Privacy Policy

Version 1.1 — effective from 27/08/2026

Summary
  • The system runs in Brazil, but some data is stored in the cloud abroad — including database backups. Section 7 says exactly what and where.
  • We never sell your data.
  • If you are a customer of a restaurant that uses Aufisoft, the restaurant is responsible for your data — we only operate the system for them. See section 3.
  • You can access, correct, export or delete your data at any time.
  • Contact our Data Protection Officer: privacy@aufisoft.com

1. Who we are

  • Legal name: LFKA DEV TECNOLOGIA LTDA
  • Company ID (CNPJ): 60.825.050/0001-30
  • City: Ourinhos / SP — Brazil
  • Website: https://aufisoft.com
  • General contact: contact@aufisoft.com

2. Data Protection Officer

  • Officer: Luis Andriolo
  • Email: privacy@aufisoft.com
  • Alternative channel: dpo@aufisoft.com

The Officer receives your complaints, provides clarification and takes action (Art. 41, §2 of the Brazilian General Data Protection Law — LGPD).

3. Who this policy speaks to

Aufisoft is a restaurant management system. That creates three different relationships, and the rules are not the same in all three. Find yours:

3.1 You use Aufisoft to run a restaurant

Owner, manager or staff member with an account.

We are the controller of your data. This policy applies to you in full.

3.2 You visit aufisoft.com

We are the controller. Sections 6, 9 and 10 apply.

3.3 You are a customer of a restaurant that uses Aufisoft

You placed an order through the online menu, or the restaurant registered you in their system.

In this case the controller of your data is the restaurant, not Aufisoft. They decided to collect your data and for what purpose; we only operate the system where it is stored — the LGPD calls this a processor (Art. 39).

In practice, this means:

  • To exercise your rights, contact the restaurant. Their contact details are on the online menu and on the receipt.
  • If you write to us anyway, we will forward it to the restaurant within 2 business days and let you know. We will not ignore you — but we also cannot decide about data we do not control.
  • We provide the restaurant with the technical means to serve you.

Section 5 describes the data the restaurant handles through our system.

4. Data from those who use Aufisoft — and why

For each purpose we state the data, the reason, the legal basis and how long we keep it.

4.1 Account and access

  • Data: name, email, password (stored encrypted, never in readable form)
  • Purpose: create and operate your account
  • Legal basis: performance of a contract — Art. 7, V
  • Retention: for as long as the account exists. On deletion we anonymise your name and email (see 4.9)

4.2 Email verification and password recovery

  • Data: email and a temporary code
  • Purpose: confirm the email is yours and let you recover access
  • Legal basis: performance of a contract — Art. 7, V
  • Retention: 15 minutes

4.3 Access security

  • Data: IP address, browser and device used, date and time
  • Purpose: keep your session, let you review and end sessions, detect misuse
  • Legal basis: legitimate interest in security — Art. 7, IX
  • Retention: 6 months

4.4 Subscription and billing

  • Data: name, tax ID, email, phone and billing address
  • Purpose: charge the subscription and meet tax obligations
  • Legal basis: performance of a contract (Art. 7, V) and legal obligation (Art. 7, II)
  • Shared with: our payment processor
  • Retention: 5 years after termination — statutory tax period
  • We do not store your card details. They stay with the payment processor; we keep only a reference

4.5 Restaurant profile

  • Data: legal name, tax ID, address, phone, email and location
  • Purpose: configure the system, calculate delivery, issue invoices
  • Legal basis: performance of a contract — Art. 7, V
  • Shared with: a mapping service, to turn an address into coordinates
  • Retention: for the duration of the contract, plus 5 years for tax purposes

4.6 Artificial intelligence assistant

This section deserves a careful read.

  • Data: everything you write in the conversation, plus the restaurant data the assistant needs to answer — products, ingredients, recipes, stock, expenses
  • Purpose: operate the assistant
  • Legal basis: performance of a contract (Art. 7, V) for the feature; legitimate interest (Art. 7, IX) to keep the technical content of the conversation for a limited time, for troubleshooting
  • Shared with: an artificial intelligence provider in the United States — the service that processes the conversation
  • Retention: the visible history stays with you while the conversation exists, and the conversation is deleted after 12 months of inactivity. The raw technical content is erased after 30 days
Please do not write third-party personal data into the conversation — customer names, tax IDs or phone numbers, for example. The assistant does not need it, and everything you write is sent to the processing service.

4.7 Error diagnostics

  • Data: your account identifiers and technical details of the error
  • Purpose: identify and fix failures
  • Legal basis: legitimate interest — Art. 7, IX
  • Retention: 30 days

4.8 Browser notifications

  • Data: the technical endpoint your browser provides to receive notifications
  • Purpose: alert you about orders and system events
  • Legal basis: your consent — Art. 7, I, given through the browser permission
  • You can revoke it at any time in your browser settings
  • Retention: until you revoke it, or 90 days without use

4.9 When you delete your account

How to ask: write to privacy@aufisoft.com. Our Officer handles the process and replies within the deadline in section 8.

We anonymise your name and email and remove your sessions.

We keep the account record, without identification, because orders and invoices issued through it must continue to exist by legal obligation (Art. 16, I of the LGPD). A 2024 order cannot vanish from the books because the person who recorded it left the company.

If you are the sole administrator of a restaurant, we will contact you first: deleting your account would leave the restaurant, its customers' data and its tax records without anyone responsible.

5. Data we process for restaurants

Here the controller is the restaurant (see 3.3). We list it for transparency — and so you know what is in the system.

WhatWhyFor how long
Customer name, phone, email and tax IDidentify who placed the orderwhile the relationship with the restaurant lasts
Delivery address and locationdeliver the ordersame
Order historyrun the restaurant and meet tax law2 years, or 5 years if an invoice was issued
Tax ID on the invoicethe restaurant's tax obligation5 years
Notes about the customercustomer serviceas the restaurant defines
Store creditthe restaurant's credit control5 years after settlement
Orders from delivery appssync with the system2 years

Delivery app orders create a customer record. When an order arrives through an integrated app, we create or update that customer's record in the restaurant's system, including the tax ID if provided. This is necessary for the restaurant to fulfil the order.

If you are a customer of a restaurant and want your data deleted, talk to them — we provide the tool, they decide. How deletion works is in 5.1.

Online menu and measurement tools. Some restaurants enable analytics and advertising tools on their menu. When that happens, we ask for your consent before any tool loads. The restaurant that configured them is responsible for those tools.

Order printing. Order data is sent to the restaurant's printer by a program installed on their computer. From that point on, the data is under the restaurant's physical control.

5.1 Deleting a customer's data

How to ask. If you are a customer of a restaurant and want your data deleted, talk to the restaurant — they decide. You can also write to our Officer at privacy@aufisoft.com; we forward it to the restaurant within 2 business days and follow it through to completion.

The restaurant carries out the deletion in the system. When orders or invoices are involved, the operation goes through our Officer, because some of the data has a retention period set by law — and it is the Officer who separates what goes from what must stay.

What happens, in three layers:

WhatWhat we doWhen
Profile, addresses, phone, email, notes and credit entriesdeletedimmediately
Name and tax ID inside orders already placedanonymised — the order still exists, without identifying who placed itimmediately
Invoice issued, where applicablekept for the statutory period, then deleted5 years from issuance

In practice: once deletion is complete, the history can no longer be linked to the person — neither by the restaurant nor by us. What survives is the accounting record, without identification, as tax law requires.

Why the invoice stays. The LGPD expressly allows retaining data to meet a legal obligation (Art. 16, I), and tax documents have their own retention period. It is neither the restaurant's choice nor ours — it is an obligation nobody can waive.

You have the right to know exactly what was deleted and what was kept, and why. Ask at privacy@aufisoft.com and we will answer within the deadline in section 8.

A new order after deletion. If the person buys again — including through a delivery app — their data will be collected once more to fulfil that order. It is not a restoration of what was deleted: it is a new collection, for a new purchase.

6. Who we share with

We do not sell data. We share only with those who need to perform part of the service:

Provider categoryWhyCountryData
Infrastructure and databasehost the systemBrazileverything, at rest
Payment processingcharge the subscriptionBrazilbilling data
Tax invoicingissue tax invoicesBrazilinvoice data, consumer's tax ID
Delivery platformssync ordersBrazilorder data
Postcode lookupfill in the addressBrazilpostcode only
Cloud storage and deliverybackups, files and site deliveryUSAdatabase backup, images, tax reports
Artificial intelligenceprocess the assistantUSAconversation content
Transactional emailsend system emailsUSAname and email
Maps and geocodingturn an address into a locationUSAaddress and coordinates
Analytics and advertisingmeasure use of the site and the panel, and how ads perform — with your consent; and menu measurement, when the restaurant enables itUSAbrowsing, with no name, email, phone number or tax ID
Network and routingroute restaurants' own domainsglobalconnection data

We also share when required by law, a court order or legal proceedings.

7. Where your data is

The system runs in Brazil. The live database — name, email, tax ID, phone, address and order history — sits on a server in Brazilian territory.

Some data is stored in the cloud outside the country, and we want to be clear about what:

WhatWhereWhy
Database backupsUnited Statesprotection against data loss; generated periodically and automatically deleted after the retention period
Product images and tax reportsUnited Statesfile storage
AI assistant contentUnited Statesprocess your conversations
System emailsUnited Statessend codes and notices
Addresses and mapsUnited Statesturn an address into a location
Browsing on the site and the panelUnited Statesmeasure usage and traffic source — only with your consent (see section 9)
Traffic for menus on custom domainsglobalroute and protect the connection

All of these providers are bound by contractual data protection commitments, and we choose each one considering the safeguards they offer. Only the data necessary for the stated purpose is sent to them.

8. Your rights (Art. 18 of the LGPD)

You can:

  • Confirm whether we process your data
  • Access your data
  • Correct incomplete, inaccurate or outdated data
  • Anonymise, block or delete unnecessary data or data processed unlawfully
  • Export your data in a machine-readable format
  • Delete data we process based on your consent
  • Know who we share your data with
  • Be informed about the option not to consent and what happens if you do not
  • Withdraw consent at any time

How to exercise them: write to privacy@aufisoft.com. We reply through the same channel.

Response time: up to 30 days. The LGPD sets 15 days in Art. 19, II, doubled for small processing agents by Art. 14 of ANPD Resolution 2/2022, which is our case. Simple requests we answer immediately.

If you are a customer of a restaurant, contact the restaurant (see 3.3).

9. Cookies and similar technologies

This section covers all three addresses: the site aufisoft.com, the admin panel app.aufisoft.com and each restaurant's online menu. The choice you make in the banner is stored in a root-domain cookie and applies to all three — you decide once, not once per address.

CategoryWhyWho operates itRequires consent?
Essentialkeep you signed in, remember language and cart, store your own cookie choiceAufisoftno — the site does not work without them
Analyticsknow which pages are viewed and how people arrive, to improve the product and decide where to investGoogle Analytics 4 and Google Tag Manager — Google LLC, United Statesyes
Advertisingmeasure how ads perform and avoid showing the same ad to someone who is already a customerMeta Pixel and Conversions API — Meta Platforms, United Statesyes

Nothing beyond the essential loads before your consent. You choose in the banner shown on your first visit, and you can change it at any time through the Cookies link in the footer — which reopens the panel with your current choice, without erasing it.

Refusing is as easy as accepting — the reject button sits next to the accept button, with the same prominence. Between them there is a Customize option that opens the categories one by one. Refusing takes no functionality away from you.

Legal basis and international transfer

The browsing data handled by the Analytics and Advertising categories is processed on the basis of your consent (art. 7, I of the LGPD), freely given and revocable at any time through the same footer link. Revoking does not erase what was already collected — it stops collection from that point on.

That data is transferred to the United States, where Google's and Meta's servers are. The transfer is made under arts. 33 to 36 of the LGPD, on the basis of standard contractual clauses in the form of ANPD Resolution No. 19/2024, signed with each supplier.

We do not send your name, email, phone number or tax ID to these tools. What leaves is a random identifier generated by the cookie itself and, in the admin panel, an internal user code that does not identify you outside our system.

10. Security

We adopt, among other measures:

  • Data stored in Brazil
  • Encryption in transit (HTTPS/TLS)
  • Passwords stored encrypted, never in readable form
  • Role and permission-based access control
  • Isolation between restaurants — one cannot access another's data
  • A single session per user, with the ability to end it
  • Incident response plan

If a security incident occurs that may pose relevant risk or harm to you, we will notify you and the ANPD within the deadlines of ANPD Resolution 15/2024.

11. Children and adolescents

Aufisoft is a management system for businesses and is not directed at anyone under 18. We do not knowingly collect data from children or adolescents.

The online menu is a general-purpose service, operated by each restaurant. If you are a legal guardian and identified improper use, write to privacy@aufisoft.com.

12. Changes to this policy

We may update this policy. Relevant changes will be communicated by email or in-app notice with reasonable advance warning.

Every version gets a number and an effective date, and previous ones remain available at aufisoft.com/privacidade/v/{version}.

13. Contact us and the ANPD

  • Data Protection Officer: privacy@aufisoft.com
  • General contact: contact@aufisoft.com
  • Brazilian Data Protection Authority (ANPD): https://www.gov.br/anpd

You may petition the ANPD at any time (Art. 18, §1), but we ask that you talk to us first — it is usually faster.

Version history

  • v1.1 — 27/08/2026: section 9 now names who operates each cookie category — Google LLC for Analytics, Meta Platforms for Advertising — states the legal basis of consent (art. 7, I) and the international transfer under arts. 33 to 36 with standard clauses in the form of ANPD Resolution No. 19/2024, and says explicitly that the admin panel is covered by the same choice. Advertising is no longer consented together with Analytics: they are two separate categories in the banner. It replaces v1.0, which was dated 01/09/2026 and was superseded before taking effect; its text remains available at /privacidade/v/1.0.
  • v1.0 — 01/09/2026: full rewrite based on the actual processing inventory. It now identifies the controller, names the processors, distinguishes controller and processor roles, states retention per purpose, declares the response deadline, and aligns the text with what the system actually does.