RASCUNHO — pendente de revisão jurídica. (DRAFT — pending legal review.) This text is meant to guide the review and has no value until approved. Items marked [PREENCHER] depend on company data; items marked [CONFIRMAR] come from internal sources and must be checked; items marked [REVISAR] need special attention from legal counsel. This is a translation of privacidade.pt.md; in case of divergence, the Portuguese version prevails [REVISAR].

nuvem.works Privacy Policy

Version: [PREENCHER] · Last updated: [PREENCHER — date]

This Policy explains which personal data nuvem.works processes, why, who we share it with, how long we keep it and how you exercise your rights, under Brazilian Law no. 13,709/2018 (General Personal Data Protection Law, LGPD).

nuvem.works is a product of NUVEM.ONLINE [PREENCHER — full legal name], CNPJ [PREENCHER], with headquarters at [PREENCHER — full address] ("Nuvem.Online", "we").

1. Who decides about your data

nuvem.works is used by organizations (our customers) to give their teams remote access to their own servers. So there are two roles:

DataControllerNuvem.Online's role
Data processed within a customer's workspace: people and roles, devices, connections, sessions, trail, saved credentialsThe customer (the organization)Processor: processes the data on the customer's behalf, only to provide the service
Personal account, sign-up, acceptance of the terms, sales contact and visits to the nuvem.works websiteNuvem.OnlineController

If you use nuvem.works through your company, requests about workspace data should go to your company first. We will support it in handling them.

2. What data we process

2.1. Account and organization

2.2. Sessions and trail

Every time someone opens an access, or tries to and is denied, we record an event in the workspace trail with:

When Nuvem.Online's operations team accesses a workspace for support, that access shows up in the customer's trail, identified as Nuvem.Online's.

What we don't keep: session content. Screen, keystrokes, clipboard, transferred files and printed documents pass through the session but are not recorded or stored by the platform.

2.3. Saved credentials

When you ask us to save a server credential (username and password, or username and SSH key), it is stored encrypted and used only at connection time, delivered directly to whoever performs the logon on the server (our gateway, for RDP; the agent, for the terminal). It is never sent to the browser, the app or the CLI and cannot be revealed, not even to you. Only you can use it.

A credential typed without the save option is used for that connection and discarded. A credential typed with the save option is kept encrypted for a few minutes, waiting for confirmation that the logon worked, and is discarded if the confirmation doesn't come.

2.4. Data sent by the agent

The agent installed on the customer's servers sends the platform, so the service can work:

The agent does not collect the content of files or documents on the server, nor the system event logs.

2.5. Desktop app and CLI

The macOS and Windows app and the CLI keep, in your computer's operating system secure storage, the login session needed to stay connected. They periodically check whether a new version is available.

2.6. Attachments

Images the workspace uploads, such as the icon of a published application.

2.7. Website visits

We measure visits to the nuvem.works website with Umami, an open source analytics tool we host ourselves. It uses no cookies, does not store your IP address and builds no visitor profile. We record pages viewed, where the visit came from (referring site and campaign parameters), approximate country, browser, system and device type, and clicks on the main buttons ("Start free", WhatsApp and download). Because it uses no cookies and does not identify you, the website shows no consent banner. [REVISAR — legal basis for analytics.]

2.8. Contact through WhatsApp

If you click "Talk to us", the conversation happens on WhatsApp, a Meta service subject to its own rules. We use your number and what you write only to reply and follow up on the conversation.

3. Why we use the data and on which legal basis

PurposeLegal basis (LGPD, art. 7)
Create and keep the account, sign up and run the workspacePerformance of a contract
Log on to servers with the saved credentialPerformance of a contract
Record the trail and produce the customer's reportsPerformance of a contract and the customer's legitimate interest in controlling access to its systems [REVISAR]
Keep application access logsCompliance with a legal obligation (Brazilian Internet Civil Framework, art. 15)
Record acceptance of the termsPerformance of a contract and regular exercise of rights
Keep the platform secure and prevent fraudLegitimate interest
Measure website visits without identifying visitorsLegitimate interest [REVISAR]
Reply to WhatsApp contactsPre-contractual steps at the data subject's request

We don't sell personal data and don't use it for advertising.

4. Who we share data with

We use providers to run the service, which process data only for that purpose:

The identity provider, e-mail delivery and analytics run on infrastructure operated by Nuvem.Online itself. [CONFIRMAR]

We may also share data when required by law or by order of a competent authority.

5. International transfer

Platform data stays in Brazil [CONFIRMAR]. Providers such as Cloudflare and Meta may process data outside the country; in those cases, the transfer follows LGPD art. 33. [REVISAR]

6. How long we keep data

DataPeriod
Workspace trail12 months, automatically removed afterwards
Application access logsAt least 6 months (Brazilian Internet Civil Framework) [REVISAR — reconcile with the trail period]
Saved credentialUntil you remove it or until the workspace ends
Credential typed with the save optionA few minutes, until the logon is confirmed
Account, organization and acceptanceWhile the contract lasts and, afterwards, for the period needed to exercise rights [PREENCHER — period]
Workspace data after terminationDeleted within [PREENCHER — period]
Analytics dataAggregates only, without identifying visitors

7. How we protect data

If a security incident may bring relevant risk or harm, we will notify the affected customers and the ANPD within the regulatory deadlines.

8. Your rights

As a data subject, you may request at any time:

Requests about an organization's workspace data (such as the trail) are forwarded to it, as the controller. You may also file a complaint with the Brazilian Data Protection Authority (ANPD).

9. Data protection officer

10. Children and teenagers

nuvem.works is a service for organizations and is not intended for anyone under 18.

11. Changes to this Policy

We may update this Policy. The current version is always on this page, with the date of the last update. Material changes will be announced in the product itself.