Imagenect — Privacy Notice (LGPD)
This Notice describes how D.E. Marketing Digital Ltda, registered under Brazilian company number (CNPJ) 63.561.334/0001-54, with registered office at Avenida Sete de Setembro, 219, Centro, Bagé/RS, CEP 96.400-006, Brazil ("Controller"), processes personal data in the licensing and use of the Imagenect software, in accordance with Brazilian Law No. 13,709/2018 (General Personal Data Protection Law — LGPD).
1. Summary
- Imagenect works locally. Scripts, images, audio, and projects remain on the user's computer and/or in the user's own cloud folders. We do not receive or access this content.
- For license control ("1 key = 1 machine"), we process a minimal set of technical data, described below, in pseudonymized form.
- We do not sell personal data and we do not use licensing data for advertising.
2. Data we do NOT collect
We do not collect project content (scripts, texts, images, audio), files on the computer, usage history of creative features, or the user's name, taxpayer ID, or address — except when voluntarily provided in a support contact or in the purchase process, which are handled in that specific context. AI analysis features embedded in the application run on the user's own computer. Integrations with third-party services (for example, ChatGPT, Google Drive, Microsoft OneDrive) use the user's own accounts and are governed by those providers' privacy policies.
3. Local discovery of shared projects
When enabled by the user, discovery monitors only the team folders selected on the computer and performs a limited check of Imagenect project signals directly inside them. Folder paths, identifiers, project names, authorship recorded in the project, and decisions such as snoozing or ignoring are stored locally on this device. The feature does not scan the entire Google Drive or Microsoft OneDrive account, connect projects automatically, or transmit this data to the Controller. The operating-system notification is optional and generic, without the project name. The user may pause or remove a monitored folder at any time without deleting folder files or local projects.
4. Data processed for licensing
- License key — a product code; it does not identify a person by itself;
- Pseudonymized machine identifier — a cryptographic hash (SHA-256) derived from operating system installation identifiers and technical characteristics of the device. It contains no name, email, documents, readable serial number, or location; it serves only to recognize the same device and prevent simultaneous use of the key on another machine;
- Dates and times of activation and of periodic license validations;
- Machine-change records — date and time, pseudonymized identifier of the released computer, count and origin (performed by the user in the app or by support) of each unbinding/transfer of the key, to prevent fraud and the improper sharing or rental of the license;
- Activation anti-fraud signals — to detect use of the same key on multiple machines (sharing/resale), we keep, for a short window and linked to the key, a pseudonymized identifier of the origin network (a hash of the IP address prefix, never the IP in clear) and the time of validations;
- Application version — sent on activation and on the periodic license validations, for support purposes and to decide update compatibility. Only the most recent version is kept, replacing the previous one; the record of acceptance described in the next item also preserves the version in force at each acceptance;
- Record of acceptance of the Terms — date and time, version and cryptographic digest (hash) of the accepted documents, language displayed, and origin of acceptance (installer or activation screen);
- Minimal purchase and delivery data — when the license is purchased through an integrated platform, we process the transaction code, product/offer identifiers, payment status, and the buyer's email encrypted in the database, exclusively to issue, deliver, resend, or revoke the key. We do not store the complete purchase payload, name, phone number, taxpayer ID, or address on this server;
- Transient technical access records — for example, IP address in the hosting provider's logs, retained for a short period for security purposes.
5. Purposes and legal bases
- Activate and validate the license and prevent simultaneous use of the same key — performance of a contract (art. 7, V) and legitimate interest in fraud prevention and security (art. 7, IX, and art. 10);
- Keep proof of acceptance of the Terms of Use — regular exercise of rights (art. 7, VI);
- Confirm the purchase, issue and deliver the license, and handle refunds or chargebacks — performance of a contract (art. 7, V) and regular exercise of rights (art. 7, VI);
- Comply with legal and regulatory obligations and orders from competent authorities (art. 7, II);
- Provide support when requested by the user — performance of a contract (art. 7, V).
6. Sharing
Licensing and delivery data is processed by contracted infrastructure providers (activation server and database hosting), payment/checkout providers, and transactional email providers, acting as processors or independent controllers according to the service and exclusively for the purchase and delivery. Data may be shared with public authorities when required by law. Personal data is not sold or assigned to third parties for commercial purposes.
7. International transfer
Infrastructure providers may store data outside Brazil (for example, in the United States). In such cases, the international transfer takes place with the safeguards of art. 33 of the LGPD, through contractual clauses and the security and compliance standards of the contracted providers.
8. Retention and deletion
- Activation/validation data: kept for the duration of the license. When the key binding is released (machine change), the machine identifier is removed from the active record;
- Machine-change records: kept as a fraud-prevention trail for the period necessary to exercise rights (as a rule, up to 5 years), and then deleted or anonymized;
- Activation anti-fraud signals: kept only for a short rolling window and then automatically discarded;
- Acceptance record and contracting-related data: kept after the license ends for the period necessary for the regular exercise of rights and compliance with legal obligations (as a rule, up to 5 years, according to applicable limitation periods), and then deleted or anonymized;
- Delivery email: kept encrypted with the contracting record while necessary for resending, support, and the regular exercise of rights, subject to the same maximum period above, and then deleted or anonymized;
- Infrastructure logs: short-term retention, defined by the hosting provider.
9. Security
We adopt technical and administrative measures proportional to the processing (art. 46 of the LGPD): encryption in transit (TLS), encryption at rest of the delivery email with a key separate from the database, cryptographically signed license tokens (Ed25519), pseudonymization of the machine identifier (hash), data minimization, and restricted access control to the license database.
10. Data subject rights (art. 18 of the LGPD)
You may request: confirmation of the existence of processing; access to data; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; information about sharing; and review of automated decisions — for example, the blocking of a key due to use on another machine can be reviewed by support. Contact channel: contact@imagenect.com. You may also file a petition with the Brazilian National Data Protection Authority (ANPD).
11. Data Protection Officer (DPO)
DPO contact: contact@imagenect.com.
12. Children and adolescents
Imagenect is intended for professional use by persons over 18 years of age.
13. Changes to this Notice
Changes will be published with a new version and date; material changes will be communicated in the application. In case of discrepancy between translated versions, the Brazilian Portuguese version shall prevail.