Legal

Privacy Policy

Version 1.0 · Last updated: 08/06/2026

This Policy explains how WiseData Business LTDA, CNPJ 53.182.850/0001-14, processes personal data in the context of the WiseData Time platform, in compliance with Brazilian Law 13.709/2018 (LGPD). This is a translation for convenience; in case of divergence, the Portuguese version prevails.

1. Scope and acceptance

This Policy applies to the wisedatatime.com website, the WiseData Time platform, the official browser extension and communications relating to these services.

By using any of these services, you confirm that you are aware of the practices described here. This Policy forms part of the Terms of Use.

2. Intended audience and minimum age

The Platform is intended for professional use by companies and self-employed professionals. It is not intended for people under 18 and we do not knowingly collect data from children or adolescents.

Where we identify a registration that breaches this rule, the account may be closed and the data deleted.

3. Roles under the LGPD

We are controllers in relation to the data of those who subscribe to or express interest in the Platform: account registration data, billing data, access records and support interactions.

We are processors in relation to the data the Customer enters into the Platform in the course of their own activity: data of the users they invite, data of the end clients they register, time entries, rates and costs. In that case, the Customer is the controller and defines the purposes of processing.

As processors, we handle that data exclusively in line with the Customer's instructions and as necessary to deliver the contracted service.

4. What data we collect

Registration data: name, email, password in encrypted form, preferred language and, where applicable, phone number.

Tax and billing data: legal name or full name, tax ID, address and details needed to issue a tax document. Complete credit card details are not stored by us — processing is handled by a third-party payment operator.

Platform usage data: clients, projects, tasks, tags, time entries with date, duration and description, billable marking, billing rates and, where recorded by the Customer, hourly costs.

Technical and security data: IP address, browser and device type, date and time of access, session history and logs of security-relevant events.

Website navigation data: pages visited, source of the visit and campaign parameters, collected as described in section 6.

Communication data: messages exchanged with support and the content of contact forms.

6. Cookies and measurement

We use essential cookies, required for authentication and session security. The Platform does not work without them, and for that reason they do not depend on consent.

We also use a tag management tool to measure website performance — pages visited, source of access and navigation between screens — in aggregate form. We do not use this measurement for behavioural advertising or to build profiles of individuals.

You can block or delete cookies in your browser settings. Blocking essential cookies will prevent use of the Platform. Further detail is in our Cookie Policy.

7. Data sharing

We share data only with processors necessary to deliver the service, always under contract and subject to confidentiality: infrastructure and hosting provider, payment operator, transactional email provider, support tool and error monitoring tool.

We may share data to comply with a legal obligation, court order or request from a competent authority, and to exercise our rights.

In the event of a corporate reorganisation, data may be transferred to the successor, maintaining the terms of this Policy, with prior notice to data subjects.

We do not sell personal data.

8. International transfers

Some of our processors maintain infrastructure outside Brazil. In those cases, the international transfer meets LGPD requirements and is supported by contractual clauses ensuring a level of protection compatible with Brazilian legislation.

9. Information security

We adopt technical and administrative measures to protect data, including encrypted traffic, passwords stored with a key derivation algorithm, two-factor authentication available, role-based access control, isolation between different customer accounts, and logging of security events.

Hourly cost data has its own access control, separate from other permissions: users without that permission do not receive those figures in the system, in reports or in exports.

No system is entirely immune to incidents. In the event of a security incident posing relevant risk to data subjects, we will notify those affected and Brazil's National Data Protection Authority within the timeframes and in the manner required by the LGPD.

10. Retention and deletion

We retain data for the duration of the contractual relationship and for the applicable statutory periods afterwards — in particular tax periods and the access-log retention period set out in Brazil's Internet Civil Framework.

Once an account is closed, the Customer has a period to export their content before permanent deletion, as stated in the Platform at the time of the request.

Deleting an account removes the data linked to it comprehensively, including domain records created during use, save for data whose retention is required by law.

Moving to a plan of narrower scope does not mean deletion: data that stops being displayed remains stored and becomes accessible again if the plan is resumed.

11. Data subject rights

Under the LGPD, you may request: confirmation that processing exists; access to the data; correction of incomplete, inaccurate or outdated data; anonymisation, blocking or deletion of unnecessary data or data processed unlawfully; portability; information about sharing; information about the possibility of withholding consent and the consequences of doing so; and withdrawal of consent.

Requests relating to data entered by a Customer into the Platform should be directed first to that Customer, who is the controller of that data. When we receive such requests, we forward them to the responsible controller and provide the necessary support.

12. Privacy contact channel

Requests relating to personal data and to this Policy should be sent to privacidade@wisedatatime.com.

We will respond within the applicable statutory period. We may request additional information to confirm the requester's identity before acting — a measure that protects the data subject themselves.

13. Communications and anti-fraud

We send transactional communications necessary to the relationship, such as registration confirmations, billing notices, budget alerts configured by the Customer and security notifications. These do not depend on consent and cannot be switched off while the account is active.

Marketing communications depend on consent and can be cancelled at any time via the unsubscribe link in each message.

We may analyse usage patterns to identify abuse, fraud or improper automated use, on the basis of the legitimate interest in protecting the Platform and other customers.

14. Browser extension (Chrome)

We offer an extension for the Google Chrome browser with a single purpose: logging project hours without leaving the tab you're in. Unlike our calculator extensions, this one requires an account and transmits data to our servers — here is exactly what it does.

There is collection and transmission of data. Time entries created, edited or deleted in the extension are sent to your account on the Platform and receive the same treatment described in this Policy. The extension also fetches the list of clients and projects in your workspace in order to display it in the panel.

What the extension stores on your device: only the access code that connects it to your account and the preference for the last project used, in the browser's own local storage, restricted to the extension's internal contexts. Nothing beyond that is persisted locally.

The access code is narrowly scoped. It authorises only time-entry operations and reading of clients and projects. It grants no access to billing rates or team costs — meaning remuneration data does not travel through the extension by architectural decision, not by configuration. You can list and revoke active codes at any time within the Platform.

The extension does not read the content of the pages you visit. It uses only the side panel, local storage and alarm permissions — the last used exclusively to refresh the icon indicator while a timer is running. We do not request permission to access tabs, page scripts or all sites.

The extension executes no remote code, uses no third-party cookies, carries no advertising and shares no data with third parties beyond the processors already listed in section 7 of this Policy.

Uninstalling the extension removes the locally stored access code along with it. We recommend also revoking it within the Platform, especially if the device is shared or replaced.

Use of the extension is additionally subject to the policies of the Chrome Web Store and of Google.

15. Offline operation

So that an hour worked isn't lost when the internet is down, the Platform temporarily holds entries not yet uploaded on the user's own device and transmits them automatically as soon as the connection returns.

That data stays on your device, is not accessible by other sites, and is removed after successful upload. While something is pending, the Platform shows that state on screen.

Clearing site data through your browser settings deletes entries that have not yet been uploaded.

16. Changes to this policy

We may update this Policy periodically. The most recent version will always be available on this page, with a version number and date.

For material changes, we will notify you by email or by notice within the Platform.

17. Governing law and jurisdiction

This Policy is governed by Brazilian law. The courts of the district of Goiânia, state of Goiás, Brazil, are elected to settle any dispute, to the exclusion of any other, however privileged.

← Back to the home page