Privacy Policy
Version 1.3.0 · in force since 2026-10-07
This policy describes how Nevalia («we», «the platform») collects, uses and protects your personal data, in compliance with Ley 19.628 (Protection of private life), Ley 21.719 (New Personal Data Protection Act), Ley 20.584 (Rights and duties of patients), DS 41/2012 MINSAL (retention of clinical records) and Ley 21.541 together with the MINSAL rules applicable to the provision of health services through telemedicine.
1. Data controller
Legal name: Clombi Studio SpA
Tax ID (RUT): 78.513.449-4
Domicile: Chile
Privacy contact: privacidad@nevalia.cl
Data Protection Officer (DPO): Appointed under Art. 50 of Ley 21.719. Enquiries to the same address.
Nevalia acts as data controller within the meaning of Art. 3(n) of Ley 21.719 in respect of registration, scheduling, payment, contact and platform log data. Health professionals are independent controllers in respect of the content of the clinical records they create about their patients (see section 4).
To exercise your ARCOP rights (Access, Rectification, Cancellation/Erasure, Objection and Portability) write to the address above. We respond within the periods set by Art. 34 of Ley 21.719 (30 business days, extendable).
2. Data we collect
2.1 Registration and profile data — patients
- Full name, email address, password (bcrypt hash).
- RUT, health insurance (previsión) and emergency contact. [REVISAR: confirmar en qué momento se piden, si son obligatorios u opcionales, qué datos incluye el contacto de emergencia y si la previsión debe tratarse como dato sensible]
- Date of birth, requested at registration to verify the minimum age and to determine whether a legal representative is required.
- Region and comuna (optional).
- Profile photo (optional, stored in Supabase Storage).
- Onboarding preferences: health and wellbeing areas of interest, subjective wellbeing level (1–10 scale), preferred session length, whether you have received professional care before. This data constitutes health and wellbeing status indicators and is treated as sensitive data under Art. 2(g) of Ley 19.628.
- Legal representative's details, only for patients aged 14 to 17: name, RUT, email address and relationship (mother, father or legal guardian), entered by the adolescent. To these is added the representative's consent (see 2.5). The professional treating the minor sees that they are a minor and the details of their representative (see section 5).
Legal basis: Performance of the contract (Art. 12(a) Ley 21.719) + explicit consent for health and wellbeing data (Art. 16 Ley 21.719), given through a mandatory checkbox during onboarding (see 2.5). For the legal representative's details: performance of the contract and the representative's consent in respect of the minor.
Retention — legal representative: the same as the patient's account (see section 8).
2.2 Registration and profile data — professionals
- Full name, email address, password (bcrypt hash).
- RUT.
- Professional licence number (registration with the Superintendence of Health), degree, specialty or field of practice (e.g. general medicine, psychology, psychiatry, nutrition, physiotherapy, speech therapy, occupational therapy, nursing, dentistry or another health specialty) and personal description.
- Profile photo (stored in Supabase Storage).
- Care modalities (online, in person or mixed), availability and fees.
- Public profile, visible in the directory of professionals. [REVISAR: confirmar qué campos del perfil son públicos]
- Bank details, to receive payments by bank transfer. [REVISAR: detallar qué datos bancarios se piden]
- Credentials for the payment gateways the professional connects, stored encrypted (see 2.7 and section 9).
- Subscription plan and the status of associated payments.
Legal basis: Performance of the contract (Art. 12(a) Ley 21.719). The licence number is public data, available in the registries of the Superintendence of Health and of the relevant professional associations. To verify the professional registration we query the Superintendence of Health, to which we send the professional's registration number or RUT (see section 7).
2.3 Scheduling and appointment data
- Date, time and duration of each scheduled appointment.
- Identifiers of the patient and the professional involved.
- Appointment status (pending, confirmed, cancelled, completed).
- Appointment modality (online or in person) and link to the Nevalia video room where applicable.
- Notes attached to the appointment and cancellation reason. [REVISAR: indicar quién redacta las notas y si pueden contener datos de salud]
- Notifications recorded by the platform (e.g. appointment notices and reminders).
Legal basis: Performance of the contract (Art. 12(a) Ley 21.719)
2.4 Clinical data (sensitive health data)
- Clinical records created by the treating professional: reason for consultation, relevant history, diagnosis, treatment plan and progress notes. The specific content varies according to the professional's specialty (e.g. nutritional record, physiotherapy protocol, medical diagnosis, psychological assessment, speech therapy plan, among others). Kept together with them are their history, their notes, the history of those notes and, if a record is closed, the reason for closing it.
- Stored encrypted with AES-256-GCM at application level, before being sent to the database. The encryption key is a server key, managed by the platform: for that reason Nevalia can decrypt this data, whereas the database provider cannot.
- Every access to a record is written to an audit log (userId, action, timestamp) under Art. 13(d) of Ley 20.584.
Special category: Health data — Art. 2(g) Ley 19.628 and Art. 16 Ley 21.719
Legal basis: Explicit consent of the data subject (Art. 16 Ley 21.719) + performance of the healthcare contract + legal obligation to keep a clinical record (Art. 12 Ley 20.584)
Retention: Minimum 15 years from the last clinical contact (Art. 12 Ley 20.584 + Art. 36 DS 41/2012 MINSAL), together with the record's history, its notes and the history of those notes. Clinical records are not deleted even if you request the erasure of your account.
2.5 Consent records
- Type of consent (terms and conditions, privacy, sensitive data, clinical consent, legal representative's consent, telemedicine, marketing, cookies, sharing with a professional) or of objection, and version of the accepted document.
- The professional before whom it was given, where applicable (as with clinical consent).
- Date and time it was given.
- IP address at the moment consent was given.
- User agent of the browser used.
- SHA-256 hash of the document text, to prove that exactly that version was accepted.
Legal basis — IP: Legitimate interest of the controller (Art. 13(b) Ley 21.719): the IP address is stored solely as non-repudiation evidence of the act of consent, to prove it before the Personal Data Protection Agency. It is not used for profiling or advertising.
Retention — IP: While the consent remains in force. Six months after consent is withdrawn, the IP is replaced by an HMAC-SHA256 fingerprint and the user agent is deleted. If you delete your account, consents and objections are kept without the IP or the user agent (see section 8).
When consents are requested:
- When you sign up: terms and conditions and privacy policy.
- During onboarding: a mandatory checkbox of consent to the processing of health data.
- On every booking: clinical consent before the professional you are booking with, and the terms and conditions and privacy policy again.
- When the account of an adolescent aged 14 to 17 is confirmed: the legal representative accepts the terms and conditions, the privacy policy and the informed consent to care, through a link received by email (see section 5).
- On entering the video call room: telemedicine consent, once for each published version of the terms; it is not requested on every entry.
Withdrawal of consents: you can withdraw a consent from the Privacy section of the platform. Doing so withdraws all of your consents of that type, not just one, and the withdrawal is recorded in the audit log.
2.6 Usage and security data
- API access logs (endpoint, timestamp, userId) with no clinical content, credentials or email addresses.
- Session tokens (JWT / refresh tokens): the access token is kept only in the browser's memory and is renewed automatically every 15 minutes; the refresh token is kept in an httpOnly cookie of the site (`nv_rt`), not accessible from JavaScript, valid for 30 days. Neither is stored in localStorage. The server keeps session tokens for up to 30 days after they expire (see section 8).
- Audit log of access to clinical records (userId, type of action, timestamp).
- The IP address and browser of every visitor to the site, which Google Fonts receives when loading the typefaces (see sections 7 and 13). [REVISAR: confirmar la base legal de este tratamiento; la alternativa es alojar las fuentes en el propio sitio para que Google no reciba esos datos]
Legal basis: Legitimate interest — platform security and compliance with legal obligations (Art. 13(b) Ley 21.719)
2.7 Payment data
- We do not store credit or debit card numbers. Card payments are processed by Transbank (Webpay and Oneclick), which is PCI-DSS Level 1 certified, and, when the professional connects them, by Flow.cl and Mercado Pago. With Webpay the card is entered at Transbank, which receives the amount and the purchase order.
- To charge the professional's subscription with Oneclick, Transbank receives the professional's card details. The platform stores, encrypted, the enrolment identifier that Transbank returns (`tbk_user`). [REVISAR: confirmar si la plataforma guarda además la marca o los últimos dígitos de la tarjeta]
- We store the transaction status (approved/declined), amount, date and the order identifier generated by the payment processor.
- We record the subscription charges the platform makes to the professional and the related invoices.
- When payment is made by bank transfer, the transfer receipt is stored, which contains the professional's bank details. [REVISAR: confirmar quién sube el comprobante y si contiene también datos bancarios o personales del pagador]
Legal basis: Performance of the contract + accounting and tax obligations (Tax Code and Art. 9 Ley 19.628)
Retention: Payment records, 6 years [REVISAR: verificar el fundamento legal (Código Tributario) de este plazo, citado en la sección 8]. Transfer receipts, 90 days. `tbk_user` of a card that has been removed, 30 days after the removal is confirmed.
2.8 Email invitations
- When a professional invites a patient by email, we temporarily store the invitee's email address, name and the invitation message until the patient accepts or the invitation expires. The invitation expires 7 days after it is sent or last resent.
- This data is not used for any purpose other than the invitation. If the invitation is not accepted, the email address, name and message are deleted when the period expires.
Legal basis: Legitimate interest of the professional in managing their patient base (Art. 13(b) Ley 21.719), on a temporary and proportionate basis
2.9 Reviews
- Reviews are voluntary (opt-in): a review of a professional is published only if you decide to publish it.
- It is published with your name and the initial of your surname. [REVISAR: confirmar que la inicial es la del apellido]
- The review includes the rating you give the professional. [REVISAR: indicar los demás campos de la reseña, como un comentario]
Legal basis: Consent of the data subject, given when deciding to publish the review
Retention: When you delete your account, only the rating of the review is kept (see section 8).
2.10 Contact form and frequently asked questions (FAQ)
- When you write to us through the contact form or submit a question through the frequently asked questions, we ask for your email address and record your IP address, together with the content of your message or question. [REVISAR: indicar qué otros campos se piden, como el nombre]
- We use the email address to reply to you. [REVISAR: indicar la finalidad y el plazo de conservación de la IP]
Legal basis: Legitimate interest in handling the enquiries you send us
Retention: Contact messages, 12 months. Email address of whoever asks a question in the FAQ, 30 days after the question is closed, with a maximum of 6 months [REVISAR: confirmar desde cuándo se cuenta ese máximo].
3. Telemedicine and clinical consent
Nevalia is a healthcare management platform that supports the telemedicine modality. Using the service involves the processing of sensitive health data. Under Art. 14 of Ley 20.584, Ley 21.541 and the MINSAL rules on telemedicine, the patient gives the following consents, at the moments indicated (when each is requested and what is stored for each is set out in section 2.5):
- Informed consent for healthcare (clinical consent): given on every booking, before the professional with whom the booking is made. It means accepting that that professional creates and maintains a clinical record with information about their health status, diagnosis and treatment, the content of which varies according to the treating professional's specialty. For patients aged 14 to 17, the legal representative also accepts the informed consent to care when confirming the account (see section 5).
- Consent for telemedicine: given on entering the video call room, once for each published version of the terms; it is not requested on every entry. It means accepting that care is provided remotely by video call, acknowledging the characteristics, advantages and limitations of this modality compared with in-person care, under Ley 21.541 and the MINSAL rules in force.
Each consent is recorded with the elements listed in section 2.5 of this policy, constituting evidence of compliance with the duty to inform required by Art. 10 of Ley 20.584.
Google Calendar (only where applicable): if the professional has connected their Google Calendar, the session is recorded as an event in that calendar. The event includes no patient data: it carries only the title «Sesión Nevalia», the time and the link to the room (or the venue, if care is in person), and has no guests. For that reason Google does not receive the patient's name or email address through this channel. Connecting Google is optional for the professional and is not a requirement for care.
Important: Nevalia is a technology platform, not a healthcare establishment. The professionals operating on it are independent providers responsible for the quality, appropriateness and timeliness of their clinical care. Nevalia does not intervene in diagnostic or therapeutic decisions.
Video calls take place in the Nevalia video room. Audio and video travel directly between the browsers of patient and professional over WebRTC, encrypted end to end (DTLS-SRTP): they do not pass through Nevalia's servers. Nevalia does not record or store the content of sessions.
To connect directly, each browser needs the other's public IP address, so patient and professional may learn each other's. That address allows, at most, an approximate location to be inferred, such as the city or the internet provider.
When a direct connection is not possible —because of the type of network one of the participants is on— the traffic is relayed through a Cloudflare TURN server. That server forwards already encrypted traffic and cannot access its content; it does process the IP addresses needed to establish the connection.
4. Processing of data by the professional
The health professional who treats the patient through Nevalia acts as an independent data controller in respect of the content of the clinical records they create, modify and consult, within the meaning of Art. 3(n) of Ley 21.719.
The professional is subject to the confidentiality obligations imposed by Art. 5 of Ley 20.584 (secrecy of clinical information), the Health Code and the sectoral health rules applicable to their specialty. In particular:
- Physicians and specialists: bound by medical secrecy under the Code of Ethics of the Chilean Medical Association and Art. 247 of the Criminal Code.
- Psychologists: bound by the duty of confidentiality of the Code of Ethics of the Chilean Association of Psychologists, which protects all information obtained in the context of the therapeutic relationship.
- Psychiatrists: bound simultaneously by medical secrecy and by the applicable specific mental health protection provisions.
- Nutritionists, physiotherapists, speech therapists, occupational therapists, nurses and dentists: bound by the confidentiality duties established by their respective professional associations and by Art. 5 of Ley 20.584.
The professional may only access a patient's clinical record in the context of an active care relationship. Any access is written to the platform's audit log.
Nevalia acts as a data processor in respect of the infrastructure that stores the clinical records. Their content is stored encrypted with a server key managed by the platform, so Nevalia can decrypt it; the database provider cannot. [REVISAR: confirmar si existe una política interna que restrinja el acceso del personal de Nevalia al contenido de las fichas; solo en ese caso puede afirmarse que Nevalia no accede a él]
If the professional closes their account, the clinical records remain stored and accessible to the patient for the minimum 15-year period required by DS 41/2012 MINSAL. Of a professional who has clinical records, their name, RUT and registration number with the Superintendence of Health are kept, and are no longer shown on their public profile.
5. Minors
Nevalia serves people from the age of 14. To that end, the date of birth is requested at registration and accounts of people under 14 are rejected: we do not knowingly collect personal data from children under 14.
For adolescents aged 14 to 17, care requires a legal representative and works as follows:
- The account is pending authorisation. The adolescent enters the name, RUT, email address and relationship of their legal representative (mother, father or legal guardian).
- The representative receives an email with a link. There they read the terms and conditions, the privacy policy and the informed consent to care, and accept them. That acceptance is recorded as the representative's consent, with the version, the hash of the text, the IP, the user agent and the date (see 2.5).
- Until the representative confirms, the adolescent cannot book.
- The professional sees that their patient is a minor and the details of their representative.
If we detect that data has been collected from a child under 14, we will delete that data immediately. Contact us at privacidad@nevalia.cl.
6. What we use your data for
- Create and manage your user or professional account.
- Verify age at registration and, for patients aged 14 to 17, manage the legal representative's authorisation.
- Enable appointment scheduling between patients and professionals across specialties.
- Enable the video room for each session when care is provided by telemedicine.
- Record the session in the professional's Google Calendar, only if they have connected it.
- Allow professionals to create and manage clinical records for their patients according to their specialty.
- Process payments for healthcare (through Webpay and, when the professional connects them, Flow and Mercado Pago).
- Manage professionals' subscriptions, including the Oneclick charge.
- Verify the professional registration by querying the Superintendence of Health.
- Publish your review of a professional, only if you decide to do so.
- Reply to messages sent through the contact form and the frequently asked questions.
- Send appointment notifications, reminders and service-related communications.
- Send patient invitations requested by the treating professional.
- Comply with legal obligations: retention of clinical records, consent records, audit logs and tax obligations.
- Improve the platform through anonymised usage metrics, excluding clinical data and personally identifiable information.
- Send marketing communications and service news, only if you have given explicit consent for it (revocable at any time).
We do not sell, rent or transfer your personal data to third parties for commercial purposes.
7. Providers and international transfers
To operate the platform we share data with the following providers and third parties, acting as data processors (Art. 3(ñ) Ley 21.719), subject to contractual confidentiality and security obligations [REVISAR: confirmar la calificación jurídica (encargado o responsable independiente) de las pasarelas de pago, de la Superintendencia de Salud y de Google Fonts, que no necesariamente actúan por cuenta de Nevalia]:
| Provider | Purpose | Data it receives | Country | Safeguard |
|---|---|---|---|---|
| Supabase Inc. | Database (PostgreSQL) and file storage | The data the platform stores (account, scheduling, consents, payments, audit), the clinical records already encrypted, and the files uploaded, such as the profile photo | USA / São Paulo (BR) | DPA + SCCs (Art. 27 Ley 21.719) |
| Render.com | Hosting of the API server (NestJS) and of the frontend (Next.js) | The data that passes through the platform's server and website | USA | DPA + SCCs (Art. 27 Ley 21.719) |
| Google LLC | Sign-in with Google (OAuth) and calendar sync (Google Calendar) | Sign-in: name, email and photo. Calendar, only if the professional connected it: the title «Sesión Nevalia», the time and the link to the room or the venue, with no guests or patient data | USA | DPA + SCCs (Art. 27 Ley 21.719) |
| Google Fonts (Google LLC) | Loading of the site's typefaces | IP address and browser of every visitor | USA | [REVISAR: confirmar la garantía de transferencia aplicable] |
| Cloudflare, Inc. | STUN/TURN servers to establish and relay the video call | The IP address and the connection; not the content, which travels encrypted | USA | DPA + SCCs (Art. 27 Ley 21.719) |
| Transbank (Webpay) | Card payment processing | Amount and purchase order; the card is entered at Transbank | Chile | PCI-DSS Level 1 |
| Transbank (Oneclick) | Charging the professional's subscription to an enrolled card | The professional's card details | Chile | PCI-DSS Level 1 |
| Flow.cl (only if the professional connects it) | Alternative payment processing | [REVISAR: confirmar qué datos se envían; en Webpay son el monto y la orden de compra] | Chile | PCI-DSS |
| Mercado Pago (only if the professional connects it) | Alternative payment processing | [REVISAR: confirmar qué datos se envían] | [REVISAR: confirmar la entidad y el país] | [REVISAR: confirmar la garantía aplicable] |
| Resend Inc. | Notification delivery and email verification | Email address and name of the recipient and the content of each email | USA | DPA + SCCs (Art. 27 Ley 21.719) |
| Superintendence of Health | Verification of the professional registration | The professional's registration number or RUT | Chile | Chilean public authority; no international transfer |
International transfers: Transfers to providers located in the USA are made under Art. 27 of Ley 21.719, through Data Processing Agreements (DPAs) incorporating Standard Contractual Clauses as the adequate safeguard mechanism. Clinical data stored in Supabase is encrypted with AES-256-GCM at application level, with a server key of the platform, so the database provider cannot decrypt its content.
Data hosted in Supabase's São Paulo (BR) region falls under the jurisdiction of the Lei Geral de Proteção de Dados — LGPD (Brazil), which recognises protections equivalent to those of Ley 21.719.
8. Retention periods
- Account data (profile, preferences): while the account is active. The account is anonymised automatically 30 days after you request its deletion, through a daily automatic process, except for what we must keep as set out below. [REVISAR: confirmar qué ocurre durante esos 30 días, por ejemplo si la cuenta queda bloqueada y si la solicitud puede cancelarse]
- Clinical data (records): minimum 15 years from the last clinical contact (Art. 12 Ley 20.584 + Art. 36 DS 41/2012 MINSAL), together with the record's history, its notes and the history of those notes. Not deleted with the account.
- Health and wellbeing onboarding data: while the account is active; deleted together with the account data when the account is deleted (see below).
- Legal representative's details (patients aged 14 to 17): the same retention as the patient's account.
- Consent and objection records: while the consent remains in force. Six months after consent is withdrawn, the IP is replaced by an HMAC-SHA256 fingerprint and the user agent is deleted. If the account is deleted, they are kept without the IP or the user agent.
- Audit logs (access to records): 6 years, aligned with the limitation periods for medical and healthcare liability. Entries cannot be modified, and only those older than 6 years are deleted.
- API access logs: 2 years, then deleted or anonymised. [REVISAR: este plazo ya estaba declarado, pero no figura entre los hechos verificados contra el código; confirmarlo con la configuración real de logs]
- Payment records: 6 years (Art. 200 of the Tax Code — limitation period of the Chilean Internal Revenue Service). [REVISAR: verificar que la cita del Código Tributario sea el fundamento correcto de este plazo]
- Transfer receipts: 90 days.
- Card enrolment identifier (`tbk_user`) of a card that has been removed: 30 days after the removal is confirmed.
- Unaccepted invitations: they expire 7 days after being sent or last resent; when they expire, the invitee's email address, name and message are deleted.
- Contact form messages: 12 months.
- Email address of whoever asks a question in the FAQ: 30 days after the question is closed, with a maximum of 6 months.
- Notifications: 180 days.
- Email verification and password recovery tokens: 7 days after they expire or are used.
- Session tokens: 30 days after they expire.
What happens when you delete your account
What is kept:
- The account's internal identifier.
- Clinical records, their history and their notes.
- Of a professional who has clinical records: their name, RUT and registration number with the Superintendence of Health, which are no longer shown on their public profile.
- Consents and objections, without the IP or the user agent.
- Audit logs.
- Appointments, without notes or cancellation reason.
- Payments (transfer receipts are deleted).
- The platform's invoices and charges.
- Reviews, only the rating.
[REVISAR: indicar el plazo y el fundamento de conservación de las citas, de la nota de las reseñas y de las facturas y cobros de la plataforma]
What is deleted:
- Your identification and contact details, and your photo.
- Health answers from onboarding, the RUT (except that of a professional who has clinical records), health insurance and emergency contact.
- The legal representative's details, if any.
- Notifications, contact messages, the email address in the FAQ and invitations.
- The public profile and bank details.
In addition:
- Google Calendar events are anonymised and access to Google is revoked.
- Sessions are closed.
9. Data security
Nevalia applies technical and organisational measures to ensure the confidentiality, integrity and availability of the data, in compliance with Art. 14 quáter of Ley 21.719:
- Clinical records, notes and histories, Google tokens, payment gateway credentials, card enrolment identifier (`tbk_user`) and the reason for closing a record, encrypted with AES-256-GCM at application level (before reaching the database), with a server key managed by the platform. The platform can decrypt them; the database provider cannot.
- Passwords stored exclusively as a bcrypt hash with cost factor 12; the password is never stored or transmitted in plain text.
- Reset and email verification tokens stored as a SHA-256 hash; the plain-text token travels only once by email and expires after 24 hours.
- Communications encrypted with TLS 1.2 or higher (HTTPS mandatory on all endpoints).
- Short-lived session tokens (JWT, 15 minutes) with automatic rotation via refresh tokens: the access token only in memory and the refresh token in an httpOnly cookie; neither in localStorage.
- Immutable audit log of every access to clinical records (userId, action, timestamp).
- Role-based access control: a professional cannot access the record of a patient who is not theirs.
Security breach notification: In the event of a security breach affecting personal data, we will notify the affected data subjects and the Personal Data Protection Agency within the periods required by Art. 14 ter of Ley 21.719 (72 hours from becoming aware of the breach to notify the Agency; a reasonable period to notify data subjects depending on severity).
10. Your rights (ARCOP + portability)
Under Arts. 11 and 14 of Ley 19.628 and Arts. 33 to 45 of Ley 21.719, you have the right to:
- Access (Art. 33 Ley 21.719): know what personal data we process about you and for what purpose. Available in Settings → Privacy → Download my data.
- Rectification (Art. 36 Ley 21.719): correct inaccurate, incomplete or outdated data.
- Erasure / Cancellation (Art. 37 Ley 21.719): request the deletion of your account and personal data when it is no longer necessary for the purpose that justified its processing. Clinical data is retained by legal obligation; section 8 sets out which other data is kept and which is deleted when the account is deleted.
- Objection (Art. 38 Ley 21.719): object to processing for specific purposes such as marketing or statistical analysis. Processing ceases unless there is a legitimate ground justifying it.
- Portability (Art. 39 Ley 21.719): receive your data in a structured, commonly used and machine-readable format (JSON), to transmit it to another controller.
- Restriction of processing / blocking (Art. 40 Ley 21.719): request the temporary suspension of processing while a rectification or objection request is verified.
- Withdrawal of consents: withdraw at any time the consents you have given, from the Privacy section of the platform (see 2.5).
To exercise any of these rights go to Settings → Privacy and personal data within the platform, or write to us at privacidad@nevalia.cl. We respond within a maximum of 30 business days, extendable by a further 15 business days where complexity justifies it (Art. 34 Ley 21.719). Exercising these rights is free of charge.
11. Additional rights as a patient (Ley 20.584)
In addition to the ARCOP rights, as a patient treated on Nevalia you have specific rights regarding your clinical information, recognised by Ley 20.584:
- Access to your clinical record (Art. 12 Ley 20.584): you may request a copy of your clinical record at any time. The professional or the platform must provide it within 15 business days.
- Confidentiality of clinical information (Art. 5 Ley 20.584): the information in your clinical record is strictly confidential and may only be shared with third parties with your express consent, or in the cases exceptionally provided for by law (imminent risk to life, legal obligation).
- Information on diagnosis and treatment (Art. 8 Ley 20.584): you have the right to be informed of your diagnosis, therapeutic options and their risks, in understandable terms, regardless of the specialty of the professional treating you.
- Refusal of treatment (Art. 14 Ley 20.584): you may withdraw your clinical consent and refuse to continue a treatment at any time. Clinical consent is withdrawn from the Privacy section (see 2.5).
- Second opinion: you may consult another health professional, of the same or another specialty, without this affecting your clinical history on the platform.
- Non-discrimination (Art. 2 Ley 20.584): healthcare may not be denied on the grounds of economic, social or ethnic condition, gender, sexual orientation, disability, religion or any other category.
If you believe your rights as a patient have been infringed by a professional operating on Nevalia, you may file a complaint with the Superintendence of Health (www.supersalud.gob.cl) and/or with us at privacidad@nevalia.cl.
12. Supervisory authority and complaints
If you believe the processing of your personal data infringes Ley 21.719, you have the right to file a complaint with the Personal Data Protection Agency, the supervisory authority created by Ley 21.719 (Art. 57 et seq.):
- Web: www.agenciadatos.cl (once the Agency is operational under the implementation timetable of Ley 21.719)
- For infringements occurring before the Agency is fully operational: you may use the judicial procedure of Art. 16 of Ley 19.628 before the Civil Court of your domicile.
We always recommend contacting us first at privacidad@nevalia.cl to resolve any concern, as we undertake to respond within a maximum of 30 business days.
13. Cookies and local storage
The refresh token of your session is kept in a cookie of our own (nv_rt), marked httpOnly —not accessible from JavaScript—, with path `/api/session` and valid for 30 days. The access token is kept only in the browser's memory. No token is stored in localStorage.
The browser uses localStorage only to store basic profile data that the interface needs (your name and your roles), with no credentials.
We also store our own session cookie (ms_session), marked httpOnly and valid for 30 days. It is a signed marker and contains no tokens. Its purpose is to let the server recognise your session before serving you a private page, so that areas containing personal data are not rendered to someone who has not signed in. It is not shared with third parties and is deleted when you sign out.
We do not use third-party tracking cookies, Google Analytics, Facebook Pixel, or any advertising tracking script. We do not build browsing behaviour profiles.
We use session cookies that are strictly necessary to maintain the authentication state during navigation. These cookies are indispensable for the service to work and do not require prior consent under Art. 13(c) of Ley 21.719 (legitimate interest in system security).
When the site loads, each visitor's browser requests the typefaces from Google Fonts, so Google receives their IP address and browser (see section 7).
If in the future we implement analytics cookies or third-party functionality, we will update this policy and request your prior explicit consent, with the option to accept granularly by category.
14. Platform shutdown or discontinuation
Should Nevalia cease operations or the platform be discontinued, we undertake to:
- Notify you by email at least 60 days in advance of the effective shutdown.
- Make available a copy of all your personal data and clinical records in a portable format (JSON/PDF) during the notice period.
- Ensure that clinical data is transferred to a designated custodian or securely destroyed, in accordance with the obligations of DS 41/2012 MINSAL regarding the 15-year retention of records.
- In the event of an acquisition or merger with another company, personal data may only be transferred if the acquirer assumes the same obligations set out in this policy, and you will be notified beforehand.
15. Changes to this policy
When we make substantial changes to this policy (extension of purposes, new providers receiving sensitive data, new categories of data processed), we will notify you by email at least 15 days in advance of it taking effect and publish the new version on this same page.
Changes involving a use of your data for purposes incompatible with the original ones, or that extend the processing of sensitive health data, will require your explicit consent again before being applied.
Minor changes (spelling corrections, updates to contact details, clarity improvements that do not alter the substance) will be published directly. The effective date in the header will always reflect the version in force.
The version history of this policy is available on request at privacidad@nevalia.cl.
Privacy enquiries: privacidad@nevalia.cl
Applicable legal framework: Ley 19.628 · Ley 21.719 · Ley 20.584 · Ley 21.541 · DS 41/2012 MINSAL