1. Who is the controller of your data
Personal data collected by the Taito platform (taito.app.br and subdomains) is processed by BGR Soluções Corporativas Ltda, enrolled under CNPJ No. 36.723.944/0001-34, with registered office at Rua Francisco Aureliano Paiva, 747, Jardim Europa, Varginha/MG, ZIP 37018-414, Brazil ("Taito", "we").
Data Protection Officer (DPO): Jocsã Cesar Naves. For any question about your data, contact our DPO at:
privacidade@universidadebgr.com.br
2. Who this policy applies to
- Visitors to the public portal taito.app.br.
- Registered users (members, leaders, managers, HR consultants).
- Assessed employees within a client company.
- Candidates who apply for jobs through the platform.
- Partners who integrate our API.
3. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identification and contact | name, e-mail, phone/WhatsApp | you, on sign-up or invitation |
| Professional data | role, company, team | you or the client company |
| Address | delivery address (when there is a physical product) | you |
| Candidate data | name, e-mail, WhatsApp, message and résumé (PDF) | you, when applying |
| Behavioural assessment data | Mapa da Excelência answers, results, IDP, feedback | you, when responding |
| Psychosocial assessment data (NR-1) | answers and results of instruments (COPSOQ, JSS, EEP, among others) | you, when responding |
| Financial data | billing and payment data | you and Mercado Pago (we do not store card data) |
| Navigation and access data | IP address, usage and performance data, access logs | automatically, when using the platform |
| Communication preferences | marketing consent | you, when you opt in |
4. Sensitive personal data — special care
The Mapa da Excelência answers, results, IDP and feedback reveal behavioural traits and, in psychosocial risk (NR-1) assessments, may reveal aspects related to health and well-being. We treat this information as sensitive personal data (art. 5, II, LGPD), with reinforced care, and use it exclusively for the purposes described below.
Two uses, handled differently:
- Company psychosocial risk mapping (NR-1): done anonymously and in aggregate — it does not identify you individually.
- Your individual (named) result, visible to your manager/consultant: only with your specific and highlighted consent, given per assessment, to guide your development, never to penalise you. You may refuse without prejudice and withdraw at any time — withdrawal applies going forward and does not undo processing already carried out lawfully (art. 8, §5).
5. Purposes and legal bases
| Purpose | Legal basis (LGPD) |
|---|---|
| Provide the platform and perform the contracted service | Performance of a contract (art. 7, V) |
| Map company psychosocial risks (NR-1) anonymously/in aggregate (sensitive data) | Controller's regulatory obligation — art. 11, II, "a" (NR-1 requires the mapping in the PGR) |
| Make the individual (named) result available to your manager/consultant to guide development (IDP) | Specific and highlighted consent — art. 11, I (voluntary, revocable, per assessment) |
| Apply the Mapa to those who respond voluntarily, outside a regulatory obligation (e.g., an individual on the portal) | Specific and highlighted consent — art. 11, I |
| Assess candidates in selection processes (contact and application data) | Preliminary contractual procedures, at the data subject's request (art. 7, V) |
| Apply a behavioural assessment (competency Mapa) to a candidate | Specific and highlighted candidate consent — art. 11, I (NR-1 psychosocial assessment does not apply to candidates) |
| Process payments and issue billing | Performance of a contract (art. 7, V) and legal obligation (art. 7, II) |
| Send marketing communications | Consent (art. 7, I), revocable at any time |
| Log access, ensure security and prevent fraud | Legitimate interest and security (art. 7, IX and X) and the legal duty to retain access logs (Brazilian Internet Framework Act, art. 15) |
| Measure aggregate usage and performance, via our own cookieless analytics (Umami), to improve the platform | Legitimate interest (art. 7, IX) |
| Comply with legal and regulatory obligations | Legal obligation (art. 7, II) |
Automated decisions: where an automated assessment (for example, comparing your profile to a role, or ranking candidates) may affect your interests, you have the right to request a review of that decision (art. 20, LGPD), through the DPO channel.
6. Who we share with
We do not sell your data. We share only as necessary, with two distinct types of third party:
a) Processors — process data on our behalf, under a data protection agreement (art. 39, LGPD):
| Processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Brevo (Sendinblue SAS) | marketing e-mail delivery | France (EU) | adequate-level country (art. 33, I — ANPD Resolution 32/2026) |
| transactional e-mail / Workspace | USA | Brazilian standard contractual clauses (art. 33, II, "b") | |
| Linode / Akamai | hosting and backup | USA | Brazilian standard contractual clauses (art. 33, II, "b") |
| Cloudflare | network security, CDN and attack protection | USA (global network) | contractual clauses + additional safeguards (art. 33, II) |
b) Independent controller — processes data on its own account for its own purposes and legal obligations:
| Third party | Purpose | Location |
|---|---|---|
| Mercado Pago | payment processing (we do not store card data) | Brazil/Argentina |
When you complete a payment, we share with Mercado Pago the data needed (such as e-mail and amount) to perform the contract (art. 7, V, LGPD); Mercado Pago is an independent controller of that data, responsible for its own processing.
International transfers: where a processor is located outside Brazil, we adopt the art. 33 LGPD safeguards indicated in the table above — an adequacy decision (EU) or standard contractual clauses.
7. Cookies and usage analytics
We use a first-party, cookieless analytics tool (Umami) that measures usage in aggregate to improve the platform. We do not use social-media pixels to track your behaviour.
8. Information security
We adopt technical and administrative measures to protect your data, including encryption at rest of the most sensitive data, with a strong algorithm (XChaCha20-Poly1305, with a random nonce per operation) and keys stored outside the source code:
- Recruitment data (résumés), address, payment data and access credentials are encrypted at rest with per-client segregated keys.
- Results, scores and free-text of the behavioural assessments (Mapa, IDP, feedback) and the answers and results of the psychosocial (NR-1) instruments are encrypted at rest.
- Access to all of this is controlled by role and, for the individual named result, conditioned on your consent (section 4).
No system is infallible; we follow good practices and continuously review our controls.
9. How long we keep your data
We keep your data only for as long as necessary for the purposes of this policy and to comply with legal obligations (arts. 15 and 16, LGPD). Reference periods are:
| Category | Reference period |
|---|---|
| Identification/contact and professional data | while the account is active + 6 months after closure, then anonymised |
| Behavioural/psychosocial data (Mapa, IDP, feedback) | 90 days after termination or consent withdrawal, then anonymised; the anonymous NR-1 aggregate is preserved |
| Candidate / résumé | up to 6 months in the talent pool, unless deletion is requested |
| Access logs (IP, login date/time) | 6 months (Brazilian Internet Framework Act, art. 15) |
| Financial / billing data | 5 years (tax periods — National Tax Code, arts. 173 and 174) |
| Proof of marketing consent | while active + 5 years after withdrawal |
Where data serves as evidence in an employment relationship, its retention may follow the specific periods of labour and social-security law.
You may request the deletion of data processed on the basis of consent, through the DPO channel (section 12), except for the cases of mandatory retention provided by law (art. 16, LGPD).
10. Your rights as a data subject (art. 18, LGPD)
You may, at any time: confirm the existence of processing; access your data; correct incomplete or outdated data; request anonymisation, blocking or deletion of unnecessary data or data processed in non-compliance; request portability; obtain information about sharing; withdraw consent; and request review of automated decisions (art. 20).
How to exercise: write to privacidade@universidadebgr.com.br. We will respond within 15 days (art. 19, I and II, LGPD).
On marketing consent: when you opt in to receive communications, we record your statement (date, time and version of this policy) as proof. You may withdraw it at any time, as easily as you gave it, in your profile or via the unsubscribe link.
11. Changes to this policy
We may update this policy. When we do, we change the effective date above and, for material changes, we notify you through the platform's channels.
12. Contact
Data Protection Officer — privacidade@universidadebgr.com.br.
You may also petition the Brazilian National Data Protection Authority (ANPD): https://www.gov.br/anpd.