Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains how BriefArq collects, uses, shares, and protects personal data of architects using the platform and their end clients, in compliance with Brazil’s General Data Protection Law (Lei nº 13.709/2018 — LGPD) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Who we are (data controller)
[COMPANY LEGAL NAME], registered under CNPJ [CNPJ], headquartered at [ADDRESS] (“BriefArq”, “we”), is the controller of personal data processed through the BriefArq platform (website, web app, and client area).
2. What data we collect
Depending on how you use BriefArq, we collect:
- Architect account data: name, email, phone, photo, city, specialty, years of experience, professional license number, billing data (processed by Stripe — BriefArq never stores your card number).
- Briefing and project data: the end client’s answers to the briefing, uploaded reference images, pricing data, notes entered by the architect.
- End client data: name, email, phone, and other information provided when responding to a briefing through a unique link.
- Browsing data: pages visited, session duration, device and browser, collected only with consent via analytics cookies (see section 5).
3. How we use your data
- Create and operate your account and the client area;
- Generate AI-assisted fee suggestions and commercial proposals;
- Process subscription billing via Stripe;
- Send transactional notifications (email, optional WhatsApp) about project progress;
- Understand product usage and improve the experience (analytics, with consent);
- Comply with legal obligations and respond to data subject requests.
4. Legal basis for processing
We process data based on: contract performance (operating the service the architect subscribed to), consent (analytics cookies, data provided by the end client in the briefing), and legitimate interest (platform security, fraud prevention), always within LGPD limits.
5. Cookies and tracking technologies
We use essential cookies for the site to function and analytics cookies, the latter enabled only after your explicit consent in the cookie banner. You can revoke consent at any time via the “Cookie preferences” link in the footer.
| Cookie | Purpose | Type |
|---|---|---|
| briefarq-cookie-consent | Stores your cookie consent choice | Essential |
| user-currency | Sets the currency shown based on your region | Functional |
| _ga, _ga_* | Google Analytics — site usage statistics | Analytics (consent) |
| ph_* | PostHog — product usage statistics | Analytics (consent) |
6. Sharing with third parties
We share data with processors that help us deliver the service, under contract and limited to the necessary purpose:
- Stripe — payment processing;
- Resend — transactional emails;
- PostHog and Google (Analytics/Tag Manager) — product analytics, only with your consent;
- WhatsApp Business (Meta) — WhatsApp notifications, only if you opt in;
- AI providers (OpenAI, Google Gemini) — processing briefings and suggestions, without using your data to train third-party models beyond what’s necessary to deliver the service.
We do not sell personal data to third parties.
7. International data transfers
Some processors (PostHog, Google, AI providers) process data on servers outside Brazil, mostly in the United States. These transfers rely on contractual clauses and safeguards recognized by the LGPD (art. 33).
8. Retention and deletion
Active account data is kept while the subscription is active. After cancellation, data is retained for up to 90 days for possible reactivation, then fully anonymized — keeping only aggregated statistics with no personal identification. Audit logs are retained for 12 months.
9. Security
We adopt technical and organizational measures to protect your data, including encryption in transit (TLS 1.3+) and at rest for sensitive data, access controls, and incident monitoring.
10. Your rights as a data subject
Under the LGPD, you may request at any time:
- Confirmation that processing exists and access to your data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or non-compliant data;
- Portability of your data to another provider;
- Deletion of data processed based on your consent;
- Withdrawal of consent at any time;
- Objection to processing based on legitimate interest.
End clients can exercise these rights directly with the architect responsible for the project, via WhatsApp or email.
11. Minors
BriefArq is not directed at individuals under 18 and does not intentionally collect data from children or teenagers.
12. Changes to this policy
We may update this policy periodically. Material changes will be communicated by email or a notice on the platform.
13. Contact and Data Protection Officer
To exercise your rights or ask questions about this policy, contact our Data Protection Officer at [DPO EMAIL].