Privacy Policy
How we handle personal data under LGPD (Law 13.709/2018).
1. Who is the Controller
CoffeeMail acts as PROCESSOR of contact list data and messages processed by our customers, and as CONTROLLER of customer account data (name, email, organisation, access logs, billing data). Legal bases are contract execution and legitimate interest in ensuring platform security.
2. Data We Collect
Account data: name, email, password hash (bcrypt), organisation. Usage data: IP address, user agent, login timestamps and platform actions. Billing data: processed by AbacatePay gateway — we do not store full card numbers. Transactional data: sender, recipient, subject and body of sent emails (encrypted at rest).
3. Purposes of Use
Data is used for: (a) providing the contracted service; (b) authentication and security; (c) issuing invoices and meeting legal obligations; (d) sending transactional communications about the account itself; (e) fraud and abuse prevention.
5. Retention
Account data: while the account is active + 5 years for accounting purposes. Sending logs and payloads: between 7 and 90 days per plan. Security audit logs: 12 months. After these periods data is anonymised or purged.
6. Data Subject Rights (LGPD art. 18)
You have the right to: confirm processing; access your data; correct incomplete data; request anonymisation, blocking or deletion; obtain portability; revoke consent. To exercise these rights, email contato@coffeemail.com.br. We respond within 15 days.
8. Information Security
We adopt technical and organisational measures: TLS 1.3 in transit, AES-256 at rest for sensitive data, bcrypt for passwords, optional MFA (TOTP) recommended for all users, immutable audit log for sensitive actions, role-based access control (RBAC) and per-organisation data segregation.
9. Privacy Channel
Questions about privacy and personal data protection should be sent to contato@coffeemail.com.br. Postal mail: Av. Paulista, 1000, São Paulo/SP, Brazil, ZIP 01310-100.
10. Changes to this Policy
This Policy may be revised periodically. Material changes will be communicated with at least 30 days notice by email to the organisation owner. The current version is always available at /privacy and the last update date is shown at the top.
11. Security Incidents
In the event of an incident that may cause relevant risk or damage to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) within 2 business days and affected subjects within 72 hours, per LGPD art. 48.
12. International Transfers
Data may be processed on infrastructure located in Brazil (GCP southamerica-east1 region). Where international transfer occurs we adopt standard contractual clauses approved by ANPD or operate with countries offering an adequate level of protection.