This Policy explains how UDISOFTBOX CONSULTORIA E TECNOLOGIA LTDA, CNPJ 40.737.902/0001-20, headquartered at Rua Bocaiuva, nº 434, Sala 1, Morada da Colina, Uberlândia/MG, CEP 38.411-126, Brazil (“INGESTIA”), processes personal data when operating INGESTIA.IO.
1. INGESTIA's roles
INGESTIA acts:
- as controller of registration, account, billing, relationship, security and usage data of the Platform itself; and
- as processor, on behalf of the customer, of the personal data contained in the databases, spreadsheets, files and other content connected by the customer.
Requests concerning individuals whose data is in Customer Data should first be sent to the customer, who determines the purposes and essential means of the processing. INGESTIA will provide technical support in accordance with the DPA.
2. Data collected
We may process:
- name, e-mail, organization, profile, account identifiers and a hashed password kept by the authentication provider;
- plan, balance, invoices and transaction history;
- records of access, queries, costs, administrative actions, IP address, date, time and security events;
- support tickets, messages and communication preferences;
- source credentials, encrypted with AES-256-GCM; and
- Customer Data, which may include personal data of the subscriber's customers, employees and other third parties.
Full card data and Pix credentials are processed by Asaas and are not stored by INGESTIA.
3. Purposes and legal bases
We process data as controller in order to:
- create and manage accounts, authenticate users and perform the contract;
- provide support, process charges and comply with legal and regulatory obligations;
- measure consumption, prevent fraud, maintain audit trails and protect the Platform;
- send operational communications and, where permitted, commercial communications; and
- exercise rights in legal proceedings and improve the service with aggregated or anonymized information.
Depending on the case, the legal bases include performance of a contract, compliance with a legal or regulatory obligation, regular exercise of rights, legitimate interest and consent. Consent will be used only when it is the appropriate legal basis and may be withdrawn.
4. Data processed on behalf of the customer
INGESTIA processes Customer Data solely to carry out documented instructions and to provide ingestion, storage, transformation, querying, AI, API, dashboards, support, security and deletion. The customer is responsible for defining the legal bases, notices to data subjects, quality and minimization of such data.
The customer must not enter sensitive personal data, data of children or adolescents, biometric data, medical records or information subject to special confidentiality without prior contracting and assessment of the necessary controls.
5. Sharing
We share only what is necessary with the cloud, hosting, metadata database, authentication, payment, AI and e-mail providers listed in the Subprocessor List. We may also share data to comply with the law or a valid order, to protect rights, or in a corporate transaction, with appropriate safeguards.
We do not sell personal data.
6. Artificial intelligence
In text-to-SQL, the schema, metadata and query text may be sent to Anthropic to generate the query. The configuration must avoid sending row content, unless a future feature discloses and requires such processing. Users should not include unnecessary personal data in the prompt.
7. Location and international transfer
Customer Data stored in BigQuery and landing files in Google Cloud Storage use the São Paulo, Brazil region. Heavy processing in Cloud Run is also carried out in that region.
Account, configuration and usage data may be processed in the United States by Vercel, Neon, Anthropic, Resend and Google (social login via OAuth — "Sign in with Google"; authentication is our own, built with the Auth.js library, and the identity is stored at Neon). INGESTIA will adopt a valid international transfer mechanism and safeguards compatible with the Brazilian General Data Protection Law (LGPD) and with Resolution CD/ANPD No. 19/2024.
8. Retention and deletion
Account data is kept during the contractual relationship and afterwards for as long as necessary to comply with obligations, exercise rights, prevent fraud and meet legal deadlines.
After termination, Customer Data may be exported for 30 (thirty) days and will be deleted from active environments within 30 (thirty) days, except for backups subject to the technical overwrite cycle, legal retention requirements and valid instructions from the controller.
Records of access to internet applications will be preserved for the applicable legal period. Anonymized data, with no reasonable possibility of re-identification, may be kept.
9. Security
We adopt controls proportionate to the risks, including TLS, encryption of credentials, tenant segregation through datasets and IAM, validation of query scope, per-tenant cache, restricted administrative access, auditing, monitoring, BigQuery time-travel, versioning in GCS and backups by the PostgreSQL provider.
Despite these controls, no environment is infallible. Incidents will be handled in accordance with the response plan, the LGPD and the regulations of the ANPD (Brazilian National Data Protection Authority).
10. Data subject rights
Under the LGPD, data subjects may request, where applicable: confirmation and access; correction; anonymization, blocking or deletion; portability; information about sharing; review of consent; objection; and review of automated decisions.
To exercise rights over account data, write to privacidade@ingestia.io. We may request proof of identity and retain data necessary to comply with the law. For data entered by a customer, we will forward the request to the controller or advise the data subject to contact it.
11. Cookies and similar technologies
The Platform may use strictly necessary cookies for session, authentication, security and preferences. Analytics or advertising cookies will only be used in accordance with the applicable settings and notice. The current list should be available in the website's cookie manager.
12. Data Protection Officer and contact
Data Protection Officer (Encarregado): Douglas Miranda de Souza Filho
Privacy channel: privacidade@ingestia.io
Address: Rua Bocaiuva, nº 434, Sala 1, Morada da Colina, Uberlândia/MG, CEP 38.411-126
13. Updates
This Policy may be updated to reflect legal, technical or commercial changes. Material changes will be communicated through appropriate means.