Institutional document
Privacy Policy
This document sets out how personal data is processed throughout the OpereBem ecosystem.
1. Purpose, scope and controller
This Privacy Policy describes the processing of personal data carried out by OpereBem through its websites, applications, products, communities, support channels and other digital services. For processing activities in which it determines the purposes and means, the controller is Mateus Teixeira, responsible for operating the OpereBem brand, hereinafter “OpereBem”.
The policy applies to the institutional website and to current or future products within the same ecosystem, including Terminal OpereBem, Student Portal, OpereBem Academy, Diário OpereBem, TradeZen or LogTrady, community, Under16, partner and careers pages, APIs, administrative areas, service status page and support services.
Where a provider or partner independently determines how it processes personal data, its own policy also applies. Specific notices presented at the point of collection supplement this document.
2. Services and processing contexts
- Account and identity: central registration, authentication, access recovery, session management, profile, plan and product integrations.
- Terminal and market data: access to tools, quotes, plans, contracted features, preferences and operational records.
- Student Portal and education: enrolments, payments, progress, assessments, certificates, materials, interest lists and academic support.
- Journal, TradeZen and LogTrady: trading accounts, transactions, imports, images, notes, checklists, setups, emotional journal, goals and performance analytics.
- Community: Discord or equivalent integrations, member identification, messages referred to moderation, verification, benefits and security logs.
- Institutional and relationship: contact, authorised marketing, partnerships, recruitment, support, Under16, surveys and service communications.
3. Categories of personal data
The categories actually processed depend on the service used and the interaction performed.
| Category | Examples |
|---|---|
| Identification and contact | Name, email, telephone, country, Brazilian taxpayer number (CPF), date of birth and legal guardian data where necessary. |
| Account and authentication | Internal identifiers, password protected by hashing, tokens, sessions, verification codes, profile, plan and permissions. |
| Contracting and payment | Product, plan, subscription status, transaction history and purchase or payment-provider identifiers. OpereBem does not store full card details where payment is processed by a third party. |
| Education | Enrolments, courses, progress, assessments, certificates, questions, answers and academic interactions. |
| Trading and user content | Broker, account, instruments, orders, results, dates, times, strategies, notes, emotions, goals, checklists, chart drawings, files and uploaded media. |
| Community and support | Username, Discord identifier and avatar, verification code, messages, requests, attachments and moderation or support records. |
| Recruitment and partnerships | Résumé, education, experience, LinkedIn, GitHub, portfolio, Discord, message and position of interest. |
| Device, use and security | IP address, browser, operating system, session identifiers, pages accessed, date, time, referrer, language, time zone, error events and access attempts. |
| Preferences and marketing | Consent records, cookie choices, campaign source, UTM parameters, themes and communication preferences. |
OpereBem does not request broker credentials, banking passwords or full card details through ordinary forms. Data subjects should not enter third-party data, excessive information or sensitive data in free-text fields, notes, messages or uploads without necessity and authorisation.
4. Sources of data
Data may be provided directly by the data subject or legal guardian; generated through use of the services; received from integrations authorised by the data subject; supplied by companies, schools or partners within a legitimate relationship; or received from authentication, payment, hosting, analytics and community providers.
Where an import contains information about other people, the person uploading it represents that they have authorisation or another valid legal basis and must limit the content to what is strictly necessary.
5. Purposes and legal bases
| Purpose | Applicable legal basis |
|---|---|
| Create and manage accounts and provide requested products, courses, certificates, support and integrations. | Performance of a contract or preliminary procedures related to a contract. |
| Process charges, reconcile subscriptions and comply with tax, accounting and regulatory duties. | Performance of a contract and compliance with a legal or regulatory obligation. |
| Protect accounts, prevent fraud and abuse, record events, investigate incidents and exercise rights. | Legitimate interests, compliance with legal obligations and the regular exercise of rights. |
| Calculate metrics, customise features, maintain and improve products and infrastructure. | Performance of a contract and legitimate interests, subject to necessity, transparency and data-subject rights. |
| Send promotional communications and enable non-essential cookies or analytics. | Consent where required, with a right to withdraw. |
| Respond to contacts, assess applications and negotiate partnerships or contracts. | Pre-contractual procedures and legitimate interests. |
| Operate initiatives intended for children and adolescents. | A legal basis appropriate to the case, always prioritising the child's best interests and obtaining guardian consent where applicable. |
Where legitimate interests are relied upon, OpereBem considers the legitimate purpose, necessity, the data subject's expectations, the impact on their rights and the available safeguards.
6. Cookies, local storage and analytics
Cookies and similar technologies may be used for authentication, security, preferences, session continuity, technical operation, measurement and analysis. Strictly necessary technologies are used to provide the service. Analytics, advertising or other optional purposes depend on the choices shown in the preference manager where applicable.
Data subjects may review their choices in the cookie manager and control technologies through their browser. Disabling necessary items may prevent authenticated features from working.
7. Children and adolescents
Children's and adolescents' personal data is processed in their best interests. In Under16 or other services intended for this audience, OpereBem provides age-appropriate information, limits collection to what is necessary, adopts access controls and requests the involvement or consent of a legal guardian where required.
Behavioural advertising is not directed at children. A legal guardian may request information, correction or account closure through the privacy channel.
8. Sharing and processors
OpereBem does not sell personal data. Data is shared only where necessary and consistently with the purposes of this policy, including with:
- hosting, database, CDN, monitoring, security, email, support and development providers;
- payment and billing providers, such as Stripe, which process data under their own legal and contractual duties;
- analytics, authentication, community and integration platforms enabled by the data subject;
- professionals bound by confidentiality, such as accountants, lawyers and auditors;
- public authorities under a legal duty, valid order or the regular exercise of rights;
- successors in a corporate reorganisation, subject to applicable safeguards.
Providers receive only the data necessary for the contracted activity and are subject to confidentiality, security and data-protection requirements consistent with their role.
9. International transfers
Some providers may process or store data in other countries. In such cases, OpereBem adopts mechanisms permitted by the LGPD and regulations issued by Brazil's National Data Protection Authority (ANPD), such as adequacy decisions, standard contractual clauses, approved specific clauses or binding corporate rules, as applicable.
10. Retention and deletion
Data is retained for the period necessary for the stated purpose. Criteria include the duration of the account or contract, availability of the requested feature, legal and regulatory periods, fraud prevention, security, audits, exercise of rights and dispute resolution.
After processing ends, data is deleted or anonymised unless retention is permitted or required by law. Backups follow their own replacement cycles and remain protected until deletion. Security-incident records are retained for the applicable regulatory period.
11. Security and incidents
OpereBem adopts technical and administrative measures proportionate to the risks, including access controls, authentication, credential protection, secure connections, permission segregation, security logs, updates, backups and provider assessments. No environment is completely immune to failure, so safeguards are reviewed as services and risks evolve.
Incidents are assessed and contained in accordance with response procedures. Where an incident may cause relevant risk or harm, OpereBem will notify the ANPD and affected data subjects under the applicable rules and deadlines.
12. Data-subject rights
Under the LGPD, data subjects may request, as applicable:
- confirmation of processing and access to data;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- portability, subject to ANPD regulations and commercial and industrial secrets;
- information about public and private entities with which data has been shared;
- information on the possibility and consequences of refusing consent;
- withdrawal of consent and deletion of data processed on that basis, subject to lawful retention;
- objection to processing based on a waiver of consent where the LGPD has been breached;
- review of decisions made solely through automated processing that affect their interests, where applicable;
- petition before the ANPD and consumer-protection bodies.
Requests should be sent to contato@operebem.com.br with the subject “Privacy and LGPD”. Additional information may be requested to confirm identity and protect the data subject. Responses follow legal deadlines; requests may be restricted where they conflict with retention obligations, third-party rights, security or commercial and industrial secrets.
13. Automated processing and financial data
The Journal, Terminal and related tools may automatically calculate metrics, classifications, alerts and analyses from data supplied or imported by the user. These outputs are informational, educational and organisational; they are not financial advice, an investment recommendation or a decision with legal effect on the data subject.
If a decision based solely on automated processing that affects a data subject's interests is implemented, clear information about the criteria and a channel to request review will be provided, subject to commercial and industrial secrets.
14. Data Protection Officer and contact channels
Controller: Mateus Teixeira, responsible for operating the OpereBem brand
Data Protection Officer: Patrick Siotti
Privacy and data-subject rights: contato@operebem.com.br, subject “Privacy and LGPD”
15. Updates and references
This policy may be updated to reflect legal, regulatory, technical or operational changes. Material changes will be communicated through an appropriate channel. The current version and its update date will remain available on this page.
Official references: Brazilian General Data Protection Law, data-subject rights, international transfers and incident reporting.
