Privacy policy

How we handle the data you and your company entrust to us, and what rights you have over it.

Última atualização: 7 September 2026

This is a translation provided for convenience. The policy in force is the Portuguese version, and in case of any divergence between the two, the Portuguese text prevails.

Read the original in Portuguese

1. Who operates the service

Dayall Sys is business management software offered over the internet.

For anything relating to this policy, to your data or to exercising your rights, the official channel is the email address vendas@dayall.com.br. We answer within 15 days.

This address is the communication channel with the data subject required by ANPD Resolution nº 2/2022, which exempts small-scale processing agents from appointing a data protection officer, but not from maintaining a channel for enquiries.

2. Two different roles

This distinction guides everything else in this document:

  • Your account data — name, email, phone and billing information of whoever subscribes to the service. Here we are the controller: we decide how that data is used.
  • The data you record in the system — your customers, suppliers, products, sales and financial entries. Here we are the processor: we only store and process it at your request. You are the one who decides what to do with that data and who answers for it before your own customers.

3. What we collect

We collect only what the service needs in order to work:

  • Sign-up: name, email, phone and company name, provided by you when creating the account.
  • Payment: handled entirely by Stripe. We neither receive nor store card numbers — we keep only the subscription identifier and the billing status.
  • Use of the system: access logs, date and time of operations and the identity of whoever performed each action, for security and audit purposes.
  • Operational data: everything you record in the system. That content is yours.

We do not collect data from minors or sensitive categories (health, biometrics, religious or political conviction) for the service to work.

4. What we use it for

  • To provide, maintain and improve how the system works.
  • To process subscription billing and issue receipts.
  • To send communications about the service: outages, relevant changes and subscription expiry.
  • To provide technical support when you ask for it.
  • To comply with legal obligations and respond to orders from a competent authority.

We do not sell your data. We do not use the content you record in the system for advertising, to train models, or for any purpose unrelated to providing the service.

5. On what legal basis

Each use above rests on one of the bases set out in the LGPD:

  • Performance of the contract (art. 7, V) — creating and maintaining your account, hosting your data, processing the subscription and providing support. It is the basis for most of what we do: without that data, there is no service to provide.
  • Compliance with a legal obligation (art. 7, II) — keeping access logs for the period set by article 15 of the Internet Civil Framework and responding to requests from a competent authority.
  • Legitimate interest (art. 7, IX) — security and audit records, prevention of fraud and misuse, and fault diagnosis. You may object to processing based on this ground through the channel above.

We do not rely on your consent to operate the system. Where consent is the basis — for example, if one day we start using advertising tools — it will be asked for beforehand, prominently, and may be withdrawn at any time.

6. Who we share it with

Only with the suppliers the service needs in order to exist, and each receives only what its function requires:

  • Google Cloud / Firebase — database hosting and user authentication.
  • Stripe — processing subscription payments.
  • WhatsApp (Meta) — when you choose to reach us there. The content of the conversation and your number pass through Meta's infrastructure, subject to its own privacy policy. If you would rather not use that channel, write to vendas@dayall.com.br.

We may also share data under a court order or a request from a competent authority, within the limits of the law.

7. International transfer

The database is in the São Paulo region. Even so, part of the processing happens outside Brazil: Google's authentication and infrastructure, Stripe's payment processing and WhatsApp support run on servers abroad, mainly in the United States and the European Union.

These transfers take place in order to perform the contract with you (article 33, item IX, of the LGPD) and are made with suppliers that contractually assume data protection obligations, through standard contractual clauses.

8. Where it lives and for how long

The data sits on Google Cloud servers, with the database hosted in the São Paulo region. Automatic backups are kept by the provider's infrastructure.

While the account is active, we keep your data. After cancellation it remains for 90 days, so the account can be reactivated without loss, and after that it may be permanently deleted. Records required by legal or tax obligation are kept for the period set by law.

Application access logs are kept for six months, as required by article 15 of the Internet Civil Framework. That period applies even after the account is deleted, because it stems from a legal obligation and not from our convenience.

9. Who on our team can see your data

We keep an internal panel used for support and subscription administration. Through it we can see your company's registration details, the contracted plan, usage volume and payment history, and take actions such as granting days of access, changing limits or blocking an account.

Every action taken through that panel is recorded with author, date, reason and previous value, in a history that not even the person who took the action can erase. Access is restricted, protected by a password and a second factor, and is not used to browse your company's commercial content out of curiosity — only when necessary to solve a problem of yours or to comply with a legal obligation.

10. Security

  • Encrypted connection (HTTPS) across all access to the system.
  • Isolation per company: the database rules prevent one account from reaching another's data.
  • Password authentication, with email confirmation and per-user permission control inside each company.
  • A record of who performed each sensitive operation, such as cancelling a sale or closing the till.

No system is immune to incidents. If a data breach occurs that may pose a relevant risk to you, we will notify you and the Brazilian National Data Protection Authority, as the LGPD requires.

11. Your rights

The General Data Protection Law (Law 13.709/2018) guarantees that you may, at any time:

  • Confirm whether we process your data and access it.
  • Correct incomplete, inaccurate or outdated data.
  • Request anonymisation, blocking or deletion of unnecessary data or data processed unlawfully.
  • Request portability of the data to another supplier.
  • Withdraw consent and request deletion of the account.
  • Be informed about who we share your data with.

To exercise any of them, write to vendas@dayall.com.br. We may ask for information confirming your identity before acting on the request — that is a protection for you.

12. Cookies and local storage

We use no advertising cookies, no social network pixels and no audience analytics tools. Nothing we keep in your browser serves to follow you around other sites. What exists is this, and only this:

  • Access session — keeps you signed in from one page to the next. Without it, the system would ask for a login on every click.
  • Screen preferences — light or dark theme and whether the sidebar is collapsed or open. They stay only in your browser.
  • Temporary sign-up data — what you typed while creating the account, so it isn't lost if the page reloads. It is discarded once sign-up finishes.

All of them are strictly necessary to deliver the service you asked for. That is why we show no cookie banner asking for authorisation: as the Brazilian National Data Protection Authority advises, necessary cookies do not require consent — asking permission for something that cannot be refused without breaking the system would be a choice in appearance only.

If one day we start using audience measurement or advertising, that changes: we will ask for your consent before any collection, with a real option to refuse, and this section will be updated.

Barcode reading by camera happens entirely inside your browser. No image is sent or stored by us — what leaves the camera is only the number that was read.

13. Changes to this policy

We may update this document. Relevant changes will be communicated by email or by notice inside the system, with reasonable notice. The date at the top of this page always shows the latest revision.