Privacy Policy for USA
I. INTRODUCTION
Shaping Bots Corp. (hereinafter “Shaping Bots”) is a company primarily engaged in providing ChatBots and data analytics tools to businesses, especially those offering services or selling products directly to consumers.
Shaping Bots aims to strictly comply with current United States Personal Data protection regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), Children’s Online Privacy Protection Act (COPPA), Fair Credit Reporting Act (FCRA), and the Gramm-Leach-Bliley Act (GLBA), as applicable depending on the nature of the data collected and processed by our entity. The purpose is to protect personal information provided by Data Subjects connected to Shaping Bots, including partners, suppliers, clients, employees, collaborators, and any other natural person whose personal data Shaping Bots collects, processes, or handles, whether directly or through third parties on its behalf.
The Privacy Policy aims to safeguard the right of Habeas Data, allowing individuals to access, modify, and correct their data collected and stored in Shaping Bots databases. In accordance with this right, Shaping Bots only collects and processes personal and business data with explicit consent from the data subject, adopting strict measures to ensure the confidentiality and privacy of such information. Additionally, this policy establishes basic corporate principles for protecting personal and business data, describes the purposes for data processing, identifies the department responsible for handling complaints and claims, and outlines procedures to access, correct, or delete information and the means available for data subjects to exercise these rights.
II. DEFINITIONS
API: Connection established to exchange information between third-party systems and Shaping Bots. Authorization: Clear, voluntary, and informed consent given by the data owner to process their personal and business data. Privacy Notice: Notification provided to personal and business data owners, orally or in writing, informing them about applicable data handling policies. Personal and Business Database: Structured grouping of personal and business data processed by an entity or individual. ChatBot: Artificial intelligence solution operating through chat tools, enabling machine-user conversations. Database Custodian: Individual designated within the company to safeguard personal and business databases. Shaping Bots Clients: Companies providing products or services to consumers, utilizing technological tools provided by Shaping Bots. Business Data: Information related to or belonging to a business registered by an owner within Shaping Bots tools. Personal Data: Information related to or identifying a specific individual. Sensitive Data: Personal information concerning private aspects of the owner, whose mishandling could lead to discrimination, such as health, sexual orientation, ethnicity, political opinions, or religious beliefs. Private Data: Personal information of intimate or confidential nature significant to the owner. Semi-Private Data: Personal information of interest to the owner and certain groups or society, not considered intimate, confidential, or public. Public Data: Personal information defined as public by law or not classified as private or semi-private. Data Processor: Entity or person processing personal and business data on behalf of the Data Controller. Methods of Collecting Personal Data: Shaping Bots may collect and manage data according to its policy via: (i) Registration and use of its technological solutions; (ii) Registration and use of its website; (iii) Signing contracts, alliances, or agreements with Shaping Bots; (iv) Registering as a Shaping Bots provider. Habeas Data: Data subjects’ right to request access, modification, deletion, or correction of their data and restrict disclosure or transfer. Data Controller: Entity or individual deciding how and why to process personal data. Data Subject: Individual owning the processed data. Processing: Any action involving personal data, such as collecting, storing, using, disclosing, or deleting. Transmission: Sharing personal data with a third party, within or outside the U.S., for processing on behalf of the Data Controller. Transfer: Sending personal data to a recipient who is also responsible for its processing, within or outside the country. Users: Clients and potential clients of Shaping Bots’ clients interacting with technological solutions. Personal Data Breach: Actions defined as crimes under U.S. law involving unauthorized use of personal information for personal or third-party benefit.
III. GUIDING PRINCIPLES FOR PERSONAL DATA PROCESSING
Shaping Bots adheres to the following principles:
Legality: Processing personal data according to applicable U.S. laws, including HIPAA, COPPA, FCRA, and GLBA.
Purpose: Processing must have a legitimate and informed purpose.
Freedom: Processing only with prior, explicit, informed consent of the data subject.
Accuracy or Quality: Information must be truthful, complete, accurate, updated, verifiable, and understandable.
Transparency: Guaranteeing data subjects’ right to information about their data.
Security: Adopting necessary technical, human, and administrative measures to prevent unauthorized or fraudulent handling.
Confidentiality: Mandatory confidentiality of non-public personal data, even post-relationship.
Restricted Access and Circulation: Processing limited to authorized personnel.
IV. RIGHTS OF DATA SUBJECTS
Data subjects may exercise the following rights freely and without limitation:
Access to personal information processed.
Update of personal data processed.
Rectification of personal data.
Opposition to personal data processing.
Request deletion when processing violates legal principles, rights, or guarantees.
Request proof of consent granted.
Withdraw consent for data processing.
File complaints with competent U.S. authorities.
Be informed about data use, policy updates, security measures, and purposes.
V. DATA COLLECTION METHODS
Shaping Bots collects data through cookies, email exchanges, website access, platform registration, ChatBot conversations, phone calls, events, and strategic partner transmissions.
VI. PURPOSES OF PERSONAL DATA PROCESSING
Personal and business data is processed primarily to provide high-quality services, marketing, fraud prevention, compliance, customer satisfaction, internal operations, credit reporting, and business relationships, among other activities explicitly detailed in this policy.
VII. DATA SUBJECT AUTHORIZATION AND CONSENT
Data subject consent is mandatory and must be prior, explicit, and informed. Users must explicitly accept the terms to access Shaping Bots services.
VIII. ACCESS CHANNELS
Requests and complaints must be directed to [email protected] to exercise data rights.
IX. LEGAL PROCEDURE FOR CONSULTATIONS AND COMPLAINTS
Consultations and complaints require specific documentation and are processed within 10 to 15 business days, respectively, with possible extensions.
X. SENSITIVE PERSONAL DATA PROCESSING
Sensitive data is minimally collected, processed with explicit consent, and under strict security measures or legal exceptions.
XI. PERSONAL DATA OF MINORS
Shaping Bots does not knowingly process data from individuals under 18 years old.
XII. NATIONAL OR INTERNATIONAL DATA TRANSFER/TRANSMISSION
Data transfer/transmission follows strict regulations ensuring adequate protection levels, with international transfers requiring explicit consent or legal exceptions.
XIII. POLICY VALIDITY
Data is retained as required for purposes stated, with annual reviews. Shaping Bots reserves the right to modify this policy unilaterally.
XIV. SEVERABILITY
Invalid conditions under applicable law do not affect the remaining policy validity.
XV. APPLICABLE LAW
This policy is governed exclusively by U.S. law, with jurisdiction for disputes assigned to U.S. courts.
XVI. POLICY UPDATE
Policy changes may be communicated through standard communication channels used by Shaping Bots.