Solução patenteada · contratação por inexigibilidade ou dispensa

Compliance Portal · Privacy

Privacy Notice

Which personal data we collect on the website and on the platform, how long we keep it, who we share it with and how you exercise your rights — context by context, in plain language.

Data protection officer (DPO): lgpd@ebaem.com.br · data subject requests answered within 15 days

Privacy Notice · Version 1.0 · In force since 2 September 2026

This notice explains, in plain terms, which personal data EBAEM LTDA (“EBAEM”, “we”) collects when you use the website www.observatoriogestao.com.br or the Observatório de Gestão platform (painel.observatoriogestao.com.br), why it collects it, how long it keeps it, who it shares it with and how you can exercise your rights.

1. Who is responsible for the processing

EBAEM LTDA — CNPJ (Brazilian tax ID) 55.054.849/0001-30 — SRTVN Quadra 702, Lote P, Edifício Rádio Center, Salas SS18 a SS28, Asa Norte, Brasília/DF, Brazil, ZIP 70719-900 — +55 (61) 98128-6479. Data protection officer (DPO): lgpd@ebaem.com.br.

When you use the platform as part of the team of a public entity or of an accredited consultant, the controller of the data your organisation enters is the organisation itself; EBAEM acts as processor, as set out in the LGPD Policy.

2. Who this notice applies to

  • visitors to the website;
  • people who fill in the contact, support, whistleblowing, data protection request or accreditation forms;
  • representatives of public entities and consultants during contracting and payment;
  • platform users (managers, civil servants, consultants and their teams);
  • people whose data appears in the public databases we monitor.

3. What data we collect, what for and for how long

ContextData collectedPurposeLegal basisRetention
Browsing the websiteIP address, browser, device, pages visited, cookiesoperation, security and aggregate statistics (the latter only with consent)legitimate interest; consent for non-essential cookieslogs: 6 months; cookies: see the Cookie Policy
Contact form and proposal requestsname, e-mail, phone, organisation, role, type of entity, messagereplying, sending a proposal, scheduling a demopre-contractual procedures; legitimate interestup to 2 years after the last contact
Supportcontact details, organisation, module affected, description of the problem, attachmentshandling and recording the ticketperformance of a contractterm of the contract + 2 years
Whistleblowing channelcontent of the report, attachments and, if you choose to identify yourself, name and e-mailinvestigating the report and replyinglegitimate interest; regular exercise of rightsduration of the investigation + the limitation period
Data protection requestsidentification, e-mail, right requested, identity verification documentsmeeting the request and evidencing that it was metcompliance with a legal obligation5 years after it is closed
Purchase and subscription (checkout)details of the person responsible, CNPJ, legal name, address, type of entity, billing details; payment is processed by Asaasformalising, invoicing and chargingperformance of a contract; legal (tax) obligation5 years after the end of the contract
User account on the platformname, e-mail, login, role, permissions, authorised companies and territories, second authentication factorauthenticating, authorising and personalising accessperformance of a contractterm + 90 days for export
Platform logs and audit trailuser, action, date and time, IP address, resource accessedsecurity, auditing and accountabilitylegal obligation; legitimate interestaccording to the configured retention policy, with controlled purging
Consultant accreditationprofessional details, areas of expertise, qualification documentsreviewing and formalising the accreditationpre-contractual procedures; performance of a contractterm + 5 years
Corporate communicationsname and e-mailproduct news and announcementsconsentuntil it is withdrawn

4. Data we do not collect

  • Sensitive data — we do not ask for it in any form. If you include it in a report, it is handled confidentially and only for the investigation.
  • Data of people under 18 — the website and the platform are intended for organisations and professionals.
  • Full card numbers — payment is processed by Asaas; we keep only the charge status and the identifiers generated by the processor.

5. Publicly available data on the platform

The platform collects and organises official federal databases (CAUC, Transferegov/SICONV, parliamentary amendments, the Federal Official Gazette, FNS, FNDE, PAC, BNDES, IBGE). Where those databases contain personal data — the name of a manager, a member of parliament or a beneficiary — the processing observes the purpose, the good faith and the public interest that justified its disclosure (LGPD, article 7, § 3) and is limited to reproducing and organising information that is already public.

6. Cookies

We use necessary, functional, analytics and performance cookies; we do not use advertising cookies. The categories, the duration and how to manage each one are in the Cookie Policy. You can review your choices at any time through the “Cookie preferences” button.

7. Who we share data with

  • Hosting and infrastructure — running and storing the platform (Brazil).
  • Cloudflare — DNS, protection against attacks and site performance.
  • hCaptcha — anti-spam protection on forms.
  • Transactional e-mail provider — sending case numbers, confirmations and notifications.
  • Asaas — payment processing (bank slip, PIX, card).
  • Google Drive (optional, configured by the customer) — archiving of reports.
  • Public authorities — when required by law, regulation or court order.

None of these partners may use your data for their own purposes. The full table, with the data involved and its location, is in the LGPD Policy.

8. International transfers

Some providers (site protection, anti-spam, e-mail) may process technical data outside Brazil, with the safeguards of article 33 of the LGPD — standard contractual clauses or equivalent — and limited to the minimum necessary. The platform data is hosted in Brazil.

9. How we protect your data

Encryption in transit (TLS) and of secrets at rest, multi-factor authentication, access control by role, company and territory, an audit trail, backups with a defined retention period, segregated environments and vulnerability management. Details in the Information Security Policy.

10. Your rights

You may request confirmation of processing, access, correction, anonymisation, blocking or deletion, portability, information about sharing, withdrawal of consent and objection to processing (LGPD, article 18). We reply within 15 days, once your identity is confirmed. If you are not satisfied, you may petition the ANPD, the Brazilian data protection authority.

11. Data protection officer and contact

Data protection officer (DPO): Mr Sanclé Albuquerque — lgpd@ebaem.com.br. Other channels: support suporte@ebaem.com.br, ombudsman ouvidoria@ebaem.com.br, sales contato@ebaem.com.br.

12. Changes and version history

We may update this notice to reflect legal or service changes. The version in force is the one published here; relevant changes are communicated by e-mail to registered users and on the site itself.

VersionDateWhat changed
1.02 September 2026Initial publication. Full revision: table by context, data not collected, sub-processors, international transfers and version history.