Legal transparency
Privacy and Data Protection Policy
Privacy and Data Protection Policy
Trimora is a software platform operated by AROEIRA DESENVOLVIMENTO DE SOFTWARES LTDA, a Brazilian company registered under CNPJ 66.968.674/0001-92.
This Policy explains how Trimora (AROEIRA DESENVOLVIMENTO DE SOFTWARES LTDA, CNPJ 66.968.674/0001-92) processes personal data on the platform, website, administrative panel, tenant environments, add-ons, TrimoraPay, integrations, and support channels, in accordance with Brazilian Federal Law No. 13,709/2018 (LGPD).
1. Roles
The tenant is normally the controller of data relating to its customers, team, schedule, services, campaigns, and operations. Trimora acts as a processor when processing this data to provide the service. Trimora is the controller of account-registration, billing, security, fraud-prevention, support, audit, institutional-communication, product-improvement, and legal-compliance data.
2. Data processed
Registration and contact data, usage and device data, billing and tax data, acceptance records (including IP address), messages and media from connected channels, and data entered by the tenant about its customers.
3. Purposes and legal bases
To provide and operate the service (performance of a contract), comply with legal and regulatory obligations, prevent fraud and ensure security (legitimate interest and legal obligation), communicate and improve the product (legitimate interest), and, where required, on the basis of consent.
4. Sharing
Data may be shared with strictly necessary processors and partners, including infrastructure, email, payment gateways, AI providers, and integrations requested by the tenant, always subject to appropriate safeguards.
5. Data-subject rights
Data subjects may request confirmation, access, correction, anonymization, portability, deletion, and information about processing by emailing [email protected]. Requests relating to a tenant's customer data are generally directed to that tenant, which acts as controller.
6. Security and retention
Technical and organizational measures are used to protect data. Data is retained for as long as necessary for the stated purposes and legal obligations, subject to the retention periods applicable after account closure.
7. Transfers and cookies
Any international transfers comply with the LGPD. The use of cookies is described in the Cookie Policy.
8. Google API Data and Limited Use
Google connections are optional and initiated by the user. Google Sign-In, Google Calendar, Google Ads, and Google Business Profile use independent authorizations. Each flow requests only the permissions required for the selected feature.
8.1 Data categories and purposes
- Google Sign-In: name, email address, profile picture, and Google Account identifier, used to create, locate, and protect the account link in Trimora.
- Google Calendar: calendar list, events, titles, descriptions, attendees, times, and locations, used to let the user select a calendar and synchronize requested appointments.
- Google Ads: accounts, campaigns, advertisements, settings, and metrics, used to create, manage, and display the performance of campaigns selected by the user.
- Google Business Profile: accessible accounts, account name, type, and verification state, used to display the authorized summary and open official management on Google when requested by the user.
8.2 Storage and security
Trimora stores only the data required for the enabled feature, such as the account link, selected calendar or account, event and campaign references, synchronization preferences, and technical security records. OAuth tokens and secrets are encrypted at rest and are never made available to artificial-intelligence features. Trimora does not receive or store the user's Google Account password.
Data is transmitted over HTTPS/TLS connections. Access is controlled by user, tenant, and integration purpose. Stored data and backups use Trimora infrastructure encryption and access controls.
8.3 Sharing, artificial intelligence, and Limited Use
Trimora does not sell data received from Google APIs, use it for third-party advertising, or share it for secondary purposes. Infrastructure processors may process this data only to the extent strictly necessary to provide and protect the selected feature, under access, confidentiality, and security controls, or where required by law.
Trimora does not use raw, aggregated, anonymized, or derived Google Workspace API data to create, train, or improve generalized or foundation artificial-intelligence models. This data is not transferred to AI providers for training, model improvement, advertising, or other secondary purposes. A central barrier blocks data classified as Google Workspace data before prompts, embeddings, memories, external caches, content telemetry, or provider calls are created, including calls to external, self-hosted, or offline models. Blocked attempts record technical evidence only, without the protected content.
Google Ads metrics may be processed by AI-assisted analytics features when the user expressly requests that feature. Their origin is classified separately, processing remains isolated by tenant, and OAuth tokens are never included. Google Business Profile data is not sent to AI providers in the current flow.
Trimora's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8.4 Retention, disconnection, and deletion
Data for each integration is retained while the connection remains active and for the period strictly necessary to provide the feature, prevent fraud, comply with legal obligations, and complete limited backup cycles. Users can separately disconnect Google Calendar, Google Ads, and Google Business Profile under Integrations, without affecting other connections, and can also revoke access through their Google Account.
Disconnecting a single product only removes that connection from Trimora. Revoking access at Google, or selecting the global revocation option in Trimora, may remove every permission granted to the Trimora OAuth project for the same Google Account. This can also disconnect Google Sign-In, Google Calendar, Google Ads, and Google Business Profile, and each required integration must then be authorized again.
Disconnecting prevents future use of the token for that purpose. Users may request access, correction, or deletion by emailing [email protected]. After the request is validated, data and tokens are deleted or anonymized, except for records that must be retained for legal obligations, fraud prevention, or limited backup cycles.
8.5 Google Maps Platform and location search
When creating a campaign, a tenant can search for a street, city, state, or postal code and choose an option supplied by Google Maps Platform. To perform this action, Trimora sends Google the text entered, a temporary session identifier, and the identifier of the selected place. Trimora retains the place reference and the text supplied by the tenant; structured addresses and coordinates received from Google are retrieved again only when required to validate or publish the campaign. Google's processing of data is described in the Google Privacy Policy, which is incorporated into this Policy by reference.
Acceptance and legal validity
Acceptance of this document is electronic and occurs through an affirmative confirmation, such as a checkbox or confirmation button, at registration, purchase of a paid plan, activation of an add-on, or activation of TrimoraPay, as applicable. Acceptance is recorded with the date and time, document version, identification of the responsible person (name, email address, and CPF/CNPJ when applicable), and IP address. A receipt is sent to the registered email address. This record has legal validity and constitutes evidence of acceptance under Article 10, paragraph 2, of Brazilian Provisional Measure No. 2,200-2/2001 and applicable law.
Governing forum
The courts of Campo Grande, State of Mato Grosso do Sul, Brazil are elected to resolve any dispute arising from this document, with waiver of any other forum, however privileged, except where mandatory jurisdiction applies, particularly under consumer-protection laws.
Trimora is a software platform operated by AROEIRA DESENVOLVIMENTO DE SOFTWARES LTDA, a Brazilian company registered under CNPJ 66.968.674/0001-92. Contact: [email protected]. Data Protection/Privacy: [email protected]. Address: Postal Code 79091-012, Brazil.