Privacy Centre

Your data, in plain sight.

Here is everything MAI collects, why, for how long, and how you get your data out whenever you want. No treasure hunt, no fine print in hiding.

Policy v2026-08 · in force since 24 August 2026 · reply within 15 days

The path of a piece of data inside MAI

Five stations. Each one links to the chapter of the policy that governs it.

  1. 01

    Collection

    We only ask for what the purpose requires. Every form states what each field is for.

    minimisation
  2. 02

    Use

    Each piece of data has a declared purpose. We do not use it for anything else without telling you.

    purpose
  3. 03

    Storage

    Storage with controlled access, files in a private area and an audit trail.

    security
  4. 04

    Deadline

    Every piece of data has a date to stop existing here. The retention table is public.

    retention
  5. 05

    Deletion

    At the end of the period or at your request: deletion with an audit record.

    art. 18

Privacy Policy

v2026-08 · in force since 2026-08-24

Draft under legal review. This text was written from MAI's real data flows and is published here for transparency, but it is not the final version. Nothing in it reduces your rights under Brazilian data protection law.

1. Who we are and our role

In short: MAI handles data in three different roles. Knowing which one applies to you changes who answers your request.

The summary helps you understand; the full text is what counts.

MAI PRO is, at the same time, a software company and a marketing agency. That means we handle personal data in three distinct roles, and each one has different consequences for you.

Controller of our own website data. When you fill in a form on maipro.app.br, chat with MAIA, request the free digital presence diagnosis or send a CV, it is MAI that decides what that data is for. We answer for it.

Controller of data belonging to those who hire the platform. Sign-up, billing, product usage and the business history the platform accumulates from day one (what we internally call the Client's Digital Life).

Processor of third-party data. When a client connects their own accounts (Google Ads, Meta, stores, CRMs) or publishes a landing page with MAI LP PRO, MAI processes data belonging to THEIR clients and visitors, following THEIR instruction. In that case the controller is the client, not MAI — and section 8 explains how your request is forwarded.

2. What data we collect and where

In short: Each surface collects something specific, and all of them are listed in the public retention table on this page.

The summary helps you understand; the full text is what counts.

There is no invisible collection: everything we keep comes in through a form you filled in, an account you connected, or the running of the service itself (such as the login record).

Public website forms: name, e-mail, phone, company and whatever you wrote. MAIA chat: what was discussed, plus contact details when you provide them. Careers: CV, contact details and the evidence of your consent (when, from where and under which text). Platform sign-up: name, e-mail and password (stored only as a hash). Billing: tax details and payment history. Access records: date, time, IP address and browser of each login.

The table in #retencao lists each of these sources with fields, purpose, legal basis and deadline. It is generated from our internal data registry — if a source does not appear there, it should not exist.

3. What we use it for

In short: Each piece of data has a declared purpose. Using it for anything else requires telling you first.

The summary helps you understand; the full text is what counts.

Sales contact is used to reply to you and run the sales conversation. CVs are used to assess you in hiring processes. Sign-up and billing data are used to perform the contract. Access records are used for account security.

Inside the platform, a client's business data feeds analyses, diagnoses and recommendations — including through artificial intelligence models. That data is not used to train third-party generic models: it serves to produce the analysis the client hired.

We do not use one client's data to produce another client's analysis. Market comparisons come from segment aggregates, never from identifiable data of another company.

4. Legal bases

In short: Consent for CVs, contract performance for the platform, legitimate interest for sales contact, legal obligation for tax and access records.

The summary helps you understand; the full text is what counts.

Consent (art. 7, I): CVs and the talent pool. You can withdraw at any time, and the withdrawal deletes the data.

Contract performance (art. 7, V): sign-up, access and operation of the platform for clients.

Legitimate interest (art. 7, IX): replying to whoever reaches out to MAI through a form or the chat. You can object — and in practice the objection is the deletion request this page handles.

Legal obligation (art. 7, II): tax documents and application access records. These are the cases where we cannot delete even at your request, and section 8 explains how that is communicated.

5. Who we share with

In short: Only with processors needed for the service to work — all listed on this page, with what each one handles.

The summary helps you understand; the full text is what counts.

The full list of processors is in the section “Who helps us operate” on this page, with each one's category and what they process. It comes from a real review of the infrastructure, not from a generic template.

We share only what the purpose requires: the e-mail provider sees the message it needs to deliver; the payment processor sees what it needs to charge; the cloud provider hosts the application.

Some processors are outside Brazil. Those cases are covered in chapter 12.

6. Cookies and similar technologies

In short: Current state described honestly: there is still no cookie consent banner on the website.

The summary helps you understand; the full text is what counts.

[CONFIRMAR] The review carried out to write this policy found no cookie banner or consent management tool on MAI's website. The site uses browser local storage to keep your session when you log into the platform.

We would rather record the gap than describe a mechanism that does not exist. Implementing consent management is an open item and will be described here once it exists.

7. How long we keep it

In short: Every piece of data has a deadline. The public table on this page shows the deadline for each source and what happens at the end of it.

The summary helps you understand; the full text is what counts.

CVs: 12 months, deleted automatically. Sales contacts: period under confirmation. Billing: statutory tax period. Access records: the period set by the Brazilian Internet Act. Privacy requests: the period needed as evidence of the response.

The table in #retencao is the up-to-date reference — it is generated from the same registry our response process uses to locate and delete data, so there is no gap between what we say and what we do.

[CONFIRMAR — infrastructure] The purge cycle for backup copies still depends on confirmation and will be described here once it is defined.

8. Your rights and how to exercise them

In short: All rights under art. 18, through the form on this page, free of charge and with no justification needed.

The summary helps you understand; the full text is what counts.

The form at the end of this page covers confirmation, access, correction, anonymisation, deletion, withdrawal of consent, portability and information about sharing.

The process is: you submit, you confirm through your e-mail, and you receive the full answer within the deadline. The e-mail confirmation exists to stop someone from requesting deletion of your data in your name — and it is less invasive than requiring an identity document.

When part of the request cannot be fulfilled (art. 16), the answer states exactly what, under which legal basis and until when. No retention happens in silence.

If your data reached us through a MAI client, we forward your request to the controller and confirm the forwarding to you.

9. Information security

In short: The practices described in this policy are the ones that exist in the code — no decorative badges.

The summary helps you understand; the full text is what counts.

The “Security in practice” section on this page lists the verified mechanisms: per-client isolation enforced on the server, passwords as bcrypt hashes, integration credentials encrypted with AES-256, private files outside the public area, pseudonymised IPs on forms, automatic deletion on schedule and an audit trail.

Whatever is not there is not there because it has not been verified — and a security claim without a mechanism is exactly the kind of sentence this policy exists not to have.

Perfect security does not exist. If you spot something odd, write to the Data Protection Officer: it is the fastest channel and the report is taken seriously.

10. Candidate data

In short: CVs stay 12 months, disappear on their own after that, and leave sooner if you ask.

The summary helps you understand; the full text is what counts.

When you send a CV through the Careers page, we keep the file and your contact details for up to 12 months, solely for current and future hiring processes. The legal basis is your consent, recorded with date, origin and the text you accepted.

The CV file is never at a public address: it is stored outside the web-served area, under a random name, and is only accessed by people with permission in the internal system.

At the end of the period, the file is deleted and the data anonymised automatically, with an audit record. You can bring that forward at any time through the form on this page.

11. Data processed under client instruction

In short: If your data came through a company that uses MAI, they decide about it — and we forward your request.

The summary helps you understand; the full text is what counts.

MAI clients publish landing pages, connect media accounts and run sales funnels inside the platform. Data about their visitors and customers passes through our infrastructure, but the purpose is decided by them.

In those cases MAI is a processor. We do not delete, correct or export that data on our own: doing so would mean deciding about third-party data in place of whoever answers for it.

What we do is forward your request to the correct controller and confirm to you that the forwarding happened. If you prefer, you can also contact them directly.

12. International transfers

In short: Some processors are outside Brazil; the list with countries is on this page.

The summary helps you understand; the full text is what counts.

Some of the processors required for the service to work are based outside Brazil — international payment processing and AI model providers, for example.

[CONFIRMAR — legal] The list of countries and the transfer instrument applicable to each processor are under confirmation and will be published in the processors section of this page.

13. Data Protection Officer and contact

In short: The channel for any data matter — including telling us we got it wrong.

The summary helps you understand; the full text is what counts.

[CONFIRMAR — D1] The name of the Data Protection Officer and the dedicated e-mail address must be defined by MAI before publication, as required by art. 41, §1 of the Brazilian data protection law.

Until then, the contact channel for data matters is the address published in the Data Protection Officer section of this page.

14. Changes to this policy

In short: Every version has a number and a date. Material changes are notified by e-mail to anyone with an active relationship with us.

The summary helps you understand; the full text is what counts.

Each version of this policy has a number and an effective date, and the version in force is the only source the website forms use to record under which text you gave your consent.

When there is a material change, we notify by e-mail everyone with an active relationship with us. Wording changes that do not alter rights or purposes go into the history only.

What you can ask for — anytime, free of charge

Brazilian data protection law guarantees it. We comply without drama and without asking why.

  • Confirm and access

    art. 18, I e II

    Find out whether we hold data about you and get a copy of it.

    Request →
  • Correct

    art. 18, III

    Update incomplete, wrong or outdated data.

    Request →
  • Delete

    art. 18, VI

    Erase data we process based on your consent.

    Request →
  • Anonymise or block

    art. 18, IV

    For data that is unnecessary, excessive or processed unlawfully.

    Request →
  • Withdraw consent

    art. 18, IX

    Take back permission you gave us — leaving the talent pool, for example.

    Request →
  • Portability

    art. 18, V

    Take your data to another provider, as regulated.

    Request →
  • Know who we share with

    art. 18, VII

    The list of entities your data was shared with.

    Request →

Not everything can be erased on the spot: the law requires us to keep some records (tax records of payments, for instance). When that happens, we reply in writing stating exactly what was deleted, what had to stay, under which legal basis and until when.

Did your data reach us through a company that uses the MAI platform? In that case they are the controller and we process it under their instruction. You can contact them directly — or send your request right here, and we forward it to the client and confirm the forwarding to you.

How long each piece of data stays here

Generated from our internal data registry — when the registry changes, this table changes with it.

  • CVs and job applications

    Form on the Careers page

    Purpose
    Assessing you for current and future roles (talent pool).
    Period
    12 months from submission
    At the end
    File deleted and data anonymised automatically, with an audit record.
  • Sales contacts

    Website forms, digital presence diagnosis, MAIA chat

    Purpose
    Replying to your enquiry and running the sales conversation.
    Period
    24 months without interaction (under confirmation)
    At the end
    Contact anonymised; business history remains without identifying you.
  • MAIA chats on the website

    MAIA chat on public pages

    Purpose
    Answering your question and routing you to the right team.
    Period
    24 months without interaction (under confirmation)
    At the end
    Contact anonymised and transcript deleted.
  • Platform account

    Client sign-up and account users

    Purpose
    Providing access to the platform and running the contracted service.
    Period
    While the contract is active
    At the end
    After termination, access data is deleted; whatever tax law requires stays under 'Billing'.
  • Commercial proposals

    Proposals sent by the sales team

    Purpose
    Formalising and tracking the negotiation.
    Period
    5 years (under confirmation)
    At the end
    Contact anonymised.
  • Forms on client landing pages

    Pages published by clients using MAI LP PRO

    Purpose
    Delivering the contact to the client who published the page. MAI acts as processor here.
    Period
    Defined by the client acting as controller
    At the end
    We forward your request to the client in charge and confirm the forwarding to you.
  • Billing and invoices

    Checkout, subscription and tax documents

    Purpose
    Charging for the service and complying with tax law.
    Period
    5 years after the taxable event
    At the end
    Deleted after the statutory tax period.
  • Access logs

    Platform login

    Purpose
    Account security and incident investigation.
    Period
    6 months (Brazilian Internet Act, art. 15) (under confirmation)
    At the end
    Deleted after the statutory period.
  • Your privacy requests

    This Privacy Centre

    Purpose
    Proving we answered you on time and as the law requires.
    Period
    5 years after the reply (under confirmation)
    At the end
    Full anonymisation of the record.

Security in practice, not as an adjective

Every item below matches a mechanism that exists in the code. None of it is a badge.

  • Forms that save before they send

    No request depends on e-mail working. The record is written first; the notification comes after and can fail without taking anything with it.

  • Per-client isolation

    Every database query is filtered by client on the server, not in the browser session. One client cannot reach another's data, not even by changing an identifier in the URL.

  • Files in a private area

    CVs and attachments live outside the web-served folder and are stored under a random name. There is no public URL to guess.

  • Automatic deletion on schedule

    Data past its deadline is deleted by a routine that runs on its own, with an audit record — it does not depend on someone remembering.

  • Passwords never stored as text

    Passwords become bcrypt hashes with cost factor 12. Not even MAI's team can read yours.

  • Encrypted integration credentials

    Tokens for the accounts you connect (Google, Meta and others) are stored encrypted with AES-256 and never appear on screen or in logs.

  • Pseudonymised IP on public forms

    Public forms store a hash of the IP address, not the address itself. Enough to curb abuse without identifying who filled it in.

  • An audit trail of what was done

    Every step of a request becomes an event that cannot be edited: when you confirmed, what was deleted in each source, what was kept and why.

  • No sensitive data on public forms

    No public MAI form asks for sensitive data — not even to delete your data. Less is more, here too.

Perfect security does not exist. Consistent practice, auditing and fast response do — and that is what you will find here. Spotted something odd? Write to our Data Protection Officer.

Who helps us operate (and what each one sees)

  • Microsoft Azure

    Hosting and database

    The entire MAI platform and database run on this infrastructure.

    country under confirmation

  • Stripe

    International payments

    Billing data for clients outside Brazil. They process the card; MAI does not store card numbers.

    Estados Unidos

  • Asaas

    Payments in Brazil

    Payments in Brazilian reais (PIX and bank slip) for Brazilian clients.

    Brasil

  • Provedor de e-mail (SMTP)

    Transactional e-mail delivery

    Delivery of the messages MAI sends: confirmations, request replies and notices.

    country under confirmation

  • Provedores de modelos de IA

    Artificial intelligence

    Generating analyses and content from the client's business data. The active provider is configurable and visible to the client in the panel.

    country under confirmation

  • Google (Ads, Analytics, Search Console)

    Client-authorised integrations

    Campaign and website metrics the client authorises MAI to read. The connection is read-only and revocable in the panel.

    Estados Unidos

  • Meta (Facebook e Instagram Ads)

    Client-authorised integrations

    Campaign metrics the client authorises MAI to read.

    Estados Unidos

Data Protection Officer

It is the Data Protection Officer you write to about any data matter — including if you think we got something wrong.

contato@maipro.app.br

The officer's full name is pending MAI's formal appointment and will be published here.

How we handle your request

  1. 01

    You submit

    The form below. You get your reference number right away.

  2. 02

    You confirm your e-mail

    We send a link to the e-mail you gave us. That is what stops anyone from requesting deletion of your data in your name. The link is valid for 48 hours.

  3. 03

    We handle it

    If anything prevents immediate fulfilment, you get the reason in writing within the deadline. We have up to 15 days for the full answer.

  4. 04

    You get the evidence

    An e-mail with what was done, item by item, and the record stays in our audit trail.

Make a request about my data

We ask only for what we need to locate your data and reply. Nothing else: no ID number, no document, no justification.

Use the e-mail you used with MAI — that is where the confirmation goes.

Free of charge, no justification required. Read the policy

The awkward questions

Do I need to justify why I want my data deleted?

No. The law does not require it and we do not ask. The form has no mandatory justification field.

How much does it cost?

Nothing. By law and on principle — exercising a right cannot carry a price.

How long until you reply?

Confirmation that your request is in progress arrives as soon as you click the link in the e-mail. The full answer comes within 15 days — usually sooner.

Why do you ask me to confirm by e-mail?

Because without it anyone could request deletion of your data using your e-mail address. The confirmation proves whoever asked has access to that inbox — it is the minimum needed, and less invasive than asking for an ID document.

Do you really delete everything? What about backups?

In the live databases, yes: deletion happens in every source where your data sits, and you get the list of what was done. Whatever the law obliges us to keep (tax records, for instance) stays, and we tell you exactly what and why. As for backups, the purge cycle still depends on confirmation from our infrastructure — which is why we do not claim anything here we cannot prove.

I applied through the Careers page. How do I leave the talent pool?

Through this same form, choosing "Delete" or "Withdraw consent" and the relationship "I sent a CV". Your CV is removed from disk and your data anonymised — and even without a request, that happens on its own 12 months after submission.

I am a platform client. Does deleting my data close my account?

In practice, yes. Account data exists to perform the contract: while it is active, we cannot delete it without taking down the service you hired. The path is to terminate the contract and then request deletion — whatever tax law requires us to keep stays for the statutory period.

My data is with MAI because a company I use is your client. What now?

In that case MAI is a processor: we handle that data under the instruction of the client, who is the controller. You can contact them directly or send the request here — we forward it and confirm the forwarding to you. What we do not do is erase third-party data on our own: that would mean deciding in place of whoever is responsible.

How do I know the policy has changed?

Every version has a number and an effective date, and the history is public. For material changes, we notify by e-mail everyone with an active relationship with us.

Transparency is not a pretty page — it is a process that works. Any questions, our Data Protection Officer replies.