LGPD • GDPR • CCPA

Global Privacy Policy

This policy transparently describes how NOKTAI collects, uses, and protects your personal data in compliance with the Brazilian LGPD, the European GDPR, and the California CCPA.

Last updated: July 2026

1. Data Controller

THANER MAIA CHAGAS, registered in Brazil under CNPJ No. 19.400.671/0001-78, with address at Rua Tonico Xavier, 81, Bom Pastor, Varginha, Minas Gerais, Brazil, and responsible for the NOKTAI brand, is the controller of personal data collected through this platform under Art. 5, VI of Brazilian Law No. 13,709/2018 (LGPD). Other data protection laws are observed when applicable to the data subject and the operation.

2. Collected Data and Purpose

Authentication Data

Name, email, and profile picture obtained via Google OAuth 2.0 — used exclusively for identification and authentication on the platform.

Integration Data (Meta/Facebook)

Access tokens for the Meta Graph API — used to manage ad campaigns, sync audiences, and access marketing metrics. These tokens are encrypted with AES-256-GCM and never stored in plain text.

Browsing Data

IP address, browser type, and visited pages — collected for security purposes, anomaly detection, and performance improvement.

Contact Data (Lock Access)

Name, company, email, and WhatsApp provided during the progressive access flow — used for identity validation and onboarding communication.

4. International Data Transfer (GDPR)

The current operation uses Hostinger as its primary infrastructure provider and Cloudflare for edge services. Depending on the data subject's location and the providers required to deliver an enabled feature, personal data may be processed outside the country of residence. Before an international transfer, NOKTAI must assess the legal basis, necessity, and safeguards required by the applicable law. This policy does not claim that Standard Contractual Clauses or provider certifications have been adopted unless they have been formally verified and recorded.

5. Data Sharing (CCPA & LGPD)

NOKTAI does not sell or rent personal data. Data may be processed by providers strictly necessary for features enabled by the user: • Hostinger: primary infrastructure and email service. • Cloudflare: DNS, CDN, edge security, and country information used for routing. • Google LLC: authentication and Google APIs authorized by the user. • Meta Platforms, Inc.: Meta APIs enabled and authorized by the user. • Stripe: payment processing when checkout is enabled. This list must be updated before any additional sub-processor is activated.

6. Retention and Deletion

Personal data will be kept only as long as the user's account is active or as long as necessary to comply with legal obligations, resolve disputes, or enforce our Terms of Service. Upon a request for account deletion, all personal data, API tokens, and integration logs will be permanently deleted within a maximum period of 30 (thirty) calendar days, except for legal retention obligations (e.g., civil access logs).

7. Data Subject Rights

In accordance with global legislation (LGPD, GDPR, CCPA), you have the following rights:

Confirmation and Access

Confirm the existence of processing and access your data (Right to Know).

Rectification

Correct incomplete, inaccurate, or outdated personal data.

Deletion (Right to be Forgotten)

Request the total deletion of unnecessary or revoked data.

Portability

Obtain a copy of your data in a structured format (JSON/CSV).

Revocation of Consent

Revoke given permissions at any time (Opt-out).

Information on Sharing

Know with which essential partners your data is processed.

8. OAuth Compliance — Meta / Facebook

Meta Platform Policy & Data Use Requirements

NOKTAI uses the Meta (Facebook) Graph API exclusively to manage advertising campaigns, synchronize custom audiences, and read marketing metrics on behalf of the data subject.

Our registered App ID with Meta is: 1722854025511534.

Limited Purpose: Data obtained via the Graph API is used exclusively to execute the services contracted by the data subject.

No Sale: NOKTAI does not sell, license, or monetize data obtained through Meta APIs.

Encryption: Access tokens are stored with AES-256-GCM encryption and decrypted in memory only during call execution.

Data Deletion: The user can request the complete deletion of their data at any time, including the revocation of the Meta token.

Data Deletion Request URL

As required by the Meta Platform Policy, our data deletion request URL is:

Channel pending activation before stage: [email protected]

9. OAuth Compliance — Google

NOKTAI uses Google OAuth 2.0 as the sole mechanism for authentication and access to Google APIs (Ads, Analytics, Search Console, BigQuery). Data use complies with the Google API Services User Data Policy.

Limited Use Compliance: Data obtained from Google APIs is used exclusively to provide the services requested by the user and is not transferred to third parties, except as necessary to operate the platform.

10. Data Protection Officer (DPO)

To exercise your rights or clarify doubts about the processing of your personal data (under LGPD, GDPR, or CCPA), please contact our Data Protection Officer:

DPO: Thaner Maia Chagas

Email: [email protected]

Response time: Up to 15 business days.

11. Cookie Policy and Consent

NOKTAI respects the principle of Privacy by Design. We use cookies divided into two categories:

  • Essential (Required) Cookies: Necessary for the system to function, including Secure Authentication Session (NextAuth.js), CSRF forgery protection, and language preference logging. These cookies do not require prior consent under GDPR.
  • Optional measurement: No optional trackers are currently loaded. Any future measurement must remain disabled until the visitor gives explicit consent.

We do not use third-party advertising cookies within our private administrative panel (SaaS).