Chatfuel

What Regulations Does Chatfuel Comply With?

Chatfuel complies with major international and regional data protection regulations.

Last updated on

Overview

Chatfuel complies with major international and regional data protection regulations. Whether you operate in Europe, the US, or Latin America, we have the safeguards and documentation to support your compliance requirements.


International Standards

GDPR (European Union)

Chatfuel is fully compliant with the General Data Protection Regulation. We implement all required technical and organizational measures for lawful data processing, including data minimization, purpose limitation, and full support for data subject rights.

HIPAA-Aligned Safeguards (United States)

While Chatfuel is not a HIPAA-covered entity, we implement technical and administrative safeguards aligned with HIPAA standards — including encryption, access controls, audit logging, and breach notification procedures. Healthcare providers handling US Protected Health Information (PHI) can request a Business Associate Agreement (BAA).


Latin America

Healthcare data is classified as "sensitive personal data" under all applicable LATAM laws. Chatfuel processes such data strictly as a Data Processor under written agreements with healthcare providers (Data Controllers).

CountryRegulationChatfuel Compliance
BrazilLGPD (Lei 13.709/2018)DPA with controller/processor roles; breach notification procedures
MexicoLFPDPPP (2025 Edition)Updated DPA with retention policies; DSR/ARCO procedures
ColombiaLey 1581 + Resolucion 1995Security controls; retention policies; cross-border safeguards
ChileLey 19.628 (2024 Reform)DSR procedures; data export; deletion protocols
ArgentinaLey 25.326Standard Contractual Clauses; GDPR-level security
PeruLey 29733Documented security controls

Infrastructure Certifications

Our cloud providers hold the following certifications:

  • ISO 27001 — information security management
  • SOC 2 Type II — security, availability, and confidentiality controls
  • HIPAA-eligible/compliant infrastructure

Available Documentation

We can provide the following documents upon request:

  • Privacy Policy (English / Spanish / Portuguese)
  • Terms of Use
  • Data Processing Agreement (DPA) with Standard Contractual Clauses
  • Subprocessor List
  • Security Policies (7 comprehensive policies)
  • Business Associate Agreement (BAA) for healthcare providers

Contact [email protected] for any compliance documentation.

On this page