This is the English version of the Privacy Policy of DEBIT PROCESSAMENTO DE DADOS LTDA ("Debit"), which operates www.debit.com.br and its related applications and APIs. Leia esta política em português.
Since it was founded in 1999, Debit has been a pioneer in software for labour and monetary-restatement calculations, serving a growing demand for technology that makes judicial and extrajudicial calculations easier to perform. Debit has become a reference for lawyers, accountants, human-resources professionals and other professionals who rely on such calculations in their daily work.
Debit currently serves more than 500,000 users throughout Brazil. Its main differentiator is allowing calculations to be performed retroactively as far back as 1964, using practical tables and an extensive list of economic indices and market data.
In light of technological change and of the resulting need to protect personal data in the digital economy — and in particular because of the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, "LGPD", Law no. 13,709/2018) — we publish below the Privacy Policy describing the ways, the means and the reasons for which we process personal data.
To request deletion of your account and of your data, see our Data Deletion page (in Portuguese), which explains the self-service procedure and the alternative channels.
We process personal data of customers, employees, service providers, partners and suppliers. We may also process personal data of job applicants and of prospective customers and partners who contact us through our various channels — website, messaging applications, social networks, telephone and in person — as well as of prospects contacted by our relationship team.
We also process personal data of third parties who are not our customers: the individuals who appear in the documents and calculations submitted by those who hire Debit — parties to judicial and administrative proceedings, workers, social-security beneficiaries and their dependants. In that processing Debit acts as a processor: the professional or company that hired our services is the controller and decides what is submitted, for what purpose and on what legal basis. If you are one of those data subjects and wish to exercise your rights, please contact the professional handling your case first; if you prefer to contact us, we will forward the request to the controller and let you know that we have done so.
For each processing operation we collect and process only the personal data necessary to fulfill its purpose.
We generally process ordinary registration data, such as: full name, e-mail address, telephone number, postal address, occupation, marital status, job title, the company the person works for or represents, identity document, professional history and social-network profiles.
Each type of data has its own retention period, and the period is enforced by an automated routine — it does not depend on anyone remembering to delete anything.
| Data | Retention period | How it is deleted |
|---|---|---|
| Document submitted for extraction by artificial intelligence (social-security statements, court decisions, contracts, timesheets) and the data extracted from it | 48 hours from submission | Automated routine, hourly. The file and the extraction are deleted together |
| AFD/AEJ electronic time-clock files (deterministic parsing, no AI) | 30 days from submission | Automated routine. The period is longer because applying the file re-reads the original |
| Calculations saved in the account and the data entered into them | While the account is active, or until you delete them | Through the platform or the API, at any time |
| Calculation moved to the trash | 15 days in the trash | Automated routine. The database record and the file on disk are removed together |
| Calculations belonging to a closed account | 30 days from closure | Automated routine |
| Technical access and request logs (without the content of the documents) | 12 months | Automated routine |
| Support diagnostic logs, when enabled at your request to investigate a specific problem | 7 days | Automated routine. It is named, has a short enablement window and never stores documents, passwords or credentials |
| Backups | Up to 15 days after the source data is deleted | Automated rotation. Backups are not used to restore data that has already been deleted, except in disaster recovery — in which case the data is deleted again afterwards |
| Registration, billing and tax records | For the period required by Brazilian tax and civil law | Kept solely to comply with legal obligations and to defend claims |
The periods above do not apply where retention is required by law or by order of a competent authority.
Personal data is processed in a professional context and in accordance with Debit's core business activities.
Debit uses three groups of cookies:
We do not use session-recording tools (tools that record a visitor's screen, clicks and typing).
No personal data is shared with third parties for purposes other than the original purpose, and no data is sold. The suppliers listed below process data on our behalf, solely to make the service possible, and are contractually bound to do so only for that purpose:
| Supplier | Purpose | Where it processes |
|---|---|---|
| Anthropic, PBC | Language model that reads documents submitted by the user and extracts calculation data from them | United States |
| Amazon Web Services, Inc. | Hosting of the platform, the API and the database | Brazil (São Paulo) and United States (Northern Virginia) |
| Cloudflare, Inc. | Page delivery and protection against attacks | Global network |
| Twilio SendGrid | Delivery of the platform's e-mail messages | United States |
| Google LLC | Corporate e-mail (the messages you send us) and website usage measurement | United States and other countries |
| Meta Platforms, Inc. | WhatsApp Business, when support is provided through that channel | United States and other countries |
| Payment institutions and billing issuers | Processing of subscription payments, bank slips and Pix transfers | Brazil |
| Slack Technologies | Internal communication of the support and sales teams | United States |
Debit may also share data with public authorities and with the Judiciary where required by law or by order of a competent authority.
Where Debit resells or operates the platform on behalf of a partner (white label), the partner has access only to the data of the accounts it serves.
Partly, yes. As the table above shows, some suppliers process data in the United States — in particular the extraction of data from documents by artificial intelligence. These international transfers are made on the basis of contractual data-protection clauses entered into by Debit with each supplier, under article 33, II of the LGPD, which ensure a level of protection compatible with Brazilian law. We follow the ANPD's rulemaking on the subject and will adjust these instruments whenever it so requires.
Documents submitted for extraction by artificial intelligence are processed under a commercial API agreement: they are not used to train models and are deleted by the supplier in accordance with the contracted policy.
These measures are reviewed over time, without reducing the overall level of protection, and follow the guidelines and recommendations of the ANPD — the Brazilian Data Protection Authority.
Some Debit services allow you, at your own choice, to connect your Google account — today for calendar (Google Calendar) and for files (Google Drive). The connection is always optional, always initiated by you, and can be disconnected at any time. This section applies to every Debit product and service that uses Google APIs, including those released in the future.
Only the minimum necessary to deliver the feature you asked for:
Debit always requests the narrowest scope capable of performing the function, and never broad scopes granting read access to your entire calendar or your entire Drive.
Exclusively to operate, for you, the feature you have enabled: creating, updating and cancelling in your calendar the appointments scheduled through the service; checking your availability in order to offer scheduling options; and writing and reading, in folders created by the application itself, the documents related to your use of the service. For no other purpose.
With no one. Data obtained through Google APIs is not sold, assigned, transferred or disclosed to third parties for any purpose unrelated to operating the feature for you, except with your express consent or to comply with a legal obligation or an order from a competent authority.
Data obtained through Google APIs — which Debit treats as sensitive data — is covered by the measures described in the previous section and, specifically, by the following:
Access credentials are kept only while the integration remains connected. When you disconnect it within the service — under Settings → Integrations → Disconnect —, Debit revokes the token with Google and deletes the credentials from its systems immediately. You may also revoke access at any time, directly with Google, at myaccount.google.com/permissions. Events created in your calendar and files written to your Drive belong to you and remain under your control, even after the integration has been disconnected.
Debit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Debit does not use or transfer such data for:
Data obtained through Google Workspace APIs is not used to develop, improve, or train non-personalized AI and/or ML models, neither by Debit nor by any third party, and is not sent to third-party language models.
The extraction of data from documents by artificial intelligence described in the earlier sections applies exclusively to files that you yourself upload to Debit's calculators and services, and never to content obtained from Google Calendar or Google Drive.
If a security incident occurs that may give rise to relevant risk or harm, we will notify those affected and the ANPD under article 48 of the LGPD. Where the incident involves data we process on behalf of a customer, we will notify that customer within 48 hours of becoming aware of it, with whatever is already known about the nature of the incident, the data involved and the measures taken.
Under article 41 of the LGPD, Debit's Data Protection Officer is Marcelo Rozgrin Marques, who can be reached at [email protected]. Data-subject requests, incident notifications and questions about this Policy should be addressed to him.
For further information or questions regarding privacy and personal-data protection, please contact us.
DEBIT PROCESSAMENTO DE DADOS LTDA
Brazilian company registry (CNPJ) no. 08.060.974/0001-72
São Paulo, SP, Brazil
Version 2.1 — last updated on 16 September 2026. Leia esta política em português.