damasiormoura.org

Privacy policy

Version 1.0 · effective October 7, 2026

This is a translation of the Portuguese version, which prevails in case of divergence.

This policy explains how we handle personal data on the damasiormoura.org website, in theMCP Omie service (the MCP connector at https://mcp-omie.damasiormoura.org/mcp) and at the sign-in service at https://idp.damasiormoura.org, under Brazil's General Data Protection Law (Law 13,709/2018, "LGPD").

1. Who we are

The service is provided by Rodrigo Damasio de Moura, CPF 289.901.468-44 ("we"). Contact:[email protected].

2. Our role for each kind of data

3. What data we handle

DataPurposeRetention
Account: name, email, verified-email flag, sign-in provider account identifier, access level (read or write) and the companies you may accessIdentify you, match the customer's invitation and apply permissionsWhile access exists; up to 6 months after removal
Omie API keys (App Key and App Secret) of each company the customer registersAccess that company's Omie account when an authorized user asksWhile the company is registered; deleted on the customer's request or when the contract ends
Omie data read or written at the user's requestAnswer the question or carry out the requested operationNo copy is kept. Lookup tables (such as the chart of accounts and bank accounts) and customer names are held in memory for up to 15 minutes to avoid repeated calls
Operations awaiting confirmation (for example, the details of a payment before you approve it) and their outcomeRun exactly what the preview showed, only once, and tell whether it already ranUp to 90 days
Audit trail: date and time, who asked, which tool, which company, which Omie method, the outcome, and identifiers and amounts of the affected recordsSecurity, accountability to the customer and incident investigation12 months
Technical connection data (IP address, date and time, browser)Abuse protection and network operationAs kept by infrastructure providers, usually a few days

The audit trail records who did what, but does not store third parties' tax IDs (CPF/CNPJ), API keys or the full content of Omie records.

This website uses no tracking cookies and no audience analytics.

4. Google account data

If you choose to sign in with Google, we request only the openid, email andprofile scopes and receive your name, your email address and the fact that Google verified it. We use this data only to identify you and check whether your email was invited by a customer. We do not access your email, files, contacts, calendar or any other Google account data.

We do not sell Google user data, do not use it for advertising, do not transfer it to third parties (except as required by law), and do not allow humans to read it except with your consent, for security purposes or to comply with the law. Our use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.

5. Legal bases

6. Who we share data with

We do not sell or rent personal data.

7. International transfers

Some of these providers (Cloudflare, Google and the AI assistant's provider) may process data outside Brazil. These transfers take place to perform the service you or your company requested, with the contractual safeguards those providers offer, under LGPD art. 33.

8. Security

No system is completely immune to failure. If a security incident may cause relevant risk or harm, we will notify the affected customers and the ANPD (Brazil's data protection authority), as required by law.

9. Your rights

You may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about sharing and review of decisions, and you may withdraw consent (LGPD art. 18). Write to our data protection officer (section 10). For data held in a customer's Omie account, we will forward your request to the customer, as controller, and support its answer.

You may also file a complaint with the ANPD.

10. Data protection officer

Rodrigo Damasio de Moura — [email protected].

11. Children

The service is meant for businesses and professionals and is not directed at anyone under 18.

12. Changes

We may update this policy. Material changes will be communicated to customers reasonably in advance; the version and date at the top of this page always identify the text in force.