LGPD · Transparency

Privacy Policy

How we process account, usage, content, audit and contact data at Rota Nacional.

Responsibility

Privacy before inference and transparency throughout the service.

1. Controller and contact

Rota Nacional is a product of Exponencial Administração e Tecnologia LTDA, Brazilian company registration 39.556.809/0001-30, with registered office at Rua Copaíba, Lot 01, Block B, Suite 408, Norte (Águas Claras), Brasília — DF, 71919-540, Brazil. Exponencial is the controller of registration, relationship, security and platform usage data. Privacy requests may be sent to juridico@exponencialadm.net.

2. When we act as processor

For prompts, documents, audio, images and other content submitted by a client organization, that organization normally determines the purpose and acts as controller. Exponencial acts as processor under the contract, configured policy and documented instructions, without using customer content for advertising.

3. Data processed

We process name, Google-verified email, profile picture, organization, role, acceptance of terms, account keys and settings; usage, quota, billing, model, status, latency, origin, browser, IP, country and region metadata; contact details; and content submitted to contracted capabilities. Standard records show PII categories and counts, not the personal values detected.

4. Purposes and legal bases

We use this data to create and protect accounts, perform the service and contracts, enforce policies and quotas, provide support, answer inquiries, prevent fraud and abuse, maintain audit trails, comply with legal duties and exercise legal rights. Depending on the context, processing is based on pre-contractual steps or contract performance, legal obligation, legitimate interests assessed against the data subject's rights, and consent when required.

5. Privacy layer and auditing

Before inference or job creation, the organization's policy may replace, remove or block detected personal data. In monitoring mode, content is not sanitized before the next step, and the organization must make that higher-risk choice. When auditing is enabled, input and output may be stored only in an AES-256-GCM encrypted envelope, with restricted and logged administrative access.

6. Retention

The standard retention period for encrypted audit content is 30 days and may be extended by contractual configuration; when it expires, the object is automatically purged. Sessions last up to 30 days and may be revoked. Account, usage, billing and security metadata is kept while needed to operate the relationship and afterwards for the period required by legal duties, fraud prevention or legal claims. Contact records are kept while the inquiry is active and for the corresponding justifiable period.

7. Sharing and international transfers

We use infrastructure, authentication, payment and processing vendors strictly necessary for the service. Core application and data infrastructure is located in Brazil, but authentication and optional inference may involve processing abroad, including in the United States. We limit transfers to what is necessary, apply the privacy layer before sending when required by policy, and use a valid mechanism under the LGPD and ANPD regulations. The region and subprocessors applicable to an enterprise engagement may be detailed in the proposal or agreement.

8. Email communications

Primary registration uses a Google account with an already verified email address; Rota Nacional has no password of its own and sends no password-reset email. A registered passkey may also be used to sign in. The public form generates an internal team notification without an automatic confirmation to the submitted address. When user notifications are enabled, they will be limited to transactional account, security, quota, service or requested-support alerts. We do not buy lists or send bulk campaigns.

9. Data-subject rights

A data subject may request confirmation and access, correction, information about sharing, anonymization, blocking, portability or deletion where applicable, revoke consent and object to unlawful processing. We may verify the requester's identity. If the request is not resolved, the data subject may petition the ANPD or consumer-protection authorities.

10. Security and updates

We use TLS, encryption at rest, credential separation, access control, abuse limits and operational logs without raw content. No detection technique is infallible; the organization remains responsible for choosing an appropriate policy and avoiding unnecessary content. This policy may be updated to reflect legal, operational or product changes.

Last reviewed: September 22, 2026.