Privacy Policy
Version 1.1 — effective from 27/08/2026
- The system runs in Brazil, but some data is stored in the cloud abroad — including database backups. Section 7 says exactly what and where.
- We never sell your data.
- If you are a customer of a restaurant that uses Aufisoft, the restaurant is responsible for your data — we only operate the system for them. See section 3.
- You can access, correct, export or delete your data at any time.
- Contact our Data Protection Officer: privacy@aufisoft.com
1. Who we are
- Legal name: LFKA DEV TECNOLOGIA LTDA
- Company ID (CNPJ): 60.825.050/0001-30
- City: Ourinhos / SP — Brazil
- Website: https://aufisoft.com
- General contact: contact@aufisoft.com
2. Data Protection Officer
- Officer: Luis Andriolo
- Email: privacy@aufisoft.com
- Alternative channel: dpo@aufisoft.com
The Officer receives your complaints, provides clarification and takes action (Art. 41, §2 of the Brazilian General Data Protection Law — LGPD).
3. Who this policy speaks to
Aufisoft is a restaurant management system. That creates three different relationships, and the rules are not the same in all three. Find yours:
3.1 You use Aufisoft to run a restaurant
Owner, manager or staff member with an account.
We are the controller of your data. This policy applies to you in full.
3.2 You visit aufisoft.com
We are the controller. Sections 6, 9 and 10 apply.
3.3 You are a customer of a restaurant that uses Aufisoft
You placed an order through the online menu, or the restaurant registered you in their system.
In this case the controller of your data is the restaurant, not Aufisoft. They decided to collect your data and for what purpose; we only operate the system where it is stored — the LGPD calls this a processor (Art. 39).
In practice, this means:
- To exercise your rights, contact the restaurant. Their contact details are on the online menu and on the receipt.
- If you write to us anyway, we will forward it to the restaurant within 2 business days and let you know. We will not ignore you — but we also cannot decide about data we do not control.
- We provide the restaurant with the technical means to serve you.
Section 5 describes the data the restaurant handles through our system.
4. Data from those who use Aufisoft — and why
For each purpose we state the data, the reason, the legal basis and how long we keep it.
4.1 Account and access
- Data: name, email, password (stored encrypted, never in readable form)
- Purpose: create and operate your account
- Legal basis: performance of a contract — Art. 7, V
- Retention: for as long as the account exists. On deletion we anonymise your name and email (see 4.9)
4.2 Email verification and password recovery
- Data: email and a temporary code
- Purpose: confirm the email is yours and let you recover access
- Legal basis: performance of a contract — Art. 7, V
- Retention: 15 minutes
4.3 Access security
- Data: IP address, browser and device used, date and time
- Purpose: keep your session, let you review and end sessions, detect misuse
- Legal basis: legitimate interest in security — Art. 7, IX
- Retention: 6 months
4.4 Subscription and billing
- Data: name, tax ID, email, phone and billing address
- Purpose: charge the subscription and meet tax obligations
- Legal basis: performance of a contract (Art. 7, V) and legal obligation (Art. 7, II)
- Shared with: our payment processor
- Retention: 5 years after termination — statutory tax period
- We do not store your card details. They stay with the payment processor; we keep only a reference
4.5 Restaurant profile
- Data: legal name, tax ID, address, phone, email and location
- Purpose: configure the system, calculate delivery, issue invoices
- Legal basis: performance of a contract — Art. 7, V
- Shared with: a mapping service, to turn an address into coordinates
- Retention: for the duration of the contract, plus 5 years for tax purposes
4.6 Artificial intelligence assistant
This section deserves a careful read.
- Data: everything you write in the conversation, plus the restaurant data the assistant needs to answer — products, ingredients, recipes, stock, expenses
- Purpose: operate the assistant
- Legal basis: performance of a contract (Art. 7, V) for the feature; legitimate interest (Art. 7, IX) to keep the technical content of the conversation for a limited time, for troubleshooting
- Shared with: an artificial intelligence provider in the United States — the service that processes the conversation
- Retention: the visible history stays with you while the conversation exists, and the conversation is deleted after 12 months of inactivity. The raw technical content is erased after 30 days
4.7 Error diagnostics
- Data: your account identifiers and technical details of the error
- Purpose: identify and fix failures
- Legal basis: legitimate interest — Art. 7, IX
- Retention: 30 days
4.8 Browser notifications
- Data: the technical endpoint your browser provides to receive notifications
- Purpose: alert you about orders and system events
- Legal basis: your consent — Art. 7, I, given through the browser permission
- You can revoke it at any time in your browser settings
- Retention: until you revoke it, or 90 days without use
4.9 When you delete your account
How to ask: write to privacy@aufisoft.com. Our Officer handles the process and replies within the deadline in section 8.
We anonymise your name and email and remove your sessions.
We keep the account record, without identification, because orders and invoices issued through it must continue to exist by legal obligation (Art. 16, I of the LGPD). A 2024 order cannot vanish from the books because the person who recorded it left the company.
If you are the sole administrator of a restaurant, we will contact you first: deleting your account would leave the restaurant, its customers' data and its tax records without anyone responsible.
5. Data we process for restaurants
Here the controller is the restaurant (see 3.3). We list it for transparency — and so you know what is in the system.
| What | Why | For how long |
|---|---|---|
| Customer name, phone, email and tax ID | identify who placed the order | while the relationship with the restaurant lasts |
| Delivery address and location | deliver the order | same |
| Order history | run the restaurant and meet tax law | 2 years, or 5 years if an invoice was issued |
| Tax ID on the invoice | the restaurant's tax obligation | 5 years |
| Notes about the customer | customer service | as the restaurant defines |
| Store credit | the restaurant's credit control | 5 years after settlement |
| Orders from delivery apps | sync with the system | 2 years |
Delivery app orders create a customer record. When an order arrives through an integrated app, we create or update that customer's record in the restaurant's system, including the tax ID if provided. This is necessary for the restaurant to fulfil the order.
If you are a customer of a restaurant and want your data deleted, talk to them — we provide the tool, they decide. How deletion works is in 5.1.
Online menu and measurement tools. Some restaurants enable analytics and advertising tools on their menu. When that happens, we ask for your consent before any tool loads. The restaurant that configured them is responsible for those tools.
Order printing. Order data is sent to the restaurant's printer by a program installed on their computer. From that point on, the data is under the restaurant's physical control.
5.1 Deleting a customer's data
How to ask. If you are a customer of a restaurant and want your data deleted, talk to the restaurant — they decide. You can also write to our Officer at privacy@aufisoft.com; we forward it to the restaurant within 2 business days and follow it through to completion.
The restaurant carries out the deletion in the system. When orders or invoices are involved, the operation goes through our Officer, because some of the data has a retention period set by law — and it is the Officer who separates what goes from what must stay.
What happens, in three layers:
| What | What we do | When |
|---|---|---|
| Profile, addresses, phone, email, notes and credit entries | deleted | immediately |
| Name and tax ID inside orders already placed | anonymised — the order still exists, without identifying who placed it | immediately |
| Invoice issued, where applicable | kept for the statutory period, then deleted | 5 years from issuance |
In practice: once deletion is complete, the history can no longer be linked to the person — neither by the restaurant nor by us. What survives is the accounting record, without identification, as tax law requires.
Why the invoice stays. The LGPD expressly allows retaining data to meet a legal obligation (Art. 16, I), and tax documents have their own retention period. It is neither the restaurant's choice nor ours — it is an obligation nobody can waive.
You have the right to know exactly what was deleted and what was kept, and why. Ask at privacy@aufisoft.com and we will answer within the deadline in section 8.
6. Who we share with
We do not sell data. We share only with those who need to perform part of the service:
| Provider category | Why | Country | Data |
|---|---|---|---|
| Infrastructure and database | host the system | Brazil | everything, at rest |
| Payment processing | charge the subscription | Brazil | billing data |
| Tax invoicing | issue tax invoices | Brazil | invoice data, consumer's tax ID |
| Delivery platforms | sync orders | Brazil | order data |
| Postcode lookup | fill in the address | Brazil | postcode only |
| Cloud storage and delivery | backups, files and site delivery | USA | database backup, images, tax reports |
| Artificial intelligence | process the assistant | USA | conversation content |
| Transactional email | send system emails | USA | name and email |
| Maps and geocoding | turn an address into a location | USA | address and coordinates |
| Analytics and advertising | measure use of the site and the panel, and how ads perform — with your consent; and menu measurement, when the restaurant enables it | USA | browsing, with no name, email, phone number or tax ID |
| Network and routing | route restaurants' own domains | global | connection data |
We also share when required by law, a court order or legal proceedings.
7. Where your data is
The system runs in Brazil. The live database — name, email, tax ID, phone, address and order history — sits on a server in Brazilian territory.
Some data is stored in the cloud outside the country, and we want to be clear about what:
| What | Where | Why |
|---|---|---|
| Database backups | United States | protection against data loss; generated periodically and automatically deleted after the retention period |
| Product images and tax reports | United States | file storage |
| AI assistant content | United States | process your conversations |
| System emails | United States | send codes and notices |
| Addresses and maps | United States | turn an address into a location |
| Browsing on the site and the panel | United States | measure usage and traffic source — only with your consent (see section 9) |
| Traffic for menus on custom domains | global | route and protect the connection |
All of these providers are bound by contractual data protection commitments, and we choose each one considering the safeguards they offer. Only the data necessary for the stated purpose is sent to them.
8. Your rights (Art. 18 of the LGPD)
You can:
- Confirm whether we process your data
- Access your data
- Correct incomplete, inaccurate or outdated data
- Anonymise, block or delete unnecessary data or data processed unlawfully
- Export your data in a machine-readable format
- Delete data we process based on your consent
- Know who we share your data with
- Be informed about the option not to consent and what happens if you do not
- Withdraw consent at any time
How to exercise them: write to privacy@aufisoft.com. We reply through the same channel.
Response time: up to 30 days. The LGPD sets 15 days in Art. 19, II, doubled for small processing agents by Art. 14 of ANPD Resolution 2/2022, which is our case. Simple requests we answer immediately.
If you are a customer of a restaurant, contact the restaurant (see 3.3).
9. Cookies and similar technologies
This section covers all three addresses: the site aufisoft.com, the admin panel app.aufisoft.com and each restaurant's online menu. The choice you make in the banner is stored in a root-domain cookie and applies to all three — you decide once, not once per address.
| Category | Why | Who operates it | Requires consent? |
|---|---|---|---|
| Essential | keep you signed in, remember language and cart, store your own cookie choice | Aufisoft | no — the site does not work without them |
| Analytics | know which pages are viewed and how people arrive, to improve the product and decide where to invest | Google Analytics 4 and Google Tag Manager — Google LLC, United States | yes |
| Advertising | measure how ads perform and avoid showing the same ad to someone who is already a customer | Meta Pixel and Conversions API — Meta Platforms, United States | yes |
Nothing beyond the essential loads before your consent. You choose in the banner shown on your first visit, and you can change it at any time through the Cookies link in the footer — which reopens the panel with your current choice, without erasing it.
Refusing is as easy as accepting — the reject button sits next to the accept button, with the same prominence. Between them there is a Customize option that opens the categories one by one. Refusing takes no functionality away from you.
Legal basis and international transfer
The browsing data handled by the Analytics and Advertising categories is processed on the basis of your consent (art. 7, I of the LGPD), freely given and revocable at any time through the same footer link. Revoking does not erase what was already collected — it stops collection from that point on.
That data is transferred to the United States, where Google's and Meta's servers are. The transfer is made under arts. 33 to 36 of the LGPD, on the basis of standard contractual clauses in the form of ANPD Resolution No. 19/2024, signed with each supplier.
We do not send your name, email, phone number or tax ID to these tools. What leaves is a random identifier generated by the cookie itself and, in the admin panel, an internal user code that does not identify you outside our system.
10. Security
We adopt, among other measures:
- Data stored in Brazil
- Encryption in transit (HTTPS/TLS)
- Passwords stored encrypted, never in readable form
- Role and permission-based access control
- Isolation between restaurants — one cannot access another's data
- A single session per user, with the ability to end it
- Incident response plan
If a security incident occurs that may pose relevant risk or harm to you, we will notify you and the ANPD within the deadlines of ANPD Resolution 15/2024.
11. Children and adolescents
Aufisoft is a management system for businesses and is not directed at anyone under 18. We do not knowingly collect data from children or adolescents.
The online menu is a general-purpose service, operated by each restaurant. If you are a legal guardian and identified improper use, write to privacy@aufisoft.com.
12. Changes to this policy
We may update this policy. Relevant changes will be communicated by email or in-app notice with reasonable advance warning.
Every version gets a number and an effective date, and previous ones remain available at aufisoft.com/privacidade/v/{version}.
13. Contact us and the ANPD
- Data Protection Officer: privacy@aufisoft.com
- General contact: contact@aufisoft.com
- Brazilian Data Protection Authority (ANPD): https://www.gov.br/anpd
You may petition the ANPD at any time (Art. 18, §1), but we ask that you talk to us first — it is usually faster.
Version history
- v1.1 — 27/08/2026: section 9 now names who operates each cookie category — Google LLC for Analytics, Meta Platforms for Advertising — states the legal basis of consent (art. 7, I) and the international transfer under arts. 33 to 36 with standard clauses in the form of ANPD Resolution No. 19/2024, and says explicitly that the admin panel is covered by the same choice. Advertising is no longer consented together with Analytics: they are two separate categories in the banner. It replaces v1.0, which was dated 01/09/2026 and was superseded before taking effect; its text remains available at /privacidade/v/1.0.
- v1.0 — 01/09/2026: full rewrite based on the actual processing inventory. It now identifies the controller, names the processors, distinguishes controller and processor roles, states retention per purpose, declares the response deadline, and aligns the text with what the system actually does.