Log inLog inStartStart

Browse

  • Modules→
  • Projects

    • Projects→
    • Kanban and Gantt→
    • WBS and risks→
    • OKRs and portfolio→

    Communication

    • Chat with Fay→
    • Meetings with AI minutes→
    • Events→

    Knowledge

    • Documents and office suite→
    • Docs, sheets and slides→
    • Whiteboards→
    • Forms→

    Time

    • Calendar→
    • Timesheets and capacity→
    • Automations→

    Sales and money

    • CRM→
    • Finance→
    • Reports→

    More

    • All features→
    • AI Module→
    • Integrations→
    • Try it free→
  • By industry

    • Law firms→
    • Agencies→
    • Associations→
    • Consulting firms→
    • Accounting→
    • Engineering→
    • All solutions→

    Featured

    • AI Module→
    • 7-day free trial→
  • Features→
  • Pricing→
  • Português
  • ·
  • English
  • ·
  • Español
Explore the FAYOL modulesExplore the FAYOL modulesExplore the FAYOL modulesExplore the FAYOL modules
Explore the FAYOL modulesExplore the FAYOL modulesExplore the FAYOL modulesExplore the FAYOL modules

Privacy Policy

Version 2026-08.3 · Last updated: August 28, 2026

This Privacy Policy describes how FAYOL collects, uses, stores, shares and protects personal data, in accordance with the General Data Protection Law (LGPD, Law No. 13,709/2018) and other applicable rules.

1. Controller, processor and Data Protection Officer

1.1. FAYOL acts as the controller of registration, billing, consent and site visitor data, and as the processor of the content the User enters on the platform (projects, tasks, documents, meetings, the customer's third-party data). In that second relationship, the customer is the controller and decides the purposes.

1.2. The contact for the Data Protection Officer (DPO) and for all personal data matters is privacidade@gestaofayol.com.br. The support channel within the platform also receives requests and forwards them.

2. Data we collect

  • Registration and profile: name, email, profile photo, job title, phone number and work area.
  • Billing: name, CPF/CNPJ, email, phone number and payment status. Card data does not pass through our servers. It goes straight to the payment processor.
  • Platform use: projects, tasks, comments, mentions, meetings, documents, budget, timesheets, OKRs, lessons learned and other content you create.
  • Meetings: the speech transcribed as text, with the name of the speaker, the messages written in the room, and the minutes and summary generated by AI. The call's audio and video travel between participants and are not recorded or stored by us. Only audio snippets are sent to an external provider to be turned into text (section 4).
  • AI agents: the agent's name, photo, description, instructions and scope; the messages in your conversation with it; and the proposals it recorded, with who decided and when (section 4).
  • Support: the support chat, the attachments sent and, for unauthenticated visitors, a random identifier stored in your browser (section 6).
  • Experience survey and per-screen signal: scores, comments, route of the rated screen, job title at the time of the response, device type and system version (section 5).
  • Acceptance of terms: a record of the version of the Terms and the Policy accepted, with date, IP and browser.
  • Technical and security: access logs, IP address, device and browser, and the audit trail events (section 7).

3. Legal bases, by processing activity

Each processing activity has its own basis, not a generic list:

  • Performance of the contract (art. 7, V): maintaining the account, work areas, projects, tasks, documents, meetings, notifications, support and the features of the AI Module purchased, including the conversation with the agent and the work summary it receives to respond.
  • Consent (art. 7, I): recording your speech as text in a transcribed meeting; responses to the experience survey and the per-screen thumbs up or down; marketing communications. It can be withdrawn (section 12). Withdrawing does not erase what was lawfully processed before.
  • Compliance with a legal obligation (art. 7, II): tax and accounting documents, records of document acceptance and retention of trails.
  • Legitimate interest (art. 7, IX): information security, fraud and abuse prevention, the security event trail and aggregated usage analysis to fix product defects.
  • Regular exercise of rights (art. 7, VI): keeping records needed for defense in legal proceedings.
  • Pre-contractual procedures (art. 7, V): support for site visitors and checkout started without an account.

4. Artificial Intelligence: what is processed and where it goes

4.1. The AI features are part of the AI Module, a paid add-on described in the Terms of Service. Without this module active in the work area, nothing in this section happens.

4.2. What data the AI processes. There are three sets, and none of them is larger than this:

  • The meeting. During a meeting with active transcription, audio snippets are sent for conversion to text. Voice is personal data and is treated as such: the resulting text is stored with the name of the speaker, the time and the source (spoken voice or message written in the room). To generate the minutes, the full record of the conversation (transcribed speech and written messages, with names and times) and the list of participants are sent to the model provider.
  • The conversation with the agent. Everything you write to the agent, the latest messages in that conversation (for continuity), the instructions and description the person gave the agent, and the FAYOL screens manual, which is the text the agent uses to teach how to use the system.
  • A summary of the work you can already see. Built with your identity (the agent never sees more than you would see on screen) and limited to: the name, status, health, percentage complete, expected end date and identifier of up to 60 active projects (with detail on the 12 most recent); the count of open and overdue tasks; the title, deadline and project of up to 8 overdue tasks; and the title and time of the next 5 meetings. If the agent is scoped to a single project, the summary is limited to that project.

4.3. This data goes to a third party, and we tell you who it is. Language processing and voice-to-text conversion are not done by us: we use an external artificial intelligence model intermediary (known as a gateway) and, behind it, the model providers, which are second-tier subprocessors. There are two, with different roles: the conversion of your voice to text is done by an OpenAI model; the writing of minutes, summaries, reports, project charters and the agents' responses is done by a Google model. We name both because it is people's voice and text that pass through them, and a category is not enough in this case. Data is sent by our server, under our access key, only at the moment you use the feature. This processing very likely takes place outside Brazil.

4.4. What we cannot state, and therefore do not state. We have no direct contract with the model provider, nor a formal statement from it on how long the content sent is retained and whether it is used to train models. Therefore: we make no promises on its behalf of zero retention or no training. What we do is (i) send only what is needed for the requested function, (ii) not send content from your work area outside the moment of use, (iii) keep the requirement for this commitment in writing as an open item in our vendor management and (iv) update this Policy when the commitment is documented. If this uncertainty is unacceptable for your case, do not activate the AI Module and handle sensitive meetings outside transcription.

4.5. The agent does nothing on its own. It proposes and a person approves. When the response implies an action (filling in fields, creating tasks, writing a text, notifying someone), a pending proposal is created, which only changes something in the system after someone with permission accepts it. We record who decided, when, and the agent's rationale. This also applies when the work area administrator enables automatic runs on the agent's profile (at a set time or when a task is assigned to it, at most one per agent per day, triggered the first time someone in the work area opens the system after the set time or by an external trigger set up by the customer): the run also ends in a pending proposal, nothing is executed without human approval and no data is sent to third parties because of it beyond the processing described in item 4.3.

4.6. Your conversation with the agent is yours. Each person has their own conversation with the same agent, and no one on the team reads another person's conversation. Deleting the agent deletes its conversation and its proposals.

4.7. There is no automated decision about you. No AI result determines, on its own, access, performance evaluation, credit approval or any effect on your legal rights: there is always a human decision in between (art. 20 of the LGPD).

4.8. We do not use the content of your work area to train our own models.

5. Contract signing: identity, document and selfie

5.1. This section applies only to signing at the Enhanced level. At the other levels none of this is requested, and anyone who uses the platform for projects, meetings or finance never goes through this.

5.2. What we ask of the person signing: CPF, date of birth and phone number; a photo of an official photo ID (CNH or RG); and a photo of yourself holding that document.

5.3. A selfie linked to you is sensitive personal data under the LGPD, and we treat it as such: stored in a private area, with restricted access and a record of who accesses it.

5.4. Automatic check, stated precisely: the two images are sent to the AI gateway of our infrastructure provider, which forwards them to a vision model. The model reads the images and returns facts: what document it is, what name, CPF and date of birth are printed, whether the selfie shows a person holding a document, and whether the two faces appear to be the same person.

5.5. The decisions are not the model's. Matching name, identical CPF and identical date of birth are checked by deterministic code on our side. The model informs; the code decides; and the entire verdict is stored as evidence of the signature.

5.6. What we do not claim, and that is why it is written down: the model's “same person” reading is not certified facial biometrics, and no text in the system calls it that. A “no” reading fails the check; an “uncertain” reading does not fail it on its own: it passes with the caveat recorded, because the anchor of the check is the pairing of name + CPF + date of birth against what the company filled in, and blocking on model uncertainty would reject legitimate people with poor-quality photos.

5.7. The same caveat from section 4 about the model provider applies to the images: we have no direct contract with it and no formal statement on how long it retains what it receives. We send only the two images and what is needed for the check, and we will update this document when there is a documented commitment.

5.8. ICP-Brasil digital certificate (A1): the .pfx file and its password travel to our server for signing, and only for that. The password is not stored, not logged and not returned: it opens the file in memory and is discarded there. The .pfx file is not kept either. What remains is what proves the signature: the holder's name, CPF, serial number, issuer and validity of the certificate, plus the cryptographic signature (CMS) over the document hash.

5.9. From the moment of signing, we also keep: IP address, browser identification, date and time, the cryptographic hash (SHA-256) of the signed document and the hashes of the two images; the hashes exist to prove that the images were not swapped afterward.

5.10. Legal basis: regular exercise of rights in legal proceedings (art. 7, VI, and art. 11, II, “d”) and compliance with a legal obligation. Without this evidence, an electronic signature does not hold up if challenged: that is what it exists for, and only that.

5.11. Retention: the document and selfie images are kept together with the signature trail, for the same period as the trail: 10 years, because they form part of the proof of the act. We say this explicitly because the period is long and the question is fair. Early deletion can be requested at privacidade@gestaofayol.com.br, and its effect is to reduce the evidentiary weight of that specific signature.

6. Experience survey and per-screen signal

5.1. Within the system you can answer an experience survey (recommendation from 0 to 10 and the reason, satisfaction from 1 to 5, ease of use from 1 to 7, whether something seemed slow and where, whether an error appeared and where, most used screens, which screen gets in the way and why, what is missing, and whether you left the system to get something done in another tool) and give a thumbs up or down per screen (“did this screen help?”, with an optional comment).

5.2. Along with it we store: the route of the rated screen (for example, “/projetos”), your job title at the time of the response, the device type (computer, tablet or phone) and the system version. We do not store IP or the full browser in these responses, and we do not store content from your work area in them. The survey can be saved in steps. Incomplete responses also teach us where the form gets tiring.

5.3. None of this goes on a public page. These responses are internal, read by those who look after the product to decide what to fix first. A public testimonial is something else: it only appears on the site when you expressly authorize publication, on a dedicated screen.

7. Support: chat and attachments

6.1. The support chat is kept to provide continuity of support. A visitor who does not yet have an account is identified by a random identifier stored in their own browser, not by name or email, unless they provide it.

6.2. Attachments sent in the chat (image, video, document) are kept in private storage, with no public address: each time one is opened, a signed temporary address, valid for 5 minutes is generated. There is a limit of 10 MB per file and on accepted types.

6.3. Retention: the period we apply is 12 months for attachments from closed chats; deletion is carried out on request and the automatic routine is being implemented. The message remains in the support history, without the file.

6.4. Support team access to attachments requires second-factor authentication when the factor is registered on the administrative account; the unconditional requirement is being implemented (timeline in our internal security policy).

8. Security event audit trail

7.1. We record, in a trail that only accepts new entries and cannot be changed or deleted by the application, not even with the service key, the events that change who has access to what: a member joining or leaving the work area, role changes, creation and changes of custom roles and permission exceptions, granting and revoking of modules, plan changes, account locking and unlocking, as well as authentication failures and use of administrative credentials.

7.2. Each entry stores when the event occurred, who the author was (with their email at the time), the work area, the action, the severity and details of what changed. It is forbidden, by system rule, to store passwords, access keys, authentication codes, full CPF/CNPJ or card data in these details.

7.3. Who reads it: the platform administration, with a second factor when registered on the account; and the Owner or Director of the work area, restricted to events in their own work area. Platform events (subscription, module, lock) are not exposed to the customer.

7.4. This trail exists to prove what happened in investigations, disputes and audits. That is why it survives the deletion of convenience data and follows the period set by our retention policy.

9. Sharing with third parties

8.1. We do not sell your data and do not share it for third-party marketing. We share it only with providers essential to the operation, under contract and a duty of confidentiality, in these categories: hosting and database; application runtime and network; account authentication; file storage; sending transactional emails; payment processing; and an external artificial intelligence model intermediary, with the respective model provider (section 4).

8.2. The list of these providers by name, with purpose and country of processing, is sent to any data subject who requests it at privacidade@gestaofayol.com.br.

8.3. We may also share data under a court order, a request from a competent authority or a legal obligation.

8.4. Status of the contracts, without window dressing: there is not yet a data processing agreement (DPA) signed with all of these vendors: several currently operate under standard adhesion terms. It is work in progress, and we say so here because leaving it out would be misleading.

10. International transfer

Some providers process data outside Brazil. The most relevant case is the AI model provider (section 4). For these transfers we rely on the grounds in art. 33 of the LGPD and seek compatible contractual safeguards; where the safeguard is not yet formalized, we say so instead of assuming.

11. Security

10.1. We apply encryption in transit (HTTPS/TLS), access control through Row Level Security (RLS) in the database, isolation by work area, segregation of administrative functions, with a second factor for administrative access when the factor is registered on the account, private file storage with temporary addresses, an audit trail that only accepts new entries (section 7) and secure development practices.

10.2. We are not ISO/IEC 27001 or SOC 2 certified. There is internally documented preparation for these frameworks. Preparation is not certification, and none of our materials may claim otherwise.

10.3. No system is completely immune to incidents. If there is an incident with relevant risk, we will notify the data subjects and the National Data Protection Authority (ANPD), as required by the LGPD.

10.4. Against scams: the email confirmation and password reset links we send point to gestaofayol.com.br/verificar. We never ask for your password by email, message or phone.

12. Retention

11.1. Periods we apply:

  • Active account: we keep the data for as long as the account exists.
  • After closure: up to 12 months, for contractual, accounting and audit matters; after that, deletion or anonymization.
  • Documents signed on the platform and signature trail: 10 years, because they prove a legal act between the parties. This period prevails over the 12 months above.
  • Images from Enhanced signing (document photo and selfie): the same 10 years, because they form part of the proof of who signed. See section 5.11, including on early deletion.
  • Contract acceptance records: the term of the contract plus 5 years.
  • Support attachments: 12 months after the chat is closed, currently carried out on request.
  • AI agent conversation and proposals: for as long as the agent exists; deleting the agent deletes both.
  • Meeting transcript and minutes: for as long as the meeting exists in the work area: it is the customer's record, and the customer decides whether to delete it.
  • Tax documents and security event trail: for the applicable legal period and the period set by our retention policy, because they are records of obligation and of proof.

11.2. How these periods are carried out, honestly: deletion is not instant or automatic in every case: part is carried out by an internal routine and part on request. If you want deletion before the period ends, ask at privacidade@gestaofayol.com.br and we will carry it out, except for what the law requires us to keep.

13. Your rights (art. 18 of the LGPD) and how to exercise them

12.1. You may request, at any time: (i) confirmation that processing exists; (ii) access to the data; (iii) correction of incomplete, inaccurate or outdated data; (iv) anonymization, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance; (v) portability to another provider, upon express request; (vi) deletion of data processed based on consent; (vii) information about whom we share with; (viii) information about the possibility of not consenting and its consequences; and (ix) withdrawal of consent.

12.2. How to exercise them: write to privacidade@gestaofayol.com.br saying which right you want to exercise. If you prefer, use the support chat within the platform, which records the request with a date. We respond within 15 days; when the request is for access, we may respond in simplified form immediately and in full within 15 days. We may ask for additional information to confirm it is you: this protects against requests made by third parties.

12.3. Optional consents (marketing, non-essential cookies) and the record of acceptances are on the Consents screen, within the system, where you can also withdraw them. Consents essential to providing the service can only be withdrawn by closing the account.

12.4. If the data was entered in the work area of a FAYOL customer (for example, by your employer or by the client of the project), the controller is that customer: we forward your request to them and support the response, as processor.

12.5. You may also file a complaint directly with the National Data Protection Authority (ANPD).

14. Cookies

We use strictly necessary cookies to keep the session authenticated and protect requests, and preference cookies (theme and last work area accessed). Analytics cookies, when they exist, depend on your acceptance and can be withdrawn on the Consents screen. We do not use advertising cookies.

15. Minors

FAYOL is intended for corporate and professional use. We do not knowingly collect data from children or adolescents.

16. Changes

This Policy may be updated. Relevant changes are announced within the platform and, when the published version changes, a new acceptance is requested on the next access. The notice appears once.

17. Contact

Data Protection Officer (DPO) and personal data matters: privacidade@gestaofayol.com.br. Questions about using the product: FAYOL's official support channel, within the platform.

Method is rhythm. Rhythm is delivery.

The Brazilian platform where deadlines, costs and your team live in one place, and the next decision is always obvious.

contato@gestaofayol.com.br
Meta Tech Provider

Product

  • All features
  • Projects and schedules
  • Meetings with minutes
  • Automations
  • Reports
  • Finance
  • AI Module

Solutions

  • Agencies
  • Engineering and construction
  • Consulting and PMO
  • Law firms
  • Accounting
  • Associations
  • See all

Company

  • Pricing
  • Terms
  • Privacy
Log inLog inStart todayStart today
  • TermsTerms
  • PrivacyPrivacy
  • Português
  • ·
  • English
  • ·
  • Español

© 2026 FAYOL

contato@gestaofayol.com.brcontato@gestaofayol.com.br

CNPJ 66.122.758/0001-00Legal name 66.122.758 Daniel Pavao BassottoGRUPO NIMA