Privacy Policy
Last updated 8 September 2026
Draft pending legal review. This policy has been prepared as a working draft and has not yet been reviewed by qualified Brazilian counsel. It should not be relied upon as a final statement of InovaNexo's data practices until that review is complete.
InovaNexo provides managed payment services to merchants operating in Brazil. Handling payment data is the core of what we do, so how we treat that data matters as much as how we move money.
This policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights available to you under Brazil's Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018). It applies to our website, our merchant dashboard and APIs, and to personal data we handle while processing payments.
1. The two roles we act in
The LGPD distinguishes between a controller (controlador), who decides why and how personal data is processed, and an operator (operador), who processes data on a controller's instructions. Which role we occupy depends on whose data it is.
- We are a controller for data about our merchants and their representatives — the people we onboard, underwrite, contract with and support. We decide what we need in order to open an account, meet our regulatory obligations and run the relationship.
- We are generally an operator for data about a merchant's own customers — the payers who complete a Pix transfer, pay a boleto or use a card. That data reaches us so we can execute the transaction the merchant asked us to execute. The merchant remains the controller of its customer relationships and is responsible for having a lawful basis to send us that data and for telling its customers how it is used.
There are limited situations in which we act as a controller over payer data even so — principally where we are meeting our own obligations under anti-money-laundering law, preventing fraud, or defending a legal claim. In those cases we are acting on our own duties, not the merchant's instructions.
2. Personal data we process
Merchant and representative data
- Business identifiers: legal name, trading name, registration number (CNPJ or foreign equivalent), registered address, corporate structure and ownership.
- Details of directors, ultimate beneficial owners and authorised representatives: full name, date of birth, nationality, tax identifiers, identity document images, proof of address.
- Contact and account data: names, business email addresses, telephone numbers, dashboard login credentials and access logs.
- Financial and risk data: settlement bank details, expected and actual volumes, chargeback history, licensing and regulatory status, and the results of screening and due diligence checks.
Payer data received while processing transactions
- Identifiers required to execute or reconcile a payment: name, CPF or CNPJ, and where relevant a Pix key, bank account or card details.
- Transaction data: amount, currency, timestamp, payment method, merchant reference, status and settlement outcome.
- Risk and device signals associated with a transaction, used for fraud prevention and monitoring.
We do not ask merchants to send us more payer data than a transaction requires, and we do not use payer data to build marketing profiles or sell it to anyone. Full card numbers, where cards are used, are handled within the card-processing environment and are not stored by us in the clear.
Website and technical data
- Server logs: IP address, user agent, pages requested and timestamps.
- Any information you volunteer when you contact us — for example the content of an email enquiry.
3. Why we process it, and our legal bases
Under the LGPD we must have a legal basis for each processing activity. The bases we rely on are set out below.
| Purpose | Legal basis (LGPD Art. 7) |
|---|---|
| Onboarding a merchant, and providing and supporting the services under our agreement | Performance of a contract, or steps taken at the request of the data subject |
| Executing, routing, settling and reconciling payments | Performance of a contract |
| Identity verification, KYB, sanctions and PEP screening, and anti-money-laundering monitoring and reporting | Compliance with a legal or regulatory obligation |
| Fraud prevention, transaction monitoring and protecting the security of our systems | Legitimate interests, and compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Regular exercise of rights in proceedings |
| Responding to enquiries and business correspondence | Legitimate interests |
| Improving service reliability and quality using aggregated or anonymised data | Legitimate interests |
Where we rely on legitimate interests, we assess whether our interest is outweighed by the rights and freedoms of the people concerned, and we do not rely on it where the processing would be unexpected or intrusive.
4. Who we share data with
We share personal data only where it is necessary for the purposes above. The categories of recipient are:
- Banking and acquiring partners in Brazil, who hold accounts, execute transactions and settle funds. A payment cannot be processed without sharing the data the receiving institution requires.
- Identity, screening and fraud-prevention providers, used to verify businesses and individuals and to check them against sanctions, watchlists and politically exposed person data.
- Regulators and authorities, including the Banco Central do Brasil, the Conselho de Controle de Atividades Financeiras (COAF), tax authorities, courts and law enforcement, where we are legally required or permitted to disclose.
- Professional advisers — auditors, lawyers and accountants — under duties of confidentiality.
- Technology suppliers who host or support our infrastructure, under written contracts that restrict them to processing on our instructions.
- An acquirer or successor, if our business or part of it is reorganised, sold or merged. We would tell affected merchants before their data moved.
We do not sell personal data, and we do not share it for third-party advertising.
5. International transfers
Our merchants are frequently established outside Brazil, and some of our suppliers operate internationally, so personal data may be transferred out of Brazil. Where that happens we rely on one of the transfer mechanisms permitted by Chapter V of the LGPD — typically standard contractual clauses, a transfer necessary for the performance of a contract, or a transfer necessary to meet a legal obligation — and we apply the same protections to the data wherever it is held.
6. How long we keep data
We keep personal data for as long as we need it for the purpose it was collected, and then for any period we are required to retain it by law. In practice:
- Identification, due diligence and transaction records are retained for the minimum period required by Brazilian anti-money-laundering legislation, running from the end of the relationship or the date of the transaction, and longer where an investigation, audit or legal claim requires it.
- Accounting and tax records are retained for the periods set by Brazilian tax and commercial law.
- Contractual and correspondence records are retained while the relationship is live and then for the applicable limitation period.
- Website server logs are retained for a short operational period consistent with the Marco Civil da Internet.
When a retention period ends, we delete the data or irreversibly anonymise it. Anonymised and aggregated data, which can no longer identify anyone, may be kept for analysis and reporting.
7. Your rights under the LGPD
Article 18 of the LGPD gives data subjects in Brazil the right to ask us to:
- Confirm whether we process data about them, and give them access to it.
- Correct data that is incomplete, inaccurate or out of date.
- Anonymise, block or delete data that is unnecessary, excessive or processed unlawfully.
- Port their data to another provider, subject to trade secrets and commercial confidentiality.
- Delete data processed on the basis of consent, where consent was the basis relied on.
- Be told which public and private bodies we have shared their data with.
- Be told what happens if they refuse consent, where consent is being asked for.
- Withdraw consent, where consent was the basis relied on.
- Object to processing carried out on a basis other than consent, where it does not comply with the law.
- Ask for review of decisions taken solely by automated processing that affect their interests.
These rights are not absolute. We may be unable to delete data we are legally obliged to keep — anti-money-laundering records in particular — and we may need to verify identity before acting on a request. We respond within the timeframes set by the LGPD.
If you are a customer of one of our merchants, the merchant is usually the controller of your data and is the right first point of contact. Send us a request anyway if you prefer and we will forward it to them and help them respond.
8. How we protect data
We apply technical and organisational measures proportionate to the sensitivity of payment data. These include encryption of data in transit and at rest, access controls on a least-privilege basis, segregation of production environments, logging and monitoring of access, secure credential handling, supplier due diligence, and staff training on confidentiality and data protection.
No system is completely secure. If a security incident occurs that is likely to create a relevant risk or damage to data subjects, we will notify the Autoridade Nacional de Proteção de Dados (ANPD) and affected individuals as the LGPD requires, and we will tell affected merchants promptly so they can meet their own obligations.
9. Cookies and this website
This marketing website is deliberately simple. It does not set advertising or cross-site tracking cookies and does not run third-party analytics or advertising tags. It loads web fonts from Google Fonts, which means your browser makes a request to Google's servers to fetch them; that request carries your IP address and is subject to Google's own privacy terms.
Our merchant dashboard uses a strictly necessary session cookie to keep you signed in. It is required for the dashboard to function and is not used for tracking.
10. Changes to this policy
We update this policy when our practices, our suppliers or the law change. The date at the top shows when it was last revised. Where a change materially affects how we handle merchant or payer data, we will tell affected merchants directly rather than relying on this page alone.
11. Contacting us
For any question about this policy, to exercise a right described above, or to raise a data protection concern, contact us at operations@inovanexo.com, or write to us at our office in São Paulo, Brazil.
You also have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).