HuberPro

Privacy Policy

Syntrp Tecnologia LTDA — Version 1.0

May 15, 2026  |  LGPD  —  Law No. 13.709/2018

Preamble

Syntrp Tecnologia LTDA, a private legal entity registered under CNPJ No. 66.408.569/0001-07, headquartered at RUA CUSTODIO SERRAO, 873, ZIP CODE 05116-011 (“Syntrp”, “we” or “our”), is the controller of personal data collected through the HuberPro application (“Application” or “Platform”).

This Privacy Policy (“Policy”) describes how we collect, use, store, share and protect the personal data of HuberPro users (“User” or “you”), in compliance with Brazilian Law No. 13.709/2018 (General Data Protection Law — LGPD), the Internet Civil Framework (Law No. 12.965/2014) and other applicable regulations.

BY USING THE HUBERPRO APPLICATION, YOU DECLARE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY AND CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED HEREIN.

1. Definitions

For the purposes of this Policy, the following definitions apply, in addition to those provided in the Terms of Use:

Personal Data: information relating to an identified or identifiable natural person.

Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or organization of a religious, philosophical or political nature; data relating to health, sexual life, genetic or biometric data.

Processing: any operation performed with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation, control, modification, communication, transfer, dissemination or extraction.

Controller: natural or legal person who makes decisions regarding the processing of personal data — in this case, Syntrp.

Processor: natural or legal person who processes data on behalf of the controller.

Data Subject: natural person to whom the personal data being processed refers — in this case, the User.

Data Protection Officer (DPO): person appointed by the controller to act as a communication channel between the controller, data subjects and the National Data Protection Authority (ANPD).

ANPD: National Data Protection Authority.

Consent: free, informed and unambiguous expression by which the data subject agrees to the processing of their personal data for a specific purpose.

2. Personal Data Collected

2.1 Data Provided Directly by the User

When creating an Account and using the Application, the User may provide the following data:

Registration data: full name, email address, password (stored in encrypted form), phone number and professional field.

Profile data: profile photo, technical specialties, geographic location (city/state), years of professional experience and other information the User chooses to include.

Generated content: questions, answers, comments and files published in the Technical Community.

Communications: messages sent to Syntrp support or service channels.

Payment data: for Premium plans, billing data such as cardholder name, partial card number and billing address. Full payment data is processed by certified third-party providers and is not stored by Syntrp.

2.2 Automatically Collected Data

When accessing and using the Application, we automatically collect:

Device data: device type, operating system, OS version, unique device identifiers, device model.

Usage data: features accessed, terms searched, session time, pages visited, interactions performed, frequency of use.

Network data: IP address, connection type (Wi-Fi, mobile data), internet provider.

Location data: approximate location based on IP. We do not collect precise GPS location without explicit consent.

Log data: access records as required by Article 15 of the Internet Civil Framework, including date, time and duration of sessions.

2.3 Third-Party Data

We may receive User data from third parties in the following situations: social login — if the User chooses to register via Google, Apple or other social authentication platforms; analytics partners — aggregated and anonymized data from application usage analytics platforms.

2.4 Data We Do Not Collect

Syntrp does not intentionally collect sensitive personal data (as defined in Article 5, II of the LGPD) through the Application. If the User voluntarily includes such data in publications in the Technical Community, they do so at their own initiative and responsibility.

3. Purposes of Data Processing

3.1 Contract Performance and Service Provision

Data is used to create and manage the User Account; authenticate access to the Application; provide the Error Database and Technical Community features; process Premium plan payments; send transactional notifications (registration confirmation, password recovery, payment confirmation).

Legal basis: contract performance (Article 7, V, LGPD).

3.2 Compliance with Legal and Regulatory Obligations

Data is used to maintain access records as required by the Internet Civil Framework; comply with tax and fiscal obligations; respond to requests from competent authorities.

Legal basis: compliance with legal or regulatory obligation (Article 7, II, LGPD).

3.3 Service Improvement and Product Development

Data is used to analyze usage behavior and improve features; identify technical failures and fix bugs; develop new features; conduct satisfaction surveys (when the User agrees).

Legal basis: legitimate interest (Article 7, IX, LGPD).

3.4 Communication and Marketing

Data is used to send communications about Application updates, new features and Error Database content; send newsletters, Premium plan offers and promotional communications — only with User consent; personalize the User experience on the Platform.

Legal basis: consent (Article 7, I, LGPD) for marketing; legitimate interest for service communications.

3.5 Security and Fraud Prevention

Data is used to detect, prevent and investigate fraudulent activities, abuse and violations of the Terms of Use; protect the integrity of the Platform and other Users; verify the User identity when necessary.

Legal basis: legitimate interest (Article 7, IX, LGPD) and compliance with legal obligation.

3.6 Regular Exercise of Rights

Data may be used in judicial, administrative or arbitration proceedings when necessary to defend Syntrp rights.

Legal basis: regular exercise of rights (Article 7, VI, LGPD).

4. Data Sharing

4.1 Sharing Scenarios

Syntrp may share the User personal data with third parties in the following situations:

Service Providers and Partners (Processors): cloud infrastructure providers, certified payment processors (PCI-DSS), usage analytics services, email and push notification services, customer support tools. These providers are contractually obligated to process data only in accordance with Syntrp instructions.

Public Authorities: when required by law, court order, or to cooperate with competent governmental or regulatory authorities.

Rights Protection: when necessary to protect the rights, property or safety of Syntrp, its Users or third parties.

Corporate Restructuring: in the event of a merger, acquisition, incorporation or sale of Syntrp assets, User data may be transferred to the acquirer.

With User Consent: for any other purpose, with the User prior and specific consent.

4.2 Data We Do Not Share

Syntrp does not sell, rent or commercialize Users personal data to third parties for marketing or third-party advertising purposes.

4.3 International Data Transfer

Some of our technology providers may be located outside Brazil. In such cases, international data transfer will only occur to countries that offer an adequate level of protection or through the adoption of appropriate contractual safeguards (standard contractual clauses), in accordance with Article 33 of the LGPD.

5. Data Retention and Deletion

5.1 Retention Periods

The User personal data will be retained for the time necessary to fulfill the purposes for which it was collected:

Active account data: for the duration of the Account.

Access log data: for a minimum of 6 (six) months, as required by Article 15 of the Internet Civil Framework, and may be extended to 1 (one) year or more by court order.

Payment data: for the period required by tax and fiscal legislation, generally 5 (five) years.

Data for legal proceedings: for the statute of limitations period for applicable actions, as provided by the Civil Code.

5.2 Data Deletion

After the retention period expires, data will be securely deleted or anonymized so the data subject can no longer be identified. The User may request early deletion of their data, subject to the legal exceptions provided in Article 16 of the LGPD.

6. Data Subject Rights

Under the terms of the LGPD (Article 18), the User has the following rights:

(1) Confirmation and access — confirm the existence of processing and access their personal data.

(2) Correction — request correction of incomplete, inaccurate or outdated data.

(3) Anonymization, blocking or deletion of unnecessary, excessive data or data processed in non-compliance with the LGPD.

(4) Portability — receive their data in a structured and interoperable format.

(5) Deletion — request deletion of data processed on the basis of consent.

(6) Information on sharing — obtain information about which entities their data has been shared with.

(7) Information about the possibility of not consenting and the consequences of such a decision.

(8) Withdrawal of consent at any time, without prejudice to the lawfulness of prior processing.

(9) Objection to processing carried out in non-compliance with the LGPD.

(10) Review of decisions made solely on the basis of automated data processing that affect the User interests.

6.1 How to Exercise Your Rights

DPO Email: [INSERT DPO EMAIL]
Platform Form: [INSERT FORM URL]

Syntrp will respond to requests within a maximum of 15 (fifteen) calendar days, which may be extended by a further 15 days with a reasoned justification.

7. Information Security

7.1 Technical and Organizational Measures

Syntrp adopts adequate technical and organizational measures to protect Users personal data against unauthorized access, destruction, loss, alteration or improper disclosure, including:

— encryption of data in transit (TLS/SSL) and at rest;

— storage of passwords with secure hashing algorithms (e.g., bcrypt);

— profile-based access control (principle of least privilege);

— security monitoring and intrusion detection;

— internal information security policies and employee training;

— periodic security testing and vulnerability assessments.

7.2 Security Incidents

In the event of a security incident that may cause relevant risk or harm to the User, Syntrp will notify the ANPD and the data subject within a reasonable timeframe, in accordance with Article 48 of the LGPD, describing the nature of the affected data, the measures taken to mitigate risks and the DPO contact information.

7.3 User Responsibility

The User is responsible for maintaining the confidentiality of their access credentials and for using secure devices. Syntrp is not responsible for security incidents resulting from the User own negligence.

8. Cookies and Similar Technologies

8.1 Use of Cookies

HuberPro may use cookies and similar technologies to: keep the User session authenticated; remember User preferences; collect usage data for analysis and service improvement; measure the effectiveness of marketing campaigns (when applicable).

8.2 Types of Technologies Used

Strictly necessary: essential for the Application to function (cannot be disabled).

Analytics/performance: collect data on how the User uses the Application, in aggregated and anonymized form.

Preference cookies: store settings chosen by the User.

Marketing: used for personalized communications, only with User consent.

8.3 Management

The User can manage their cookie and tracking preferences in the Application settings. Disabling certain technologies may affect the operation of some features.

9. Children's Data

HuberPro is not directed at children under 13 (thirteen) years of age. Users between 13 and 17 years of age must have the assistance or legal representation of their guardians to register and use the Application. If Syntrp identifies that data from children under 13 was collected without adequate parental consent, such data will be promptly deleted.

10. Data Protection Officer (DPO)

Under the terms of Article 41 of the LGPD, Syntrp designates as Data Protection Officer:

Name: [INSERT DPO NAME]
Email: [INSERT DPO EMAIL]
Address: RUA CUSTODIO SERRAO, 873, JAGUARA, SAO PAULO – SP, ZIP CODE 05116-011

The DPO is the official communication channel between Syntrp, Users and the National Data Protection Authority (ANPD).

11. Third-Party Links and Integrations

The Application may contain links to third-party websites or services, including social login platforms and external tools. This Policy does not apply to third-party services. We recommend that the User read the privacy policies of each service accessed outside of HuberPro.

12. Changes to this Policy

Syntrp reserves the right to update this Policy periodically to reflect changes in its data processing practices, legal changes or service improvements. Significant changes will be communicated to the User with a minimum of 15 (fifteen) days notice, through notification in the Application or by email. Continued use of the Application after changes take effect will constitute acceptance of the new version of the Policy.

13. Contact and Support Channels

For questions, requests or complaints about this Policy or about the processing of your personal data, the User may contact Syntrp through the following channels:

General email: CONTATO@SYNTRP.COM
DPO email: [INSERT DPO EMAIL]
Website: WWW.HUBERPRO.COM
Postal address: RUA CUSTODIO SERRAO, 873, JAGUARA, SAO PAULO – SP, ZIP CODE 05116-011
Phone: 11 2367-3650

The User may also file a complaint with the National Data Protection Authority (ANPD) at: www.gov.br/anpd.

14. Governing Law and Jurisdiction

This Policy is governed by Brazilian law, in particular the LGPD (Law No. 13.709/2018) and the Internet Civil Framework (Law No. 12.965/2014). Any disputes arising from this Policy shall be submitted to the courts of SAO PAULO – SP, except where privileged jurisdiction is provided by law for consumers.

Syntrp Tecnologia LTDA  —  HuberPro  —  Version 1.0  —  May 15, 2026

Botão WhatsApp Flutuante
Building the technological infrastructure for critical business operations

Follow us

CONTACT
contato@syntrp.com
11 99308-7403

© 2026 Syntrp Tecnologia LTDA · CNPJ 66.408.569/0001-07 · All rights reserved.