LGPD & GDPR
Privacy Policy
Draft for legal review — do not publish without validation from a lawyer specialized in Brazilian data protection law (LGPD) and/or GDPR.
1. Data Controller
[COMPANY NAME], CNPJ [xx.xxx.xxx/xxxx-xx], is the controller of personal data processed under this Policy, in accordance with the Brazilian General Data Protection Law (Lei 13.709/2018 — LGPD) and, when applicable to users in the European Union, the General Data Protection Regulation (GDPR — Reg. UE 2016/679).
Data Protection Officer (DPO): [name or contact email — mandatory under LGPD art. 41]
Contact: privacy@diakon.app.br
2. Personal Data Collected
- Account data: name, email, company, position.
- Usage data: access logs, IP address, actions performed on the platform.
- Payment data: processed directly by the payment processor (Stripe); Diakon stores only transaction identifiers, not full card details.
- Submitted content: organizational documents and information sent for analysis — may contain third-party personal data depending on what the user chooses to submit.
3. Purposes of Processing
- Provision of the contracted Service (analysis and generation of recommendations).
- Account management, authentication, and billing.
- Service-related communication (updates, support).
- Compliance with legal and regulatory obligations.
- With specific consent: marketing communications.
4. Legal Basis (LGPD art. 7 / GDPR art. 6)
- Contract performance (Service provision).
- Legitimate interest (Service improvement, security).
- Consent (marketing communications, non-essential cookies).
- Legal obligation (tax/accounting data).
5. Data Sharing
Data may be shared with: payment processors (Stripe), infrastructure providers (Cloudflare), and analytics tools (Cloudflare Web Analytics) — all under contractual data protection obligations. Diakon does not sell personal data to third parties.
6. International Transfer
Some providers (e.g., Cloudflare, Stripe) may process data outside Brazil. These transfers are based on [standard contractual clauses / applicable adequacy mechanism — to be specified with legal counsel], as required by LGPD art. 33 and, when applicable, GDPR Chapter V.
7. Data Retention
Data is retained for the duration of the account and, after closure, for the period necessary to comply with legal obligations (e.g., tax) or exercise regular rights, after which it is deleted or anonymized. [Define specific retention periods with legal counsel — e.g., tax data for 5 years under Brazilian legislation.]
8. Data Subject Rights
Under the LGPD (art. 18) and GDPR (arts. 15–22), data subjects may request: confirmation of processing, access, correction, anonymization/deletion, portability, information about sharing, withdrawal of consent, and objection to processing based on legitimate interest. Requests can be made at privacy@diakon.app.br.
9. Security
Diakon adopts technical and administrative measures to protect personal data against unauthorized access, including encryption in transit, role-based access control (RBAC), and secure authentication.
10. Cookies
The site uses essential cookies (platform operation) and, where applicable, analytics cookies (Cloudflare Web Analytics). [If non-essential cookies are used, a specific consent banner will be required for GDPR compliance and evolving ANPD cookie regulations.]
11. Minors
The Service is not directed to individuals under 18. We do not intentionally collect data from minors without proper parental consent where applicable.
12. Changes to this Policy
Material changes will be communicated with reasonable notice through the same channels used for the Terms of Use.
13. Contact and Complaints
Questions or complaints about data processing: privacy@diakon.app.br. Data subjects may also contact the Brazilian Data Protection Authority (ANPD) or, where applicable, the data protection authority of their EU country.