Privacy Policy
Mai 30, 2026
Privacy Policy
Last updated: May 30, 2026.
This Privacy Policy explains how Cavfy ("Cavfy", "we", "us" or "our") collects, uses, stores, shares and protects your personal data when you access or use our website cavfy.com and related services (the "Platform"). We are committed to protecting your privacy and to processing your personal data in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018, "LGPD") and the European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
By using the Platform you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Platform.
Data Controller
The controller responsible for processing your personal data is Cavfy. For any privacy-related matter, including requests to exercise your rights, you may contact us at [email protected].
Data Protection Officer
The person responsible for handling data protection matters (the data protection officer, or "encarregado" under the LGPD) is Paulo Coutinho. You may contact the data protection officer for any question or request regarding your personal data at [email protected].
Personal Data We Collect
Data you provide directly. When you create an account or use the Platform, we may collect your name, email address, password (stored in encrypted form), profile picture, language preference and any other information you choose to add to your profile.
Learning and usage data. We collect information related to your activity on the Platform, such as courses and articles you access, lessons you complete, enrollment records, course progress, certificates issued and content you generate or submit.
Payment data. When you purchase a subscription, product or credits, payments are processed by our payment provider. We do not store your full credit card number. We retain transaction records such as plan, amount, status and date for billing, tax and accounting purposes.
Technical data. We automatically collect technical information such as your IP address, browser type, device information, operating system, access dates and times, and pages viewed. This data may be collected through cookies and similar technologies.
How We Use Your Data
We process your personal data to create and manage your account; to provide, maintain and improve the Platform and its features; to deliver courses, articles, lessons and certificates; to process payments, subscriptions and credits; to communicate with you about your account, transactions and support requests; to send service-related and, where permitted, marketing messages; to ensure security, prevent fraud and abuse; to produce aggregated statistics; and to comply with legal and regulatory obligations.
Legal Bases for Processing
We only process your personal data when we have a legal basis to do so. Under the LGPD and the GDPR, our legal bases include: the performance of a contract with you (for example, providing the Platform and the services you request); your consent (for example, for non-essential cookies and certain marketing communications); compliance with a legal or regulatory obligation; and our legitimate interests (for example, securing the Platform and improving our services), provided such interests are not overridden by your rights and freedoms.
Cookies and Similar Technologies
We use cookies and similar technologies to operate the Platform and to understand how it is used. Cookies are small files stored on your device.
Essential cookies. These are strictly necessary for the Platform to function, including authentication, security and remembering your cookie preferences. They cannot be disabled because the Platform would not work properly without them.
Analytics cookies. With your consent, we use analytics cookies, including Google Analytics, to measure audience and understand how visitors interact with the Platform. These cookies are only activated after you accept them.
When you first visit the Platform, a cookie banner allows you to accept or reject non-essential cookies. You can change your choices at any time through the cookie settings available on the Platform. Rejecting non-essential cookies will not affect access to essential features.
Sharing of Personal Data
We do not sell your personal data. We may share your personal data with third parties only when necessary and in the following situations: with service providers that operate on our behalf, such as payment processors, hosting providers, email delivery services and analytics providers; with authorities or third parties when required to comply with a legal obligation, court order or to protect our rights; and with successors in the event of a corporate reorganization, merger or acquisition, subject to this Privacy Policy.
The main categories of recipients with whom we may share personal data, acting as our processors or sub-processors, include: payment providers (such as Stripe) to process payments and subscriptions; analytics providers (such as Google Analytics) to measure the use of the Platform, where you have consented; hosting and infrastructure providers to operate and store the Platform; and email delivery providers to send transactional and service messages. Each of these providers processes personal data only as necessary to perform the services we contract from them.
Some of these providers, such as analytics and payment services, may process data outside your country of residence.
International Data Transfers
Your personal data may be transferred to and processed in countries other than your own, including countries that may have different data protection rules. When we transfer personal data internationally, we adopt appropriate safeguards required by the LGPD and the GDPR, such as standard contractual clauses or transfers to jurisdictions recognized as providing an adequate level of protection.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, to provide the Platform, and to comply with our legal, tax and regulatory obligations. When personal data is no longer required, we delete it or anonymize it. Transaction and billing records may be retained for the period required by applicable law.
Your Rights
Subject to applicable law, you have the right to: confirm whether we process your personal data and access it; request the correction of incomplete, inaccurate or outdated data; request anonymization, blocking or deletion of unnecessary or excessively processed data; request data portability; obtain information about entities with which we share your data; withdraw your consent at any time; object to processing carried out on the basis of legitimate interests; and request the deletion of personal data processed with your consent.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes established by the applicable law. You also have the right to lodge a complaint with the competent supervisory authority, such as the Brazilian National Data Protection Authority (ANPD) or your local European data protection authority.
Account Deletion
You may delete your account at any time directly from your profile settings on the Platform, or by contacting us at [email protected]. When you delete your account, your personal data is removed or anonymized, except for information we are required to retain to comply with legal, tax or regulatory obligations, or to exercise or defend legal claims. Deleting your account may result in the permanent loss of your enrollments, progress, certificates and other content associated with your account.
Marketing Communications
We may send you service-related messages that are necessary to operate your account and that you cannot opt out of while you maintain an account, such as transactional and security notices. Where we send marketing communications or newsletters, we do so only when permitted by law or based on your consent, and you may withdraw your consent or unsubscribe at any time using the link provided in the message or by contacting us at [email protected].
Automated Decisions and Artificial Intelligence
The Platform may offer features that use artificial intelligence to generate text or images at your request. These features assist you and do not make decisions that produce legal effects or similarly significant effects on you. We do not use your personal data to make solely automated decisions that significantly affect you. Should this ever change, we will inform you and you will have the right to request human review of the decision, as provided by the LGPD and the GDPR.
Personal Data Breaches
We maintain procedures to detect, investigate and respond to personal data breaches. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required by applicable law, the affected data subjects, within the timeframes set out by the LGPD and the GDPR.
Data Security
We adopt technical and organizational measures designed to protect your personal data against unauthorized access, loss, alteration, destruction or disclosure. These measures include encryption of passwords, access controls and secure connections. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children's Privacy
The Platform is not directed to children below the age of consent established by applicable law, and we do not knowingly collect personal data from them without proper parental or guardian authorization. If you believe a minor has provided us with personal data without such authorization, please contact us so we can take appropriate action.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you through the Platform. We encourage you to review this Privacy Policy periodically.
Contact
If you have any questions, requests or complaints regarding this Privacy Policy or the processing of your personal data, please contact us at [email protected].