroad and remote access from abroad to personal data stored in Chile by technology providers, affiliated companies, data processors, or authorized third parties involved in the provision of Gauss Control’s services.
Where applicable, such international transfers shall be carried out in accordance with applicable personal data protection laws and on the basis of the authorizations, lawful grounds, or enabling legal mechanisms applicable in each case, including, where appropriate, adequacy decisions, contractual clauses, binding corporate instruments, or other mechanisms recognized under applicable law.
Gauss Control shall endeavor to ensure that third parties involved in the processing of personal data are subject to appropriate confidentiality, security, and personal data protection obligations consistent with the nature of the data processed and the risks associated with such processing.
The lawfulness of an international transfer of personal data is independent from the lawfulness of the processing of the data being transferred. Accordingly, in the case of sensitive or biometric data, having a lawful basis for its processing pursuant to Article 13 does not exempt Gauss Control from additionally complying with the specific requirements applicable to international transfers set forth in this Article. Likewise, compliance with such international transfer requirements does not exempt Gauss Control from having a lawful basis for processing such data. The data subject’s consent is not the only mechanism that may authorize an international transfer of sensitive or biometric data: such transfer may also be based on an adequacy decision, contractual clauses, binding corporate rules, or any other instrument recognized by the Data Protection Law that provides appropriate safeguards. Consent shall remain an exceptional mechanism applicable to specific and non-routine transfers where such safeguards are unavailable.
Google Cloud Platform (GCP) – Google LLC: Gauss Control’s primary cloud infrastructure provider. Location: Data is primarily hosted and processed on servers located in the United States (us-central1).
Amazon Web Services (AWS) – Amazon.com, Inc.: Secondary cloud infrastructure used for object storage through Amazon S3. Storage buckets are hosted in the United States region (us-east-1).
MongoDB Atlas – MongoDB Inc.: Fully managed cloud-based NoSQL database platform. It stores historical configurations of IoT devices.
Auth0 (Okta, Inc.): Identity-as-a-Service provider used for secure authentication, user access control, and token generation (JWT).
Artificial Intelligence and Monitoring Providers: Specialized cloud platforms provided by hardware vendors.
Article 8. Processing of Personal Data on Behalf of Third Parties.
When Gauss Control acts as a third-party agent or Data Processor on behalf of its clients or other Data Controllers, personal data shall be processed exclusively for the purposes defined by the respective Data Controller and in accordance with the documented instructions provided by such Controller, the contracts, data processing addenda, or equivalent agreements entered into between the parties, and applicable law.
In such cases, Gauss Control shall not use personal data for its own purposes where such purposes are incompatible with the instructions received, nor shall it carry out processing activities other than those necessary for the performance of the contracted services or those expressly authorized by the respective Data Controller.
Notwithstanding the foregoing, Gauss Control may use data processed on behalf of its clients to develop, train, test, or improve its predictive models and other technology tools, provided that such data has first been anonymized or, where anonymization is not possible due to the nature of the processing, where there is a prior agreement with the respective Data Controller and, in the case of sensitive or biometric data, the consent of the data subject or another applicable lawful basis under the Data Protection Law.
The specific conditions applicable to each processing activity, including processing instructions, security measures, the use of service providers or sub-processors, international transfers, retention periods, return, deletion, blocking, or anonymization of personal data, and any other specific obligations associated with the engagement, shall be governed by the contracts, data processing addenda, or equivalent agreements entered into with the respective Data Controller, without prejudice to compliance with the obligations established under the Data Protection Law.
Where applicable, data subjects should contact the respective Data Controller to obtain information regarding the specific conditions applicable to the processing of their personal data, without prejudice to any rights they may exercise directly against Gauss Control in the circumstances provided for under applicable law.
Each Data Controller shall be responsible for obtaining and demonstrating to Gauss Control the authorizations, consents, and other lawful bases required for the processing of the personal data entrusted to Gauss Control, as well as for complying with its own obligations as a Data Controller under the Data Protection Law, including, among others, making its respective personal data processing policy available to data subjects, duly informing them of the purposes and conditions of the processing, and responding to the exercise of their rights. Gauss Control may contractually require its clients to provide evidence of compliance with these obligations.
Article 9. Personal Data of Minors.
In the exceptional event that Gauss Control’s solutions or services involve the processing of personal data of minors, such processing shall be carried out in accordance with the specific requirements and safeguards established under the Data Protection Law and other applicable regulations.
En caso de que, de forma excepcional, las soluciones o servicios de Gauss Control involucren el tratamiento de datos personales de menores de edad, dicho tratamiento deberá realizarse de conformidad con las exigencias y salvaguardas especiales establecidas por la Ley de Datos y demás normativa aplicable.
If Gauss Control becomes aware that it has collected personal data of minors in violation of applicable regulations, it shall take reasonable measures to delete, block, or otherwise regularize such data in accordance with applicable law.
Article 10. Applicability of this Policy.
Given the nature of the services provided, Gauss Control may act, depending on the specific context and the nature of the processing carried out, either as a Data Controller or as a third-party agent or Data Processor, as provided under the Data Protection Law:
(a) Gauss Control as Data Controller. Gauss Control shall act as Data Controller with respect to personal data that it processes directly for the management of its commercial, contractual, employment, and operational relationships, including, among others, data relating to its employees, clients, suppliers, platform users, website visitors, and other third parties with whom it maintains a direct relationship.
(b) Gauss Control as Third-Party Agent or Data Processor. Gauss Control shall act as a third-party agent or Data Processor with respect to the personal data of drivers, operators, workers, authorized users, and other individuals whose data is processed through the technology solutions, platforms, monitoring systems, and predictive models provided by the company to its clients, where such processing is carried out exclusively on their behalf, in accordance with their instructions, and for the purposes determined by them, in which case such clients shall act as Data Controllers.
The purposes and lawful bases described in this Policy shall apply solely to processing activities in which Gauss Control acts as Data Controller.
Notwithstanding the foregoing, where contracts, data processing addenda, or other specific agreements entered into between Gauss Control and its clients, suppliers, or employees specifically regulate the processing of personal data, such instruments shall prevail over this Policy with respect to the matters expressly governed therein. This Policy shall apply on a supplementary basis to any matters not expressly addressed in the relevant agreements.
Title II. Guiding Principles
Title II. Guiding Principles
Article 11. Data Processing Principles.
In the processing of personal data, Gauss Control shall at all times observe the principles established under the Data Protection Law, which shall guide the design, implementation, and execution of all processing activities carried out by the company, whether acting as Data Controller or as a third-party agent or Data Processor.
- Lawfulness and Fairness: Personal data shall be processed only on the basis of a valid lawful basis and through transparent procedures consistent with the reasonable expectations of data subjects. Gauss Control shall identify, demonstrate, and communicate the lawful basis applicable to each processing activity.
- Purpose Limitation: Personal data shall be collected and processed for specified, explicit, and lawful purposes and shall not subsequently be used for purposes incompatible with those that justified its collection.
- Proportionality: The processing of personal data shall be limited to data that is adequate, relevant, and strictly necessary to fulfill the purposes that justify its processing. Personal data shall also be retained only for as long as necessary to fulfill such purposes or for the period required under applicable law.
- Data Quality: Gauss Control shall adopt reasonable measures to ensure that personal data is accurate, complete, relevant, and kept up to date, allowing for its rectification or updating where appropriate.
- Accountability: Gauss Control shall be responsible for compliance with personal data protection laws and shall adopt the necessary measures to ensure and demonstrate compliance with the principles and obligations established by law.
- Security: Gauss Control shall implement appropriate measures, taking into account the nature of the data processed and the risks associated with such processing, in order to protect personal data against unauthorized access, loss, alteration, destruction, disclosure, or any other form of unlawful or improper processing.
- Transparency and Information: Data subjects shall have access to clear, accurate, up-to-date, and readily accessible information regarding the conditions under which their personal data is processed, as well as the rights granted to them by law and the mechanisms available to exercise those rights.
- Confidentiality: All persons who, by virtue of their duties or a contractual relationship with Gauss Control, have access to personal data shall be subject to a duty of confidentiality and secrecy with respect to such information. This obligation shall remain in effect even after the termination of the corresponding employment, contractual, or commercial relationship.
Title III. Lawfulness and Processing of Sensitive Data
Artículo 12. Regla General de Licitud.
Gauss Control shall process personal data only where there is a valid lawful basis under the Data Protection Law. Such processing may be based, among other grounds, on the data subject’s freely given, prior, specific, unambiguous, and informed consent; the necessity to perform or fulfill a contract; compliance with legal obligations; the pursuit of legitimate interests of the Data Controller or third parties, provided that such interests are not overridden by the fundamental rights and freedoms of the data subject; the establishment, exercise, or defense of legal rights or claims; and any other grounds provided for by law.
Where processing requires the data subject’s consent, such consent shall be obtained and documented in accordance with the requirements of applicable law. When Gauss Control acts as a third-party agent or Data Processor on behalf of its clients, the respective Data Controller shall be responsible for ensuring the existence of a sufficient lawful basis for the processing of personal data and, where applicable, for obtaining the corresponding consent.
In the case of processing activities involving the capture of images or other biometric data of employees within the context of an employment relationship, consent shall generally not constitute an appropriate lawful basis, given the relationship of dependency between the employee and the employer. In such cases, the respective Data Controller shall base the processing on legitimate interests, subject to a proportionality assessment, and regulate such processing in accordance with applicable labor laws, including its incorporation into the Internal Regulations on Order, Hygiene, and Safety where appropriate. Gauss Control relies on the respective Data Controller to carry out such assessment and implement the corresponding employment-related regulations.
In the course of its activities, Gauss Control shall endeavor to ensure that data processing activities are limited to what is strictly necessary to fulfill the stated purposes and are carried out in accordance with the principles established under the Data Protection Law.
Where processing is based on the data subject’s consent, such consent may be withdrawn at any time, without affecting the lawfulness of any processing carried out prior to such withdrawal.
Article 13. Sensitive and Biometric Data.
In connection with the provision of its technology services, Gauss Control may process special categories of personal data, including biometric data and data relating to the human biological profile, as defined in Article 4.
Sensitive personal data shall be processed only where there is a valid lawful basis and the specific requirements established under the Data Protection Law are satisfied. In all cases, Gauss Control shall implement enhanced security measures and limit the processing to what is strictly necessary for the legitimate purposes that justify it.
When Gauss Control acts on behalf of its clients as a third-party agent or Data Processor, the respective Data Controller shall be responsible for ensuring the existence of a sufficient lawful basis for the processing of such sensitive data and, where required, for obtaining and demonstrating the data subject’s express consent. Notwithstanding the foregoing, Gauss Control may contractually require its clients to provide evidence of compliance with applicable legal obligations and to provide the instructions necessary for the processing of this category of data.
Access to sensitive and biometric data shall be restricted exclusively to authorized personnel and service providers who require access to such data in order to perform their duties. The processing of such data for purposes incompatible with those that justified its collection is prohibited.
Without prejudice to the general rules on retention, deletion, and blocking established in Article 14, where sensitive and biometric data is processed on behalf of a client, such data shall remain subject to the instructions of the respective Data Controller, and Gauss Control shall delete or return it in accordance with the terms set forth therein.
Article 14. Retention, Storage, and Deletion of Personal Data.
Gauss Control shall retain personal data only for as long as necessary to fulfill the purposes that justified its collection and processing, or for the period required to comply with legal, regulatory, contractual, security, audit, traceability, legal defense, or competent authority requirements.
Once such purposes have been fulfilled or the applicable retention periods have expired, personal data shall be deleted, anonymized, or blocked, as appropriate, in accordance with the Data Protection Law and Gauss Control’s internal information lifecycle management policies.
Upon termination of the contractual relationship with the respective Data Controller, Gauss Control shall delete or return the personal data processed on its behalf, as provided in the applicable contract, data processing addendum, or equivalent agreement. Notwithstanding the foregoing, Gauss Control may retain such data in a blocked state and without operational access for the minimum period necessary for the establishment, exercise, or defense of legal claims or to comply with legal or contractual obligations.
When Gauss Control acts as a third-party agent or Data Processor on behalf of its clients, the retention, return, deletion, anonymization, or blocking of personal data shall be carried out in accordance with the instructions of the respective Data Controller, the applicable contracts, and applicable law.
Title IV. Rights of Data Subjects
Article 15. Guaranteed Rights.
Every data subject, acting personally or through a duly authorized representative, has the right to exercise, free of charge and under the terms established by law, the rights granted by applicable regulations in connection with the processing of their personal data.
In particular, data subjects shall have the following rights:
- Right of Access: To request and obtain information regarding the personal data concerning them that is being processed, its source, the purposes of the processing, the categories of recipients, the expected retention period, and any other information required by law.
- Right to Rectification: To request the correction, updating, or completion of personal data that is inaccurate, incomplete, or outdated.
- Right to Erasure: To request the deletion of personal data where its processing lacks a lawful basis, where the data is no longer necessary for the purposes that justified its collection, or where any other circumstance provided for by law applies.
- Right to Object: To object to the processing of personal data in the circumstances provided for by law, particularly where such processing is based on legitimate interests or is carried out for direct marketing purposes.
- Right to Data Portability: To request and receive a copy of their personal data in a structured, commonly used, and generic electronic format, and to request its disclosure or transfer to another Data Controller, where applicable.
- Right to Restriction: To request the temporary suspension of certain processing activities involving their personal data, in the circumstances established by law.
- Right to Object to Automated Individual Decision-Making: The data subject shall have the right not to be subject to a decision based solely on the automated processing of their personal data, including profiling, where such decision produces legal effects concerning them or significantly affects them. The data subject may also request information regarding the general criteria used, express their point of view, and request human intervention where applicable.
Gauss Control shall adopt the necessary measures to facilitate the effective exercise of these rights and to respond in a timely manner to requests submitted by data subjects, in accordance with applicable regulations.
If Gauss Control rejects a request or fails to respond within the statutory time limits, the data subject may file a claim with the Personal Data Protection Agency in accordance with the procedure established by law.
Title V. Procedure for Exercising Rights
Article 16. Communication Channels and Response Times.
To exercise any of their rights, the data subject must submit a detailed request to pd@gausscontrol.com.
Gauss Control shall acknowledge receipt of the request and provide a response within the maximum period established under the Data Protection Law. Where circumstances justify an extension of the response period, such period may be extended in accordance with applicable law, and the data subject shall be duly informed of such extension.
The exercise of the rights of access, rectification, erasure, objection, restriction, and data portability shall always be free of charge for the data subject.
Title VI. Security, Privacy by Design, and Incidents
Article 17. Privacy by Design and by Default.
Gauss Control shall implement appropriate technical and organizational measures from the design stage and throughout the processing lifecycle to ensure that, by default, only the specific personal data strictly necessary for the relevant processing activity is processed.
Gauss Control shall apply these criteria taking into account the nature of the data processed, the risks associated with the processing, the functionalities of its platforms, the instructions provided by its clients when acting as a Data Processor, and its internal information security policies.
|
Article 18. Security Measures.
Gauss Control shall implement reasonable and appropriate technical, organizational, and administrative measures to protect personal data against unauthorized access, loss, alteration, disclosure, destruction, or any other form of unlawful or improper processing.
Such measures shall be defined taking into account the nature of the personal data processed, the categories of data subjects involved, the risks associated with the processing, the state of the art, Gauss Control’s internal information security policies, and the requirements established under applicable law.
Such measures may include, as appropriate, access controls, authentication mechanisms, profile and permission management, contractual confidentiality obligations, traceability, backups, encryption, pseudonymization, monitoring, information classification, incident management, and other reasonable security measures.
Article 19. Security Incidents and Breaches.
In the event of security incidents or breaches affecting personal data, Gauss Control shall implement the appropriate containment, analysis, mitigation, documentation, and response measures in accordance with the Data Protection Law and its internal procedures.
Where a security breach must be reported pursuant to applicable law, Gauss Control shall make the required notifications to the Personal Data Protection Agency and, where applicable, to the affected data subjects, within the time limits and in the manner established under the Data Protection Law.
When Gauss Control acts as a third-party agent or Data Processor, it shall notify the respective Data Controller of any incidents or breaches affecting personal data processed on its behalf, so that the appropriate measures and notifications may be undertaken in accordance with applicable law and the relevant agreements.
Title VII. Effective Date and Amendments.
Article 20. Term and Amendments.
This Privacy Policy shall remain in effect indefinitely from its effective date, without prejudice to any updates that Gauss Control may make in accordance with the provisions set forth below.
Version: [1]
Effective Date: [27/07/2026]
Last Updated: [27/07/2026]
Gauss Control may amend this Privacy Policy to reflect legal, regulatory, operational, or technological changes. The current version shall remain permanently available through the channels made available by the company for this purpose.