Privacy Policy
Última atualização / Last updated: 2026-07-24 Effective date: June 16, 2026
Portuguese (Brazil) version. This is the binding and prevailing version. The English-language version is provided for convenience only; in the event of any discrepancy, the Portuguese version prevails.
0. Preamble — Identification, effectiveness and language prevalence
0.1. This Privacy Policy (“Policy”) describes how Sparsu, a platform conducted by Antônio Amaral Egydio Martins, a natural person domiciled in the city of São Paulo/SP, Brazil, currently in the process of incorporating a legal entity, available at https://sparsu.com (hereinafter “Sparsu” or, simply, the “Company”, “we”), processes personal data. The Company is the party holding decision-making power over the processing of personal data described herein, in its capacity as controller (art. 5, VI, of Law No. 13,709/2018 — the General Personal Data Protection Law, “LGPD”), in the cases set out in Section 3. Until the incorporation of the legal entity is completed, the role of controller is performed by the natural person identified above; once the company is incorporated, this Policy will be updated to reflect its corporate name and CNPJ enrollment number, without prejudice to the obligations already undertaken.
0.2. This Policy constitutes the privacy notice required by art. 9 of the LGPD and forms part of, being referenced by, the Terms of Use of the Platform. Acceptance of the Terms of Use entails awareness of and adherence to this Policy, in the manner provided therein.
0.3. Last updated: 2026-07-24. This version takes effect on June 16, 2026. Subsequent amendments observe the provisions of Section 16.
0.4. Language prevalence. This Policy is drafted in Brazilian Portuguese, the sole binding and enforceable version. Any translation into another language is intended for the reader’s convenience and produces no autonomous effects; should there be any discrepancy in meaning between the Portuguese version and any translation, the Portuguese version prevails (a clause also reproduced in the English edition).
1. Definitions
For the purposes of this Policy, the terms below, in the singular or plural, have the meaning assigned below. The binding terms are those indicated in Portuguese; the English expression in parentheses is reserved for the translation.
1.1. Titular (data subject): the natural person to whom the processed personal data relate (art. 5, V, of the LGPD). In the context of this Policy, this is typically the Client’s Cardholder.
1.2. Portador do cartão (cardholder): the data subject in the chargeback chain — the end customer of the acquiring or payment institution. They are a third party in relation to the Company and a consumer for the purposes of the Consumer Defense Code — CDC (Law No. 8,078/1990; STJ Precedent 297). They are not a user of the Platform.
1.3. Controlador(a) (controller): the party responsible for decisions concerning the processing of personal data — purposes and means (art. 5, VI, of the LGPD). The Company acts as controller when it reuses Chargeback Data sourced from the Client for its own purposes (Section 3.2).
1.4. Operador(a) (operator / processor): the party that carries out processing on behalf of the controller, according to the controller’s documented instructions (art. 5, VII, of the LGPD). The Company acts as operator when conducting disputes and chargebacks on behalf of the Client, under the Data Processing Agreement (art. 39 of the LGPD). The binding term in Portuguese is “operador”; processor is reserved for the translation.
1.5. Encarregado (Data Protection Officer — DPO): the person designated as the channel of communication between the controller, the data subjects, and the National Data Protection Authority — ANPD (art. 41 of the LGPD), and also the contact for security incidents (Resolution CD/ANPD No. 15/2024). The Company’s Encarregado is yet to be appointed — see Section 14.
1.6. Tratamento (processing): any operation carried out with personal data — collection, storage, use, sharing, deletion, among others (art. 5, X, of the LGPD). The permanent storage of chargebacks is continuous processing, keeping the Company under the full regime of the LGPD for as long as the data subsists.
1.7. Dado pessoal (personal data): information relating to an identified or identifiable natural person (art. 5, I, of the LGPD).
1.8. Dado anonimizado (anonymized data): data relating to a data subject who cannot be identified, considering the technical means reasonably available at the time of processing (art. 5, III and XI, and art. 12 of the LGPD). Anonymized data fall outside the scope of the LGPD to the extent that re-identification is not reasonably possible — a condition that delimits the product-development repository (Section 7).
1.9. Anonimização (anonymization): the process by which data can no longer be associated, directly or indirectly, with a data subject, considering reasonable means (art. 5, XI, and art. 12 of the LGPD), carried out here through one-way keys and the generalization/aggregation of attributes, without direct identifiers. It is conditional: it holds for as long as re-identification is not reasonably possible.
1.10. Legítimo interesse (legitimate interest): the legal basis of art. 7, IX, of the LGPD, for legitimate and concrete purposes of the controller, conditioned upon a documented balancing test (art. 10) and upon safeguards. It does not support sensitive personal data (art. 11).
1.11. Relatório de Legítimo Interesse — LIA (Legitimate Interest Assessment — LIA) or balancing test: the dated record required by art. 10 of the LGPD that structures purpose, necessity, balancing, and safeguards, concluding, conditioned upon the safeguards, as to whether or not the rights of the data subject prevail.
1.12. Direito de oposição (right to object): under art. 18, §2, of the LGPD, the data subject may object to processing carried out on the basis of a hypothesis of waiver of consent, in the event of a breach of the provisions of the LGPD. Independently of this statutory right, the Company undertakes, as a contractual commitment and legitimate-interest safeguard, to assure the data subject the right to object, at any time, to processing grounded in legitimate interest on grounds relating to their particular situation, in which case processing in the controller role ceases with respect to the objecting data subject (Sections 7 and 12).
1.13. Requisição de titular — DSAR (data-subject request — DSAR): a request to exercise the rights of arts. 18 to 22 of the LGPD and, separately, to object (art. 18, §2), recorded and responded to within the legal time frame.
1.14. Cliente / Instituição contratante (Client): any person, natural or legal, who registers on the Platform and uses the Services/APIs by accepting the Terms — among others a payment institution, an acquirer/credenciadora or a sub-acquirer (subadquirente) (whether or not authorized by the Central Bank of Brazil — BCB), a merchant (lojista), or a natural person (pessoa física); the controller of its cardholders’ data for dispute purposes. Any person with access to the website may register.
1.15. PAN truncado (truncated PAN): the only datum derived from the card number ever stored — the BIN of the first 6 digits together with the last 4 digits, at most. There is no field for the full card number.
1.16. Dados de Autenticação Sensíveis — SAD (Sensitive Authentication Data — SAD): CVV/CVC/CVV2/CVC2/CID/CAV2, the full magnetic stripe, and the PIN/PIN block — forbidden from storage by the Company, without exception, even if encrypted; rejected at the Platform’s edge.
1.17. Transferência internacional de dados (international data transfer): any operation that places personal data on infrastructure outside Brazilian territory, subject to a mechanism of art. 33 of the LGPD (Section 9).
1.18. Acordo de Tratamento de Dados — DPA (Data Processing Agreement — DPA): the instrument governing processing in the operator role, in accordance with the Client-controller’s documented instructions (art. 39 of the LGPD), and which does not authorize the Company’s own (controller) use.
1.19. Dados de Chargeback (Chargeback Data): the dispute data processed, as enumerated in Section 4.
1.20. Plataforma and Serviços (Platform / Services): the set of software, API, web interface, and infrastructure provided by the Company for ingestion, storage, assembly of representment packages, contestation and response to disputes, management of reason codes/ARNs, and chargeback evidence files.
2. Origin of the data and to whom this Policy applies
2.1. Origin of the data. The personal data of cardholders processed by the Company are not collected directly from the data subject (cardholder). They originate from the Clients (acquirers, payment institutions, sub-acquirers, merchants and individual registrants), which forward them to the Platform in the course of disputes and chargebacks. This Policy reaches cardholders through the Client, which holds the consumer relationship with them.
2.2. Position of the cardholder. The cardholder is a third party in relation to the Company and a consumer for the purposes of the CDC (STJ Precedent 297). The body of dispute outcomes may constitute a consumer database (art. 43 of the CDC), with the consequences set out in Sections 10, 12, and 13.
2.3. Categories of data subjects and applicable role. This Policy is organized by category of data subject, indicating the applicable role (operator or controller):
(a) Representatives and Authorized Users of the Client who access the API and the Platform interface — registration, authentication, and access-log data, processed to enable and protect access to the Platform; with respect to these data, the Company acts predominantly as controller of the strictly operational access data;
(b) Cardholders (the consumer data subjects, reached through the Client) — the Chargeback Data described in Section 4, processed in the operator role when serving the Client (Section 3.1) and in the controller role when reused for the Company’s own purposes (Section 3.2);
(c) Visitors to the website https://sparsu.com — data strictly necessary to make the website available and, when the visitor requests an analysis, sends a contextual question about an article, or submits the commercial-qualification form, first name, last name, work e-mail, the topic-limited message, and the structured professional and company information described in Section 15 so the Company can assess the request and contact them.
2.4. Territorial scope. This Policy addresses the regime of the LGPD and applicable Brazilian law. Where personal data flow to US-based sub-processors, the United States regime (CCPA/CPRA and the GLBA Safeguards Rule) also applies to that processing, as detailed in the dedicated US section (Section 17).
2.5. Children, adolescents, and the elderly (art. 14 of the LGPD). The Platform is intended for use by adults (professional and individual registrants alike) and is not directed at the direct collection of data of children or adolescents. Where cardholder data forwarded by the Client pertain to a child or adolescent, such data receive the special protection of art. 14 of the LGPD and are processed in the best interest of the child or adolescent. Data of the elderly are treated as a heightened-risk category for the purposes of assessing the severity of any security incident (Resolution CD/ANPD No. 15/2024, art. 5), with the corresponding precautions.
3. Processing agents — the two roles (operator and controller)
The allocation of roles is made by purpose, and not by data set. The Company acts in two roles, kept separate throughout all processing.
3.1. The Company as OPERATOR
3.1.1. The Company acts as operator (art. 5, VII, of the LGPD) when it processes Chargeback Data on behalf of and according to the documented instructions of the Client, within the execution of disputes and chargebacks, under the terms of the Data Processing Agreement (art. 39 of the LGPD).
3.1.2. In this case, the Client is the controller: it defines the purposes, the means, and the retention period and is responsible for the legal basis and the duty of transparency (art. 9) toward its data subjects; the Company is limited to complying with and enforcing such instructions. The legal basis is the performance of a contract (art. 7, V) and/or the Client’s own bases (art. 7, X), passed through by the Data Processing Agreement.
3.2. The Company as CONTROLLER
3.2.1. The Company acts as controller (art. 5, VI, of the LGPD) when, independently determining the purposes and the means, it reuses Chargeback Data sourced from the Client for its own purposes — product analysis and benchmarking and the development, improvement, and provision of its products and services (Sections 6 and 7).
3.2.2. In this case, the processing is governed by this Policy and by the Company’s own legal basis — legitimate interest (art. 7, IX), assessed in a documented balancing test (LIA, art. 10) —, with the data subject being assured the right to object (art. 18, §2).
3.3. Non-erosion of the division of roles
3.3.1. The legal basis of one role is never reused to justify the other. The Data Processing Agreement (operator) does not authorize the Company’s own use (controller); and the purpose restriction of the operator scope does not suppress the separately disclosed right of own use of the controller.
3.3.2. Where the controller role applies, the Company acknowledges the joint and several liability of art. 42 of the LGPD.
3.4. Routing of requests according to the role
3.4.1. Data-subject requests relating to data processed in the OPERATOR role are routed to the Client-controller, with whom the Company cooperates. Requests relating to data processed in the CONTROLLER role are responded to directly by the Company (see Sections 12 and 13).
3.5. The regime of processing in the operator role is detailed in the Data Processing Agreement (DPA) per Client, referenced in the Terms of Use; in the event of a conflict touching cardholder data, the order of precedence set out in the Terms of Use (prevalence of the instrument signed per Client) governs the resolution.
4. Categories of personal data processed
4.1. In the operator role and, when reused, in the controller role, the Company processes the following categories of Chargeback Data in its operational repository:
(a) truncated card data — the BIN of the first 6 digits and the last 4 digits; (b) the card network (e.g., Visa, Mastercard, Elo, Hipercard, Amex); (c) ARN — acquirer reference number; (d) the dispute reason code; (e) the transaction amount and currency; (f) the merchant name; (g) the device identifier — device fingerprint; (h) the cardholder’s name, e-mail, and document fragment; (i) the dispute status; (j) the record’s source/origin — source feed; and (k) evidence-file metadata — storage pointer, content type, and SHA-256 hash.
4.2. The device identifier (device fingerprint) is a persistent online identifier (art. 5, I, of the LGPD) and is on the ANPD’s high-risk radar; it is processed with a sensitivity flag and discarded at the anonymization boundary (Section 7).
4.3. The evidence-file metadata are governed as personal data because the underlying files routinely contain cardholders’ personal data.
4.4. With respect to the Client’s Authorized Users, the Company processes registration data, credentials, and application access logs, in the manner set out in Sections 2.3(a) and 11.
5. Data minimization — what is NEVER stored
5.1. Principle (art. 6, III, of the LGPD). The Company observes the principle of necessity, limiting processing to the indispensable minimum. As to the card number, only the truncated PAN is stored (the BIN of the first 6 plus the last 4 digits), at most; the full card number (full PAN) is never stored.
5.2. Data never stored. The Company never stores, under any circumstances, even if encrypted:
(a) the full card number (full PAN); (b) CVV/CVC/CVV2/CVC2/CID/CAV2 (verification code); (c) the PIN or PIN block; (d) the full magnetic stripe (track/track1/track2); — items (b) to (d) constitute Sensitive Authentication Data (SAD); and (e) the full CPF/CNPJ — only a fragment of up to 8 characters of the document is processed.
5.3. No recombinable second representation. The Company does not maintain any second representation of the card number (such as a hash, token, or alternative truncation of the same PAN) that, combined with the truncated PAN, would allow the number to be reconstructed.
5.4. Legitimate-interest safeguard. The minimization described here is a present and true fact and constitutes an essential safeguard of the balancing test that grounds the use in the controller role (Section 6).
6. Purposes of processing and legal bases (by purpose)
6.1. The Company observes the principle of specific purpose (arts. 6, I, and 9 of the LGPD): each processing operation corresponds to a determined purpose, there being no generic purpose of “operating the platform”. The legal basis is assigned by purpose.
6.2. Operator purposes.
(a) P1 — Execution of the dispute lifecycle: to ingest, store, assemble representment packages, contest, and respond to chargebacks/disputes on behalf of the Client, observing reason codes, ARNs, evidence files, and the card networks’ deadlines. (b) P2 — Operational retention: to maintain the dispute record for the time necessary to its lifecycle and to the Client’s defense.
Legal basis of P1 and P2: performance of a contract (art. 7, V) and/or the Client’s own bases (art. 7, X), passed through by the Data Processing Agreement (art. 39). In these purposes, the Company is the operator.
6.3. Controller purposes.
(a) P3 — Product analysis and benchmarking; and (b) P4 — Development, improvement, and provision of the Company’s products and services, including analytical and predictive models for fraud prevention and dispute management.
The disclosure language for these purposes is set out in Section 7. Legal basis of P3 and P4: legitimate interest (art. 7, IX), supported by a documented balancing test (LIA, art. 10). In these purposes, the Company is the controller, and the data subject is assured the right to object (art. 18, §2) — see Sections 7, 12, and 13.
6.4. Consent — rejected as the backbone. The Company does not adopt consent as the primary basis for processing, and this is recorded transparently (art. 6, X, accountability), for the following reasons: (i) there is no direct channel with cardholders, who are third parties to the Company; (ii) consent is revocable at any time (art. 8, §5), which would render the processing structurally unstable; and (iii) it is impracticable and fragile for card-dispute data forwarded by Clients, with whom — not the cardholders — the Company has its relationship. The right to revoke consent is preserved only in the cases where consent comes to be effectively used.
6.5. Sensitive data (art. 11). Legitimate interest does not support sensitive personal data. Sensitive data and sensitive inferences are excluded from the product analysis and development repository in the controller role.
6.6. Present and true posture. The Company describes effective commitments. The LIA is conditioned upon the safeguards; some of them — in particular anonymization, the exclusion of sensitive data, the retention limits, transparency, and the objection/request flow — are under implementation, such that the legitimate-interest conclusion is conditional and does not represent an assertion of full compliance at the present time.
7. Product development and the anonymization boundary
7.1. In its capacity as controller, the Company may use the Chargeback Data for the development, improvement, and provision of its products and services, including analytical and predictive models for fraud prevention and dispute management, as well as for product analysis and benchmarking. This processing is grounded in the Company’s legitimate interest (art. 7, IX, of the LGPD), assessed in a documented balancing test (Legitimate Interest Assessment — LIA, art. 10), and observes safeguards, in particular the minimization of the data and anonymization.
7.2. Anonymization boundary (art. 12). The data may be anonymized — through one-way keys and the generalization/aggregation of attributes, without direct identifiers — for the purposes of item 7.1. Once anonymized, and to the extent that re-identification is not reasonably possible by the Company through available means, such data cease to be personal data and fall outside the scope of the LGPD (art. 12).
7.3. Conditional nature. The effect of exclusion from the scope of the LGPD is conditioned upon the reasonable impossibility of re-identification; the Company does not declare absolute or permanent irreversibility. Higher-cardinality identifiers — in particular the device identifier, the ARN, and exact values — are discarded or generalized at the anonymization boundary, as they raise the risk of re-identification.
7.4. Right to object. Under art. 18, §2, of the LGPD, the data subject may object to processing carried out on the basis of a hypothesis of waiver of consent, in the event of a breach of the provisions of the LGPD. Independently of art. 18, §2, the Company assures the data subject, as a legitimate-interest safeguard, the right to, at any time, object to this processing on grounds relating to their particular situation, through the Encarregado’s channel, in which case such processing will cease with respect to the data subject who objected.
8. Sharing and recipients
8.1. The Chargeback Data originate from the Clients (acquirers, payment institutions, sub-acquirers, merchants and individual registrants) and may be shared with sub-operators and other recipients strictly for the provision of the Services and, in the controller role, for the Company’s own purposes (Sections 6 and 7), always with the purpose of the sharing being indicated.
8.2. Categories of recipients. Without prejudice to the per-Client indication, the recipients fall within the following categories of sub-operators: cloud infrastructure providers, object storage, evidence and e-mail storage, and hosting of analytical models. The regime of these sub-operators — internal register and flow-down of obligations — is governed in the Terms of Use and in the Data Processing Agreement.
8.3. Disclosure to third parties only by court order. Stored records, personal data, and the content of communications are made available to third parties only upon a valid court order (arts. 7, II and III, and 10, §§1 and 2, of the Brazilian Civil Rights Framework for the Internet — Law No. 12,965/2014), except for communications to the data subject themselves and to the competent authorities under the terms of the law.
9. International data transfer
9.1. Residency in Brazil by default. Personal data are processed and stored in Brazilian territory by default.
9.2. Mechanisms of art. 33. Any international transfer — such as cross-border transfers to US-based LLM/OCR sub-processors, or to sub-operators located in the European Union or the European Economic Area (EEA) — occurs only under a mechanism of art. 33 of the LGPD:
(a) standard contractual clauses (Resolution CD/ANPD No. 19/2024) for destinations without an adequacy decision; and (b) the adequacy decision for the European Union / EEA (Resolution CD/ANPD No. 32/2026), where the destination falls within the scope of that resolution.
9.3. No conflation of mechanisms. The mechanisms of item 9.2 are not interchangeable. The Company does not treat as adequate, for this purpose, the United Kingdom, Switzerland, or a region outside the EEA of a European supplier, nor does it invoke the European Union adequacy before the existence of an effective flow to a destination within the relevant scope.
9.4. Dates and numbering. The resolutions are cited by their abbreviated name; publication dates and the internal numbering of articles are subject to confirmation by legal counsel and are not asserted here as definitive.
9.5. Secrets and credentials. The custody of operational secrets and credentials (such as keys and connection strings) in a third-party service outside Brazil does not constitute an international transfer of personal data, as these are credentials, not data-subject data; the operational personal data remain resident in Brazil.
10. Retention period and deletion
10.1. Default horizon. Each personal-data record carries a retention horizon (an expiry date on each record); there is no retention for an indefinite period. The default horizon is approximately 5 (five) years, anchored in the consumer-record ceiling of art. 43 of the CDC and in the dispute lifecycle, after which the datum is deleted or anonymized. This period is an adjustable default in the retention policy, and not an absolute value.
10.2. Specific horizons. No single period applies: (a) the application access logs (Civil Rights Framework for the Internet) are kept for at least 6 (six) months, under confidentiality; and (b) the compliance artifacts are kept for at least 5 (five) years.
10.3. CDC rules on negative information. To the extent that the body of data constitutes a consumer database (art. 43 of the CDC) — a characterization to be confirmed with legal counsel —, the following rules are observed:
(a) negative information on a dispute outcome (such as a lost chargeback or confirmed fraud) linked to a cardholder is not kept or made available in a credit-record or scoring context beyond 5 (five) years (art. 43, §1); and (b) once the statute of limitations relating to the collection has run, no information is made available that prevents or hinders renewed access to credit (art. 43, §5).
10.4. Deletion. Deletion occurs upon the end of the purpose, by data-subject request, and by ANPD determination, reaching the primary repository and, where feasible, the derived data sets.
10.5. Prior notice of the opening of a record (art. 43, §2, of the CDC). Dispute records are, by their nature, opened without the cardholder’s request. In this case, art. 43, §2, of the CDC requires prior written notice to the consumer of the opening of the record. This notice is given through the Client institution, which holds the consumer relationship with the cardholder (consistent with the operator-role routing described in Section 3.4); the Company cooperates with the Client to enable it.
11. Information security
11.1. The Company adopts and/or is implementing the following technical and administrative security measures suitable to protect personal data (arts. 46 to 49 of the LGPD; art. 7, VIII, and art. 10, §4, of the Civil Rights Framework for the Internet; arts. 13 and 16 of Decree No. 8,771/2016). Some of these controls are under implementation, consistent with the provisions of Section 6.6, and it is not asserted that the entire set is fully operational at the present time:
(a) minimization at ingestion and PAN truncation (Section 5); (b) encryption in transit (TLS) and at rest, with key management; (c) role-based access control and least privilege; (d) multi-factor authentication (MFA) for access to personal data; (e) audit logging with a detailed inventory of accesses (identification of the agent, date/time, and resource accessed); and (f) logical segregation per Client.
11.2. Such measures are presented as adopted and/or under implementation by the Company.
11.3. The secret anonymization key and the other secrets are never recorded in a log.
12. Data-subject rights
12.1. The Company assures the data subject the exercise of the rights provided for in arts. 18 to 22 of the LGPD, in particular:
(a) confirmation of the existence of processing and access to the data (art. 18, I and II); (b) correction of incomplete, inaccurate, or outdated data (art. 18, III); (c) anonymization, blocking, or deletion of unnecessary, excessive, or non-compliantly processed data (art. 18, IV); (d) portability (art. 18, V); (e) deletion of data processed with consent (art. 18, VI); (f) information on sharing (art. 18, VII); (g) information on the possibility of not consenting and on the consequences of refusal (art. 18, VIII); and (h) revocation of consent (art. 18, IX), where consent is the basis used.
The numbering of the art. 18 incisos indicated above is subject to confirmation by legal counsel against the consolidated text in force, so that any renumbering or revision does not affect the substance of the rights assured. The form and time frame for confirmation and access are further governed by art. 19 of the LGPD (Section 13).
12.2. Right to object (art. 18, §2) — highlight. Under art. 18, §2, of the LGPD, the data subject may object to processing carried out on the basis of a hypothesis of waiver of consent, in the event of a breach of the provisions of the LGPD. Separately, and independently of that provision, the Company assures the data subject, as a contractual commitment and legitimate-interest safeguard, the right to object, at any time, to processing grounded in legitimate interest on grounds relating to their particular situation. Once the objection is exercised, processing in the controller role (purposes P3 and P4) ceases with respect to the data subject who objected. This right is disclosed and honored autonomously, even though it does not correspond to one of the request types currently cataloged in the system.
12.3. Consequences of not providing data (art. 9, II). Transparently: (a) with respect to data processed in the operator role, the cardholder does not provide data directly to the Company — the data are forwarded by the Client —, such that there is no “refusal” opposable to the Company; and (b) with respect to processing in the controller role, the control instrument available to the data subject is the right to object (art. 18, §2), and not the refusal of consent.
12.4. Consumer-law layer (CDC). Additionally, the cardholder, in their capacity as consumer: (a) has the right of access to the data held and to their sources (art. 43, caput, of the CDC); and (b) may demand correction, with communication to any recipients of the corrected information within 5 (five) business days (art. 43, §3) — a shorter and stricter period than the LGPD standard, reaching the derived data sets and attributes.
12.5. Petition and complaint. The data subject may petition in relation to their data before the Company and file a complaint with the ANPD (art. 18, caput, and §1, of the LGPD); in their capacity as consumer, they may also resort to the consumer-protection bodies (such as Procon).
12.6. Civil Rights Framework right. Without prejudice to the LGPD deletion right, the data subject has the right to the definitive deletion of personal data upon the end of the relationship, by request, except in the cases of mandatory retention (art. 7, X, of the Civil Rights Framework for the Internet).
12.7. Exercise by role. With respect to data processed in the operator role, the rights are exercised through the Client-controller, with whom the Company cooperates; with respect to data processed in the controller role, directly before the Company (Section 13).
12.8. Automated decisions. The data subject may request review of automated decisions (art. 20 of the LGPD). It is clarified that the outputs of the Company’s analytical and predictive models concern the dispute, and do not constitute an automated decision producing legal effects or significant impact on the person of the cardholder.
13. How to exercise rights
13.1. Single channel. Requests to exercise rights must be addressed to the Encarregado by e-mail at comercial@sparsu.com.
13.2. Identity verification. The Company adopts an identity-verification step for the requester and admits exercise through a duly authorized representative.
13.3. Response time. The Company responds within the legal time frame: it may provide an immediate, simplified response or a complete response within the applicable legal time frame (art. 19, §2, of the LGPD). For corrections, the stricter 5 (five) business-day period of the CDC (art. 43, §3) is also observed for communication to the recipients of the corrected information, reaching the derived data sets. The exact number of days of the LGPD general time frame will be informed in accordance with the legal regime in force.
13.4. Direct path or via the Client. As the cardholder is a third party reached through the Client, the exercise of rights may take place directly before the Company (data processed in the controller role) or through the Client (data processed in the operator role), with the respective allocation of responsibility indicated in Section 3.4.
13.5. Refusals and scope. Any refusals are recorded with the respective justification. Fulfillment reaches the primary repository and, where feasible, the derived data sets.
14. Data Protection Officer (DPO)
14.1. Pending appointment. The Company’s Encarregado is yet to be appointed. Until the appointment, the e-mail address comercial@sparsu.com is used as the designated channel, with no determinate person being indicated at the present time.
14.2. Unified channel. The same contact constitutes the channel for (a) data-subject communications, (b) communications with the ANPD (art. 41 of the LGPD), and (c) security-incident communications (Resolution CD/ANPD No. 15/2024).
15. Cookies and tracking technologies
15.1. As of the present date, the website https://sparsu.com uses only cookies strictly necessary to its operation. Should non-essential cookies or other tracking technologies come to be used, this Section will be updated with the respective description and, where required, with the collection of the data subject’s consent. In any event, the Company does not store access logs of other internet applications without the data subject’s consent (art. 16, I, of the Civil Rights Framework for the Internet).
15.2. Strictly functional local storage. In addition to the cookies above, the website analysis form uses browser local storage (sessionStorage), limited to temporarily holding what the visitor themselves types — first name, last name and work e-mail — so that the entry is not lost when a panel is accidentally closed, a link is followed, or the page is reloaded. This data stays in the visitor’s browser, is not transmitted to the Company through this local-storage mechanism, and is not used for tracking, profiling, advertising or any form of cross-site identification. The stored content is valid for 5 (five) minutes from the last keystroke; once that period has elapsed, it is discarded on the next page load and is never reused to fill in forms. The storage is bound to the browser tab and is not shared with other tabs; the Company clarifies, however, that the browser may persist it to disk in order to restore the session after a tab is closed or crashes, in which case the 5 (five)-minute period above continues to be applied on read. Attached files are not stored by this mechanism under any circumstances. In the commercial-qualification and contextual blog-inquiry forms, no answer — including first name, last name, e-mail, and message — is written to sessionStorage: the entry remains only on the current page until submission or until the visitor leaves. The independent transmission of data is described next.
15.3. Contact for the analysis response. When a visitor fills in their first name, last name and work e-mail in “Where we should send the response,” the notice beside those fields explains that these three details will be sent to the Company once they are complete and valid and the visitor pauses briefly — or when the visitor leaves the page — even without activating the final button. The sole purpose is to respond to the requested analysis and conduct the preliminary steps requested by the visitor; the Company acts as controller under art. 7, V, of the LGPD. The only consequence of not providing all three fields is that the visitor will not receive this contact.
15.4. Commercial qualification. Through the “Discuss my operation” and “Open the contact page” buttons, the visitor may submit, in addition to their first name, last name and work e-mail, the following data: company name and optional website, role or title, operation profile, company size, and monthly chargeback-count and value ranges. The “Other” operation-profile option reveals a text field with five visible lines and a 1,000-character limit. This information is transmitted only when the visitor activates “Send information.” Its purpose is to understand the request, prepare the commercial contact, and internally order follow-up; the Company acts as controller under art. 7, V, of the LGPD. An internal score is calculated from the structured answers to support the order of human review, without automated rejection, a disqualification message, or any legal or similarly significant effect on the visitor. The only consequence of not providing the required fields is being unable to submit this request.
15.5. Contextual article inquiry. In articles that offer this contact, the visitor may submit their first name, last name, the e-mail entered in the “Work e-mail” field, and an editable message limited to 500 characters, accompanied by a fixed topic identifying the article. Technical validation checks the e-mail format but does not verify that its domain is corporate. The message starts with the content context already filled in and is transmitted only when the visitor activates “Send message.” The form tells the visitor not to include a full card number, CVV, PIN, documents, or cardholder data; the backend rejects patterns of sensitive authentication data and full card numbers before forwarding the notification. That filter does not identify every possible category of personal data in free text. The sole purpose is to understand and respond to the requested question; the Company acts as controller under art. 7, V, of the LGPD. The only consequence of not providing the required fields is being unable to submit the request.
15.6. These flows do not offer file upload or read spreadsheets, PDFs, or documents, and they do not request structured Chargeback Data fields. The website sends the fields described in Sections 15.3 through 15.5, the language, and the fixed source identifier to the Company’s backend; for the blog form, it also sends the fixed topic and the bounded message. Because the message is editable, it may contain information outside the stated purpose entered by the visitor. It is treated as personal free text, and the form instruction remains applicable even with the PAN and sensitive-authentication-data filter. The backend forwards the notification and, for the commercial flow, the internal prioritization to a fixed internal mailbox through the transactional e-mail provider Resend. To limit abuse, the application code holds, for up to 1 (one) hour and in memory only, a keyed pseudonymous digest derived from the connection IP; the raw IP is not persisted by this flow in application code. Identical submissions are identified, also by a keyed in-memory digest only, for up to 24 (twenty-four) hours.
15.7. The notification in the internal mailbox is retained for up to 6 (six) months after the last contact related to the request, unless a shorter period, a data-subject request, or a specific legal duty applies. Resend documents a default e-mail-data retention period of 30 (thirty) days and storage of metadata, logs, and API data in the United States; that international transfer is recorded in the Company’s ROPA and is subject to the LGPD art. 33 safeguards described in Section 9. The visitor may exercise the Section 12 rights through the channel in Section 13.
16. Amendments to this Policy
16.1. The Company may revise this Policy, upon notice through https://sparsu.com, indicating the respective effective date. This Policy describes only the present reality of the processing, containing no speculative forecasts as to future purposes or products.
16.2. Material amendments are communicated; the continuation of the relationship after the new version takes effect entails awareness of the amendments.
17. United States regime (CCPA/CPRA and GLBA) — active commitments
This Section governs the processing of personal data that takes place under, or flows into, the United States legal regime, as a live commitment of the Company’s go-to-market. It complements, and does not replace, the LGPD regime described above; where the United States regime applies to a given processing operation, both regimes apply cumulatively. These commitments are substantiated by the Company’s internal CCPA, GLBA, and FTC-Act compliance records, available to clients and regulators on request.
17.1. Explicit disclosure of ML/AI model training
17.1.1. Yes — the Company trains its own models on Chargeback Data. Plainly and without euphemism: the Company reuses the Chargeback Data it permanently stores to train its own machine-learning models, specifically dispute-triage models (which classify and route disputes) and win-probability models (which estimate the likelihood of a successful representment). This is a secondary purpose of the Company, for its own benefit, distinct from running disputes on behalf of the Client.
17.1.2. Purpose. The purpose of this training is to develop, improve, and provide the Company’s products and services for dispute triage and management, as already described in Sections 6.3 (P4) and 7. The model outputs concern the dispute, not the person of the cardholder (Section 12.8).
17.1.3. Anonymization safeguard. This training observes the anonymization boundary of Section 7.2: higher-cardinality identifiers (in particular the device identifier, the ARN, and exact values) are discarded or generalized, and the data are anonymized through one-way keys and the generalization/aggregation of attributes, to the extent that re-identification is not reasonably possible (art. 12 of the LGPD). Sensitive data and sensitive inferences are excluded from the training repository (Sections 6.5 and 7.1). The conditional nature of anonymization stated in Section 7.3 applies here in full.
17.2. Controller / “business” determination for the ML use
17.2.1. For the model-training use described in Section 17.1, the Company is an independent controller under the LGPD and makes a firm determination that it is a “business” under the CCPA/CPRA (Cal. Civ. Code §1798.140(d)) — the entity that determines the purposes and means of that processing. The Company does not claim service-provider/contractor shelter for this own-use ML; that shelter is reserved for the dispute work it performs on behalf of the Client, which is governed by the Data Processing Agreement carrying the CCPA service-provider/contractor certification in force. Conflating the two lanes is expressly rejected (Section 3.3).
17.3. CCPA/CPRA consumer rights
17.3.1. With respect to the personal information of California consumers (cardholders) processed by the Company as a business, the Company honors the following rights:
(a) Right to know / access — to know the categories and specific pieces of personal information collected, the sources, the purposes (including the own-use ML purpose), and the categories of recipients (Cal. Civ. Code §§1798.100, .110, .115); (b) Right to delete (§1798.105) — propagated to the raw store and, where feasible, to the derived ML datasets; (c) Right to correct (§1798.106) — reaching the dispute store and any derived features; (d) Right to opt out of sale/sharing (§§1798.120, .135) — the Company does not sell and does not share personal information for cross-context behavioral advertising, and maintains a “Do Not Sell or Share My Personal Information” capability regardless; (e) Right to limit the use of sensitive personal information (SPI) (§1798.121) — truncated PAN, cardholder financial-account fragments, and document fragments are treated as SPI, and the SPI→ML flow is gated so that SPI use does not escape the limitation; (f) Global Privacy Control (GPC) — the Company honors GPC browser/agent signals as a binding opt-out of sale/sharing, deterministically (no model in the loop), as a mandatory mechanism (§1798.135(b)).
17.4. LGPD titular rights (cross-reference)
17.4.1. The rights of the data subject (titular) under arts. 18 to 22 of the LGPD — confirmation/access, correction, anonymization/blocking/deletion, portability, information on sharing, revocation of consent, and the right to object to legitimate-interest processing (art. 18, §2) — are assured in full as set out in Section 12, and are exercised through the channel of Section 13. The exercise of these rights is not diminished by the cumulative application of the United States regime.
17.5. Sensitive personal / financial-data handling
17.5.1. The Company treats truncated PAN, cardholder financial-account fragments, and document fragments as sensitive personal information for CCPA/CPRA purposes and as nonpublic personal information (NPI) for GLBA Safeguards Rule purposes (15 U.S.C. §§6801–6809; 16 CFR Part 314). The Company adopts a written information-security program satisfying the Safeguards Rule on both the service-provider and the financial-institution reading, layered on top of the security measures of Section 11. The data-minimization posture of Section 5 (no full PAN, no SAD) is an essential safeguard here as well.
17.6. International transfers United States ↔ Brazil
17.6.1. Personal data are resident in Brazil by default (Section 9.1). Where data flow to US-based sub-processors (in particular contemplated LLM/OCR sub-processors), that transfer occurs only under a mechanism of art. 33 of the LGPD (Section 9.2(a) — standard contractual clauses) and is simultaneously subject to the United States regime described in this Section. Transfers out of the United States back to Brazil follow the same default of Brazilian residency.
17.7. FTC Act §5 substantiation
17.7.1. The disclosures in this Section are made to be specific, current, and substantiated by the Company’s internal processing, consistent with Section 5 of the FTC Act (15 U.S.C. §45) and the FTC’s algorithmic-disgorgement posture, as substantiated by the Company’s internal FTC-Act compliance records. The safeguards marked as under implementation in Sections 6.6, 7.3, and 11.1 remain so marked here; the Company does not over-claim a safeguard not yet built.
17.8. Contact
17.8.1. Requests and communications under the United States regime are addressed to the same unified channel as the LGPD requests: comercial@sparsu.com (Sections 13 and 14). [CONFIRM: whether a separate US-facing privacy contact or toll-free method is required for CCPA notice-at-collection — to be confirmed with legal counsel.]
18. Applicable law and contact
18.1. Applicable law. This Policy is governed by Brazilian legislation, in particular the LGPD (Law No. 13,709/2018); the ANPD is the competent authority. The United States regime of Section 17 applies cumulatively to the processing it describes.
18.2. Contact. Data Protection Officer (Encarregado): to be appointed; channel: comercial@sparsu.com. Controller: Sparsu, conducted by Antônio Amaral Egydio Martins (legal entity in formation), domiciled in São Paulo/SP, Brazil.
18.3. Prevalence and effectiveness. It is reaffirmed that the Portuguese version prevails over any translation in the event of a discrepancy. Last updated: 2026-07-24.
This Policy forms part of and is referenced by the Terms of Use of the Platform. The Portuguese version is the sole binding version; the English version is a faithful translation for the reader’s convenience.