Privacy Policy

At Factorial, protecting your personal data is not an afterthought — it is a core part of how we design our products and operate our business. This policy explains, in plain language, exactly what information we collect, why we collect it, how we safeguard it, and what rights you have over it.

Last updated: 15 June 2025 Applicable in all jurisdictions where we operate, including Brazil (LGPD) and the European Union (GDPR)

Section 01

Introduction

FACTORIAL LTDA. ("Factorial", "we", "our", or "us"), a legal entity incorporated under Brazilian law with CNPJ 44.259.221/0001-54, headquartered at Avenida Paulista, 1439, Conjunto 12, Bela Vista, São Paulo – SP, Brazil, operates the website factorialhr.site and the HR management platform accessible therein. In this capacity we act as the data controller for personal information provided directly through our website and as a data processor for employee data managed on behalf of our business clients.

This Privacy Policy describes how Factorial collects, uses, stores, shares, and protects personal data in connection with our website and services. It has been drafted to comply with Brazil's General Data Protection Law (Lei Geral de Proteção de Dados — LGPD, Law No. 13,709/2018) and, where applicable, Regulation (EU) 2016/679 of the European Parliament (GDPR), as well as other relevant privacy regulations.

By visiting our website, submitting a contact form, signing up for a free trial, or otherwise engaging with any of our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of our website and services and contact us at contato@factorialhr.site to request removal of any data we may hold about you.

Where our platform is deployed by a business client (an employer) to manage its workforce, that client acts as the data controller for their employees' data. In such cases, Factorial acts solely as a data processor, and the client's own privacy notices govern that processing. This policy pertains specifically to data collected through our public-facing website and our direct commercial relationship with prospective and current clients.

Section 02

Information We Collect

We collect personal data through several distinct channels. The type and scope of data collected depends on how you interact with us — whether you simply browse our website, request a product demonstration, start a free trial, or become a paying customer.

Data You Provide to Us Directly

Contact & enquiry forms

When you complete a contact, demo-request, or callback form on our website, we collect your full name, business email address, phone number, company name, company size (number of employees), and the content of your message or enquiry. This information is needed to respond to your request and to route it to the appropriate member of our team.

Free trial & account registration

When you sign up for a free trial or create an account, we collect your name, work email address, a password of your choice (stored in hashed form — never in plain text), your company's legal name, tax identifier (CNPJ or equivalent), and billing address. We may also ask for your job title and department in order to personalise your onboarding experience.

Payment & billing information

Subscription payments are processed by our third-party payment processors (Stripe and/or Pagar.me). We do not store full credit-card numbers or CVV codes on our servers. We do retain invoice records including billing name, address, and the last four digits of the payment instrument for accounting and fraud-prevention purposes.

Support conversations & feedback

When you open a support ticket, use our in-app chat, respond to a satisfaction survey, or leave a review, we collect the content of that communication, associated metadata (timestamps, browser/device type), and any attachments you choose to share. This helps us resolve your issue and improve the product.

Newsletter & marketing subscriptions

If you opt in to receive our HR insights newsletter, webinar invitations, or product announcements, we collect your email address and your stated preferences. Subscription is always opt-in; you may unsubscribe at any time via the link in any email we send.

Data We Collect Automatically

When you visit our website, our servers and third-party analytics tools automatically collect certain technical and behavioural information. This includes:

  • IP address and approximate geolocation derived from it (city/region level; we do not collect precise GPS location)
  • Browser type and version, operating system, screen resolution, and device type
  • Referring URL — the page or advertisement that brought you to our website
  • Pages visited, time spent on each page, scroll depth, and links clicked during your session
  • UTM parameters attached to links from our marketing campaigns, allowing us to measure campaign effectiveness
  • Date, time, and duration of each visit
  • Error logs and crash reports, which help our engineering team maintain platform stability

Most of this information is collected through cookies and similar tracking technologies, which are described in detail in Section 4 of this policy.

Data From Third-Party Sources

In some circumstances we may receive data about you from third-party sources, including: LinkedIn and other professional networks where you engage with our company page; data enrichment services (such as Clearbit) that supplement information you provide with firmographic details about your employer; and business partners who refer clients to us and share basic contact information with your prior consent. We only use such data in accordance with this policy and any consent you may have provided to those third parties.

Section 03

How We Use Your Information

We process your personal data only for clearly defined, legitimate purposes and always on the basis of a lawful legal ground. The table below summarises the key processing activities, their purpose, and the legal basis under LGPD and GDPR:

Purpose Data Used Legal Basis (LGPD / GDPR)
Responding to enquiries and demo requests submitted via website forms Name, email, phone, company, message content Legitimate interest; Pre-contractual measures
Providing, operating, and supporting our HR software platform Account data, usage data, support communications Contract performance
Processing subscription payments and issuing invoices Billing name, address, payment token Contract performance; Legal obligation
Sending product updates, release notes, and service announcements Email address, account details Contract performance; Legitimate interest
Sending marketing emails and newsletters Email address, preference data Consent (opt-in)
Measuring website performance and improving user experience Anonymised/pseudonymised analytics data, cookies Legitimate interest; Consent (where required)
Running targeted advertising campaigns on Google, LinkedIn, and Meta Hashed email, cookie identifiers, IP-derived segments Consent (via cookie banner)
Fraud detection, security monitoring, and abuse prevention IP address, login metadata, access logs Legitimate interest; Legal obligation
Compliance with tax, accounting, and regulatory obligations Invoicing and transaction records Legal obligation
Personalising onboarding flows and in-app recommendations Role, company size, industry, usage patterns Legitimate interest; Consent

We do not sell your personal data to any third party, and we never use your data for purposes incompatible with those stated above. Where we rely on legitimate interest as our legal basis, we have conducted a balancing test to confirm that our interests do not override your fundamental rights and freedoms. You may request a summary of that balancing assessment by contacting us at the address in Section 11.

Section 04

Cookies & Tracking Technologies

Our website uses cookies, pixel tags, web beacons, and local storage to deliver core functionality, measure performance, and — with your consent — serve relevant advertising. Below we explain what each category of cookie does and how you can control them.

What Is a Cookie?

A cookie is a small text file placed on your device when you visit a website. Cookies allow a site to remember your actions or preferences (such as language, font size, or login status) over a period of time, so you don't have to re-enter them each time you visit or navigate between pages. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (stored for a defined period).

Cookie Categories We Use

Category Purpose Examples Consent Required?
Strictly Necessary Enable core website functionality — authentication, security tokens, load balancing, and remembering cookie preferences. Session ID, CSRF token, cookie consent state No — essential to site operation
Analytics & Performance Help us understand how visitors use the site so we can improve page speed, content, and navigation. Google Analytics 4 (_ga, _gid), Hotjar (hjSession) Yes
Functional / Preference Remember your language preference, chat widget state, and other personalisation choices. Intercom, HubSpot chat Yes
Marketing & Advertising Allow us to serve relevant ads, measure ad performance, and build retargeting audiences on Google, Meta, and LinkedIn. Google Ads (_gcl), Meta Pixel (fbp, fbc), LinkedIn Insight Tag (li_fat_id) Yes

Managing Your Cookie Preferences

When you first visit our website, a cookie consent banner provides you with granular controls to accept all, reject all non-essential, or customise your preferences by category. You may revisit and change these choices at any time by clicking the "Cookie Settings" link in our site footer. Changes take effect immediately.

You can also control cookies at the browser level. Most browsers allow you to block or delete cookies via their settings menus (typically found under Privacy, Security, or Site Settings). Note that disabling strictly necessary cookies may impair the functionality of the website or prevent you from logging into your account. Browser-level opt-outs for advertising can also be configured via the Digital Advertising Alliance's opt-out portal or the Network Advertising Initiative.

We use Google Analytics 4 with IP anonymisation enabled, meaning your full IP address is never stored by Google Analytics. Hotjar's data is processed under a Data Processing Agreement that restricts use to our stated analytics purposes only.

Section 05

Sharing With Third Parties

We do not sell, rent, or trade your personal data. We share data only in the limited circumstances described below, and always under contractual terms that require third parties to protect your data with at least the same standard of care we apply ourselves.

Service Providers (Data Processors)

We engage carefully vetted technology partners who process data solely on our instructions and for no other purpose:

  • Cloud Infrastructure: Amazon Web Services (AWS) in the São Paulo region (sa-east-1) — servers, databases, and file storage
  • Email Delivery: SendGrid (Twilio) — transactional emails such as password resets, invoices, and notification alerts
  • CRM & Marketing Automation: HubSpot — storing and managing contact records for leads and customers, sending marketing emails to opted-in contacts
  • Customer Support: Intercom — in-app and website chat, ticketing, and help centre delivery
  • Payment Processing: Stripe and Pagar.me — handling credit-card and boleto bancário payments; neither provider stores raw card data on our behalf
  • Analytics: Google Analytics 4 and Hotjar — aggregated behavioural analytics, session recordings (PII masked), and heatmaps
  • Error Monitoring: Sentry — capturing application errors and performance metrics to ensure platform stability
  • Video Conferencing: Google Meet and Zoom — used for product demonstrations and customer onboarding calls

Each of these providers is bound by a Data Processing Agreement (DPA) and, where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission to govern international data transfers.

Business Transfers

If Factorial is involved in a merger, acquisition, asset sale, or insolvency proceeding, personal data may be transferred as part of that transaction. We will notify affected users before any such transfer takes effect and before data becomes subject to a materially different privacy policy.

Legal Requirements & Public Authorities

We may disclose personal data to courts, regulators, the Brazilian Autoridade Nacional de Proteção de Dados (ANPD), law enforcement agencies, or other government bodies when we are legally required to do so, when disclosure is necessary to protect our legal rights, or when there is a credible threat to the physical safety of any person. We will, where legally permitted, notify you of any such request before complying.

Section 06

Data Retention

We retain personal data for no longer than is necessary for the purpose for which it was collected, subject to any overriding legal obligation to retain it for a longer period. Our specific retention periods are as follows:

Data Category Retention Period Rationale
Website contact and demo request form submissions 24 months from date of submission, or until you request deletion Typical sales cycle and follow-up period
Active customer account data Duration of the contract + 12 months post-termination Dispute resolution and reactivation window
Invoice and financial records 10 years from the date of the transaction Brazilian tax law (Lei 9.430/1996) and accounting standards
Marketing email opt-in records Until consent is withdrawn, plus 3 years as proof of consent Regulatory compliance and dispute resolution
Website analytics data (Google Analytics 4) 14 months (rolling window, as configured in GA4) Trend analysis; Google's default retention period
Support tickets and chat transcripts 36 months from ticket closure Quality assurance and training
Server and application access logs 90 days Security incident investigation
Deleted user accounts 30 days in backup systems, then permanently purged Operational recovery window; thereafter no residual copies

When retention periods expire, data is either permanently deleted or irreversibly anonymised (so that it can no longer be linked to any individual). We conduct quarterly data hygiene reviews to enforce these schedules across all systems.

Section 07

Data Security

Factorial takes the security of your personal data seriously and has implemented a layered set of technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction.

  • Encryption in transit: All communication between your browser and our servers is encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS. Our HSTS policy is submitted to browser preload lists to prevent downgrade attacks.
  • Encryption at rest: All databases and file stores hosted on AWS are encrypted at rest using AES-256. Backups are encrypted using the same standard before being stored in geographically separate AWS regions.
  • Password security: User passwords are hashed using bcrypt with a suitable work factor. We never store, log, or transmit passwords in plain text under any circumstances.
  • Access controls: Internal access to personal data is granted on a strict need-to-know basis, enforced through role-based access control (RBAC). Privileged access requires multi-factor authentication (MFA) and is subject to quarterly access reviews.
  • Vulnerability management: We conduct periodic penetration tests by independent security firms, automated dependency scanning via Dependabot, and static code analysis in our CI/CD pipeline.
  • Incident response: We maintain a documented data breach response procedure. In the event of a breach likely to result in risk to individuals, we will notify the ANPD and affected data subjects within 72 hours of becoming aware of the incident, in accordance with LGPD Art. 48.
  • Employee training: All Factorial employees who handle personal data receive privacy and information security training upon joining and at least annually thereafter.
  • Vendor security: We assess the security posture of all data processors before engagement and require them to maintain industry-recognised certifications (e.g., ISO 27001, SOC 2 Type II) where applicable.
No method of data transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. We encourage you to use a strong, unique password for your Factorial account and to enable two-factor authentication where available.

Section 08

Your Rights

Depending on your location and the applicable law, you have a number of rights regarding your personal data. We are committed to honouring these rights promptly and without undue burden. The rights available to you under Brazil's LGPD and the EU's GDPR are broadly aligned and are set out below:

Right of Access

You may request a copy of all personal data we hold about you, as well as information about how it is processed, where it originated, and with whom it has been shared. We will provide this within 15 days of verifying your identity.

Right to Rectification

If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to request that we correct or update it. Many fields can be edited directly within your Factorial account; for others, contact our team.

Right to Erasure

You may request that we delete your personal data when it is no longer necessary for the purpose for which it was collected, when you withdraw consent, or when processing is unlawful. Note that certain data must be retained to comply with legal obligations and cannot be deleted on request.

Right to Restriction

You may request that we restrict the processing of your data — for example, while a dispute about accuracy is being resolved, or where processing is unlawful but you prefer restriction to deletion.

Right to Portability

Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, commonly used, machine-readable format (CSV or JSON) so that you can transfer it to another provider.

Right to Object

You have the right to object to processing based on legitimate interest, including profiling for direct marketing purposes. Where your objection relates to direct marketing, we will cease that specific processing immediately and unconditionally.

Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Currently, no such fully automated decisions are made in our product without human review.

Withdraw Consent

Where we process your data on the basis of your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw marketing consent via the unsubscribe link in any email.

How to Exercise Your Rights

To exercise any of the rights described above, please send a written request to contato@factorialhr.site with the subject line "Data Subject Request". To protect your privacy, we will ask you to verify your identity before processing the request — typically by confirming the email address associated with your account or by providing a government-issued ID for non-account holders.

We will acknowledge your request within 3 business days and aim to fulfil it within 15 days. In complex or high-volume cases, this period may be extended by a further 30 days, in which case we will notify you of the extension and the reasons for it. We will never charge a fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we will explain our decision in writing.

If you believe your rights have not been adequately addressed, you have the right to lodge a complaint with the Brazilian Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd, or with the supervisory authority in your EU member state of residence.

Section 09

Children's Privacy

Factorial's website and HR management platform are intended exclusively for use by business professionals and organisations. Our services are not directed at, and are not designed to attract, children under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age through our website or platform.

If you are a parent or guardian and you believe that a minor has provided us with personal data without your consent, please contact us immediately at contato@factorialhr.site. We will promptly investigate the matter and, if confirmed, delete the relevant information from our records without delay.

Note that our platform may be used by client companies (employers) to manage HR records that include data about young employees or apprentices who are 16 years of age or older and legally employed. In those cases, the employer acts as the data controller and is responsible for ensuring that appropriate consent and legal grounds exist for processing such data.

Section 10

Changes to This Policy

Privacy law, technology, and our business practices evolve over time. We review this Privacy Policy at least annually and update it whenever there is a material change to our data processing activities, legal obligations, or organisational structure.

When we make changes, we will update the "Last updated" date at the top of this page. For changes that are material — meaning they meaningfully alter your rights, introduce new categories of data collection, or affect the purposes for which we use your data — we will provide more prominent notice. Depending on the nature of the change, this may include a notification banner on our website, an email to all registered account holders, or an in-app notification.

Your continued use of our website or platform after the effective date of any updated policy constitutes your acknowledgement of the updated terms, subject to any additional consent we are required to obtain from you. If you do not agree with the updated policy, you have the right to close your account and request deletion of your data as described in Section 8.

We maintain an archive of previous versions of this policy, which are available upon request by contacting contato@factorialhr.site.

Section 11

Contact Us & Data Controller Details

If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we handle your personal data, please do not hesitate to get in touch. Our team is committed to responding to all privacy-related enquiries within 3 business days.

Data Controller — Legal Entity Details

Company name: FACTORIAL LTDA.
CNPJ: 44.259.221/0001-54
Registered address: Avenida Paulista, 1439, Conjunto 12, Bela Vista, São Paulo – SP, Brazil, CEP 01311-200
Privacy enquiries & data subject requests: contato@factorialhr.site
Response time: We acknowledge all privacy-related requests within 3 business days and aim to resolve them within 15 business days.

When submitting a request, please include your full name, the email address associated with your account (if applicable), and a clear description of your request so we can identify you and respond efficiently. For data deletion or export requests, we may ask you to verify your identity before proceeding, to protect your data from unauthorised access or manipulation.

Regardless of where you are located, you are always entitled to approach us directly before escalating a concern to a supervisory authority — and we strongly encourage this, as most issues can be resolved quickly through direct dialogue. That said, you retain the unconditional right to file a complaint with the ANPD (Brazil) or the relevant EU supervisory authority at any time.