Português (Brasil): Política de Privacidade
This Privacy Policy explains how the following controller processes personal data:
- Controller: Tevlio Tecnologia da Informação Ltda.
- CNPJ: 68.407.558/0001-20
- Address: R. Doutor Arlindo Luz, 540, Sala 01, Centro, Ourinhos, SP, CEP 19.900-011, Brazil
- Encarregado (Data Protection Officer): Pedro Lucca Soares Cruzeiro
- Encarregado contact and Data Subject request channel: privacy@tevlio.com
This policy explains how we process personal data. Where the LGPD requires consent, we will request it separately and you may withdraw it.
The Portuguese (Brazil) version is the original and controls if this English translation conflicts with it, always subject to mandatory law and any signed agreement that provides otherwise.
1. Scope and roles
This policy covers Tevlio Mail, Tevlio Cloud, Tevlio Helpdesk, Tevlio websites, and related support, billing, security, and Account-administration activities (the “Services”).
Tevlio ordinarily acts as Controller for personal data concerning website visitors, prospective customers, Account Owners, authorized users, billing contacts, and people who communicate directly with us.
When a Customer submits or controls personal data through the Services on behalf of its users, correspondents, employees, customers, or other people ("Customer Personal Data"), the Customer ordinarily acts as Controller and Tevlio as its Operator or Processor. That processing follows the Data Processing Addendum ("DPA"), the applicable agreement, and the Customer’s lawful instructions.
If your data was submitted by a Tevlio Customer, that Customer is ordinarily responsible for responding to your request. You should contact it first. Tevlio will provide the assistance required by law and the DPA.
Brazil’s Lei Geral de Proteção de Dados Pessoais ("LGPD") is the primary law guiding this policy. Mandatory laws where a Data Subject is located or processing occurs may provide additional rights when they legally apply.
2. Personal data and sources
We receive data directly from you or the Customer; automatically when the Services are used; and from integrations, providers, public sources, or authorities where necessary and permitted.
| Category | Examples |
|---|---|
| Account, contact, and preference data | Name, email address, company, role, profile, language, Account-recovery details, and communication choices |
| Billing and transaction data | Billing address, CPF or CNPJ where needed, tax data, invoices, payments, and transaction identifiers |
| Customer Content | Messages, files, attachments, tickets, contacts, domain, DNS or cloud configurations, and other data submitted by the Customer |
| Network, device, and security data | IP address, browser, device, login, authentication, timestamps, diagnostics, and fraud, spam, or abuse signals |
| Service and website usage | Features and pages used, referring page, settings, performance, and product events |
| Support and correspondence | Tickets, emails, survey responses, attachments, and other information provided to support |
3. Purposes and legal bases
We process personal data only where there is a legitimate purpose and an applicable legal basis. The main combinations are:
- creating and administering Accounts, providing support, and supplying, billing, and maintaining the Services — contract performance or steps taken before a contract;
- issuing tax documents, keeping required records, and responding to valid orders — compliance with a legal or regulatory obligation;
- authenticating users, protecting Accounts, preventing spam, fraud, and abuse, diagnosing failures, and improving the Services — legitimate interests, the regular exercise of rights, or another permitted basis, with an assessment of necessity and impact;
- sending operational, billing, security, and contractual-change notices — contract performance, legal obligation, or legitimate interests;
- sending optional marketing communications — consent or legitimate interests where permitted, always with an unsubscribe method;
- investigating incidents and establishing, exercising, or defending rights — the regular exercise of rights and other applicable legal bases; and
- processing Customer Personal Data — the Customer’s instructions, with the Customer responsible for determining its own purpose and legal basis.
Where we rely on consent, refusal or withdrawal will not affect earlier processing or processing based on another lawful ground. We may produce aggregated statistics or effectively anonymized data and will not attempt to re-identify it.
4. Cookies, analytics, and marketing
We use cookies or local storage necessary for authentication, security, language, and preferences. We do not intentionally use third-party advertising cookies on Tevlio product pages.
We use aggregate metrics to understand website usage, without analytics cookies or persistent cross-site identifiers. We do not intentionally send Account identifiers or Customer Content to the tool used for this purpose. Its identity and practices are disclosed exclusively in the Vendors and Subprocessors List .
Tevlio does not sell personal data, share it for cross-context behavioral advertising, or upload Customer email addresses to advertising platforms to create or suppress audiences. If these practices change, we will update this policy before the change and provide any required consent or right to object.
You may unsubscribe from optional communications using the unsubscribe link or support. Required Account, security, billing, or legal notices may continue.
5. Customer Content and authorized access
We do not use Customer Content for advertising unrelated to the Services or sell it. Authorized Tevlio personnel may access it only to the minimum extent necessary to:
- provide support requested by an authorized user;
- diagnose or correct a failure that cannot reasonably be resolved using metadata or automated tools;
- investigate a security threat, fraud, abuse, or policy violation;
- maintain, protect, or restore the Services; or
- comply with a valid legal obligation or order.
Access is limited according to role and need, subject to confidentiality, and logged as appropriate to the risk. We prefer metadata, automated diagnostics, and redacted examples where they are sufficient.
6. Disclosures and recipients
We disclose only the data reasonably necessary for the relevant purpose:
- Vendors: infrastructure, storage, monitoring, security, payment, support, communications, and analytics. Our public vendor list identifies purposes, data categories, and processing locations. Vendors acting as independent Controllers also follow their own privacy notices and legal obligations.
- Customer-enabled integrations: if the Customer enables an integration, we exchange the data needed for it to operate. The Customer should review the third party’s terms and privacy policy.
- People authorized by the Customer: administrators, users, and other recipients the Customer selects or permits through the Services.
- Legal obligations and protection of rights: authorities or third parties where required by law or valid order, or where needed to protect rights, safety, and integrity, investigate abuse, or exercise rights. Where permitted and reasonable, we will seek to narrow disproportionate requests and notify the affected Customer.
- Corporate transactions: potential buyers, advisers, or successors in a merger, acquisition, reorganization, financing, or asset sale, under confidentiality protections and with legally required notices.
7. Sensitive data, children, and adolescents
Tevlio does not request sensitive personal data for ordinary Account registration. Customer Content may contain sensitive data selected by the Customer or its users. In that case, the Customer is responsible for the lawfulness, necessity, and instructions for processing, and Tevlio will apply the safeguards and restrictions provided by the Service, the DPA, and law.
Accounts and access as an authorized user are intended exclusively for people who are at least 18 years old. Customer must not allow children or adolescents to access or use the Services. This restriction does not prevent Customer Content from mentioning or containing minors’ data; in that case, Customer must have a legal basis, observe their best interests, limit Processing to what is necessary, and meet other applicable requirements.
Before offering a feature directed to minors or likely to be accessed by them, Tevlio will assess the application of Brazil’s Digital Statute for Children and Adolescents and implement the legally required technical, informational, privacy, and security measures. If we learn that Tevlio unlawfully collected a minor’s registration data, we will take appropriate steps to restrict or delete it.
8. International transfers
Tevlio is established in Brazil and operates infrastructure and processes data in Brazil. We also use providers in other countries where needed to provide, protect, support, or administer the Services.
Destination countries, vendors, purposes, data categories, and processing locations are maintained in our public vendor list .
Data may be electronically transmitted, stored, or accessed abroad while the Services are provided and for the periods in Section 13. Purposes include infrastructure, storage, redundancy, security, abuse prevention, payments, support, communications, and administration. Only the categories needed by each provider are disclosed; Customer Content is sent only to providers that need to process it for the applicable Service.
For transfers governed by the LGPD, Tevlio adopts and maintains a valid mechanism under Article 33 of the LGPD and ANPD regulations. Where contractual clauses are the applicable mechanism, the complete and unmodified ANPD standard clauses form part of the instrument executed with the importer. Tevlio maintains a completed record of the parties, purposes, data, responsibilities, onward transfers, and security measures. Other mandatory laws may require additional safeguards.
As Controller or exporter, Tevlio selects providers, contractually limits purposes, and requires security measures, assistance with Data Subject rights, onward-transfer rules, and deletion or return at the end of processing, subject to legal retention. Each importer is responsible for meeting its legal and contractual obligations.
You may request information or a copy of the clauses applicable to the transfer free of charge. We will respond within the legal period, currently up to 15 days for the request provided by ANPD regulations, subject to lawful protection of commercial and industrial secrets. You may also exercise the rights in Section 9 and petition the ANPD .
Details for transfers of Customer Personal Data are in the DPA .
9. Your rights
Under and within the limits of the LGPD, you may request:
- confirmation that processing exists and access to the data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed contrary to law;
- portability, subject to regulation, commercial and industrial secrets, and applicable feasibility;
- deletion of data processed with consent, subject to legal retention exceptions;
- information about public and private entities with which data was shared;
- information about the possibility and consequences of refusing consent;
- withdrawal of consent through a free and facilitated procedure;
- objection to processing conducted contrary to law; and
- review of automated decisions as described in Section 10.
Mandatory laws in other locations may provide additional rights where they apply to the processing.
You may exercise rights through available Account settings or the Tevlio Encarregado . We may request proportionate information to confirm identity, representative authority, and the data involved. We will not disclose another person’s data in response to a request.
Where Tevlio acts as Operator, we will route the request to the responsible Customer or explain how to contact it. Where Tevlio acts as Controller, we will respond within the legal deadlines. For access under Article 19 of the LGPD, we will provide a simplified response immediately where feasible or a complete statement within 15 days, unless a different legal period applies.
You may complain to Tevlio and petition the Brazilian National Data Protection Agency or another competent authority.
10. Automated processing
Security systems may automatically score signup, login, messaging, or network activity for spam, fraud, and abuse risk. A high-risk result may trigger an additional challenge, usage limit, temporary restriction, or manual review.
Where law provides this right, you may request review of a decision made solely through automated processing that affects your interests and information about the criteria and procedures used, subject to lawful protection of commercial and industrial secrets.
Tevlio does not use solely automated decisions to decide employment, credit, insurance, or similar matters unrelated to the Services.
11. Security
We use technical and organizational measures proportionate to the nature and risk of processing. No system is immune from every threat. Our current program is described in the Security Overview .
12. Security incidents
We maintain procedures to assess, contain, investigate, document, and remediate personal-data incidents.
Where Tevlio acts as Operator, it will notify the responsible Customer without undue delay after becoming aware of an incident involving Customer Personal Data and provide available information needed for the Customer’s obligations.
Where Tevlio acts as Controller, it will notify the ANPD and Data Subjects where required by law. Under current Brazilian rules, confirmed incidents that may cause relevant risk or damage must be reported within 3 business days after the Controller becomes aware, unless specific legislation provides a different deadline.
13. Retention and deletion
We retain data only as long as needed for the purpose, Customer instructions, legal obligations, security, and the exercise of rights. Reference periods are:
| Data | Reference retention |
|---|---|
| Account and profile data | While the Account is active; deletion from active systems within 60 days after termination, unless lawful retention applies |
| Customer Content | As configured or instructed while the Account is active; deletion from active systems within 60 days after termination or a valid instruction |
| Recovery copies | Isolated from ordinary use and overwritten or deleted on a rolling cycle generally not exceeding an additional 60 days |
| Application access records governed by the Brazilian Civil Rights Framework for the Internet | At least 6 months after the event where the legal obligation applies |
| Security and authentication records | For a period proportionate to risk and, where needed, longer to investigate incidents, prevent abuse, or comply with law |
| Billing, tax, and accounting records | For the period required by applicable laws |
| Support and legal correspondence | During the relationship and for a proportionate period afterward, ordinarily no more than 5 years unless a dispute or legal duty requires longer |
| Marketing preferences | Until withdrawal or opt-out; we may retain a minimal record to respect the choice |
Some Services provide trash, archive, or configurable retention. Data may remain according to those settings until deleted. Deletion does not apply to data that must be retained by law or is needed to exercise rights; its use will be restricted to those purposes.
Where data no longer needs to identify a person, we may irreversibly anonymize it instead of deleting it.
14. Changes and contact
We may update this policy when our practices, Services, providers, or obligations change. We will notify affected Account Owners of material changes where required by law. If a new purpose requires consent, it will be requested separately; continued use will not be treated as consent.
Questions, complaints, and requests may be submitted to the Tevlio Encarregado or mailed to the postal address at the beginning of this policy.