BRAZUKVoltar ao início
PortuguêsEnglish
Privacy

Your data deserves context, control and protection.

This policy explains how Brazuk processes personal data, why it does so, and the choices and rights available in Brazil and where the service is offered, including the United Kingdom.

Updated on 15 August 2026 · privacy-2026-08-15

1. Controller and contact

The controller is BRAZUK TECNOLOGIA E SERVICOS LTDA, Brazilian company registration CNPJ 68.473.612/0001-35, Avenida Paulista, 1636, Suite 1105, Bela Vista, São Paulo/SP, 01310-200, Brazil. Independent shops and providers may be controllers for their own purposes. For privacy questions or rights requests, contact privacy@brazuk.app.

2. Scope

This policy applies to the app, website and Brazuk features that link to it. External services reached through links or integrations have their own policies, which you should read before use.

3. Data we process

We may process registration and contact details, date of birth, city and postcode, profile and preferences, content and messages, security and support records, device data, transactions and payment status, reviews, agreements and evidence you voluntarily provide. Full card details remain with the payment processor.

4. Location and device permissions

Precise location, camera, photos and notifications are accessed only after an action or permission appropriate to the requested feature. You can deny or withdraw permissions in device settings, although some features may stop working. Where sufficient, we use city or postcode instead of precise location.

5. Purposes and lawful bases

We process data to create and perform your account and orders (contract), protect the platform, prevent fraud, moderate and improve the service (assessed legitimate interests), comply with law and authorities (legal obligation), and, where stated, send marketing, use optional permissions or carry out another specific purpose with consent. Accepting the Terms and acknowledging this policy does not replace analysis of the lawful basis for each activity.

6. Brazuk Score and profiling

The Score summarises internal signals such as checks, completed transactions, confirmed agreements and reviews linked to genuine relationships. A single negative report should not reduce the result without appropriate confirmation or review. Challenged events have no impact during review, and behavioural signals stop affecting the Score after the defined period.

7. Decisions and human review

Brazuk does not use the Score, on its own and solely by automated means, to make decisions with legal or similarly significant effects about you. Authorised access must be only an additional factor. You can request an explanation, correct data, challenge events, object to profiling and request human review.

8. Sharing

We do not sell personal data. We share only what is necessary with providers that host and protect the platform, payment and communication processors, parties to a transaction you choose, temporarily authorised recipients, advisers and authorities where there is a lawful basis. Contracts and controls limit provider use.

9. International transfers

Because Brazuk serves an international community, data may be processed in Brazil, the United Kingdom and countries where contracted providers operate. Where required, we use mechanisms under the LGPD and the ANPD International Data Transfer Regulation, including applicable standard clauses, together with mechanisms recognised by the UK GDPR, risk assessments and appropriate contractual safeguards.

10. Retention

We retain data for as long as needed for the purpose and applicable obligations. Behavioural Score signals and access logs may be kept for up to 24 months; closed codes for up to 90 days. Agreements, disputes, evidence, acceptance and security records may be retained longer where needed for a legal obligation, fraud prevention or legal claims. Data is then deleted or anonymised.

11. Security

We use access controls, database policies, private storage, infrastructure encryption, expiring codes, audit records and incident review. No system is infallible, so report suspected unauthorised access immediately and never share credentials.

12. Your LGPD and UK GDPR rights

Depending on the circumstances, you can request confirmation of processing, access, correction, anonymisation, blocking, erasure, portability, information about sharing, restriction, objection and review of automated decisions covered by law. We will verify identity and respond within the applicable legal timeframe, explaining any permitted extension.

13. Consent, objections and marketing

Where processing relies on consent, you can withdraw it at any time without affecting earlier processing. You can object to direct marketing at any time and, in some circumstances, to processing based on legitimate interests. Notification preferences do not replace operating-system settings.

14. Account deletion

You can request deletion through app controls or support. Deletion removes or disassociates data that no longer needs to be kept. Minimal records may remain restricted where law, security, fraud prevention or legal claims justify retention.

15. People under 18

Brazuk does not allow people under 18 to register. If we learn that an account was created contrary to this rule, we may block it and delete the data, retaining only what is needed for security or a legal obligation.

16. Storage, analytics and communications

We use essential storage for authentication, security and preferences. Optional analytics and promotional communications must respect the choices presented. Operational messages needed for an account or transaction may be sent regardless of marketing preference.

17. Changes to this policy

The version and date of this policy are displayed above. We will explain material changes before incompatible new uses where required and seek specific consent if that is the necessary lawful basis.

18. Questions and complaints

Send requests to privacy@brazuk.app. In Brazil, you may petition the National Data Protection Authority (ANPD) after attempting to exercise your rights with the controller. Where the UK GDPR applies, you may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We encourage you to contact us first so we can investigate and respond.