Privacy Policy
Thesum Tecnologia Ltda. ("Thesum", "we", "us") is committed to protecting the privacy and personal data of our users in accordance with Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13.709/2018) and applicable international privacy standards.
1. Data We Collect
We collect: (a) Account Data — name, email, company name, and CNPJ provided during registration; (b) Financial Data — balance sheets (balancetes) and financial statements uploaded by the user for analysis; (c) Usage Data — anonymized interaction logs, feature usage patterns, and session metadata used to improve the platform; (d) Communication Data — messages sent through our contact forms or support channels.
2. Purpose and Legal Basis
Your data is processed for: (a) Execution of the service contract (Art. 7, V LGPD) — running the financial analysis engine, generating strategic reports, and delivering advisory outputs; (b) Legitimate interest (Art. 7, IX LGPD) — improving platform performance, developing new features, and conducting anonymized benchmarking analyses; (c) Consent (Art. 7, I LGPD) — sending marketing communications, which can be withdrawn at any time.
3. Data Sharing
We do not sell personal data. Financial data uploaded to the platform is never shared with third parties. Anonymized, aggregated benchmarking data (containing no identifiable company information) may be used to improve the accuracy of our sector analysis engine. Infrastructure providers (cloud hosting, email delivery) process data strictly under our instructions and contractual safeguards.
4. Data Retention
Account and financial data is retained for the duration of the active subscription plus 12 months. Upon account deletion, all identifiable data is permanently purged within 30 business days. Anonymized analytical derivatives (benchmarking indices) are retained indefinitely as they contain no personal information.
5. Your Rights (LGPD Art. 18)
You have the right to: (a) confirm the existence of processing; (b) access your data; (c) correct incomplete or inaccurate data; (d) anonymize, block, or delete unnecessary data; (e) request data portability; (f) delete personal data processed with consent; (g) obtain information about sharing practices; (h) revoke consent at any time. Requests can be submitted to privacidade@thesum.com.br and will be processed within 15 business days.