Privacy

Privacy Policy.

Last updated: July 6, 2026 · version RV02

This Policy describes how Domos, operated by SELVAGEN, collects, uses, stores and shares your personal data. It is aligned with Brazil's LGPD (Law 13.709/2018), and, where applicable, with the EU General Data Protection Regulation (GDPR — Regulation EU 2016/679) and the UK-GDPR.

1. Who We Are

Domos is a platform operated by SELVAGEN DESIGN E ARQUITETURA LTDA, Brazilian CNPJ No. 31.104.552/0001-73, headquartered at Rua Domingos José Martins, 75, Sala 107, Bairro do Recife, Recife/PE, 50.030-200, Brazil, acting as the **data controller** for personal data processed by this service.

General contact for privacy matters: privacidade@selvagen.com

Data Protection Officer (DPO / Encarregado, art. 41 LGPD): **Paulo Roberto Dutra Carvalho**, Founder of SELVAGEN. Direct contact: `privacidade@selvagen.com`.

2. Data We Collect

We collect the following categories of data:

- **Account data:** email (required), name (optional), avatar image (optional), preferred language.

- **Usage data:** dome projects created, parameters used, exports performed, active plan, subscription history.

- **Payment data:** we do **not** store credit card data. Processing is handled entirely by Stripe. We only receive transaction confirmation and the last 4 digits of the card for invoice identification.

- **Technical data:** IP address, browser type, operating system, access timestamps (kept as security logs).

We do not collect sensitive data (art. 5, II LGPD and Art. 9 GDPR) — racial or ethnic origin, religious belief, political opinion, trade-union membership, health data, genetic or biometric data, sex-life data — in the ordinary operation of the platform.

3. How We Use Your Data

We use your data to:

- **Operate the platform:** authentication, save projects, export files.

- **Process payments** via Stripe.

- **Send operational communications** (signup confirmation, invoices, material service changes, security notices).

- **Send marketing communications**, only upon your specific and granular opt-in, with unsubscribe option in each message (Section 8).

- **Improve the product** through **aggregated and anonymised** analysis — no individual identification.

- **Comply with legal and tax obligations**, including invoice issuance and accounting retention.

- **Prevent fraud and ensure infrastructure security**.

We do not make solely automated decisions with legal effects or relevant impact on the user (art. 20 LGPD; Art. 22 GDPR). All platform functionality follows from parameters consciously configured by the user.

4. Legal Basis for Processing

4.1 Under LGPD (art. 7)

- **Contract performance** — to provide the service you contracted.

- **Legal or regulatory obligation** — invoice issuance, accounting retention, authority requests.

- **Legitimate interests** — fraud prevention, platform security, product improvement, preceded by proportionality and transparency analysis.

- **Consent** — for marketing communications and specific processing requiring this basis (specific, granular and revocable opt-in).

4.2 Under GDPR (Art. 6) — where applicable to EU/UK data subjects

- **Contract performance** — Art. 6(1)(b): for service provision.

- **Legal obligation** — Art. 6(1)(c): tax and regulatory obligations.

- **Legitimate interests** — Art. 6(1)(f): security, fraud prevention, product improvement, following balancing test.

- **Consent** — Art. 6(1)(a): marketing and other specific processing, revocable at any time.

5. Sharing with Third Parties

We share data only with operators strictly necessary to run the service:

- **Supabase Inc.** (database and authentication) — stores account and project data. Headquartered in the United States.

- **Stripe Inc.** (payment processing) — receives email, name and transaction data. Headquartered in the United States.

- **Application hosting provider** — receives technical logs.

- **Transactional email provider** — receives email and name to deliver operational messages.

The complete and updated list of sub-processors, with purpose, data processed, location and legal safeguards for international transfers, is available at `domos.selvagen.com/subprocessors`.

We do **not** sell, rent or commercialise your personal data with third parties for marketing purposes. For California residents (CCPA/CPRA), we do not "sell" or "share" personal information as defined by those statutes.

6. Cookies & Similar Technologies

We use the following cookie categories:

- **Session (essential):** keep you authenticated during use.

- **Preferences (essential):** language, theme, UI settings.

At this time, we do **not** use third-party analytics or marketing cookies. If that changes, we will update this Policy and request prior consent as required by applicable law, with granular acceptance (by category) and easy revocation mechanism.

7. Data Retention

We retain your data for the following periods:

- **Account and project data:** while the account is active + 30 days after closure, to allow reactivation.

- **Authentication and security logs:** up to 12 months, on the basis of legitimate interest in fraud prevention and incident investigation.

- **Tax data** (invoices, payment receipts): for the minimum legal period (5 years under Brazilian law, or equivalent in the user's jurisdiction).

- **Support communication records:** up to 24 months, for service and history.

After these periods, data is permanently removed or anonymised, under art. 12 LGPD.

8. Your Rights

As the data subject, you have the right to:

- **Confirm** that your data is being processed.

- **Access** your data.

- **Correct** incomplete, inaccurate or outdated data.

- **Anonymise, block or delete** unnecessary, excessive or non-compliantly processed data.

- **Portability** of your data to another provider.

- **Delete** data processed based on consent.

- **Information** about shared use of your data.

- **Information** about the possibility of withholding consent and the consequences.

- **Withdraw consent** at any time, as easily as it was given.

- **Object to processing** carried out on bases other than consent, in case of non-compliance with LGPD (art. 18, § 2), or under Art. 21 GDPR when applicable.

- **Review of automated decision** affecting your interests (art. 20 LGPD; Art. 22 GDPR).

- **Lodge a complaint** with the competent authority — the Brazilian Data Protection Authority (ANPD), or the supervisory authority of the competent EU/UK Member State, or the equivalent US state authority where applicable.

Additionally, if you are a California resident, you have the rights provided by the CCPA/CPRA, including right to know, delete, correct, opt-out of sale/sharing (not applicable — we do not sell/share), limit use of sensitive personal information (not applicable — we do not collect sensitive data), and non-discrimination for exercising these rights.

To exercise any of these rights, send a request to `privacidade@selvagen.com`. We respond within 15 (fifteen) calendar days, extendable by an equal period in case of justified complexity.

9. Security

We implement the following technical and organisational measures:

- Encryption in transit (HTTPS/TLS) on all communications.

- Encryption at rest in the database (Supabase native feature).

- Passwords stored only as hashes, never in plain text.

- Database access controlled via Row Level Security (RLS).

- Administrative access restricted by principle of least privilege.

- Logging of access and critical changes.

- Internal incident response policy.

No system is 100% secure. In the event of an incident that may pose relevant risk to the rights and freedoms of data subjects:

- **LGPD (art. 48):** we will notify the ANPD and affected subjects within a reasonable period, in line with authority regulation.

- **GDPR (Art. 33 and 34):** we will notify the competent supervisory authority within 72 (seventy-two) hours of becoming aware of the incident, and communicate to data subjects without undue delay when the incident represents high risk.

10. International Transfers

Part of the infrastructure running Domos (Supabase, Stripe, hosting) is located outside Brazil, notably in the United States.

In these cases, providers ensure an adequate level of protection under LGPD art. 33, through:

- **Standard Contractual Clauses (SCC)** approved by the European Commission, complemented by a Transfer Impact Assessment (TIA) where the transfer involves EU/UK data subjects, in observance of the *Schrems II* ruling (C-311/18).

- **Relevant international certifications** of the operators (SOC 2 Type II, ISO 27001, where applicable).

- **Additional technical and organisational safeguards**, including encryption in transit and at rest.

The updated list of sub-processors and the legal bases applicable to each transfer are available at `domos.selvagen.com/subprocessors`.

11. Children

The service is intended for users aged 18 (eighteen) and over. We do not knowingly collect personal data from children or adolescents.

If we identify minor data collected without parental authorisation, we remove it immediately. Requests from legal guardians can be sent to `privacidade@selvagen.com`.

12. Changes to This Policy

We may update this Policy periodically. Material changes will be communicated by email and via platform notice with at least 30 (thirty) days notice.

The last-updated date is always shown at the top of this document.

Contact & Data Protection Officer (DPO)

SELVAGEN maintains a Data Protection Officer (DPO / Encarregado) responsible for receiving communications from data subjects and from Brazil's National Data Protection Authority (ANPD), under art. 41 LGPD, as well as from applicable supervisory authorities when the data subject is in the EU/UK. Channel for exercising privacy rights and communications with the DPO: `privacidade@selvagen.com`. Data Protection Officer (LGPD art. 41): **Paulo Roberto Dutra Carvalho**, Founder of SELVAGEN. EU Representative (Art. 27 GDPR) and UK Representative (UK-GDPR): given the size and operating model of Domos — a Brazilian micro-enterprise without large-scale processing or systematic monitoring of EU/UK data subjects —, the exception under Art. 27(2) GDPR applies. This position will be re-assessed if the volume or nature of processing requires formal designation. California / US state privacy rights: applicable CCPA/CPRA disclosures are included in Section 8 of this Policy. Additi