This document covers only privacy and data protection. The rules for using the Platform are in a separate document, the Terms of Use. This English text is a translation for convenience; in case of divergence, the Portuguese version prevails.
1. Scope
This policy describes how Acurys Aparelhos Auditivos Ltda ("Acurys"), company ID (CNPJ) 52.554.909/0001-95, handles personal data in the operation of the AcurysSystem platform ("Platform"), available at app.acurys.com.br. It applies to the subscribing companies ("Clients"), to Platform users and to the data subjects whose data is entered into it.
2. Roles
- Controller: the Client company, which decides on the processing of its own customers', patients' and contacts' data.
- Processor: Acurys, which processes that data on the Client's behalf and under its instructions.
- Data subject: the individual the data refers to.
For the Client company's own registration and billing data, and for its users' data, Acurys acts as controller.
3. Data processed
- Client company: legal name, company ID, address, contact and billing data.
- Platform users: name, e-mail, phone, access role, sign-in records and audit records of actions performed (author, date and time).
- Entered by the Client about data subjects: identification and contact data, service history, appointments, sales, tax documents and, depending on the Client's business, health data (for example, audiological and hearing-aid fitting information). The Client is responsible for the legal basis of that processing.
- Technical data: IP address, session identifiers and error logs, used for security, auditing and diagnostics.
- From the integrations authorized by the Client: see section 6.
4. Purposes and legal bases
| Purpose | Legal basis (LGPD) |
|---|---|
| Providing the Platform's features to the Client | Performance of a contract |
| Processing data subjects' data entered by the Client | Controller's instruction (legal basis defined by the Client) |
| Billing, invoicing and tax obligations | Legal obligation and performance of a contract |
| Security, auditing, fraud prevention and troubleshooting | Legitimate interest and legal obligation |
| Support and service communications | Performance of a contract |
We do not sell personal data and do not share it with third parties for advertising. We do not use Client data to train third-party artificial intelligence models.
5. Tenant isolation
Each Client has an isolated Environment. Isolation is enforced at every layer — database, access rules and server calls — so that one company cannot access another company's data. Integration credentials are kept server-side and are never exposed to the browser.
6. Data obtained from integrations authorized by the Client
Integrations operate on accounts owned by the Client itself, authorized through OAuth, and can be revoked at any time.
TikTok
The content module uses the TikTok for Developers APIs (Login Kit and Content Posting API). From the connected account, the Platform accesses and stores only: the OAuth token, the profile's identifier (open_id) and display name, and the id and status of the videos uploaded by the Platform itself.
We do not access, collect or store comments, messages, follower lists, audience data, other profiles' content or any TikTok end-user information. The data is used exclusively to upload, schedule and confirm the publication of the Client's own content, and is never sold, shared with third parties or used for advertising or model training.
The Client can revoke access at any time in the Platform's Connections screen — which deletes the stored token and immediately stops any scheduled posting — or in the TikTok app, under Settings and privacy > Security and permissions > Connected apps. TikTok's own processing is governed by the TikTok Privacy Policy.
YouTube
The module uses the YouTube API Services. From the connected channel, the Platform accesses and stores only the OAuth token, the channel id and name, and the id and status of the videos uploaded by the Platform itself. We do not access viewer data, comments or audience metrics. By using the module, the Client agrees to the YouTube Terms of Service; Google's processing is governed by the Google Privacy Policy. Access can be revoked in the Connections screen or at myaccount.google.com/permissions.
Meta (Instagram and Facebook)
From the connected account, the Platform accesses the OAuth token, the page or account id and name, and the messages exchanged between the Client and its own contacts, which appear in the service desk. We do not collect audience data or third-party profile content.
Sales channels and other services
In the integrations with Mercado Livre, TikTok Shop, Amazon, electronic invoicing providers and Google services, the Platform processes the data needed to run the Client's operation — orders, buyer delivery data, tax documents, campaign cost — always restricted to the Client's own accounts.
7. Sharing and sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database and file storage | United States |
| Supabase (PostgreSQL) | Analytical database and reporting | United States |
| Stripe | Subscription payment processing | United States |
We also share data when required by law or by a competent authority. International transfers arising from the use of these providers observe the safeguards required by the LGPD.
8. Security
Measures include tenant data isolation; role-based access control with least privilege; encryption in transit (HTTPS/TLS); credentials kept in a server-only vault; audit logging; and error monitoring. Details are in the Information Security Policy.
No system is immune to incidents. In the event of a relevant security incident involving personal data, we will notify the Client and the competent authority as required by the LGPD and take containment and corrective measures.
9. Retention and deletion
- Data is kept while the account is active.
- After termination, the Client may request an export of its data.
- Data is then deleted or anonymized, except what must be kept due to a legal obligation (for example, tax documents) or for the regular exercise of rights.
- Integration tokens are deleted as soon as the connection is removed.
- Audit and security logs are kept for as long as needed for their purpose.
10. Data subject rights
Data subjects may request confirmation of processing, access, correction, anonymization, portability, information about sharing and deletion of their data, and may withdraw consent where consent is the legal basis.
If your data was entered by a company that uses the Platform, contact that company first — it is the controller. As processor, Acurys assists the Client in fulfilling the request. You may also write to contato@acurys.com.br and we will forward it to the person in charge.
11. Cookies
The Platform uses only cookies and local storage strictly necessary for it to work — keeping the session authenticated, remembering screen preferences and protecting against automated abuse. We do not use advertising cookies in this application.
12. Children's data
The Platform is intended for professional use by companies. Data of children and adolescents that a Client may enter (for example, patients) is processed under that Client's responsibility, in the best interest of the data subject and on the legal basis required by the LGPD.
13. Changes to this policy
We may update this policy. The version in force is always published on this page with its effective date, and material changes are communicated to Clients.
14. Contact / Data Protection Officer
Requests and questions about personal data processing:
contato@acurys.com.br.
Acurys Aparelhos Auditivos Ltda · CNPJ 52.554.909/0001-95 · São Paulo, Brazil ·
phone (Brazil) 0800 486-2000.