What Regulations Does Chatfuel Comply With?
Chatfuel complies with major international and regional data protection regulations.
Last updated on
Overview
Chatfuel complies with major international and regional data protection regulations. Whether you operate in Europe, the US, or Latin America, we have the safeguards and documentation to support your compliance requirements.
International Standards
GDPR (European Union)
Chatfuel is fully compliant with the General Data Protection Regulation. We implement all required technical and organizational measures for lawful data processing, including data minimization, purpose limitation, and full support for data subject rights.
HIPAA-Aligned Safeguards (United States)
While Chatfuel is not a HIPAA-covered entity, we implement technical and administrative safeguards aligned with HIPAA standards — including encryption, access controls, audit logging, and breach notification procedures. Healthcare providers handling US Protected Health Information (PHI) can request a Business Associate Agreement (BAA).
Latin America
Healthcare data is classified as "sensitive personal data" under all applicable LATAM laws. Chatfuel processes such data strictly as a Data Processor under written agreements with healthcare providers (Data Controllers).
| Country | Regulation | Chatfuel Compliance |
|---|---|---|
| Brazil | LGPD (Lei 13.709/2018) | DPA with controller/processor roles; breach notification procedures |
| Mexico | LFPDPPP (2025 Edition) | Updated DPA with retention policies; DSR/ARCO procedures |
| Colombia | Ley 1581 + Resolucion 1995 | Security controls; retention policies; cross-border safeguards |
| Chile | Ley 19.628 (2024 Reform) | DSR procedures; data export; deletion protocols |
| Argentina | Ley 25.326 | Standard Contractual Clauses; GDPR-level security |
| Peru | Ley 29733 | Documented security controls |
Infrastructure Certifications
Our cloud providers hold the following certifications:
- ISO 27001 — information security management
- SOC 2 Type II — security, availability, and confidentiality controls
- HIPAA-eligible/compliant infrastructure
Available Documentation
We can provide the following documents upon request:
- Privacy Policy (English / Spanish / Portuguese)
- Terms of Use
- Data Processing Agreement (DPA) with Standard Contractual Clauses
- Subprocessor List
- Security Policies (7 comprehensive policies)
- Business Associate Agreement (BAA) for healthcare providers
Contact [email protected] for any compliance documentation.