Fraterly processes personal data and operational data related to the administrative management of lodges, obediences and powers. This policy explains what information may be collected, for which purposes, under which legal bases, for how long it may be retained and how data subjects may exercise their rights.
1. Data controller
The data controller is Fraterly Ltda., CNPJ 37.649.941/0001-60, with registered office at R Chiara Lubich, 371 - APT 92, Jundiaí, São Paulo, 13212-117, Brazil.
Privacy contact: privacidade@fraterly.online
General contact: contact@fraterly.online
2. Categories of data
- Contact data: name, email, phone, organization and country.
- Account data: access credentials, authentication factors, recovery history and preferences.
- Administrative data: members, offices, degrees, sessions, minutes, attendance, documents and charges.
- Technical data: IP, device, browser, access timestamps, operational logs and security events.
- Location data: when GPS-based attendance validation is enabled and authorized.
3. Processing purposes
- To provide the contracted SaaS service and keep the environment available.
- To authenticate users, protect accounts and manage permissions by profile, context and degree.
- To support secretariat, treasury, library, minutes, documents, communications and reports.
- To handle onboarding, support, demos and commercial contact.
- To comply with legal, tax, contractual, audit and information security obligations.
4. Legal bases
Processing may rely, depending on the case, on contract performance, pre-contractual steps, legal obligation, legitimate interest, consent and the exercise of legal rights. Where geolocation, non-essential communications or optional features are involved, specific consent may be required.
5. Potentially sensitive data
Certain records may reveal associative, documentary, philosophical or ritual information. For that reason, Fraterly adopts a design based on minimization, document classification, logical segregation, permissions by context and, where applicable, additional degree-based control.
6. Sharing and subprocessors
Fraterly does not sell personal data. Information may only be shared with infrastructure providers, email services, support providers, billing processors, competent authorities or administrators properly authorized by the client entity, always within the necessary purpose.
7. International transfers
Because the service is designed for global operation, processing may occur on infrastructure located outside the data subject’s country. In such cases, Fraterly seeks to apply appropriate safeguards, such as contractual clauses, data processing agreements and equivalent security controls.
8. Information security
- Strong authentication and MFA readiness.
- Access control by profile, entity, context and degree.
- Document classification and logical segregation of data.
- Access logs, operational logs and before/after audit trails.
- Backups, traceability and recovery mechanisms.
9. Retention
Data is retained for as long as necessary to fulfil contractual and legal purposes. Logs, financial records, consents and critical documentation may be kept for different periods depending on law, client policy and security needs.
10. Data subject rights
Data subjects may request access, correction, update, objection, restriction, portability, deletion and information about sharing, in accordance with applicable law. Requests may be submitted through the privacy channel indicated in this policy.
11. Cookies and preferences
The website and application may use technical cookies, session cookies, language preferences and, in the future, analytics or marketing cookies, always in line with applicable law and any required consent collection.
12. GDPR, LGPD and applicable rules
Fraterly’s operation takes into account GDPR, LGPD and other local rules on data protection, security, billing and retention. The final wording of this policy should be validated by legal counsel before definitive commercial publication.
13. Policy updates
This policy may be revised to reflect changes in the technical architecture, commercial model, subprocessors, data flows and applicable law. The version published on the site will always be the current one.
