Last updated

Privacy Policy

June 14, 2026

Your privacy is important to us. This Privacy Policy explains how Bitize collects, uses, shares, stores, and protects personal data processed due to the use of the website www.biterp.ai and the products and services of bitERP, operated by C D Tirabassi Junior Tecnologia da Informação Ltda. (Bitize), in compliance with Law No. 13.709/2018 — General Data Protection Law (LGPD) and other applicable regulations.

By browsing the site, contracting our services, or providing your data, you declare that you are aware of this Policy. When processing depends on consent, it will be requested specifically and prominently.

1. Definitions

#definicoes

To facilitate reading, these are the main terms used in this Policy:

  • Personal data: any information related to an identified or identifiable natural person (for example: name, email, phone, CPF, IP address, location).
  • Sensitive personal data: data about racial or ethnic origin, religious belief, political opinion, union membership or organization of a religious, philosophical, or political nature, data concerning health or sexual life, genetic or biometric data (art. 5, II, of the LGPD).
  • Data subject: the natural person to whom the personal data refers.
  • Processing: any operation performed with personal data, such as collection, use, access, storage, sharing, elimination, among others.
  • Controller: the one who makes decisions about the processing of personal data.
  • Processor: the one who processes personal data on behalf of the controller and following their instructions.
  • Data Protection Officer (DPO): person appointed to act as a communication channel between the controller, the data subjects, and the National Data Protection Authority (ANPD).
  • Cookies and similar technologies: small files and identifiers stored on your device that allow recognizing navigation, remembering preferences, and measuring site usage.
  • ANPD: National Data Protection Authority.

2. Who is the controller of your data

#quem-e-o-controlador-dos-seus-dados

The controller, that is, who makes decisions about the processing of your personal data, is:

  • Corporate name: C D TIRABASSI JUNIOR TECNOLOGIA DA INFORMAÇÃO LTDA
  • CNPJ: 42.064.856/0001-70 (headquarters)
  • Trade name: Bitize
  • Address: Rua Eugênio Rabello, nº 98, Jardim Embaixador, Sorocaba/SP, ZIP 18040-436, Brazil
  • Brand/product: bitERP (accessible at www.biterp.ai)

3. Data Protection Officer (DPO)

#encarregado-pelo-tratamento-de-dados-dpo

In compliance with art. 41 of the LGPD, we appoint the Data Protection Officer responsible for receiving your requests and acting as a communication channel between you, Bitize, and the National Data Protection Authority (ANPD):

  • Data Protection Officer: Carlos Tirabassi Jr.
  • Email for privacy matters: privacy@bitize.com.br

4. Our roles in processing: when we are Controller and when we are Processor

#nossos-papeis-no-tratamento-quando-somos-controlador-e-quando-somos-operador

Bitize can act in two different roles, depending on which data is being processed:

4.1. Bitize as Controller

We are controllers regarding the data of people with whom we have a direct relationship, deciding on the purposes and means of processing. This is the case, for example, of the data of:

  • visitors to the website www.biterp.ai;
  • interested parties who fill out the Contact Form (leads);
  • participants of the Founding Client Program;
  • legal representatives and users who register and manage the client's account on bitERP.

The processing of these data is governed by this Policy.

4.2. Bitize as Processor

When a client uses bitERP and enters third-party personal data into the platform — such as data of their own clients, suppliers, employees, or partners —, these data are processed by Bitize on behalf of and under the instructions of the client, who is the controller of this information.

In this case, we act as processors: we process the data only to enable the contracted functionalities (for example, document issuance, financial management, registrations, and reports), according to the applicable Terms of Use and Data Processing Agreement.

As processors:

  • we do not use these data for our own purposes, except when necessary to operate, protect, and improve the platform, or to fulfill a legal obligation;
  • it is up to the client (controller) to define the legal basis, respond to data subjects' requests, and ensure they have authorization to enter the data into the platform;
  • we direct to the controller data subjects who contact us about data that belong to a client's usage context, and we may support them in responding.

5. What personal data we collect

#quais-dados-pessoais-coletamos

5.1. Data you provide us

Contact Form

  • Name
  • Email
  • Subject
  • Message (free text — may contain any data you choose to include)

Founder Client Program Form

  • Full name
  • Company name
  • Phone
  • Number of employees
  • CNPJ
  • Email
  • Record of acceptance of the Terms of Use and this Privacy Policy

5.2. Registration and use data of the bitERP platform

When you hire and use bitERP, we process, as controllers (item 4.1), the data necessary to create, maintain, and protect your account, for example:

  • account and representative/user registration data (name, email, phone, position);
  • access credentials (stored securely);
  • client company data (corporate name, CNPJ, address);
  • records of platform usage, settings, access and activity logs necessary for security, support, and continuous service improvement.

5.3. Third-party data entered by the client on the platform

The data that the client enters into bitERP about their own clients, suppliers, employees, and partners are processed by Bitize as an operator (item 4.2), exclusively to execute the contracted functionalities. The client is responsible (controller) for these data, including having a legal basis to process them.

5.4. Automatically collected data (navigation)

Collected by cookies and analysis tools when you access the site, for example:

  • IP address and approximate location data
  • Device type, browser, and operating system
  • Pages visited, source of access, clicks, and time spent
  • Campaign source and attribution data (source of access and UTM parameters: source, medium, campaign, content, and term)
  • Cookie and session identifiers
  • Session recordings and heatmaps, in an anonymized/aggregated form, when applicable
  • Gravações de sessão e mapas de calor (heatmaps), de forma anonimizada/agregada, quando aplicável

We do not seek to collect sensitive personal data (art. 5º, II, of the LGPD). We ask that you do not include this type of information in free text fields.

7. Cookies and analysis tools

#cookies-e-ferramentas-de-analise

The site uses cookies and similar technologies. They can be:

  • Essential: necessary for the basic functioning of the site; do not require consent.
  • Analysis/performance: help understand how the site is used, to improve it; only activated after your consent, given through the consent banner.

The analysis tools we use are:

  • Google Analytics 4 (GA4) — Google LLC
  • PostHog — PostHog, Inc.
  • Microsoft Clarity — Microsoft Corporation (includes heatmaps and session recording)

You can accept, refuse, or adjust non-essential cookies at any time through the consent banner or the site's cookie settings, without prejudice to navigation in essential functions. It is also possible to manage cookies directly in your browser.

  • usa a base legal de legítimo interesse para mensuração de ROI e atribuição de campanha, com avaliação de balanceamento documentada;
  • guarda primeiro toque e último toque por até 90 dias;
  • é limpo quando você recusa o banner, e a partir dessa oposição a LP deixa de gravar novas atribuições locais;
  • não libera, por si só, o envio desses dados para ferramentas de terceiros antes do consentimento.

Você pode aceitar, recusar ou ajustar os cookies não essenciais a qualquer momento pelo banner de consentimento ou pelas configurações de cookies do site, sem prejuízo da navegação nas funções essenciais. Também é possível gerenciar cookies diretamente no seu navegador.

⚙️ Refusal or revocation of consent deactivates the corresponding analysis tools from that moment.

8. Data sharing with third parties

#compartilhamento-de-dados-com-terceiros

We do not sell your personal data. We may share them with:

  • Operators who process data on our behalf and under our instructions, such as cloud hosting providers, email, customer service, marketing automation, and the analysis tools mentioned in item 7;
  • Artificial intelligence model providers, used to enable the AI functionalities of the bitERP platform. The content sent to these providers is processed exclusively to handle the user's request and in a mode that does not authorize the use of this content for model training (no training mode). The relationship with these providers occurs, as a rule, when we act as operators (item 4.2) of the content entered by the customer on the platform; the updated list of these sub-operators and the respective safeguards are included in the Data Processing Agreement signed with the customer;
  • Public authorities, when required by law, regulation, or court order;
  • Third parties in case of corporate reorganization (merger, acquisition, etc.), preserving the protections of this Policy.

We require operators to adopt security measures and process data in accordance with the LGPD. In all cases, we supervise the data recipients and seek to ensure adherence to good security and legal compliance practices.

8.1. Connection with external AI assistants via MCP

The bitERP provides an MCP (Model Context Protocol) server at `mcp.biterp.ai` that allows the user to connect their account to third-party AI assistants of their choice (for example, Claude from Anthropic, or ChatGPT from OpenAI). When the user activates this connection, authentication is mediated by our identity provider (Clerk — Clerk, Inc.), and the chosen AI assistant can send commands to bitERP and receive corresponding responses. In this flow, the request parameters and data returned by the tools (which may contain registration, financial, and tax data of the tenant) are transmitted to the AI assistant provider chosen by the user and are subject to the privacy policy of that provider. This connection is optional, user-controlled, and can be revoked at any time. Bitize does not control the processing performed by the external AI provider after receiving this data.

9. International data transfer

#transferencia-internacional-de-dados

Some of the tools and providers above may process data on servers outside Brazil (for example, GA4 — Google LLC; Microsoft Clarity — Microsoft Corporation; and PostHog — PostHog, Inc., all with infrastructure in the United States). The same may occur with artificial intelligence model providers (item 8), which may process, abroad, the content necessary for the platform's AI functionalities. In these cases, the transfer observes the requirements of arts. 33 to 36 of the LGPD and Resolution CD/ANPD No. 19/2024, which regulates international data transfer and approved the standard contractual clauses (SCC).

To ensure an adequate level of protection for your data, we rely on contractual safeguards signed with each supplier through their Data Processing Agreements, which incorporate transfer contractual clauses (including the Standard Contractual Clauses and, when applicable, the ANPD's standard clauses) and information security commitments.

10. How long we keep your data

#por-quanto-tempo-guardamos-seus-dados

We keep personal data only for as long as necessary to fulfill the purposes of this Policy or to meet legal obligations. In general:

  • Contact data (lead): up to 12 months after the last contact, when there is no ongoing contractual relationship.
  • Data from the Founding Customer Program: throughout the relationship and for up to 5 years after its termination, to safeguard the regular exercise of rights.
  • Registration and platform usage data: during the term of the contract and for the applicable legal periods after its termination.
  • Third-party data entered by the customer on the platform: for the period defined in the contract with the customer (controller); after termination, deleted or returned as contracted and by law.
  • Records of acceptances (Terms of Use and Privacy Policy): for the same period as the registration they refer to, as proof of consent.
  • Navigation data and analysis cookies: according to the configuration of each tool (for example, up to 14 months in Google Analytics 4). Campaign attribution data (UTMs) linked to a registration follow the period of that registration.
  • Access and security logs: for the minimum legal period applicable (as a rule, 6 months, under the Internet Civil Framework).
  • Data necessary for legal, tax, and accounting obligations: for the periods required by law (as a rule, 5 years).

The retention periods maintained after the end of the relationship are based on the regular exercise of rights and compliance with legal obligations (art. 7, II and VI, of the LGPD) and, therefore, may persist even after the revocation of any consent.

Once the purpose is concluded, the data is deleted or anonymized, except for the conservation hypotheses provided for in art. 16 of the LGPD (compliance with legal obligations, research by a research body with anonymization, or regular exercise of rights).

11. Your rights as a data subject

#seus-direitos-como-titular

Under art. 18 of the LGPD, you can, at any time and free of charge, request:

  • Confirmation of the existence of processing;
  • Access to your data;
  • Correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data with the LGPD;
  • Data portability to another provider, upon request;
  • Deletion of data processed based on consent, except for the cases of art. 16;
  • Information about the entities with which we share your data;
  • Information about the possibility of not providing consent and the consequences of this;
  • Revocation of consent, at any time;
  • Review of decisions made solely based on automated processing, if any.

We will respond to your requests whenever possible. However, these rights are not absolute: in some cases, the response may be partial or denied — for example, due to a legal obligation to retain data or the need for the regular exercise of rights — in which case we will provide the necessary justifications. When the request refers to data processed under the condition of operators (item 4.2), we may forward it to the customer controller or support them in the response.

12. How to exercise your rights

#como-exercer-seus-direitos

To exercise any of the rights above, contact us via the email indicated in item 3. We may request information to confirm your identity before responding to the request. We will respond as soon as possible, observing the deadlines and procedures of the LGPD.

13. How to revoke consent

#como-revogar-o-consentimento

You can revoke consent for analytics cookies via the consent banner or the site's cookie settings. For marketing communications, use the unsubscribe link in the messages or the channel in item 3. Revocation does not affect the lawfulness of processing carried out before it.

14. Data Security

#seguranca-dos-dados

We adopt appropriate technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination (art. 6, VII, and art. 46 of the LGPD), including access controls, encryption when applicable, and monitoring. Despite our efforts, no system is completely immune to incidents; in case of a relevant security incident, we will act in accordance with applicable law and notify the data subjects and the ANPD when required.

15. Security Guidelines for Data Subjects

#orientacoes-de-seguranca-aos-titulares

With some precautions, you help maintain a safer relationship in the processing of your data:

  • Keep your access credentials (login and password) to bitERP confidential and do not share them.
  • Be wary of messages (email, SMS, WhatsApp) requesting passwords, card data, or urgent payments on behalf of Bitize/bitERP. If in doubt, do not respond and seek official channels.
  • Always check the sender and the domain of links before clicking; our official channels use Bitize/bitERP domains.
  • Provide truthful information and keep your registration data up to date.
  • Immediately report any suspicion of misuse of your data or unauthorized access to your account, through the channel in item 3.

16. Processing of Children's and Adolescents' Data

#tratamento-de-dados-de-criancas-e-adolescentes

bitERP is intended for companies and professionals and is not directed at individuals under 18 years of age. We do not intentionally collect data from children and adolescents. If you identify such collection, contact us through the channel in item 3.

17. Changes to this Policy

#alteracoes-nesta-politica

This Policy may be updated at any time. Relevant changes will be informed on the site, with the indication of the new "Last updated" date at the top of this document. We review this Policy periodically and whenever there are changes in legislation or in our services. We recommend periodic consultation.

18. Complaints to the ANPD

#reclamacoes-a-anpd

Without prejudice to direct contact with us, you may file a complaint with the National Data Protection Authority (ANPD) if you believe your rights have not been met.

19. Contact

#contato

Questions about this Policy or about the processing of your data can be sent to privacy@bitize.com.br.