Privacy policy
This policy explains how we handle personal data on the damasiormoura.org website, in theMCP Omie service (the MCP connector at https://mcp-omie.damasiormoura.org/mcp) and at the sign-in service at https://idp.damasiormoura.org, under Brazil's General Data Protection Law (Law 13,709/2018, "LGPD").
1. Who we are
The service is provided by Rodrigo Damasio de Moura, CPF 289.901.468-44 ("we"). Contact:[email protected].
2. Our role for each kind of data
- Data about people who use the service (account, access, audit trail): we are the controller.
- Data held in our customers' Omie accounts (customers, suppliers, receivables, invoices, orders): the customer — the firm or company that hired the service — is the controller, and we are aprocessor, handling it only to carry out requests made by people the customer authorized.
3. What data we handle
| Data | Purpose | Retention |
|---|---|---|
| Account: name, email, verified-email flag, sign-in provider account identifier, access level (read or write) and the companies you may access | Identify you, match the customer's invitation and apply permissions | While access exists; up to 6 months after removal |
| Omie API keys (App Key and App Secret) of each company the customer registers | Access that company's Omie account when an authorized user asks | While the company is registered; deleted on the customer's request or when the contract ends |
| Omie data read or written at the user's request | Answer the question or carry out the requested operation | No copy is kept. Lookup tables (such as the chart of accounts and bank accounts) and customer names are held in memory for up to 15 minutes to avoid repeated calls |
| Operations awaiting confirmation (for example, the details of a payment before you approve it) and their outcome | Run exactly what the preview showed, only once, and tell whether it already ran | Up to 90 days |
| Audit trail: date and time, who asked, which tool, which company, which Omie method, the outcome, and identifiers and amounts of the affected records | Security, accountability to the customer and incident investigation | 12 months |
| Technical connection data (IP address, date and time, browser) | Abuse protection and network operation | As kept by infrastructure providers, usually a few days |
The audit trail records who did what, but does not store third parties' tax IDs (CPF/CNPJ), API keys or the full content of Omie records.
This website uses no tracking cookies and no audience analytics.
4. Google account data
If you choose to sign in with Google, we request only the openid, email andprofile scopes and receive your name, your email address and the fact that Google verified it. We use this data only to identify you and check whether your email was invited by a customer. We do not access your email, files, contacts, calendar or any other Google account data.
We do not sell Google user data, do not use it for advertising, do not transfer it to third parties (except as required by law), and do not allow humans to read it except with your consent, for security purposes or to comply with the law. Our use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
5. Legal bases
- Performance of the contract with the customer and preliminary steps (LGPD art. 7, V): account, access and operation of the service.
- Legitimate interest (art. 7, IX): audit trail, security and abuse prevention, limited to what is necessary.
- Compliance with legal or regulatory obligations (art. 7, II), where applicable.
- For Omie data, the legal basis is set by the customer, as controller; we follow its instructions.
6. Who we share data with
- Omie — the customer's ERP, which receives calls made with the company's API key.
- The AI assistant you connected (for example, Claude, by Anthropic) — the service's answers are delivered to it, because that is where you ask. The assistant's processing is governed by the agreement between you or your company and its provider.
- Cloudflare — network, certificates and attack protection between the internet and our servers.
- Google — only if you choose to sign in with Google.
- Authorities — when required by law or court order.
We do not sell or rent personal data.
7. International transfers
Some of these providers (Cloudflare, Google and the AI assistant's provider) may process data outside Brazil. These transfers take place to perform the service you or your company requested, with the contractual safeguards those providers offer, under LGPD art. 33.
8. Security
- Omie API keys encrypted with AES-256-GCM, with one key per customer; only the last 4 characters of the App Key remain readable, for identification.
- Isolation between customers in code and in the database (row-level security): a customer cannot reach another customer's data.
- OAuth 2.1 sign-in; access requires an invitation and a verified email.
- Operations that move money or issue tax documents require explicit confirmation.
- All connections are encrypted (HTTPS).
No system is completely immune to failure. If a security incident may cause relevant risk or harm, we will notify the affected customers and the ANPD (Brazil's data protection authority), as required by law.
9. Your rights
You may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about sharing and review of decisions, and you may withdraw consent (LGPD art. 18). Write to our data protection officer (section 10). For data held in a customer's Omie account, we will forward your request to the customer, as controller, and support its answer.
You may also file a complaint with the ANPD.
10. Data protection officer
Rodrigo Damasio de Moura — [email protected].
11. Children
The service is meant for businesses and professionals and is not directed at anyone under 18.
12. Changes
We may update this policy. Material changes will be communicated to customers reasonably in advance; the version and date at the top of this page always identify the text in force.