Privacy Policy

Last updated: 2026-04-22

A Portuguese (pt-BR) version of this policy is available at /privacidade.

1. Introduction

EXCELVERTON & TATHI CONSULTORIA LTDA (CNPJ: 61.424.364/0001-93), the company behind the PBI Portal platform (https://www.pbiportal.com.br), is committed to protecting our users' privacy. This Privacy Policy describes how we collect, use, store and protect your personal information.

2. Data Collected

We collect the following types of data:

  • Account data: name, email address, phone number
  • Payment data: processed by Mercado Pago (we do not store card data)
  • Communication data: messages sent via WhatsApp and in-app chat
  • Technical data: IP address, browser type, operating system

3. Use of Data

We use your data to:

  • Manage your account and the services you have contracted
  • Send confirmations and notifications
  • Process payments and issue receipts
  • Provide AI-based support
  • Improve the platform experience and features
  • Comply with legal and regulatory obligations

4. Sharing

Your data may be shared with:

  • Payment processors: Mercado Pago
  • Infrastructure providers: Microsoft Azure
  • WhatsApp/Meta: for communication

5. Security

We use security measures such as encryption, access controls, isolated infrastructure and backups to protect your data.

6. Your Rights (LGPD / GDPR-equivalent)

Under the Brazilian General Data Protection Law (LGPD), you have the right to: access, correct, and delete your data; withdraw consent; and request data portability.

7. Social Media Integrations (TikTok, Facebook, YouTube, Instagram)

PBI Portal offers optional features that automate content publishing to social networks. When you voluntarily connect a social media account to the platform via OAuth, we collect and store the following information:

  • TikTok (Login Kit + Content Posting API): open_id, avatar, display name (scope user.info.basic); access and refresh tokens issued by TikTok; metadata of the videos you authorize us to publish (scopes video.upload and video.publish).
  • Meta (Facebook/Instagram): Page ID, Page Access Token, business ID and metadata of authorized posts.
  • YouTube: channel ID, OAuth 2.0 refresh_token (offline access) and metadata of authorized videos.

Usage: data collected from these social networks is used exclusively to (i) identify the connected account, (ii) publish the content you request from PBI Portal, and (iii) display post status and history. We do not sell this data, do not share it with third parties beyond essential infrastructure providers, and do not use it for advertising.

Storage: tokens are stored encrypted in Azure Key Vault. Post metadata lives in a managed PostgreSQL database (Azure Flexible Server) with restricted access.

Revocation: you can disconnect any social account at any time inside PBI Portal (Settings → Integrations → Disconnect) or directly in the corresponding social network (e.g. TikTok > Settings > Manage connected apps). When you disconnect, we remove tokens and associated metadata within 7 days.

Retention: TikTok tokens are kept only while the integration remains active. Publishing logs are retained for 90 days for audit and support purposes.

8. Contact

For privacy-related inquiries, please contact: contato@pbiportal.com.br