Balance — Chile Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Chilean resident covered by this Annex. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) the entry into force of Ley 21.719 (Ley que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales, scheduled for December 2026 per its 24-month vacatio legis from publication in the Diario Oficial on 13 December 2024) — at which point §§ 2, 3, 4, 6, 7, 8, and 11 of this Annex must be rewritten to reflect the new regime, (b) any reglamento, circular, or instrucción of the Agencia de Protección de Datos Personales ("APDP") issued upon or after its constitution under Ley 21.719, (c) any amendment to Ley 19.628 sobre Protección de la Vida Privada prior to its repeal-and-replacement by Ley 21.719, (d) any amendment to Ley 21.430 sobre Garantías y Protección Integral de los Derechos de la Niñez y Adolescencia, (e) any amendment to Ley 19.496 sobre Protección de los Derechos de los Consumidores (the CPL) or its Reglamento or any Circular Interpretativa issued by the Servicio Nacional del Consumidor ("SERNAC") that materially alters the operational rules below, (f) any amendment to Ley 21.459 (the cybercrimes statute that replaced Ley 19.223) or to Ley 20.526 (online-grooming amendment to the Código Penal), (g) any decision of the Tribunal Constitucional or the Corte Suprema that materially changes the constitutional or statutory interpretation of Art 19 N°4 of the Constitución Política de la República ("CN") or of Ley 19.628 / Ley 21.719, (h) any change to a sub-processor's Chile data-handling posture under our sub-processor register, or (i) Chile securing an EU adequacy decision under GDPR Art 45 (none in force at the Effective date) or ratifying Convention 108+ (signed by Chile on 10 October 2023; ratification pending at the Effective date). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Chile row).
- Children's Privacy Notice § 14 (Country annexes — Chile row).
- Child Safety Standards § 13 (Country annexes — Chile row).
- Terms of Service § 19 (Chile consumer-protection carve-out under Ley 19.496).
- Subscription Terms § 20 (Chile consumer-rights overlay — Art 3 ter right of retraction; Ley 21.398 Pro-Consumidor overlays).
- Data Retention & Deletion Policy § 14 (Chile complaint route — courts under Ley 19.628 habeas data civil procedure pre-Dec-2026; APDP from Dec-2026).
- our breach-notification runbook § 9 (Chile breach-notification posture — no statutory breach-notification regime under Ley 19.628; the regime begins on the entry into force of Ley 21.719 in December 2026).
- our international-transfer pack § 6 (Ley 19.628 international-transfer treatment — consent-based at the Effective date — and the Ley 21.719 transfer regime that will replace it).
This Annex is the canonical Chile-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Chilean resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Chilean resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The authoritative Spanish-language version is republished at Chile annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Chilean residents.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Chile ("Chile"), without distinction between the 16 regiones (including the Región Metropolitana de Santiago) and any comuna within them.
We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Chile as the country of residence, this Annex applies, even if the other signals are non-Chilean. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
Both the current Ley 19.628 (Art 1, as in force at the Effective date) and the future Ley 21.719 (Art 1, entering into force in December 2026) have extraterritorial effect that reaches a foreign controller targeting Chilean residents. Balance squarely targets Chilean residents through Google Play and through publication of this Annex at balance.babayagaprogram.com. Ley 21.719 Art 1(b) in particular extends the territorial scope to controllers established outside Chile that offer goods or services to data subjects located in Chile, or that monitor their behaviour to the extent that such behaviour takes place in Chile (the GDPR-Art-3(2)-aligned scope clause).
2. Statutory framework — what applies (the dual-regime cutover)
The Chilean data-protection regime is in the middle of a generational rewrite. At the Effective date (9 June 2026), the principal personal-data statute is Ley 19.628 sobre Protección de la Vida Privada of 1999, as amended. Six months later, on the entry into force of Ley 21.719 in December 2026, Ley 19.628 is repealed and replaced by a GDPR-aligned regime that creates the Agencia de Protección de Datos Personales ("APDP") as Chile's first autonomous data-protection authority. This Annex addresses both regimes — the regime in force at the Effective date and the regime that will take its place in December 2026 — so that Balance's posture is correct on day one of Ley 21.719 as well.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitución Política de la República de Chile | CN, Decreto Supremo N° 100 of 2005 Texto Refundido, as amended; Art 19 N°4 (right to respect and protection of private life, the honour of the person and the family, and the protection of personal data, as elevated to constitutional rank by Ley 21.096 of 16 June 2018); Art 19 N°5 (inviolability of the home and of every form of private communication); Art 20 (recurso de protección — the constitutional protection remedy) | The constitutional anchor for the personal-data-protection regime. Ley 21.096 inserted the express "y la protección de sus datos personales" clause into Art 19 N°4 in 2018, giving personal-data protection constitutional rank and opening the recurso de protección under Art 20 to data-protection claims. | Applies in full as the foundational constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Ley 19.628 sobre Protección de la Vida Privada | Ley 19.628 of 28 August 1999, as amended (notably by Ley 19.812 of 2002, Ley 20.575 of 2012 — "Ley Dicom", and Ley 20.521 — adolescent civic data); supplemented by Decreto Supremo 779/2000 (regulation on the public-sector registry of databanks). | The current personal-data-protection regime: definitions (Art 2); consent + statutory carve-outs as lawful bases (Arts 4, 7, 10, 20); access, rectification, cancellation, and opposition rights — the four classical "ARCO" rights (Arts 12, 13, 14, 15, 16); habeas data civil procedure in the Juzgados de Letras en lo Civil (Arts 16, 17); international transfer is unregulated (no specific transfer-mechanism article — transfers proceed on the data-subject's consent or statutory carve-out); the supervisory-authority gap (no autonomous DPA — supervision is by the courts via habeas data and, in the public sector, by the Consejo para la Transparencia via Ley 20.285 on access to public information). | Applies in full at the Effective date and until 12 December 2026. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below, with dual-regime notes indicating where the operational rule changes on the entry into force of Ley 21.719. |
| Ley 21.719 — Ley que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales | Ley 21.719 of 13 December 2024 (Diario Oficial 13 December 2024); 24-month vacatio legis per its transitional article — enters into force in December 2026. | The new comprehensive GDPR-aligned data-protection regime: GDPR-aligned definitions (controller, processor, data subject, personal data, special category data); a six-lawful-bases regime aligned with GDPR Art 6 (consent, contract, legal obligation, vital interests, public-interest task, legitimate interests); a full rights catalogue including portability and objection; a children's-data regime that requires the holder of parental responsibility's consent for the processing of data of children under 14, with the adolescent's own informed assent layered in for 14–17 (Ley 21.719 Arts 16-bis et seq.); a mandatory DPO for high-risk controllers (Encargado de Prevención equivalent); a mandatory DPIA for high-risk processing; an international-transfer regime with adequacy decisions, Cláusulas Tipo (Chilean SCCs to be issued by the APDP), BCRs, certifications, and codes of conduct; a breach-notification obligation (with a benchmark broadly aligned with the GDPR 72-hour rule); an administrative-fine regime calibrated by reference to gravity and turnover; and the creation of the Agencia de Protección de Datos Personales (APDP) as the supervisory authority. | NOT in force at the Effective date. Comes into force in December 2026. From that moment, the rules in §§ 3, 4, 6, 7, 8, and 11 of this Annex will be rewritten to reflect the new regime. Balance is already operationally GDPR-aligned (cross-reference: EU / EEA annex § 6 + § 8) so the substantive posture below already anticipates Ley 21.719; the regulatory cites are the only thing that change on day one. |
| Ley 21.096 | Reforma constitucional que consagra el derecho a la protección de los datos personales of 16 June 2018 | Amended CN Art 19 N°4 to elevate personal-data protection to constitutional rank. | Applies as the foundational constitutional layer (see § 3 below). |
| Ley 21.430 — Ley sobre Garantías y Protección Integral de los Derechos de la Niñez y Adolescencia | Ley 21.430 of 15 March 2022 | The principal child-protection statute. Implements the UN Convention on the Rights of the Child in domestic Chilean law. Codifies the interés superior del niño, niña o adolescente (best-interest principle) at Art 7. Codifies the right to be heard (Art 9) and the right to privacy (Art 24). Establishes the Sistema de Garantías y Protección Integral de la Niñez y la Adolescencia. | Applies in full to every Chilean kid covered by this Annex. Treatment in §§ 5, 7, 14 below. |
| Ley 21.067 | Crea la Defensoría de los Derechos de la Niñez of 22 January 2018 | Creates the Defensoría de los Derechos de la Niñez, the autonomous national child-rights ombudsperson. | The Defensoría de la Niñez is a complaint route — see § 15 below. |
| Ley 21.090 | Crea la Subsecretaría de la Niñez of 13 April 2018 | Creates the Subsecretaría de la Niñez within the Ministerio de Desarrollo Social y Familia as the cabinet-level policy authority for child rights. | Policy and cooperation route — see § 14 below. |
| Ley 21.302 | Crea el Servicio Nacional de Protección Especializada a la Niñez y Adolescencia of 2021 | Creates Mejor Niñez, the specialised child-protection service that replaced the protection-side functions of the former SENAME. | Cooperation route for protection cases — see § 14 below. |
| Ley 20.084 | Establece un Sistema de Responsabilidad de los Adolescentes por Infracciones a la Ley Penal | Adolescent criminal-responsibility statute (covers ages 14–17). | Relevant context for criminal-procedure handling of adolescent users; not directly engaged by Balance's processing. |
| Ley 21.057 | Regula entrevistas grabadas en video y otras medidas de resguardo a menores de edad víctimas de delitos sexuales of 20 January 2018 (effective progressively from 2019) | Mandates recorded video-interviews of minor victims of sexual offences, to prevent re-victimisation. | Relevant context for prosecutorial handling of CSAE referrals from Balance — see § 14 below. |
| Ley 21.459 — Establece normas sobre delitos informáticos, deroga la ley N° 19.223 y modifica otros cuerpos legales con el objeto de adecuarlos al Convenio de Budapest | Ley 21.459 of 20 June 2022 | The modernised cybercrimes statute. Replaced Ley 19.223. Adopted in implementation of Chile's accession to the Budapest Convention on Cybercrime. Defines illicit access to a computer system (Art 2), illicit interception (Art 3), illicit interference with data (Art 4), illicit interference with a system (Art 5), forgery (Art 6), forgery of payment instruments (Art 7), computer fraud (Art 8), abusive provision of services (Art 9), and trade in passwords / access tokens (Art 10). | Applies. Cross-reference in Child Safety Standards § 8 (Chile CSAE routes — see § 14 below). |
| Código Penal | Código Penal — Arts 366 quáter (sexual conduct or communication with a minor under 14 — Ley 20.526 amendment), 366 quinquies (production of pornographic material involving minors), 367 (corruption of minors), 374 bis (commercialisation, distribution, exhibition, importation, and storage of pornographic material involving minors), 411 quáter (trafficking in persons including child trafficking) | The Chilean criminal-law backbone for CSAM, online grooming, and child-sexual-exploitation offences. The grooming-specific offence (online sexual communication with a minor under 14) is in Art 366 quáter as amended by Ley 20.526 of 2011 and supplemented by Ley 21.013 (mistreatment of minors). | Applies. Cross-reference in Child Safety Standards § 8 (Chile CSAE routes — see § 14 below). |
| Ley 20.526 | Sanciona el acoso sexual de menores, la pornografía infantil virtual y la posesión de material pornográfico infantil of 13 August 2011 | The grooming + virtual-CSAM + possession-of-CSAM amendment to the Código Penal. | Applies as integrated into the Código Penal — see Arts 366 quáter, 366 quinquies, 374 bis. |
| Ley 19.496 — Sobre Protección de los Derechos de los Consumidores | Ley 19.496 of 7 March 1997, as amended (notably by Ley 19.955 of 2004, Ley 20.555 — Ley SERNAC Financiero of 2011, Ley 21.081 of 2018 — empowering SERNAC, Ley 21.398 of 2021 — Ley Pro Consumidor, and Ley 21.521 — Ley Fintec of 2023) | The principal consumer-protection statute (the "CPL"). Art 3 — rights of the consumer; Art 3 ter — the 10-day right of retraction for distance contracts (the Chilean equivalent of the AR botón de arrepentimiento); Art 17 B + 17 C — duty of professional information and pre-contract transparency for financial and digital services; Art 16 — abusive contract terms; Art 50 — collective and diffuse interest actions. Ley 21.398 added the fácil término obligation — a subscription must be terminable through the same channel by which it was contracted, in no more steps than were required to contract it. | Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below. |
| Ley 21.398 — Ley Pro Consumidor | Ley 21.398 of 24 December 2021 | Strengthened the CPL, particularly for e-commerce and digital services: the fácil término one-click cancellation obligation, an explicit prohibition of "letra chica" misleading terms, mandatory pre-contract disclosure rules for online subscriptions, and SERNAC's enhanced enforcement powers. | Implemented by the in-app subscription-cancellation flow per Subscription Terms § 20. |
| Ley 19.223 | Tipifica figuras penales relativas a la informática of 7 June 1993 | The first Chilean cybercrime statute. Repealed by Ley 21.459 of 2022. | Not in force. Listed here for completeness only. |
| Convention 108 + Convention 108+ | Convención para la protección de las personas con respecto al tratamiento automatizado de datos de carácter personal (Council of Europe ETS 108 of 28 January 1981) and its Protocolo Modificativo (CETS 223 of 18 May 2018). | Chile signed the modernised Convention 108+ on 10 October 2023. Ratification is pending at the Effective date. | Relevant as a context-setting instrument for the Ley 21.719 transfer regime once Chile completes ratification. Treatment in § 8 below. |
| EU adequacy | None as of the Effective date — Chile does not have an EU adequacy decision under GDPR Art 45. | Distinct from Argentina (Decision 2003/490/EC) and Uruguay (Decision 2012/484/EU), Chile does not yet hold an adequacy finding. The European Commission's adequacy assessment of Chile is contingent on the full entry into force of Ley 21.719 + the constitution of the APDP + accumulated practice. | Relevant only as context. Balance's transfer mechanism for the CL-to-US leg does not rely on adequacy. Treatment in § 8 below. |
(Any prospective Chilean Proyecto de Ley de Inteligencia Artificial — Boletín N°16.821-19 or successor — and any APDP circular or instrucción on automated-processing or algorithmic-decision rules are intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such prospective Chilean regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authority — the dual regime
3.1 At the Effective date — no autonomous DPA
Ley 19.628, the regime in force at the Effective date, does not establish an autonomous data-protection authority. Supervision of the private sector is by the ordinary civil courts through the habeas data civil procedure under Ley 19.628 Arts 16–17, and through the recurso de protección under CN Art 20 invoking Art 19 N°4. In the public sector, the Consejo para la Transparencia ("CPLT") has limited supervisory functions under Ley 20.285 on access to public information. Neither the CPLT nor any other autonomous body is competent to receive private-sector data-protection complaints in the manner of the AAIP (Argentina), or an EU DPA — until the APDP takes office in December 2026.
| Field | Value (at the Effective date) |
|---|---|
| Forum | Juzgados de Letras en lo Civil — the ordinary civil-trial courts — for habeas data actions under Ley 19.628 Arts 16–17. Constitutional protection actions under CN Art 20 are filed before the Corte de Apelaciones of the relevant jurisdiction. |
| Public-sector supervisory body | Consejo para la Transparencia (CPLT) — Morandé 360, piso 7, Santiago, Chile; https://www.consejotransparencia.cl/; not competent for private-sector matters. |
| Procurement of the data-protection bill | Ministerio de Economía, Fomento y Turismo; Ministerio Secretaría General de la Presidencia; Ministerio de Justicia y Derechos Humanos — the executive bodies that piloted Ley 21.719 through Congress; not competent for private-sector enforcement. |
| Consumer-side parallel forum | Servicio Nacional del Consumidor (SERNAC) — for matters that overlap with the CPL (which most digital-service privacy disputes do). See § 16 below. |
3.2 From December 2026 — the Agencia de Protección de Datos Personales (APDP)
Ley 21.719 creates the Agencia de Protección de Datos Personales (APDP) as Chile's first autonomous, specialised data-protection authority. The APDP is constituted as a functionally and budgetarily autonomous body, with regulatory, supervisory, enforcement, and sanctioning powers comparable in scope to the AAIP (Argentina) and the EU DPAs. The APDP is constituted on the entry into force of Ley 21.719 in December 2026.
| Field | Value (from December 2026) |
|---|---|
| Name | Agencia de Protección de Datos Personales (APDP) |
| Status | Autonomous body, governed by a Council and headed by a Director |
| Powers | Issue circulares and instrucciones; conduct on-site and remote audits; receive and investigate complaints; impose administrative fines; certify cross-border transfer mechanisms (Chilean SCCs, BCRs, codes of conduct, certifications) |
| Headquarters | To be determined by APDP's constitutive act in December 2026 |
| Website | To be published by the APDP at its constitution; placeholder reference: pending APDP publication |
| Complaint channel | Will be published by the APDP upon constitution; placeholder reference: pending APDP publication |
| To be published by the APDP upon constitution | |
| Phone | To be published by the APDP upon constitution |
On the entry into force of Ley 21.719 in December 2026, this § 3 will be rewritten to insert the APDP's published contact details and to remove the "no autonomous DPA" treatment.
3.3 No mandatory DPO designation at the Effective date
Ley 19.628 does not mandate the appointment of a Data Protection Officer for foreign controllers offering services to Chilean residents. Ley 21.719 (December 2026 onward) introduces a DPO-equivalent obligation for high-risk controllers. Balance will assess whether the Ley 21.719 DPO obligation is engaged for its Chile-processing footprint upon the law's entry into force; if engaged, a Chilean DPO will be designated and this Annex will be republished with the DPO's contact details.
In the interim — and unless and until a Chilean DPO is designated — the single point of contact for Chilean residents is (named individual: ), with the Juzgados de Letras en lo Civil and the Cortes de Apelaciones as the judicial fora (and, from December 2026, the APDP as the supervisory authority).
3.4 Database registration
Ley 19.628 Art 22 requires the registration of personal-databanks of the public sector in the Registro de Bancos de Datos Personales maintained by the Servicio de Registro Civil e Identificación. Ley 19.628 does not require the registration of private-sector databanks. Accordingly, Balance is not required to register its databanks at the Effective date. Ley 21.719 abolishes the public-sector registry as such and replaces it with a different model based on records of processing activities (Art 30-equivalent) and on the APDP's registry of high-risk controllers; Balance's registration obligations under Ley 21.719 will be assessed on entry into force.
4. Lawful bases — the dual regime
4.1 At the Effective date — Ley 19.628 Art 4
Ley 19.628 Art 4 establishes a default consent-based regime: the treatment of personal data requires the express written consent of the data subject, unless one of the specific statutory carve-outs in Arts 4 inciso 5, 7, 10, or 20 applies. The principal carve-outs that Balance relies on for Chilean residents at the Effective date are:
| Processing purpose | Lawful basis (Ley 19.628) | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | Ley 19.628 Art 4 — express consent of the parent at sign-up, evidenced in the Spanish-language consent screen; supplemented by Ley 19.628 Art 4 inciso 5 — processing necessary for the development of an existing juridical relationship between the parties (the parent's subscription contract with Balance) | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | Ley 19.628 Art 4 — express consent of the parent or holder of parental responsibility under the patria potestad doctrine of the Código Civil + Ley 21.430 best-interest principle; supplemented by Ley 21.430 Arts 7 + 24 (best interest + right to privacy) as the substantive child-protection overlay | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | Ley 19.628 Art 4 — express consent; Ley 19.628 Art 4 inciso 5 — necessary for the development of the juridical relationship | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | Ley 19.628 Art 4 inciso 5 — necessary for the juridical relationship; supplemented by the controller's legitimate interest in maintaining the integrity of the service and the deber de seguridad y confidencialidad under Ley 19.628 Arts 11 + 7 (the obligation to maintain the security and confidentiality of the data) | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations (Ley 19.628 habeas data responses; CPL consumer-rights requests; cooperation duties under Ley 21.430; CSAE-report obligations) | Ley 19.628 Art 4 inciso 5 + Art 20 — necessary for compliance with a legal obligation of the controller; supplemented by Código Penal and Ley 21.459 cooperation duties | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | Ley 19.628 Art 4 — express written consent of the parent | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | Ley 19.628 Art 4 inciso 5 — necessary for the subscription contractual relationship | H4; CPL overlay in § 16 below |
4.2 From December 2026 — Ley 21.719 Art 12
Ley 21.719 Art 12 introduces a GDPR-Art-6-aligned six-lawful-bases regime: (a) consent; (b) contract; (c) legal obligation; (d) vital interests; (e) public-interest task; (f) legitimate interests. From December 2026, Balance's processing of Chilean-resident data will be mapped to the Ley 21.719 lawful bases as follows: (i) running the service = Ley 21.719 Art 12(b) contract + Art 12(a) consent for the parent's sign-up + Art 12(a) consent of the parent on behalf of the kid; (ii) operational alerts = Art 12(b) contract; (iii) abuse and fraud prevention = Art 12(f) legitimate interest (with a documented legitimate-interest assessment under Ley 21.719's equivalent of GDPR Art 6(1)(f), already prepared in our Data Protection Impact Assessment § 7); (iv) compliance with legal obligations = Art 12(c) legal obligation; (v) VPC for the kid's data = Art 12(a) consent of the holder of parental responsibility under Ley 21.719 Art 16-bis (children's-data article).
This § 4.2 will be promoted from "future" to "current" on the entry into force of Ley 21.719.
Balance does not rely on Ley 19.628 carve-outs for "data from sources of public access" (Art 4 inciso 5 — accessible-from-publicly-available-sources) as the lawful basis for any kid-side processing.
5. Ley 21.430 — children's rights overlay
Ley 21.430 is the principal Chilean child-protection statute. The principal Balance-side handshakes are:
5.1 Best-interest-of-the-child principle (Art 7)
Ley 21.430 Art 7 establishes the interés superior del niño, niña o adolescente as the controlling principle for any action that concerns a child. The constitutional anchor is CN Art 19 N°1 + Art 19 N°4 + the UN Convention on the Rights of the Child (ratified by Chile via Decreto Supremo N° 830 of 1990) + Ley 21.430 itself. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.
5.2 Right to privacy of the child and adolescent (Art 24)
Ley 21.430 Art 24 protects the privacy of children and adolescents, including in the digital environment. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).
5.3 Right to be heard (Art 9)
Ley 21.430 Art 9 codifies the kid's right to be heard in any matter that concerns them. Balance's architectural posture preserves this principle through the kid-app design (the kid sees their own limits, schedules, tasks, and earned-time ledger in their own kid-app UI; the kid can request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision).
5.4 No advertising directed at children
Ley 21.430 does not contain an explicit federal prohibition of advertising directed at children, but the best-interest principle (Art 7) read with the privacy principle (Art 24) and the CPL's general prohibition on misleading advertising (Ley 19.496 Arts 28 + 33) operates as a substantive overlay. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes (federal child-protection system)
Ley 21.430 establishes the Sistema de Garantías y Protección Integral de la Niñez y la Adolescencia. The principal Chilean child-protection bodies are: (i) Defensoría de los Derechos de la Niñez (Ley 21.067) — the autonomous national child-rights ombudsperson; (ii) Subsecretaría de la Niñez (Ley 21.090) — the cabinet-level policy authority within the Ministerio de Desarrollo Social y Familia; (iii) Mejor Niñez (Ley 21.302) — the specialised child-protection service for protection cases. Balance cooperates with each on incidents that involve Chilean kids — see § 14 below.
6. Ley 19.628 ARCO rights — and the Ley 21.719 catalogue from December 2026
6.1 The current ARCO rights (Ley 19.628 Arts 12–16) — in force at the Effective date
A Chilean resident has the following rights under Ley 19.628 at the Effective date. The article-list mirrors Ley 19.628 as in force at the Effective date.
- Art 12 — Right of access. The data subject is entitled to know what data about them is being processed, the origin of the data, the purposes of the processing, and the identification of any onward recipients. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a Spanish plain-language summary. - Art 12 — Right of rectification. The right to require the controller to correct inaccurate, erroneous, equivocal, incomplete, or outdated data. Honored in-app at Settings → Account → Edit and at
. - Art 12 — Right of cancellation (deletion). The right to require the controller to cancel (delete) data whose treatment is illegitimate or whose retention is no longer necessary. Honored at Settings → "Delete my account" / "Delete this kid"; at Delete-account page; or at
. Cascade per Data Retention & Deletion Policy § 7. - Art 12 — Right of opposition (objection). The right to oppose the use of the data for advertising, market research, or commercial-prospection purposes. Balance does not use Chilean residents' data for any of those purposes, so the right is satisfied by default; nonetheless, an explicit opposition request will be honored at
. - Art 16 — Habeas data civil action. Where the controller does not honor an Art 12 request within the statutory window, the data subject may bring a habeas data civil action before the Juzgado de Letras en lo Civil with jurisdiction over the data subject's domicile. The procedural rules are in Ley 19.628 Arts 16–17.
- CN Art 20 — Recurso de protección. Where the data subject considers that the controller's conduct constitutes an arbitrary or illegal act or omission that deprives, disturbs, or threatens the legitimate exercise of the constitutional right to data protection under Art 19 N°4, the data subject may file a recurso de protección before the Corte de Apelaciones with jurisdiction. The recurso de protección is a fast-track constitutional remedy.
6.2 Timeline (Ley 19.628)
- Access, rectification, cancellation, and opposition (Art 12): the controller must respond within two working days of the request (Ley 19.628 Art 12 inciso 6 — "dentro del plazo de dos días hábiles"). Where the request is for rectification or cancellation, the controller must execute the change within the same window where the request is well-founded; where the controller refuses, the controller must inform the data subject of the reasoned refusal within the same two-working-day window.
- Habeas data civil action (Art 16): the procedure is summary; the court is required to act with celerity.
- Recurso de protección (CN Art 20): the Corte de Apelaciones docket; typically resolved within weeks to months depending on workload.
Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to seek judicial habeas data redress and, from December 2026, the right to file a complaint with the APDP.
6.3 The future Ley 21.719 rights catalogue — from December 2026
From December 2026, the rights catalogue is rewritten as follows (Ley 21.719 Arts 14 et seq.):
- Right of access — equivalent to current Art 12 access right, plus the right to receive a copy of the data being processed.
- Right of rectification — equivalent to current Art 12 rectification right.
- Right of suppression (deletion) — equivalent to current Art 12 cancellation right, expanded to include withdrawal-of-consent-driven deletion and no-longer-necessary deletion.
- Right of opposition (objection) — broadened to include objection on grounds of the data subject's particular situation, not only the advertising-related grounds in Ley 19.628.
- Right to portability — new under Ley 21.719; the Art 12 JSON export is already portable.
- Right to block — new under Ley 21.719; the right to require the controller to suspend processing pending a dispute about accuracy or legitimacy.
- Right to be informed — the right to receive the privacy-notice information; satisfied by the global Privacy Policy + this Annex.
- Right to file a complaint with the APDP — new under Ley 21.719.
- Right to compensation for damage — under the general Chilean tort regime (Código Civil Arts 2314 et seq.) read with Ley 21.719's administrative-fine regime.
The Ley 21.719 timeline is broadly aligned with the GDPR 1-month timeline + extensions for complex requests. The exact timeline will be confirmed by the APDP's first instrucciones after constitution.
6.4 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of the Chilean cédula de identidad or RUT) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.
6.5 No cost
The exercise of the Ley 19.628 Art 12 rights is free of charge (Ley 19.628 Art 12 inciso 6). A fee may only be charged where the data subject submits more than one request within a 6-month period without proving a legitimate interest in repeating the request. Ley 21.719 preserves the no-cost principle for routine requests.
6.6 Language
A request may be submitted in Spanish (preferred for Chilean residents) or in English.
7. Children's data — Ley 19.628 + Ley 21.430 + Ley 21.719
Ley 19.628 does not contain an explicit children-specific article equivalent to GDPR Art 8. The treatment of children's data at the Effective date is governed by:
- Ley 19.628 Art 4 — express consent of the data subject; where the data subject is a child, the consent is given by the holder of parental responsibility under the patria potestad doctrine of the Código Civil Arts 243 et seq.
- Ley 21.430 — best-interest principle (Art 7), right to be heard (Art 9), right to privacy (Art 24).
- CN Art 19 N°4 — constitutional protection of personal data, with the constitutionally-recognised heightened protection of children under CN Art 19 N°1 + Art 19 N°10 + Art 19 N°11.
- CRC Art 3 — UN Convention on the Rights of the Child best-interest principle, internalised via Decreto Supremo N° 830 of 1990.
From December 2026, Ley 21.719 introduces an explicit children's-data article: - Ley 21.719 Art 16-bis (or successor in the as-promulgated text): processing of personal data of children under 14 requires the express consent of the holder of parental responsibility (the parent or legal guardian) under the patria potestad doctrine. For adolescents 14 to 17, the adolescent's own informed assent is layered in alongside the parent's consent for processing that is not necessary for the contract.
For Balance:
- Children and adolescents (under 18). Processing requires the express, informed, specific consent of the parent or legal guardian. Balance obtains this via the VPC mechanism in United States annex § 5 (the same VPC mechanism is engaged for Chilean residents): email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device, accompanied by a Spanish-language Verifiable Parental Consent screen that itemises the categories of data being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights. Cross-reference: Ley 19.628 Art 4 (today) + Ley 21.719 Art 16-bis (from December 2026).
- No kid-self-serve consent path. Balance's architectural posture is identical regardless of the kid's age — the parent always consents on behalf of the kid; there is no kid-self-serve consent path inside Balance. This is the most-protective reading of Ley 21.430 Art 24 + Ley 21.719 Art 16-bis read with the patria potestad doctrine.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Chile — the dual regime
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Chilean resident's data leaves Chile at the point of being uploaded to the Balance backend.
8.1 At the Effective date — Ley 19.628's permissive transfer regime
Ley 19.628 does not contain a specific international-transfer article. The Chilean position at the Effective date is that international transfers are governed by the same consent + statutory-carve-out architecture that governs domestic processing under Ley 19.628 Art 4. Balance relies on the following stack to satisfy Ley 19.628 for the CL → US transfer at the Effective date:
- Express data-subject consent. The parent's sign-up consent prominently discloses the international transfer (cross-reference: Privacy Policy § 12 + the in-app Spanish-language consent screen). Consent is collected as the principal lawful basis for the transfer at the Effective date.
- Contractual safeguards — Chile-side processor DPAs. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor DPA that incorporates the substance of the EU SCCs as a substantive overlay, even though Chile does not (yet) mandate a Chile-specific SCC at the Effective date. The full transfer pack is in our international-transfer pack § 6.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
8.2 From December 2026 — Ley 21.719 GDPR-aligned transfer regime
Ley 21.719 introduces a GDPR-Chapter-V-aligned international-transfer regime: (i) transfers to countries with an adequacy decision issued by the APDP; (ii) transfers under Cláusulas Tipo (Chilean SCCs to be issued by the APDP); (iii) transfers under Binding Corporate Rules approved by the APDP; (iv) transfers under codes of conduct approved by the APDP; (v) transfers under APDP-approved certifications; (vi) transfers under specific derogations (data subject's explicit consent, contractual necessity, important public interest, vital interest, legal-claim).
From December 2026, Balance's CL → US transfer stack will be: - Principal mechanism: Chilean Cláusulas Tipo (Chilean SCCs) signed with each US sub-processor in respect of Chilean-resident data, once the APDP publishes its Cláusulas Tipo template. Until that template is published and signatures are obtained, the transitional mechanism is the parent's explicit consent under the Art 12-aligned derogation, with EU-SCC substance preserved in the underlying processor DPAs. - Supplementary measures: the E2EE described in § 8.1 above. - Onward-transfer restrictions: every sub-processor's DPA forbids onward transfer of Chilean-resident data to a third country outside the Ley 21.719 framework without the controller's prior written authorisation.
8.3 No EU adequacy for Chile
The European Commission has not issued an adequacy decision in respect of Chile under GDPR Art 45. The EU position on Chile is under assessment and is contingent on the full entry into force of Ley 21.719 + the APDP's accumulated supervisory practice + the ratification of Convention 108+. Accordingly, the EU adequacy path is not available as a transfer tool for any Chile-resident leg at the Effective date or in the short-to-medium term.
8.4 Transfer mechanism — the CL-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the CL-KZ axis is covered by Chile-side processor DPAs signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
9. Data residency for Chilean residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Chilean resident's data held in Chile? | No. Every Chilean resident's data is held in the United States. The Ley 19.628 transfer mechanism in § 8.1 above (and from December 2026 the Ley 21.719 transfer mechanism in § 8.2) is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs. |
| Is there a Chilean establishment? | No. Balance has no permanent establishment in Chile. |
| Where is the supervisory authority? | At the Effective date: no autonomous DPA — the Juzgados de Letras en lo Civil and the Cortes de Apelaciones are the fora. From December 2026: the Agencia de Protección de Datos Personales (APDP). |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Chile does not impose a comprehensive data-localisation mandate on parental-control services under either Ley 19.628 or Ley 21.719.
10. Sub-processors touching Chilean resident data
| Sub-processor | Role | Location of processing | Chilean transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Parent's express consent (Ley 19.628 Art 4) + processor DPA with EU-SCC substance; Chilean Cláusulas Tipo to be added on APDP publication (Ley 21.719); E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Parent's express consent + Google Cloud Data Processing Addendum (EU-SCC substance); Chilean Cláusulas Tipo to be added on APDP publication; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Parent's express consent + Google Cloud Data Processing Addendum (EU-SCC substance); Chilean Cláusulas Tipo to be added on APDP publication; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Chilean kid + parent devices | United States | Parent's express consent + Google Cloud DPA; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Parent's express consent + Google Cloud DPA. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Parent's express consent + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Chilean parent users | United States | Parent's express consent + processor DPA with EU-SCC substance. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7. The Ley 19.628 deber de seguridad y confidencialidad (Arts 11 + 7) is the substantive overlay at the Effective date; the Ley 21.719 GDPR-Art-32-aligned security obligation will be the overlay from December 2026. The full sub-processor list, with each row's DPA status, is at our sub-processor register.
11. Breach notification — the dual regime
11.1 At the Effective date — no statutory breach-notification regime under Ley 19.628
Ley 19.628 does not contain an explicit breach-notification article. There is no statutory obligation under Ley 19.628 to notify a Chilean supervisory authority of a personal-data breach (because there is no autonomous DPA), nor an explicit statutory obligation to notify affected data subjects of a personal-data breach. The closest substantive obligation is the Ley 19.628 Arts 11 + 7 deber de seguridad y confidencialidad (duty of security and confidentiality), read with the Código Civil tort regime that may engage controller liability for damage caused by a breach.
Despite the absence of a statutory breach-notification regime under Ley 19.628, Balance's posture is to notify affected data subjects of a personal-data breach without undue delay on a best-effort basis — anticipating the Ley 21.719 regime that takes effect in December 2026 — and to cooperate with any Chilean authority (court, Ministerio Público, SERNAC) that requests information about the breach in the discharge of that authority's statutory functions.
| Audience | Trigger | Deadline (at the Effective date) | Channel |
|---|---|---|---|
| Affected data subjects | A breach likely to cause significant harm to data subjects. | Without undue delay — Balance's voluntary best-effort posture, anticipating Ley 21.719. | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected). |
| SERNAC | A breach that also constitutes a CPL-grade incident (e.g., affects the parent's consumer rights). | "Reasonable" — no statutory deadline at the Effective date. | Filed via the SERNAC complaint portal where the parent is also filing. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | Carabineros + PDI Cibercrimen + Ministerio Público + Defensoría de la Niñez + Te Protejo Chile. |
11.2 From December 2026 — Ley 21.719 breach-notification obligation
Ley 21.719 introduces a GDPR-Art-33/34-aligned breach-notification regime:
- APDP notification — the controller must notify the APDP of any personal-data breach without undue delay, with a 72-hour benchmark from the controller becoming aware.
- Data-subject notification — where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must notify affected data subjects without undue delay.
From December 2026, the channel for the APDP notification will be the APDP's incident-notification portal (to be published by the APDP on constitution). The internal breach-decision SLA in our breach-notification runbook § 5.4 + § 9 is already aligned with the 72-hour benchmark — preliminary classification within one business day, fuller assessment within seven days, APDP notification within the 72-hour benchmark from December 2026 onward.
11.3 Minimum content of the future APDP notification
The APDP notification (from December 2026) will state, following the Ley 21.719 / GDPR-Art-33-aligned content rules:
- the nature of the personal data affected;
- the categories and approximate number of data subjects involved;
- the technical and security measures in place at the time of the incident;
- the risks for the data subjects;
- the measures adopted or proposed to mitigate the effects of the incident;
- a Privacy Officer contact point (, named individual: ).
The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering will be produced by external Chilean counsel on filing.
12. Cookies and electronic direct marketing
Ley 19.628 does not contain a specific ePrivacy / cookies article. The Chilean substantive position on cookies and electronic direct marketing is derived from: (i) Ley 19.628 Art 4 consent as the lawful basis for any cookie that processes personal data; (ii) Ley 19.496 CPL provisions on pre-contract information, abusive terms, and the prohibition of misleading advertising; (iii) Ley 19.628 Art 12 right of opposition to data uses for advertising / market research / commercial-prospection purposes; and (iv) from December 2026, Ley 21.719's GDPR-aligned consent baseline for the placement of cookies that process personal data.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent in the Spanish-language consent screen.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send electronic direct marketing to Chilean residents. The only email Balance sends to Chilean parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 19.496 + Ley 21.398 Pro-Consumidor require pre-existing consent and a one-click unsubscribe for any commercial communication; if Balance ever introduces a marketing channel, we will comply with both rules.
13. Lawful-access requests and the encryption posture
Chilean authorities may serve a lawful-access request on Balance via:
- A judicial order under the Código Procesal Penal (CPP, Ley 19.696 of 12 October 2000, as amended).
- A Ministerio Público request under the Ley Orgánica Constitucional del Ministerio Público (Ley 19.640 of 1999) and the CPP.
- A judicial intercept order under CPP Arts 222 et seq. (interception of communications).
- A Juzgado de Letras en lo Civil order in the habeas data civil procedure (Ley 19.628 Arts 16–17).
- A Corte de Apelaciones order in the recurso de protección (CN Art 20).
- A SERNAC information-request under Ley 19.496 + Ley 21.081 (the SERNAC-empowerment statute).
- An APDP information-request (from December 2026, under Ley 21.719).
- A judicial order under the Convenio sobre la Ciberdelincuencia (Budapest Convention), implemented domestically by Ley 21.459.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Chilean counsel to assess the validity of the request and the appropriate response; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the Ministerio Público — Unidad Especializada en Cibercrimen, with the Policía de Investigaciones de Chile (PDI) — Brigada Investigadora del Cibercrimen Metropolitana (BRICIB), and with Carabineros de Chile — Sección Cibercrimen, on any CSAE-related referral, via the routes in § 14 below.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Chile
A Chilean resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in Spanish for Chilean reporters. - Defensoría de los Derechos de la Niñez — the autonomous national child-rights ombudsperson. Online:
https://www.defensorianiniez.cl/. Information line: 800-222-247. - Subsecretaría de la Niñez — Línea Fono Infancia — Ministerio de Desarrollo Social y Familia. Online:
https://www.subsecretarianinez.gob.cl/. - Mejor Niñez — Servicio Nacional de Protección Especializada a la Niñez y Adolescencia (Ley 21.302) — protection cases. Online:
https://www.mejorninez.cl/. - Ministerio Público — Fiscalía Nacional — Unidad Especializada en Cibercrimen —
https://www.fiscaliadechile.cl/. Denuncias: via the Fiscalía's online intake athttps://www.fiscaliadechile.cl/Fiscalia/denuncia/index.door by telephone at any fiscalía local. - Ministerio Público — Unidad Especializada en Delitos Sexuales y Violentos —
https://www.fiscaliadechile.cl/. - Policía de Investigaciones de Chile (PDI) — Brigada Investigadora del Cibercrimen Metropolitana (BRICIB) and the regional Brigadas Investigadoras del Cibercrimen —
https://www.pdichile.cl/. Denuncias:https://www.pdichile.cl/Como-Denunciaror at any PDI unit. - Policía de Investigaciones de Chile (PDI) — Brigada Investigadora de Delitos Sexuales y Menores (BRISEXME) —
https://www.pdichile.cl/. - Carabineros de Chile — Cibercrimen —
https://www.carabineros.cl/. Fono Familia: 149; Plan Cuadrante: at any local comisaría. - Te Protejo Chile — the Chilean arm of the INHOPE-aligned regional hotline network. Online: report intake at
https://www.teprotejo.org/cl/(where available) or via the Latin American regional intake athttps://www.teprotejo.org/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Chilean coordination route via the Ministerio Público and Carabineros INTERPOL Chile.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Chilean resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| At the Effective date — Juzgados de Letras en lo Civil and Cortes de Apelaciones | Ley 19.628 habeas data civil action (Arts 16–17) and recurso de protección (CN Art 20 + Art 19 N°4) | The Juzgado de Letras en lo Civil with jurisdiction over the data subject's domicile; the Corte de Apelaciones with jurisdiction. |
| From December 2026 — Agencia de Protección de Datos Personales (APDP) | Ley 21.719 + APDP circulares and instrucciones | To be published by the APDP on constitution |
| Servicio Nacional del Consumidor (SERNAC) | Ley 19.496 consumer-protection + Ley 21.398 Pro-Consumidor | https://www.sernac.cl/; national line 800-700-100; intake at https://www.sernac.cl/portal/604/w3-propertyvalue-23086.html |
| Consejo para la Transparencia (CPLT) | Public-sector data-protection matters under Ley 20.285 (NOT competent for private-sector matters) | https://www.consejotransparencia.cl/ |
| Ministerio Público — Fiscalía Nacional | Cybercrime + child-sexual-exploitation + collective Ley-19.628-grounded prosecutions | https://www.fiscaliadechile.cl/ |
| Defensoría de los Derechos de la Niñez | Child-rights complaints (Ley 21.430 + Ley 21.067) | https://www.defensorianiniez.cl/ |
| Instituto Nacional de Derechos Humanos (INDH) | Human-rights complaints | https://www.indh.cl/ |
| Cortes ordinarias (Justicia Civil / Penal) | General civil and criminal jurisdiction | Per jurisdiction |
A Chilean resident may always first raise the matter with us at (DSAR; named individual: ). We will respond within the Ley 19.628 Art 12 two-working-day window (at the Effective date) or — from December 2026 — within the Ley 21.719 GDPR-aligned timeline. Raising the matter with us first is not a precondition to seeking judicial habeas data redress, a constitutional recurso de protección, or — from December 2026 — an APDP complaint.
16. Consumer rights — the Ley 19.496 + Ley 21.398 overlay
Ley 19.496 (as amended by Ley 21.398 Pro-Consumidor of 2021) is the principal Chilean consumer-protection statute (the "CPL"). Where the parent is acting as a consumidor within the meaning of Ley 19.496 Art 1, the following overlays apply to the subscription purchase flow and to the Terms of Service.
16.1 Pre-contract information (Ley 19.496 Art 3 b) + Art 17 B + Art 28)
The parent is entitled to información veraz y oportuna on the essential characteristics of the service. Implemented in Subscription Terms § 5.
16.2 10-day right of retraction — derecho de retracto (Ley 19.496 Art 3 ter)
Ley 19.496 Art 3 ter grants the consumer a 10-day right of retraction for distance contracts (which include in-app subscriptions), computed from the date of the contract or from the first delivery of the service, whichever is later. This is the Chilean equivalent of the Argentine botón de arrepentimiento (AR Annex § 16.2). Balance's subscription is concluded at a distance (in-app); the 10-day right of retraction applies and is implemented in Subscription Terms § 20. The right of retraction is honored regardless of whether the parent has used the service in the 10-day window — the parent is entitled to a full refund through the Google Play Billing refund route.
16.3 Fácil término — easy-cancellation obligation (Ley 21.398)
Ley 21.398 added the fácil término obligation to the CPL: a subscription concluded online must be terminable through the same channel by which it was contracted, in no more steps than were required to contract it, and without retention-call procedures or other friction. Balance's subscription-cancellation flow is implemented via the Google Play subscriptions screen + the in-app "Cancel subscription" action (under the subscription settings); both routes satisfy the fácil término requirement.
16.4 Abusive contract terms (Ley 19.496 Art 16)
Ley 19.496 Art 16 declares null any contract term that: (i) limits the supplier's liability for damages contrary to public order; (ii) reverses the burden of proof to the consumer's detriment; (iii) imposes a unilateral right of termination on the supplier; (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 16 risk.
16.5 Forum
Ley 19.496 Art 50 A operates on a consumer-protective basis. The Balance Terms of Service preserve the consumer's domicile forum and the SERNAC complaint route (see Terms of Service § 19); choice-of-law clauses that would displace Chilean law to the prejudice of the Chilean consumer are presumptively null under Ley 19.496 Art 16.
16.6 Sello SERNAC
Balance is not currently a holder of the Sello SERNAC voluntary certification. The substantive contractual posture is nonetheless drafted to be Sello SERNAC-compatible.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2).
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- The entry into force of Ley 21.719 in December 2026 is an automatic off-cycle trigger — §§ 2, 3, 4, 6, 7, 8, and 11 will be rewritten as of that date, and the Last updated field will be set to the Ley 21.719 entry-into-force date.
- An APDP circular or instrucción (once the APDP is constituted) that materially affects Balance's posture triggers an off-cycle update to the relevant operational section.
- A material amendment to Ley 21.430 triggers an off-cycle update to § 5 + § 7 + § 14.
- A material amendment to Ley 19.496 or Ley 21.398 that materially affects the subscription flow triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to Ley 21.459 (cybercrime) or to the relevant Código Penal articles (Arts 366 quáter, 366 quinquies, 374 bis) triggers an off-cycle update to § 13 + § 14.
- A material decision of the Tribunal Constitucional or the Corte Suprema that materially affects the interpretation of CN Art 19 N°4 or of Ley 19.628 / Ley 21.719 triggers an off-cycle update to the relevant operational section.
- Chile securing an EU adequacy decision under GDPR Art 45 or ratifying Convention 108+ triggers an off-cycle update to § 8.
- A material change to a sub-processor's Chile-side transfer paperwork triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Designated Child Safety Officer co-signs any change to § 5 (Ley 21.430), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The authoritative Spanish-language version is republished at Chile annex.
End of Chile Country Annex.