Privacy Policy — StackUp Automations
- Controller
- BRUNO SANTOS CONSULTORIA DE SISTEMAS LTDA, trading as Bruno on Apps — CNPJ 33.279.051/0001-53, registered at R. Sta Cruz, 2187, Sala 10, Vila Mariana, São Paulo/SP, 04121-002, Brazil.
- Privacy and data protection contact
- [email protected]
1. Who we are and what this policy covers
StackUp Automations is the automation-as-a-service platform operated by Bruno on Apps and published at stackuphost.com. This Privacy Policy explains how we process personal data under Brazilian Law 13.709/2018 (Lei Geral de Proteção de Dados — LGPD).
It addresses two audiences, with different roles:
- StackUp customers (the companies that subscribe to the platform) — for these, Bruno on Apps is the controller of account, billing and usage data.
- People whose data flows through the subscribed automations (someone filling in a customer's contact form, for instance) — for these, Bruno on Apps is a processor: it handles the data under instruction and on behalf of the customer company, which is the controller.
2. Definitions (LGPD Art. 5)
- Personal data: information relating to an identified or identifiable natural person.
- Data subject: the natural person the data refers to.
- Controller: whoever decides on the processing.
- Processor: whoever carries out the processing on the controller's behalf.
- Processing: any operation on personal data (collection, use, storage, deletion, among others).
3. What data we process
3.1 Customer data (we act as controller)
- Account: name, email and account identifier.
- Authentication: login identifiers managed by the identity provider (Keycloak, self-hosted). StackUp never stores the password in plain text.
- Billing: subscribed plan, charge history and identifiers held by the payment provider.
- Usage: automation execution metrics, plan allowance consumption and audit records.
3.2 Data flowing through the automations (we act as processor)
This is processed under the customer company's instruction and varies with the automation it subscribes to. In the lead capture and qualification automation, for example, it is whichever fields the customer chooses to collect in its own form — typically name, email, phone and the message sent — plus the classification result and the execution record.
StackUp neither requires nor encourages the collection of sensitive personal data. The legal basis and the purpose of processing that data are the responsibility of the customer company, as controller.
4. Legal bases (Art. 7)
- Performance of a contract (Art. 7, V): delivering the service the customer subscribed to.
- Compliance with a legal or regulatory obligation (Art. 7, II): retaining tax and contractual records and answering legitimate requests.
- Legitimate interest (Art. 7, IX): platform security, fraud and abuse prevention, and service improvement — always with a proportionality test and never overriding the data subject's rights.
For data flowing through the automations, the legal basis is defined and guaranteed by the customer company, which is the controller.
5. Purposes
- Run the automations the customer subscribed to.
- Authenticate users and protect accounts.
- Process charges and issue tax documents.
- Produce usage metrics and reports for the customer and enforce plan limits.
- Ensure security, prevent abuse and meet legal obligations.
6. Sharing and sub-processors
To run the service we use third parties that process data strictly under contract and instruction. This is the complete list:
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Google (Gemini API) | AI classification, only when the local model cannot answer | Content submitted for classification | USA |
| Google (Gmail/SMTP) | Sending the automations' notification emails | Recipient email and notification content | USA |
| Asaas | Charging and tax invoicing | Name, tax ID and amount | Brazil |
| Cloudflare | Network edge, content delivery and attack protection | IP address and request metadata | Global |
| Telegram | Telegram notifications, only when the customer switches that channel on | Conversation identifier and notification content | Global |
Artificial intelligence runs first on a model hosted in our own infrastructure, with nothing sent to a third party. The external provider is reached only as a declared alternative, when the local model cannot answer. Under the commercial terms we hold with that provider, content sent this way is not used to train models.
We do not sell personal data to third parties, nor release it for advertising purposes.
7. International transfers
International transfers follow LGPD Art. 33, with standard contractual clauses and adequate safeguards. Sub-processors located outside Brazil are identified in the table in section 6.
8. Retention and deletion
- Automation execution records: 90 days by default, unless the plan sets a different window.
- Contract acceptance evidence and financial records: for the applicable legal period.
- Account data: for as long as the relationship lasts, then for the minimum legal retention period.
Expired records are deleted by an automatic routine, not case by case on request.
9. Data subject rights (Art. 18)
We guarantee the rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing.
The portal implements these requests technically: export of the account's data in a machine-readable format (Art. 18, II and V) and deletion, which anonymises personal data while preserving only the records the law requires (Art. 16). Exercising these rights is free and answered within the LGPD deadlines; where an immediate answer is not possible, the data subject is told why or by when.
Requests about data that flowed through an automation should be addressed to the customer company, which controls that data. We support it technically in answering them.
10. Security
- Encryption in transit (TLS) on every public connection, with HSTS.
- Secrets encrypted at rest and separated per environment; never in code, logs or messages.
- Per-customer (multi-tenant) isolation at the application and data layers.
- Role-based access control, with authentication delegated to the identity provider.
- Security headers at the edge and a restrictive content policy in the browser.
- Continuous security and dependency scanning in the development cycle, blocking delivery on failure.
Personal data is never written to application logs; audit records identify the account, not the content.
11. Cookies
We use strictly necessary cookies only. There are no advertising, cross-site tracking or audience analytics cookies — and therefore no consent banner to show.
| Cookie | What it does | Lifetime |
|---|---|---|
| suh-theme | Remembers the choice between light and dark theme | 1 year |
| NEXT_LOCALE | Remembers the chosen language | 1 year |
| Authentication session | Keeps the portal session of a signed-in user | For the session |
12. Changes to this policy
This policy may be updated. Material changes are announced through the usual channels and, where they materially alter the subscribed terms, require a fresh acceptance in the portal.
The English and Spanish versions are courtesy translations. In case of divergence, the Brazilian Portuguese version prevails.
13. Contact
- Data protection officer (DPO): Bruno Santos
- Email: [email protected]
- Address: R. Sta Cruz, 2187, Sala 10, Vila Mariana, São Paulo/SP, 04121-002, Brazil
- Registered name: BRUNO SANTOS CONSULTORIA DE SISTEMAS LTDA (trading as Bruno on Apps) — CNPJ 33.279.051/0001-53