What we store and why
NAVEO is built following the principles of Chilean personal data protection law: purpose, minimisation, security, limited retention and the rights of individuals.
Data we store
| Data | What for | How long |
|---|---|---|
| Email address | To identify you and send your reports | While you have an account |
| Name | To address you. Optional | While you have an account |
| Company details | To identify the organisation in the report | While you have an account |
| Declared consumption | To calculate your footprint | While you have an account |
| Supporting documents | Traceability of each figure | While you have an account |
| IP and login attempts | To protect your account from unauthorised access | 90 days |
We do not store card details. When charging is active, payment is processed by Flow and NAVEO only receives the confirmation.
Your rights
- Access. Request a copy of what we hold about you
- Rectification. Correct anything that is wrong
- Erasure. Ask us to delete your account and your data
- Portability. Receive your data in a reusable format
hola@naveo.cl — stating which of these rights you want to exercise. It is logged and we confirm once it is done.
Security
These are the measures that are implemented today:
- The whole site runs over HTTPS
- Passwords are stored hashed, never in plain text
- Documents live outside the public folder and are only served after permission checks
- Each organisation is isolated from the others at database level
- Administrative actions are logged
We do not claim encryption at rest or "100% secure". We list only what is actually implemented and can be demonstrated.
Third parties
NAVEO uses these external services:
- Hostinger — site and database hosting
- Make — automations and recommendations. Receives totals, sector, region and size. Does not receive company name, tax ID, emails or documents
- Flow — payments, once charging is active
- Google Fonts — site typefaces