Security and privacy
What your compliance team needs to know
Who we are on paper, how we handle personal data, and where to write when something goes wrong.
Both channels are public: the security one sits in the domain's security.txt, and the DPO's in the Privacy Policy.

How we handle data
The answers a vendor questionnaire usually asks for, at the level of detail we can actually back up.
Where to write
Vulnerability
Good-faith security issue reports. We answer within 48 hours.
Data protection officer
Data subject rights and questions about data processing. There is an appointed officer with its own CNPJ and address, as Brazil's LGPD (art. 41) requires.
Availability
Incidents and service history, published outside our own infrastructure so they stay up when it doesn't.
If you are a data subject and want confirmation, access, correction or erasure of your data, the request is made on the Data protection officer page.
The full documents are the Privacy Policy and the Terms of Use. This page is their operational summary, not a replacement.

