We aim to collect only the data reasonably necessary to operate, protect and improve our services. We do not sell personal data.
1. Scope and data controller
This Policy applies to the websites, applications, software, content and other digital services operated by ANA CLARA ROCHA CLAUDINO, doing business as ACR DIGITAL BUSINESS, CNPJ 57.381.954/0001-09 (“ACR,” “we,” “us” or “our”).
For purposes of Brazil’s General Data Protection Law (Lei Geral de Proteção de Dados, or “LGPD”), ACR is the controller when it determines why and how personal data is processed. Our registered address is Rua Óseias Furtoso, 1051 — Leonor, Londrina, Paraná — 86073-170, Brazil.
2. Personal data we collect
The categories collected depend on the product you use and the choices you make.
Identity and contact data
Name, email address, telephone number, country and information submitted through forms or support requests.
Account and service data
Login details, preferences, subscription status, product settings and content you provide when using our services.
Health and wellness data
Information voluntarily provided for personalized plans, such as goals, routines, dietary preferences, measurements and progress entries.
Transaction data
Purchase, subscription, billing and payment-status information. Payment card details may be processed directly by our payment providers.
Technical and usage data
IP address, device and browser information, approximate location, access logs, pages viewed, interactions and diagnostic information.
Communications
Messages, feedback, survey responses and records of communications with our support or business teams.
We receive information directly from you, automatically through your use of our services, and from vendors that help us provide payments, hosting, analytics, security, customer support and marketing services.
3. How we use personal data
- Provide, personalize and maintain our InfoApps, SaaS products and digital services.
- Create and manage accounts, subscriptions, purchases and customer support.
- Process transactions and provide service, billing and administrative communications.
- Improve usability, reliability, security, content and product performance.
- Understand service usage and measure the effectiveness of our communications.
- Prevent fraud, abuse, security incidents and violations of our terms.
- Comply with legal, accounting, tax and regulatory obligations.
- Send promotional communications where permitted by law and according to your choices.
4. Legal bases for processing
Where the LGPD applies, we process personal data under one or more appropriate legal bases, including your consent; performance of a contract or steps requested before entering a contract; compliance with legal or regulatory obligations; protection of life or physical safety where applicable; exercise of rights in legal proceedings; and our legitimate interests, provided that your fundamental rights and freedoms are respected.
You may withdraw consent at any time. Withdrawal does not affect processing already performed lawfully before the request.
5. Health and wellness information
Certain information entered into health-focused products may qualify as sensitive personal data. We process this information only for clearly disclosed purposes, such as providing requested personalization, tracking user-entered progress and improving the relevant service, and only when an applicable legal basis permits it.
Where required, we request specific and highlighted consent. We do not use sensitive data for unlawful discrimination or sell it. Our products provide informational and organizational support and do not replace diagnosis, treatment or advice from a qualified healthcare professional.
6. Payments and subscriptions
Payments may be handled by independent payment providers such as Stripe. When you enter payment information, that information may be collected directly by the payment provider under its own privacy terms and security standards. We may receive limited transaction information, such as payment status, billing contact information, amount, currency and transaction identifiers, to fulfill your purchase, manage subscriptions, prevent fraud and maintain accounting records.
We do not use payment information for purposes unrelated to providing, securing and administering the transaction and associated services.
7. Cookies and similar technologies
We may use cookies, pixels, local storage and comparable technologies to keep services functioning, remember preferences, maintain security, understand performance and, where permitted, measure marketing activity.
Where required, non-essential cookies are used according to your consent choices. You can also control cookies through browser settings, although disabling necessary cookies may affect functionality.
8. When we share personal data
We may disclose personal data only as reasonably necessary to:
- Vendors processing data on our behalf, including hosting, infrastructure, analytics, communications, customer support and security providers.
- Payment processors, financial institutions and fraud-prevention providers involved in transactions.
- Professional advisers, auditors and service providers bound by confidentiality obligations.
- Authorities or other parties where disclosure is required by law, legal process, or necessary to protect rights and safety.
- A successor or participant in a legitimate corporate transaction, subject to appropriate safeguards.
Service providers are authorized to process personal data only for contracted purposes and under applicable data-protection obligations. We do not sell personal data.
9. International data transfers
Because our services may operate globally, personal data can be processed in countries other than the country where you live. When personal data is transferred internationally, we use appropriate safeguards and transfer mechanisms required by applicable law, considering the nature of the data and the destination.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the service, maintaining transaction and security records, resolving disputes, enforcing agreements and complying with legal, tax, accounting and regulatory requirements.
Retention periods vary according to the type of data, the service involved, legal requirements and relevant risks. When data is no longer required, we take reasonable steps to delete, anonymize or securely isolate it.
11. Information security
We apply reasonable administrative, technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure or destruction. These measures may include access controls, authentication, monitoring, backups, vendor review and encryption where appropriate.
No electronic transmission or storage system is completely secure. If you believe your account or data may have been compromised, contact us promptly.
12. Your privacy rights
Depending on applicable law, including the LGPD, you may request:
To protect you, we may need to verify your identity before completing a request. Rights are subject to legal exceptions, including situations where retention is required by law. Requests can be sent without charge to the contact listed below.
13. Children and adolescents
Our services are intended for adults and are not directed to children. We do not knowingly collect personal data from children without the authorization and safeguards required by applicable law. If you believe a child has provided data improperly, contact us so we can evaluate and take appropriate action.
14. Changes to this Policy
We may update this Policy to reflect changes in our services, practices, technologies or legal obligations. The current version will be posted on this page with an updated effective date. When legally required, we will provide additional notice or request renewed consent.
15. Contact us
For privacy questions, requests or concerns, contact the controller through the channel below. Please describe your request clearly and identify the service involved.
ACR Digital Business — Privacy Contact
ANA CLARA ROCHA CLAUDINO · CNPJ 57.381.954/0001-09
Rua Óseias Furtoso, 1051 — Leonor, Londrina, Paraná — 86073-170, Brazil