Account Privacy Policy
Last updated 2026-07-31
Account Privacy Policy
Version 2026-07-31 — in force from 31 July 2026
This policy covers the personal data of people who hold a Fidei account — business owners, their staff, and administrators. It does not cover your customers' data: for that, Fidei acts as your processor and the relevant documents are the Member Privacy Notice and the Data Processing Agreement.
1. Who is responsible
For the data described here, Weslley David Botelho Santos ("Fidei") is the data controller.
Avenue Coghen 23, 1180 Uccle, Brussels, Belgium — company number BE1032.434.445 Data protection contact: Weslley David Botelho Santos (contact@botelho.solutions) — no separate DPO appointed, contact@botelho.solutions
2. What we collect about you
When you sign up: your full name, your work email address, your password (stored only as a scrypt hash — we never hold the password itself), your business's name and category, your chosen interface language, and the plan you selected.
Your first location, if you enter one: its name, street address, city and postcode.
At the moment you accept these documents: which documents you accepted, at which version and in which language, the exact wording you were shown, the date and time, your IP address and a short description of your browser.
While you use the service: a session token in your browser's local storage, the actions you take that are attributed to you (for example, which staff member applied a stamp), and short-lived security records such as failed login counts keyed by your email address and IP.
We do not collect payment card details. We do not track you across other websites.
3. Why we use it, and on what legal basis
| What we do | Legal basis |
|---|---|
| Create and run your account, and provide the service | Performance of a contract — GDPR Art. 6(1)(b); LGPD Art. 7(V) |
| Bill you and keep accounting records | Contract and legal obligation — GDPR Art. 6(1)(b), 6(1)(c); LGPD Art. 7(V), 7(II) |
| Keep proof that you accepted our terms and policies | Legal obligation and legitimate interests — GDPR Art. 6(1)(c), 6(1)(f); LGPD Art. 7(II), 7(IX) |
| Protect the service: rate limiting, abuse prevention, security logs | Legitimate interests — GDPR Art. 6(1)(f); LGPD Art. 7(IX) |
| Send you service messages you cannot opt out of (outages, security, billing, changes to these terms) | Performance of a contract — GDPR Art. 6(1)(b); LGPD Art. 7(V) |
| Send you product news and tips | Your consent — GDPR Art. 6(1)(a); LGPD Art. 7(I) |
Product emails are optional and separate. Declining them changes nothing about your account.
4. Who else sees it
- Our hosting and infrastructure providers: Vercel Inc. (application hosting) and Neon, Inc. (PostgreSQL database), acting on our written instructions.
- Professional advisers — accountants, lawyers — where genuinely needed.
- Authorities, where we are legally required to disclose.
We do not sell your data or share it for anyone else's marketing.
5. Transfers outside your country
We operate in both the European Union and Brazil. Transfers from the EU/EEA rely on the European Commission's Standard Contractual Clauses with supplementary safeguards where needed; transfers from Brazil rely on standard contractual clauses under LGPD Art. 33(II). Ask contact@botelho.solutions for a copy.
6. How long we keep it
- Account and business data: for as long as your account is open, then deleted or anonymised.
- Billing and accounting records: as long as tax and company law require.
- Consent records: 5 years, since they must outlive the processing they authorise.
- Security and rate-limiting data: hours, then deleted automatically.
7. Your rights
Under the GDPR: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent at any time (which does not affect what was done beforehand).
Under the LGPD, additionally: confirmation that processing exists; anonymisation, blocking or deletion of unnecessary or unlawfully processed data; information about with whom your data has been shared; information about the consequences of refusing consent; and review of decisions taken solely by automated means.
Write to contact@botelho.solutions. We answer within one month, and will say so if we need longer.
Complaints. In the EU/EEA, to your local data protection authority or the Belgian Data Protection Authority (APD/GBA). In Brazil, to the ANPD. You do not have to contact us first.
8. Automated decisions
We do not make decisions about you by automated means alone.
9. Security
Passwords are hashed with scrypt and never stored in readable form. Access to production data is restricted to staff who need it. Traffic is encrypted in transit. Sign-up and login endpoints are rate limited. Where we know of a residual weakness, we say so rather than implying there is none: session tokens are held in browser local storage, which is mitigated by a strict Content Security Policy but is not equivalent to an HttpOnly cookie.
If a breach is likely to result in a risk to your rights, we will notify the relevant authority within 72 hours and tell you without undue delay where the risk is high.
10. Changes
If this policy changes materially, we will ask you to review and accept the new version in the app. Previous versions remain published.
Contact: contact@botelho.solutions.