1 Who we are and who this policy applies to
Graffenno is a family of cloud-based enterprise management systems. This policy applies to the institutional website, the platform available at graffenno.com, and the SeuPDV and SeuPOS applications.
For data provided directly to us, such as when registering an account, requesting a demonstration, or contacting support, Graffenno acts as the controller, defining the purposes and means of processing.
When a customer uses the platform to serve their own contacts, the customer is the controller of that contact data, and Graffenno acts as the processor, handling that information according to the customer's instructions and the agreement in place.
2 Data we collect
We collect only the data necessary to enable access to the platform, provide support, comply with legal obligations, and improve the user experience.
- Registration data: name, email, phone number, company, and position provided during registration or in contact forms
- Account and billing data: contracted plan, data required for billing, and payment history
- Platform usage data: access logs, actions performed, date and time of operations, and device identifiers
- Technical data: IP address, browser type, operating system, and pages visited
- Communication data: messages exchanged with support and information provided during service interactions
- Data processed on behalf of the customer: records of customers, suppliers, products, tax documents, and other information entered by the customer into the system, in its capacity as processor
3 Purposes of processing
Personal data is used for the specific purposes described below, and is not processed in a manner incompatible with what was disclosed to the data subject.
- Creating, maintaining, and authenticating platform access accounts
- Providing the contracted services and making the plan's features available
- Processing billing, issuing tax documents, and administering the agreement
- Providing technical support and responding to requests received
- Ensuring platform security, preventing fraud, and investigating incidents
- Communicating news, updates, and content related to the product, when applicable
- Producing aggregated usage statistics to improve the platform
- Complying with legal and regulatory obligations and requests from competent authorities
4 Legal bases
All processing carried out by Graffenno relies on a legal basis provided for in the Lei Geral de Proteção de Dados (Lei nº 13.709/2018, the Brazilian General Data Protection Law).
Performance of a contract supports the processing necessary to provide the contracted services, including account creation, platform operation, and billing.
Compliance with a legal or regulatory obligation supports the retention of records and the issuance of documents required by applicable law.
Legitimate interest supports activities such as fraud prevention, information security, and service improvement, always with an assessment of the impact on the data subject's rights.
Consent is used when the purpose requires a specific manifestation by the data subject, such as certain marketing communications, and may be withdrawn at any time.
5 Data sharing
Graffenno does not sell personal data. Sharing occurs only when necessary to provide the service, to comply with legal obligations, or with the data subject's authorization.
Suppliers acting as Graffenno's processors handle data exclusively according to our instructions and are subject to contractual confidentiality and security obligations.
- Cloud infrastructure and hosting providers for the services
- Tax authorities, financial institutions, and integrated service providers, to enable the issuance of tax documents, billing, and contracted integrations
- Payment methods and billing services, to process transactions
- Analytics and communication tools used in the operation of the website and support
- Public authorities, when there is a legal request or court order
6 Cookies and similar technologies
The website uses cookies and similar technologies for functionality, audience measurement, and campaign measurement, including Google Analytics, Meta Pixel, and TikTok Pixel.
Details of the cookie categories used and instructions for managing them are available in the Cookie Policy.
7 Retention and deletion
Personal data is retained for as long as necessary to fulfill the purposes for which it was collected, or for the period required by applicable law, whichever is longer.
Once the agreement ends, account data may be retained for an additional period to meet legal retention obligations, the regular exercise of rights, and any potential need to substantiate operations.
At the end of the applicable periods, the data is securely deleted or anonymized.
8 Information security
We adopt technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, disclosure, or dissemination.
No system is completely immune to incidents. Should a significant security incident occur that could pose a risk or harm to data subjects, we will take appropriate action and make the notifications required by law.
- Encryption of data in transit
- Individual authentication per user, with unique credentials
- Permission controls by team and by access profile
- Logs of access and operations performed on the platform
- Infrastructure hosted with recognized cloud providers
9 Data subject rights
The law grants data subjects the right to confirm the existence of processing, access their data, correct incomplete or outdated information, request anonymization, blocking, or deletion of unnecessary data, request portability, obtain information about sharing, and withdraw consent.
Requests may be submitted through the channels indicated in this policy. To protect your data, we may request confirmation of your identity before fulfilling the request.
The privacy portal provides an explanation of each right and how to exercise it.
10 Changes to this policy
This policy may be updated to reflect changes to the platform, applicable law, or data processing practices. The current version is always available on this page, along with the date of the last update.
Material changes are communicated through registered contact channels or through a notice on the website.
11 Contact
Questions, requests, and complaints related to personal data may be sent to the data protection officer at [email protected].
You can also speak with our team through the support channel available on the website. All requests are logged and answered within the timeframes required by law.
Still have questions?
Talk to our team at [email protected] or through the chat on this site.
