Privacy Policy

Version 1.0 · Effective from: 22 July 2026

This is an English translation provided for convenience. Taito is operated in Brazil and this Policy is governed by Brazilian law, in particular the Brazilian General Data Protection Law (LGPD — Law No. 13.709/2018). In case of divergence, the Portuguese version at /privacidade prevails.

1. Who is the controller of your data

Personal data collected by the Taito platform (taito.app.br and subdomains) is processed by BGR Soluções Corporativas Ltda, enrolled under CNPJ No. 36.723.944/0001-34, with registered office at Rua Francisco Aureliano Paiva, 747, Jardim Europa, Varginha/MG, ZIP 37018-414, Brazil ("Taito", "we").

Data Protection Officer (DPO): Jocsã Cesar Naves. For any question about your data, contact our DPO at:

privacidade@universidadebgr.com.br

2. Who this policy applies to

  • Visitors to the public portal taito.app.br.
  • Registered users (members, leaders, managers, HR consultants).
  • Assessed employees within a client company.
  • Candidates who apply for jobs through the platform.
  • Partners who integrate our API.

3. What personal data we collect

Category Examples Source
Identification and contact name, e-mail, phone/WhatsApp you, on sign-up or invitation
Professional data role, company, team you or the client company
Address delivery address (when there is a physical product) you
Candidate data name, e-mail, WhatsApp, message and résumé (PDF) you, when applying
Behavioural assessment data Mapa da Excelência answers, results, IDP, feedback you, when responding
Psychosocial assessment data (NR-1) answers and results of instruments (COPSOQ, JSS, EEP, among others) you, when responding
Financial data billing and payment data you and Mercado Pago (we do not store card data)
Navigation and access data IP address, usage and performance data, access logs automatically, when using the platform
Communication preferences marketing consent you, when you opt in

4. Sensitive personal data — special care

The Mapa da Excelência answers, results, IDP and feedback reveal behavioural traits and, in psychosocial risk (NR-1) assessments, may reveal aspects related to health and well-being. We treat this information as sensitive personal data (art. 5, II, LGPD), with reinforced care, and use it exclusively for the purposes described below.

Two uses, handled differently:

  • Company psychosocial risk mapping (NR-1): done anonymously and in aggregate — it does not identify you individually.
  • Your individual (named) result, visible to your manager/consultant: only with your specific and highlighted consent, given per assessment, to guide your development, never to penalise you. You may refuse without prejudice and withdraw at any time — withdrawal applies going forward and does not undo processing already carried out lawfully (art. 8, §5).

5. Purposes and legal bases

Purpose Legal basis (LGPD)
Provide the platform and perform the contracted service Performance of a contract (art. 7, V)
Map company psychosocial risks (NR-1) anonymously/in aggregate (sensitive data) Controller's regulatory obligation — art. 11, II, "a" (NR-1 requires the mapping in the PGR)
Make the individual (named) result available to your manager/consultant to guide development (IDP) Specific and highlighted consent — art. 11, I (voluntary, revocable, per assessment)
Apply the Mapa to those who respond voluntarily, outside a regulatory obligation (e.g., an individual on the portal) Specific and highlighted consent — art. 11, I
Assess candidates in selection processes (contact and application data) Preliminary contractual procedures, at the data subject's request (art. 7, V)
Apply a behavioural assessment (competency Mapa) to a candidate Specific and highlighted candidate consent — art. 11, I (NR-1 psychosocial assessment does not apply to candidates)
Process payments and issue billing Performance of a contract (art. 7, V) and legal obligation (art. 7, II)
Send marketing communications Consent (art. 7, I), revocable at any time
Log access, ensure security and prevent fraud Legitimate interest and security (art. 7, IX and X) and the legal duty to retain access logs (Brazilian Internet Framework Act, art. 15)
Measure aggregate usage and performance, via our own cookieless analytics (Umami), to improve the platform Legitimate interest (art. 7, IX)
Comply with legal and regulatory obligations Legal obligation (art. 7, II)

Automated decisions: where an automated assessment (for example, comparing your profile to a role, or ranking candidates) may affect your interests, you have the right to request a review of that decision (art. 20, LGPD), through the DPO channel.

6. Who we share with

We do not sell your data. We share only as necessary, with two distinct types of third party:

a) Processors — process data on our behalf, under a data protection agreement (art. 39, LGPD):

Processor Purpose Location Transfer safeguard
Brevo (Sendinblue SAS) marketing e-mail delivery France (EU) adequate-level country (art. 33, I — ANPD Resolution 32/2026)
Google transactional e-mail / Workspace USA Brazilian standard contractual clauses (art. 33, II, "b")
Linode / Akamai hosting and backup USA Brazilian standard contractual clauses (art. 33, II, "b")
Cloudflare network security, CDN and attack protection USA (global network) contractual clauses + additional safeguards (art. 33, II)

b) Independent controller — processes data on its own account for its own purposes and legal obligations:

Third party Purpose Location
Mercado Pago payment processing (we do not store card data) Brazil/Argentina

When you complete a payment, we share with Mercado Pago the data needed (such as e-mail and amount) to perform the contract (art. 7, V, LGPD); Mercado Pago is an independent controller of that data, responsible for its own processing.

International transfers: where a processor is located outside Brazil, we adopt the art. 33 LGPD safeguards indicated in the table above — an adequacy decision (EU) or standard contractual clauses.

7. Cookies and usage analytics

We use a first-party, cookieless analytics tool (Umami) that measures usage in aggregate to improve the platform. We do not use social-media pixels to track your behaviour.

8. Information security

We adopt technical and administrative measures to protect your data, including encryption at rest of the most sensitive data, with a strong algorithm (XChaCha20-Poly1305, with a random nonce per operation) and keys stored outside the source code:

  • Recruitment data (résumés), address, payment data and access credentials are encrypted at rest with per-client segregated keys.
  • Results, scores and free-text of the behavioural assessments (Mapa, IDP, feedback) and the answers and results of the psychosocial (NR-1) instruments are encrypted at rest.
  • Access to all of this is controlled by role and, for the individual named result, conditioned on your consent (section 4).

No system is infallible; we follow good practices and continuously review our controls.

9. How long we keep your data

We keep your data only for as long as necessary for the purposes of this policy and to comply with legal obligations (arts. 15 and 16, LGPD). Reference periods are:

Category Reference period
Identification/contact and professional data while the account is active + 6 months after closure, then anonymised
Behavioural/psychosocial data (Mapa, IDP, feedback) 90 days after termination or consent withdrawal, then anonymised; the anonymous NR-1 aggregate is preserved
Candidate / résumé up to 6 months in the talent pool, unless deletion is requested
Access logs (IP, login date/time) 6 months (Brazilian Internet Framework Act, art. 15)
Financial / billing data 5 years (tax periods — National Tax Code, arts. 173 and 174)
Proof of marketing consent while active + 5 years after withdrawal

Where data serves as evidence in an employment relationship, its retention may follow the specific periods of labour and social-security law.

You may request the deletion of data processed on the basis of consent, through the DPO channel (section 12), except for the cases of mandatory retention provided by law (art. 16, LGPD).

10. Your rights as a data subject (art. 18, LGPD)

You may, at any time: confirm the existence of processing; access your data; correct incomplete or outdated data; request anonymisation, blocking or deletion of unnecessary data or data processed in non-compliance; request portability; obtain information about sharing; withdraw consent; and request review of automated decisions (art. 20).

How to exercise: write to privacidade@universidadebgr.com.br. We will respond within 15 days (art. 19, I and II, LGPD).

On marketing consent: when you opt in to receive communications, we record your statement (date, time and version of this policy) as proof. You may withdraw it at any time, as easily as you gave it, in your profile or via the unsubscribe link.

11. Changes to this policy

We may update this policy. When we do, we change the effective date above and, for material changes, we notify you through the platform's channels.

12. Contact

Data Protection Officer — privacidade@universidadebgr.com.br.

You may also petition the Brazilian National Data Protection Authority (ANPD): https://www.gov.br/anpd.