TopStudio3D CommerceOSBack to system

Privacy Policy

Last updated: August 6, 2026

1. Purpose and Scope

This Policy explains how TopStudio3D CommerceOS handles personal data in the ERP, calculator, catalog, subscriptions, and AI features, in compliance with Law No. 13.709/2018 (LGPD). The user who registers their customers' data acts as the Controller of that data; the platform acts as the Operator, following the user's instructions.

2. Data Processed

  • Registration and account: name, email, identifiers, profile, and acceptance records.
  • Business and operations: contacts, business document, address, printers, supplies, costs, inventory, orders, customers, and suppliers.
  • Content: photos, descriptions, technical sheets, and materials sent or generated in TopStudio3D.
  • Subscription: customer, product, price, subscription, and payment status identifiers.
  • Security and usage: date, device/browser, audit records, navigation, and conversion events when authorized.
  • Integrity and account health: volume of registered pieces, quantity and status of AI jobs, failure rate, workflow status, credit consumption and refunds, and activity frequency. These indicators are aggregated and do not expose the specific content of user materials.

3. Purposes and Legal Bases

Data is processed to execute the contract and deliver features; comply with legal and regulatory obligations; prevent fraud and protect the service based on legitimate interest; fulfill data subject requests; and, when necessary, upon consent, as in the use of optional cookies. Consent may be revoked without affecting prior lawful processing.

The integrity and account health indicators (item 2) are processed based on the platform's legitimate interest in ensuring security, preventing fraud and abuse, verifying proper resource utilization, and evaluating contracted value delivery, without the need for additional consent.

4. Sharing and Operators

Data may be processed by essential infrastructure and hosting providers, by Stripe for payments and subscriptions, by OpenAI for AI features, and by Google when metrics/advertising cookies are authorized. Card data is provided directly to Stripe and is not stored by the platform. We do not sell personal data.

5. Artificial Intelligence

Photos, technical data, and instructions selected by the user may be sent to the AI API to generate reports, images, and texts. The user should avoid entering unnecessary or sensitive personal data in the submitted content. Automated results must be reviewed before publication or commercial use.

6. International Transfer

Some operators may process data outside Brazil. In such cases, we use recognized providers and adequate contractual and technical measures, observing the mechanisms permitted by the LGPD and ANPD regulations.

7. Cookies

Necessary cookies and local storage maintain session, security, and preferences and do not depend on optional authorization. Metrics and advertising cookies remain disabled until authorized via the banner. The choice can be changed at any time in "Cookie Preferences".

8. Retention and Deletion

Data is kept while the account or contractual relationship is active and, thereafter, for the period necessary to comply with legal obligations, defend rights, prevent fraud, and audit. Once these periods end, data will be deleted or anonymized, except for retention authorized by law.

9. Security and Incidents

We adopt access controls, logical isolation between accounts, audit records, and protected credential storage. No environment is entirely immune to risks. Relevant incidents will be evaluated and, when required, reported to data subjects and the ANPD in accordance with the law.

10. Data Subject Rights

The data subject may request confirmation and access, correction, anonymization, blocking, or deletion, portability, information about sharing, review of automated decisions, consent revocation, and opposition to unlawful processing. Requests can be made through the Privacy Center in Settings or via the support channel displayed in the system. Identity may be validated before fulfillment.

11. Children and Adolescents

The service is intended for business activities and is not directed at children. Data of children and adolescents should not be registered without a legal basis and observance of the best interest of the data subject.

12. Changes and Contact

This Policy may be updated to reflect legal or operational changes. Material changes will be communicated and may require new acceptance. Questions and requests should be sent through the contact channel available in the system header.

Your privacy matters

We use necessary cookies for the service to work and, only with your permission, analytics cookies. Learn more in our Privacy Policy.