JCrave

Legal

Compliance with the LGPD.

Brazil's General Data Protection Law (Law 13.709/2018) regulates the processing of personal data in Brazil. See how JCrave applies the LGPD in our own systems and in the systems we deliver to clients.

Last updated · April 2026

01

Principles

We process personal data based on the LGPD principles: purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination and accountability.

03

Client data we process

In projects where we process third-party data (the client's clients, for example), we act as the Operator. The Controller is the contracting client, who defines the processing purposes.

We apply appropriate technical measures: encryption, role-based access, audit logging, retention policy and secure data disposal.

04

LGPD in the systems we deliver

  • Restricted access by user profile and hierarchical level
  • Audit logging of every relevant action
  • Data encryption in transit (TLS) and at rest
  • Retention policy configurable per data type
  • Export and deletion mechanisms upon data subject request
  • Explicit opt-in for marketing communications
  • Data flow documentation (Data Mapping)
05

Data subject rights

The data subject can exercise their rights under art. 18 of the LGPD by contacting suporte@jcrave.tech. We respond within 15 business days.

06

Data Protection Officer

For data protection matters, the official channel is suporte@jcrave.tech.

07

Incidents

In case of an incident involving personal data, we notify the Brazilian National Data Protection Authority (ANPD) and affected data subjects within a reasonable timeframe, as required by the LGPD. The channel for responsible vulnerability disclosure is suporte@jcrave.tech.