Privacy Policy – Conecta
Last updated: October 30, 2025
Our commitment: to simplify and protect.
Hello! At Conecta, we have one purpose: to simplify people's relationship with their assets. And this simplicity, which is in our DNA, is reflected in how we take care of your personal data.
This Privacy Policy was created to be as clear and direct as possible, without fine print or complicated jargon. We want you to know exactly what data we collect, why we need it, and how we ensure its complete security. After all, trust is the foundation of any asset.
Before we begin, it's important to know who the data controller is, meaning the entity responsible for making decisions about how your data will be processed.
For all purposes of this policy, the controller is CONECTA INTELIGÊNCIA FINANCEIRA LTDA., registered under CNPJ (Brazilian Taxpayer ID) No. 62.569.487/0001-85, headquartered in the City of Belo Horizonte, State of Minas Gerais.
If any questions remain after reading, our support channels are always open to you.
What personal data do we collect and why?
To offer an ecosystem that truly simplifies your life with your property, we need some information. Each piece of data collected has a clear purpose, always linked to improving your experience and the platform's security.
1. Data you provide directly:
- What?
- Registration data, such as: full name, identification documents, nationality, address, date of birth, parentage, gender, US Person declaration and PEP* (politically exposed person) declaration - (when applicable), marital status, and property regime, for the correct qualification of parties in contracts and instruments, ensuring the legal validity of asset operations, among others.
- Contact data, such as phone and e-mail.
- Company you work for and profession.
- Declared income and proof of income.
- Pix keys and related information.
- Copies of identification documents such as ID card (RG), Driver's License (CNH), CPF (Brazilian Taxpayer ID), among others; parentage (for identity validation and fraud prevention in registrations and official documents).
- Profile picture.
- Biometric data, such as your facial photograph, fingerprint, and/or facial biometrics to unlock the app via device (fingerprint, touch ID, and face ID), and facial recognition for authentication and fraud protection purposes.
- Financial details (such as bank details, payment history, income, and assets, when strictly essential for credit analysis), payment processing, or management of assets/liabilities linked to the contracted services.
*PEP is the term used to refer to people who are, or have family or close contact with people who hold political positions, such as parents, uncles/aunts, cousins, and even boyfriends or girlfriends.
- Why? To create your account, verify your identity, ensure it is really you in control, and for the formalization and execution of specific services and contracts you may hire us for, such as credit intermediation, real estate advisory, asset management, or other services related to your assets. This data, besides being crucial for the formalization, execution, registration, and security of the specific services and contracts you may enter into with us - such as credit intermediation, notary services, asset management, or other services involving your assets, serves to comply with specific legal and regulatory obligations in the financial, real estate, and notary sectors. We also need it to handle requests, answer questions, get in touch, whether by phone, e-mail, SMS, WhatsApp, or other communication means, including sending notifications or push alerts regarding the use of Conecta services, for marketing purposes, and other matters related to your contract, products, and services from Conecta. We also continuously seek to improve our services and your experience on the platform.
2. Data about your use of our platform:
- What? Information about the transactions and services you use within Conecta, interactions with our support team, and your browsing history on our site and app.
- Why? To offer the contracted services, authenticate your financial transactions, resolve any technical problems, and, of course, improve the platform to make it increasingly intelligent and intuitive for you (here, we use the legal bases of contract execution and our legitimate interest in improving our services).
3. Data we collect automatically:
- What? IP address, device type (mobile or computer), operating system, geolocation data, and non-essential cookies for marketing and performance (always with your permission and explicit consent). We use tools such as Google Tag Manager to manage marketing and performance analysis tags. Non-essential cookies are only activated with your explicit consent.
- Why? To increase your account's security, preventing fraud and identifying suspicious access. This information also helps us understand how the platform is being used to optimize performance (our legal basis is legitimate interest in ensuring security and improving the platform, in addition to fraud prevention).
4. Data we may receive from third parties:
- What? Information from credit and financial bureaus, including banks, fraud prevention partners, and public sources.
- Why? To further protect you and our ecosystem against illicit activities and to supplement our security analyses, ensuring an always-reliable business environment. It is also used to perform eligibility/viability analyses for the services and transactions you seek, such as credit analysis for financing, evaluation of real estate collateral, verification of the fiscal and registration regularity of assets, as well as for fraud prevention and ensuring a reliable and secure business environment for all parties involved (the legal basis is credit protection and our legitimate interest in preventing fraud).
5. Who we may share your data with:
Transparency is one of our pillars. Your data is only shared when strictly necessary and always with maximum security.
- Business Partners: Companies that help us enable Conecta's services, such as financial institutions to process credit or notary offices to register a document, real estate brokers for intermediation, real estate appraisal companies, and providers of technological and cloud services. They only access the data essential to fulfill your request, and with these partners, we sign Data Processing Agreements (DPAs) or specific addendums, requiring them to maintain the same level of security and compliance with the LGPD that we apply internally.
- Authorities and Regulatory Bodies: To comply with legal, judicial, or regulatory obligations from the financial, real estate, and notary sectors, such as those from the Central Bank, Securities and Exchange Commission (CVM), Federal Revenue, and Courts of Justice.
- Group Companies: To offer a more integrated and complete experience, always within the purposes described in this policy and under the same data protection guidelines.
- Fraud Prevention and Risk Analysis Companies: To ensure your security and that of our ecosystem, we may share data to validate your identity and prevent fraudulent activities, always with an appropriate legal basis.
We require all our partners to maintain the same level of security and compliance with the General Data Protection Law (LGPD) that we apply internally.
6. How long we keep your data:
We will keep your personal data only for the time necessary to fulfill the purposes for which we collected it.
This means that, even after your account is closed, we may need to keep your data for an additional period to comply with legal or regulatory obligations (such as rules from the Central Bank and the Federal Revenue), to resolve disputes, or for the exercise of our rights in legal proceedings.
Rest assured: after this period, your data will be securely deleted or anonymized (transformed into data that can no longer identify you).
7. Your rights: you are always in control:
We believe in your autonomy. Here, you are the owner of your data and have full control over it.
At any time, you can:
- Confirm if we process your data.
- Access what that data is.
- Correct incomplete or outdated information.
- Request the anonymization, blocking, or deletion of data that is no longer necessary, when applicable.
- Request a review of automated decisions. You have the right to request a review of decisions made solely based on automated processing of personal data that affect your interests, including challenging these decisions and requesting human intervention when applicable.
- Request the portability of your data to another service or product provider, when regulated.
- Know with whom we share your data.
- Object to the processing of your personal data when the legal basis for the processing is Conecta's legitimate interest, if you consider that the processing is violating your fundamental rights and freedoms.
- Revoke your consent for the use of data, when that is the legal basis we use.
To exercise your rights, simply contact our Data Protection Officer (DPO) via the e-mail dpo@conecta.email, or through a specific form on our website. We will respond to your request within 15 (fifteen) days, as provided by the LGPD, always seeking the best way to meet your request.
8. Security first:
Protecting your assets is our mission, and that starts with protecting your data.
We use the most modern security practices on the market, including end-to-end encryption for data in transit and at rest, continuous monitoring of our networks and systems, and strict need-based access control, to ensure your information is always secure.
We adopt the principle of "Privacy by Design and by Default" in all development of our products and services.
Furthermore, we conduct periodic security tests (such as penetration tests and vulnerability scans).
9. Data of Children and Adolescents:
Our services are aimed at people over 18 years of age. We do not intentionally collect personal data from children and adolescents.
If, in a specific situation and strictly necessary for the provision of our services (such as, for example, in processes of acquiring real estate in a minor's name or asset management involving minors as beneficiaries or heirs), there is a need to process personal data of minors under 18, this will only be done with the specific and explicit consent of at least one parent or legal guardian, ensuring that such processing always occurs in the best interest of the minor.
If we become aware of the unintentional collection of a minor's data without due consent, we will proceed with its immediate deletion.
10. International Data Transfer:
Some of our suppliers and partners, especially for cloud technology services (such as storage servers and communication tools), may be located outside of Brazil.
When this happens, Conecta ensures that the transfer of your data is carried out in full compliance with Chapter V of the General Data Protection Law (LGPD).
We adopt all necessary measures to protect your information, ensuring that the level of protection for personal data transferred internationally is equivalent to that required by Brazilian law.
11. Notification of Security Incidents:
The security of your data is our highest priority. Should any security incident occur that could result in relevant risk or harm to you (such as unauthorized access, destruction, loss, alteration, communication, or dissemination of personal data), Conecta commits to notifying the National Data Protection Authority (ANPD) and the affected data subjects, in compliance with Art. 48 of the General Data Protection Law (LGPD). We will make every effort to mitigate possible damages and investigate the causes of the incident, informing about the corrective measures adopted or to be adopted to prevent new occurrences.
12. Talk to us about your data:
If you have any questions about this Privacy Policy or want to exercise your rights, we have a dedicated channel for it.
Talk to our Data Protection Officer (DPO), Olavo Lara Resende Baeta, at the e-mail: dpo@conecta.email.
The DPO is the person responsible for handling all matters related to the protection of your data here at Conecta.
13. Changes to this policy:
We are always looking to improve. Therefore, this Privacy Policy may undergo updates.
When this happens, you will be notified by e-mail or by an alert in our application.
We recommend that you access this page periodically to stay informed about any changes.
14. For the legally curious: Details on legal bases and Jurisdiction:
At Conecta, transparency is one of our pillars. For those who wish to delve deeper into the legal foundations that allow us to process your personal data, we detail below the legal bases mentioned throughout our Policy, based on the General Data Protection Law (LGPD - Law No. 13.709/2018).
- Compliance with a legal or regulatory obligation (Art. 7, II of the LGPD): We use this legal basis to process data essential for complying with laws and regulations in the financial, real estate, and fiscal sectors, such as the rules of the Central Bank of Brazil and the Federal Revenue. This includes, for example, the data we collect to verify your identity and prevent money laundering.
- Execution of a contract (Art. 7, V of the LGPD): When you create an account and use our services, we establish a contract. The processing of data such as your name, CPF, and contact information is essential for us to fulfill our part of the agreement: open your account, process your transactions, and offer the platform's services.
- Legitimate interest (Art. 7, IX of the LGPD): In some situations, we process your data based on our legitimate interest, always aiming to improve your experience and ensure the security of our ecosystem. This happens, for example, when we analyze how you use our platform to identify improvements or when we monitor activities to prevent fraud. In these cases, we always balance our interest with your rights and freedoms, ensuring your privacy is respected.
- Credit protection (Art. 7, X of the LGPD): To ensure a secure business environment for everyone, we may process data to perform analyses and consultations related to credit protection. This legal basis allows us, for example, to access information from credit bureaus to supplement our security assessments.
This Privacy Policy will be governed, interpreted, and executed in accordance with the laws of the Federative Republic of Brazil, especially Law No. 13.709/2018 (General Data Protection Law – LGPD), regardless of the laws of other states or countries. The jurisdiction of the District of Belo Horizonte, Minas Gerais, is chosen as the sole competent forum to resolve any issues arising from this Policy, with express waiver of any other, however privileged it may be.
Rua Canopus, 11, 1 Andar - Santa Lúcia, BH | +55 31 9 9171-1718 | www.conecta.inc