Carregando…
Carregando…
Carregando…
Legal
Transparency on data collection and use at Legnova. Last updated: July 23, 2026.
This page complements the Terms of Use. Cookie preferences can be changed anytime via the “Cookies” link in the site footer.
Legnova (“we”, “platform” or “Service”) is SaaS software for legal requirements and IMS management (environment, OHS and quality), with modules for licenses, obligations, nonconformities, action plans, ISO and, depending on the plan, ESG and an AI assistant.
This Privacy Policy describes how we process personal data on legnova.com.br, in the app and through support and sales channels, in line with Brazil’s LGPD (Law No. 13.709/2018).
Controller: Legnova. Privacy and data-subject requests: [email protected].
We collect only what is needed to provide, protect and improve the Service. Typically:
We process personal data to:
Plans with an AI assistant may process only the context needed for the request — questions, excerpts of standards or operational data you or the organization provide in that flow.
We do not use customer content to train Legnova’s public models. AI use is subject to plan limits and human validation of suggestions: the platform does not replace legal advice or technical decisions by a duly licensed professional.
We do not sell personal data. Data is processed by Legnova to provide, protect and improve the Service and to meet legal obligations.
When there is a legal obligation or a valid public authority order, we may disclose strictly necessary information.
Cookies and similar technologies are used as follows:
You can change your choice anytime via the “Cookies” link in the footer. Disabling essential cookies in the browser may prevent use of the Service.
When the customer company registers users, owners, suppliers or employees, it acts as controller of that data in the employment and operational context. Legnova processes it as a processor under the customer’s instructions to provide the Service.
The customer organization must inform data subjects, obtain adequate legal bases and manage internal access (invites, roles and user removal).
We keep data while the account or organization is active and for as long as needed for legal obligations, dispute resolution or defense of rights.
After account closure, operational content and related personal data may be deleted or anonymized within a reasonable time, subject to backups and mandatory legal retention.
We apply technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS), role-based access controls, logical isolation between organizations, password hashes, audit logs and backups.
No system is 100% invulnerable. In a relevant incident with risk to data subjects, we will take the measures required by the LGPD, including notice when required.
We prefer infrastructure in Brazil. When processing occurs in another country, we adopt LGPD safeguards (contractual and/or technical) compatible with the required protection level.
Under the LGPD, you may request:
Send your request to [email protected]. We may ask for identity confirmation before fulfilling it.
The Service is intended for professional/business use. We do not knowingly collect children’s personal data. If improper registration is identified, contact us for removal.
This policy may be updated to reflect legal, technical or Service changes. The current version will always be on this page with the revision date. Material changes may be communicated by email or platform channels.
Privacy questions, requests or exercise of rights: [email protected].
You may also lodge a complaint with Brazil’s National Data Protection Authority (ANPD) via official channels at gov.br/anpd.