Privacy Policy

Version 1 | Last updated: 06/09/2026

This policy explains what data Accordfy collects, why, who it is shared with and what you can demand about it. It applies both to people who use the platform and to people who visit a guide published on it.

1.What data we collect

From people with an Accordfy account

Name, email address and profile picture, obtained from Google sign-in; preferred language; date and IP address of the last sign-in; and the content of the guides you create. When you subscribe, also: your Brazilian tax number (CPF or CNPJ) and phone number — which go straight to the payment processor and are not stored by us — plus your billing history (amount, date, status and invoice link).

From people who fill in a form on the website

Name, email address, phone number, company and the message sent, plus the IP address and the page it came from. We use the IP address to limit automated submissions.

From people who visit a published guide

IP address, device type, browser, operating system, approximate country and city, referring page and which sections were opened. This data feeds the guide owner's analytics and is handled in aggregate — the goal is to measure use, not to identify people.

When you use the AI assistant

We record that the call happened, which feature triggered it and the volume processed, for cost and quota control. The content sent to the AI provider is what you typed or the text of the guide.

2.Why we use the data

We use data to: operate the platform and maintain your account; issue and confirm charges; send operational notices (payment, invitation, guide transfer, trial ending); reply to what you write to us; measure guide usage for the owner's analytics dashboard; and prevent abuse and fraud.

We do not sell data. We do not use your data to train AI models.

3.Legal basis for processing

We process data on the basis of performance of the contract (operating the platform you signed up for), compliance with legal obligations (tax and accounting), and legitimate interest (security, fraud prevention and aggregate usage metrics). Non-essential communications rely on your consent, which you may withdraw at any time.

4.Cookies and similar technologies

We use cookies to keep you signed in and to remember preferences such as language. On public guides, we use an identifier so the same visit is not counted twice. We do not use advertising cookies, remarketing or social media pixels. You can block cookies in your browser; some functions will stop working.

5.Sharing and transfer of data

We share only what is needed for the service to work, with providers acting as data processors:

  • Payment processing (Asaas): billing data, including tax number and card. Accordfy does not store card numbers.
  • Authentication (Google): used for sign-in; we receive name, email address and picture.
  • Email delivery (Resend): the address and content of transactional messages.
  • AI providers (OpenAI, Anthropic): the text you send to the assistant.
  • Maps and business data (Google): when you use the map block or the business data import.
  • Hosting: the servers where the application and files live.
  • Some of these providers keep servers outside Brazil. In those cases, the international transfer follows the grounds set out in the Brazilian LGPD.

    6.Data you publish in guides

    The content you put in a guide is public by nature — it is a page made to be read. If you enter someone else's personal data (photos, names, phone numbers), you are the controller of that data and are responsible for the legal basis of its use. Sections marked as on-site stay out of search engines, but the link with a token gives access to whoever holds it: it is not secrecy.

    7.Retention period

    We keep data for as long as the account exists. After closure, content is kept for 6 months so the account can be reactivated; billing records are kept for 5 years, the period required by Brazilian tax law. Visit metrics are kept in aggregate form. Once the period ends, data is deleted or anonymised.

    8.Your rights

    The Brazilian LGPD guarantees you:

  • Confirmation that we process your data, and access to it
  • Correction of incomplete or outdated data
  • Anonymisation, blocking or deletion of unnecessary data
  • Portability to another provider
  • Information about who we share your data with
  • Withdrawal of consent, where processing relies on it
  • To exercise any of these, write to contato@accordfy.com. We respond within 15 days.

    9.Information security

    We take technical and organisational measures to protect data: restricted access to production credentials, encrypted traffic, card data never stored by us, and event logging for investigation. No system is immune to incidents; if one occurs that carries material risk, we will notify the data subjects and the Brazilian data protection authority (ANPD) as required by the LGPD.

    10.Data Protection Officer and Contact

    Data Protection Officer: Fabricio Paschoal — contato@accordfy.com. Controller: PASCCO TECNOLOGIA LTDA, CNPJ 68.514.644/0001-31, with its registered office at Rua Antônio de Oliveira Lino, 534, Jardim Santa Alice, Santa Bárbara d'Oeste/SP, Brazil, postcode 13458-517.

    11.Changes to this policy

    This policy may be updated. Material changes will be communicated by email or within the platform, and the update date at the top of this page always reflects the version in force.

    12.Language of this document

    This English version is provided for convenience. Processing is governed by Brazilian law and the Portuguese version of this policy prevails in the event of any divergence between the two texts.

    Any questions about this document? Talk to us.