Solution How it works Contact Access Platform
Legal

Privacy Policy

Smart Journey - Brazil, European Economic Area, and United States

1. Scope and commitment

Smart Journey is a behavioral intelligence platform operated by Potencialize Digital LTDA, located in São Paulo, Brazil. This Privacy Policy explains how personal data may be collected, used, stored, disclosed, protected, and deleted in connection with our websites, platform, products, and services.

Our practices are intended to address applicable requirements of Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), the European Union General Data Protection Regulation (GDPR) as applicable in the European Economic Area, and United States federal and state privacy laws that apply to a particular activity or individual. Rights and obligations vary by jurisdiction, relationship, product configuration, and the role performed by Potencialize Digital in a processing operation.

2. Our role in processing personal data

Potencialize Digital may act as a controller or business when it determines the purposes and principal means of processing, including account administration, commercial relationships, support, security, contracts, and its internal operations.

Potencialize Digital may act as a processor, operator, or service provider when Smart Journey processes personal data on behalf of a client and under that client's lawful instructions. In that context, the client generally determines the relevant purposes and configurations and is responsible for obligations assigned to it as controller or business.

If your request concerns data controlled by a Smart Journey client, we may direct the request to that client or assist the client as required by contract and applicable law.

3. Categories of information

3.1 Information provided directly

  • name, email address, telephone number, and professional or company information;
  • account, registration, contract, support, and service-administration information;
  • information submitted through forms, support channels, or communications.

3.2 Technical and operational information

  • usage events and interactions with platform functionality;
  • pages or digital contexts in which Smart Journey technology operates;
  • browser, device, operating-system, language, timezone, IP address, network information, and approximate location derived from network signals;
  • events relating to Digital Assistants and other configured functionality;
  • technical logs required for security, operation, reporting, and service continuity.

The exact information processed depends on the service, client configuration, and functionality used.

3.3 Sensitive and special-category data

Smart Journey is not designed for the collection of sensitive personal data or GDPR special-category data. Such data should not be submitted unless a specific operation has an appropriate legal basis, safeguards, and documented instructions.

4. Purposes of processing

Depending on the relationship and service, information may be processed to:

  • provide, operate, configure, maintain, and improve contracted services;
  • administer accounts, credentials, permissions, contracts, and client relationships;
  • provide Smart Journey functionality and generate reports or indicators;
  • provide support and operational or administrative communications;
  • protect systems, infrastructure, clients, users, and the public;
  • identify and prevent fraud, misuse, security incidents, and unlawful activity;
  • comply with law, regulatory obligations, and lawful government requests;
  • establish, exercise, or defend legal claims;
  • support service continuity and enforce applicable agreements.

Personal data will not be used for an incompatible purpose without the notice, legal basis, consent, or other measure required by applicable law.

5. Legal bases

5.1 Brazil

Where the LGPD applies, processing may rely on consent, performance of a contract or preliminary procedures, compliance with legal or regulatory obligations, legitimate interests subject to the required assessment and safeguards, regular exercise of rights, or another legal basis provided by the LGPD.

5.2 European Union

Where the GDPR applies, processing may rely on consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest where applicable, or legitimate interests that are not overridden by the individual's rights and freedoms.

5.3 United States

Where applicable United States privacy laws apply, we process personal data for disclosed business or commercial purposes, as a service provider or processor for clients, or as otherwise permitted by law. The applicable basis and required notices depend on the state, the relationship, and the processing activity.

6. Disclosure of information

Potencialize Digital does not sell or rent personal data under its responsibility for third parties' own advertising or commercial use.

Information may be disclosed when reasonably necessary to:

  • provide data and reports to the client that controls the relevant digital environment;
  • allow authorized agencies, consultants, or intermediaries to implement, administer, support, or analyze contracted services;
  • engage infrastructure, cloud, hosting, communication, support, security, and other necessary providers;
  • comply with law, legal process, court orders, and competent authorities;
  • protect rights, safety, systems, services, and legitimate interests;
  • support a corporate transaction subject to appropriate confidentiality and legal safeguards.

Processors, operators, service providers, and subprocessors are required to process personal data for authorized purposes and under applicable contractual confidentiality, security, and data-protection obligations.

7. United States privacy disclosures

Residents of states with applicable comprehensive privacy laws may have rights to know or access, correct, delete, or obtain a portable copy of personal data and to opt out of certain processing, including sale, targeted advertising, or profiling in furtherance of decisions producing legal or similarly significant effects, where those activities and rights are covered by applicable law.

We do not discriminate against an individual for exercising an applicable privacy right. Where an appeal right applies, instructions for appealing a decision will be provided with our response. Authorized-agent requests may require proof of authorization and verification of the individual's identity.

Smart Journey's processing on a client website is generally governed by that client's notices and choices when the client acts as the relevant business or controller. Requests concerning that processing should normally be directed to the client first.

7.1 California notice

During the preceding 12 months, depending on the relationship and configuration, we may have collected the following categories described by California law: identifiers; customer-record and account information; commercial or professional information; internet or other electronic-network activity; approximate geolocation; and communications or inferences associated with service operation. Sources include individuals, Smart Journey clients, authorized implementers, automatic interactions with configured technology, and service providers.

These categories are used for the purposes in Section 4 and may be disclosed for those purposes to the recipients in Section 6. Potencialize Digital does not sell personal information or share personal information for cross-context behavioral advertising under its responsibility, does not use or disclose sensitive personal information to infer characteristics, and does not offer financial incentives for personal information.

Our public website does not interpret a legacy browser "Do Not Track" setting as a verified privacy request because no uniform standard applies to that signal. Where a legally recognized opt-out preference signal applies to covered processing, it will be handled as required by applicable law.

8. European Economic Area privacy disclosures

Individuals whose processing is subject to the GDPR may have rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent. They may also lodge a complaint with the competent supervisory authority. Withdrawal of consent does not affect processing lawfully performed before withdrawal.

Where processing is based on legitimate interests, the relevant interests, necessity, proportionality, reasonable expectations, and safeguards must be considered. Where required, a data-protection impact assessment will be performed for processing likely to result in a high risk to individuals.

9. Brazilian privacy disclosures

Individuals covered by the LGPD may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or unlawful data, portability where applicable, information about disclosures, deletion of data processed on consent where legally available, information about consent choices, withdrawal of consent, and opposition in the circumstances established by law.

When Potencialize Digital acts as operator, requests concerning data controlled by a client may be forwarded to the relevant controller or the individual may be directed to the appropriate channel.

10. Exercising privacy rights

Requests may be submitted through the privacy channels in Section 18. We may request information reasonably necessary to verify identity, authority, jurisdiction, and the data concerned. Verification information will be used only to process and document the request and to prevent unauthorized disclosure or alteration.

We will respond within the period required by the law applicable to the verified request. Certain rights may be limited by legal exceptions, contractual roles, security requirements, the rights of others, or obligations to retain information. If a request is denied in whole or part, we will provide the explanation required by applicable law.

11. Retention and deletion

Personal data is retained only for as long as reasonably necessary for the purpose of processing, the applicable client relationship, legal or regulatory obligations, contract administration, security, accountability, or the establishment, exercise, or defense of claims.

When a purpose ends and no legal basis requires continued retention, data will be deleted, anonymized, or otherwise handled in a manner permitted by applicable law. Retention periods vary by data category and processing operation.

12. Security

Potencialize Digital uses technical and administrative measures intended to protect systems and personal data under its responsibility against unauthorized access, loss, alteration, destruction, improper disclosure, or incompatible processing. Measures may include encrypted communication, authentication, access controls, permission restrictions, environment segregation, technical monitoring, activity records, security-focused development practices, and infrastructure improvement.

No technological environment can be guaranteed to be completely secure. This does not remove our obligation to adopt appropriate prevention, response, and mitigation measures.

13. Security incidents

We assess security incidents involving personal data according to their nature, scope, affected information, and potential impact. When Potencialize Digital acts as controller, business, or equivalent responsible party, legally required notices will be provided to affected individuals and competent authorities within applicable periods.

When acting as processor, operator, or service provider, Potencialize Digital will notify the relevant client without undue delay as required by contract or applicable law and provide information reasonably necessary for that client to meet its obligations.

14. International transfers

Our infrastructure and providers may process information in countries other than the country where it was collected. Where a transfer is regulated, Potencialize Digital will use a mechanism recognized by applicable law, which may include an adequacy decision, approved contractual clauses, a contractual transfer mechanism, or another lawful safeguard.

For transfers subject to the GDPR, the mechanism may include European Commission Standard Contractual Clauses where appropriate. For transfers subject to the LGPD, the mechanism will follow the requirements and safeguards recognized by Brazilian law and applicable ANPD regulation.

15. Cookies and similar technologies

Smart Journey and related websites may use cookies and similar technologies to maintain sessions, preserve essential functionality, administer authentication, record events, evaluate service operation, support security, and provide contracted experiences.

Where consent or another specific choice mechanism is legally required, the relevant mechanism will be made available for the applicable processing. Browser controls may block certain technologies, but blocking technologies that are technically necessary may affect functionality.

16. Automated processing and Smart Journey

Smart Journey may use rules, events, and behavioral signals configured by clients to personalize content or trigger Digital Assistant functionality. Potencialize Digital does not design Smart Journey for decisions that produce legal or similarly significant effects without the additional governance, legal basis, notices, safeguards, and human review required by applicable law.

The information processed by each feature depends on the client's configuration. Clients are responsible for ensuring their chosen configurations, notices, instructions, and legal bases are appropriate for their use.

17. Children's privacy

Smart Journey's commercial services are not directed to children under 13 in the United States or to children below the minimum age established by applicable law in another jurisdiction. We do not knowingly request that children provide personal data directly through our business contact channels.

Clients may not use Smart Journey in environments directed to children unless Potencialize Digital has expressly authorized that use in writing and the client has established the legal basis, parental authorization, notices, configurations, and safeguards required by applicable law.

18. Privacy contact

Privacy questions and requests may be sent to:

If applicable law permits a complaint to a data-protection authority, you may contact the authority competent for your place of residence, work, or the alleged infringement.

19. Changes to this Policy

This Policy may be updated to reflect changes in our services, infrastructure, processing activities, or applicable law. The current version will be published on this page with its update date. Material changes will be communicated through appropriate channels where required by law.

20. Governing framework

This Policy is interpreted according to the law applicable to the relevant processing activity and individual. Nothing in this Policy limits non-waivable rights available under the LGPD, GDPR, applicable United States privacy laws, or another mandatory law.

POTENCIALIZE DIGITAL LTDA
São Paulo, State of São Paulo, Brazil
Last updated: September 2026