Privacy and Data Protection Policy

This is the English version of the Privacy Policy of DEBIT PROCESSAMENTO DE DADOS LTDA ("Debit"), which operates www.debit.com.br and its related applications and APIs. Leia esta política em português.

Since it was founded in 1999, Debit has been a pioneer in software for labour and monetary-restatement calculations, serving a growing demand for technology that makes judicial and extrajudicial calculations easier to perform. Debit has become a reference for lawyers, accountants, human-resources professionals and other professionals who rely on such calculations in their daily work.

Debit currently serves more than 500,000 users throughout Brazil. Its main differentiator is allowing calculations to be performed retroactively as far back as 1964, using practical tables and an extensive list of economic indices and market data.

In light of technological change and of the resulting need to protect personal data in the digital economy — and in particular because of the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, "LGPD", Law no. 13,709/2018) — we publish below the Privacy Policy describing the ways, the means and the reasons for which we process personal data.

What rights do data subjects have?

  1. Confirmation that their personal data is being processed;
  2. Access to their personal data;
  3. Correction of incomplete, inaccurate or outdated data;
  4. Anonymization, blocking or deletion of data that is excessive, unnecessary or processed in breach of the LGPD;
  5. Portability of the data to another service or product provider;
  6. Deletion of personal data processed on the basis of consent, after that consent is withdrawn, unless another legal basis applies;
  7. Information about with whom their data has been shared;
  8. Information about the option not to consent and about the consequences of refusing;
  9. Withdrawal of consent;
  10. Objection to the context and/or the purpose of the processing, including where the processing relies on a legal basis other than consent;
  11. Petition to the data-processing agents and to the Brazilian Data Protection Authority (ANPD);
  12. Information about the criteria and procedures used in automated decisions;
  13. Review of decisions taken solely on the basis of automated processing that affect their interests;
  14. Assurance of ownership of their personal data and of their fundamental rights to freedom, intimacy and privacy.

To request deletion of your account and of your data, see our Data Deletion page (in Portuguese), which explains the self-service procedure and the alternative channels.

Whose personal data does Debit process?

We process personal data of customers, employees, service providers, partners and suppliers. We may also process personal data of job applicants and of prospective customers and partners who contact us through our various channels — website, messaging applications, social networks, telephone and in person — as well as of prospects contacted by our relationship team.

We also process personal data of third parties who are not our customers: the individuals who appear in the documents and calculations submitted by those who hire Debit — parties to judicial and administrative proceedings, workers, social-security beneficiaries and their dependants. In that processing Debit acts as a processor: the professional or company that hired our services is the controller and decides what is submitted, for what purpose and on what legal basis. If you are one of those data subjects and wish to exercise your rights, please contact the professional handling your case first; if you prefer to contact us, we will forward the request to the controller and let you know that we have done so.

What types of personal data does Debit process?

For each processing operation we collect and process only the personal data necessary to fulfill its purpose.

We generally process ordinary registration data, such as: full name, e-mail address, telephone number, postal address, occupation, marital status, job title, the company the person works for or represents, identity document, professional history and social-network profiles.

What are the purposes of the processing?

  • Customer service;
  • Technical support to customers;
  • Hiring of professionals and service providers;
  • Deletion of personal data;
  • Compliance with legal or regulatory obligations;
  • Performance of contractual obligations;
  • Management and administration of the company.

How long do we keep the data?

Each type of data has its own retention period, and the period is enforced by an automated routine — it does not depend on anyone remembering to delete anything.

DataRetention periodHow it is deleted
Document submitted for extraction by artificial intelligence (social-security statements, court decisions, contracts, timesheets) and the data extracted from it48 hours from submissionAutomated routine, hourly. The file and the extraction are deleted together
AFD/AEJ electronic time-clock files (deterministic parsing, no AI)30 days from submissionAutomated routine. The period is longer because applying the file re-reads the original
Calculations saved in the account and the data entered into themWhile the account is active, or until you delete themThrough the platform or the API, at any time
Calculation moved to the trash15 days in the trashAutomated routine. The database record and the file on disk are removed together
Calculations belonging to a closed account30 days from closureAutomated routine
Technical access and request logs (without the content of the documents)12 monthsAutomated routine
Support diagnostic logs, when enabled at your request to investigate a specific problem7 daysAutomated routine. It is named, has a short enablement window and never stores documents, passwords or credentials
BackupsUp to 15 days after the source data is deletedAutomated rotation. Backups are not used to restore data that has already been deleted, except in disaster recovery — in which case the data is deleted again afterwards
Registration, billing and tax recordsFor the period required by Brazilian tax and civil lawKept solely to comply with legal obligations and to defend claims

The periods above do not apply where retention is required by law or by order of a competent authority.

In what context is personal data processed?

Personal data is processed in a professional context and in accordance with Debit's core business activities.

What legal bases does Debit rely on?

  • Consent of the data subject;
  • Where necessary to perform a contract, or preliminary procedures related to a contract, to which the data subject is a party and at their request;
  • Where necessary for Debit to comply with a legal or regulatory obligation;
  • Where necessary for the regular exercise of rights in judicial, administrative or arbitral proceedings;
  • Where necessary to serve the legitimate interests of Debit or of a third party.

How does Debit use cookies?

Debit uses three groups of cookies:

  • Essential — session, authentication and security. The website does not work without them and they cannot be refused.
  • Usage measurement — Google Analytics 4, to understand which pages and features are used. The reports we consult are aggregated.
  • Source attribution — they record which link or campaign brought you to us, so that we know what works. This is the only marketing purpose of our cookies: we do not display advertising on the website and we do not sell, rent or transfer your browsing data to advertising networks.

We do not use session-recording tools (tools that record a visitor's screen, clicks and typing).

With whom is personal data shared?

No personal data is shared with third parties for purposes other than the original purpose, and no data is sold. The suppliers listed below process data on our behalf, solely to make the service possible, and are contractually bound to do so only for that purpose:

SupplierPurposeWhere it processes
Anthropic, PBCLanguage model that reads documents submitted by the user and extracts calculation data from themUnited States
Amazon Web Services, Inc.Hosting of the platform, the API and the databaseBrazil (São Paulo) and United States (Northern Virginia)
Cloudflare, Inc.Page delivery and protection against attacksGlobal network
Twilio SendGridDelivery of the platform's e-mail messagesUnited States
Google LLCCorporate e-mail (the messages you send us) and website usage measurementUnited States and other countries
Meta Platforms, Inc.WhatsApp Business, when support is provided through that channelUnited States and other countries
Payment institutions and billing issuersProcessing of subscription payments, bank slips and Pix transfersBrazil
Slack TechnologiesInternal communication of the support and sales teamsUnited States

Debit may also share data with public authorities and with the Judiciary where required by law or by order of a competent authority.

Where Debit resells or operates the platform on behalf of a partner (white label), the partner has access only to the data of the accounts it serves.

Does data leave Brazil?

Partly, yes. As the table above shows, some suppliers process data in the United States — in particular the extraction of data from documents by artificial intelligence. These international transfers are made on the basis of contractual data-protection clauses entered into by Debit with each supplier, under article 33, II of the LGPD, which ensure a level of protection compatible with Brazilian law. We follow the ANPD's rulemaking on the subject and will adjust these instruments whenever it so requires.

Documents submitted for extraction by artificial intelligence are processed under a commercial API agreement: they are not used to train models and are deleted by the supplier in accordance with the contracted policy.

What technical and administrative measures does Debit adopt to keep personal data secure?

  • Encryption in transit — all traffic between your browser and our servers uses HTTPS/TLS, with a certificate that also attests to the identity of the website.
  • Encryption at rest — data stored in our databases and backups is written with encryption at rest. Credentials for third-party services that you connect to your account (integration tokens) are encrypted with AES-256-GCM before being written, decrypted only at the moment of use, and never written to logs.
  • Access control — individual credentials, with the access level defined by the administrator and limited to what the role requires. API access is authenticated by a key issued to each customer.
  • Separation between customers — each account sees only its own data; access to a calculation is verified on every request.
  • Access and operation logging — we store the technical record of the call, not the content of the documents.
  • Automated deletion — the routines described in the retention section run on their own, hourly.
  • Restricted staff access — Debit personnel only access a customer's data to handle a support request from that customer or to deal with an incident, and such access is logged.
  • Maintenance — updating of dependencies and remediation of known vulnerabilities.
  • Physical documents — stored in locked cabinets or drawers, with restricted access.

These measures are reviewed over time, without reducing the overall level of protection, and follow the guidelines and recommendations of the ANPD — the Brazilian Data Protection Authority.

Data obtained through Google APIs

Some Debit services allow you, at your own choice, to connect your Google account — today for calendar (Google Calendar) and for files (Google Drive). The connection is always optional, always initiated by you, and can be disconnected at any time. This section applies to every Debit product and service that uses Google APIs, including those released in the future.

What Google user data Debit accesses

Only the minimum necessary to deliver the feature you asked for:

  • Account identification (openid and email scopes) — the identifier and the e-mail address of your Google account, so that we know which account is connected.
  • Calendar (calendar.events and calendar.freebusy scopes) — your calendar events and your free/busy periods.
  • Files (drive.file scope) — only the files and folders created by the application itself, or that you select and open within it. This scope does not give Debit access to the rest of your Google Drive.

Debit always requests the narrowest scope capable of performing the function, and never broad scopes granting read access to your entire calendar or your entire Drive.

How that data is used

Exclusively to operate, for you, the feature you have enabled: creating, updating and cancelling in your calendar the appointments scheduled through the service; checking your availability in order to offer scheduling options; and writing and reading, in folders created by the application itself, the documents related to your use of the service. For no other purpose.

With whom that data is shared

With no one. Data obtained through Google APIs is not sold, assigned, transferred or disclosed to third parties for any purpose unrelated to operating the feature for you, except with your express consent or to comply with a legal obligation or an order from a competent authority.

How that data is protected

Data obtained through Google APIs — which Debit treats as sensitive data — is covered by the measures described in the previous section and, specifically, by the following:

  • Encryption in transit — all communication with the Google APIs and with our servers uses HTTPS/TLS.
  • Encryption at rest — the credentials granting access to your Google account (OAuth tokens) are encrypted with AES-256-GCM before being written and are decrypted only at the moment of use. They never appear in logs, on screens or in reports.
  • Access control and isolation — individual credentials, least privilege, and separation by account: each account accesses only its own data, verified on every request.
  • Operation logging — we store the technical record of the call, not the content of your events or files.
  • Restricted staff access — Debit personnel only access this data to handle a support request from you or to deal with a security incident, and such access is logged.

How long it is kept and how you delete it

Access credentials are kept only while the integration remains connected. When you disconnect it within the service — under Settings → Integrations → Disconnect —, Debit revokes the token with Google and deletes the credentials from its systems immediately. You may also revoke access at any time, directly with Google, at myaccount.google.com/permissions. Events created in your calendar and files written to your Drive belong to you and remain under your control, even after the integration has been disconnected.

Limited Use

Debit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Debit does not use or transfer such data for:

  • targeted advertising, personalized advertising or retargeted advertising;
  • sale or assignment to data brokers, information resellers or aggregators;
  • credit assessment, risk analysis or lending decisions.

Artificial intelligence and machine learning

Data obtained through Google Workspace APIs is not used to develop, improve, or train non-personalized AI and/or ML models, neither by Debit nor by any third party, and is not sent to third-party language models.

The extraction of data from documents by artificial intelligence described in the earlier sections applies exclusively to files that you yourself upload to Debit's calculators and services, and never to content obtained from Google Calendar or Google Drive.

What if there is a security incident?

If a security incident occurs that may give rise to relevant risk or harm, we will notify those affected and the ANPD under article 48 of the LGPD. Where the incident involves data we process on behalf of a customer, we will notify that customer within 48 hours of becoming aware of it, with whatever is already known about the nature of the incident, the data involved and the measures taken.

Who is the Data Protection Officer?

Under article 41 of the LGPD, Debit's Data Protection Officer is Marcelo Rozgrin Marques, who can be reached at [email protected]. Data-subject requests, incident notifications and questions about this Policy should be addressed to him.

For further information or questions regarding privacy and personal-data protection, please contact us.

DEBIT PROCESSAMENTO DE DADOS LTDA

Brazilian company registry (CNPJ) no. 08.060.974/0001-72

São Paulo, SP, Brazil

Version 2.1 — last updated on 16 September 2026. Leia esta política em português.