Last updated: August 26, 2026 — Version 1.0
This Privacy Policy and Personal Data Processing Policy sets out how SINTESIS S.A., hereinafter "BRIZEN", collects, uses, stores, discloses, protects and, where applicable, deletes or anonymizes the personal data of people who interact with BRIZEN through its websites, reservation system, Property Management System (PMS), communication channels, properties, booking and stay processes, and other related services. BRIZEN recognizes every person's right to the protection of their personal data and adopts measures intended to ensure that such processing is lawful, fair, transparent, and proportionate. This Policy is formulated with particular regard to Law No. 21.719, which regulates the protection and processing of personal data and creates the Personal Data Protection Agency. Law No. 21.719 requires the data controller to permanently keep available a processing policy identifying, among other elements, the controller, the categories of data processed, the purposes, the lawful bases, the recipients, the security measures, the retention periods, and the rights of data subjects.
The controller responsible for the processing of personal data is SINTESIS S.A. (RUT 96.665.810-K), with registered address at Av. Alfredo Barros Errazuriz 1954, of. 1303, Chile. For inquiries, requests, or the exercise of rights related to personal data, data subjects may contact administracion@brizen.cl. SINTESIS S.A. may appoint a Data Protection Officer where required under applicable law.
This Policy applies to the personal data of individuals who interact with BRIZEN, including: • Guests and travelers • People who make or request a reservation • Guest companions • People requesting information about our properties • Website users • People who contact BRIZEN by email, WhatsApp, or other channels • Representatives or contacts of companies that book accommodation • People involved in administrative, commercial, or billing processes related to BRIZEN When a person provides personal data belonging to third parties, they represent that they hold the authority necessary to do so and undertake, where applicable, to inform those third parties of such processing.
Depending on the relationship with BRIZEN and the specific purpose, we may process the following categories of data. Identification data: first and last name, nationality, date of birth, ID document or passport number, information necessary to verify identity, signature where applicable. Contact data: email address, phone number, address, country or city of residence, contact details associated with a reservation. Booking and stay data: check-in and check-out dates, unit booked, number of guests, preferences or requests related to the stay, booking and stay history, information necessary to manage changes, cancellations, and no-shows, communications related to the stay. Payment and billing information: payment method used, information necessary to verify or process a payment, payment status, billing data, tax information where applicable, transaction records associated with a reservation. BRIZEN does not need to directly store complete bank card data when payment processing is carried out by a specialized provider; in those cases, processing will be governed by that provider's own terms and privacy policies. Data derived from communications: information contained in communications made with BRIZEN through enabled channels, when necessary to manage a reservation, provide the service, resolve requests, maintain operational records, or exercise or defend legal rights. Technical and browsing data: IP address, browser type and version, device, operating system, date and time of access, pages or features used, technical information necessary for the site's security and operation. The use of cookies or similar technologies is also governed by the site's corresponding settings and, where necessary, by consent mechanisms.
BRIZEN does not deliberately request or process sensitive personal data for ordinary commercial purposes. Data concerning health, biometrics, sex life, sexual orientation, gender identity, ethnic or racial origin, religious beliefs, and political, union, or trade affiliations, and other categories considered sensitive under applicable law, will only be processed when a lawful basis permits it and strictly to the extent necessary for the corresponding purpose.
Personal data may be obtained: • Directly from the data subject • When making a reservation • When completing forms • During the check-in process • Through communications with BRIZEN • Through booking platforms or channels used by the guest • Through providers that legitimately take part in delivering the service • From publicly available sources, where applicable and in accordance with applicable law
BRIZEN processes personal data for the following purposes. Reservation management: receiving and managing booking requests, confirming reservations, checking availability, managing date changes, managing cancellations and no-shows, administering rates, charges, and reservation conditions, and keeping records associated with the reservation. Delivering the stay: managing check-in and check-out, facilitating access to the unit, providing information necessary for the stay, handling guest requests, coordinating operational matters, providing support during the stay, and managing incidents related to the accommodation. Payments and administration: processing and verifying payments, managing charges, issuing tax documents where applicable, reconciling transactions, managing refunds, keeping accounting and financial records, and complying with tax, accounting, and legal obligations. Service-related communications: we may use contact data to send communications that are necessary or reasonably related to a reservation or stay (confirmations, arrival instructions, check-in/check-out information, booking changes, operational notices, payment communications, and responses to inquiries or incidents). These communications are part of the service and are not necessarily commercial communications. Security and incident prevention: protecting the safety of guests, staff, and third parties, detecting misuse, preventing fraud, investigating incidents, protecting IT systems, and exercising or defending legal rights. Compliance with legal obligations: data may be processed when necessary to comply with legal obligations or valid requests from competent authorities. Law No. 21.719 provides, among other lawful bases, compliance with legal obligations and the conclusion or performance of contracts. Service improvement: BRIZEN may use aggregated, statistical, or anonymized information to analyze how its services perform, improve processes, detect issues, and develop enhancements. Once information has been effectively anonymized in accordance with applicable law, it ceases to be considered personal data.
BRIZEN does not process personal data indiscriminately. Each processing activity must have a lawful basis appropriate to its purpose. Depending on the case, processing may be based on: • The performance or preparation of an accommodation contract • Compliance with legal obligations • The data subject's consent • The legitimate interests of BRIZEN or third parties, when these do not override the data subject's rights and freedoms • The establishment, exercise, or defense of legal claims • Other lawful bases contemplated under applicable law When BRIZEN requests consent, it will be freely given, informed, specific, prior, and unambiguous, and may be withdrawn using means equivalent to those used to grant it. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
BRIZEN may send commercial or direct marketing communications only when a lawful basis permits such processing. Where processing is based on consent, the person may withdraw it at any time. Communications strictly necessary to manage a reservation, contract, payment, stay, security matter, or guest request are not considered commercial communications merely because they are sent through an electronic channel.
BRIZEN may disclose or grant access to personal data, only when a purpose and lawful basis justify it, to the following categories of recipients: • Technology providers that render services to BRIZEN • Reservation system providers • Booking distribution or intermediation platforms • Payment processing providers • Billing or accounting service providers • Technology infrastructure and storage providers • Communications providers • Providers necessary for the operation and security of the properties • Professional advisors bound by confidentiality duties • Public authorities where there is a legal obligation or power to do so Third parties acting as data processors must process data in accordance with SINTESIS S.A.'s instructions and for the contracted purposes. SINTESIS S.A. will not sell its guests' or users' personal data to third parties.
When a person books through an external platform, that platform may process their personal data as an independent controller, in accordance with its own policies and terms. BRIZEN will process the data it legitimately receives from those platforms to manage the reservation, provide the accommodation, and fulfill the purposes described in this Policy. Where applicable, BRIZEN may disclose data to third parties to perform the accommodation contract or comply with legal obligations.
Some technology providers used by BRIZEN may store or process personal data outside of Chile. Where an international transfer takes place, SINTESIS S.A. will seek to carry it out in accordance with the rules established under applicable Chilean law. Law No. 21.719 provides for international transfers to countries with adequate levels of protection and mechanisms intended to provide adequate safeguards where applicable. Where applicable, BRIZEN will disclose the existence of international transfers, the country or territory involved, and the applicable safeguards.
SINTESIS S.A. will retain personal data only for as long as necessary to fulfill the purposes for which it was collected, provide the contracted services, comply with legal obligations, resolve disputes, exercise or defend legal rights, and keep the records legitimately required. Once the purposes have been fulfilled and the applicable retention periods have elapsed, SINTESIS S.A. will, as appropriate, delete the data, anonymize it, or retain it where a legal obligation or basis permits or requires this. Specific retention periods may vary depending on the category of information and its purpose.
SINTESIS S.A. adopts technical and organizational measures intended to protect personal data against unauthorized access, loss, destruction, alteration, leakage, unlawful processing, and misuse. Security measures are determined by considering the nature of the data, the purposes of processing, the associated risks, available technology, and the necessary resources. Law No. 21.719 contemplates measures such as encryption, pseudonymization, recovery mechanisms, and periodic evaluation of the measures implemented. Internal access to personal data is limited to people who need it to perform their duties. Anyone with access to personal data is bound by confidentiality obligations, even after their relationship with SINTESIS S.A. ends.
SINTESIS S.A. maintains procedures to detect, manage, and mitigate incidents that could compromise personal data. When a security breach occurs that poses a reasonable risk to the rights and freedoms of data subjects, SINTESIS S.A. will act in accordance with the applicable legal obligations regarding notification and reporting. Law No. 21.719 establishes reporting obligations for certain security breaches and, in some cases, direct notification to affected data subjects.
BRIZEN's website may use cookies and similar technologies necessary for technical operation, security, session management, usage analysis, experience improvement, performance measurement, and additional features. Where certain cookies require consent, it will be requested through the corresponding mechanisms. Users may manage cookies through the options available on the site or through their browser's settings.
BRIZEN may use automated processes for certain operational functions, such as availability, rate calculation, information classification, inconsistency detection, or internal management. BRIZEN does not intend to use personal data to make decisions based solely on automated processing that produce legal effects or significantly affect a person, unless a legal basis permits it and appropriate safeguards are adopted. Where applicable, BRIZEN will disclose the existence of automated decisions, the significant logic applied, and the consequences anticipated for the data subject.
In accordance with applicable law, data subjects may exercise, among others, the following rights: • Access to their personal data • Rectification of inaccurate, incomplete, or outdated data • Erasure of their data where applicable • Objection to certain processing • Temporary blocking of processing in the cases established by law • Portability of their data where legal requirements are met • Withdrawal of consent where processing is based on it Law No. 21.719 expressly recognizes the rights of access, rectification, erasure, objection, portability, and blocking.
Requests should be sent to administracion@brizen.cl. The forms or electronic mechanisms that BRIZEN makes available for this purpose may also be used. The request must allow the data subject to be identified and specify the right they wish to exercise, together with the information necessary to locate the data where applicable. SINTESIS S.A. may request reasonable identity verification to prevent personal data from being disclosed to an unauthorized person. Law No. 21.719 establishes mechanisms for data subjects to exercise their rights promptly, efficiently, and effectively.
Where applicable, data subjects may request the temporary blocking of their data or its processing while a request for rectification, erasure, or objection is being resolved. Law No. 21.719 provides for this right and sets out the conditions and timeframes applicable to its exercise.
Where the requirements established by law are met, data subjects may request a copy of the personal data they provided to BRIZEN in a structured, commonly used, electronic format. Portability applies in the cases and conditions established under Law No. 21.719.
BRIZEN does not direct its digital services to minors. When it is necessary to process the data of children or adolescents in connection with a reservation or stay, SINTESIS S.A. will apply the measures and lawful bases required under applicable law and will process only the data necessary for the corresponding purpose.
SINTESIS S.A. and anyone involved in the processing of personal data must maintain the confidentiality of the information they have access to. This obligation remains in force even after the relationship with the data subject has ended.
SINTESIS S.A. will seek to incorporate personal data protection by design and by default into its systems, processes, and features. This includes, among other measures: • Collecting only the data that is necessary • Limiting access • Establishing retention periods • Protecting data during storage and transmission • Assessing risks associated with new features • Avoiding processing that is incompatible with the purposes disclosed Law No. 21.719 expressly establishes the duty of privacy by design and by default.
SINTESIS S.A. may update this Policy when necessary due to legal, regulatory, technological, operational, or service-related changes. The version in force is always the one published on BRIZEN's website. When a change involves material modifications to the purposes or conditions of processing, SINTESIS S.A. will adopt the information or consent measures required under applicable law. The version in force will always identify its date and version number.
If a person believes that BRIZEN has infringed their rights regarding the protection of personal data, they may use the complaint mechanisms established under applicable law. Once Law No. 21.719 enters into force, data subjects may file a complaint with the Personal Data Protection Agency when a controller rejects or fails to timely respond to a request to exercise rights, under the terms established by law.
This Policy is in force as of August 26, 2026. For any aspects subject to provisions that enter into force after the publication of this Policy, SINTESIS S.A. will apply the legal provisions in force at each time and will adapt its processes and systems to the new obligations within the timeframes established by law.
Data controller identification
SINTESIS S.A.
RUT: 96.665.810-K
Registered address: Av. Alfredo Barros Errazuriz 1954, of. 1303, Chile
Email: administracion@brizen.cl
Website: brizen.cl
Version: 1.0 · Publication date: August 26, 2026
© 2026 Brizen Apartments — Santiago, Chile. All rights reserved.