Chile — ANX-CL: Processing Mandate and Contract, with International Transfer Clauses
Document ID: ANX-CL · Version: 1.0 · Effective date: [[TO CONFIRM: publication date, which must precede 1 December 2026]]
Language: Spanish controls (es/annex-cl.md: "Mandato y Contrato de Encargo, con Cláusulas de Transferencia Internacional"). This English text is a convenience translation.
Applies to: Clinics established in the Republic of Chile. Part of the Master Data Processing Agreement (the "MDPA"). Terms defined in the MDPA have the same meaning here.
1. Nature and timing
1.1 Until 30 November 2026. This Annex, together with the MDPA, is the written mandate under Article 8 of Law 19.628 on the Protection of Private Life ("Law 19.628"). By it, the Clinic, as responsable del registro o banco de datos, entrusts to VstreamX, as mandatary, the processing of the Clinic Data. It specifies the conditions of use of the data, which VstreamX must respect.
1.2 From 1 December 2026. This Annex, together with the MDPA, is also the contract between the responsable (the Clinic) and the encargado (VstreamX) under Article 15 bis of Law 19.628 as amended by Law 21.719 ("the amended Law"). It meets the international transfer requirements of Articles 27 and 28 of the amended Law.
1.3 Postponement. If the entry into force of Law 21.719 is postponed, clause 1.2 takes effect on the new date.
2. Content required by Article 15 bis
| Element | Content |
|---|---|
| Object | The processing of the Clinic Data by VstreamX to provide DentalX to the Clinic. |
| Duration | The term of the Clinic's use of the Service, followed by the periods in MDPA clause 14. |
| Purpose | As MDPA Schedule 1 states. VstreamX processes the data only on the Clinic's instructions (MDPA clause 3). |
| Type of personal data | As MDPA Schedule 1 states, including sensitive data concerning health. |
| Categories of data subjects | As MDPA Schedule 1 states, including children and adolescents. |
| Rights and obligations of the parties | The MDPA and this Annex. |
3. Obligations of the encargado
VstreamX:
- (a) processes the data only in accordance with the Clinic's instructions;
- (b) does not process the data for a different purpose, and does not communicate or transfer it, except to the authorised Sub-processors (clause 4) or where the law requires it. If VstreamX processed the data for its own purposes, it would be considered responsable for that processing, and would be jointly and severally liable with the Clinic for the resulting infringements (Art. 15 bis);
- (c) keeps the data confidential, and binds its personnel to that duty, which survives the end of the contract (MDPA clause 5);
- (d) applies the security measures in MDPA Schedule 2;
- (e) assists the Clinic in responding to data subjects' rights (clause 6) and in reporting security breaches (clause 7);
- (f) at the end of the service, returns the data to the Clinic through the complete export, and then deletes it as MDPA clause 14 provides; and
- (g) makes available to the Clinic the information needed to demonstrate compliance, and allows audits (MDPA clause 12).
4. Sub-processors: written authorisation
4.1 Authorisation. The Clinic gives its written authorisation to the Sub-processors named in MDPA Schedule 3, each with its service and location.
4.2 Obligations. Each Sub-processor is bound by the same obligations as VstreamX. VstreamX remains responsible to the Clinic for them.
4.3 Changes. Changes follow MDPA clause 7. For a Clinic in Chile, the authorisation of a new Sub-processor is given in writing in the Service.
5. International transfer clauses
5.1 The transfer. From 1 December 2026, the communication of the Clinic Data to VstreamX in Canada, and onward to the Sub-processors in the United States and other countries, is an international transfer under Article 27 of the amended Law, unless the Agency for the Protection of Personal Data (the "Agency") determines otherwise [[TO CONFIRM: whether the Agency's practice treats storage by a foreign encargado as a transfer]]. The Parties adopt the following contractual clauses as the guarantee required by Article 27.
5.2 Commitments of VstreamX, as recipient. VstreamX:
- (a) Purpose: processes the data only for the purposes in MDPA Schedule 1;
- (b) Security: applies the measures in MDPA Schedule 2, appropriate to sensitive health data;
- (c) Onward transfers: makes onward transfers only to the Sub-processors in MDPA Schedule 3. Each is under obligations that ensure a level of protection equivalent to these clauses;
- (d) Rights: enables the data subjects, through the Clinic, to exercise their rights of access, rectification, suppression, opposition, portability and blocking (clause 6);
- (e) Public authorities: applies MDPA clause 16 to any request for access by a public authority;
- (f) Laws of the destination: declares that, after the assessment summarised in the assessment pack (MDPA clause 13.5), it has no reason to believe that the laws applicable to it prevent it from complying with these clauses. If that changes, it informs the Clinic without delay. In that case the Clinic may suspend the transfer and terminate the affected service with export;
- (g) Supervision: accepts that the Agency may supervise compliance with these clauses, and cooperates with it; and
- (h) Liability: is liable to the Clinic for damage caused by its breach of these clauses. The limitation of liability in the Terms does not limit liability that the amended Law makes joint and several (MDPA clause 17.2(b)).
5.3 Third-party beneficiaries. Data subjects may enforce clauses 5.2(a), (d), (e) and (h) against VstreamX as third-party beneficiaries, to the extent Chilean law allows it.
5.4 Agency model clauses. When the Agency approves standard contractual clauses, the Parties will adopt them in place of clause 5.2, as MDPA clause 18.4 provides.
6. Rights of data subjects
VstreamX assists the Clinic within 5 business days (MDPA clause 8), so that the Clinic can answer data subjects within the periods of the amended Law.
7. Security breaches
7.1 Notice to the Clinic. VstreamX notifies the Clinic within 24 hours of establishing a breach of the security measures affecting the Clinic Data (MDPA clause 9).
7.2 What the Clinic must do. From 1 December 2026, the Clinic must report such breaches to the Agency. Where the breach concerns sensitive data, such as health data, the Clinic must also inform each affected data subject, in clear and simple language. VstreamX provides the information it holds for those notices.
8. Clinical records
8.1 Access. Under Law 20.584 on the rights and duties of patients, access to the clinical record is limited to the persons directly involved in the patient's care, and to the other persons the law allows. The Clinic configures the roles in the Service to that effect.
8.2 Retention. The clinical record must be kept for at least 15 years. DentalX does not auto-delete clinical records. At the end of the service, the export allows the Clinic to keep them.
9. Applicable law
Law 19.628, as amended, applies to the processing of the Clinic Data whatever law governs the commercial relationship under MDPA clause 23.
Items to confirm before publication (Chile)
- The publication date, which must precede 1 December 2026, and the status of the postponement bill (Boletín 18.623-07).
- Whether the Agency's practice treats storage by a foreign encargado as an international transfer (§5.1).