Legal

Privacy Policy

Version 2.0 · Last updated: June 7, 2026

This Privacy Policy complies with Brazil's General Personal Data Protection Law — LGPD (Law No. 13,709/2018) and other applicable regulations, including resolutions from Brazil's National Data Protection Authority (ANPD).

See how Zonix EM helps your company comply with the LGPD when managing Android devices: MDM and LGPD →

This is a translation of the original Portuguese-language document, provided for informational purposes. In the event of any discrepancy between this translation and the original Portuguese version, the Portuguese version shall prevail.

1. Identification and Introduction

Y. Ferreira de Lima da Silva Consultoria em TI LTDA ("Zonix EM", "we", "us", "our"), a private legal entity registered under CNPJ No. 68.312.733/0001-03, headquartered in São Paulo/SP, Brazil, is the Data Controller for the personal data processed within the Zonix EM MDM platform ("Platform").

This Privacy Policy describes how we collect, use, store, share, and protect the personal data of our customers, users, visitors, and other data subjects, in accordance with Brazil's LGPD and other applicable regulations.

By using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with its terms, we recommend that you do not use our services.

2. Definitions

For the purposes of this Policy, we adopt the following definitions, in line with the LGPD:

  • Personal data: information related to an identified or identifiable individual.
  • Sensitive personal data: data concerning racial or ethnic origin, religious belief, political opinion, union membership, health, sex life, or genetic or biometric data when linked to an individual.
  • Processing: any operation carried out with personal data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation, control, modification, communication, transfer, disclosure, or extraction.
  • Data subject: the individual to whom the personal data relates.
  • Controller: the individual or legal entity that makes decisions regarding the processing of personal data — in this case, Zonix EM.
  • Processor: the individual or legal entity that processes personal data on behalf of the Controller.
  • Data Protection Officer (DPO): the person appointed by the Controller to act as the communication channel between the Controller, data subjects, and the ANPD.
  • ANPD: Brazil's National Data Protection Authority, the federal government body responsible for overseeing personal data protection in Brazil.

3. Personal Data We Collect

We collect the following categories of personal data:

3.1 Registration data

Full name, email address, company/organization, contact phone number, and password (stored encrypted with bcrypt).

3.2 Usage and access data

IP address, browser user-agent, authentication logs, records of actions performed on the Platform, access date and time, and session data.

3.3 Billing data

Information needed to process payments (managed by Stripe). We do not store credit card data directly. This data is subject to Stripe's Privacy Policy.

3.4 Managed device data

Technical information about the Android devices enrolled under the customer's account: model, manufacturer, operating system version, device identifier (IMEI/serial number), compliance status, installed applications, and geographic (GPS) location when enabled by the administrator with the consent of the devices' end users.

3.5 Communication data

Content of messages sent through contact and support forms, including the history of interactions with our team.

3.6 Consent records

Record of acceptance of the Terms of Use and this Privacy Policy, including date, time, version of the document accepted, and user identifier.

3.7 Accessibility Service in the Companion App (Zonix EM - Agent)

The companion app installed on managed Android devices ("Zonix EM - Agent") may use the Android Accessibility Service to enable remote support: allowing an authorized operator from the customer organization to control the device (taps, gestures, and typing) during a support session. This capability is disabled by default and is only enabled after the device user's explicit acceptance, given through a two-step in-app flow — a non-dismissible disclosure followed by a separate confirmation — before Android's Accessibility Settings are opened. No taps, gestures, or screen content are transmitted to an operator outside of an active support session that you have authorized, and the permission can be revoked at any time in the device's Accessibility Settings, which immediately ends this capability.

The same Accessibility Service is also used, when the device is configured in kiosk mode by the organization's policy, to detect the kiosk-exit gesture and to keep the device restricted to the authorized app(s) — uses tied to the device-management configuration set by the customer organization, not to the individual remote-support consent described above.

4. Legal Bases for Processing

Zonix EM's processing of personal data is based on the following legal bases set out in Articles 7 and 11 of the LGPD:

  • Consent (Art. 7, I): for the processing of communication and marketing data, subject to the data subject's express consent.
  • Contract performance (Art. 7, V): for data necessary to provide the contracted services, such as registration, billing, and managed device data.
  • Compliance with a legal obligation (Art. 7, II): for data retention required by tax, labor, and regulatory law.
  • Legitimate interest (Art. 7, IX): for usage and access data, platform security, fraud prevention, and service improvement, provided the data subject's fundamental rights and interests do not prevail.
  • Credit protection (Art. 7, X): for billing and collection data.

5. Purposes of Processing

We use personal data for the following purposes:

  • Creating, authenticating, and managing user accounts;
  • Providing mobile device management (MDM) services;
  • Processing payments and managing subscriptions;
  • Sending transactional communications (registration confirmations, security alerts, invoices, device notifications);
  • Technical support and customer service;
  • Security monitoring, fraud prevention, and protecting the integrity of the Platform;
  • Generating aggregated usage statistics and continuously improving our services;
  • Complying with legal and regulatory obligations;
  • Recording and demonstrating consent as required by the LGPD;
  • Marketing communications and updates, when the data subject has given specific consent.

We do not use personal data for automated decision-making that produces legal effects or otherwise significantly affects data subjects, without human review.

6. Data Sharing

We do not sell, rent, or transfer personal data to third parties for our own commercial purposes. We may share data with the following processors, strictly in connection with the purposes described in this Policy:

  • Google LLC (Google Cloud / Android Management API): for managing and communicating with corporate Android devices. Subject to the Google Cloud Data Processing Addendum.
  • Stripe Inc.: for secure payment processing. Subject to the Stripe Data Processing Agreement.
  • Resend Inc.: for sending transactional emails. Subject to Resend's privacy policies.
  • Vercel Inc.: for hosting and delivering the web application. Access data may be processed on its servers.
  • Microsoft Corporation (Clarity): for usage analysis of the public site (heatmaps and session recordings). Loads from the first visit in cookie-less mode (see section 10); cross-visit tracking is only enabled after the visitor consents.

All processors are assessed for their security practices and are contractually required to process data exclusively according to our instructions.

We may also disclose personal data when required by law, court order, or a competent government authority, or to protect the rights, property, or safety of Zonix EM, its customers, and the public.

7. International Data Transfers

Some of our processors (Google, Stripe, Resend, Vercel, Microsoft) are companies headquartered in the United States, which involves an international transfer of personal data.

These transfers are carried out based on appropriate protection mechanisms, including contractual clauses equivalent to the European Union's Standard Contractual Clauses (SCCs) and/or certifications such as the Data Privacy Framework (DPF), ensuring a level of protection consistent with that required by the LGPD (Art. 33).

Information about the specific safeguards of each processor may be obtained by request to the DPO.

8. Data Retention and Deletion

We retain personal data for the following periods:

  • Active account data: for as long as the account is active and the contract is in force.
  • After account closure: data is retained for up to 90 days to allow for possible recovery, and is deleted or anonymized after that period.
  • Billing and tax records: retained for 5 years, as required by Brazilian tax law (CTN, Art. 174) and corporate law (Law 11,638/2007).
  • Access logs: retained for 6 months, as required by Art. 15 of the Marco Civil da Internet (Law 12,965/2014).
  • Consent records: retained for as long as necessary to demonstrate LGPD compliance, which may be up to 5 years after the end of the contractual relationship.

At the end of the applicable periods, data is securely deleted or anonymized in a way that cannot be reversed to identify the data subject.

9. Data Security

We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, destruction, or improper disclosure:

  • Encryption in transit via TLS 1.2+ for all communications;
  • Encryption at rest for sensitive data in the database;
  • Passwords stored with bcrypt hashing (cost ≥ 12);
  • Role-based access control (RBAC) following the principle of least privilege;
  • Data isolation per tenant (multi-tenancy with row-level isolation);
  • Continuous security monitoring and immutable audit logs;
  • Short-lived tokens for sensitive operations (impersonation, resets);
  • Periodic security reviews and vulnerability management.

In the event of a security incident that may affect personal data, we will notify the ANPD and affected data subjects within the timeframes and requirements set out in the LGPD (Art. 48).

10. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

  • Essential cookies: necessary for the Platform to function, such as session authentication and language preferences. These cannot be disabled.
  • Aggregate measurement (Vercel Analytics): used to understand how users interact with the Platform. Data is collected in aggregate form and does not individually identify the data subject.
  • Google Analytics 4 — anonymous mode: the GA4 script loads from your first visit, but in “Consent Mode” with analytics_storage denied by default: in this state Google only receives aggregate, cookieless signals that do not individually identify you.
  • Google Analytics 4 — cookies (after consent): measure visits, traffic sources and navigation across the site tied to a session identifier. The _ga cookie is only created after your consent in the cookie banner.
  • Microsoft Clarity — cookie-less mode: the script loads from the first visit, but with analytics_Storage denied by default (Clarity Consent API v2): in this “no-consent mode”, Clarity still records that page's session (heatmap, clicks, scrolling) without a cookie, using a new identifier on every page — it never links your behavior across different pages or visits. Form fields and sensitive content are masked in recordings from the start.
  • Microsoft Clarity — cookies (after consent): once you accept, Clarity starts using a persistent cookie and links browsing behavior across pages and visits, enabling more complete heatmaps and session recordings.

No tool uses a cookie or persistent identifier before you accept in the banner shown on your first visit — GA4 and Clarity, in anonymous/cookie-less mode, still collect page-usage data (aggregate statistics for GA4; that page's session recording, not linked to any other, for Clarity), but without an identifier that persists across visits. Refusing is as simple as accepting, and refusing does not limit any functionality of the site.

You can review or withdraw your decision at any time through the Cookie preferences link in the footer of every page. You can also configure your browser to refuse non-essential cookies.

Google Analytics and Microsoft Clarity are operated by companies headquartered in the United States, which involves an international transfer of data — see the international transfer section of this policy.

11. Data Subject Rights (LGPD — Art. 18)

Under Article 18 of the LGPD, you have the following rights regarding your personal data:

  • Confirmation and access (Art. 18, I and II): confirm that processing exists and access your personal data.
  • Correction (Art. 18, III): correct incomplete, inaccurate, or outdated data.
  • Anonymization, blocking, or deletion (Art. 18, IV): request the anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
  • Portability (Art. 18, V): receive your data in a structured, interoperable format, subject to trade and industrial secrets.
  • Deletion (Art. 18, VI): request deletion of data processed based on consent, except where retention is legally required.
  • Information about sharing (Art. 18, VII): obtain information about public and private entities with which we share data.
  • Information about the right to refuse consent (Art. 18, VIII): be informed of the possibility of not giving consent and the consequences of refusal.
  • Withdrawal of consent (Art. 18, IX): withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Review of automated decisions (Art. 20): request review of decisions made solely on the basis of automated processing.
  • Petition to the ANPD (Art. 18, §1): file a complaint with Brazil's National Data Protection Authority.

To exercise any of these rights, send your request to privacy@zonixem.com with the subject line "LGPD Rights — [your name]". We will respond within 15 business days, in line with the timeframe set by the ANPD.

We may request documentation to verify your identity before fulfilling the request, to ensure the protection of your data.

12. Data of Minors

The Zonix EM Platform is intended exclusively for legal entities and their adult representatives, for corporate use. We do not intentionally collect personal data from minors under 18 years of age.

If we become aware that data belonging to minors has been collected without the proper consent of their legal guardians, we will delete that information immediately. Please contact our DPO if you become aware of such a situation.

13. Data Protection Officer (DPO)

Under Article 41 of the LGPD, we have appointed a Data Protection Officer (DPO) to act as the communication channel between Zonix EM, data subjects, and the ANPD:

Data Protection Officer

Y. Ferreira de Lima da Silva Consultoria em TI LTDA

Email: privacy@zonixem.com

Address: São Paulo, SPBrasil

14. Changes to this Policy

We may update this Policy periodically to reflect changes in our practices, applicable law, or the services offered. We will notify data subjects of material changes by email and/or a prominent notice on the Platform, at least 30 days before they take effect.

The most recent version will always be available at zonixem.com/legal/privacy. The date of the last update is shown in the header of this document. Continued use of the Platform after the changes take effect constitutes acceptance of the new version.

15. Contact and Support Channel

For questions, requests, or complaints related to the processing of personal data:

We respond to all data subject requests within 15 business days, in accordance with ANPD guidelines.

Version 2.0 — June 7, 2026
Privacy Policy | Zonix EM | Zonix EM