Nippy Launch – Privacy Policy
This Privacy Policy explains how Cleefcompany SpA collects, uses, stores, shares, and protects personal data when you visit nippylaunch.com, create a Nippy Launch account, purchase or use a membership, access the Resource Library, contact support, subscribe to communications, or use related services.
1. Who is responsible for your data
Cleefcompany SpA is the data controller for personal data processed for Nippy Launch’s own purposes.
Cleefcompany SpA, operator of Nippy Launch; Chilean Tax ID (RUT) 76.997.914-K; legal address: Eulogia Sanchez 065, Providencia, Santiago Metropolitan Region, Chile. Legal representative: Cleef Millien.
Privacy request form: Nippy Launch Support
This Policy applies the transparency standards introduced by Chilean Law No. 21,719, which amends Law No. 19,628 and takes effect on December 1, 2026. Until then, the currently effective text of Law No. 19,628 applies. Other privacy laws, including the GDPR, may also apply to a particular user or processing activity.
2. Scope
This Policy applies to Nippy Launch websites, registration and login pages, membership areas, forms, support channels, newsletters, analytics, and related services controlled by Cleefcompany SpA. It does not govern an independent third party’s website, software, payment service, hosting service, or privacy practices.
If we process personal data solely on behalf of a business customer under separate written instructions, that customer may be the controller and Cleefcompany SpA may act as a processor for that limited activity. Those arrangements may be governed by a separate data-processing agreement.
3. Personal data we collect
3.1 Account and identity data
- First and last name, email address, phone number, username, and account identifier.
- Password or authentication data in protected form; we do not need to know your plain-text password.
- Profile information, including a public profile image if you choose a supported social sign-in method such as Google.
- Company, role, country, language, and similar details when you provide them.
3.2 Transaction and membership data
- Selected plan, price, billing interval, order date, coupon, renewal and cancellation status.
- Payment status, transaction identifier, billing contact information, tax or invoice information, and limited payment-method details supplied by the processor.
- Download, update, plan-entitlement, and resource-access records needed to operate the membership.
3.3 Communications and content
- Support requests, emails, contact-form submissions, feedback, survey responses, reviews, comments, and community activity.
- Files, screenshots, URLs, technical details, or credentials you voluntarily provide for support. Do not send sensitive personal data, live customer databases, or production credentials unless we specifically request them through an approved secure method.
3.4 Technical and usage data
- IP address, approximate location derived from IP, browser, device, operating system, language, referral URL, and timestamps.
- Pages viewed, buttons or links used, session activity, error logs, security events, downloads, and interaction with emails.
- Cookie identifiers, consent choices, analytics identifiers, and similar online technologies.
3.5 Marketing and preference data
- Newsletter subscriptions, communication preferences, campaign source, affiliate or referral attribution, and unsubscribe status.
3.6 People concerned by the processing
The people whose data may be processed include public-site visitors, prospective customers, account holders, FREE, PLUS and PRO members, purchasers, newsletter subscribers, support contacts, affiliate-referred visitors, community participants where enabled, and representatives of business customers or suppliers.
We do not intentionally request sensitive personal data for ordinary Nippy Launch use. Please do not provide health, biometric, financial-account, government-identity, or other sensitive data unless it is strictly necessary and we have expressly authorized a secure method and lawful purpose.
4. How we obtain data
- Directly from you when you register, purchase, complete a form, communicate with us, or use the Service.
- Automatically through our website, server logs, cookies, analytics, security, and membership technologies.
- From service providers such as payment processors, authentication providers, email services, affiliate platforms, analytics providers, and support tools.
- From public or business sources when reasonably necessary to prevent fraud, verify a business relationship, or respond to an inquiry.
5. Why we use personal data
5.1 Purposes
We use personal data only for specific, explicit, and lawful purposes, including to:
- Create, authenticate, secure, and administer your account.
- Process orders, confirm transactions, manage renewals, cancellations, refunds, taxes, and invoices.
- Provide plan-based access to the Resource Library, downloads, updates, guides, tools, courses, and other materials.
- Deliver support, troubleshoot issues, communicate service notices, and respond to requests.
- Operate, monitor, test, maintain, personalize, and improve the website and Service.
- Measure traffic, content performance, conversions, campaigns, and product usage.
- Send newsletters, offers, and educational communications when permitted; you may unsubscribe from marketing at any time.
- Prevent fraud, abuse, credential sharing, malicious activity, payment disputes, and security incidents.
- Comply with tax, accounting, consumer, privacy, law-enforcement, and other legal obligations.
- Establish, exercise, or defend legal claims and protect users, Cleefcompany SpA, and third parties.
5.2 Lawful bases and legitimate interests
The lawful basis depends on the activity and law that applies. We may rely on:
- Contract or pre-contractual steps: to register an account, process a purchase, deliver a membership, provide downloads and updates, administer renewals or cancellations, and answer a request made before purchase.
- Legal obligation: to maintain tax, accounting, consumer, security, and compliance records or respond to a binding legal request.
- Consent: for optional marketing, non-essential cookies, an optional integration, or another activity for which consent is requested. Consent may be withdrawn for future processing.
- Legitimate interests, where permitted: to secure accounts and systems, prevent fraud and abuse, measure and improve the Service, maintain ordinary customer communications, protect intellectual property, and establish or defend legal claims, provided those interests are not overridden by the person’s rights and freedoms.
- Protection of rights or another basis expressly authorized by applicable law.
Where processing relies on legitimate interests, a user may request information about the balancing assessment and may object when the law permits.
6. Payments
Payments are processed by the provider displayed at checkout, which currently may include PayPal. The processor receives payment credentials directly under its own privacy policy and security practices. Nippy Launch generally receives transaction confirmation, payer contact details, payment status, amount, currency, and a transaction identifier, but not your complete card number, bank credentials, or PayPal password.
7. Cookies and similar technologies
Nippy Launch uses cookies and similar technologies for the following categories:
- Strictly necessary: login, account, checkout, security, fraud prevention, network delivery, and consent storage.
- Functional: preferences, language, forms, media, and user-interface features.
- Analytics: understanding visits, pages, interactions, and performance. Current website technology may include Google Site Kit, Google tag, Google Analytics, or Google Tag Manager where enabled.
- Marketing and attribution: measuring campaigns, newsletter activity, referrals, or affiliate conversions where enabled.
Where consent is required, non-essential technologies should not be activated until you make the relevant choice. You may use the site’s cookie controls, where available, or your browser settings to reject or delete cookies. Blocking necessary cookies may prevent login, checkout, or other core functions. Browser-based signals such as Global Privacy Control will be honored where required by applicable law and technically supported.
8. When we share personal data
We do not sell personal data for money. We disclose data only as reasonably necessary for the purposes described in this Policy, including to:
- Hosting, content-delivery, database, backup, and security providers, including Hostinger where used.
- Payment processors, including PayPal where selected.
- Authentication, analytics, measurement, and website providers, including Google services where enabled.
- Email, CRM, form, newsletter, support, and communication providers.
- Professional advisers such as accountants, auditors, insurers, and lawyers under confidentiality duties.
- Government bodies, regulators, courts, law enforcement, or other parties when required by law or reasonably necessary to protect rights and security.
- A buyer, successor, investor, or adviser involved in a proposed or completed merger, financing, reorganization, sale, or transfer of all or part of the business, subject to appropriate safeguards.
- Other parties when you direct us or give valid consent.
Some privacy laws define certain analytics or advertising disclosures as a sale, sharing, or targeted advertising even when no money is paid for the data. Where such laws apply, we will provide the required notice and opt-out mechanism.
Service providers acting as processors or third-party agents must process personal data only for authorized purposes and under applicable contractual, confidentiality, security, return-or-deletion, and assistance obligations. Each provider remains responsible for its independent processing when it acts as a separate controller.
9. International data transfers
Cleefcompany SpA is based in Chile, while hosting, payment, authentication, analytics, email, support, security, or infrastructure providers may process data in the United States or other countries. Those countries may not provide the same level of protection as Chile or the person’s home jurisdiction.
Where required, an international transfer will rely on a lawful mechanism such as a destination recognized as adequate, contractual clauses or another binding instrument providing appropriate safeguards, binding corporate rules, a certified compliance mechanism, a legal necessity, or explicit consent when that basis is valid. Information about the applicable destination and safeguards may be requested through the privacy contact channel.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, managing business and customer relationships, maintaining records, complying with legal obligations, processing transactions, protecting security, preventing fraud and abuse, resolving disputes, and establishing, exercising, or defending legal claims.
The applicable retention period is determined by considering the nature and sensitivity of the data, the purpose for which it was collected, the duration of the business or contractual relationship, applicable legal and accounting requirements, operational requirements, security risks, potential disputes, and whether the information can be anonymized instead of deleted.
Our general retention criteria are:
- Membership access and account credentials: Membership access, authentication credentials, downloads, support entitlements, and plan-based permissions are disabled or removed when the account closure, cancellation, or termination becomes effective under the applicable Terms. Cleefcompany SpA is not required to maintain an active membership account after the applicable access entitlement ends.
- Account, profile, CRM, and relationship records: Limited identity, contact, profile, entitlement, activity, CRM, and business-relationship records may be retained after account closure for as long as Cleefcompany SpA reasonably determines they remain necessary for customer history, business administration, contractual records, fraud prevention, dispute resolution, legal compliance, or the establishment, exercise, or defense of legal claims. Retaining these records does not keep the membership account active or restore access to the Service.
- Membership, order, invoice, refund, and transaction records: These records may be retained for as long as reasonably necessary to comply with tax, accounting, auditing, payment, chargeback, consumer protection, contractual, fraud-prevention, and other legal or business-record requirements. They may also be retained while a transaction, investigation, dispute, audit, or legal claim remains pending or reasonably foreseeable.
- Support communications and service records: Support requests, communications, troubleshooting information, and ordinary service records may be retained for as long as reasonably necessary to maintain service history, provide operational continuity, improve support, document actions taken, prevent repeated abuse, resolve disputes, and establish, exercise, or defend legal claims.
- Security, authentication, and technical logs: Security events, login records, authentication data, device information, access logs, and technical records may be retained for as long as reasonably necessary to protect accounts and systems, investigate incidents, prevent fraud or abuse, enforce these Terms, maintain evidence, and comply with applicable security or legal obligations.
- Marketing and communication records: Marketing subscription data may be retained until consent is withdrawn, the person unsubscribes, or the communication program ends. A minimal suppression record may be retained for as long as reasonably necessary to honor the opt-out and prevent unwanted communications.
- Cookie and analytics identifiers: These are retained according to the duration stated in the Cookie Policy, consent interface, browser settings, or applicable provider configuration.
- Routine backups: Personal data contained in routine backups remains subject to normal backup rotation and recovery procedures. A backup may be isolated or retained longer when reasonably necessary for security recovery, business continuity, investigation, legal compliance, or preservation of evidence.
Personal data may be retained for a longer period when authorized or required by law, supported by valid consent, or reasonably necessary for an ongoing contractual, accounting, security, fraud-prevention, dispute-resolution, or legal purpose.
When identifiable personal data is no longer reasonably necessary for a lawful purpose, it will be deleted, anonymized, or securely isolated in accordance with applicable law and operational requirements. Anonymized or aggregated information that no longer identifies an individual may be retained and used for business, analytical, historical, statistical, security, and service-improvement purposes.
11. Security
We apply privacy by design and by default and use technical, organizational, and administrative measures appropriate to the nature of the personal data, the purposes of the processing, and the associated risks. These measures may include data minimization, role-based access controls, authentication, encrypted connections, software updates, logging, monitoring, backups, recovery procedures, confidentiality obligations, incident-response procedures, and service-provider reviews. Detailed security configurations are not publicly disclosed where doing so could create additional risk.
Our measures are selected to support the confidentiality, integrity, availability, and resilience of personal data and relevant systems, as well as the timely restoration of access following an incident. Access is limited to authorized personnel and service providers with a legitimate operational need. However, no website, system, or transmission method can be guaranteed to be completely secure.
You are responsible for protecting your account credentials and for notifying us promptly if you suspect unauthorized access to your account.
From December 1, 2026, Cleefcompany SpA will document personal-data security breaches and, where a breach creates a reasonable risk to the rights and freedoms of affected individuals, report it to the Chilean Data Protection Agency through the most expeditious means reasonably available and without undue delay.
Where a reportable breach involves sensitive personal data, personal data relating to children under fourteen years of age, or data concerning economic, financial, banking, or commercial obligations, Cleefcompany SpA will also notify affected individuals as required by applicable law. Such notification will be provided in clear and plain language and will identify the affected data, the reasonably foreseeable consequences of the breach, and the protective or remedial measures adopted, to the extent required by law.
12. Your privacy rights
Depending on your location and the law that applies, you may have the right to:
- Confirm whether we process your personal data and obtain access to it.
- Correct inaccurate, incomplete, or outdated data.
- Request deletion or cancellation when legal requirements are met.
- Object to certain processing or request restriction of processing.
- Request temporary blocking of processing while an eligible rectification, deletion, or objection request is being decided.
- Receive eligible data in a portable format and, where technically feasible, request transfer to another controller.
- Withdraw consent at any time for future processing based on consent.
- Unsubscribe from marketing communications without affecting service or transactional messages.
- Ask about the source, purpose, recipients, retention, and safeguards for your data.
- Object to a solely automated decision that produces legal or similarly significant effects and request meaningful information, an explanation, human intervention, and review where applicable.
- Complain to the competent privacy or consumer authority and seek available judicial remedies.
12.1 How to exercise a right
Submit a Privacy Request through Nippy Launch Support. If you prefer to use email, use the official public company email stated in the Terms and Conditions.
Your request should identify you, provide a valid email address or another electronic contact method for receiving our response, identify the relevant personal data or processing activity, and describe the right you wish to exercise. Do not send passwords, complete payment credentials, private keys, or unrelated sensitive information. We may take proportionate measures to verify your identity and, where applicable, your authority to act on behalf of another person before processing the request.
From December 1, 2026, Cleefcompany SpA will acknowledge receipt of the request and issue a decision no later than 30 calendar days after the request is received. Where permitted by law, this period may be extended once for up to 30 additional calendar days.
A substantiated request for temporary blocking made in connection with a request for rectification, deletion, or objection will be decided within two business days after receipt. Until that temporary-blocking request is decided, Cleefcompany SpA will not process the personal data covered by the request, although the data may continue to be securely stored.
A temporary-blocking request may be denied where it is unsupported or where a justified legal basis permits the relevant processing to continue. Any denial will be explained as required by law and communicated to the Chilean Data Protection Agency where legally required.
If a request is denied, in whole or in part, or is not answered within the applicable legal period, the individual may submit a complaint to the Chilean Data Protection Agency within 30 business days, in accordance with applicable law.
Before December 1, 2026, requests will be handled according to the procedures and deadlines then in force.
Certain rights may be limited where processing or retention remains necessary for the performance of a contract, compliance with a legal obligation, security purposes, freedom of expression, the public interest, or the establishment, exercise, or defense of a legal claim. Any complete or partial denial will be explained as required by applicable law.
13. Additional information for EEA and UK users
Where the GDPR or UK GDPR applies, the lawful bases described in Section 5 apply to the relevant processing. You may contact us for information about legitimate interests, international-transfer safeguards, or the service providers used for your data. You may also lodge a complaint with the supervisory authority in your country. You are not required to provide optional data, but we may be unable to create an account, process a payment, or provide a requested feature without data marked as required.
14. Automated decision-making
Nippy Launch does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on users. We may use automated tools to detect spam, security threats, unusual account activity, or payment risk, with human review where appropriate.
15. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children for Nippy Launch memberships. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
16. Third-party links and software
The Service may link to or provide third-party websites, plugins, themes, integrations, hosting, payment, or authentication services. The third party’s privacy policy governs its independent collection and use of data. Review those policies before providing data or enabling an integration.
17. Changes to this Policy
We may update this Policy to reflect changes in law, technology, providers, or the Service. The effective date will be updated. If a change is material, we will provide additional notice when required, such as by email or a prominent website notice. Earlier versions should be retained for internal records.
18. Contact
For privacy questions, consent withdrawal, or the exercise of a data-protection right, use the Nippy Launch Support page. Open Nippy Launch Support
Website: nippylaunch.com
The data controller’s legal identity, representative, and postal address are stated in Section 1.
Please use the subject Privacy Request for access, rectification, deletion, opposition, temporary blocking, portability, consent withdrawal, automated-decision review, or another data-protection request.
Related policies: Terms and Conditions | Privacy Policy | License Agreement
Effective date: September 08, 2026Â
