This page describes, in general terms, the technical and organizational measures Orvium applies to protect personal data, and where we stand on Chile’s Ley 21.719. We describe controls that are actually in place — we do not list aspirations here.
We maintain a documented procedure to detect, contain and investigate security incidents. Where an incident affects personal data, Ley 21.719 requires us to notify the Agencia de Protección de Datos Personales without undue delay, and to notify affected data subjects when the breach is likely to result in a high risk to their rights. To report a vulnerability or a suspected incident, write to privacidad@orvium.ai. We do not pursue legal action against researchers who report in good faith and do not exfiltrate data.
The law enters into force on 1 December 2026. We publish our honest status rather than a compliance claim we cannot yet back:
| Requirement | Status |
|---|---|
| Information duty at the point of collection | Implemented |
| Prior blocking of third-party tags + granular consent | Implemented |
| Consent records kept as evidence | Implemented in the browser; server-side persistence pending |
| Public channel to exercise ARSOPB rights | Implemented |
| Published subprocessor list | Implemented |
| Signed DPAs with every provider | In progress |
| Records of processing activities | In progress |
| Internal rights-request SLA and ticketing | In progress |
| Legal review of all published texts | Pending |
We deliberately do not claim to be “compliant with Ley 21.719” while any row above is unfinished. Stating it before it is true would itself be a risk.