Privacy and the protection of personal data are priorities for the Abrasel NDP platform. This Privacy Policy explains how the platform collects, uses, stores, shares, and protects information in the context of our website, the Abrasel administrative management platform, and related services. The platform is operated by Jéssica Naiara dos Santos, registered under CNPJ No. 42.182.370/0001-37, headquartered in Londrina/PR, Brazil. We process personal data in accordance with the Brazilian General Data Protection Law (LGPD) – Law No. 13.709/2018. By using our services, you acknowledge that you have read and understood this Policy.
1. Scope
This Policy applies to the processing of personal data carried out in connection with:
- Our institutional website and promotional pages;
- The Abrasel NDP platform, including the regional unit’s management panel;
- Administrator users, directors and administrative staff who access the platform;
- The persons recorded by the Client (service providers, meeting contacts, participants and other individuals related to the regional unit’s operation);
- The documents and content processed by the platform;
- Integrations with third-party services (such as Microsoft 365 / Teams, email, digital signature and the AI gateway);
- Automations and artificial intelligence (AI) features;
- The cookies and tracking technologies used;
- Support and customer service channels.
2. Roles under the LGPD
The LGPD distinguishes between different roles in the processing of personal data. Depending on the situation, the platform operator may act in different roles:
When the operator acts as Controller
In relation to data of website visitors, leads, and the contracting units (for example, registration, billing, and communication data of the regional unit and its representatives), the operator may act as Controller, defining the purposes and means of processing.
When the operator acts as Processor
In relation to records, documents, meeting data, and other data processed on behalf of the contracting Abrasel unit, the operator normally acts as Processor (Operator), processing data according to the Client’s instructions.
The contracting Client as Controller
The Abrasel regional or sectional unit that contracts the platform is the Controller of the data it inserts and manages — service providers, persons, meeting participants, directors, staff and other contacts. It is the Client’s responsibility to define the purposes of processing, ensure an appropriate legal basis, inform data subjects, and configure the platform in compliance with the LGPD.
3. Data Collected
We may collect and process the following categories of data:
Registration data
- Name of the unit, company, CNPJ (corporate taxpayer ID);
- Email, phone, address;
- Billing data.
User data
- Name, email, phone;
- Group, role and permissions;
- Access logs.
Registration and operational data
- Service providers (name, CNPJ/CPF, banking details);
- Vehicles and corporate cards;
- Persons and meeting contacts (name, phone, email).
Operation data
- Reimbursements, mileage, expenses and corporate card records;
- Institutional documents (official letters, receipts, forms);
- Meetings, attendance, transcriptions and minutes;
- Attachments, receipts and supporting files;
- Internal notes and processing status.
Technical data
- IP address, browser, device, and operating system;
- Date and time of access, logs, and usage events;
- Cookies and similar identifiers.
Payment data
- Contracted plan and billing status;
- Financial history;
- Data processed by payment gateways.
AI data
- Prompts and knowledge bases;
- Questions and answers;
- Curated memory and content used by the assistant.
4. Sensitive Data
The platform does not require sensitive personal data for the general operation of the regional unit’s management. However, depending on how the Client uses it, sensitive data may pass through the platform, such as financial data, personal identification documents, or other data protected by law.
When this occurs, the Client, as Controller, is responsible for:
- Adopting an appropriate legal basis for the processing;
- Informing data subjects about the processing;
- Configuring the platform in a manner compatible with the LGPD and other applicable rules.
5. Purposes of Processing
We process personal data for the following purposes:
- To create and manage user accounts;
- To provide the contracted services;
- To control reimbursements, mileage, expenses and the corporate card;
- To generate institutional documents (official letters, receipts, forms);
- To manage meetings, attendance and the generation of minutes;
- To operate integrations with third-party services;
- To enable use by directors and administrative staff according to their permissions;
- To process artificial intelligence features (always under user confirmation for actions);
- To provide support to the Client;
- To improve and enhance the platform;
- To ensure the security of the services;
- To prevent fraud and misuse;
- To maintain the audit trail and comply with legal and regulatory obligations;
- To carry out billing and manage payments;
- To send operational communications;
- To send commercial communications, where permitted.
6. Legal Bases
The operator’s processing of personal data may be based on the following legal bases provided for in the LGPD:
- Performance of a contract or preliminary procedures;
- Compliance with a legal or regulatory obligation;
- Legitimate interest;
- Consent, where applicable;
- Regular exercise of rights in judicial, administrative, or arbitration proceedings;
- Credit protection, where applicable.
7. Sharing with Third Parties
In order to provide the services, the operator may share personal data with third parties, always to the extent necessary, including:
- Hosting and cloud infrastructure providers;
- Database providers;
- Artificial intelligence services (AI gateway);
- Payment gateways;
- Email delivery services;
- Authentication services;
- Microsoft 365 / Teams, for calendar, recording and meeting transcription;
- Digital signature services (Gov.br / ITI);
- WhatsApp, for notifications and document delivery, where enabled;
- Analytics and monitoring services;
- Technical support providers;
- Public authorities, when required by law or court order.
The operator does not sell personal data.
8. International Transfer
Some data may be processed outside Brazil, as part of our cloud, AI, infrastructure, payment, and integration providers may operate in other countries. In these cases, we seek to adopt appropriate measures to protect the data, in accordance with the LGPD.
9. Security
We adopt reasonable security measures, both technical and administrative, to protect personal data against unauthorized access, loss, and misuse, such as:
- Access control and granular permissions;
- Encryption, where applicable;
- Log recording and audit trail;
- Permission segregation;
- Backups;
- Monitoring;
- Complementary administrative and technical measures.
Although we make ongoing efforts to protect data, no system is completely immune to incidents, and absolute security cannot be guaranteed.
10. Retention
Personal data is retained for as long as the account is active and for as long as necessary for the purposes described in this Policy. Data may be retained for an additional period to comply with legal obligations, audits, security, billing, or the regular exercise of rights.
Records, documents and files follow the storage limits of the contracted plan. After cancellation, there is a retention period before definitive deletion, and backups may retain data for an additional technical period. Further details may be set out in our Backup and Data Retention Policy.
11. Data Subject Rights
Under the LGPD, data subjects may exercise the following rights:
- Confirmation of the existence of processing;
- Access to the data;
- Correction of incomplete, inaccurate, or outdated data;
- Deletion of data, where applicable;
- Portability;
- Withdrawal of consent;
- Information about data sharing;
- Objection to processing carried out on a basis other than consent;
- Review of automated decisions, where applicable.
When the operator acts as Processor, requests from data subjects whose data was inserted by the Client (service providers, persons, meeting participants, directors, staff and other contacts) must be directed to the contracting Client, who is the Controller of such data.
12. Cookies
We use cookies and similar technologies, which may be:
- Essential cookies, necessary for the operation of the website and the platform;
- Analytics cookies, which help us understand usage and improve the services;
- Marketing cookies, where applicable, for promotional purposes.
You can disable or manage cookies in your browser settings, being aware that this may affect some features. Further information may be set out in our Cookie Policy.
13. Audit Trail and Permissions
The platform records the actions performed by Users in an audit trail (who did what and when) and controls access through granular permissions. These records are essential for the security, transparency and accountability of the regional unit, and are processed on the basis of legitimate interest and the performance of the contract, as well as the Client’s own instructions as Controller.
14. AI and Privacy
The platform may process data through artificial intelligence features to read data from the modules, generate suggestions, draft minutes from transcriptions, and propose actions. The AI assistant executes actions only upon user confirmation and never acts on its own. The Client is responsible for configuring AI with caution and for reviewing and confirming the actions and content generated.
Data processed on the platform is not used for the public training of third-party models, except with authorization. When AI processing depends on external providers (AI gateway), it is subject to the conditions and practices of those providers.
15. Data Protection Officer / Privacy Contact
For questions about privacy and the LGPD, please contact us at: [email protected].
16. Updates to This Policy
This Privacy Policy may be updated periodically. Relevant changes will be communicated by email, notice in the platform panel, or publication on the website. We recommend that you review this document periodically.