Compliance Portal · Privacy
Privacy Notice
Which personal data we collect on the website and on the platform, how long we keep it, who we share it with and how you exercise your rights — context by context, in plain language.
Data protection officer (DPO): lgpd@ebaem.com.br · data subject requests answered within 15 days
Privacy Notice · Version 1.0 · In force since 2 September 2026
This notice explains, in plain terms, which personal data EBAEM LTDA (“EBAEM”, “we”) collects when you use the website www.observatoriogestao.com.br or the Observatório de Gestão platform (painel.observatoriogestao.com.br), why it collects it, how long it keeps it, who it shares it with and how you can exercise your rights.
1. Who is responsible for the processing
EBAEM LTDA — CNPJ (Brazilian tax ID) 55.054.849/0001-30 — SRTVN Quadra 702, Lote P, Edifício Rádio Center, Salas SS18 a SS28, Asa Norte, Brasília/DF, Brazil, ZIP 70719-900 — +55 (61) 98128-6479. Data protection officer (DPO): lgpd@ebaem.com.br.
When you use the platform as part of the team of a public entity or of an accredited consultant, the controller of the data your organisation enters is the organisation itself; EBAEM acts as processor, as set out in the LGPD Policy.
2. Who this notice applies to
- visitors to the website;
- people who fill in the contact, support, whistleblowing, data protection request or accreditation forms;
- representatives of public entities and consultants during contracting and payment;
- platform users (managers, civil servants, consultants and their teams);
- people whose data appears in the public databases we monitor.
3. What data we collect, what for and for how long
| Context | Data collected | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Browsing the website | IP address, browser, device, pages visited, cookies | operation, security and aggregate statistics (the latter only with consent) | legitimate interest; consent for non-essential cookies | logs: 6 months; cookies: see the Cookie Policy |
| Contact form and proposal requests | name, e-mail, phone, organisation, role, type of entity, message | replying, sending a proposal, scheduling a demo | pre-contractual procedures; legitimate interest | up to 2 years after the last contact |
| Support | contact details, organisation, module affected, description of the problem, attachments | handling and recording the ticket | performance of a contract | term of the contract + 2 years |
| Whistleblowing channel | content of the report, attachments and, if you choose to identify yourself, name and e-mail | investigating the report and replying | legitimate interest; regular exercise of rights | duration of the investigation + the limitation period |
| Data protection requests | identification, e-mail, right requested, identity verification documents | meeting the request and evidencing that it was met | compliance with a legal obligation | 5 years after it is closed |
| Purchase and subscription (checkout) | details of the person responsible, CNPJ, legal name, address, type of entity, billing details; payment is processed by Asaas | formalising, invoicing and charging | performance of a contract; legal (tax) obligation | 5 years after the end of the contract |
| User account on the platform | name, e-mail, login, role, permissions, authorised companies and territories, second authentication factor | authenticating, authorising and personalising access | performance of a contract | term + 90 days for export |
| Platform logs and audit trail | user, action, date and time, IP address, resource accessed | security, auditing and accountability | legal obligation; legitimate interest | according to the configured retention policy, with controlled purging |
| Consultant accreditation | professional details, areas of expertise, qualification documents | reviewing and formalising the accreditation | pre-contractual procedures; performance of a contract | term + 5 years |
| Corporate communications | name and e-mail | product news and announcements | consent | until it is withdrawn |
4. Data we do not collect
- Sensitive data — we do not ask for it in any form. If you include it in a report, it is handled confidentially and only for the investigation.
- Data of people under 18 — the website and the platform are intended for organisations and professionals.
- Full card numbers — payment is processed by Asaas; we keep only the charge status and the identifiers generated by the processor.
5. Publicly available data on the platform
The platform collects and organises official federal databases (CAUC, Transferegov/SICONV, parliamentary amendments, the Federal Official Gazette, FNS, FNDE, PAC, BNDES, IBGE). Where those databases contain personal data — the name of a manager, a member of parliament or a beneficiary — the processing observes the purpose, the good faith and the public interest that justified its disclosure (LGPD, article 7, § 3) and is limited to reproducing and organising information that is already public.
6. Cookies
We use necessary, functional, analytics and performance cookies; we do not use advertising cookies. The categories, the duration and how to manage each one are in the Cookie Policy. You can review your choices at any time through the “Cookie preferences” button.
7. Who we share data with
- Hosting and infrastructure — running and storing the platform (Brazil).
- Cloudflare — DNS, protection against attacks and site performance.
- hCaptcha — anti-spam protection on forms.
- Transactional e-mail provider — sending case numbers, confirmations and notifications.
- Asaas — payment processing (bank slip, PIX, card).
- Google Drive (optional, configured by the customer) — archiving of reports.
- Public authorities — when required by law, regulation or court order.
None of these partners may use your data for their own purposes. The full table, with the data involved and its location, is in the LGPD Policy.
8. International transfers
Some providers (site protection, anti-spam, e-mail) may process technical data outside Brazil, with the safeguards of article 33 of the LGPD — standard contractual clauses or equivalent — and limited to the minimum necessary. The platform data is hosted in Brazil.
9. How we protect your data
Encryption in transit (TLS) and of secrets at rest, multi-factor authentication, access control by role, company and territory, an audit trail, backups with a defined retention period, segregated environments and vulnerability management. Details in the Information Security Policy.
10. Your rights
You may request confirmation of processing, access, correction, anonymisation, blocking or deletion, portability, information about sharing, withdrawal of consent and objection to processing (LGPD, article 18). We reply within 15 days, once your identity is confirmed. If you are not satisfied, you may petition the ANPD, the Brazilian data protection authority.
11. Data protection officer and contact
Data protection officer (DPO): Mr Sanclé Albuquerque — lgpd@ebaem.com.br. Other channels: support suporte@ebaem.com.br, ombudsman ouvidoria@ebaem.com.br, sales contato@ebaem.com.br.
12. Changes and version history
We may update this notice to reflect legal or service changes. The version in force is the one published here; relevant changes are communicated by e-mail to registered users and on the site itself.
| Version | Date | What changed |
|---|---|---|
| 1.0 | 2 September 2026 | Initial publication. Full revision: table by context, data not collected, sub-processors, international transfers and version history. |
