Privacy Policy

How LexPayroll processes personal data, under Brazil’s Lei nº 13.709/2018 (LGPD) and applicable law.

Version 1.0 · Effective 2026-08-16

1. Who processes your data

The controller of personal data processed on this platform is [DEFINE BEFORE PRODUCTION] (legal name), registered under company number [DEFINE BEFORE PRODUCTION], with offices at [DEFINE BEFORE PRODUCTION].

Data Protection Officer, as required by article 41 of the LGPD: [DEFINE BEFORE PRODUCTION]. Privacy contact: [DEFINE BEFORE PRODUCTION].

When your company subscribes to LexPayroll and records third-party data in it (employees, contractors, client companies), your company acts as the controller of that data and LexPayroll acts as processor, handling it only under your company’s instructions and the agreement in place.

2. What data is processed

The list below describes what the system actually collects and stores today. It is derived from the platform’s own source code.

CategoryWhat it covers, and why
User accountName, email, access role, account status, language preference and the organization the person belongs to. Required to authenticate and to decide what each person may see and do.
Access credentialPasswords are stored and verified by Supabase Auth, always in hashed form; the platform never has access to a password in clear text. When sign-in happens through Google or Microsoft, only the identity of the provider is recorded.
Demo requestFirst and last name, work email, company, job title, company type, employee band, free-text message and market of interest. Provided voluntarily through the website form.
Payroll compliance dataClient companies and their worksites, collective agreements and clauses, uploaded contracts and documents, findings, tasks and issued process reviews. This may contain personal data of third parties, entered by the client company.
AI assistant usageThe question asked, the answer produced, who asked it and the account it belongs to. Retained for history, answer auditing and contractual usage accounting.
Operational recordsAI spend per account, an audit trail of administrative actions, a notification delivery log and server error messages.
Public website accessThe event that occurred (page viewed, simulator opened, map state consulted), page path, language, referral origin and approximate location (country, region and city) taken from network edge headers. This log does NOT store IP addresses or any visitor identifier, and therefore cannot reconstruct an individual’s browsing.

The platform neither requests nor requires sensitive personal data to function. Documents uploaded by a client company may contain it; in that case the client company defines the purpose and the necessity.

3. Why data is processed, and on what legal basis

PurposeLegal basis (LGPD art. 7)
Creating and maintaining the account, authenticating access and delivering the contracted servicePerformance of a contract (item V).
Audit records, administrative action trails and query historyLegitimate interest (item IX), for information security and proof of compliance; legal or regulatory obligation (item II) where applicable.
Preventing fraud and abuse, limiting automated use and protecting the platformLegitimate interest (item IX).
Answering a demo request and the commercial contact that follows from itPre-contractual steps taken at the data subject’s request (item V).
Sending operational notices (credentials, material regulatory change, quota warnings)Performance of a contract (item V).
Measuring aggregate use of the public websiteLegitimate interest (item IX). The log carries no IP address and no visitor identifier, which reduces the impact on the individual to virtually none.

4. Cookies and similar technologies

LexPayroll uses strictly necessary and preference cookies only. There is no advertising cookie, no cross-site tracking and no third-party tag loaded on any page.

CookiePurpose and lifetime
sb-… (Supabase Auth)Keeps the authenticated session. Strictly necessary: without it there is no way to sign in. Lifetime follows the access token validity configured for the project.
lp-persistirStores your choice to stay signed in or to end the session when the browser closes. Preference.
lp-aba-vivaA session cookie recording that the window is still open. It is what makes “do not stay signed in” actually work. Expires when the browser closes.
lexpayroll_idiomaStores the interface language you chose. Preference.
lex_paisStores which edition of the site you chose (Brazil, United States or global) so the choice survives your next visit. Preference.

Because no non-essential cookie is used, no cookie consent banner is shown. Should that change, the consent mechanism will be in place before the technology is activated, not after.

The platform also uses browser local storage to remember screen preferences (for example, whether you have already seen the first-access guide). That information stays on your device and is not sent to our servers.

5. Who data is shared with

We do not sell personal data and we do not transfer it for a third party’s own purposes. Data is handled by infrastructure vendors acting as processors, solely to deliver the service:

ProcessorWhat it handles
SupabaseDatabase, authentication and file storage. This is where platform data resides.
VercelApplication hosting and execution. Handles request data in transit and keeps technical execution logs.
CloudflareContent delivery and domain protection. Sees request network metadata, including the originating IP address, which the platform does not store.
OpenAIProcesses text sent to the AI features (assistant, document analysis, process review and regulatory triage) in order to produce the answer.
ResendTransactional email delivery (credentials and regulatory notices). Handles the destination address and the message content.

Data may also be disclosed to comply with a legal obligation or an order from a competent authority. Beyond the processors above there is no further sharing: [DEFINE BEFORE PRODUCTION] (confirm before publishing whether any contracted processor is missing from this list).

6. International transfer

The platform’s infrastructure and the processors listed above are based or operate outside Brazil, primarily in the United States. Personal data processed here is therefore transferred internationally.

The transfer is made to perform the contract with the data subject or the contracting company (LGPD art. 33, VI) and is supported by the contractual clauses agreed with each processor. The specific safeguards in each agreement must be confirmed and listed before publication: [DEFINE BEFORE PRODUCTION].

7. How long data is kept

Data is kept while the account is active and for as long as the purposes described here require. The retention period for each category depends on the contract and on applicable legal obligations, and must be defined before publication rather than estimated here:

  • User account and credentials: [DEFINE BEFORE PRODUCTION]
  • Compliance data and documents uploaded by the client company: [DEFINE BEFORE PRODUCTION]
  • Assistant history and answer audit records: [DEFINE BEFORE PRODUCTION]
  • Audit and operational logs: [DEFINE BEFORE PRODUCTION]
  • Unconverted demo requests: [DEFINE BEFORE PRODUCTION]
  • Public website access log: kept in aggregate form with no visitor identifier, which makes it impossible to link to a person.

Once the period ends or the purpose is met, data is deleted or anonymised, except where retention is required by law (LGPD art. 16).

8. Security

  • All traffic is served over HTTPS, with HSTS and a content security policy applied to every response.
  • Access is authenticated by a signed token verified on every request, with server-side permission checks per role — never in the interface alone.
  • Each account’s data is isolated per account, both in the application and by access policies in the database itself.
  • Uploaded documents are held in private storage, reachable only through a single-use signed URL.
  • Passwords are never written to logs, and the database service key is never sent to the browser.

No measure removes risk entirely. In the event of a security incident posing relevant risk to data subjects, the controller will notify Brazil’s National Data Protection Authority and the affected individuals, as required by LGPD art. 48.

9. Automated decisions

The platform uses artificial intelligence to produce analyses, process checklists, regulatory summaries and answers with cited legal sources. That output supports the work of payroll and legal professionals: it does not decide about anyone on its own, does not determine rights and produces no direct legal effect on any individual.

The payroll, vacation and termination simulators are deterministic — they compute from written rules, with no AI involved. Under LGPD art. 20, a data subject may request review of a decision taken solely on the basis of automated processing; today the platform makes no such decision.

10. Your rights

Under LGPD art. 18 you may request, at any time:

  • confirmation that processing exists;
  • access to the data we hold about you;
  • correction of incomplete, inaccurate or outdated data;
  • anonymisation, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • portability to another provider, subject to trade and industrial secrets;
  • deletion of data processed on the basis of your consent;
  • information about who we share your data with;
  • information about the option not to give consent and the consequences of refusing;
  • withdrawal of consent, where processing relies on it;
  • objection to processing based on legitimate interest where the law is not being observed.

To exercise any of these rights, write to [DEFINE BEFORE PRODUCTION]. We will respond within the periods set by law. If your data was entered into the platform by the company you work for, we will forward the request to that company, which is the controller of that data.

11. Changes to this policy

This policy carries a version number, shown at the top of the page. Material changes — to purpose, legal basis, data category, processor or retention period — increase the version and are communicated to platform users; where the change requires it, renewed acceptance will be requested before use continues.

Editorial corrections that do not change the processing described do not increase the version, so that a request for renewed acceptance keeps meaning something.