RASCUNHO — pendente de revisão jurídica. (DRAFT — pending legal review.) This text is meant to guide the review and has no value until approved. Items marked [PREENCHER] depend on company data; items marked [CONFIRMAR] come from internal sources and must be checked; items marked [REVISAR] need special attention from legal counsel. This is a translation of
privacidade.pt.md; in case of divergence, the Portuguese version prevails [REVISAR].
nuvem.works Privacy Policy
Version: [PREENCHER] · Last updated: [PREENCHER — date]
This Policy explains which personal data nuvem.works processes, why, who we share it with, how long we keep it and how you exercise your rights, under Brazilian Law no. 13,709/2018 (General Personal Data Protection Law, LGPD).
nuvem.works is a product of NUVEM.ONLINE [PREENCHER — full legal name], CNPJ [PREENCHER], with headquarters at [PREENCHER — full address] ("Nuvem.Online", "we").
1. Who decides about your data
nuvem.works is used by organizations (our customers) to give their teams remote access to their own servers. So there are two roles:
| Data | Controller | Nuvem.Online's role |
|---|---|---|
| Data processed within a customer's workspace: people and roles, devices, connections, sessions, trail, saved credentials | The customer (the organization) | Processor: processes the data on the customer's behalf, only to provide the service |
Personal account, sign-up, acceptance of the terms, sales contact and visits to the nuvem.works website | Nuvem.Online | Controller |
If you use nuvem.works through your company, requests about workspace data should go to your company first. We will support it in handling them.
2. What data we process
2.1. Account and organization
- Personal account: name, e-mail and account identifier in our identity provider.
- Sign-up: country, the organization's document (CNPJ or CPF), organization name and workspace identifier.
- Acceptance of the terms: accepted version, the person who accepted, date, time and IP address.
- Workspace membership: the organizations you belong to, your role and your groups.
2.2. Sessions and trail
Every time someone opens an access, or tries to and is denied, we record an event in the workspace trail with:
- the time, the person, the connection and device involved, and the result;
- the source IP address and browser or app;
- the server account used (for example,
Administratororroot); - the session's start, end, duration and reason for ending;
- for terminal sessions, the amount of data transferred;
- for a command run through the CLI, the command text (we don't record what is sent to it through standard input, nor its output).
When Nuvem.Online's operations team accesses a workspace for support, that access shows up in the customer's trail, identified as Nuvem.Online's.
What we don't keep: session content. Screen, keystrokes, clipboard, transferred files and printed documents pass through the session but are not recorded or stored by the platform.
2.3. Saved credentials
When you ask us to save a server credential (username and password, or username and SSH key), it is stored encrypted and used only at connection time, delivered directly to whoever performs the logon on the server (our gateway, for RDP; the agent, for the terminal). It is never sent to the browser, the app or the CLI and cannot be revealed, not even to you. Only you can use it.
A credential typed without the save option is used for that connection and discarded. A credential typed with the save option is kept encrypted for a few minutes, waiting for confirmation that the logon worked, and is discarded if the confirmation doesn't come.
2.4. Data sent by the agent
The agent installed on the customer's servers sends the platform, so the service can work:
- server name, operating system and agent version;
- CPU, memory, disk and network usage, and uptime;
- the sessions open on the server, with each one's system user;
- on pool servers, the list of published applications.
The agent does not collect the content of files or documents on the server, nor the system event logs.
2.5. Desktop app and CLI
The macOS and Windows app and the CLI keep, in your computer's operating system secure storage, the login session needed to stay connected. They periodically check whether a new version is available.
2.6. Attachments
Images the workspace uploads, such as the icon of a published application.
2.7. Website visits
We measure visits to the nuvem.works website with Umami, an open source analytics tool we
host ourselves. It uses no cookies, does not store your IP address and builds no visitor
profile. We record pages viewed, where the visit came from (referring site and campaign
parameters), approximate country, browser, system and device type, and clicks on the main buttons
("Start free", WhatsApp and download). Because it uses no cookies and does not identify you, the
website shows no consent banner. [REVISAR — legal basis for analytics.]
2.8. Contact through WhatsApp
If you click "Talk to us", the conversation happens on WhatsApp, a Meta service subject to its own rules. We use your number and what you write only to reply and follow up on the conversation.
3. Why we use the data and on which legal basis
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and keep the account, sign up and run the workspace | Performance of a contract |
| Log on to servers with the saved credential | Performance of a contract |
| Record the trail and produce the customer's reports | Performance of a contract and the customer's legitimate interest in controlling access to its systems [REVISAR] |
| Keep application access logs | Compliance with a legal obligation (Brazilian Internet Civil Framework, art. 15) |
| Record acceptance of the terms | Performance of a contract and regular exercise of rights |
| Keep the platform secure and prevent fraud | Legitimate interest |
| Measure website visits without identifying visitors | Legitimate interest [REVISAR] |
| Reply to WhatsApp contacts | Pre-contractual steps at the data subject's request |
We don't sell personal data and don't use it for advertising.
4. Who we share data with
We use providers to run the service, which process data only for that purpose:
- Oracle Cloud Infrastructure — hosting of the platform and attachment storage, in the São Paulo region, Brazil [CONFIRMAR].
- Cloudflare — DNS and delivery of the
nuvem.workswebsite [CONFIRMAR]. - Meta (WhatsApp) — only when you choose to talk to us there.
The identity provider, e-mail delivery and analytics run on infrastructure operated by Nuvem.Online itself. [CONFIRMAR]
We may also share data when required by law or by order of a competent authority.
5. International transfer
Platform data stays in Brazil [CONFIRMAR]. Providers such as Cloudflare and Meta may process data outside the country; in those cases, the transfer follows LGPD art. 33. [REVISAR]
6. How long we keep data
| Data | Period |
|---|---|
| Workspace trail | 12 months, automatically removed afterwards |
| Application access logs | At least 6 months (Brazilian Internet Civil Framework) [REVISAR — reconcile with the trail period] |
| Saved credential | Until you remove it or until the workspace ends |
| Credential typed with the save option | A few minutes, until the logon is confirmed |
| Account, organization and acceptance | While the contract lasts and, afterwards, for the period needed to exercise rights [PREENCHER — period] |
| Workspace data after termination | Deleted within [PREENCHER — period] |
| Analytics data | Aggregates only, without identifying visitors |
7. How we protect data
- The customer's servers open no inbound ports: the agent only makes outbound connections.
- Saved credentials are encrypted, never handed to the browser, the app or the CLI, and cannot be revealed.
- For terminal sessions, the channel between the browser and the agent is end-to-end encrypted.
- The application has no permission to change or delete the trail.
- Access within the workspace follows roles and groups.
- Agent updates are verified by signature before being installed.
If a security incident may bring relevant risk or harm, we will notify the affected customers and the ANPD within the regulatory deadlines.
8. Your rights
As a data subject, you may request at any time:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary data or data processed in breach of the LGPD;
- data portability;
- information about who we share your data with;
- review of decisions made solely on automated processing;
- objection to processing based on legitimate interest, where applicable.
Requests about an organization's workspace data (such as the trail) are forwarded to it, as the controller. You may also file a complaint with the Brazilian Data Protection Authority (ANPD).
9. Data protection officer
- Name: Wallacy Santos Ferreira
- E-mail: wallacy@nuvem.online
- Phone: +55 11 4210-1289
- Data subject request form: nuvem.online/privacy
10. Children and teenagers
nuvem.works is a service for organizations and is not intended for anyone under 18.
11. Changes to this Policy
We may update this Policy. The current version is always on this page, with the date of the last update. Material changes will be announced in the product itself.