Kockpit · GLIP
Privacy and Data Protection Policy
How GLIP and Kockpit collect, process, store and protect personal data across their operations and services.
Last updated: June/2026
I. Purpose and Scope
GLIP and Kockpit (jointly, the “Platforms” or the “Company”) are unequivocally committed to the privacy, confidentiality and protection of the personal data of their users, clients and partners. This Privacy Policy sets out, clearly and transparently, how such data is collected, used, stored, shared and disposed of in the context of the Platforms' digital operations and services.
II. Data Collection and Purposes
We collect only data strictly necessary to enable, maintain and improve the contracted services, observing the principles of purpose, adequacy and necessity set out in applicable law. The collected data falls into the following categories:
- Registration data: name, work email, phone and role. Purpose: user identification, access authentication, contract management and institutional communications.
- Browsing and technical data: IP address, essential cookies, access logs, application records and performance data. Purpose: security, fraud prevention, compliance with legal obligations (notably the Brazilian Civil Rights Framework for the Internet — Law 12.965/2014) and continuous user-experience improvement.
- Client operational data: information extracted from integrated systems (ERPs, SPED ECD and similar sources) under express authorization from the corporate client. Purpose:delivery of the contracted management-intelligence services.
III. Legal Bases
Data processing is grounded in the legal hypotheses set out in articles 7 and 11 of the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD), in particular: performance of a contract; compliance with legal or regulatory obligation; legitimate interest; and consent, where applicable.
IV. Data Sharing
The Platforms do not sell personal data. Any sharing occurs exclusively with operators and subprocessors strictly necessary for service delivery (cloud infrastructure, authentication and analytics providers), all bound by contractual confidentiality and data protection obligations.
V. Storage and Retention
Data is stored in secure environments, with retention limited to the period required to fulfill the stated purposes or legal and regulatory obligations, and is then disposed of or anonymized at the end of its lifecycle.
VI. Data-Subject Rights
The data subject may, at any time, exercise the rights provided in article 18 of the LGPD by contacting the Data Protection Officer (DPO) through the channel listed at the end of this Policy.
Questions about this document? Reach out to GLIP/Kockpit's Data Protection Officer (DPO): . dpo@glip.com.br.
