Privacy Policy
Last updated: May 11, 2026
AegisPanel is committed to protecting your privacy. This policy describes how we collect, use and protect your personal data in compliance with the Brazilian General Data Protection Law (LGPD) — Law No. 13.709/2018.
1. Data We Collect
- Account data: name, email address and password (stored as a hash).
- Usage data: history of audits performed, daily quota consumption and access logs.
- Payment data: we do not store payment data. Transactions are processed securely via Stripe.
- Technical data: IP address, browser type and operating system, for security purposes.
2. How We Use Your Data
- Provide and operate the proxy auditing service;
- Manage your account, subscription and daily audit quota;
- Send service-related communications (confirmations, expiration alerts);
- Detect and prevent fraud and misuse of the platform;
- Improve the quality and features of the product.
3. Legal Basis for Processing
We process your data based on the following legal grounds set out in the LGPD:
- Performance of a contract: to provide the contracted service;
- Legitimate interest: for security, fraud prevention and service improvement;
- Compliance with a legal obligation: when required by law.
4. Data Sharing
We do not sell your personal data. We may share it only with:
- Clerk: authentication and account management (identity provider);
- Supabase: database (hosted in the US with adequacy to data-protection standards);
- Stripe: payment processing;
- PostHog: anonymous usage analytics for product improvement;
- Competent authorities: when required by law or court order.
5. Data Retention
We keep your data for as long as necessary to provide the service and comply with legal obligations. Accounts inactive for more than 12 months may have their data deleted, subject to prior notice by email.
6. Your Rights (LGPD)
As the data subject, you have the right to:
- Confirm whether your data is being processed;
- Access the data we hold about you;
- Correct incomplete, inaccurate or outdated data;
- Request the anonymization, blocking or deletion of your data;
- Request the portability of your data;
- Withdraw consent, where applicable.
7. Security
We adopt technical and organizational measures to protect your data, including encryption in transit (TLS), authentication managed by a dedicated identity provider, rate limiting on the APIs and row-level access control in the database.
8. Cookies
We use strictly necessary cookies for authentication and session, plus usage-analytics cookies (PostHog) to understand navigation and improve the product. We do not use advertising or tracking cookies for third-party marketing.
9. DPO Contact
To exercise your rights or get more information about the processing of your data, get in touch through our support channel. We will respond within 15 business days.