Privacy Policy
This Policy explains how Donnu Convert processes personal data. It is part of the Terms of Use and should be read together with the Cookie Policy.
1. Controller
The controller of personal data processed in the account relationship is DONNU LTDA, CNPJ 65.082.197/0001-09, with its head office at Rua Lorena, 649, Loja Parte, Padre Eustaquio, Belo Horizonte/MG, Brazil, ZIP 30.730-170.
2. Roles: controller and processor
It is important to distinguish two contexts:
- Account data: with respect to the data of account holders and platform users, including billing data, Donnu acts as controller.
- Visitor data: with respect to data processed by the Tag on our customers' sites, including the Leads typed into Pop-up forms, Donnu acts as processor, and the customer who installed the Tag is the controller. The customer is responsible for informing its Visitors and obtaining the applicable legal bases. Donnu processes this data only to provide the service, following the customer's instructions and this document.
3. Data we process
3.1. Account holders
- Registration data: name, email, preferred language, and a record of acceptance of the Terms (version and date);
- Account and team data: account name and time zone, registered Companies and sites, invited people, their roles, and the Companies they can access;
- Credentials: password stored only as a cryptographic hash (never in plain text);
- Billing data: plan, subscription status, and customer and subscription identifiers at Stripe. Card data is entered directly with Stripe and is never received or stored by Donnu;
- Usage and technical logs: IP address, browser and device information, dates and times of access, and actions taken on the platform.
3.2. Visitors of customers' sites (Donnu as processor)
- Pseudonymous identifier: a random code stored in the browser's local storage (localStorage) on the customer's own site domain, used to keep the Visitor in the same variant, apply frequency rules, and count unique visitors;
- Interaction events: Pop-up impressions, clicks, closes, and form submissions, page views, the variant shown, interaction time, and the element clicked (such as the button text, the coupon, or the rating given);
- Visit context: page address, referring address (referrer), device type (desktop, mobile, or tablet), inferred from the browser, and campaign parameters (UTM);
- IP address: used at request time for security (rate limiting) and, where applicable, to estimate location. It is not stored in the service database, although the hosting provider's technical logs may contain it for a limited time;
- Approximate location: country, state, and city, estimated from the IP address only when a Pop-up on the site uses location targeting. The estimate uses a database installed on our own servers (DB-IP Lite, by DB-IP, db-ip.com, under the CC BY 4.0 license), without sending the IP to third parties, and the location is kept only in the Visitor's browser, for targeting;
- Leads: the content of the form fields the customer set up in its Pop-ups (for example, name, email, or phone), typed and submitted by the Visitor.
We do not perform fingerprinting and we do not track Visitors across different sites. Form fields are defined by the customer; Donnu does not, on its own initiative, request sensitive personal data.
4. Purposes and legal bases
- Providing and operating the service, authenticating and billing: performance of a contract (LGPD, art. 7, V);
- Security, fraud prevention, and service improvement: legitimate interest (art. 7, IX), respecting the rights of the data subject;
- Compliance with legal and regulatory obligations: legal obligation (art. 7, II);
- Non-essential cookies, where applicable: consent (art. 7, I);
- Visitor data: processed on behalf of the customer, to show Pop-ups, apply targeting, record Leads, and produce reports. The legal basis for this processing is defined by the customer, as controller.
5. Sharing
We do not sell personal data. We may share data with:
- infrastructure providers and sub-processors that enable the service, under confidentiality and security obligations: Railway (hosting of the dashboard, the API, and the database) and Netlify and Cloudflare (marketing site and DNS);
- Stripe, the payment processor, which receives the subscriber's email and the account name to enable billing, and receives card data directly, processing it under its own privacy policy;
- authorities, when required by law, court order, or to exercise our rights.
Location estimates use a local database, with no data sent to third parties. The platform does not send automated emails.
6. International transfer
Service data, including Visitor data and Leads, is hosted on infrastructure located in the United States (Railway), and billing data is processed by Stripe, which may process it outside Brazil. For these international transfers, we adopt the safeguards required by applicable law for the international transfer of data.
7. Retention
We keep data for as long as necessary for the purposes of this Policy and the contractual relationship, and for the periods required by law. In particular:
- Account data: for as long as the account exists. The end of a subscription does not delete the account or its data;
- Visitor events and Leads: for as long as the customer keeps them in the account. The customer can delete Leads at any time, and deleting a Pop-up deletes its events and Leads;
- Account deletion: can be requested by emailing contato@donnu.com.br. Once the relationship ends, data may be deleted or anonymized after a reasonable period, except where the law requires retention;
- Backups: kept by the hosting infrastructure, they may retain already deleted data for a limited period, until they are replaced.
8. Security
We adopt appropriate technical and organizational measures, such as per-account data isolation, access control by role (owner, admin, and user) and by Company, passwords stored with a strong cryptographic hash (scrypt), sessions recorded in the database with a protected cookie (httpOnly), limits on sign-in attempts and requests, and transmission over a secure connection (HTTPS), along with audits and security testing. No system, however, is completely immune to incidents, and we cannot guarantee absolute security.
9. Your rights
Under the LGPD, you may request: confirmation that processing exists; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary data or data processed unlawfully; portability; information about sharing; and withdrawal of consent. To exercise these rights, including to request deletion of your account, use the contact in Section 13.
Visitor requests relating to customers' sites, including requests about Leads, should be directed to the respective customer, in its capacity as controller. The customer's account owner and admins can delete Leads directly in the dashboard.
10. Cookies
The use of cookies and similar technologies, including the local storage used by the Tag on customers' sites, is detailed in the Cookie Policy.
11. Minors
The platform is intended for professional use by people 18 or older and is not directed to minors. We do not intentionally collect data from children or adolescents.
12. Changes
This Policy may be updated at any time. Material changes will be communicated by reasonable means before they take effect. The version in force will always be available on the platform, with its date.
13. Data protection officer and contact
To exercise your rights or raise privacy matters, contact our data protection officer (DPO) at contato@donnu.com.br.
CNPJ 65.082.197/0001-09
Rua Lorena, 649, Loja Parte, Padre Eustaquio, Belo Horizonte/MG, Brazil, ZIP 30.730-170
Privacy: contato@donnu.com.br