This Policy explains how Autentiva, operated by M4B - MOBILE FOR BUSINESS, processes personal data, in compliance with Law No. 13,709/2018 (LGPD). It applies to the website, the platform and the public product validation page.
From the customer (company and its team): name, email and password (stored encrypted), company details and billing data. Payment data (card, etc.) is collected and processed directly by the payment gateway — we do not store the card number.
From platform usage: the products, batches and codes the customer registers, and access logs for the customer area.
From social login (Google/Meta), if you use it: when you sign in or sign up with Google or Meta, we receive from the provider your name, your email and confirmation that the email was verified — to create or link your account. We do not receive your password from the provider and we do not post anything on your behalf. An account created this way starts with no password; you can set one later via "Forgot password".
From scans (the consumer who scans the QR): when someone validates a product, we record the date/time, the browser (user-agent), the approximate location (city/country) and a pseudonymized fingerprint of the IP (hash) — we do not keep the IP address in clear text nor data that directly identifies the consumer. These records support the scan counter and the anti-cloning signal.
We do not sell personal data. We share data only with providers necessary to operate the service, under contract and a duty of confidentiality:
We keep data while the account is active and for as long as necessary for the purposes above and for legal obligations. After cancellation, data may be deleted or anonymized, except for records the law requires us to preserve. Scan records, pseudonymized by nature, have their technical data (browser agent and origin identifier) anonymized after about 12 months, keeping only aggregate counts for the anti-cloning service.
You may request: confirmation and access to your data, correction, anonymization or deletion, portability, information about sharing and withdrawal of consent. To exercise these rights, write to our data protection officer (DPO) — contact below.
If you have an account, you can also download your data and delete your account at any time under My account, in the dashboard.
We adopt technical and organizational measures such as HTTPS, encrypted passwords, pseudonymization of the scans' IP and role-based access control. No system is 100% immune, but we work to protect your data.
We may update this Policy. Relevant changes will be communicated through the platform's channels, with the updated date revised at the top.
For questions or to exercise your data subject rights, use our contact page (subject “Privacy / LGPD”).