Privacy policy
This policy covers two kinds of data: what Apsio collects about the people who use its site and console, and the telemetry your app sends, which Apsio processes for you under the data processing agreement.
This text has not been reviewed by a lawyer yet and is not in force. It describes how Apsio is designed to work, so the final version can be written from it. Placeholders in square brackets are still open.
Who we are
Apsio is operated by [Legal name of the operating company, CNPJ and address]. For the telemetry your app sends, your organization is the controller and Apsio is the processor.
This site
This site sets no cookies and loads no third-party scripts or fonts. Your language choice is kept in your browser's local storage so the site does not redirect you again. [Add any analytics before it is installed.]
Your account
When you create an account we keep your name, work email, organization and the actions you take in the console. Sign-in runs through our identity provider, and payments through Stripe, which receives your card details directly; Apsio only sees the card's country, brand and last four digits.
Your app's telemetry
The SDKs are built to collect as little personal data as possible: no IDFV, IDFA or Android ID, users identified only by a hash your app provides, no IP addresses stored, text masked in replay by default, and request bodies off unless you turn them on.
Where data is stored
During early access, data is stored in one region, US East. An EU region comes next.
Retention and erasure
Telemetry is kept for the retention of your plan or the shorter period you set per project, then deleted. Erasure of one user's data is available on request. [Retention of account and billing records, as required by Brazilian tax law.]
Your rights
You can ask for access to, correction of, or deletion of your personal data, under the GDPR and the LGPD. [Data protection officer or contact, and the supervisory authorities.]