Legal

Public Summary of Security Measures

Version 1 · Effective October 5, 2026 · Previous versions

Article 14-quinquies of Law No. 19,628 on the Protection of Personal Data, as amended by Law No. 21,719

Wiseplan Consultora SpA provides human resources services—including recruitment, payroll outsourcing, labor advisory services, and consulting—and, in the course of these activities, processes personal data belonging to employees, candidates, and business contacts, both its own and those of its clients. This document summarizes, for the information of these individuals and the organizations that entrust their data to Wiseplan, the security measures the company implements to protect that data.

This is a summary. The internal policy that supports it contains the details of each control and is not published, because accurately describing an organization’s defenses would make it easier to breach them. The following outlines the required standard and how it is verified.

What Is Protected

Wiseplan's measures are designed to preserve four attributes of information:

— Confidentiality: ensuring that information is known only to those who need to know it.

— Integrity: Data must be accurate and must not be altered without authorization or without a trace.

— Availability: ensuring that information is accessible when needed, particularly during critical processes.

— Resilience: the organization's ability to recover from an incident and restore its services.

How Security Is Managed

Management approves the security policy and provides the resources to implement it. The Data Protection Officer coordinates its implementation, maintains records demonstrating compliance, and serves as the point of contact for data subjects and the regulatory authority. An internal counterpart oversees the technical implementation, which is carried out by specialized contractors.

Anyone who works at Wiseplan or provides services to the company is subject to these rules, regardless of whether they work in person or remotely.

Who Can Access the Information

Access is granted on a named basis, according to role rather than on trust, and is limited to what each person needs to perform their job. Credentials are personal and non-transferable. Access rights are reviewed periodically and, in addition, whenever a person changes roles or leaves the organization.

Multi-factor authentication is required for all services that support it. Administrative access is limited to the minimum number of people necessary and is reviewed more frequently.

How Equipment and Communications Are Protected

Corporate devices use disk encryption, protection against malware, and up-to-date security updates. Remote access is conducted over encrypted channels. Confidential information is transmitted only through authorized corporate channels; personal messaging and unauthorized online services are not permitted.

No actual information about employees, candidates, or clients is entered into artificial intelligence tools that have not been expressly authorized for that use.

The institutional website operates entirely over an encrypted connection.

Cloud Providers and Services

No vendor may access personal data without a data processing agreement that imposes on it the obligations set forth in Section 15-bis of the law: to process the data only in accordance with Wiseplan’s instructions, not to use it for its own purposes, to maintain confidentiality indefinitely, to implement security measures, to report incidents, and to return or delete the data upon termination of the service.

Before contracting a service, verify where the data will be stored, who the service provider’s subcontractors are, and what security measures it implements. Any certifications held by the provider are taken into account but do not replace the contract. Any changes to the infrastructure or subcontractors must be communicated in advance.

Access by providers located outside Chile is also evaluated in accordance with the law's rules on international data transfers.

Data Requiring Enhanced Protection

Health data, the results of psychological and occupational assessments, biometric data, and records of financial obligations are subject to enhanced security measures: restricted classification, limited access to individuals whose job requires it (verified at each review), encryption in transit and at rest, a prohibition on transmission through unauthorized channels, and, as a general rule, deletion once the purpose that justified their collection has been fulfilled.

Support and Continuity

Repositories containing personal data are backed up regularly, and the ability to restore them is tested at least once a year, with the results documented. The continuity of critical processes does not depend on a single person or a single system.

Record of What Is Happening

Access and relevant operations on repositories containing personal data are logged, and those logs are retained for a minimum period of twelve months. Monitoring is conducted in accordance with labor regulations and fundamental individual rights: its purpose is information security, not individual surveillance.

What happens if there's an incident?

Any event that compromises or threatens to compromise information security must be reported immediately through the designated internal channel, without the person who detects it being required to assess its severity. Wiseplan assesses the risk, contains the incident, and, when appropriate, notifies the Personal Data Protection Agency and the affected individuals, in accordance with the terms and deadlines established by law. Once the incident is resolved, its causes are reviewed, and measures are taken to prevent its recurrence.

People

New employees at Wiseplan receive individual credentials, undergo an orientation on security and data protection, and sign a confidentiality agreement that remains in effect after their employment ends. A change in job role triggers a review of their access privileges, and termination of employment results in the revocation of those privileges. Employees receive regular training.

Review and Improvement

The extent to which controls are implemented is verified periodically, and the policy establishing them is reviewed at least once a year or whenever a regulatory, technological, or business change warrants it. Wiseplan maintains documented records of compliance with these measures, in accordance with the principle of accountability under the law.

Contact

For inquiries regarding this summary or the processing of your personal data, as well as to exercise your rights of access, rectification, erasure, objection, portability, and blocking, please contact the Data Protection Officer at Wiseplan Consultora SpA at datospersonales@wiseplan.cl.

Wiseplan's General Personal Data Protection Policy and privacy notices by data subject category are available on this website.