Privacy Policy
Last updated: August 24, 2026. This Policy explains how Ecofyx processes personal data on its public pages, accounts, operations, support and billing.
1. Responsible entity and privacy channel
TIAGO BONFIM FERNANDES, CNPJ 20.979.792/0001-03, is responsible for Ecofyx and is established in Pindamonhangaba, São Paulo, Brazil. Privacy requests: contato@ecofyx.com.
2. Data-processing roles
- Controller: Ecofyx determines the processing of data required for registration, authentication, security, support, communications, billing, fraud prevention and service administration.
- Processor: as a general rule, Ecofyx processes on behalf of the Customer the registrations, responses, photos, files, locations and other operational records entered into operations.
- Customer as Controller: the organization or account owner determines the purpose, questions, people involved, permissions and period of use of Customer Content.
In some situations, these roles may vary according to the actual purpose and applicable law.
3. Data that may be processed
- Account and team: name, email, phone, organization, role, preferences, language, plan and permissions.
- Authentication and security: password protected by hashing, tokens, email confirmation, IP addresses, sessions, access attempts and technical logs.
- Sign in with Google: when this option is used, the unique Google Account identifier (
sub), name, email address and email-verification status needed to create or link the account and authenticate access. - Operations: forms, responses, registrations, comments, statuses, responsible persons, dates, times, photos, attachments and history.
- Location: coordinates, accuracy, associated point or area and required metadata when a geolocation feature is used.
- Commercial and billing: plan, billing cycle, payment status, billing identifiers and required tax information. Full card data is handled by the payment provider, not by Ecofyx.
- Support: messages, attachments, technical diagnostics and support history.
- Browsing: device, browser, pages accessed, cookies and authorized metrics.
Sign in with Google and Google user data
When a User chooses Continue with Google, Ecofyx uses Google Identity Services exclusively as an authentication method. Ecofyx receives and processes only the basic identity data required for this flow: the unique Google Account identifier (sub), name, email address and email-verification status.
- This data is used to create or locate the Ecofyx account, securely link an existing account, authenticate access, protect the session and prevent fraud or misuse.
- Ecofyx does not request access to the contents of Gmail, Google Drive, Google Calendar or Google Contacts in order to sign users in.
- Google user data received for sign-in is not sold or used by Ecofyx for advertising.
- The Google Account link is retained while needed for authentication and may be removed when the account is deleted, subject to legal obligations and minimal security records that may need to be retained.
- Use of data received from Google is limited to the purposes described in this Policy and to the permissions actually requested by Ecofyx.
4. Purposes and legal grounds
Data may be used to:
- create and manage accounts, teams, operations, templates and forms;
- authenticate users, protect sessions, prevent fraud and investigate incidents;
- record and display responses, evidence, alerts, results, history and exports;
- process subscriptions, payments, renewals, cancellations and tax obligations;
- provide support, answer requests and communicate service events;
- comply with legal or regulatory obligations and exercise rights in proceedings;
- improve performance and experience, using optional metrics only after consent when required.
Legal grounds may include performance of a contract and preliminary procedures, compliance with legal obligations, regular exercise of rights, legitimate interests subject to necessity and data-subject rights, fraud prevention and consent for optional purposes. The Customer is responsible for determining the legal basis for Customer Content under its control.
5. Geolocation, photos and sensitive data
Location and photos are collected only when the corresponding feature is activated and authorized by the device or when the User submits the content. The Customer must inform the people involved and limit collection to what is necessary.
Ecofyx does not require sensitive personal data as a general condition of use. If a Customer configures forms that process health, biometric, religious, trade-union, racial-origin, political-opinion, sex-life or genetic data, the Customer must assess the specific legal basis, risks, permissions and safeguards required.
6. Sharing and subprocessors
Data may be shared, to the extent necessary, with:
- hosting, database, storage, backup and security providers;
- email and transactional communication providers;
- payment and billing partners, such as Asaas, when a paid subscription is contracted;
- map and geocoding services activated by the User;
- Google Analytics or equivalent technology: Analytics cookies and storage are used only when authorized; before authorization, Google tag may operate in Consent Mode with storage denied and cookieless signals for aggregated measurement;
- technical-support, legal, accounting or security providers subject to confidentiality duties;
- public authorities when required by law, a valid order or the need to exercise legal rights.
Ecofyx does not sell personal data.
7. International transfers
Some providers may process data outside Brazil. In such cases, Ecofyx will consider mechanisms permitted by the LGPD and contractual, technical and organizational measures compatible with the risk and the contracted service.
8. Retention, backups and deletion
- Account and operational data are retained while necessary to provide the service and during the contractual relationship.
- Security, billing, support and evidentiary records may be retained for the periods required to comply with obligations, prevent fraud and exercise rights.
- After deletion or termination, data may be deleted or anonymized, except where retention is legally permitted or required.
- Backups follow a technical retention cycle and may keep temporary copies until normal rotation, with restricted access and recovery-only purposes.
- The account owner may request permanent deletion in Preferences. Before doing so, the owner should export any required data using the available tools.
9. Security and incidents
Measures appropriate to the nature of the service are used, including account separation, access control, session protection, request validation, rate limiting, upload protection, technical logs, backups and monitoring. No system can eliminate all risks.
Relevant incidents will be investigated, contained and communicated in accordance with applicable law, ANPD regulations, risks to data subjects and the Controller/Processor roles. Customers must keep contact information current and cooperate when they are Controllers of the affected data.
10. Data-subject rights
Where applicable, data subjects may exercise rights of confirmation, access, correction, information about sharing, portability, anonymization, blocking, deletion, objection, review of automated decisions, information about consent and withdrawal of consent. Requests should be sent to contato@ecofyx.com.
To protect data, Ecofyx may verify identity and legitimacy. When Ecofyx acts only as Processor, the request may be directed to the Customer acting as Controller.
11. Artificial intelligence
Idea-based creation resources may prepare prompts or, when an AI integration is configured and activated, send to the AI provider only the content supplied by the User and the context required for generation. Users should not include secrets, unnecessary personal data or sensitive data in prompts. Generated suggestions must be reviewed by an authorized person before publication.
12. Children and adolescents
Ecofyx is not directed specifically to children. If a Customer processes data relating to children or adolescents in an operation, the Customer must observe their best interests, provide appropriate transparency, limit collection and obtain authorizations when required. Higher-risk operations should receive a specific assessment.
13. Cookies and map services
Essential cookies support authentication, security and preferences. Optional Analytics and marketing cookies and storage depend on the choice recorded in the cookie manager. Google Analytics may initialize in Consent Mode with storage denied and send cookieless signals for aggregated measurement until authorization is granted. When map resources are opened, map providers may receive technical data such as IP address and the approximate area required to deliver the map. See the Cookie Policy.
14. Changes and contact
This Policy may be updated to reflect legal, technical or provider changes. Material changes will be communicated reasonably. Contact: contato@ecofyx.com.
15. References
This Policy takes into account Brazilian Law No. 13,709/2018 (LGPD), Law No. 12,965/2014 (Brazilian Internet Civil Framework), their regulations and guidance from the Brazilian National Data Protection Authority (ANPD).