Security

Privacy Policy

Understand how Linkana collects, uses and protects your personal data, in line with LGPD.

Last updated:

Linkana (“Linkana”, “we”) is committed to protecting your privacy and personal data.

This Privacy Policy explains how we collect, use, share and protect your personal data when you:

  • visit our websites;
  • use our platform and services; or
  • interact with us through sales, marketing, support or other business operations.

It also explains your privacy rights and how you can exercise them.

1. Who we are and how to reach us

Linkana Tecnologia Ltda. is the controller of your personal data when you interact with our websites and platform, unless otherwise indicated.

Data Protection Officer (DPO)

You can contact our DPO with questions about this policy or to exercise your rights as a data subject.

2. What this policy covers

This Privacy Policy applies to the processing of personal data related to:

  • visitors to Linkana websites;
  • users of our platform and services;
  • representatives and contacts of customers, suppliers and partners;
  • any other individual whose personal data we process in the context of our activities.

We process personal data in compliance with applicable laws, including:

  • Brazilian General Data Protection Law — LGPD ;
  • other relevant privacy laws in the jurisdictions where we operate.

When we refer to “personal data”, we mean any information that identifies or can identify an individual.

3. What personal data we collect

The data we collect depends on how you interact with us.

3.1 Information you provide

We may collect:

  • Identification and contact data
    • full name;
    • business email;
    • company name, role and job title;
    • phone number;
    • other information you provide.
  • Account and profile data
    • login/email used to access the platform;
    • notification preferences and settings;
    • information exchanged with our support team.
  • Commercial relationship data
    • information about the relationship between your company and Linkana;
    • records of communications with our sales, customer success and support teams;
    • contractual and billing information (for customer and supplier contacts).

3.2 Information we collect automatically

When you visit our websites or use the platform, we automatically collect:

  • IP address and approximate location;
  • browser type and version;
  • device type and operating system;
  • pages visited, links and buttons clicked, date and time of access;
  • identifiers and events generated by analytics tools.

This information is collected through cookies and similar technologies. See section 6. Cookies and similar technologies.

3.3 Sensitive personal data

In limited situations, and only when necessary and permitted by law, we may collect and process sensitive personal data, such as:

  • data on racial or ethnic origin ;
  • data on sexual orientation ;
  • data on health or special needs/disability.

This data is normally collected only:

  • voluntarily, in diversity and inclusion initiatives; or
  • to provide accessibility and specific accommodations.

When we process sensitive data, we do so for specific and legitimate purposes and apply additional security and access controls, as required by LGPD and other applicable laws.

We do not use sensitive data for behavioral advertising or marketing profiling.

We use your personal data for the purposes below. The applicable legal basis may vary depending on the law and your relationship with Linkana.

  1. Provide and operate our services

     * create and manage user accounts;
     * provide access to the platform;
     * respond to support requests and technical questions.

    Legal basis: contract performance or preliminary procedures; legitimate interest.

  2. Manage our relationship with you or your company

     * communicate about the use of the platform and services;
     * manage billing, invoicing and contractual matters;
     * record the history of the commercial relationship.

    Legal basis: contract performance; compliance with legal obligation; legitimate interest.

  3. Improve our websites and services

     * understand how users navigate the websites and use the platform;
     * analyze performance and usability;
     * develop new features and services.

    Legal basis: legitimate interest; in some cases, consent (e.g., for certain cookies/analytics, when required by law).

  4. Communication and marketing

     * send news about Linkana, content, event invitations and feature information;
     * invite to webinars, communities and related initiatives.

    Legal basis: legitimate interest or consent, depending on applicable law. You can opt out of marketing communications at any time using the “unsubscribe” link in the email or by contacting us.

  5. Comply with legal and regulatory obligations

     * meet tax, accounting, regulatory and authority requirements;
     * respond to requests from public bodies, regulators or the Judiciary;
     * keep records required by law.

    Legal basis: compliance with legal or regulatory obligation.

  6. Ensure security, prevent fraud and protect rights

     * protect the platform and our infrastructure;
     * prevent fraud, abuse and security incidents;
     * exercise or defend rights in judicial, administrative or arbitration proceedings.

    Legal basis: legitimate interest; compliance with legal obligation; in some cases, protection of life or physical safety.

  7. Diversity, inclusion and accessibility initiatives (sensitive data)

     * analyze data (preferably aggregated/anonymized) to promote diversity and inclusion;
     * provide accessibility and necessary adjustments.

    Legal basis: specific and prominent consent, or other hypotheses allowed by LGPD for sensitive data.

When the legal basis is consent, you may revoke it at any time, without prejudice to the processing carried out until then. Revocation may affect the availability of certain features or services.

5. With whom we share your personal data

We may share your personal data with:

  • Service providers (processors) Companies that help us operate our business and provide services, for example:

    * cloud and infrastructure providers;
    * analytics, monitoring and security tools;
    * communication, helpdesk and support platforms;
    * financial, accounting and legal service providers.

These providers process personal data only according to our instructions and are subject to contractual obligations of confidentiality and data protection.

  • Business partners and customers In B2B contexts, we may share data with customers and partners when necessary for service provision, always in accordance with contracts and applicable law.

  • Public authorities and regulators When required by law, we may share data with authorities, regulators, courts and oversight bodies, including the ANPD in Brazil.

  • Corporate operations In the event of a merger, acquisition, corporate reorganization or sale of assets, personal data may be transferred as part of the transaction, under appropriate contractual protection.

6. Cookies and similar technologies

We use cookies and similar technologies on our websites and platform to:

  • ensure the correct and secure functioning of the site and platform (strictly necessary cookies);
  • measure and improve performance and user experience (analytics/performance cookies);
  • support marketing and advertising campaigns, when permitted (targeting/advertising cookies);
  • remember preferences and improve navigation (functional cookies).

When required by law (including LGPD):

  • we only use non-essential cookies (such as analytics and advertising) with your consent ;
  • a banner or preference center will allow you to accept or refuse cookie categories;
  • you can change your cookie preferences at any time, through the controls available on the site and/or in your browser settings.

Note: strictly necessary cookies are essential for the site and platform to function and cannot be disabled by our internal controls. You can still block them in the browser, but this may affect site functionality.

7. International data transfers

We may store and process your personal data in countries other than your own, for example, when we use cloud providers or other providers located abroad.

When we carry out international data transfers, we adopt measures to ensure an adequate level of protection, including:

  • compliance with LGPD rules on international data transfer;
  • entering into contracts with specific data protection clauses with our providers and partners.

8. How long we keep your data

We keep your personal data for as long as necessary to:

  • provide our services;
  • maintain the relationship with you or the company you represent;
  • comply with legal and regulatory obligations;
  • resolve disputes and exercise or defend rights in proceedings.

When personal data is no longer needed for these purposes, we will delete or anonymize it, unless there is a legal obligation or permission to keep it for an additional period.

9. How we protect your data

We adopt technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, alteration or destruction. These measures include, as applicable:

  • data encryption in transit and at rest;
  • access controls and the principle of least privilege;
  • network and application security controls;
  • logging, monitoring and incident detection;
  • secure development practices and vulnerability management;
  • security and privacy training and awareness initiatives.

If a security incident occurs that may cause relevant risk or harm to you, we will follow our incident response process and notify the competent authorities (including ANPD) and affected data subjects, when required by law.

10. Your rights as a data subject

Your rights may vary according to applicable law, but generally include:

10.1 Rights under LGPD (Brazil)

When LGPD applies to the processing of your data, you have, among others, the following rights (LGPD art. 18):

  • Confirmation of the existence of processing ;
  • Access to the personal data processed by Linkana;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion of unnecessary, excessive or non-compliant data;
  • Portability of data to another service or product provider, upon express request and observing ANPD rules;
  • Deletion of personal data processed based on consent, except in hypotheses of retention authorized by law;
  • Information about public and private entities with which we share data;
  • Information about the possibility of not providing consent and about the consequences of refusing;
  • Revocation of consent, at any time, upon express manifestation.

All these requests will be fulfilled free of charge and through an identity verification process, to protect you and your data.

11. How to exercise your rights

You can exercise your privacy rights or ask questions about this Privacy Policy by contacting us:

To speed up the response, please:

  • indicate which right(s) you wish to exercise;
  • provide enough information so we can verify your identity (or your authorization to act on behalf of another person);
  • detail, when possible, which data or interactions your request refers to.

We will respond within the timeframes established by LGPD. If we need more time, within what the law allows, we will inform you of the reason and the new estimated timeframe.

Personal data eventually collected to handle your request will be used only for this purpose and kept for the time necessary to demonstrate compliance with legal obligations.

If you are not satisfied with our response, you can also file a complaint with ANPD or the competent data protection authority in your jurisdiction.

12. Updates to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to our services;
  • changes in applicable laws;
  • improvements in our privacy and security practices.

When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you through the platform, email or other channels.

We recommend that you review this Privacy Policy periodically to stay informed about how we process and protect your personal data.