Privacy Policy

This policy explains how Hendu handles personal data on this website and in the product, following the structure of Brazil's General Data Protection Law (Law 13.709/2018). It applies to site visitors, to anyone who fills in a form, and to people who use the platform inside a customer company.

Who handles your data

Hendu is operated by CASSIO MASSASHI DUARTE SAGAWA CONSULTORIA EM MARKETING LTDA, registered under Brazilian company number (CNPJ) 39.398.580/0001-52, which is the controller of the personal data you give it directly, such as the data in a form on this site and the data in a platform account. For the work content a customer company connects to Hendu, that company is the controller and Hendu acts as a processor, handling the content only to deliver the contracted service.

What data we handle

On the site, we handle what you type into a form: name, work email, phone, role, and the answers you give in a diagnostic when you choose to answer one. We also handle browsing data, such as pages viewed, traffic source and cookie identifiers.

In the product, we handle your account data and the work content your company connects, which can include messages, calendar, CRM records, documents and meeting transcripts. That content remains the customer company's.

Why we handle it

To deliver the material or the access you asked for. To talk to you about Hendu, where there is a commercial relationship or demonstrated interest. To operate, maintain and improve the platform. For security, fraud prevention and access logging. And to comply with legal or regulatory obligations.

On what legal basis

Performance of a contract, for customers and for companies in active negotiation. Legitimate interest, for communicating with people who requested material and for service security, always kept within what the purpose requires. Consent, where the law requires it, with a record of when and how it was given and the option to withdraw at any time. Compliance with a legal or regulatory obligation, where applicable.

Your data is not used to train models

Work content connected by a customer company is not used to train any model shared with other customers or with third parties. Processing happens within that company's context, and the language model providers Hendu uses are contracted on the condition that they neither retain nor train on the content they receive.

Who we share it with

With the processors the service needs to run, in the categories of cloud hosting and infrastructure, email delivery, site usage measurement, customer support and language model providers. All of them are contracted under terms that require the same level of protection as this policy, and each receives only the minimum its function needs. Hendu does not sell personal data.

International transfers

Part of the infrastructure and some processors sit outside Brazil. In those cases, transfers rely on the safeguards set out in Chapter V of the LGPD, including specific contractual data protection clauses.

How long we keep it

Contact data from someone who requested material is kept for up to 24 months after the last interaction, or until you ask for deletion, whichever comes first. Account data and work content are kept for the term of the contract and for 90 days after it ends, the window in which the company can export what is its own; after that they are deleted. Application access logs are kept for six months, as Brazil's Internet Civil Framework requires. Data under a legal or tax obligation is kept for five years, and during that time it is handled only for the purpose that requires keeping it.

Your rights

The LGPD gives you the right to confirmation that processing exists, access to the data, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about who the data was shared with, information about the option not to consent, and withdrawal of consent. To exercise any of them, write through the contact form on this site. You will get an answer within the legal deadline.

If you use Hendu inside a customer company and your request concerns that company's work content, Hendu forwards the request to the company, which is the controller of that content, and supports the response.

Cookies

Necessary cookies keep the site working, and there are four: the one that unlocks your access to a material after sign-up, the one that stores the language you chose, the one that stores your theme preference, and the one that keeps your diagnostic answers, which stay in your browser and are not sent before you finish. They do not depend on consent, because without them the site does not deliver what you came for.

The other three categories only run if you allow them, and you choose one by one. Usage measurement, with Google Analytics, shows which chapters get read and where reading stops, in aggregate. Session recording, with Microsoft Clarity, registers pointer movement, scrolling and clicks to reveal where the page confuses people, with form fields masked. Advertising and remarketing, with Google and Meta, measures how our campaigns perform and allows showing Hendu ads to people who already visited — and that is the category that shares browsing data with those two companies.

All three are on by default when you enter the site, and the notice on your first visit says so and shows where to switch them off. You can switch any of them off, at any time, under Cookie preferences, in the footer of every page — and switching off applies immediately, in that browser. Switching all of them off takes nothing away from the content: the report opens, the diagnostic works and the result shows up the same way. If you also want Hendu to delete data already collected about you, just ask through the site's contact page and we will delete it within the legal deadline. Blocking cookies in your browser also works, and then the parts of the site that depend on the necessary ones stop working.

Security

Encryption in transit and at rest, role-based and logged internal access, and an audit trail of the actions agents carry out. A security incident that could pose relevant risk to data subjects is reported to them and to Brazil's National Data Protection Authority, within the deadline and in the form the law requires.

How to talk to us about personal data

The data protection officer is Cássio Sagawa, reachable at [email protected]. Requests about personal data and questions about this policy can be sent to that address or through the contact form on this site, and are answered within the legal deadline.

Changes to this policy

When this policy changes in a relevant way, the date at the top is updated and platform account holders are notified. Previous versions can be requested through the contact channel.