Record of processing
A summary of the observatory's personal data processing activities.
Version 1.5, of 4 October 2026. aGo lab is the controller for all processing.
In progress
Rights requests
| Field | Detail |
|---|---|
| Purpose | To receive, handle and answer requests for access, rectification, erasure, objection, portability and blocking |
| Lawful basis | Compliance with a legal obligation of the controller |
| Data | Name, email address, the details of the request, and the dates and text of its handling |
| Recipients | None |
| Retention | Four years from when the reply is sent, the limitation period for legal action over a breach of the law |
API keys
| Field | Detail |
|---|---|
| Purpose | To issue a consortium institution with an API key with a higher quota, and to write to it about the key |
| Lawful basis | The written agreement with the institution |
| Data | The institutional email address and an optional label |
| Recipients | None |
| Retention | While the key is active and for thirty days after it is deactivated |
Query limit
| Field | Detail |
|---|---|
| Purpose | To limit how many queries per minute the API receives and how many requests its forms receive, and to count how many queries the API receives each day and from how many distinct network origins, keeping for each day only the total of queries and the total of origins |
| Lawful basis | The controller’s legitimate interest in keeping the service available; for the daily count, legitimate interest for statistical purposes in the public interest |
| Data | A digest of the network address, computed with a key held only by the observatory; the address itself is not stored |
| Recipients | None |
| Retention | Deleted every day, once the day just ended has been counted; all that remains of each day is the total of queries and the total of origins |
Planned, not yet carried out
Export records by company
The National Customs Service export records by company, which may name a sole trader. They would be used only to calculate and check aggregates, without publishing or releasing any individual data, with the copy encrypted and the cells that cover very few companies suppressed. The observatory does not capture them until their impact assessment is signed.
Institutional dashboard accounts
Account access to the institutional dashboard for the people that consortium companies appoint. The observatory opens no account until the consortium has approved the text of the terms of use.
| Field | Detail |
|---|---|
| Purpose | To provide authenticated access to the dashboard, record acceptance of the terms of use and audit sign-ins and downloads |
| Lawful basis | Performance of the terms of use the person accepts, and the controller’s legitimate interest in secure access |
| Data | Username, email address, company, password hash, encrypted authenticator secret, a log of sign-ins and downloads with the network prefix, and the acceptance of the terms with its version, date and network prefix |
| Recipients | None |
| Retention | To be published before the first account is opened |
| Closure | The person can ask for it at any time at hola@ago.cl |
What the observatory does not process
From the SAG register of beekeepers, the observatory uses only the aggregates or anonymised data the agency itself publishes or supplies, never the data of individual beekeepers. News is published in Atom feeds, which anyone can follow from a feed reader without giving any data.