Privacy Policy
Last updated: 2026-07-27
At Brenia, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered content generation platform for brand management, social media publishing, and promotional content creation, in compliance with Chile's Law No. 21.719 on personal data protection and with applicable international data protection regulations.
1. Legal Framework and Compliance
We operate from Chile and our primary legal framework is Law No. 21.719 on the protection of personal data. This Policy is also designed to comply with the following international regulations applicable to our users abroad:
Chile's Law No. 21.719 (Personal Data Protection)
Chilean law governing the protection and processing of personal data and creating the Agencia de Protección de Datos Personales (Personal Data Protection Agency), in force since December 1, 2026. It is the primary legal framework applicable to this platform, whose data controller is domiciled in Chile.
GDPR (General Data Protection Regulation)
European Union Regulation 2016/679, applicable to all EU/EEA residents.
CCPA (California Consumer Privacy Act)
California Civil Code §§ 1798.100-1798.199, applicable to California residents.
LGPD (Lei Geral de Proteção de Dados)
Brazilian Law No. 13,709/2018, applicable to Brazilian residents.
PIPEDA (Personal Information Protection and Electronic Documents Act)
Canadian federal privacy law applicable to Canadian residents.
UK GDPR
United Kingdom General Data Protection Regulation, applicable to UK residents post-Brexit.
2. Data Controller
Brenia, a company domiciled in Chile, is the data controller responsible for your personal data under Law No. 21.719. For any privacy-related inquiries or to exercise your rights, you can contact us at:
Email: [email protected]
Privacy and data protection contacts: [email protected] / [email protected]
3. Personal Data We Collect
We collect the following categories of personal data:
3.1 Identity Data
- ○ Full name
- ○ Username
- ○ Profile picture/avatar
3.2 Contact Data
- ○ Email address
- ○ Social media profiles (Instagram, LinkedIn)
3.3 Technical Data
- ○ IP address
- ○ Browser type and version
- ○ Operating system
- ○ Device information
- ○ Time zone and approximate location data
- ○ Cookie identifiers
3.4 Usage Data
- ○ Pages visited and features used
- ○ Time spent on the platform
- ○ Click patterns and navigation paths
- ○ Error logs and performance data
3.5 Content Data
- ○ Brand profiles and configurations
- ○ AI-generated images and copy
- ○ Content scheduling and publishing data
- ○ Campaign and theme data
3.6 Third-Party Data
- ○ Data from Instagram (profile, posts, metrics) if connected
- ○ Data from LinkedIn (profile, pages, metrics) if connected
- ○ Payment information processed by our payment processors (Stripe, Flow.cl, Paddle)
4. Legal Bases for Processing (Law No. 21.719 and GDPR Art. 6)
We process your personal data under the following legal bases recognized by Chile's Law No. 21.719 and, where applicable, by the GDPR:
Consent
When you explicitly agree to the processing, such as accepting cookies, receiving marketing communications, or connecting third-party accounts (Law No. 21.719; GDPR Art. 6(1)(a)).
Contract Performance
Processing necessary to provide our services as agreed in the Terms and Conditions (Law No. 21.719; GDPR Art. 6(1)(b)).
Legal Obligation
Processing required to comply with legal requirements, for example tax records and fraud prevention (Law No. 21.719; GDPR Art. 6(1)(c)).
Legitimate Interest
Processing necessary for our legitimate interests, such as improving our services, platform security, and brand analytics, provided these do not override your fundamental rights and freedoms (Law No. 21.719; GDPR Art. 6(1)(f)).
Sensitive personal data is never processed on the basis of legitimate interest. Any processing of sensitive data would only take place in the cases expressly authorized by Law No. 21.719, such as the data subject's express consent.
5. Purposes of Data Processing
We use your personal data for the following purposes:
- • Providing and maintaining our services
- • Managing your account and authentication
- • Generating AI-powered content (images, copy, videos) based on your brand profile
- • Communicating with you about updates, support, and marketing (with consent)
- • Personalizing your experience on the platform
- • Analyzing usage patterns to improve our services
- • Ensuring platform security and preventing fraud
- • Complying with legal obligations
- • Training and improving our AI/ML models (with anonymized brand data; raw brand configurations are excluded)
6. Publicly Available Social Media Data
Brenia processes data that is publicly available on social media — in particular public Instagram profiles and posts — for the purpose of performing brand analysis and generating recommendations and content for our users. This processing is based on legitimate interest, is limited to information the data subject has manifestly made public, and does not include sensitive personal data.
If you are the holder of one of those accounts and wish to object to this processing or request the deletion of your data, write to our privacy contacts: [email protected] / [email protected]. We will handle your request within the legal timeframe.
7. Data Sharing and Disclosure
We may share your personal data with:
7.1 Service Providers
- ○ Cloud hosting providers (for data storage)
- ○ Payment processors (Stripe, Flow.cl, Paddle)
- ○ Analytics providers
- ○ Email service providers
7.2 Third-Party Integrations
When you connect third-party services (Instagram, LinkedIn), data is shared according to their respective privacy policies.
7.3 Legal Requirements
We may disclose data when required by law, court order, or to protect our legal rights.
7.4 Business Transfers
In case of merger, acquisition, or sale of assets, your data may be transferred to the successor entity.
We do not sell your personal data to third parties.
8. Data Processors (Sub-processors)
To operate the platform we use the following providers, which act as processors or sub-processors on behalf of Brenia:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA |
| Flow.cl | Payment processing | Chile |
| Paddle | Payment processing | United Kingdom |
| Resend | Transactional email | USA |
| Apify | Retrieval of public social media and website data | USA / EU |
| fal.ai | AI image and video generation | USA |
| Google Gemini | Artificial intelligence models | USA |
| OpenAI | Artificial intelligence models | USA |
| Anthropic | Artificial intelligence models | USA |
| Cloudflare (R2 / CDN) | File storage and delivery | USA / global |
| Amazon Web Services | Storage | USA |
| MaxMind | Approximate IP-based geolocation | USA |
| Meta / Instagram | Social media publishing integration | USA |
| Social media publishing integration | USA | |
| Late (getlate.dev) | Instagram publishing | USA |
| Laravel Forge | Hosting infrastructure | USA |
International transfers of personal data to these providers rely on adequate contractual safeguards and, where applicable, on the data subject's consent, in accordance with the international data transfer rules of Law No. 21.719.
9. International Data Transfers
Your data may be transferred to and processed in countries other than Chile or your jurisdiction. When transferring data abroad, we ensure adequate protection through:
- ○ Contractual safeguards with each data processor, in accordance with the international data transfer rules of Law No. 21.719
- ○ Standard Contractual Clauses (SCCs) approved by the European Commission, for data of EU/EEA residents
- ○ Adequacy decisions for countries with equivalent data protection
- ○ Your explicit consent for specific transfers
10. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, with the following concrete timeframes:
- ○ Guest sessions (e.g., /start): data provided without registering, including IP address and uploaded material, is deleted 30 days after the session expires
- ○ Guest visit records (IP address and approximate geolocation): anonymized after 90 days
- ○ Account data: retained while your account exists and deleted when you delete it
- ○ After account deletion: personal data deleted within 30 days, except where legal retention is required
- ○ Application technical logs: retained for 14 days
- ○ Legal/tax records: retained for the legally required period (typically 5-7 years)
- ○ Anonymized/aggregated data: may be retained indefinitely for analytics purposes
11. Your Data Protection Rights
Depending on your jurisdiction, you have the following rights:
11.1 Rights under Law No. 21.719 (Chile)
- • Right of Access: obtain confirmation of processing and a copy of your personal data
- • Right to Rectification: correct inaccurate, outdated, or incomplete data
- • Right to Deletion: request the removal of your personal data
- • Right to Object: object to the processing of your data, including processing based on legitimate interest
- • Right to Portability: receive your data in a structured, commonly used format and transmit it to another controller
- • Right to Blocking: request the temporary suspension of processing while a rectification or objection request is resolved
11.2 Rights under GDPR (EU/UK Residents)
- • Right of Access (Art. 15): Obtain a copy of your personal data
- • Right to Rectification (Art. 16): Correct inaccurate data
- • Right to Erasure (Art. 17): Request deletion of your data ("Right to be Forgotten")
- • Right to Restriction (Art. 18): Limit how we process your data
- • Right to Data Portability (Art. 20): Receive your data in a structured format
- • Right to Object (Art. 21): Object to processing based on legitimate interests
- • Rights related to Automated Decision-Making (Art. 22): Not be subject to solely automated decisions
11.3 Rights under CCPA (California Residents)
- • Right to Know: What personal information we collect and how it is used
- • Right to Delete: Request deletion of your personal information
- • Right to Opt-Out: Opt out of the sale of personal information (we do not sell data)
- • Right to Non-Discrimination: Equal service regardless of exercising your rights
11.4 Rights under LGPD (Brazilian Residents)
- • Confirmation of data processing
- • Access to your data
- • Correction of incomplete or inaccurate data
- • Anonymization, blocking, or deletion of unnecessary data
- • Data portability
- • Deletion of data processed with consent
- • Information about third parties with whom data is shared
- • Revocation of consent
To exercise any of these rights, write to our privacy contacts: [email protected] / [email protected]. We will respond within the legally required timeframe (as a general rule, 30 days for Law No. 21.719 and GDPR, and 45 days for CCPA). Exercising these rights is free of charge.
13. Data Security
We implement appropriate technical and organizational measures to protect your data:
- ○ Encryption in transit (TLS/SSL) and at rest
- ○ Regular security assessments and audits
- ○ Access controls and authentication mechanisms
- ○ Employee training on data protection
- ○ Incident response procedures
In case of a security breach affecting your data, we will notify the Agencia de Protección de Datos Personales and the affected data subjects as required by Law No. 21.719 and, where the GDPR applies, the relevant supervisory authority within 72 hours.
14. Children's Privacy
Our services are not directed to individuals under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through a prominent notice on our platform. The "Last updated" date at the top indicates when this policy was last revised.
16. Data Protection Contact
For privacy-related inquiries or to exercise your rights, contact our data protection team:
Emails: [email protected] / [email protected]
17. Complaints and Supervisory Authorities
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority:
- ○ Chilean Residents: Agencia de Protección de Datos Personales
- ○ EU Residents: Your local Data Protection Authority (DPA)
- ○ UK Residents: Information Commissioner's Office (ICO)
- ○ California Residents: California Attorney General
- ○ Brazilian Residents: Autoridade Nacional de Proteção de Dados (ANPD)
We encourage you to contact us first at [email protected] so we can address your concerns directly.
18. Contact Information
For any questions about this Privacy Policy or our data practices:
Email: [email protected]
Privacy contacts: [email protected] / [email protected]
By using Brenia, you acknowledge that you have read and understood this Privacy Policy.