Last updated: August 5, 2026

1. Purpose and scope

Asesorías e Inversiones Celeste SpA, hereinafter interchangeably "Celeste", "Janus GRC", "Janus" or "the Company", makes this Privacy and Cookie Policy available to persons who visit or use its website https://www.janusgrc.cl and to its clients, hereinafter the "users".

This Policy allows users to understand how Janus collects, processes, communicates, retains and protects their personal data, as well as the rights they may exercise and how to do so.

This Policy is informational in nature. Browsing the website does not constitute consent for those processing activities that require authorization. Where consent is required, Janus will request it through a free, informed, specific, prior, unequivocal and separate affirmative statement or action for each purpose.

The processing of personal data carried out by Janus is governed by Law No. 19.628 on the Protection of Private Life, as amended by Law No. 21.719, which enters into force on December 1, 2026, and by the regulations issued by the Personal Data Protection Agency.

1.1 Definitions

  • Personal data: Any information linked to or referring to an identified or identifiable natural person.
  • Sensitive personal data: Those referred to in Article 2(g) of Law No. 19.628 (as amended by Law No. 21.719), including data concerning health, biological profile, biometric data, ethnic or racial origin, ideological convictions, religious beliefs, union or trade membership, socioeconomic situation, and sexual life or orientation. Data of this nature inferred or deduced from other data are equally considered sensitive.
  • Data processing: Any operation or set of operations performed on personal data, such as collection, recording, organization, retention, storage, modification, extraction, consultation, use, communication, transfer, transmission, blocking, suppression or deletion.
  • Data controller (responsable): The natural or legal person who decides on the purposes and means of processing personal data.
  • Data processor (encargado): The third party who processes personal data on behalf of the controller, pursuant to Article 15 bis.
  • Profiling: Any form of automated processing that uses personal data to evaluate, analyze or predict certain aspects of a person, such as their interests, preferences or behavior.
  • International transfer: Any communication of personal data to a recipient located outside the territory of the Republic of Chile, including remote access to such data and its storage on servers located abroad.
  • Security breach: Any breach of security measures that results in the destruction, leakage, loss or accidental or unlawful alteration of personal data, or the unauthorized communication of or access to such data.
  • Personal Data Protection Agency or APDP: The administrative authority responsible for supervising, interpreting and applying the personal data protection regulations, as provided by Law No. 19.628, as amended by Law No. 21.719.

1.2 Principles applicable to the processing of personal data

Janus processes personal data in accordance with the principles of Law No. 19.628 (as amended by Law No. 21.719):

  • Lawfulness and fairness: Processing is based on a lawful ground and carried out in good faith.
  • Purpose: Data is collected for specific, explicit and lawful purposes, and is not processed in a manner incompatible with them.
  • Proportionality: Only data that is necessary, relevant and not excessive for the purpose is processed (minimization).
  • Quality: Data is kept accurate, complete and up to date.
  • Accountability: Janus adopts measures to comply and to demonstrate compliance (proactive accountability).
  • Security: Technical and organizational measures appropriate to the risk are adopted.
  • Transparency and information: Data subjects are informed in accordance with the duty of information and transparency (Article 14 ter).
  • Confidentiality: Those who process data maintain secrecy (Article 14 bis).

1.3 Who is the controller and how to contact them?

The controller of your data is:

Asesorías e Inversiones Celeste SpA Tax ID (RUT) No. 77.447.200-1 Cerro El Plomo 5420, office 1306, district of Las Condes, Metropolitan Region.

  • Data Protection Officer: Ángel Anguita (angel@anguitaosorio.cl)
  • Contact email: privacidad@janusgrc.cl
  • For inquiries or to exercise your rights, write to that address. Handling these requests is free of charge.

2. Janus's dual role: controller and processor

Janus takes part in the processing of personal data under two distinct capacities, and this Policy governs only the first of them:

  • As a controller. Janus decides the purposes and means of processing the data it collects through its website, its commercial activities and its relationship with clients (for example, contact, account and billing data). This Policy refers exclusively to those processing activities.

  • As a processor (Article 15 bis). When a client contracts the Janus platform, the personal data that the client and the persons who interact with its channels enter into the platform —including reports, cases, data subjects' data and consent or rights-exercise records— are processed by Janus on behalf of and according to the client's instructions. In these processing activities the controller is the client, not Janus, and the relationship is governed by the corresponding data processing agreement or addendum.

Accordingly, if you wish to exercise your rights over data that was entered into the platform by an organization that uses Janus (for example, a report or a request submitted through that organization's channel), you must address that organization, which acts as controller. Janus, as processor, will refer or handle such requests solely in accordance with the controller's instructions.

3. What data do we process as a controller?

As a controller, Janus processes the personal data that users provide through the website, contact or demo-request forms, and the contracting and commercial use of its services, for the purposes described below.

3.1 Inquiries and contact or demo requests

When a user sends an inquiry or requests a demonstration, Janus uses the data provided (name, email, phone, company or organization, and the content of the inquiry) to receive, manage and respond to the request, and for any necessary subsequent commercial follow-up.

The lawful basis is Janus's legitimate interest in handling the communications addressed to it and in managing its commercial relationships. The user may object to this processing in accordance with section 10.

3.2 Contracting and account administration

When an organization contracts the platform, Janus processes the data of contact persons and authorized users (name, email, role, access credentials and account activity logs) in order to set up and administer the account, enable access, provide support and ensure the security of the service. The lawful basis is the performance of the service agreement and Janus's legitimate interest in the security of its systems.

3.3 Billing and payments

To process the contract, Janus processes the name, tax ID, contact details and transaction data necessary to charge for the service, issue the corresponding tax documentation and comply with its legal and accounting obligations.

Payments are processed directly by the payment provider through redirection to its platform. Janus does not collect or store the full card number or its verification code. The lawful bases are the performance of the transaction and compliance with legal obligations applicable to Janus.

3.4 Security and access logs

Janus processes IP addresses and access and operation logs to ensure the security, availability and traceability of its systems, as well as to prevent fraud and misuse. The lawful basis is Janus's legitimate interest in the security of its systems.

3.5 Data of children and adolescents

The Janus website and services are directed at persons over 18 years of age and at organizations. Janus does not deliberately collect personal data of children or adolescents through its website. If Janus becomes aware that it has collected such data without the required authorization, it will proceed to delete it. Anyone may report this circumstance to privacidad@janusgrc.cl.

4. Legal basis for processing

The processing of personal data by Janus is based, as applicable, on the user's consent, the performance of a contract, compliance with a legal obligation, or Janus's legitimate interest, pursuant to Articles 12 and 13 of Law No. 19.628, as amended by Law No. 21.719.

The following table summarizes the correspondence between purposes and lawful bases:

Purpose Data processed Lawful basis
Responding to inquiries and demo requests Name, email, phone, company, content of the inquiry Janus's legitimate interest in handling the communications addressed to it
Contracting and account administration Contact data, credentials, activity logs Performance of the contract and legitimate interest in service security
Billing and payments Name, tax ID, contact and transaction data Performance of the transaction and compliance with legal obligations
Issuance of tax and accounting documentation Identification and transaction data Compliance with a legal obligation
Site security and fraud prevention IP address, access logs Janus's legitimate interest in the security of its systems
Strictly necessary cookies Session identifier, security token Necessary to provide a requested functionality

The user has the right to withdraw their consent at any time, where processing is based on it. Withdrawing it will be as easy as granting it, and its withdrawal does not affect the lawfulness of processing carried out beforehand. Where processing is based on Janus's legitimate interest, the user may request information about the balancing carried out and object to the processing in accordance with section 10.

5. Retention period of personal data

Janus retains personal data only as long as the purpose that justified its collection persists, according to the following criteria:

  • Inquiries and demo requests: for as long as their handling lasts and for the time necessary for commercial follow-up and traceability.
  • Account and contractual-relationship data: for as long as the account remains active and for the period necessary to address any liabilities once the relationship ends.
  • Billing, payments and tax documentation: 6 years, pursuant to Article 17 of the Tax Code and other applicable accounting regulations.
  • Consent and rights-exercise records: for as long as they are necessary as evidence of compliance with this Policy and the law.
  • Access and security logs: for the time necessary for the security and traceability purposes that justified their collection.

Once these periods have elapsed, data is irreversibly deleted or anonymized, unless it must be kept blocked to comply with a legal obligation or to address possible liabilities, for the limitation period of the corresponding actions.

6. Recipients and processors

Users' personal data will not be sold or assigned to third parties for their own purposes.

Janus communicates personal data only in the following cases:

  • To providers that act as processors on behalf of Janus. With all of them Janus enters into the processing contracts or addenda required by Article 15 bis, which bind the processor to process the data solely in accordance with Janus's instructions, to maintain confidentiality, to adopt security measures and to delete or return the data at the end of the service.
  • To public bodies and competent authorities where required by law or within judicial or administrative proceedings.
  • To external advisors subject to a duty of confidentiality, where necessary for the defense of Janus's legitimate interests.

The categories of processors Janus works with are: web hosting and cloud infrastructure providers; authentication and email service providers; and payment processing platforms. The updated list, with the identity and location of each processor, is available upon request at privacidad@janusgrc.cl.

7. International data transfers

Some of the cloud infrastructure providers indicated in section 6 use infrastructure located outside Chile, so processing may involve international transfers of personal data, mainly to the United States of America.

Janus adopts appropriate safeguards for these transfers through the contractual arrangements entered into with those providers, in accordance with the rules on international transfers of Law No. 19.628, as amended by Law No. 21.719. Documentation regarding our relationship with cloud service providers and the safeguards applicable to each transfer is available upon request at privacidad@janusgrc.cl.

8. Security measures

Janus adopts the technical and organizational measures necessary to ensure a level of security appropriate to the risk of the processing, considering the state of the art, the nature of the data and the possible consequences of a breach. Among them are:

  • Encryption of communications between the user's browser and the platform.
  • Access control based on profiles and on the need-to-know principle, with reinforced authentication for systems containing personal data.
  • Logging of accesses and operations on the databases (auditing).
  • Internal confidentiality policies and periodic staff training.
  • Periodic backups and recovery procedures.
  • Evaluation of providers before engaging them and periodic review of the measures they apply.

No security measure can absolutely guarantee the inviolability of information systems. Janus reviews and updates its measures periodically.

9. Security breaches

Janus has an internal procedure for the detection, assessment, containment and documentation of security breaches affecting personal data.

Where a breach occurs that entails a risk to the rights and freedoms of data subjects, Janus will notify the Personal Data Protection Agency by electronic means and without undue delay.

Where the breach affects sensitive personal data, data relating to economic, financial, banking or commercial obligations, or data of children and adolescents, Janus will also notify the affected data subjects, in clear and simple language, indicating the nature of the breach, its possible consequences, the measures adopted and a point of contact for further information.

Where Janus acts as a processor, it will bring the breach to the attention of the controlling client without undue delay, so that the client can fulfill its own notification duties.

Janus keeps a record of all detected breaches, their effects and the corrective measures adopted.

10. Users' rights

Users may exercise the following rights before Janus, which are personal, free of charge and non-waivable:

  • Access: obtain confirmation of whether Janus processes their data and access it, as well as learn its origin, the purpose of the processing, its retention period, the recipients to whom it is communicated and any international transfers.
  • Rectification: request the correction of inaccurate, outdated or incomplete data.
  • Deletion: request the deletion of their data when it is no longer necessary, when they withdraw their consent, when they object to the processing without another legitimate ground, or when it has been processed unlawfully.
  • Objection: request that Janus stop processing their data for a given purpose, including profiling and commercial communications. In the case of commercial or direct-marketing communications, objection requires no justification.
  • Portability: request their data in a structured, generic and commonly used format that can be read by automated means, and its direct transmission to another controller, where processing is based on consent or a contract and is carried out by automated means.
  • Temporary blocking: request the temporary suspension of any processing operation while a rectification, deletion or objection request is resolved.
  • Automated decisions: not to be subject to decisions based solely on the automated processing of their data, including profiling, that produce legal effects or similarly significantly affect them, as well as to request human intervention, express their point of view and challenge the decision.

10.1 How to exercise these rights

These rights may be exercised by writing to privacidad@janusgrc.cl, indicating the right to be exercised and attaching the information that allows the requester's identity to be verified. Janus will only require the information strictly necessary for such verification and will not retain copies of identity documents beyond what is indispensable.

Janus will confirm receipt of the request and respond in writing within the legal period, which will not exceed 30 calendar days from receipt, extendable once for an equal period where the complexity of the request justifies it, a circumstance that will be communicated to the requester in due course.

For temporary-blocking requests, Janus will respond within two business days. Until the request is resolved, the data subject to the request will not be processed.

If Janus denies the request in whole or in part, it will state the grounds for its decision and the available means of challenge.

Remember that, with respect to data entered into the platform by a client organization, Janus acts as a processor and not as a controller; in such cases you must exercise your rights before that organization (section 2).

10.2 Complaint before the Personal Data Protection Agency

If Janus does not respond within the deadline, denies the request, or the user considers that their rights have not been properly addressed, they may file a complaint before the Personal Data Protection Agency, in the form and within the time limits established by law. The complaint before the Agency does not require representation by an attorney.

11. Cookie Policy

What are cookies?

Cookies are small files or fragments of information stored on the user's device when they visit a website, which allow, among other functions, maintaining the security and operation of the site.

Cookies used by Janus

Janus uses only strictly necessary cookies for the operation, continuity and security of the platform. Specifically:

Cookie Purpose Requires consent?
Session cookie (JSESSIONID) Securely maintain the authenticated user's session No. It is a condition for the operation of the site
Security token (CSRF protection) Prevent cross-site request forgery attacks on forms No. It is a condition for the security of the site

These cookies are indispensable to provide a functionality expressly requested by the user and therefore do not require consent.

Janus does not use analytics, advertising, personalization or third-party cookies, nor tracking technologies. As no non-essential cookies are installed, no cookie consent banner is displayed.

Browser configuration

The user may block, restrict or delete cookies through their browser configuration. Disabling strictly necessary cookies could prevent or affect the operation of certain site features, such as signing in.

12. Acceptance, validity and modifications of this Policy

This Policy is informational in nature and its publication does not, in itself, constitute the user's consent for processing that requires it. Consent is obtained separately, specifically and unequivocally in each case where the law requires it.

Janus may modify this Policy where necessary due to changes in its processing activities, in the applicable regulations or in the criteria of the Personal Data Protection Agency. Modifications will be brought to the user's attention through this same website, indicating the date of the latest update.

Where the modification substantially affects the purposes of the processing or the rights of users, Janus will communicate it prominently and, where appropriate, obtain consent again.

Users are advised to consult this page periodically.