Who we are and what this document explains
Legado is a management platform for political offices, pre-candidacies and campaigns, operated by MultPlace LTDA, registered under CNPJ 42.274.830/0001-57, with offices at Estrada do Matadouro, Águas Claras, Salvador, BA, 41311-262.
This Policy explains what personal data we process, why, who we share it with, and what you can require from us. It follows Brazil's General Data Protection Law (Law 13.709/2018) and the local rules that apply in the countries where we operate.
If anything remains unclear, write to our Data Protection Officer at privacidade@legado.social. We answer every request.
Two different roles, and why that matters to you
This is the most important part of this document, and the part almost no privacy policy explains properly.
For your account data — name, email, phone, subscription, support tickets — we are the controller: we decide how that data is processed and we answer for it.
For the data you enter into the platform — voters, supporters, vendors, donors, your office's contacts — you decide. For that data, you (or the organisation you represent) are the controller, and we are only the processor: we store and process it following your instructions, and we do not use that base for any purpose of our own.
In practice that means three things:
- Each team sees only its own data. The isolation is enforced in the database, as a row-level access rule, not merely on screen.
- We do not sell, rent or hand over your contact base to anyone.
- The responsibility for having a lawful basis to process that data — consent, legitimate interest or another — belongs to whoever enters it. We provide the tools; the decision is yours.
What data we process
Data about people who use the platform
- Registration: name, email, phone, profile picture, role.
- Authentication: password (stored only as a hash, never as plain text) or the provider identifier when you sign in with Google, Apple or Microsoft.
- Preferences: theme, language, time zone and per-module settings.
- Usage: session records (start, last activity), time logged against tasks, and a history of actions taken on records, for internal auditing and so the customer knows who changed what.
- Account verification, when you choose to verify: full name, country, document type and number, document image and selfie.
- Billing: plan, number of seats, invoices and subscription status. We never receive or store your card number — payment is processed by Stripe, which handles that data directly.
Data you enter about other people
- Electorate and supporters: name, WhatsApp, email, Instagram, state or province, municipality, neighbourhood and, when provided, approximate location.
- Declared profile: relationship with the campaign, preferred office, topic and candidate.
- Demographic profile, when filled in: gender, age range, colour or race, education, income range, religion, marital status and occupation.
- Office contacts: vendors, donors, partners and spokespeople, with tax or identity document, address, contact details, payment key and notes.
- Finance: entries, payments, receipts and attachments.
- Calendar, tasks and content produced in the platform's modules.
Sensitive data
Colour or race, religion and political conviction are sensitive data and demand greater care. The platform allows recording them because that is a legitimate part of campaign work, but:
- These fields are optional. The platform works without them.
- Every record stores the lawful basis chosen (consent or legitimate interest) and the consent date, where applicable.
- In the public form a voter fills in themselves, consent is mandatory and recorded with date and time.
- Verification document images and selfies also receive stronger treatment: they are kept in private storage, reachable only by those who must review them.
Data collected automatically
- IP address and browser identification at specific moments: account deletion requests, support messages sent without signing in, submission of the home page form, and acceptance of the legal documents. We use this for security, abuse prevention and as proof of acceptance.
- Approximate location from IP, only to show your city and state and to filter news for your region. That lookup is made by your browser against an external service and the result is stored only on your device, for 12 hours.
- Push notifications, if you allow them: the subscription address generated by your browser and the device identifier.
What we use it for, and on what lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and maintaining your account, providing the contracted service | Performance of a contract |
| Charging the subscription, issuing invoices, managing seats | Performance of a contract |
| Support, ticket responses and service communications | Performance of a contract |
| Deadline, reminder and summary notifications you configured | Performance of a contract |
| Security, fraud and abuse prevention, audit logging | Legitimate interest |
| Product improvement based on aggregate metrics | Legitimate interest |
| Account identity verification | Consent |
| Voter data entered by you | Defined by you, recorded on each record |
| Compliance with a legal obligation or court order | Legal obligation |
We do not use your data or your contact base for advertising, commercial profiling or sale to third parties.
Artificial intelligence
The platform has AI features — assistant, text generation, image generation, automatic receipt reading and help article suggestions. You should know exactly what happens when you use them:
- When you use an AI feature, the relevant content is sent to the model provider. Depending on the feature, that may include task text, financial data, contact records or electorate information.
- We use Anthropic for text and Google for image generation. Both handle that content as processors, in order to answer the request.
- Neither we nor those providers use your content to train models.
- Assistant conversations are stored in your account so you can revisit them. If you generate a share link for a conversation, anyone with the link can read it — treat that as publishing.
- AI output can be wrong. Generated content is a draft: reviewing it before any public use is on you.
Who we share data with
We share only what is necessary, with suppliers that perform part of the service:
| Supplier | Purpose |
|---|---|
| Supabase | Database, authentication and file storage |
| Anthropic | Text AI features |
| Image generation; Google sign-in | |
| Stripe | Payment and subscription processing |
| Apple, Microsoft | Social sign-in, when you choose it |
| Browser notification services | Delivery of push notifications |
| Messaging provider | Sending the WhatsApp messages you configure |
| Hosting and automation providers | Running the infrastructure |
| Postcode, map and geolocation services | Address lookup and map display |
We may also share data where there is a legal obligation or an order from a competent authority, and in the event of a corporate reorganisation, keeping the same conditions set out in this Policy.
Some of these suppliers are located outside your country. Those international transfers are made with the safeguards required by the applicable law.
Cookies and storage on your device
We do not use advertising or third-party tracking cookies. We use:
- Strictly necessary cookies, to keep your session open and remember your chosen language.
- Browser local storage, for things that only concern your device: theme, recent searches, a running timer, news already seen and drafts. None of that is sent to anyone, and it disappears when you clear your browser data.
How long we keep data
- Account data: for as long as the account exists.
- Account deletion: once requested, your account enters a 30-day window in which you can change your mind. Before requesting it, the system requires you to download a full backup of your data, encrypted with a key only you hold. After 30 days, the account and the team's data are deleted.
- Closure record: we keep a reduced record of the closure (reason, date, lifetime) to understand why people leave. The data identifying you in that record is automatically anonymised after 6 months.
- Verification documents: kept for as long as necessary to evidence the review carried out and to meet legal obligations.
- Tax and financial data: for the period required by applicable law.
- Voter and contact data entered by you: for as long as you keep the record. You can archive or permanently delete any record at any time — permanent deletion cannot be undone.
Your rights
You have the right to: confirm whether we process your data; access it; correct incomplete or outdated data; request anonymisation, blocking or erasure of unnecessary data or data processed unlawfully; request portability; be told who we share it with; know what happens if you do not consent; and withdraw consent.
In practice, inside the platform:
- Access and portability: the "My data" screen generates a file with your data in an open format, with no need to ask anyone.
- Correction: you edit your own data on the account and team screens.
- Deletion: the account deletion screen walks you through the whole process.
- Any other request: write to privacidade@legado.social.
If your request concerns data someone else entered about you — for example, if a campaign recorded you as a voter — we will forward the request to whoever controls that base, and help as needed so it is answered.
Security
We apply technical and administrative measures proportionate to the risk: encryption in transit, per-team data isolation enforced in the database itself, access control by role and by module, private storage for sensitive documents, audit logging of changes, and a customer backup encrypted in the browser before deletion.
No system is immune. If a security incident occurs with relevant risk to you, we will notify you and the competent data protection authority, as the law requires.
Children and adolescents
The platform is intended for people over 18, engaged in political or professional activity. We do not knowingly collect data from minors. If we identify such a record, it will be removed.
Changes to this Policy
When we change this document, we publish a new version with a date and a summary of what changed, and keep previous versions available on this same page. If the change is significant, we will ask you to accept it again when you sign in.
Governing law and contact
This Policy is governed by Brazilian law, in particular Law 13.709/2018. For users outside Brazil, we also comply with the applicable local data protection rules, including Argentina's Law 25.326, Chile's Law 19.628, Paraguay's Law 1.682 and Uruguay's Law 18.331.
The courts of Salvador/BA, Brazil, are elected to settle disputes, without prejudice to the data subject's right to approach the data protection authority in their own country.
Data Protection Officer: Deivide Araujo — privacidade@legado.social
