Privacy Policy
Last updated: May 26, 2026
Courtesy translation. In case of any discrepancy, the Brazilian Portuguese version prevails.
View the official version in Brazilian Portuguese
Effective: as of the date of publication.
1. Who we are and to whom this Policy applies
Gráfica Plus is a trade name operated by AGENCIA CLONE LTDA, registered with the CNPJ/MF (Brazilian National Registry of Legal Entities) under No. 44.695.258/0001-25 ("Gráfica Plus", "we", "our platform", "Controller").
Gráfica Plus is a software as a service (SaaS) that offers an online catalog, order management, CRM, WhatsApp automations, email marketing, paid traffic management and other tools for print shops, stationery stores and visual communication companies.
This Policy describes the processing of personal data of three distinct groups:
- Visitors to the institutional website and public pages (landing page, plans, FAQ, blog, open catalogs).
- Subscribing Customers (owners and operators of print shops) who subscribe to the platform and use it to manage their businesses.
- End Customers (buyers) who interact with the Subscribing Customers' stores — for example, when placing an order in a public catalog or chatting through the print shop's WhatsApp.
With respect to Visitors and Subscribing Customers, Gráfica Plus acts as Controller of the personal data. With respect to End Customers registered by the Subscribing Customer on the platform, Gráfica Plus acts as Processor, processing the data on behalf of the Subscribing Customer, who is the Controller of that data under the Brazilian General Data Protection Law (Law No. 13.709/2018 — LGPD).
2. Data Protection Officer (DPO)
In accordance with Article 41 of the LGPD, we maintain an exclusive channel for privacy matters, data subject requests and communication with the National Data Protection Authority (ANPD):
- Data Protection Officer email: privacidade@graficaplus.com.br
- Response time for requests: up to 15 (fifteen) business days from receipt.
3. Personal data we collect
3.1. Subscribing Customer data
Collected at registration, at subscription and during use of the platform:
- Identification: full name, email, phone/WhatsApp.
- Company data: trade name, address, CEP (postal code), number, CNPJ or CPF (Brazilian tax IDs) of the person in charge (when provided).
- Physical store location data: coordinates (latitude/longitude) and address, when filled in.
- Access credentials: email and password (stored only as an encrypted hash by the authentication provider).
- Billing and subscription data: contracted plan, cycle (monthly/annual), payment method (card or Pix), payment history, subscription status and external identifiers from payment gateways.
- Payment data processed by the gateways (Mercado Pago and Asaas): CPF/CNPJ, payer name, email and phone. Gráfica Plus does not store full card numbers, CVV or expiration dates. This data travels directly from the user's browser to the payment gateway, which operates under PCI-DSS certification.
- Brand settings: logo, cover image, primary/secondary colors, descriptions.
- Authentication logs: date and time of login and logout, IP address, browser agent (user agent), account security events.
- Onboarding answers and service categories chosen during initial setup.
3.2. End Customer data (processed on behalf of the Subscribing Customer)
When a Subscribing Customer uses the platform to sell to or interact with its customers, the following data is processed — provided directly by the End Customer in the public catalog, in conversations, or registered manually by the Subscribing Customer:
- Contacts (CRM): name, normalized phone number, email, CEP (postal code), address, number, tags, avatar photo.
- Orders: name, phone, email, CPF (when provided), shipping address, items, amounts, notes, tracking code and lead times.
- WhatsApp conversations: history of messages sent and received, media (images, audio, documents), times, read status, internal notes and indicators of AI-generated messages.
- Leads and prospects collected by the Subscribing Customer (extensions, imports, manual capture).
- Email marketing lists and recipients uploaded by the Subscribing Customer and their respective events (sends, opens, clicks, failures, bounces).
Responsibility for the legal basis, purpose and accuracy of this data lies with the Subscribing Customer, who acts as Controller. Gráfica Plus processes this data in accordance with operational instructions and this agreement.
3.3. Browsing and device data
- IP address, session identifiers and browser agent.
- Pages accessed and actions performed within the authenticated dashboard.
- Error diagnostics (stack traces, execution context) through a specialized technical failure monitoring service, with identification of the user and store involved.
3.4. Paid traffic campaign data
- Meta Ads (Facebook/Instagram) campaign identifiers linked to the store.
- Aggregate metrics: reach, impressions, clicks, spend, conversions and attributed revenue.
- Conversion events sent via the Meta Conversion API (CAPI), which may include pseudonymized data (email/phone hashes, IP, agent) for the sole purpose of measuring and optimizing the Subscribing Customer's own campaigns.
- CSV files imported from external campaigns.
3.5. Public review data (Google)
When the Subscribing Customer links its Google My Business profile, we collect public profile information (average rating, number of reviews, place identifier) for aggregate display in the dashboard.
3.6. Data we do not collect
We do not collect sensitive personal data (racial origin, religious belief, political opinion, health, sexual orientation, genetic or biometric data) for our own purposes. If such data is freely entered by the Subscribing Customer in free-text fields (notes, conversations), responsibility for the specific legal basis under Art. 11 of the LGPD lies entirely with the Subscribing Customer.
4. Purposes and legal bases (LGPD, Art. 7)
We process personal data based on the following legal grounds, according to the purpose:
| Purpose | Legal basis |
| Enabling registration, authentication and use of the contracted features | Performance of a contract (Art. 7, V) |
| Processing payments, managing subscriptions and issuing charges | Performance of a contract + legal/regulatory obligation (Art. 7, V and II) |
| Recording access logs for security and auditing | Compliance with a legal obligation (Art. 7, II) and legitimate interest (Art. 7, IX) |
| Prevention of fraud and abuse, and protection of the platform | Legitimate interest (Art. 7, IX) |
| Technical support, customer service and service improvement | Performance of a contract + legitimate interest |
| Sending operational communications (billing, failures, alerts, updates) | Performance of a contract |
| Sending marketing communications from Gráfica Plus to the Subscribing Customer | Consent (Art. 7, I), revocable at any time |
| Compliance with court orders and tax obligations | Legal obligation (Art. 7, II) and regular exercise of rights (Art. 7, VI) |
As for the processing of End Customer data entered by the Subscribing Customer on the platform, the applicable legal basis is defined by the Subscribing Customer itself, as Controller of that data.
5. Sharing of data with third parties
We do not sell personal data. We share data only with service providers necessary for the operation of the platform and under contract. The main processors and partners are:
| Partner | Purpose | Location |
| Cloud infrastructure provider | Database hosting, authentication and serverless functions | Servers in the configured region (may include international transfer) |
| Payment gateways licensed in Brazil | Payment processing (card, Pix), recurring subscriptions and, where applicable, subaccounts for payouts, under the PCI-DSS standard | Brazil |
| WhatsApp Cloud API (Meta) | Sending and receiving WhatsApp messages through Meta's official channels | United States and other countries |
| Meta advertising platform | Management, measurement and optimization of paid campaigns configured by the Subscribing Customer itself | United States and other countries |
| International language model (AI) provider | Generation of AI responses in conversations and suggestions in emails, when enabled by the Subscribing Customer | United States |
| Google public services (My Business/Maps) | Retrieval of public information from the Subscribing Customer's business profile (rating and review count) | United States and other countries |
| Technical failure monitoring service | Error capture and diagnostics for fixing | United States |
| CDN, DNS and attack protection provider | Content delivery, DDoS mitigation, edge security | Global network |
| Email providers integrated by the Subscribing Customer | Sending of marketing and transactional email (each Subscribing Customer connects its own provider) | Varies by provider |
The up-to-date list of the specific named sub-processors may be requested by the data subject at any time through the channel indicated in item 2, without prejudice to the role and purpose already described above.
We may also share data with public authorities upon legal order, in fraud investigations, or in the event of a merger, acquisition, corporate restructuring or sale of assets — in which case this Policy will continue to apply to the recipient.
6. International data transfer
Some of the partners listed above process data outside Brazil. When this occurs, we ensure that the transfer meets the requirements of Art. 33 of the LGPD, by means of:
- Specific contractual clauses with the international processor;
- The processor's internal policy adequate to Brazilian legislation;
- Where applicable, the data subject's specific consent to the transfer.
7. Email marketing and messages
The platform allows the Subscribing Customer to send emails and WhatsApp messages to its own contacts. Regarding this type of sending:
- The Subscribing Customer is solely responsible for obtaining and maintaining the appropriate legal basis (consent, legitimate interest or performance of a contract) for each recipient of its campaigns.
- All marketing email sent through the platform will include an unsubscribe mechanism (opt-out) easily accessible to the recipient.
- Gráfica Plus records technical sending events (delivery, open, click, failure, bounce) for the purpose of measurement and abuse prevention.
- Unauthorized mass communications (SPAM), the use of lists acquired from third parties without a legal basis, and sends in breach of the WhatsApp Business and Meta policies result in account suspension.
With respect to communications sent by Gráfica Plus itself to the Subscribing Customer, we send transactional messages (billing, security, updates to terms, operational alerts) based on the performance of the agreement, and promotional messages based on consent, always with an option to unsubscribe.
8. Cookies and similar technologies
We use cookies and the browser's local storage strictly to ensure the operation of and experience on the platform:
| Category | Examples | Purpose |
| Essential | Authentication session cookie; interface preference cookies | Keep the user signed in and preserve usage preferences |
| Local storage (localStorage/sessionStorage) | Dashboard filters, message drafts, dialog state | Restore usage context without a new request to the server |
| Error monitoring | Specialized technical diagnostics service | Capture of failures for fixing |
| Campaign measurement (only when enabled by the Subscribing Customer) | Conversions API of the advertising platform contracted by the Customer | Attribute conversions to the Subscribing Customer's own campaigns |
We do not use third-party behavioral advertising cookies for our own purposes. You can block cookies in your browser settings, but this may prevent parts of the authenticated platform from working.
9. Artificial Intelligence
When the Subscribing Customer enables AI assistants in conversations or assisted email generation, the content of the message and the relevant context (configured AI profile, store knowledge base, previous messages in the same conversation) are sent to an international language model (LLM) provider contracted by Gráfica Plus, solely to produce the requested response. The content:
- Is not used to train the provider's models (per the API agreement);
- Is processed transiently and returned to the store's dashboard;
- Is stored in the conversation history only within the platform itself.
10. Data subject rights (LGPD, Art. 18)
You may, at any time, exercise the following rights over your personal data:
- Confirmation of the existence of processing;
- Access to the data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary or excessive data or data processed in non-compliance with the LGPD;
- Portability of the data to another service provider, subject to trade and industrial secrets;
- Deletion of personal data processed based on consent;
- Information about the public and private entities with which the data was shared;
- Information about the possibility of not giving consent and the consequences of refusal;
- Revocation of consent, at any time;
- Objection to processing carried out on the basis of one of the grounds that waive consent, in the event of non-compliance with the LGPD;
- Review of automated decisions that affect your interests.
To exercise any of these rights, send a request to privacidade@graficaplus.com.br stating: full name, registered email, a description of the request and, when necessary, a document proving your identity or legal representation. We will respond within 15 (fifteen) business days.
If you are an End Customer of a store hosted on Gráfica Plus, your requests should be directed first to the Subscribing Customer (the print shop/store you dealt with), as it is the Controller of your data. If your request is not addressed, we forward it to the Subscribing Customer and provide support with the response.
11. Retention and deletion
We keep your personal data for as long as necessary for the stated purposes. For reference:
- Registration and operational data: for as long as the contractual relationship lasts.
- After the account is closed, we will keep data for up to 90 (ninety) days to allow recovery, billing verification or the handling of any dispute. After this period, the data is deleted or anonymized.
- Financial and tax records: kept for the period required by tax legislation (up to 5 years, under the Brazilian National Tax Code).
- Internet application access logs: kept for at least 6 (six) months, in compliance with Art. 15 of the Marco Civil da Internet.
- Communications subject to dispute: retained for as long as the investigation and the applicable statute of limitations last.
The Subscribing Customer may request the immediate deletion of specific data at any time — except for data we must preserve due to a legal obligation.
12. Information security
We adopt reasonable technical and administrative measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS) for all traffic with the server;
- Encryption at rest for sensitive data in the database;
- Storage of passwords exclusively as hashes;
- Row-level access control policies in the database, ensuring isolation between stores;
- Segregation of service keys between the public frontend and privileged server functions;
- Detailed logging of authentication events;
- Continuous monitoring of errors and unauthorized access attempts;
- Regular backups managed by the infrastructure provider.
Despite these measures, no system is completely immune to failures. In the event of a security incident that may result in relevant risk or harm to data subjects, we will notify those affected and the ANPD within a reasonable time, in accordance with Art. 48 of the LGPD.
13. Children and adolescents
The platform is intended for professional use by people over 18 years of age. We do not knowingly collect data from children or adolescents. If we identify a registration in this condition, we will remove the data. Parents or legal guardians may request deletion through the channels in this Policy.
14. Automated decisions
Some features — such as AI suggestions in conversations, automatic lead classifications and campaign recommendations — involve automated decisions. You have the right to request a review of these decisions. No automated decision, on its own, produces definitive legal effects on the data subject.
15. Changes to this Policy
This Policy may be updated to reflect regulatory changes, new integrations or operational improvements. The current version will always be available on this page, with the date of update. Material changes will be communicated by email and/or a prominent notice in the authenticated dashboard, with reasonable advance notice.
16. Contact and channels
- Data Protection Officer (DPO): privacidade@graficaplus.com.br
- General support: contato@graficaplus.com.br
- National Data Protection Authority (ANPD): if the request is not addressed, the data subject may file a petition directly at gov.br/anpd.
17. Governing law and jurisdiction
This Policy is governed by the laws of the Federative Republic of Brazil, in particular by Law No. 13.709/2018 (LGPD) and by the Marco Civil da Internet (Law No. 12.965/2014). The courts of the data subject's domicile are chosen to settle any disputes arising from this Policy.