1. Processing roles
We act as controller for account, billing, support, security, and platform usage data — information we need in order to exist as a service.
We act as processor for the content you submit for task execution: prompts, documents, files, client data, and business information. For that content, you (or the organization you represent) are the controller, and we process it solely on your instructions.
2. Data you provide
- Identification and contact: name, email, optional phone, preferred language, and profile picture.
- Organization data: company name, industry, size, brand, visual identity, and business context.
- Billing data: legal name, tax identification, and billing address. Card data is collected and stored directly by the payment processor.
- Work content: prompts, messages, uploaded files, library documents, meeting minutes, audio recordings when voice features are used, and any other information submitted with a task.
- Support: messages, tickets, attachments, and service history.
3. Data collected automatically
- Application access logs: IP address, date, and time, as required by article 15 of the Internet Civil Framework.
- Device technical data: browser type, operating system, screen resolution, and language.
- Usage events: screens visited, tasks created, deliverables generated, errors, and response times.
- Cookies and equivalent technologies, as described in the Cookie Policy.
This data supports security, fraud prevention, technical diagnostics, and product improvement. We do not run cross-site advertising tracking.
4. Purposes and legal bases
| Purpose | Data involved | Legal basis (LGPD) |
|---|---|---|
| Account creation and management | Identification, contact, credentials | Performance of a contract (art. 7, V) |
| Task execution and deliverable generation | Work content, company context | Performance of a contract (art. 7, V) |
| Agent personalization and memory | Task history, preferences, context | Contract and legitimate interest (art. 7, V and IX) |
| Billing and subscription management | Billing and plan usage data | Contract and legal obligation (art. 7, V and II) |
| Security, fraud, and abuse prevention | Access logs, events, IP | Legitimate interest and legal obligation (art. 7, IX and II) |
| Retention of access logs | IP, date, and time | Legal obligation — Internet Civil Framework, art. 15 |
| Customer support | Tickets, attachments, history | Performance of a contract (art. 7, V) |
| Product and institutional communications | Name and email | Legitimate interest, with opt-out at any time (art. 7, IX) |
| Product improvement with aggregate data | Anonymized metrics | Anonymized data — outside LGPD scope (art. 12) |
| Compliance with court orders | Strictly requested data | Legal obligation (art. 7, II) |
5. How the AI uses your history
Delivery quality depends on context. The platform therefore maintains an organizational memory: information about your company, previous decisions, approved documents, tone of voice, and delivery standards.
When you open a new task, we automatically select the relevant excerpts of that history and send them to the model together with your request. That is what allows an agent to point out that a proposal created weeks ago already exists and can be updated rather than rewritten.
- Memory is scoped to your workspace and never shared between different customers.
- We do not use your content to train our own or third-party models.
- Our contracts require model providers not to use content sent through our API for training.
- You can delete documents, tasks, and memory items at any time, removing them from future context selection.
Do not submit sensitive personal data, data of children and adolescents, or legally privileged information beyond what is strictly necessary for the requested task.
6. Sharing with suppliers
We do not sell personal data and do not share it with third parties for advertising. Sharing happens only with suppliers necessary to operate the service, under contracts imposing confidentiality, security, and purpose limitation:
| Supplier | Purpose | Location |
|---|---|---|
| OpenAI | Modelos de linguagem, transcrição e síntese de voz | Estados Unidos |
| Anthropic | Modelos de linguagem para raciocínio e redação | Estados Unidos |
| Google (Gemini) | Modelos de linguagem e multimodais | Estados Unidos |
| Supabase | Banco de dados, autenticação e armazenamento de arquivos | Estados Unidos / União Europeia |
| Cloudflare | Entrega de aplicação, proteção contra abuso e execução de funções | Rede global |
| Stripe | Processamento de pagamentos e gestão de assinaturas | Estados Unidos / Irlanda |
| Resend | Envio de e-mails transacionais | Estados Unidos |
We may also share data with competent authorities upon lawful request, and with an acquirer in a corporate reorganization, in which case this Policy remains applicable or is replaced by an equally protective one.
7. International transfers
Some suppliers are located outside Brazil, notably in the United States and the European Union. International transfers rely on article 33 of the LGPD, supported by contractual clauses ensuring a level of protection compatible with Brazilian law.
8. Storage and retention
| Category | Retention period |
|---|---|
| Work content and deliverables | For the life of the account, plus 30 days after closure |
| Account data | For the life of the account, plus 30 days after closure |
| Application access logs | 6 months (Internet Civil Framework, art. 15) |
| Tax and billing records | 5 years, as legally required |
| Legal acceptance records | 5 years after closure, as contractual evidence |
| Meeting recordings and audio | While the user keeps the item; deleted immediately on request |
Once these periods elapse, data is securely deleted or irreversibly anonymized.
9. Information security
- Encryption in transit with TLS 1.2 or above on every connection.
- Encryption at rest for the database and file storage.
- Logical isolation per workspace, enforced by row-level security in the database.
- Role-based access control with least privilege for internal staff.
- Audit logging of sensitive operations.
- Secrets and API keys kept in a managed vault, never in source code.
- Backup routines with periodic restore testing.
- Security assessment of suppliers before engagement.
Material security incidents are reported to affected data subjects and to the Brazilian Data Protection Authority within a reasonable period, under article 48 of the LGPD. Vulnerabilities can be reported to seguranca@squadia.online.
10. Your rights
Under article 18 of the LGPD, you may request at any time:
- confirmation that processing exists and access to your data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary or excessive data;
- portability to another provider in a structured, interoperable format;
- deletion of data processed on the basis of consent;
- information about sharing carried out;
- withdrawal of consent, where consent is the legal basis;
- objection to processing based on legitimate interest;
- review of automated decisions affecting your interests.
Requests should be sent to privacidade@squadia.online and are answered within 15 days. We may ask for additional information to verify the requester's identity.
11. Deletion and portability
Documents, tasks, meetings, and memory items can be deleted directly in the platform. Closing the account removes access immediately and starts the deletion period described above.
Deliverables can be exported in the formats originally generated. Structured portability requests for account and history data can be made through the privacy channel.
12. Children and adolescents
The platform is not intended for people under 18. If we identify a minor's account without proper representation, the account is closed and the data deleted.
14. Changes to this Policy
This Policy may be updated. The version and effective date appear at the top of the page, and material changes are notified by email or in-app before taking effect.
15. Data protection officer and contact
Data protection officer: [NOME DO ENCARREGADO]. Contact: privacidade@squadia.online. Address: [ENDEREÇO COMPLETO]. You may also file a complaint with the Brazilian Data Protection Authority (ANPD).
This document has contractual value. If you are unsure how it applies to a specific situation, consult a qualified professional.