This is a convenience translation. In case of divergence, the Portuguese (pt-BR) version prevails.
Policy
Privacy Policy
Last updated: August 28, 2026version 1.0
01Who we are and how to reach us
INDENE SECURITY LTDA, Brazilian corporate taxpayer number (CNPJ) (em registro), is the controller of the data processed in the contexts described in this policy, under art. 5, VI, of Brazilian Law No. 13,709/2018 (the General Personal Data Protection Law, LGPD).
For any question about this policy, or to exercise the rights described in the data subject rights section, the official channel is contato@indene.io, which reaches the Data Protection Officer (DPO).
02What this policy covers
Two distinct environments, with distinct processing:
- This website (indene.io): public, institutional pages, with no sign-up. Processing here is limited to browsing metrics and whatever you send us by e-mail.
- The Indene platform (the product): an authenticated environment contracted by client organizations, with the data categories described in the following sections.
03Data collected on this website
- Browsing metrics: we use OpenPanel, an analytics tool operated on our own infrastructure (analytics.uspery.cloud), cookie-free and with no cross-site tracking. It records navigation events (page viewed, language) under an anonymous identifier; we build no individual profile and sell no data to third parties.
- Infrastructure records: the site is served by Cloudflare, which keeps edge logs (IP address, user agent) for security and attack mitigation, plus aggregate performance metrics (Cloudflare Web Analytics, cookie-free).
- E-mail contact: if you write to us, we process your name, e-mail address and the content of the message in order to reply and, when requested, follow up commercially.
The site's typefaces are served from our own domain: no connection is made to third-party font servers while you browse.
04Data collected on the platform
In the product, we work with three categories of data:
- Registration and account data: name, corporate e-mail, access role (executive, audit, operations, administrator) and linked organization. Login uses a one-time access code sent by e-mail; no password is stored.
- Platform usage data: audit trail (who changed what, when), access records, language preference and active organization.
- Data entered by the client organization: control evidence, maturity assessments, business process data and risk quantification that the organization itself registers or imports. This set is treated as confidential to the client organization; we act as processor, not controller, over it (art. 5, VII, LGPD), except where it contains identifiable personal data of that organization's staff, in which case this policy also applies.
05Legal basis for processing
Each processing purpose rests on a legal basis under art. 7 of the LGPD:
- Performance of a contract: operating the account and the product contracted by the client organization.
- Compliance with a legal or regulatory obligation: retention of audit trail and evidence required by Central Bank of Brazil rules (e.g. CMN Resolution No. 4,893/2021 on cyber security policy for financial institutions).
- Legitimate interest: security of the site and the platform, fraud prevention, aggregate browsing metrics and product improvement, always subject to a proportionality assessment and without prejudice to the data subject's rights.
- Consent: non-essential cookies and marketing communications, if they ever exist (see the Cookie Policy).
06Data sharing
Data may be shared with:
- Infrastructure providers (hosting, database, transactional e-mail, self-hosted analytics), always under a data processing agreement and confidentiality clauses.
- Regulatory and judicial authorities, when required by law, court order or a supervisory body's request (e.g. the Central Bank of Brazil).
- The client organization itself, within the limits of each user's access role; never across distinct client organizations.
Isolation between organizations is enforced in the database (row-level security), not just in the application: no query, even under a code fault, crosses an organization's boundary.
07International transfer
The site is distributed through Cloudflare's global network, and the platform's infrastructure providers may operate servers outside Brazil. In those cases, transfers follow the mechanisms of art. 33 of the LGPD (standard contractual clauses, adequacy decision or the data subject's specific consent, as applicable). This section will be detailed with the definitive providers before commercial launch.
08Retention and deletion
Account data is kept for as long as the client organization's contract lasts. Audit trail and evidence have a minimum retention set by the regulation applicable to the client's sector (typically 5 years for financial institution records). Commercial contact messages are kept for as long as needed to handle them. Once the relationship ends and the legal retention period expires, data is deleted or irreversibly anonymized.
09Information security
Technical and organizational controls applied today:
- On this website: served exclusively over HTTPS with HSTS, a strict Content Security Policy (CSP) with no undeclared third-party scripts, and protection headers against clickjacking and content sniffing.
- On the platform: per-organization isolation enforced by database row-level security; an immutable audit trail for every change to a score, evidence item or control status; passwordless authentication (one-time code valid for 10 minutes); encryption in transit (TLS) on all communication.
No system is infallible; security incidents affecting personal data will be reported to the ANPD (Brazilian data protection authority) and to affected data subjects within the deadlines of art. 48 of the LGPD.
10Data subject rights
Under art. 18 of the LGPD, the data subject may request, at any time:
- Confirmation that processing exists, and access to the data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary data or data processed in violation of the law;
- Portability of the data to another service provider;
- Deletion of data processed on the basis of consent;
- Information on the public and private entities the data was shared with;
- Information on the option of refusing consent and its consequences;
- Withdrawal of consent, where that is the legal basis.
Requests are answered within 15 days, extendable once for an equal period with justification.
11Use by minors
The site and the product are intended for corporate (B2B) use by adults at client organizations. We do not knowingly collect data from anyone under 18.
12Changes to this policy
This policy may be updated to reflect legal, regulatory or operational changes. The date at the top of this page always indicates the version in force; material changes will be communicated by e-mail to client organization administrators.
13Legislation observed and target certifications
Items marked as targets are part of the product compliance roadmap and have not yet been obtained; no certification is claimed as completed in this version of the document.
Legislation observed (in force)
- LGPD (Lei 13.709/2018)
- Marco Civil da Internet (Lei 12.965/2014)
- CMN Resolução 4.893/2021
- BCB Resolução 85/2021
Target certifications (none obtained)
- ISO/IEC 27001
- ISO/IEC 27701
- SOC 2 Type II