Privacy Policy
Last updated: May 2026
1. Introduction
OODA Intelligence (“we”, “our”) is committed to protecting the privacy of its users. This Privacy Policy describes how we collect, use, store and protect your personal information.
2. Data We Collect
2.1 Data provided by the user
- Full name and corporate e-mail address
- Organization information (name, tax ID, industry)
- Authentication data (credentials, 2FA tokens)
2.2 Data collected automatically
Important: the Brazilian data protection authority (ANPD) treats IP address and User-Agent as personal data whenever they can identify an individual. We handle this data with the same care applied to all other personal data.
- IP address — stored hashed/anonymized after 30 days; kept raw only for security logs (brute force protection, fraud detection)
- User-Agent / device fingerprint — used to detect login anomalies (e.g. unknown device)
- Access and activity logs — endpoints called, timestamps, HTTP response codes
- Usage and interaction data — aggregated whenever possible (does not identify individual users)
- Essential cookies — session, CSRF, preferences; see the Cookie Policy
2.3 Data submitted through this site’s contact form
The contact form on oodaintel.com collects exclusively name, e-mail, organization, request type and message, plus the interface language and the address of the page the submission was made from. No other data is collected at that moment.
| Item | How we handle it |
|---|---|
| Specific purpose | Answering the request submitted (demo, plan information, partnership, press or other subject) and conducting the resulting commercial discussions |
| Legal basis | Preliminary procedures related to a contract, taken at the data subject’s own request (Art. 7, V of the LGPD) |
| Recipient | Google LLC — Google Apps Script and Google Sheets, on servers outside Brazil (see §6.1 and §6.4) |
| Retention | 24 months from submission; after that period the records are deleted (see §7) |
| What we do not do | We do not use this data for advertising, we do not enrich it with external sources, and we neither transfer nor sell it to third parties |
Filling in the form is voluntary: you can reach us by e-mail (contact@oodaintel.com) without providing this data through the form. Because the processing relies on Art. 7, V, it does not depend on consent — but you may, at any time, request deletion of your submission through the Data Protection Officer.
3. Purpose of Processing
We use your data to:
- Provide and maintain the platform services
- Authentication and access control
- Security auditing and compliance
- Service-related communications
- Continuous improvement of the platform
- Answer requests submitted through this site’s contact form (see §2.3)
4. Legal Basis
Personal data is processed on the following legal grounds of the LGPD (Law 13,709/2018):
- Performance of a contract (Art. 7, V): to deliver the contracted services.
- Pre-contractual procedures (Art. 7, V): to answer requests submitted through this site’s contact form, at the data subject’s own request. This is the legal basis for the data described in §2.3.
- Legitimate interest (Art. 7, IX): for platform improvement and security.
- Legal obligation (Art. 7, II): to comply with regulatory obligations.
- Consent (Art. 7, I): for non-essential cookies and technologies, and for any other purpose we disclose to you at the time of collection. Consent is always specific, optional and revocable at any time, without prejudice to the processing already carried out before revocation.
5. Storage and Security
- Sensitive data is encrypted with Fernet (AES-128-CBC).
- Multi-tenant access control with per-organization isolation.
- Audit logs covering more than 50 event types.
- Encrypted backups with configurable retention.
- Brute force protection and rate limiting.
6. Data Sharing
We do not sell, rent or share personal data with third parties. The only sharing that takes place is:
6.1 Processors (subcontractors)
Infrastructure providers that process data under our instructions (Art. 5, VII of the LGPD):
| Provider | Purpose | Location |
|---|---|---|
| AWS (Amazon Web Services) | Application hosting, RDS, S3 | São Paulo, Brazil (sa-east-1) |
| Google LLC (Apps Script + Sheets) | Receiving and storing this site’s contact form data (name, e-mail, organization, request type and message) and sending the internal notification | United States / global |
Sentry (optional, with sendDefaultPii=false) |
Error monitoring without PII | Own servers — can be disabled |
| CloudFront / Cloudflare (if enabled) | CDN and DDoS protection | Globally distributed |
All processors are bound by Standard Contractual Clauses (DPA) ensuring a level of protection equivalent to the LGPD.
6.2 Legally required sharing
- Compliance with a legal or regulatory obligation.
- Court order or request from a competent authority (with prior notice to the data subject, except where prohibited by law).
- Defence of rights in judicial, administrative or arbitration proceedings.
6.3 With consent
Any other sharing requires your express, free and informed consent, which may be revoked at any time.
6.4 International transfer
Data submitted through this site’s contact form is processed by Google LLC (Apps Script and Google Sheets), on servers outside Brazil — an international transfer supported by standard contractual clauses (Art. 33 of the LGPD). Should we enable any other provider outside Brazil, this page will be updated beforehand.
7. Data Retention
Retention policy by data type:
| Data | Default retention | Rationale |
|---|---|---|
| User account | For the term of the contract | Performance of a contract |
| This site’s contact form submissions | 24 months after submission | Pre-contractual procedures (Art. 7, V) |
| Raw IP in logs | 30 days (hashed afterwards) | Operational security |
| Audit logs | 6 to 24 months (varies by plan) | Compliance + investigation |
| Essential cookies | Session to 1 year | Site operation |
| Non-essential cookies | 12 months (renewable) | Consent |
| Data after account deletion | Deleted within 30 days | Data subject right |
| Backups | 90 days (rolling) | Disaster recovery |
| Data under legal obligation | As per applicable law (e.g. 5 years for e-invoices) | Legal obligation |
After the retention period, data is irreversibly deleted or anonymized.
8. Data Subject Rights
Under Art. 18 of the LGPD you have 9 guaranteed rights — among them confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about sharing, and revocation of consent.
To exercise them, see the Data Subject Rights page, which lists them in full along with the request form and applicable deadlines.
9. Cookies
We use cookies by category with active opt-in (non-essential cookies blocked until consent is given). See full details in the Cookie Policy and manage your preferences through the floating cookie button (bottom-left corner) or in the footer.
10. Data Protection Officer (DPO)
OODA Intelligence has formally appointed its Data Protection Officer, as required by Art. 41 of the LGPD:
- E-mail: dpo@oodaintel.com
- Dedicated page: Data Protection Officer
- Response time: up to 15 (fifteen) calendar days, as per Art. 19 §1 of the LGPD
11. Complaints to the ANPD
If you believe the LGPD has been breached, you may file a complaint with the Brazilian National Data Protection Authority through the ANPD citizen channel.
12. Updates
This policy may be updated to reflect legal or operational changes. When a relevant change occurs, we will notify you by e-mail and/or a banner on the site. Version: 2026.05.