Privacy Policy

How we handle personal data under LGPD (Law 13.709/2018).

1. Who is the Controller

CoffeeMail acts as PROCESSOR of contact list data and messages processed by our customers, and as CONTROLLER of customer account data (name, email, organisation, access logs, billing data). Legal bases are contract execution and legitimate interest in ensuring platform security.

2. Data We Collect

Account data: name, email, password hash (bcrypt), organisation. Usage data: IP address, user agent, login timestamps and platform actions. Billing data: processed by AbacatePay gateway — we do not store full card numbers. Transactional data: sender, recipient, subject and body of sent emails (encrypted at rest).

3. Purposes of Use

Data is used for: (a) providing the contracted service; (b) authentication and security; (c) issuing invoices and meeting legal obligations; (d) sending transactional communications about the account itself; (e) fraud and abuse prevention.

4. Sharing

We share data only with: (a) infrastructure providers (PostgreSQL, RabbitMQ, GCP Cloud Run); (b) AbacatePay payment gateway; (c) Spedy fiscal gateway; (d) authorities when required by law. We do not sell personal data.

5. Retention

Account data: while the account is active + 5 years for accounting purposes. Sending logs and payloads: between 7 and 90 days per plan. Security audit logs: 12 months. After these periods data is anonymised or purged.

6. Data Subject Rights (LGPD art. 18)

You have the right to: confirm processing; access your data; correct incomplete data; request anonymisation, blocking or deletion; obtain portability; revoke consent. To exercise these rights, email contato@coffeemail.com.br. We respond within 15 days.

7. Cookies and Sessions

We use essential cookies for login session (HttpOnly, SameSite=Strict) and theme/language preferences. We do not use advertising or third-party tracking cookies. Session cookies expire on logout or after configured inactivity.

8. Information Security

We adopt technical and organisational measures: TLS 1.3 in transit, AES-256 at rest for sensitive data, bcrypt for passwords, optional MFA (TOTP) recommended for all users, immutable audit log for sensitive actions, role-based access control (RBAC) and per-organisation data segregation.

9. Privacy Channel

Questions about privacy and personal data protection should be sent to contato@coffeemail.com.br. Postal mail: Av. Paulista, 1000, São Paulo/SP, Brazil, ZIP 01310-100.

10. Changes to this Policy

This Policy may be revised periodically. Material changes will be communicated with at least 30 days notice by email to the organisation owner. The current version is always available at /privacy and the last update date is shown at the top.

11. Security Incidents

In the event of an incident that may cause relevant risk or damage to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) within 2 business days and affected subjects within 72 hours, per LGPD art. 48.

12. International Transfers

Data may be processed on infrastructure located in Brazil (GCP southamerica-east1 region). Where international transfer occurs we adopt standard contractual clauses approved by ANPD or operate with countries offering an adequate level of protection.