LGPD Policy
How CoffeeMail complies with the Brazilian General Data Protection Law (Law 13.709/2018).
1. Legal Framework
This page describes how CoffeeMail complies with the Brazilian General Data Protection Law (Law 13.709/2018, LGPD), the Marco Civil da Internet (Law 12.965/2014) and related Brazilian legislation. This document complements but does not replace our Privacy Policy, which explains how we handle personal data in plain language.
2. CoffeeMail's Roles
For contact lists, senders and email contents processed by our customers, CoffeeMail acts as PROCESSOR, handling data under the customer's instructions, who acts as CONTROLLER (LGPD art. 5, VI and VII). For account registration data (name, email, organisation, access logs, billing data), CoffeeMail acts as CONTROLLER. The primary legal bases are contract performance (art. 7, V) and legitimate interest for platform security and fraud prevention (art. 7, IX).
3. Legal Bases Used
We process personal data based on: (a) contract performance, to deliver the contracted service; (b) legitimate interest, for platform security, fraud prevention and improvement of our controls; (c) consent, for non-essential cookies and marketing communications; (d) legal or tax obligation, for issuing NFS-e invoices and retaining accounting records for 5 years.
4. Data Processed and Purposes
We process: (a) registration data — name, email, bcrypt password hash, CNPJ/CPF when applicable; (b) usage data — IP address, user agent, login timestamps and sensitive actions; (c) transactional data — sender, recipient, subject and body of sent emails, retained per plan quota; (d) billing data — processed by the payment gateway, with no local storage of full card numbers. Each category is used strictly for the purposes stated in this Policy and in our Privacy Policy.
5. Data Subject Rights (art. 18)
Data subjects have the right to: (i) confirm processing; (ii) access their data; (iii) correct incomplete or outdated data; (iv) request anonymisation, blocking or deletion of unnecessary data; (v) obtain portability; (vi) revoke consent; (vii) lodge a complaint with ANPD. To exercise these rights, email contato@coffeemail.com.br. We respond within 15 days, per art. 18, §5.
6. DSAR — Export and Erasure
Data subjects may request a complete export of their personal data in structured JSON, and account deletion with subsequent anonymisation, via the platform's official endpoints: GET /v1/platform/me/data-export and DELETE /v1/platform/me. After deletion, we preserve only accounting metadata required by Brazilian tax law (art. 16 and art. 37 of the CTN), as detailed in the Privacy Policy.
7. Privacy Channel
Questions about privacy, personal data protection and exercising rights should be sent to contato@coffeemail.com.br. Postal address for formal correspondence: Av. Paulista, 1000, Bela Vista, São Paulo/SP, Brazil, ZIP 01310-100.
8. International Transfers
Personal data is processed preferentially on infrastructure located in Brazil (GCP southamerica-east1 region). When international transfer is required, we adopt standard contractual clauses approved by ANPD or operate with countries offering an adequate level of personal data protection.
9. Security Incidents
In the event of an incident that may cause relevant risk or damage to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) within 2 business days, per LGPD art. 48, and affected subjects within 72 hours, via the registered contact channels.
10. Changes to this Policy
This Policy may be revised periodically. Material changes will be communicated with at least 30 days notice by email to the organisation owner. The current version is always available at /lgpd and the last update date is shown at the top.