Skip to main content
Draft template. Replace the [BRACKETED] placeholders and have this text reviewed by a lawyer before publishing or accepting customers. It is a starting point, not legal advice.

Privacy Policy

Last updated: September 25, 2026

1. Controller and contact

[COMPANY LEGAL NAME], [TAX ID / CNPJ], [ADDRESS], is the controller of the personal data described here. Data protection contact / DPO: [NAME], [PRIVACY EMAIL]. For personal data contained in Customer data, we act as the Customer's processor.

2. Data we process

  • Account data: name, work email, password hash, organization name, role.
  • Service data submitted by the Customer: agents, integrations, resources, permissions, policies and action metadata (agent, action, resource, destination, record counts, timestamps, risk results, review decisions and notes). We are designed not to receive the content of your records.
  • Security and usage data: IP address, request logs, API key identifiers and last-use time, error diagnostics.
  • Browser storage: a session token and your language preference in local storage. We do not use advertising cookies.

3. Purposes and legal bases (LGPD art. 7 / GDPR art. 6)

  • Provide and operate the service: performance of a contract.
  • Secure the service, prevent fraud and abuse, keep audit trails: legitimate interest and compliance with legal obligations.
  • Communicate about the service, support and important changes: contract and legitimate interest.
  • Product analytics in aggregate form: legitimate interest [or consent, if you add analytics cookies].

4. Sharing and processors

We do not sell personal data. We use infrastructure providers as processors, including [Amazon Web Services, region: REGION], [email provider], [error monitoring provider]. Each is bound by data protection terms. We may disclose data when required by law.

5. International transfers

Data may be processed outside your country. Where required we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.

6. Retention

Account data is kept while your account is active. Events and audit logs are kept for the retention period of your plan (for example 7 days to 1 year). After termination data is deleted within [30-90] days, except what we must keep by law. Backups expire on their normal cycle.

7. Your rights

Under the LGPD (art. 18) and, where applicable, the GDPR, you may request confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent, and object to processing. Contact [PRIVACY EMAIL]. If your data is in a Customer's workspace, we may direct your request to that Customer. You may also complain to the ANPD or your local authority.

8. Security

We apply measures such as tenant isolation, hashed passwords, hashed API keys, access control and audit logging. See our Security page. No system is perfectly secure; we will notify affected parties and authorities of incidents as required by law.

9. Children

The service is for businesses and is not directed to people under 18.

10. Changes

We will post updates here and notify you of material changes.

Security