TA
T A DigitalSolutions
PRIVACY AND TRANSPARENCY

Privacy Policy

How personal data is processed to operate, protect and improve the platform.

Updated August 12, 2026.

1. Controller and contact

T A DIGITAL SOLUTIONS, CNPJ 68.448.867/0001-48, determines processing related to the platform. Privacy requests may be initiated through the official support channel shown on the website; identity may be verified before fulfilling requests involving account data.

2. Data processed

We may process name, email, protected credentials, business data, subscription and payment information, projects, files, TAYA interactions, support, preferences, acceptance records, IP address, session, browser and device type.

3. Purposes and legal bases

Data is used to perform the contract, authenticate users, deliver content, process payments, provide support, prevent fraud, maintain security, comply with law and establish or exercise rights, as well as consent or assessed legitimate interests where applicable.

4. Artificial intelligence and content

Inputs, files and context may be sent to essential AI providers to create the requested deliverable. Processing is limited to the contracted operation and the security and quality measures described here and in applicable agreements. Do not submit secrets, passwords or unnecessary personal data.

5. IP, sessions and devices

Access records are used for authentication, abuse prevention, diagnostics and security. Operational data in the administration panel must be restricted and masked where possible. Public visitors may be represented by pseudonymous identifiers and approximate data.

6. Sharing and transfers

Data may be processed by essential infrastructure, storage, payment, email, support, analytics and AI operators. Some may be located abroad; contractual mechanisms and safeguards consistent with applicable law will be used where required.

7. Retention

Data is retained as needed to provide the service, protect accounts, comply with obligations, resolve disputes and exercise rights. Periods vary by category; data without an operational or legal need should be deleted, anonymized or aggregated.

8. Security and incidents

We use proportionate access controls, least privilege, revocable sessions, encryption in transit, audit records, backups and monitoring. Relevant incidents will be handled and communicated in accordance with applicable legal requirements.

9. Data-subject rights

Where applicable, data subjects may request confirmation, access, correction, sharing information, objection, portability, anonymization or deletion and may withdraw consent. Certain data may be retained to comply with law or exercise rights.

10. Children and minors

The platform is intended for people able to enter into a contract and is not designed for independent registration by children. Incompatible processing may lead to account restriction and a review for deletion or regularization.

11. Operational profiling

Risk, security, usage and recommendation indicators may be processed automatically. Material restrictions should not rely solely on an automated classification where the law provides a right to human review.

12. Updates

Material changes will be identified by a new version. Renewed acceptance may be requested when a change materially affects processing or relies on consent.