Privacy Policy
Last updated: October 8, 2026 · version 1.3
How Keypoint handles the data of people who create an account, subscribe to Lens or visit our website, and what your rights are.
1. Who we are and who this policy applies to
KEYPOINT SOLUÇÕES EM TECNOLOGIA LTDA, CNPJ registration in progress, headquartered at Goiânia/GO, Brazil, is the controller of the personal data described in this policy: data of people who create an account and subscribe to Keypoint Lens (the “Customers”), usage and billing data, and data of people who visit our public website or join the waitlist.
This policy does NOT cover the data of visitors and buyers of our Customers’ websites. For that data, the Customer is the controller and Keypoint is the processor; see the Data Processing Agreement (DPA).
Data Protection Officer (DPO): [email protected].
2. What data we collect
- Registration: name, e-mail, phone, company; CPF or CNPJ (Brazilian tax IDs) for invoicing.
- Billing: payment data, which is tokenized by the gateway (Asaas or Stripe); we do not receive your full card number.
- Access and security: login records, IP address, device and browser data.
- Service usage: actions in the dashboard, features used, quota consumption, settings.
- Support: messages and attachments you send us.
- Public website and waitlist: e-mail and data you provide in forms; the minimum technical data needed for security (anti-bot).
- Integrations you authorize: ad data read from Meta Ads (via OAuth) and, if connected, WhatsApp Business data (via the official API).
3. Why we use data and on what legal bases
| Purpose | Legal basis (LGPD art. 7 / GDPR art. 6) |
|---|---|
| Create and maintain the account, provide the Service, support | Performance of a contract |
| Bill, issue NFS-e and meet tax and accounting obligations | Performance of a contract and legal obligation |
| Security, fraud and abuse prevention, access logs | Legitimate interests (and legal obligation where applicable) |
| Product improvement using minimal and, where possible, aggregated data | Legitimate interests |
| Marketing e-mails and measurement cookies | Consent (which you can withdraw at any time) |
Where we rely on legitimate interests we apply data minimization and you may object, as provided by law.
5. Who we share data with
We share data only with the subprocessors listed on the “Subprocessors” page, as needed for hosting, delivery, payment, authentication and AI analysis, and with authorities where required by law or court order. We do not sell personal information and we do not share it for cross-context behavioral advertising.
6. International transfers
Our servers are in France (European Union), but some subprocessors are in the United States, Iceland or other countries. International transfers are made under article 33 of the LGPD and, for data subject to the GDPR, using the European Commission’s Standard Contractual Clauses (SCCs), adequacy decisions and/or the provider’s own safeguards, as applicable.
7. How long we keep data
- Account data: while the account is active.
- After cancellation or closure: archived for 30 days and then permanently deleted, with a notice 1 day before.
- Tax and billing records: for the period required by tax and accounting law.
- Security logs: for as long as necessary for the purpose and for the applicable legal periods.
8. Security
We use encryption in transit (TLS), role-based access control, access logging, two-factor authentication (available), Meta and gateway tokens kept on the server only, and masking of sensitive fields in the browser before sending. No measure is infallible; in case of an incident posing a relevant risk, we will notify affected individuals and the authorities as the law requires.
9. Your rights
Under article 18 of the LGPD you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about sharing, deletion of data processed on the basis of consent, and withdrawal of consent. If the GDPR applies to you (EU/EEA/UK), you also have the rights in articles 15 to 22: access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with significant effects. California residents have the right to know, delete and correct their personal information under the CCPA.
We do not sell or share personal information, so there is nothing to opt out of under “Do Not Sell or Share My Personal Information”. We do not discriminate against anyone who exercises their rights. To exercise any right, write to [email protected]; we reply within the periods set by law. You may also complain to the Brazilian data protection authority (ANPD) or, if you are in the EU/UK, to your local supervisory authority.
10. Minors
The Service is not intended for people under 18 and we do not knowingly collect their data. If we identify such a case, we will delete the data.
11. Data of visitors to our Customers’ websites
When a Customer installs the Lens recorder on their website, Keypoint processes visitor and buyer data as a processor, only on the Customer’s instructions. If you are a visitor of a site that uses Lens and want to exercise your rights, please contact the site owner first; we can also help through [email protected] if you give us your visit ID, when you have it.
12. Changes to this policy
We may update this policy. Material changes will be notified by e-mail or in the app, 30 days in advance when they affect your rights. The date of the last update is shown at the top of this page.
13. Contact
Privacy and Data Protection Officer (DPO): [email protected] · Security: [email protected] · Support: [email protected].