This Privacy Policy describes the procedures used by Interfy for processing Personal Data. It applies to all forms of data collection that we use to provide our services. For a better understanding of this Policy, we describe below the definitions of the terms used.
Certifications and compliance
See full detailsISO/IEC 27001:2022
SOC 2 Type II
In progressLGPD
GDPR
HIPAA Ready
BAA available
1. Definitions
Personal Data: information that allows a natural person to be identified, directly or indirectly, including through data cross-referencing. Example: identification number, national ID/tax ID, address, photograph, religious or political affiliation, date of birth, health data, biometrics, etc.
Data Subject: the owner of the data, i.e., the natural person to whom the data refers.
Data Processing: any action performed with personal information, such as capture, viewing, sharing, receipt, editing, deletion, transfer, etc.
Purpose: the objective sought through the processing of the data.
Controller: the natural or legal person designated by Interfy to respond to inquiries and ensure that data processing is carried out in accordance with applicable law, respecting the rights of data subjects.
Processor: the natural or legal person who processes data on behalf of the controller.
Third Party: a natural or legal person, public or private, with whom Interfy has or may have a relationship.
Data Protection Officer: the natural or legal person designated by Interfy to respond to inquiries and ensure that data processing is being carried out in accordance with the LGPD, respecting the rights of data subjects.
2. What are your rights as a data subject
- As a data subject, you have the right to easy access to information about the processing of your data, which must be made available in a clear, appropriate and conspicuous manner.
- You may confirm the existence of processing, and request and have access to the data.
- If you identify that the data is incomplete, inaccurate or outdated, you may request correction.
- Interfy does not keep unnecessary data, but if any data is considered excessive, you may request anonymization, blocking or deletion, including if it is being processed in non-compliance with applicable law.
- If you need your data transferred to another provider, you may request data portability, upon express request, subject to trade and industrial secrets.
- If you have given us consent to process your data, you may request its deletion, except in cases provided for by applicable law.
- We will inform you which public or private entities Interfy has shared your data with, whenever sharing occurs.
- If you do not wish to give us your consent for data processing, we will respect your decision and inform you of any consequences of not providing it.
- You have the right to withdraw your consent, through an express statement, free of charge and easily.
- If necessary, you have the right to file a petition with the ANPD (Brazilian data protection authority), consumer protection bodies and data protection regulatory institutions, if your data is processed inappropriately by Interfy.
- You may object to data processing based on a case where consent is waived, in the event of non-compliance with applicable law.
- If Interfy processes data in an automated manner and makes decisions based solely on that processing that affect your interests, you may request a review of such decisions.
- At any time you may request clear and adequate information about the criteria and procedures used for automated decisions, subject to trade and industrial secrets.
- To exercise your data protection rights, send your request to privacy@interfy.ai; our data protection officer will take the necessary steps to handle your request.
- If you withdraw your consent and there is no other legal basis supporting the processing, we will stop processing your data for the consented purpose.
- Any information you provide on blogs or websites, publicly exposed on the internet in places without access control, cannot have its protection guaranteed by us, nor can we limit who may copy or share such data.
3. What data we process
Interfy is a provider of intelligent document management and business process automation services, bringing together document management (Documents), process automation (Process), intelligent capture (Capture) and electronic and digital signature (Sign) in a single platform. Our services are provided online, contracted directly by customer companies or through business partners and distributors. We process the data necessary to activate and keep our services running, ensure security and availability, diagnose technical issues, remember useful information for better use of the service, send necessary maintenance notifications and alerts, provide technical support, offer training and best-practice guidance, inform about improvements and new features, and offer relevant complementary services to users and prospective users.
Each individual or legal entity that contracts our services may store and process data using the features available on our platform, and is identified as CONTROLLER, with Interfy acting as PROCESSOR. In that capacity, we keep the data secure and accessible, deleting it or providing a copy upon the CONTROLLER's express request, respecting the settings defined by it. As PROCESSOR, Interfy undertakes to handle information classified as personal data strictly following the criteria defined by the CONTROLLER and specified in the GDPR and the LGPD and other applicable regulations, solely for the purposes set out in the terms of use, and Interfy may not be held liable before the National Data Protection Authority (ANPD) and/or other authorities, data subjects, or any other institution with the power to impose administrative or judicial penalties.
If Interfy is penalized in its capacity as PROCESSOR, it retains the right of recourse to seek reimbursement from the CONTROLLER for all losses, damages and expenses arising from the wrongdoing, in addition to other measures necessary to protect Interfy's rights.
Interfy and the companies belonging to the group have no control over what data users store, in accordance with item 8 of our Terms of Use.
To use our services you provide the following information, considered Personal Data, for which Interfy is responsible as CONTROLLER: when contracting the services, as a platform user, or when you access our sites and send us a personal résumé, you provide us with your name, email, phone, job title and résumé data (which vary depending on each data subject).
See the full Terms of Use4. What we use each piece of data for
Name and email: we use this data to send the initial notification of the creation of your workspace and, subsequently, communications related to the service, maintenance needs, updates, legal obligations, marketing information about new products and features, offers, or any other content necessary to improve service delivery. You may opt out of receiving marketing messages by selecting the option available in the body of the email. If we receive a communication by email, we may retain the message, including our replies, for the purpose of maintaining a service history.
Phone number: we collect the phone number for subsequent contact via WhatsApp or other messaging apps, in order to handle support requests more quickly and accurately, send notices and marketing material, or for contacts from our finance department, when appropriate and necessary. We will not add you to any group without a prior invitation.
Résumé: résumés submitted by data subjects are stored in our database for 24 months, used to select candidates in our hiring processes when a new position is opened.
Job title: is stored in the customer and partner records so that we can identify the roles of each person we have a relationship with, directing us to the right people when necessary.
Payment data: used to process the monthly billing of the services. When the credit and/or debit card payment option is selected, Interfy does not store it — it is associated with a subscription ID in the payment processor (for example, Stripe or PayPal), which collects and maintains the data for processing. Interfy retains only the associated ID; our subprocessors have their own privacy policies. For the other payment methods made available, we collect and retain billing information, subscription records and payment records to ensure continuity of the services. In addition to the data above, we may collect: location, access device IP and access device identification.
5. How we collect and use each piece of data
Your location: we may collect, store and monitor location data when you access one of our sites or the Interfy application. Combined with other data, this data may make you identifiable; it is necessary for the proper functioning of some services, such as identifying the local currency and language.
Access device IP: combined with the email address and location, it allows us to identify where the user is allocated on our platform and which region they belong to, helping to improve our support procedures and identify possible region-related issues, such as service performance issues.
Access device identification: when accessing the services via a mobile device, we may collect, store, monitor and access device identifiers, which may make you identifiable if combined with other data. We store this data to render pages according to the device size and restrict functions not suited to certain types of device.
Other data we process from the data collected above:
Cookies: help you log in to the platform faster, by storing information about how you browse the site; this information, sent to us anonymously, allows us to improve your browsing experience. A persistent cookie remains on your hard drive after you close the browser, and may be removed according to your browser's instructions; a session cookie is temporary and disappears when the browser is closed.
Log files: when you use the Service, our servers automatically record certain information sent by your browser, such as web request, IP address, browser type, referring/exit pages and URLs, number of clicks, how you interact with links in the Service, domain names, landing pages, pages viewed, mobile carrier and other information.
Web beacons: we may use them in HTML-based emails sent to users, which allows us to track which of them are opened by recipients and online usage patterns, generating more detailed statistics and making our services more appealing to users.
6. Data collected optionally
You may add your photo to your platform access profile when using the services. This action is optional and you may remove it whenever you wish.
You may also send us your data by filling out an online form, sending an email or contacting us via chat. This data is processed to provide the information you request from us and may be used for direct marketing and for analytical purposes.
If you sign up for one of our online events, you will submit your contact information, through which we will provide access to the event; this data is processed to help us better understand our user base or prospective users and for direct marketing purposes.
You may unsubscribe from Interfy marketing communications by following the unsubscribe instructions in the footer of promotional emails, or by sending an email to privacy@interfy.ai.
7. Data collected from third parties
We may collect data from third-party sources so that you can log in to our services, or if you share data stored in our services with third parties — these third-party services may send us information about you and your public profile, provided that your account settings in the third party's application allow this type of sharing.
We may also receive information associated with the use of our sites from third-party applications. If you visit our sites, we may monitor and record your activities, and our third-party providers may provide us with additional information available for public access.
The information we collect may also be used for identification, authentication, fraud prevention and to improve the service we provide, including troubleshooting, market research and compliance with our Terms of Use.
8. How Interfy, as PROCESSOR, handles the documents and data you store on the platform
The content stored by you and by the people in your organization on the Interfy platform is not viewed by our support team, unless the platform administrator provides login and password access to one of our staff members, for the sole purpose of technical support and guidance on using the application — the user must be deactivated by the administrator at the end of the support session. Each customer receives an isolated database, ensuring the protection of access to information: only people to whom the platform administrator provides login and password with the corresponding permissions will have access to the content. All stored content and data (records, electronic files, metadata, forms, processes, etc.) are transferred to our servers on AWS infrastructure (certified ISO/IEC 27001:2022, SOC 2 Type II and HIPAA Ready, in addition to compliance with LGPD and GDPR), through typing, scanning and/or upload by persons authorized by the CONTROLLER, in accordance with the rules and settings predefined by the platform administrator; content travels between workstations or devices and is transferred via HTTPS, using TLS encryption.
9. Sharing with third parties
Interfy may share your data with business partners when we believe they are trustworthy and may have products and services relevant to you, or so that we can perform this services agreement — such as, for example, hosting providers. When we need to do this, we make sure the third party is trustworthy and will maintain the confidentiality of your data.
If Interfy undergoes a merger, acquisition or change in its ownership structure, the company may share your data with third parties as a result of that process.
If you access our application using third-party apps directly, your data may be shared with them; make sure you trust the app and review the data protection policies of its owning company.
We may share data with third-party applications through the use of an API, where stored data may be queried and/or copied to other applications, with the proper consent of the CONTROLLER responsible for the data stored on our platform.
Interfy may disclose your personal data when required by law or legal provision, for the purpose of protecting the safety of any individual in matters of fraud, protecting the right to life and liberty, or protecting Interfy's rights.
We use third-party analytics tools, which collect information sent by your browser as part of a web page request, browser add-ons and other information, to help us measure traffic and usage trends for our Services.
Interfy may store and process personal data in third-party marketing systems, customer relationship management (CRM) systems and email management systems, in order to promote the company's operations and facilitate interactions with users and prospective customers.
10. Blog and community
We may create publicly accessible blogs and communities, including forums. Any information you include in these areas may be read by other people, whom we cannot control, and may also be collected and used by anyone who accesses that content; posted information may remain available even after you close your account.
If you remove information posted on the blog and/or community service, copies may remain stored in the service's cache or with other users. If you would like us to remove such information, send an email to privacy@interfy.ai; however, in some cases, we may not be able to remove such information.
11. International data sharing
Hosting for our services is distributed across the regions below:
- Amazon AWS — São Paulo (Brazil) and Virginia (United States of America).
Data is distributed automatically through the technological resources applied within the infrastructure itself. To ensure data protection, we adopt security measures following LGPD requirements and, together with the AWS provider, use safeguards against accidental destruction, unauthorized access, automated backups and organizational measures aligned with our security policy, among other reasonable technical measures.
Data from users in the European Union, United Kingdom, Liechtenstein, Norway, Iceland and other countries is stored in the United States (US) through Interfy and its service providers; if you do not reside in the US, the laws may differ from the laws where you reside. By using the Services, you acknowledge that any personal information about you is being provided to Interfy in the US and hosted on US servers, and you authorize Interfy to transfer, store and process your information from and in the United States and, when necessary, in other countries indicated in this policy. Users from Brazil may have their data stored in the United States and in Brazil.
12. Data processing and retention period
Data for which Interfy is CONTROLLER: data collected directly or by our customers from the Platform is kept only for as long as necessary to provide the services, or for as long as needed to comply with our legal, accounting and tax agreements and obligations. For deletion or anonymization, we have established internal policies to ensure the security of the process, and we may retain the data for up to 3 months after use of the services ends, as a safety margin before it is deleted or anonymized. Data used by the marketing department may be retained for as long as we understand our services may be relevant for a future engagement, or until you unsubscribe or request deletion of the data.
Data for which Interfy is PROCESSOR: is retained until the CONTROLLER requests deletion and until we can safely carry it out, confirming that all data has been permanently deleted, which may take up to 90 days. Interfy requires all individuals and legal entities contracting and using our services to act in compliance with all applicable laws and regulations, in addition to this policy, and may unilaterally terminate the provision of services if it detects that the customer's users are violating personal data protection rules, as specified in our Terms of Use.
Data processed to maintain compliance: the data necessary to meet the tax, social security, labor and legal obligations of the Interfy group, in any of the countries in which we operate, is retained for the period determined by the law of each country.
See the full Terms of Use13. Consent
By agreeing to our Privacy Policy and by signing up to use our platform or any of our Services, you acknowledge that you agree to it and authorize us to process your data in accordance with this policy.
You have the right to withdraw, in whole or in part, your consent for us to process your Personal Data. To do so, contact privacy@interfy.ai, and we will stop processing your personal data for the purposes originally consented to, except where there are compelling legal reasons for us to continue processing your Personal Data that override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.
14. Correct, update or delete your information
You may request the correction, updating or deletion of the personal information you provide directly to Interfy; our team will make its best efforts to fulfill your request within the applicable legal timeframe, but we will not be liable for any failure to deliver our response.
When your information is processed by one of our customers who contract our services, you should direct your requests directly to your provider (our services customer), who acts as the CONTROLLER of your data.
15. Privacy rights for California residents
California residents have the right to request from us a notice identifying the categories of personal information we share with our partners or third parties for marketing purposes, including contact information for each third party. If you are a California resident, use our services and wish to request such information, send a request to privacy@interfy.ai.
16. Children's personal information
We do not knowingly collect or solicit personal information from children under 13 years of age, in accordance with our Subscription Agreement. If you are under 13 years of age, do not attempt to register for the services or send us any personal information about yourself. If we become aware of an account created by a person under 13 years of age, or of information sent to us directly under these conditions, we will delete all such information as quickly as possible. If you become aware that a child under 13 years of age has registered an account on our services or provided personal information, please contact us at privacy@interfy.ai.
17. Legal basis for processing personal data
We only process your personal information if we have a legal basis for doing so. We use the following legal bases:
- Contractual necessity: data is processed to fulfill our Terms of Service with you, and is essential for us to be able to provide the services — without it we would be unable to do so. This includes essential account data, essential primary cookies, connection data and third-party account information (if any), such as in the case of login via Active Directory.
- Consent: in some cases, we process personal data based on the consent formally provided by you at the time of collection, expressly requested at the time of collection.
- Legitimate interest: we collect certain categories when we believe they favor our legitimate interest or that of third parties, such as billing data, online form data, additional account data, phone, chat and email (when collected through means other than the service's user account), event and community data, tracking cookies, support tickets, device identifiers and web beacons.
- Other reasons: we may process data to comply with legal, accounting, tax and labor obligations, to protect the vital interests of data subjects, or to meet the requirements of government institutions and/or the judiciary.
18. General provisions
If this Privacy Policy is updated, we will make a new post on this page updating the information.
Our policy only covers access to our sites and applications. Links to third-party sites are not covered by our Privacy Policy.