Privacy Policy — Fabapp
Last updated: July 22, 2026
This Privacy Policy ("Policy") describes how FABAPP TECNOLOGIA S.A., CNPJ No. 04.013.941/0001-10, headquartered at Av. Paulista, 171, andar 4, Bela Vista, São Paulo/SP, CEP 01311-904 ("Fabapp", "we"), processes personal data within the scope of the Fabapp platform, the website, and related services (the "Platform"), in compliance with Lei nº 13.709/2018 (LGPD — Brazil's General Data Protection Law) and other applicable rules.
By using the Platform, you represent that you have read and understood this Policy. It is incorporated into the Terms of Use.
1. Roles: controller and processor
1.1. As controller, Fabapp processes personal data of its clients, users, and visitors (for example, registration, billing, use of the Platform).
1.2. As processor, Fabapp processes personal data of the end users of the applications that you create and publish on the Platform ("End Users"), on your behalf and instruction. In this case, you are the controller of that data and the processing complies with the Data Processing Addendum.
2. Data we process
a) Registration and account data: name/corporate name, email, telephone, credentials, position, company.
b) Billing data: data necessary for payment, processed by third-party payment processors (we do not store complete card data).
c) Usage and device data: IP address, identifiers, device/browser type, operating system, pages and features accessed, access logs and date/time, approximate location inferred from the IP.
d) Client Content: prompts, instructions, files, data, and other materials that you enter or generate on the Platform, including the data of your End Users (processed as a processor — see item 1.2).
e) Communications: support messages, emails, and interactions.
f) Third-party data and public sources: for example, when using social login or integrations that you authorize (e.g., Google Workspace), and B2B prospecting data (name, corporate email, position) from public sources or partners, where permitted.
3. Why we process and on what legal basis (LGPD, art. 7º and 11)
| Purpose | Legal basis |
|---|---|
| Create and maintain your account and provide the Platform | Performance of contract (art. 7º, V) |
| Process payments and prevent fraud | Performance of contract / legal obligation / legitimate interest |
| Support and communication with you | Performance of contract / legitimate interest |
| Information security and abuse prevention | Legitimate interest (art. 7º, IX) / legal obligation |
| Improve the Platform and develop/train AI models and technologies | Legitimate interest (art. 7º, IX), with safeguards, or consent where required |
| Comply with legal and regulatory obligations and authority orders | Legal obligation / regular exercise of rights |
| Marketing and prospecting | Consent or legitimate interest, with an opt-out option |
4. Use of data for AI improvement and training
4.1. To operate and improve the Platform and to develop, train, tune, and improve artificial intelligence models and other technologies, Fabapp may use data processed on the Platform, including Client Content and Input Data, in the manner provided by the license set out in the Terms of Use.
4.2. We adopt proportionate safeguards, such as access controls and, where applicable, aggregation, pseudonymization, or anonymization. Anonymized data ceases to be personal data for the purposes of the LGPD (art. 12).
4.3. Whenever the applicable legal basis is legitimate interest, you may exercise the right to object to the processing, as described in item 8, except in cases where the law authorizes the continuation of the processing.
5. Sharing and sub-processors
5.1. We do not sell your personal data. We may share it with:
- Processors/sub-processors that provide us with services (cloud hosting, payment processing, analytics, security, communication, support);
- Artificial intelligence providers that process prompts and content to generate the results (for example, language and image model providers contracted by Fabapp);
- Affiliates of the group;
- Authorities and third parties, to comply with a legal obligation, court order, exercise rights, or investigate fraud;
- Successors in a corporate reorganization or transfer of assets.
5.2. Processors handle data in accordance with our instructions and the applicable legal bases. A list of the main sub-processors may be made available upon request at privacy@fabapp.com.
6. International transfer
6.1. The Platform and its suppliers may process data in other countries. In such cases, we will adopt the safeguards required by the LGPD (art. 33 to 36), such as adequate contractual clauses, guarantees of a compatible level of protection, or another legal basis for transfer.
7. Retention and deletion
7.1. We retain data for as long as necessary for the purposes for which it was collected and for compliance with legal obligations, the exercise of rights in proceedings, and fraud prevention.
7.2. Once the account is terminated, the data will be deleted or anonymized when no longer necessary, within up to 30 (thirty) days of the request, subject to the cases of mandatory retention (for example, retention of internet application access logs for the legal period of the Marco Civil da Internet — Brazilian Internet Civil Framework) and the maintenance of backup copies for a reasonable technical period.
8. Rights of the data subject (LGPD, art. 18)
You may, at any time, request: confirmation of the existence of processing; access to the data; correction; anonymization, blocking, or deletion of unnecessary data or data processed in noncompliance; portability; information about sharing; information about the possibility of not consenting and the consequences; revocation of consent; and objection to processing based on legitimate interest.
How to exercise: send a request to privacy@fabapp.com. We may request information to confirm your identity. We will respond within the legal deadlines. Some rights are not absolute and may be limited by other legal bases and regulatory obligations.
If you are an End User of an application created by a Fabapp client, your rights must, as a rule, be exercised before that client (controller); we may forward you to them.
9. Security
9.1. We adopt reasonable and compatible technical, administrative, and organizational measures to protect data against unauthorized access, loss, alteration, and destruction, including encryption and access management. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
9.2. In the event of a security incident that may entail a relevant risk, we will notify the data subjects and the Autoridade Nacional de Proteção de Dados (ANPD — Brazil's National Data Protection Authority) in accordance with the legislation.
10. Cookies
The use of cookies and similar technologies is described in the Cookie Notice.
11. Children and adolescents
The Platform is not intended for minors under 16 years of age. We do not intentionally collect data from children. If we identify improper processing, we will adopt the appropriate measures. If your application is directed at children/adolescents, you are responsible for observing their best interest and the applicable legal bases (LGPD, art. 14).
12. Data Protection Officer (DPO) and contact
Encarregado pelo Tratamento de Dados Pessoais (DPO — Data Protection Officer) — contact channel: privacy@fabapp.com.
FABAPP TECNOLOGIA S.A., Av. Paulista, 171, andar 4, Bela Vista, São Paulo/SP, CEP 01311-904.
13. Changes to this Policy
We may update this Policy. Material changes will be communicated by reasonable means. The "last updated" date at the top indicates the version in effect.