Privacy Policy
- Version:
4.0.0- In force since:
- October 02, 2026
- Supersedes:
- 3.0.0 (September 9, 2026)
- Operated by:
- GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88
This Policy describes how GMB TECNOLOGIA LTDA, CNPJ 68.727.144/0001-88, headquartered in Belo Horizonte/MG, Brazil (“Upuai”, “we”), processes personal data on the Upuai Cloud platform, in compliance with the Brazilian General Data Protection Law (Law no. 13,709/2018 — LGPD).
Language. This is a courtesy translation. The Portuguese version at upuai.com.br/privacidade is the binding version; in case of divergence, it prevails.
1. Two distinct roles
This Policy covers personal data for which we are the Controller: data about people who create an account, subscribe and use the Platform.
Personal data you process inside your own applications — belonging to your customers and end users — follows a different regime: there you are the Controller and we are the Processor, acting solely on your instructions. That relationship is governed by the Data Processing Addendum (DPA). We do not access the contents of your databases, buckets and volumes except to provide support you request, to comply with a legal order, or to contain a security incident.
2. Data we collect
Account data. Name, email address and, where you use social login, your profile picture and your account identifier at GitHub, GitLab or Google.
We do not collect passwords. Authentication uses a one-time code sent to your email or an external provider. There is no Upuai account password.
Access and session data. IP address and user agent (browser or CLI) associated with your active sessions and with the record of your acceptance of the legal documents; date and time of last access.
Audit records. Significant actions on the Platform — creation, modification and deletion of resources — with the actor’s identity, IP address, user agent, date and time.
Tokens and credentials. API tokens you issue (stored only as a cryptographic digest, never in plain text) and credentials for integrations you voluntarily connect, such as GitLab and Cloudflare, stored encrypted.
Billing data. Customer, subscription and invoice identifiers at the payment processor, amounts, currency, status and dates. We do not store credit card data — it is collected and processed directly by the payment processor.
Commercial contact data. If you complete the public contact form: name, company, email, phone number and the message sent.
Technical and browsing data. Browser and operating system information, pages visited and referral source, collected via cookies as described in section 8 and in the Cookie Policy.
Customer Content. Source code, container images, environment variables, databases, files and application execution logs. We treat this content as confidential. Where it contains third-party personal data, the DPA applies.
3. How we use data
We use data to: provide, maintain and operate the Platform; authenticate you and protect your account; build, deploy and run your applications; process payments and manage your subscription; send service communications such as deployment, billing, security and maintenance notices; provide support; detect, investigate and prevent fraud, abuse and security incidents; produce aggregate usage statistics; and comply with legal and regulatory obligations and orders from competent authorities.
With your consent, we also use data to measure site audience.
While you hold an account on the Platform, we send marketing communications about our own products and similar services — product news, technical content and offers — on the basis of legitimate interests. Every such email carries a one-click unsubscribe link, and your mail provider’s native “Unsubscribe” button works as well. You may object at any time, without giving a reason and without any effect on the service you subscribed to, there or under Settings → Notifications.
We do not sell personal data and we do not use it to train artificial intelligence models.
4. Legal bases (LGPD art. 7)
| Purpose | Legal basis |
|---|---|
| Creating and maintaining an account, providing the service, billing | Performance of a contract (art. 7, V) |
| Security, fraud and abuse prevention, audit records | Legitimate interests (art. 7, IX) |
| Tax and accounting obligations, authority orders | Compliance with a legal obligation (art. 7, II) |
| Audience and advertising cookies | Consent (art. 7, I) |
| Marketing communications to customers, about our own and similar products | Legitimate interests (art. 7, IX) |
| Exercising rights in proceedings | Regular exercise of rights (art. 7, VI) |
Operational communications about the service you subscribed to — deployment failure, invoice, security incident — are not marketing and are sent on the basis of performance of the contract.
On the legitimate-interests basis for marketing: it is limited to people who are already our customers and to our own products, similar to the ones you subscribed to; it does not extend to third parties or to sharing with advertisers. We balanced that someone subscribing to an infrastructure platform reasonably expects news about it, and that the impact is low given the ability to opt out in one click. You may object to this processing at any time (art. 18, §2), and we stop — with no consequence for the service you subscribed to.
5. Automated failure summaries using artificial intelligence
When a build or deployment fails, the execution logs may be sent to Google Gemini to generate a summary of the error shown in the dashboard. Those logs may contain excerpts of your code, file paths and messages from your application.
The processing is based on performance of the contract, and the provider acts as a subprocessor, with no authorization to use the content to train models. You can disable this feature in the project settings; the dashboard will then show the raw log without a summary.
6. Storage, security and international transfers
Where data resides. Production infrastructure runs on our own dedicated servers, in a datacenter located in Belo Horizonte/MG, Brazil. Your applications, databases, buckets and volumes remain in Brazil.
International transfers. There are two situations in which data leaves Brazil:
- External backup copy. A daily copy of our control database — containing account, workspace and billing data, not the contents of your applications — is encrypted before it leaves our infrastructure and stored with an external storage provider, with 30-day retention and tamper protection. The decryption key is not shared with the provider.
- Foreign subprocessors. Payment processor, email provider, language model provider, identity and audience providers. The full list, with purpose and country, is at /en-US/subprocessors.
Transfers rely on article 33 of the LGPD, through contractual data protection clauses agreed with each vendor and, where applicable, on necessity for performance of the contract.
Security. Our measures include: encryption in transit (TLS) and encryption of secrets at rest; role-based access control; isolation between workspaces via namespaces and network policy; audit records; vulnerability scanning of images; signing of Platform images; and infrastructure backups.
No system is immune to incidents. In the event of a security incident posing relevant risk to data subjects, we will notify those affected and the Brazilian data protection authority (ANPD) within the statutory deadlines.
7. Sharing
We share personal data only with: subprocessors listed at /en-US/subprocessors, contractually bound to process it on our instructions; public authorities, where required by law or court order; and third parties in a corporate reorganization, such as a merger or acquisition, in which case data subjects will be notified and this Policy will continue to apply until any amendment.
8. Cookies
We use strictly necessary, preference, audience and advertising cookies. Audience and advertising cookies are activated only after your consent, which you may grant, refuse and withdraw at any time through the preferences panel linked in the footer of every page. A cookie-by-cookie breakdown is in the Cookie Policy.
9. Retention
| Data | Period |
|---|---|
| Account data | For as long as the account exists |
| Customer Content after account closure | 15 days, then irreversible deletion |
| Personal data after account closure | Up to 30 days, subject to the exceptions below |
| Access logs (IP, user agent) | 6 months (Internet Civil Framework, art. 15) |
| Audit records | 12 months |
| Records of acceptance of legal documents | For as long as the account exists and for 5 years thereafter, as evidence of the contractual relationship |
| Build and deployment execution logs | 30 days |
| Application runtime logs | 12 hours to 30 days, depending on Plan |
| Tax and payment documents | 5 years (tax legislation) |
| Unconverted commercial contacts | 24 months from last contact |
10. Your rights (LGPD art. 18)
At any time you may: confirm the existence of processing; access your data; correct incomplete, inaccurate or outdated data; request anonymization, blocking or deletion of unnecessary data or data processed unlawfully; request portability; obtain information about sharing; be informed about the possibility of withholding consent and its consequences; and withdraw consent.
Directly in the dashboard, without contacting us:
- Access and correct — Settings › Account.
- Export your data — Settings › Account › Export my data. Produces a structured file with your personal data, suitable for portability.
- Delete your account — Settings › Account › Delete account. Deletion removes your personal data and your resources, subject to the statutory retention periods in section 9.
- Communication preferences — Settings › Notifications.
- Cookie preferences — link in the footer of any page.
For the remaining rights, or if you prefer to speak to a person, write to contato@upuai.com.br. We respond within 15 days.
11. Data Protection Officer
Data Protection Officer channel: contato@upuai.com.br.
Formal correspondence to the Data Protection Officer: via the same email address, or request a postal address through it.
You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd.
12. Children and adolescents
The Platform is not intended for people under 18 and we do not knowingly collect data from children and adolescents. If we identify such an account, it will be closed and the data deleted.
13. Changes to this Policy
We may update this Policy. Material changes — a new purpose, new legal basis, new data category or new recipient — will be communicated by email and on the Platform 30 days before they take effect, and continued use of the Platform after that date constitutes acceptance of the new version. Where a change depends on consent, that consent will be collected separately, and silence will not be treated as consent. The current version and history are at /legal.
GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88 — Belo Horizonte/MG, Brazil.