Logo BriefArq
Subscribe now

Privacy Policy

Last updated: August 4, 2026

This Privacy Policy explains how BriefArq collects, uses, shares, and protects personal data of architects using the platform and their end clients, in compliance with Brazil’s General Data Protection Law (Lei nº 13.709/2018 — LGPD) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Who we are (data controller)

[COMPANY LEGAL NAME], registered under CNPJ [CNPJ], headquartered at [ADDRESS] (“BriefArq”, “we”), is the controller of personal data processed through the BriefArq platform (website, web app, and client area).

2. What data we collect

Depending on how you use BriefArq, we collect:

  • Architect account data: name, email, phone, photo, city, specialty, years of experience, professional license number, billing data (processed by Stripe — BriefArq never stores your card number).
  • Briefing and project data: the end client’s answers to the briefing, uploaded reference images, pricing data, notes entered by the architect.
  • End client data: name, email, phone, and other information provided when responding to a briefing through a unique link.
  • Browsing data: pages visited, session duration, device and browser, collected only with consent via analytics cookies (see section 5).

3. How we use your data

  • Create and operate your account and the client area;
  • Generate AI-assisted fee suggestions and commercial proposals;
  • Process subscription billing via Stripe;
  • Send transactional notifications (email, optional WhatsApp) about project progress;
  • Understand product usage and improve the experience (analytics, with consent);
  • Comply with legal obligations and respond to data subject requests.

4. Legal basis for processing

We process data based on: contract performance (operating the service the architect subscribed to), consent (analytics cookies, data provided by the end client in the briefing), and legitimate interest (platform security, fraud prevention), always within LGPD limits.

5. Cookies and tracking technologies

We use essential cookies for the site to function and analytics cookies, the latter enabled only after your explicit consent in the cookie banner. You can revoke consent at any time via the “Cookie preferences” link in the footer.

CookiePurposeType
briefarq-cookie-consentStores your cookie consent choiceEssential
user-currencySets the currency shown based on your regionFunctional
_ga, _ga_*Google Analytics — site usage statisticsAnalytics (consent)
ph_*PostHog — product usage statisticsAnalytics (consent)

6. Sharing with third parties

We share data with processors that help us deliver the service, under contract and limited to the necessary purpose:

  • Stripe — payment processing;
  • Resend — transactional emails;
  • PostHog and Google (Analytics/Tag Manager) — product analytics, only with your consent;
  • WhatsApp Business (Meta) — WhatsApp notifications, only if you opt in;
  • AI providers (OpenAI, Google Gemini) — processing briefings and suggestions, without using your data to train third-party models beyond what’s necessary to deliver the service.

We do not sell personal data to third parties.

7. International data transfers

Some processors (PostHog, Google, AI providers) process data on servers outside Brazil, mostly in the United States. These transfers rely on contractual clauses and safeguards recognized by the LGPD (art. 33).

8. Retention and deletion

Active account data is kept while the subscription is active. After cancellation, data is retained for up to 90 days for possible reactivation, then fully anonymized — keeping only aggregated statistics with no personal identification. Audit logs are retained for 12 months.

9. Security

We adopt technical and organizational measures to protect your data, including encryption in transit (TLS 1.3+) and at rest for sensitive data, access controls, and incident monitoring.

10. Your rights as a data subject

Under the LGPD, you may request at any time:

  • Confirmation that processing exists and access to your data;
  • Correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion of unnecessary or non-compliant data;
  • Portability of your data to another provider;
  • Deletion of data processed based on your consent;
  • Withdrawal of consent at any time;
  • Objection to processing based on legitimate interest.

End clients can exercise these rights directly with the architect responsible for the project, via WhatsApp or email.

11. Minors

BriefArq is not directed at individuals under 18 and does not intentionally collect data from children or teenagers.

12. Changes to this policy

We may update this policy periodically. Material changes will be communicated by email or a notice on the platform.

13. Contact and Data Protection Officer

To exercise your rights or ask questions about this policy, contact our Data Protection Officer at [DPO EMAIL].