Data Protection Addendum
Last updated: September 2026
This addendum is a technical draft. It must be reviewed by legal counsel before publication, in particular against Ley 21.719 (Chile) and Ley 8968 (Costa Rica). Items marked [●] require a decision by Percus.
This addendum governs the processing of personal data that Percus SpA ("Percus") carries out on behalf of its clients ("the Client") when providing the personalized video platform. It forms part of the services agreement with each Client. Where a Client's specific agreement sets different terms, the agreement prevails.
1. Roles of the parties
- The Client is the data controller. It decides which data is used, for what purpose and on what legal basis, including data subjects' consent where required.
- Percus is the data processor. It processes personal data only on the Client's behalf, following its documented instructions and solely to provide the contracted service.
Percus does not use Client data for its own purposes, and does not sell, rent or share it with third parties other than the sub-processors listed in section 7.
2. Applicable law
Percus processes data in accordance with the data protection laws that apply to the Client and to Percus, including:
- Chile: Ley 19.628 on the Protection of Private Life and, once in force, Ley 21.719.
- Costa Rica: Ley 8968 on the Protection of Individuals with regard to the Processing of their Personal Data, and its regulations.
- The laws of each Client's country, where different from the above.
3. Personal data processed
| Category | Data subjects | Data | Does Percus store it? |
|---|---|---|---|
| Platform users | Client staff who use the backoffice | Name, email address, identity provider ID (Microsoft Entra ID or Google), assigned roles | Yes, while the account is active |
| Personalization data | The Client's end customers (for example, pension fund members) | Whatever the Client chooses to show in the video: name, balances, contributions, projections, among others | No, under API integration (see section 4) |
| Viewing analytics | End customers who watch the video | Pseudonymized identifier (SHA-256 hash computed in the browser), session ID, device and browser type, country, playback and interaction events | Yes. Does not include name, the Client's identifier or IP address |
The analytics identifier is treated as pseudonymized personal data: Percus cannot link it to a person, but the Client could using its own systems.
4. API integration without storage
Under the standard integration, personalization data is always delivered by API at viewing time, from the Client's systems to the Percus player in the end customer's browser:
- The data travels encrypted (TLS 1.2 or higher) and is held only in the player's memory during viewing.
- It is not written to databases, files, logs or browser storage.
- A breach of Percus infrastructure does not expose this data, because it is never stored there.
Percus also offers an optional model in which the Client uploads data in advance and Percus stores it. That model is used only when the Client requests it in writing, and is then set out in the agreement. See Data Handling.
5. Confidentiality
Percus limits access to personal data to the staff who need it to provide the service. All such staff are bound by confidentiality obligations that continue after their relationship with Percus ends.
6. Security measures
Percus applies technical and organizational measures appropriate to the risk, including:
- Encryption in transit with TLS 1.2 or higher for all communications.
- Databases in private AWS networks, not reachable from the internet.
- Test and production environments in separate AWS accounts.
- Authentication federated with the Client's identity provider, which enforces its own multi-factor authentication (MFA) policy. The platform stores no passwords.
- Role-based access control and data isolation per organization.
- Secrets managed in AWS Secrets Manager and encryption keys in AWS KMS.
Percus keeps these measures under continuous review and is working toward ISO/IEC 27001 certification. Details are in Infrastructure and Compliance.
7. Sub-processors
The Client authorizes Percus to use the following sub-processors:
| Sub-processor | Service | Data location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute, databases, storage and content delivery) | United States (us-east-1 region, Northern Virginia) |
Microsoft Entra ID and Google act as identity providers for platform user sign-in. When the Client uses its own Microsoft Entra ID, that service is contracted and managed by the Client.
Percus will notify the Client at least 30 days before adding or replacing a sub-processor. The Client may object on reasonable grounds within that period. Percus requires each sub-processor to meet data protection obligations equivalent to those in this addendum.
8. International transfers
Percus infrastructure runs on AWS in the United States. The Client authorizes this transfer for the provision of the service. Percus applies the safeguards required by applicable law, including the relevant contractual clauses with AWS.
Percus support staff with access to the platform operate from [●] (list countries). Percus will inform the Client of any change to these locations.
9. Security incident notification
Percus will notify the Client of any security incident affecting the Client's personal data without undue delay and, at the latest, within 24 hours of becoming aware of it. The notification will include, as far as known:
- The nature of the incident and its date and time.
- The categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to mitigate it.
- A Percus contact for follow-up.
Percus will support the Client in any notifications the Client must make to the supervisory authority and to data subjects.
10. Data subject rights
If Percus receives a request directly from a data subject (access, rectification, erasure, objection or other rights), it will forward it to the Client without responding on its own. Percus will help the Client respond to such requests within [●] business days, including deleting the analytics events linked to a pseudonymized identifier when the Client requires it.
11. Return and deletion of data
When the agreement ends, and within the following 30 days, Percus will:
- Deliver to the Client, on request, the information Percus stores on its behalf (configuration, templates and analytics) in a downloadable format.
- Delete that information from its systems and issue a certificate of deletion.
Backups are deleted automatically when their 30-day retention period ends. Personalization data delivered by API needs no deletion, because Percus does not store it.
12. Audit
Percus will make available to the Client the information needed to demonstrate compliance with this addendum, including the executive summary of independent penetration tests under a non-disclosure agreement. The Client, or an auditor it appoints, may carry out an audit [●] (for example, once a year), with at least 30 days' notice, during business hours and without disrupting the service.
13. Contact
For questions about this addendum or the processing of personal data:
Email: security-compliance@percus.cl Company: Percus SpA, Santiago, Chile