// Legal

Privacy policy

Last updated: 25 July 2026

This policy describes what personal data UID Studio LLC processes through the site uid-security.com, for what purpose, for how long, and how you can exercise your rights.

This is a translation provided for convenience. The Spanish version is the binding one; in case of discrepancy, the Spanish text prevails.

1. Who processes your data

The data controller is UID Studio LLC. For any question about this policy or about your data, write to us at contacto@uid-studio.cl.

2. What data we collect

Only what you give us when you complete the contact form, plus the minimum technical data that accompanies that submission:

  • What you fill in: name, email, and optionally company, role, type of service, estimated scope and the message you write.
  • Technical data of the submission: IP address, approximate country and city derived from that IP, browser (user agent) and date and time. We attach these to the email as anti-fraud evidence and so that we can investigate abuse of the form.
  • Server logs: our web server records accesses with IP, requested path and user agent, like any server.

We do not collect special categories of data, and we ask you not to include sensitive information or credentials in the form message.

3. What we use it for

  • To answer your request and prepare a service proposal.
  • To maintain the commercial contact arising from that request.
  • To prevent and detect abuse of the form (spam, automated submissions, injection attempts).

We do not use your data for third-party advertising, we do not sell it and we do not transfer it to anyone for commercial purposes.

4. Lawful basis

Processing relies on your consent, which you give when you send the form, and on the legitimate interest of protecting the security of the site in the case of the anti-fraud technical data. You can withdraw your consent at any time by writing to us.

5. Cookies and tracking

This site does not use cookies, neither first-party nor third-party, and it does not identify you or track you across sites.

We use Cloudflare Web Analytics to know how many visits each page receives and how the site performs. It is analytics without cookies and without persistent identifiers: it does not build profiles, does not track across sites and does not use device fingerprinting. For this, your browser loads a script from static.cloudflareinsights.com and sends aggregated metrics (page view, referrer, browser type and load times) to Cloudflare, which processes them as a data processor. It is the only third-party resource on the site: there are no tracking pixels or heat maps, and fonts are served from our own domain.

The form keeps its state through signed single-use tokens, which live in the page's memory and disappear when you close it.

6. Who we share it with

Only with the providers needed for the site to work, and only to that extent:

  • Hostinger — server hosting and outbound mail service (SMTP).
  • Cloudflare — content delivery network, protection against attacks and cookie-free web analytics. It processes inbound traffic, including your IP address, and the aggregated visit metrics described in section 5.

Both act as data processors and may process data outside Chile. There are no other recipients.

7. How long we keep it

  • Contact requests: up to 24 months from the last contact, unless the relationship results in a contract, in which case the applicable legal and contractual periods govern.
  • Server logs: up to 90 days.

8. Your rights

You can ask us at any time to access your data, rectify it, delete it, object to its processing, request its portability or withdraw your consent. Write to us at contacto@uid-studio.cl from the address you contacted us with; we reply within the legal deadlines.

If you consider that we did not handle your request properly, you can complain to the competent supervisory authority for personal data protection.

9. Security

The site is served exclusively over HTTPS with HSTS. The form applies origin verification, a signed single-use token, a captcha and rate limiting by IP. The mail service credentials live only on the server and are never exposed in the browser.

If you find a vulnerability in this site, we appreciate a responsible report: the details are in security.txt.

10. Legal framework

This policy is governed by Law No. 19.628 on the protection of private life and is aligned with the obligations of Law No. 21.719, which comes into full force in December 2026.

11. Changes

If we modify this policy, we update the date in the header. Substantial changes are communicated to anyone with an active request with us.