Legal

Privacy Policy

Last updated: August 14, 2026

This Policy explains how Autentiva, operated by M4B - MOBILE FOR BUSINESS, processes personal data, in compliance with Law No. 13,709/2018 (LGPD). It applies to the website, the platform and the public product validation page.

1. Data we collect

From the customer (company and its team): name, email and password (stored encrypted), company details and billing data. Payment data (card, etc.) is collected and processed directly by the payment gateway — we do not store the card number.

From platform usage: the products, batches and codes the customer registers, and access logs for the customer area.

From social login (Google/Meta), if you use it: when you sign in or sign up with Google or Meta, we receive from the provider your name, your email and confirmation that the email was verified — to create or link your account. We do not receive your password from the provider and we do not post anything on your behalf. An account created this way starts with no password; you can set one later via "Forgot password".

From scans (the consumer who scans the QR): when someone validates a product, we record the date/time, the browser (user-agent), the approximate location (city/country) and a pseudonymized fingerprint of the IP (hash) — we do not keep the IP address in clear text nor data that directly identifies the consumer. These records support the scan counter and the anti-cloning signal.

2. What we use it for and on what legal basis

  • Providing the service (creating an account, generating codes, validating products, charging the subscription) — basis: performance of a contract.
  • Security and anti-fraud (detecting cloning, limiting abuse, scan statistics) — basis: legitimate interest.
  • Complying with legal obligations (tax, accounting) — basis: legal obligation.
  • Communications about the account and the service — basis: performance of a contract / legitimate interest.

3. Sharing and subprocessors

We do not sell personal data. We share data only with providers necessary to operate the service, under contract and a duty of confidentiality:

  • Cloud hosting (infrastructure and database), which may keep servers outside Brazil (e.g., the United States) — the international transfer follows the LGPD's safeguards;
  • Sending transactional emails (confirmation, password reset, invitations);
  • Payment gateway (processing of subscriptions).

4. Cookies

We use only essential cookies (session and security/CSRF) for the login and the platform to work. We do not use third-party advertising tracking cookies.

5. Retention and deletion

We keep data while the account is active and for as long as necessary for the purposes above and for legal obligations. After cancellation, data may be deleted or anonymized, except for records the law requires us to preserve. Scan records, pseudonymized by nature, have their technical data (browser agent and origin identifier) anonymized after about 12 months, keeping only aggregate counts for the anti-cloning service.

6. Your rights (LGPD)

You may request: confirmation and access to your data, correction, anonymization or deletion, portability, information about sharing and withdrawal of consent. To exercise these rights, write to our data protection officer (DPO) — contact below.

If you have an account, you can also download your data and delete your account at any time under My account, in the dashboard.

7. Security

We adopt technical and organizational measures such as HTTPS, encrypted passwords, pseudonymization of the scans' IP and role-based access control. No system is 100% immune, but we work to protect your data.

8. Changes

We may update this Policy. Relevant changes will be communicated through the platform's channels, with the updated date revised at the top.

9. Data protection officer (DPO) and contact