This policy explains personal data processing on the CivilTalks website and in Builder BO. The identity of the controller, the privacy contact, purposes, service providers involved and retention criteria are presented on this page.
PRIVACY
About this policy
DATA
Information you provide
Builder BO receives the professional and commercial information you choose to provide to introduce your business and an expansion project. The current version does not accept attachments. Do not submit sensitive personal data, children’s data, payment information, credentials, unnecessary trade secrets or third-party information without authorization.
PURPOSES
Use of information
Information is used to save, resume and assess the request, respond to the contact and prepare a potential contractual relationship. Limited technical data may also be processed for operation, security, rate limiting, abuse prevention and auditing. Builder does not make solely automated decisions, and the content is not used for marketing or unauthorized training.
INFRASTRUCTURE
Direct technical collection abroad
Technical connection and security data may be collected directly by infrastructure operators abroad. When that is the concrete flow verified in the V06 record, it will be documented separately as direct international collection under article 6 of CD/ANPD Resolution No. 19/2024 and will not automatically be described as an international transfer.
PROVIDERS
Transfers of data submitted through Builder
OpenAI Sites, Cloudflare, Resend and GoDaddy/Titan are recorded separately by role and flow in the table on this page. The table distinguishes direct technical collection from cases in which professional, company, commercial and operational data voluntarily provided through Builder are sent abroad. Before submission, Builder asks for specific, prominent, unchecked and revocable consent to those transfers. The notice identifies the purpose, data categories, providers, known locations, absence of guaranteed residency in Brazil and the withdrawal channel. Anyone who does not wish to use Builder may contact CivilTalks by email or WhatsApp.
RIGHTS
Retention and rights
Data is retained for the periods or according to the criteria stated on this page and applicable obligations. Requests for access, correction, consent withdrawal or deletion must be sent to info@civiltalks.com and will be answered within 15 days. When an account is deleted, personal data will be erased within 30 days, except for records the law requires us to retain. Data controller: VERUM CIVILTALKS INOVAÇÃO E SISTEMAS LTDA.
Data controller
- Legal name
- VERUM CIVILTALKS INOVAÇÃO E SISTEMAS LTDA
- Registration
- CNPJ 66.391.001/0001-12
- Registered address
- Quadra SHIS QI 15, Bloco A, Sobreloja 47, Setor de Habitações Individuais Sul / Lago Sul, Brasília - DF
Privacy contact
- info@civiltalks.com
- Responsible role
- Privacy and LGPD channel — data controller: VERUM CIVILTALKS INOVAÇÃO E SISTEMAS LTDA
Last updated
- Policy version
- 2026-09-06.1
- Effective date and time
- September 6, 2026 at 10:01 PM GMT-3
Purposes and retention
| Purpose | Data categories | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Receive, save, resume and assess the Builder BO submission, respond to the commercial request and prepare a potential proposal. | Representative’s professional identification: name, work email, role, optional phone number and contact language, Business identification and context: name, headquarters country, type, website or institutional profile and investment readiness, Commercial information about the solution, markets, objectives, pricing and channels, Operational information about sales, delivery, logistics, requirements, competitors, team and constraints, Acknowledgement metadata, notice version, reference number, revisions and draft status | LGPD, article 7(V) — preliminary procedures related to a potential contract, requested by the data subject. | Authorized CivilTalks commercial team, OpenAI Sites, Cloudflare, Resend, GoDaddy | Unsubmitted draft for 30 days after the last edit; after submission, as a lead, for 24 months after the last interaction or until an applicable opt-out, according to the detailed rules below. |
| Operate and protect the website and Builder BO, prevent abuse, control concurrent edits and maintain traceability for relevant events. | Pseudonymous session token and random request, submission, reference, revision and event identifiers, One-way hash derived from the network address for attempt limiting, Dates, times, operation status, schema version and audit events without form contents in technical logs | LGPD, article 7(IX), together with articles 10 and 46 — legitimate interests for security, rate limiting, abuse prevention and auditing, subject to a balancing test, minimization, restricted access and a limited retention period. | Authorized CivilTalks technical team, OpenAI Sites, Cloudflare | Access/application logs, audit/security logs and technical rate-limit buckets for 12 months; then delete. |
Providers and international flows
| Provider | Service | Role | Purpose | Data categories | Countries | Relevant subprocessors | Transfer mechanism | Retention | Security measures | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|
| OpenAI Sites | Orchestration of website publishing and hosted configuration. | Processor for the hosted website publishing, maintenance and support layer | Host, publish, maintain, operate and support the website and Builder BO experience | Technical connection, device, cookie, usage, security-event and pseudonymous identifier data, Professional, company, commercial and operational data entered in Builder, with consent and submission metadata | United States — contracting entity applicable to the Brazilian customer and location of multiple infrastructure, support and moderation providers, Australia, Brazil, Canada, Finland, France, Germany, India, Indonesia, Ireland, Italy, Japan, Malaysia, Mexico, Netherlands, Norway, Philippines, Poland, Singapore, South Africa, South Korea, Spain, Sweden, Switzerland, UAE and United Kingdom — additional published locations for providers that may support Sites | Cloudflare Ltd, Microsoft Corporation, CoreWeave, Inc., Oracle Cloud Infrastructure, Google Cloud Platform, Amazon Web Services, Inc., Cerebras, Snowflake, Inc., TaskUs, LLC, Intercom, Inc., Salesforce, Accenture International Limited, Confluent, Cinder Technologies, Inc., Okta, Inc. — authentication services via Auth0, OpenAI OpCo, LLC, OpenAI, LLC, OpenAI Ireland Ltd., OpenAI UK Ltd., OpenAI Japan Ltd. | Builder-specific consent, together with the Sites DPA as the processor contract and a complementary safeguard; the DPA clauses for the EEA, Switzerland and UK are not presented as Brazilian standard clauses. | The DPA retains hosted data during the service and provides for return or deletion upon instruction, expiry or termination, subject to legal duties; it does not set one operational day count for every record. | Encryption in transit and at rest, strict access controls and security monitoring stated by the provider, Personnel confidentiality, reasonable technical and organizational measures, incident assistance and end-of-term deletion provided by the DPA | Verified record Processor document: ChatGPT Sites Data Processing Addendum (Published 2026-07-09) Public version date: July 8, 2026 at 09:00 PM GMT-3 Official document Verified at: September 6, 2026 at 04:23 PM GMT-3 Official source |
| Cloudflare | Website execution and D1 persistence; R2 is retained only for the controlled deletion of legacy attachments. | Processor for execution, edge security and D1 persistence; R2 remains limited to legacy-attachment deletion | Run and protect the site, control abuse and persist drafts, submissions, consent records and technical trails in D1 | Technical connection data, security events, pseudonymous identifiers and request metadata, Builder professional, company, commercial and operational data, plus consents, revisions and audit trails | Cloudflare global network and D1 automatic placement; product documentation does not promise a single country in this mode, United States, EEA, United Kingdom, Japan, Australia, Canada, Singapore and India — published Google and Oracle locations for Cloudflare Developer Platform, United Kingdom, Singapore, Australia, Germany, Portugal, France, Japan, Canada, Netherlands, UAE, United States, South Korea, Mexico, Malaysia, India, Sweden and Switzerland — group entities for account and engineering support | Slack Technologies, Inc. — customer-support communications, Zendesk, Inc. — customer support and account management, Salesforce, Inc. — customer support and account management, Google LLC — Cloudflare Developer Platform, Oracle America, Inc. — Cloudflare Developer Platform, Cloudflare Ltd., Cloudflare Pte. Ltd., Cloudflare Australia Pty Ltd, Cloudflare Germany GmbH, Cloudflare Portugal, Unipessoal Lda., Cloudflare France SAS, Cloudflare Japan K.K., Cloudflare (Canada) Information Technology Co., Ltd., Cloudflare Netherlands B.V., Cloudflare Middle East FZ-LLC, Area 1 Security, LLC, Cloudflare Korea LLC, Cloudflare Mexico S. de R.L de C.V., Cloudflare Malaysia Sdn. Bhd., Cloudflare Capability Center (India) Private Limited, Cloudflare Sweden AB, Cloudflare Switzerland GmbH | Builder-specific consent and the current Cloudflare DPA as the processor contract and a complementary safeguard; adoption of ANPD Brazilian standard clauses is not asserted. | D1 records follow the CivilTalks schedule. The DPA limits processing to necessity or the agreement; D1 Time Travel is always active for 7 days on Free or 30 days on Paid, without proving which plan Sites manages. | D1 and R2 document AES-256-GCM at rest and TLS in transit, ISO 27000 program, vulnerability testing, bug bounty, intrusion detection, geographic resilience, least privilege, strong MFA and audit logging described in the DPA | Verified record Processor document: Cloudflare Customer Data Processing Addendum (Version 6.4 — effective 2026-04-03) Public version date: April 2, 2026 at 09:00 PM GMT-3 Official document Verified at: September 6, 2026 at 04:23 PM GMT-3 Official source |
| Resend | Transactional delivery of the Builder BO assessment, without attachments. | Processor for transactional email delivery | Deliver the Builder submission to info@civiltalks.com and record its technical sending status | Sender, recipient, subject, assessment text and technical delivery metadata; no attachments and no open or click tracking | Brazil — transactional routing selected in São Paulo (sa-east-1), United States — headquarters, account data, email metadata, logs and API records; every published subprocessor is in the United States | Amazon Web Services, Inc., Anthropic, PBC, Attio Limited, Cloudflare, Inc., Datadog, Inc., Elastic N.V., Estuary Technologies, Inc., Google, Inc., Inngest Inc, Liveblocks, Inc., Metabase, Inc., Not Just Tickets Limited / Plain, PlanetScale, Inc., Retool, Inc., RunPod, Inc., Salesforce, Inc. — Slack, Snowflake Inc., Stripe, Inc., Supabase, Inc, Svix Inc., Tinybird Inc., Vercel Inc. | Builder-specific consent and the Resend DPA as the processor contract and a complementary safeguard; adoption of ANPD Brazilian standard clauses is not asserted. | The DPA covers the agreement term and provides for deletion of user and customer data within 90 days after account termination. Security documentation describes 30-day point-in-time backups; the application does not rely on them for restoration. | TLS 1.3 or higher in transit, encryption at rest and row-level isolation for sensitive data stated by the provider, SOC 2 Type II, annual penetration testing and employee MFA stated by the provider, Dedicated sending key restricted to civiltalks.com; open and click tracking disabled in the verified panel | Verified record Processor document: Resend Data Processing Addendum (Last updated 2026-08-27) Public version date: August 26, 2026 at 09:00 PM GMT-3 Official document Verified at: September 6, 2026 at 04:23 PM GMT-3 Official source |
| GoDaddy | Hosting of the info@civiltalks.com mailbox that receives transactional messages. | Contractual processor for the Professional Email powered by Titan mailbox; Titan provides and stores the mailbox service | Receive and store the Builder transactional message in the info@civiltalks.com mailbox | Sender, recipient, subject, Builder submission text and message metadata; no attachments sent by Builder | United States and Cayman Islands — GoDaddy and Titan, United States, Canada, Spain and Estonia — locations in Titan's subprocessor list | Titan Solution Ltd SEZC — Cayman Islands, Amazon Web Services, Inc. — USA, Zendesk, Inc. — USA, SendGrid, Inc. — USA, Pendo.io, Inc. — USA, Canny Inc. — Canada, Typeform — Spain, Proofpoint, Inc. — USA, OpenAI — USA, WebSpellChecker — Estonia, MoEngage — USA | Builder-specific consent, the GoDaddy DPA and Professional Email/Titan terms as complementary contractual safeguards; Titan's GDPR clauses are not presented as a Brazilian mechanism. | CivilTalks deletes lead messages after 24 months without interaction, subject to contracts, legal duties or legal hold. Titan Trash is deleted after 30 days and permanently deleted items cannot be restored; the agreements provide for deletion or return at termination under their terms. | Risk-based measures, least privilege, event logging, encryption or pseudonymization and MFA for internal remote access described in the GoDaddy DPA, SPF, DKIM, DMARC, anti-spam and antivirus documented for Professional Email powered by Titan; account posture is verified separately | Verified record Processor document: GoDaddy Data Processing Addendum (Last revised 2024-09-13) Public version date: September 12, 2024 at 09:00 PM GMT-3 Official document Verified at: September 6, 2026 at 04:23 PM GMT-3 Official source |
Processing flows
| Provider | Flow type | Purpose | Data categories | Countries | Legal basis or condition |
|---|---|---|---|---|---|
| OpenAI Sites | Direct international collection | Deliver, maintain and protect the hosted site and record necessary technical events | Technical connection, device, cookie, usage, security-event and pseudonymous identifier data | United States and other published Sites infrastructure and support locations, with no data-residency guarantee at launch | Direct technical collection by an overseas processor, separate from the Builder transfer; security relies on legitimate interests with minimization and LGPD articles 10 and 46 safeguards. |
| OpenAI Sites | International transfer | Process the Builder request the data subject chose to submit | Professional, company, commercial and operational data entered in Builder, with consent and submission metadata | United States and other published locations for providers that may support Sites | Specific, prominent, unticked and revocable international-transfer consent under LGPD article 33(VIII); the DPA serves as the processor contract and a complementary safeguard. |
| Cloudflare | Direct international collection | Deliver the site, mitigate bots, apply request limits and protect the application | Technical connection data, security events, pseudonymous identifiers and request metadata | Cloudflare global network | Direct technical collection by an overseas processor, separate from the Builder transfer; security relies on legitimate interests with minimization and LGPD articles 10 and 46 safeguards. |
| Cloudflare | International transfer | Persist and process drafts, submissions, consents and audit trails in D1 | Builder professional, company, commercial and operational data, plus consents, revisions and audit trails | Global locations resulting from D1 automatic placement and the published Developer Platform providers | Specific, prominent, unticked and revocable international-transfer consent under LGPD article 33(VIII); the DPA serves as the processor contract and a complementary safeguard. |
| Resend | Processing in Brazil | Route the transactional delivery through the selected region | Message text and metadata needed for sending | Brazil — São Paulo | Preliminary procedures requested by the data subject under LGPD article 7(V); the routing region was verified in the panel. |
| Resend | International transfer | Process content and metadata needed for delivery and maintain service records | Sender, recipient, message text, metadata, logs and API records | United States | Specific, prominent, unticked and revocable international-transfer consent under LGPD article 33(VIII); the DPA serves as the processor contract and a complementary safeguard. |
| GoDaddy | International transfer | Deliver and retain the request message in the business mailbox monitored by CivilTalks | Sender, recipient, subject, Builder submission text and message metadata | United States, Cayman Islands, Canada, Spain and Estonia | Specific, prominent, unticked and revocable international-transfer consent under LGPD article 33(VIII); the contractual documents serve as complementary safeguards. |
Retention criteria by data class
| Data class | Period or criterion |
|---|---|
| Draft | Unsubmitted Builder BO drafts: delete 30 days after the last edit. |
| Lead | Leads: anonymize 24 months after the last interaction, or earlier upon an applicable opt-out, subject to any legal retention obligation. |
| Contract | Contracts and active-client data: retain for the engagement term and 5 years after termination; then delete, subject to specific legal obligations. |
| File | Legacy attachments not linked to an active record: delete after 90 days. Builder BO does not accept new attachments. |
| Consent | Evidentiary consent records linked to processing activities: retain while processing continues and for 5 years afterwards; then delete. Separately, the local CMP technical preference (ct_consent in cookie and localStorage) expires after 180 days. |
| Access/application log | Access and application logs: delete after 12 months. |
| Audit/security log | Audit and security logs: delete after 12 months; the deletion event retains only non-personal metadata needed to audit the deletion itself. |
| Backup | Backups: 30-day rotation; deleted data leaves backups within 35 days through overwriting. |