Privacy Policy

2026-04-17

Table of Contents

Privacy Policy

Effective date: April 17, 2026 | Version: 1.0

This Privacy Policy explains how your personal data is collected, used, shared, and protected when you use Retorno ("Service"), available at https://retorno.io. This policy is aligned with the Brazilian General Data Protection Law (LGPD β€” Lei 13.709/2018) and provides best-effort compliance with CCPA and GDPR principles.

1. Data Controller

Dusik Consultoria em Ti Ltda CNPJ: 52.470.169/0001-09 Email: eduardo@retorno.io

2. Data Protection Officer (DPO)

Contact our DPO / Encarregado de Dados at: eduardo@retorno.io

3. Data We Collect

CategoryExamplesSource
Account dataName, email address, password hashProvided by you
Site & profile dataWebsite URL, LinkedIn profile URLProvided by you
ICP dataIdeal Customer Profile answers, target audience descriptionsProvided by you
Enrichment dataProspect names, job titles, company info, LinkedIn public profilesApollo.io, Firecrawl
Outreach dataMessages sent, response status, campaign historyGenerated by the Service
Usage & analyticsPages visited, feature usage, session data, IP addressPostHog (post-consent)
Cookie dataAuthentication tokens, consent preferencesYour browser
PurposeData categoriesLegal basis (LGPD art. 7)
Account creation and authenticationAccount dataPerformance of contract (art. 7, V)
Delivering the outreach serviceICP, site/profile, enrichment, outreach dataPerformance of contract (art. 7, V)
Prospect enrichment via third partiesSite/profile dataLegitimate interest (art. 7, IX)
Product analytics and improvementsUsage & analyticsConsent (art. 7, I)
Security and fraud preventionAccount, usage dataLegitimate interest (art. 7, IX)
Legal complianceAll categories as neededLegal obligation (art. 7, II)

5. Sharing with Sub-processors

Sub-processorPurposeLocation
VercelHosting and CDNUnited States
Anthropic (Claude API)ICP inference and message generationUnited States
UnipileLinkedIn integrationEU
ResendTransactional and outreach email deliveryUnited States
Apollo.ioProspect data enrichmentUnited States
FirecrawlWebsite crawling and scrapingUnited States
PostHogProduct analyticsUnited States

We do not sell personal data to third parties.

6. International Data Transfers

Some sub-processors are located outside Brazil, primarily in the United States. These transfers rely on:

  • Standard contractual clauses or equivalent safeguards where available.
  • The necessity of the transfer for performance of the contract between you and the controller (LGPD art. 33, II).
  • Your consent where no other legal basis applies (LGPD art. 33, VIII).

7. Data Retention

  • Account data: Retained while your account is active, plus 30 days after deletion.
  • Outreach and enrichment data: Retained for 12 months after the last campaign activity, then anonymized or deleted.
  • Analytics data: Retained for up to 24 months.
  • Legal compliance data: Retained as required by applicable law.

8. Your Rights (LGPD art. 18)

As a data subject, you have the following rights:

  1. Confirmation of the existence of processing.
  2. Access to your personal data.
  3. Correction of incomplete, inaccurate, or outdated data.
  4. Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD.
  5. Portability of your data to another service provider.
  6. Deletion of data processed with your consent.
  7. Information about public and private entities with which your data has been shared.
  8. Information about the possibility of denying consent and its consequences.
  9. Revocation of consent at any time.

To exercise any of these rights, contact us at eduardo@retorno.io. We will respond within 15 business days.

9. Cookies

We use essential cookies and analytics cookies (PostHog, post-consent only). For details, see our Cookie Policy.

10. Security

We implement reasonable technical and organizational measures to protect your data, including encryption in transit (TLS), secure credential storage, and access controls. However, no method of electronic transmission or storage is 100% secure.

11. Children

The Service is not intended for anyone under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us at eduardo@retorno.io.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 15 days before taking effect. The "Effective date" at the top will be updated accordingly.

13. Contact

Dusik Consultoria em Ti Ltda CNPJ: 52.470.169/0001-09 DPO: eduardo@retorno.io General: eduardo@retorno.io