Last updated
June 14, 2026
Your privacy is important to us. This Privacy Policy explains how Bitize collects, uses, shares, stores, and protects personal data processed due to the use of the website www.biterp.ai and the products and services of bitERP, operated by C D Tirabassi Junior Tecnologia da Informação Ltda. (Bitize), in compliance with Law No. 13.709/2018 — General Data Protection Law (LGPD) and other applicable regulations.
By browsing the site, contracting our services, or providing your data, you declare that you are aware of this Policy. When processing depends on consent, it will be requested specifically and prominently.
To facilitate reading, these are the main terms used in this Policy:
The controller, that is, who makes decisions about the processing of your personal data, is:
In compliance with art. 41 of the LGPD, we appoint the Data Protection Officer responsible for receiving your requests and acting as a communication channel between you, Bitize, and the National Data Protection Authority (ANPD):
Bitize can act in two different roles, depending on which data is being processed:
We are controllers regarding the data of people with whom we have a direct relationship, deciding on the purposes and means of processing. This is the case, for example, of the data of:
The processing of these data is governed by this Policy.
When a client uses bitERP and enters third-party personal data into the platform — such as data of their own clients, suppliers, employees, or partners —, these data are processed by Bitize on behalf of and under the instructions of the client, who is the controller of this information.
In this case, we act as processors: we process the data only to enable the contracted functionalities (for example, document issuance, financial management, registrations, and reports), according to the applicable Terms of Use and Data Processing Agreement.
As processors:
Contact Form
Founder Client Program Form
When you hire and use bitERP, we process, as controllers (item 4.1), the data necessary to create, maintain, and protect your account, for example:
The data that the client enters into bitERP about their own clients, suppliers, employees, and partners are processed by Bitize as an operator (item 4.2), exclusively to execute the contracted functionalities. The client is responsible (controller) for these data, including having a legal basis to process them.
Collected by cookies and analysis tools when you access the site, for example:
We do not seek to collect sensitive personal data (art. 5º, II, of the LGPD). We ask that you do not include this type of information in free text fields.
We process your data only for legitimate, specific, and informed purposes, observing the principle of necessity (use limited to the minimum necessary). The main purposes and respective legal bases (art. 7º of the LGPD) are:
| Purpose | Legal basis (LGPD) |
|---|---|
| Respond to contacts and lead requests | Pre-contractual procedures (art. 7º, V) and/or legitimate interest (art. 7º, IX) |
| Operationalize the Founder Client Program | Contract execution or pre-contractual procedures (art. 7º, V) |
| Create, maintain, and manage the client's account on the ERP | Contract execution (art. 7º, V) |
| Provide support and attend to client requests | Contract execution (art. 7º, V) and/or legitimate interest (art. 7º, IX) |
| Send marketing communications and updates | Consent (art. 7º, I) and/or legitimate interest (art. 7º, IX) |
| Measure and analyze site usage (analysis cookies) | Consent (art. 7º, I) |
| Attribute marketing campaign sources (UTMs) | Consent (art. 7º, I) and/or legitimate interest (art. 7º, IX) |
| Ensure security, prevent fraud and abuse | Legitimate interest (art. 7º, IX) |
| Comply with legal, fiscal, and regulatory obligations | Compliance with legal/regulatory obligation (art. 7º, II) |
| Exercise rights in an eventual process | Regular exercise of rights (art. 7º, VI) |
When the basis is legitimate interest, we limit processing to what is strictly necessary and maintain an assessment that weighs this interest against your rights and freedoms (art. 10 of the LGPD). You can request more information through the channel in item 3.
Regarding the data entered by customers on the platform (item 5.3), the definition of the legal basis is up to the customer, as the controller of this data.
The site uses cookies and similar technologies. They can be:
The analysis tools we use are:
You can accept, refuse, or adjust non-essential cookies at any time through the consent banner or the site's cookie settings, without prejudice to navigation in essential functions. It is also possible to manage cookies directly in your browser.
Você pode aceitar, recusar ou ajustar os cookies não essenciais a qualquer momento pelo banner de consentimento ou pelas configurações de cookies do site, sem prejuízo da navegação nas funções essenciais. Também é possível gerenciar cookies diretamente no seu navegador.
⚙️ Refusal or revocation of consent deactivates the corresponding analysis tools from that moment.
We do not sell your personal data. We may share them with:
We require operators to adopt security measures and process data in accordance with the LGPD. In all cases, we supervise the data recipients and seek to ensure adherence to good security and legal compliance practices.
The bitERP provides an MCP (Model Context Protocol) server at `mcp.biterp.ai` that allows the user to connect their account to third-party AI assistants of their choice (for example, Claude from Anthropic, or ChatGPT from OpenAI). When the user activates this connection, authentication is mediated by our identity provider (Clerk — Clerk, Inc.), and the chosen AI assistant can send commands to bitERP and receive corresponding responses. In this flow, the request parameters and data returned by the tools (which may contain registration, financial, and tax data of the tenant) are transmitted to the AI assistant provider chosen by the user and are subject to the privacy policy of that provider. This connection is optional, user-controlled, and can be revoked at any time. Bitize does not control the processing performed by the external AI provider after receiving this data.
Some of the tools and providers above may process data on servers outside Brazil (for example, GA4 — Google LLC; Microsoft Clarity — Microsoft Corporation; and PostHog — PostHog, Inc., all with infrastructure in the United States). The same may occur with artificial intelligence model providers (item 8), which may process, abroad, the content necessary for the platform's AI functionalities. In these cases, the transfer observes the requirements of arts. 33 to 36 of the LGPD and Resolution CD/ANPD No. 19/2024, which regulates international data transfer and approved the standard contractual clauses (SCC).
To ensure an adequate level of protection for your data, we rely on contractual safeguards signed with each supplier through their Data Processing Agreements, which incorporate transfer contractual clauses (including the Standard Contractual Clauses and, when applicable, the ANPD's standard clauses) and information security commitments.
We keep personal data only for as long as necessary to fulfill the purposes of this Policy or to meet legal obligations. In general:
The retention periods maintained after the end of the relationship are based on the regular exercise of rights and compliance with legal obligations (art. 7, II and VI, of the LGPD) and, therefore, may persist even after the revocation of any consent.
Once the purpose is concluded, the data is deleted or anonymized, except for the conservation hypotheses provided for in art. 16 of the LGPD (compliance with legal obligations, research by a research body with anonymization, or regular exercise of rights).
Under art. 18 of the LGPD, you can, at any time and free of charge, request:
We will respond to your requests whenever possible. However, these rights are not absolute: in some cases, the response may be partial or denied — for example, due to a legal obligation to retain data or the need for the regular exercise of rights — in which case we will provide the necessary justifications. When the request refers to data processed under the condition of operators (item 4.2), we may forward it to the customer controller or support them in the response.
To exercise any of the rights above, contact us via the email indicated in item 3. We may request information to confirm your identity before responding to the request. We will respond as soon as possible, observing the deadlines and procedures of the LGPD.
You can revoke consent for analytics cookies via the consent banner or the site's cookie settings. For marketing communications, use the unsubscribe link in the messages or the channel in item 3. Revocation does not affect the lawfulness of processing carried out before it.
We adopt appropriate technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination (art. 6, VII, and art. 46 of the LGPD), including access controls, encryption when applicable, and monitoring. Despite our efforts, no system is completely immune to incidents; in case of a relevant security incident, we will act in accordance with applicable law and notify the data subjects and the ANPD when required.
With some precautions, you help maintain a safer relationship in the processing of your data:
bitERP is intended for companies and professionals and is not directed at individuals under 18 years of age. We do not intentionally collect data from children and adolescents. If you identify such collection, contact us through the channel in item 3.
This Policy may be updated at any time. Relevant changes will be informed on the site, with the indication of the new "Last updated" date at the top of this document. We review this Policy periodically and whenever there are changes in legislation or in our services. We recommend periodic consultation.
Without prejudice to direct contact with us, you may file a complaint with the National Data Protection Authority (ANPD) if you believe your rights have not been met.
Questions about this Policy or about the processing of your data can be sent to privacy@bitize.com.br.