1. Who we are and our role
In short: MAI handles data in three different roles. Knowing which one applies to you changes who answers your request.
The summary helps you understand; the full text is what counts.
MAI PRO is, at the same time, a software company and a marketing agency. That means we handle personal data in three distinct roles, and each one has different consequences for you.
Controller of our own website data. When you fill in a form on maipro.app.br, chat with MAIA, request the free digital presence diagnosis or send a CV, it is MAI that decides what that data is for. We answer for it.
Controller of data belonging to those who hire the platform. Sign-up, billing, product usage and the business history the platform accumulates from day one (what we internally call the Client's Digital Life).
Processor of third-party data. When a client connects their own accounts (Google Ads, Meta, stores, CRMs) or publishes a landing page with MAI LP PRO, MAI processes data belonging to THEIR clients and visitors, following THEIR instruction. In that case the controller is the client, not MAI — and section 8 explains how your request is forwarded.
2. What data we collect and where
In short: Each surface collects something specific, and all of them are listed in the public retention table on this page.
The summary helps you understand; the full text is what counts.
There is no invisible collection: everything we keep comes in through a form you filled in, an account you connected, or the running of the service itself (such as the login record).
Public website forms: name, e-mail, phone, company and whatever you wrote. MAIA chat: what was discussed, plus contact details when you provide them. Careers: CV, contact details and the evidence of your consent (when, from where and under which text). Platform sign-up: name, e-mail and password (stored only as a hash). Billing: tax details and payment history. Access records: date, time, IP address and browser of each login.
The table in #retencao lists each of these sources with fields, purpose, legal basis and deadline. It is generated from our internal data registry — if a source does not appear there, it should not exist.
3. What we use it for
In short: Each piece of data has a declared purpose. Using it for anything else requires telling you first.
The summary helps you understand; the full text is what counts.
Sales contact is used to reply to you and run the sales conversation. CVs are used to assess you in hiring processes. Sign-up and billing data are used to perform the contract. Access records are used for account security.
Inside the platform, a client's business data feeds analyses, diagnoses and recommendations — including through artificial intelligence models. That data is not used to train third-party generic models: it serves to produce the analysis the client hired.
We do not use one client's data to produce another client's analysis. Market comparisons come from segment aggregates, never from identifiable data of another company.
4. Legal bases
In short: Consent for CVs, contract performance for the platform, legitimate interest for sales contact, legal obligation for tax and access records.
The summary helps you understand; the full text is what counts.
Consent (art. 7, I): CVs and the talent pool. You can withdraw at any time, and the withdrawal deletes the data.
Contract performance (art. 7, V): sign-up, access and operation of the platform for clients.
Legitimate interest (art. 7, IX): replying to whoever reaches out to MAI through a form or the chat. You can object — and in practice the objection is the deletion request this page handles.
Legal obligation (art. 7, II): tax documents and application access records. These are the cases where we cannot delete even at your request, and section 8 explains how that is communicated.
5. Who we share with
In short: Only with processors needed for the service to work — all listed on this page, with what each one handles.
The summary helps you understand; the full text is what counts.
The full list of processors is in the section “Who helps us operate” on this page, with each one's category and what they process. It comes from a real review of the infrastructure, not from a generic template.
We share only what the purpose requires: the e-mail provider sees the message it needs to deliver; the payment processor sees what it needs to charge; the cloud provider hosts the application.
Some processors are outside Brazil. Those cases are covered in chapter 12.
6. Cookies and similar technologies
In short: Current state described honestly: there is still no cookie consent banner on the website.
The summary helps you understand; the full text is what counts.
[CONFIRMAR] The review carried out to write this policy found no cookie banner or consent management tool on MAI's website. The site uses browser local storage to keep your session when you log into the platform.
We would rather record the gap than describe a mechanism that does not exist. Implementing consent management is an open item and will be described here once it exists.
7. How long we keep it
In short: Every piece of data has a deadline. The public table on this page shows the deadline for each source and what happens at the end of it.
The summary helps you understand; the full text is what counts.
CVs: 12 months, deleted automatically. Sales contacts: period under confirmation. Billing: statutory tax period. Access records: the period set by the Brazilian Internet Act. Privacy requests: the period needed as evidence of the response.
The table in #retencao is the up-to-date reference — it is generated from the same registry our response process uses to locate and delete data, so there is no gap between what we say and what we do.
[CONFIRMAR — infrastructure] The purge cycle for backup copies still depends on confirmation and will be described here once it is defined.
8. Your rights and how to exercise them
In short: All rights under art. 18, through the form on this page, free of charge and with no justification needed.
The summary helps you understand; the full text is what counts.
The form at the end of this page covers confirmation, access, correction, anonymisation, deletion, withdrawal of consent, portability and information about sharing.
The process is: you submit, you confirm through your e-mail, and you receive the full answer within the deadline. The e-mail confirmation exists to stop someone from requesting deletion of your data in your name — and it is less invasive than requiring an identity document.
When part of the request cannot be fulfilled (art. 16), the answer states exactly what, under which legal basis and until when. No retention happens in silence.
If your data reached us through a MAI client, we forward your request to the controller and confirm the forwarding to you.
9. Information security
In short: The practices described in this policy are the ones that exist in the code — no decorative badges.
The summary helps you understand; the full text is what counts.
The “Security in practice” section on this page lists the verified mechanisms: per-client isolation enforced on the server, passwords as bcrypt hashes, integration credentials encrypted with AES-256, private files outside the public area, pseudonymised IPs on forms, automatic deletion on schedule and an audit trail.
Whatever is not there is not there because it has not been verified — and a security claim without a mechanism is exactly the kind of sentence this policy exists not to have.
Perfect security does not exist. If you spot something odd, write to the Data Protection Officer: it is the fastest channel and the report is taken seriously.
10. Candidate data
In short: CVs stay 12 months, disappear on their own after that, and leave sooner if you ask.
The summary helps you understand; the full text is what counts.
When you send a CV through the Careers page, we keep the file and your contact details for up to 12 months, solely for current and future hiring processes. The legal basis is your consent, recorded with date, origin and the text you accepted.
The CV file is never at a public address: it is stored outside the web-served area, under a random name, and is only accessed by people with permission in the internal system.
At the end of the period, the file is deleted and the data anonymised automatically, with an audit record. You can bring that forward at any time through the form on this page.
11. Data processed under client instruction
In short: If your data came through a company that uses MAI, they decide about it — and we forward your request.
The summary helps you understand; the full text is what counts.
MAI clients publish landing pages, connect media accounts and run sales funnels inside the platform. Data about their visitors and customers passes through our infrastructure, but the purpose is decided by them.
In those cases MAI is a processor. We do not delete, correct or export that data on our own: doing so would mean deciding about third-party data in place of whoever answers for it.
What we do is forward your request to the correct controller and confirm to you that the forwarding happened. If you prefer, you can also contact them directly.
12. International transfers
In short: Some processors are outside Brazil; the list with countries is on this page.
The summary helps you understand; the full text is what counts.
Some of the processors required for the service to work are based outside Brazil — international payment processing and AI model providers, for example.
[CONFIRMAR — legal] The list of countries and the transfer instrument applicable to each processor are under confirmation and will be published in the processors section of this page.
13. Data Protection Officer and contact
In short: The channel for any data matter — including telling us we got it wrong.
The summary helps you understand; the full text is what counts.
[CONFIRMAR — D1] The name of the Data Protection Officer and the dedicated e-mail address must be defined by MAI before publication, as required by art. 41, §1 of the Brazilian data protection law.
Until then, the contact channel for data matters is the address published in the Data Protection Officer section of this page.
14. Changes to this policy
In short: Every version has a number and a date. Material changes are notified by e-mail to anyone with an active relationship with us.
The summary helps you understand; the full text is what counts.
Each version of this policy has a number and an effective date, and the version in force is the only source the website forms use to record under which text you gave your consent.
When there is a material change, we notify by e-mail everyone with an active relationship with us. Wording changes that do not alter rights or purposes go into the history only.