Graffenno privacy portal
Here you'll find your rights as a data subject, how to exercise them, and what we do to protect the information that passes through the platform.
What the law guarantees you
The LGPD guarantees data subjects a series of rights over their personal data. All of them can be exercised with us.
Access
Know which personal data of yours we process and obtain a copy of it.
Correction
Request the correction of incomplete, inaccurate, or outdated data.
Deletion
Request the deletion of data, subject to legal obligations.
Portability
Request the portability of data to another service provider.
Withdrawal of consent
Withdraw consent previously given, at any time.
Information about sharing
Know which entities your data has been shared with.
Graffenno and the Brazilian General Data Protection Law (LGPD)
Law No. 13,709/2018 (LGPD) defines how personal data may be processed in Brazil. It guides how the platform is built and how your account is operated.
Legal basis for each use
Every instance of data processing on the platform relies on a legal basis, such as contract performance, compliance with a legal obligation, or legitimate interest.
Specific purpose
Data is processed for the purposes communicated to the data subject and is not used in a manner incompatible with what was disclosed.
Retention for as long as necessary
Information is kept for as long as the purpose requires or for the period required by applicable legislation, and is then deleted or anonymized.
Security and prevention
We adopt technical and administrative measures to protect personal data from unauthorized access and from situations of loss or improper alteration.
Graffenno as processor
When your company uses the platform to serve its own customers, you are the controller of your contacts' data and Graffenno acts as the processor, handling that information according to your instructions and the contract entered into.
Graffenno as controller
For data you provide directly to us, such as when requesting a demo, creating an account, or contacting support, Graffenno is the controller and is responsible for the purposes and means of the processing.
How to make a privacy request
Any of the rights above can be requested through official channels. The request is logged and answered within the deadlines set by law.
- 1
Gather the information
Have on hand the information that identifies you or your account, such as your registered email, and clearly describe which right you wish to exercise.
- 2
Send the request
Write to [email protected] or reach out through the website's support chat widget. The request is forwarded to the data protection officer.
- 3
Identity confirmation
It may be necessary to confirm your identity before the request is fulfilled. This step exists precisely to protect your data from third parties.
- 4
Response
The request is reviewed and answered within the deadlines set by legislation, with information about what was done or, if applicable, the legal justification for denial.
Talk to our DPO
The officer responsible for the processing of personal data is the channel for questions, requests, and complaints related to privacy and data protection at Graffenno.
Protection isn't a promise, it's a configuration
The security of the data that passes through the platform comes from technical controls and access decisions that remain in the hands of whoever administers the account.
- Data traffic protected by encryption in transit
- Individual per-user access, with their own credentials
- Team permissions, limiting what each person can see
- Data Processing Agreement (DPA) available on the Enterprise plan
Platform controls
- Encryption
- Per-user access
- Team permissions
- DPA
Read the full documents
The terms and policies detail the rules for using the platform and the processing of personal data.
About privacy and data
Your company. When you use Graffenno to run your business, you define the purposes of the processing and are the controller of that data. Graffenno acts as the processor, handling the information according to your instructions and the contract.
Send the request to [email protected] or reach out through the website's support chat widget. The request is forwarded to the data protection officer, who reviews and responds within the legal deadlines, subject to the record-keeping obligations set by law.
Yes. Contact with the officer responsible for the processing of personal data is made through the email [email protected], which also handles questions and complaints about privacy and data protection.
Yes. The Data Processing Agreement (DPA) is available on the Enterprise plan. If your company has specific compliance requirements, talk to our sales team before signing up.
Transparency from the first contact to the last piece of data
Talk with our team about privacy, security, and compliance before signing up.
- Guided onboarding
- Human support over WhatsApp
