Privacy & Data Protection Policy (LGPD) – Trilha CuboPlus
Last updated: 2026-07-20
Trilha CuboPlus, a brand within the technology ecosystem of Cubotimize Soluções em Inteligência Tecnológica LTDA (Av. Rio Branco, 26, Centro – Rio de Janeiro/RJ, ZIP 20090-001, CNPJ 25.002.129/0001-60), takes the privacy and security of corporate information extremely seriously.
This Privacy Policy transparently establishes how personal and corporate data is processed, stored, and protected within the Trilha CuboPlus platform, in full compliance with Brazil's General Data Protection Law (LGPD – Law No. 13.709/2018).
1. Our Key Differentiator: Data Isolation by Digital Capsule
Unlike traditional market solutions (which commonly use shared databases, mixing data and records from multiple clients in the same logical structure), Trilha CuboPlus was designed under a tenant isolation architecture:
- What does this mean in plain terms? It's as if each client company lived in its own exclusive, fortified "digital home." When contracting Trilha CuboPlus, our platform automatically provisions a dedicated digital capsule for your organization.
- Dedicated Database (all plans): your employees' and learning paths' structured data lives in a database exclusively dedicated to your company — it never shares tables with other clients' records. This is our central commitment to data segregation, valid across all plans.
- File and Media Isolation (all plans): Documents (PDF/DOCX/PPTX) and natively hosted videos (a feature available on request on the Custom Enterprise plan) are stored in object infrastructure (Cloudflare R2/Stream) with per-tenant isolation: on every plan, each tenant receives a dedicated storage bucket and a dedicated API key scoped exclusively to that bucket — one tenant's credential only accesses that tenant's storage. Media access is protected by signed URLs with domain lock. Enterprise or Custom-contract clients may negotiate a dedicated storage account or a different provider (e.g., Amazon S3, Google Cloud Storage). This dedicated bucket+key isolation is, on Advanced and Enterprise plans, added to the physically dedicated server and database provided on those plans — noting that Cloudflare R2 object storage runs on Cloudflare's shared edge infrastructure.
- Result: we eliminate cross-data leak risks and offer compliance with the strict IT and LGPD requirements of public agencies and large enterprises.
- Architecture Evolution: Cubotimize reserves the right to evolve the technical infrastructure architecture — including the provisioning method, internal isolation model, or hosting components used — provided that equivalent guarantees of non-mixing of client data and tenant access security are preserved. Any structural change will be communicated with at least 30 (thirty) days' notice by email to the account manager, with the Client's right to not renew the subscription in the next cycle if they disagree with the changes being assured.
2. What Data We Process and For What Purposes?
The platform operates on a B2B model, acting primarily as a Data Processor (while the Client acts as the Controller of their employees' and students' data). We collect and process data for the following purposes:
2.1 Registration and Billing Data (Control Plane):
- Data: Name, business email, phone, CNPJ/CPF, corporate address, and billing data (processed in encrypted form by Stripe or Paddle).
- Purpose: To enable contracting, legal service billing (invoice issuance), support communications, and version updates.
2.2 User and Student Data (Tenant-Level):
- Data: Name, email, and access credentials provided by the Client to register students and employees in their dedicated platform. The platform makes available on all plans authentication via Google Workspace (Google Sign-in), in which public profile data (name and corporate email) may be received directly from Google's identity provider upon user consent in the OAuth 2.0 flow, in accordance with Google's Privacy Policy (https://policies.google.com/privacy).
- Purpose: Creation of student profiles, access control, dashboard personalization, and generation of pedagogical progress reports for administrators.
2.3 Legal Bases for Processing (art. 7 of LGPD):
- Contract execution (art. 7, V): registration, billing, authentication, and capsule provisioning data, necessary to provide the contracted service.
- Compliance with legal/regulatory obligation (art. 7, II): retention of tax and billing data (e.g.: invoice issuance) and legally required record-keeping.
- Legitimate interest (art. 7, IX): information security (anti-bot protection), product telemetry and improvement metrics, and non-conversion/cancellation forms — always with safeguards and without prevailing over data subjects' fundamental rights.
- Consent (art. 7, I): non-essential cookies (telemetry/Google Analytics), collected via preference banner, and the Google OAuth authentication flow.
- Student/employee data (Tenant): Cubotimize acts as Processor and handles it according to the instructions and legal basis defined by the Client (Controller), pursuant to art. 39 of LGPD.
3. Processing of Materials by Artificial Intelligence (Google API)
The instant generation of corporate learning paths uses state-of-the-art intelligent processing:
- Secure Flow: Corporate documents (PDF, DOCX, PPTX) and video/audio media uploaded by managers are processed through Google's AI APIs, always in paid (billed) mode, appropriate to the contracted tier:
- All plans (Starter, Standard, Advanced, and Custom Enterprise): processing via Google AI Studio (Google AI) on the paid plan, in accordance with the Gemini API Terms of Service (https://ai.google.dev/gemini-api/terms). The infrastructure for this processing may be located outside Brazil.
- In-country AI processing residency (upon request): government or regulated contracts that require AI processing within national territory may, subject to a feasibility study and a specific commercial proposal, be served via Vertex AI (Google Cloud) — with data residency in a Brazilian region (São Paulo), network controls (VPC Service Controls), customer-managed encryption keys (CMEK), and audit logs — in accordance with Google Cloud Terms of Service (https://cloud.google.com/terms).
- No Model Training: In accordance with Google's applicable terms of service for paid use of these APIs, the context materials provided by companies (prompts, documents, and generated responses) are not used to train or improve Google's AI models. Processing fully complies with Google's terms of service, and your trade secrets and operational information remain secure and isolated within Trilha CuboPlus's operational pipeline.
- AI Provider/Model Evolution: Cubotimize may, in the future, change the AI provider or model used (and adapt its proprietary prompts) for technical, financial, or feature improvement reasons, at its discretion, always maintaining this Policy's guarantees — paid plan processing and no use of company data to train models — and focus on product viability and continuity.
- YouTube Videos (No Extraction): for learning paths/lessons based on YouTube videos, the platform does not extract, download, copy, or transcribe the audio, video, or captions from YouTube. The video is merely embedded via YouTube's official player (embed); the AI processes exclusively the description and/or support material about the content that the manager themselves provides, of their own authorship or license (Section 3 of the Terms). No content is scraped from YouTube by the platform.
- Natively Hosted Corporate Videos (Cloudflare Stream — Custom Enterprise, on request): when native video hosting via Cloudflare Stream is contracted, the audio/content of the corporate video uploaded by the manager may be processed and transcribed by the AI to generate study material. This processing occurs only on the contracted feature (Custom Enterprise); data remains isolated per tenant, with no use for model training.
- Files and Corporate Material (PDF/DOCX/PPTX, media): documents and materials uploaded by the manager travel over an encrypted channel (TLS) and are kept in the tenant's isolated storage (private bucket in Cloudflare R2, with a dedicated per-tenant API key scoped exclusively to the tenant's bucket), available for viewing on the platform and for download when the manager (LMS Admin) enables it, by that tenant's users. The text of the documents is sent to Google's AI APIs in paid mode (no model training). Under no circumstances are corporate files or media used to train AI models.
4. Telemetry & Continuous Improvement (SaaS Analytics Hub)
To refine the tool's features, identify performance bugs, and improve the general usability of Trilha CuboPlus, we implemented a Centralized SaaS Telemetry system:
- How it works: Silent routines send aggregated usage events (e.g.: "Lesson Viewed", "Quiz Generation Executed Successfully", "Learning Path Completion Time") to our secure analytics center.
- Google Analytics: On the platform's public domains (such as trilha.cubo.plus), we use Google Analytics (analytics.google.com), a web traffic analysis service provided by Google LLC. Google Analytics uses first-party cookies to collect anonymized statistical data (pages visited, time spent, traffic source, and device type), with IP anonymization enabled. Data collected is used solely for site optimization and is not cross-referenced with student personal data on dedicated tenant portals. Use of Google Analytics is subject to Google's Privacy Policy (https://policies.google.com/privacy) and Google's Data Processing Terms (https://business.safety.google/processorterms/).
- Microsoft Clarity: Also on the public domains, we use Microsoft Clarity (clarity.microsoft.com), by Microsoft Corporation, for heatmaps and anonymized session recordings (cursor, clicks, and scrolling) that guide usability improvements. Clarity automatically masks sensitive content, is activated only after acceptance of telemetry cookies in the banner, and does not cross-reference this data with student personal data on dedicated tenant portals. Use is subject to Microsoft's Privacy Statement (https://privacy.microsoft.com/privacystatement).
- Student Privacy: Telemetry events are 100% anonymized and aggregated. We collect only the corporate Tenant identifier and the volume of the accessed feature, without exposing student names, emails, or any confidential proprietary content in learning materials.
- Version Notes Channel (Release Notes): To provide visibility on new platform updates, improvements, and AI features, each tenant's application integrates a visual news section that securely and non-intrusively queries the central API, without processing, cross-referencing, or storing any personally identifiable student data.
5. Centralized Suggestion & Improvement Box
- Every usability suggestion, compliment, or non-conformity report made by managers or students through the platform's feedback widget is directed and stored directly in our centralized database.
- This simplifies triage and analysis by Cubotimize's support and product teams to prioritize roadmap updates that benefit all platform instances globally.
- Non-Conversion and Cancellation Form: When the admin user opts not to convert the free trial into a subscription, or requests cancellation within the 30-day window provided in the Terms of Use, they may inform, through a brief form, the reasons for non-contracting or withdrawal. Data processed: company/account identification (Control Plane level) and the stated reason, without student personal data. Legal basis: legitimate interest (art. 7, IX, of LGPD) in continuous service improvement. Purpose: exclusively internal analysis and improvement of Cubotimize's products and services. Completion does not condition the exercise of cancellation or any refund, which remain assured regardless of the response.
6. Cookies and Tracking Technologies
We use cookies and browser identifiers strictly for functional purposes (maintaining active sessions with complete login security), traffic statistics, and performance optimization. For more details, see our Cookie Policy.
- Anti-Bot Protection (Cloudflare Turnstile): We use Cloudflare Turnstile on login and registration screens for silent human verification, without persistent tracking cookies, in accordance with Cloudflare's Privacy Policy (https://www.cloudflare.com/privacypolicy/).
- Google Sign-in Authentication (OAuth 2.0): The platform makes available on all plans the option to log in via Google Workspace using the OAuth 2.0 protocol. The authentication flow involves temporarily redirecting the user's browser to Google's servers (accounts.google.com). During this process, Google may set its own session cookies on the google.com domain to manage authentication. The Trilha CuboPlus platform stores only a secure session token (httpOnly) linked to the authenticated profile, without retaining long-lived Google access tokens. For more information, see Google's Privacy Policy (https://policies.google.com/privacy).
- Google Analytics: We use Google Analytics on the platform's public domains for anonymized statistical traffic data collection, in accordance with Google's Privacy Policy (https://policies.google.com/privacy).
- Microsoft Clarity: We use Microsoft Clarity on the public domains for heatmaps and anonymized session recordings, upon consent in the cookie banner, in accordance with Microsoft's Privacy Statement (https://privacy.microsoft.com/privacystatement).
- Transactional Email Measurement: The transactional and notification emails sent by the platform (such as registration confirmation, password reset, and billing notices) are delivered by the Zoho ZeptoMail service and may contain an open-measurement pixel and links with redirection for click measurement, processed through our own subdomain (track-trilha.cubo.plus). We collect delivery, open, and click indicators for the purposes of operating the service, ensuring security (detection of delivery failures, bounces, and abuse), and providing support, based on legitimate interest (art. 7, IX, of LGPD). We do not use these indicators for advertising. Processing by Zoho is subject to Zoho's Privacy Policy (https://www.zoho.com/privacy.html).
7. Data Retention and Disposal
- Personal and pedagogical data is actively maintained in exclusive digital capsules while the corporate contract is active.
- Non-Activated Accounts (Registration Without Contracting): the registration data of accounts created and not activated (without a contracted plan) is deleted after 30 (thirty) calendar days from registration, with prior email reminders, as part of onboarding cleanup — a scenario distinct from the non-payment window described below.
- Suspension for Non-Payment and Preservation Window: In case of non-payment, access to the study environment is suspended, but data remains fully preserved during a regularization window of up to 45 (forty-five) calendar days from the date of suspension, allowing automatic reactivation without data loss if payment is confirmed within this period. After this period without regularization, Definitive Deletion described below applies.
- Definitive Deletion: Upon annual subscription cancellation request, and after the applicable legal audit and billing periods have elapsed, the entire digital capsule structure and that Client's exclusive data vault are permanently and irreversibly deleted from our physical servers, making any future recovery impossible.
- Legal Retention of Tax and Contractual Data: Even after capsule deletion, registration and billing data strictly necessary for compliance with legal and tax obligations (e.g.: invoice issuance, bookkeeping, and defense in legal proceedings) are retained for the applicable legal period — generally 5 (five) years — after which they are eliminated.
- Access Log Retention (Marco Civil da Internet): In compliance with art. 15 of Law No. 12.965/2014 (Marco Civil da Internet), application access logs are securely and confidentially maintained for a minimum period of 6 (six) months, and may be retained for a longer period upon request by competent authority.
8. International Data Transfer
Part of the infrastructure and operators that enable the platform is located outside Brazil. We work to ensure that all international transfers comply with arts. 33 to 36 of LGPD and the standard contractual clauses approved by ANPD (Resolution CD/ANPD No. 19/2024):
- Hosting Infrastructure (VPS): on all plans, the dedicated stack and Tenant database are hosted on servers (VPS) located in Brazil (currently in the Campinas/SP region), ensuring national residency of the application's structured data. AI processing, on all plans, is performed via Google AI Studio (paid plan), whose infrastructure may be located outside Brazil. AI processing residency within national territory is not part of the standard offering; when required by government or regulated contracts, it may be evaluated upon request, subject to a feasibility study and a specific commercial proposal (involving, for example, the use of Vertex AI/São Paulo and the possible replacement of storage and media sub-processors). Media storage (Cloudflare R2/Stream) and the other sub-processors listed below may operate outside Brazil.
- Overseas Operators and Sub-processors: Google (Google AI Studio / Google Cloud), Stripe and Paddle (payments), Cloudflare (R2, Stream, Workers, and Turnstile), Microsoft (Clarity — experience analytics on public domains), and Zoho (ZeptoMail — transactional email delivery and measurement) may process data on servers outside Brazil, each under their own contractual safeguards and security certifications.
- Basis and Safeguards: transfers occur because they are necessary for contract execution and service provision (art. 33, IX c/c art. 7, V, of LGPD) and supported by standard contractual clauses and confidentiality and security commitments equivalent to LGPD standards (art. 33, II, of LGPD and Resolution CD/ANPD No. 19/2024). In all cases, tenant segregation and the absence of use of data for AI model training are preserved.
- Client Transparency: the Tenant, as Controller, is informed of the infrastructure location. AI processing residency within national territory (for example, via Vertex AI/São Paulo) is not part of the standard offering and may be evaluated upon request for contracts that require it, subject to a feasibility study and a specific commercial proposal.
9. Information Security and Incident Response
- We adopt technical and organizational measures to protect personal data (capsule isolation, encryption in transit via TLS, access controls, daily backups, and password-protected backups).
- To diagnose and resolve support requests, authorized members of the Cubotimize team may, on an exceptional basis, access the Client's account panel (billing, plan, and settings) temporarily assuming the manager's identity. This access (i) is legally based on the performance of the contract (art. 7, V) and the legitimate interest in providing support (art. 7, IX); (ii) requires the operator's reinforced authentication (2FA) and is time-limited; (iii) is fully recorded in an audit trail (operator identity, account accessed, reason, date/time, and IP); and (iv) does not extend to the learning environment (LMS) or to student data. The data subject may request from the DPO the history of support accesses to their account.
- Incident Communication (art. 48 of LGPD): in the event of a security incident that may pose relevant risk or harm to data subjects, Cubotimize will notify ANPD and affected Clients/data subjects within a reasonable timeframe (observing ANPD regulations), informing the nature of the data, the risks involved, and the mitigation measures adopted. The internal procedure is documented in our compliance guide.
10. Contact Channels (Data Protection Officer – DPO)
If the Client, manager, or data subject needs any clarification, rectification, or wishes to exercise their rights under article 18 of LGPD, they may contact our Data Protection Officer (DPO). Cubotimize commits to responding to data subject requests within up to 15 (fifteen) calendar days from the date of the request, pursuant to art. 19, §1 of LGPD. Upon request, data subjects may exercise the following rights:
- Confirmation of data processing existence and access to data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
- Data portability to another provider, upon express request;
- Deletion of personal data processed based on consent;
- Information about entities with which Cubotimize has shared data;
- Revocation of consent; and
- Filing a complaint with the National Data Protection Authority (ANPD).
Legal Limits to Deletion Rights: the right to deletion is not absolute. Under art. 16 of LGPD, certain data is retained even after a deletion request when necessary to comply with a legal or regulatory obligation — for example, invoice and billing data issued in the Client's name, retained for the applicable tax period (generally 5 years) —, for the regular exercise of rights in proceedings, or for research by research bodies (with anonymization whenever possible). Once these conditions are met, data is eliminated.