DPO Privacy
DPO Privacy
PlatformSolutionsAI governancePlansContentAbout us
PTENES
Book a demo
Book a demo
PlatformSolutionsAI governancePlansContentAbout usBook a demo
Legal content

Privacy Policy

How DPO Privacy processes personal data, for what purpose, for how long, and how you can exercise your rights.

Last updated: September 26, 2026

SummaryControllerRoles in processingData processedPurposes and legal basesArtificial intelligenceSharingInternational data transferSecurityRetentionData subject rightsCookiesData Protection OfficerUpdates

This is a courtesy translation. In case of any discrepancy, the Portuguese version prevails.

Summary

DPO Privacy processes personal data to provide its privacy governance and data protection platform, offer support, ensure the security of the service and comply with legal obligations. We do not sell personal data. Data is shared only with suppliers essential to the operation and with authorities, when required by law.

The data our customers enter into the platform is processed exclusively in accordance with each customer's instructions, under the terms of the contract entered into with that customer. The rights provided for in the LGPD (Brazilian General Data Protection Law, Law No. 13,709/2018) may be exercised at any time through the channels indicated in this Policy.

What we process

Registration, billing, technical and platform usage data.

What for

To provide the platform, offer support, ensure security and comply with the law.

With whom

Only suppliers essential to the operation and authorities, when required by law.

Your control

The rights under the LGPD may be exercised at any time through the channels set out in this Policy.

1. Identification of the controller

SYNTEZ LAB DESENVOLVIMENTO DE SOFTWARE LTDA, registered with the CNPJ (Brazilian National Registry of Legal Entities) under No. 68.825.766/0001-49, headquartered in São Paulo/SP, owner of the DPO Privacy platform.

2. Scope and roles in processing

This Policy applies to personal data processed by DPO Privacy in its capacity as controller, that is, data of:

  • Website visitors
  • Prospects who request a demonstration or commercial contact
  • Platform users, with regard to registration, authentication, support and account security
  • Representatives of customers and suppliers, for contractual and billing purposes

Data entered by customers into the platform. In these cases, DPO Privacy acts as processor, and the customer is the controller. This processing is governed by the contract and the data processing agreement entered into with each customer. Examples:

  • Records of processing activities
  • Information about data subjects
  • Incidents, suppliers and assessments

Data subjects who wish to exercise rights over this data must contact the controller organization. If DPO Privacy receives a request of this nature, it will be forwarded to the responsible customer.

3. Personal data processed and source

Collected directly from you

  • Registration and contact: name, corporate e-mail, organization, position and professional telephone number.
  • Billing: data of the person responsible for finance. Card data is processed directly by the payment provider, and DPO Privacy does not store the full card number.

Collected automatically

  • Technical: IP address, browser, operating system and session identifiers.
  • Usage: features accessed, date, time and records of interaction on the platform.

Received from third parties

When the administrator of a customer organization registers users, we receive from that administrator the name, corporate e-mail and access profile of those users.

4. Purposes and legal bases

PurposeLegal basis (LGPD)
Providing the platform, managing accounts and offering supportPerformance of a contract (Art. 7, V)
Invoicing and billingPerformance of a contract and compliance with a legal obligation (Art. 7, V and II)
Retention of application access logsCompliance with a legal obligation (Art. 7, II, and Art. 15 of the Marco Civil da Internet (Brazilian Internet Civil Rights Framework, Law No. 12,965/2014))
Information security and fraud preventionLegitimate interest (Art. 7, IX) and guarantee of fraud prevention (Art. 11, II, "g", where applicable)
Improvement of the platform based on usage metricsLegitimate interest (Art. 7, IX)
Handling requests for demonstrations and commercial contactPreliminary procedures related to a contract (Art. 7, V)
Institutional communications to customersLegitimate interest (Art. 7, IX)
Marketing communications and non-essential cookiesConsent (Art. 7, I)
Regular exercise of rights in proceedingsArt. 7, VI

For processing based on legitimate interest, DPO Privacy carries out a prior proportionality assessment and ensures the data subject's right to object. Additional information may be requested from the Data Protection Officer.

5. Use of artificial intelligence

The platform offers optional artificial intelligence features, activated only upon the express decision of each customer organization. When activated:

  • The data is processed exclusively to generate the suggestions requested by the user.
  • Suggestions are subject to human validation before any record is made.

DPO Privacy does not make decisions based solely on automated processing that affect the interests of data subjects.

6. Sharing

DPO Privacy does not sell or trade personal data. Data is shared only with:

  • Cloud infrastructure and hosting providers
  • Payment and fraud prevention providers
  • Support, error monitoring and observability tools
  • Artificial intelligence providers, only when the feature is enabled by the customer
  • Aggregate website traffic measurement service (Cloudflare Web Analytics), which does not use cookies or identify individual visitors
  • Public authorities, when required by law or by a valid judicial or administrative order

All suppliers are subject to contractual obligations of confidentiality, security and data protection. The list of sub-processors may be requested from the Data Protection Officer.

7. International data transfer

Some suppliers may store or process data outside Brazil. In such cases, the transfer complies with Art. 33 of the LGPD and Resolution CD/ANPD No. 19/2024 (issued by the Board of Directors of the ANPD, the Brazilian Data Protection Authority), through the adoption of standard contractual clauses or another valid mechanism.

8. Security

DPO Privacy adopts technical and administrative measures to protect data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration or disclosure, including:

  • Encryption in transit and at rest
  • Multi-factor authentication
  • Role-based access control and segregation of duties
  • Audit logs
  • Periodic access reviews

In the event of a security incident that may result in significant risk or damage to data subjects, DPO Privacy will notify the ANPD and the affected data subjects, pursuant to Art. 48 of the LGPD and applicable regulations.

9. Retention and deletion

Personal data is retained for as long as necessary to fulfill the purposes of this Policy, in accordance with the following criteria:

Account data and data entered by the customer

For the term of the contract. After termination, they remain available for export for 30 days and are then deleted, unless otherwise provided in the contract.

Application access logs

At least 6 months, pursuant to Art. 15 of the Marco Civil da Internet.

Tax and billing documents

For the period required by tax legislation.

Data necessary for defense in proceedings

Judicial, administrative or arbitral, until the applicable statutes of limitations have expired.

Once these periods have ended, the data is deleted or anonymized.

10. Data subject rights

Pursuant to Art. 18 of the LGPD, you may request:

  • Confirmation of the existence of processing
  • Access to the data
  • Correction of incomplete, inaccurate or outdated data
  • Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance with the law
  • Portability
  • Deletion of data processed on the basis of consent
  • Information about sharing
  • Information about the possibility of not providing consent and its consequences
  • Withdrawal of consent
  • Objection to processing carried out on the basis of other legal grounds, in the event of non-compliance with the LGPD
  • Review of automated decisions

Step 1

Send your request to privacidade@dpoprivacy.com.br.

Step 2

We may request additional information to confirm your identity and protect your data.

Step 3

The request will be answered within the legal deadlines. The complete access statement will be provided within 15 days, pursuant to Art. 19, II, of the LGPD.

You may also file a petition with the Autoridade Nacional de Proteção de Dados (ANPD, Brazilian Data Protection Authority).

11. Cookies

We use cookies that are essential to the operation and authentication of the platform. Optional analytics cookies, such as those from Google Analytics, are activated only upon consent recorded in the preferences panel, which may be changed at any time. To count visits to the website, we use Cloudflare's aggregate measurement, which does not set cookies or identify who visits.

Read the Cookie Policy

12. Minors

The platform and the website are intended for professional use and are not directed at persons under 18 years of age.

13. Data Protection Officer (DPO)

E-mail: privacidade@dpoprivacy.com.br

14. Updates

This Policy may be updated due to legal, regulatory or operational changes. The date of the current version is always stated at the beginning of this document. Relevant changes will be communicated to customers through the registered channels.

We recommend reading this Policy together with the Terms of Use, the Cookie Policy and the data processing agreement applicable to customers.

This document describes the processing carried out by DPO Privacy and does not replace the legal analysis of each organization's privacy program.

DPO Privacy

Privacy and personal data protection governance platform for managing compliance with the LGPD (Brazilian General Data Protection Law) and the GDPR.

Platform

  • Modules
  • AI governance
  • Data and Technology
  • Enterprise
  • Plans
  • Security

Company

  • About us
  • Contact

Resources

  • Content
  • Help Center
  • Frequently asked questions

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© 2026 DPO Privacy · All rights reserved · Made in Brazil

Developed bysyntez