BrazilRecords Desk

Privacy Policy

Last updated: August 2026

Who this policy covers

This policy applies to law firms and their authorized staff who submit requests through Brazil Records Desk. It does not apply to the end clients of those firms — the firm is responsible for informing its clients about any data sharing arrangements.

What we collect at initial request (Stage 1)

When you submit an intake request, we collect: the law firm name and U.S. state, the name and email address of the submitting attorney or paralegal, client initials (not full name), record type, Brazilian state, city, and registry if known, matter purpose, urgency, and whether apostille or translation coordination may be needed.

We record the timestamp and a one-way hash (SHA-256) of your IP address for audit purposes. We do not store your raw IP address.

No full client names, dates of birth, identification numbers, or sensitive personal data are collected at this stage.

What we collect after quote approval (Stage 2)

After your firm reviews and approves a quote, we may send a secure link (expiring, not publicly accessible) to collect additional information needed to locate and retrieve the requested record. This may include: full legal name, date of birth, place of birth, parents' names, Brazilian identification numbers (CPF, RG), and registry details.

This information is collected only when operationally required and only through the secure link we send. It is stored in our secure database and used solely to process the matter.

Document storage

Documents uploaded to or retrieved for a matter are stored in a private, access-controlled storage bucket. They are not publicly accessible. Download links are generated once the matter is marked ready and remain valid for 30 days from that date.

Technical & security logs

To protect the integrity of the service and investigate matters if a dispute or question arises, we record limited technical information each time a request is submitted or a document is downloaded: the IP address and browser/device identifier (user agent) used, together with a timestamp. This information is stored separately from the day-to-day matter records used to process your request and is not used for tracking, profiling, or marketing purposes.

The legal basis for this processing is our legitimate interest in maintaining the security of the service, preventing misuse, and being able to respond to questions about when and how a specific request or document was accessed (LGPD Art. 7, IX). We are not currently subject to the California Consumer Privacy Act (CCPA) or similar U.S. state privacy laws based on our size and operations, but we follow their transparency principles as a matter of good practice, since individuals whose records we handle may reside in any U.S. state.

These technical logs are retained for as long as reasonably needed for security and audit purposes and are not shared with third parties except where required by law.

How we use this information

Information is used solely to fulfill the requested document retrieval or coordination service and to communicate status updates by email. We do not sell, share, or rent your data to third parties. We do not use it for advertising.

Analytics

We use Plausible Analytics for aggregate, anonymous website traffic statistics. Plausible is cookie-free and does not collect personal data. No intake or matter data is sent to any analytics service.

Retention and document security

Matter records are retained for operational and legal purposes according to applicable law. Once documents are made available for download, the download window remains open for 30 days; after that period, the files are automatically and permanently deleted from our systems.

This time-limited document access model protects your privacy under LGPD (Brazil's Lei Geral de Proteção de Dados) and GDPR (EU's General Data Protection Regulation), ensuring sensitive personal and legal information is not unnecessarily retained. We do not store client documents indefinitely — they are either securely accessed within the limited window or permanently removed.

The 30-day document download window described above is fixed and automatically enforced. The retention period for matter records themselves (case metadata, not the documents) after a matter closes is still being finalized — we will not make promises here that do not reflect our actual practice. If you have questions about data held for a specific matter, contact us using the information below.

Your rights

You may request access to, correction of, or deletion of personal data we hold about your firm or its authorized contacts. To make a request, contact us at the address below. We will respond within a reasonable time. We may need to verify your identity before acting on a request.

Regarding client data collected for a specific matter: because we act on the instruction of the law firm, rights requests relating to client data should be directed to the law firm in the first instance.

Service providers

We use the following service providers in operating this service: Neon (database hosting), Cloudflare (R2 storage, Turnstile bot protection), Resend (transactional email), and Vercel (application hosting). Each operates under its own data processing terms.

Contact

Questions about this policy or requests regarding your data: andrefoppa@gmail.com