Privacy Policy
Effective date: 28 July 2026
This Privacy Policy explains how ÓRUS DIGITAL ("HexTrack", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the HexTrack platform and related websites, applications, and services (the "Service").
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
1. Who we are (data controller and DPO)
For the purposes described in section 4 below, the data controller is:
- Controller: ÓRUS DIGITAL
- Company registration number: CNPJ 38.084.946/0001-56
- General contact: contato@hextrack.com.br
- Data protection contact / DPO: contato@hextrack.com.br
If you have any questions about this Policy or how we handle personal data, contact us at contato@hextrack.com.br.
2. Controller and processor roles (important)
HexTrack is a multi-tenant CRM. Our role under data protection law depends on the data:
- We are the controller of personal data relating to our own customers and their users — for example, account registration details, billing information, support communications, and usage data. Section 4 describes how we act as controller.
- We are a processor of the personal data that our customers upload to or generate within the Service about their own contacts and end-customers ("End-Customer Data") — for example, the names, phone numbers, and email addresses of a customer's leads, and the content of conversations a customer has with them. For that data, our customer is the controller and decides why and how it is processed. We process it only on the customer's documented instructions, under a data processing agreement that reflects the requirements of Article 28 of the UK GDPR. Section 8 describes this in more detail.
If you are an individual whose data has been uploaded to HexTrack by one of our customers (an End-Customer), please direct requests about that data to the relevant customer as controller. We will assist them in responding.
3. Personal data we collect
3.1 Account and identity data
Name, business name, email address, phone number, username, password (stored in hashed form), role, and profile settings.
3.2 Billing and transaction data
Subscription plan, billing contact details, billing address, VAT/tax details, transaction history, and partial payment-instrument details. Full card numbers are handled by our payment provider (Stripe) and are not stored by us.
3.3 Usage, device and log data
Log data, IP address, device and browser type, pages and features used, dates and times of access, and diagnostic and performance information.
3.4 Communications and support data
Messages you send us, support tickets, and related correspondence.
3.5 Customer Data / End-Customer Data (processed on behalf of our customers)
When you use the Service, you may upload or generate data about your own contacts and end-customers, including their names, phone numbers, and email addresses; the content of conversations (including WhatsApp and other omnichannel messages); notes; and advertising and traffic identifiers such as gclid, fbclid, and UTM parameters used to attribute leads to campaigns. For this data we act as processor (see section 8).
3.6 Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy (see section 12).
4. Purposes and legal bases (where we are the controller)
| Purpose | Personal data | Legal basis (UK GDPR Art. 6) |
|---|---|---|
| Create and administer your account; provide the Service | Account, identity, usage | Performance of a contract |
| Process payments and manage subscriptions | Billing, transaction | Performance of a contract |
| Provide customer support | Communications, account | Performance of a contract; legitimate interests |
| Keep the Service secure; prevent fraud and abuse | Usage, log, device | Legitimate interests; legal obligation |
| Maintain and improve the Service | Usage, log | Legitimate interests |
| Send service and administrative messages | Account, contact | Performance of a contract; legitimate interests |
| Send marketing about our products (where permitted) | Contact | Consent, or legitimate interests where allowed by PECR |
| Comply with legal and tax obligations | Billing, transaction | Legal obligation |
| Establish, exercise, or defend legal claims | As relevant | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to processing based on legitimate interests (see section 9). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Sub-processors and third parties we share data with
We use trusted third parties (sub-processors) to help us provide the Service. Each is bound by contract to protect personal data and to process it only as instructed. Our current categories of sub-processors are:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing and subscription billing (GBP) | Billing and transaction data |
| OpenAI | AI assistant features | Content and prompts you submit to the AI features |
| Anthropic | AI assistant features | Content and prompts you submit to the AI features |
| Transactional email provider | Transactional and notification email delivery | Recipient email address, message content |
| Cloud hosting provider | Cloud hosting, storage, and infrastructure | All categories of data hosted in the Service |
| WhatsApp / Meta | WhatsApp and omnichannel messaging | Contact identifiers and message content |
A current list of sub-processors is available on request from contato@hextrack.com.br. We may update this list; where we act as processor, we will give affected customers notice of new sub-processors as required by the applicable data processing agreement.
We may also disclose personal data to professional advisers, regulators, law enforcement, or other authorities where required by law, and to a successor entity in connection with a merger, acquisition, or sale of assets.
We do not sell personal data.
6. International transfers
Some of our sub-processors are located outside the United Kingdom. Where we transfer personal data outside the UK, we ensure an appropriate level of protection by relying on one or more of the following safeguards under Chapter V of the UK GDPR:
- transfers to a country covered by UK adequacy regulations; or
- the International Data Transfer Agreement (IDTA) issued by the Information Commissioner's Office (ICO), or the UK Addendum to the European Commission's Standard Contractual Clauses; together with, where appropriate, supplementary measures.
You may request more information about these safeguards, including a copy of the relevant mechanism, by contacting contato@hextrack.com.br.
7. Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements:
- Account data: for the duration of your account, and typically for a limited period after closure to handle final administration and disputes.
- Billing and tax records: retained for the period required by UK tax and accounting law (generally at least 6 years).
- Usage and log data: retained for a limited period for security, troubleshooting, and analytics.
- Marketing data: until you withdraw consent or object, and then suppressed as needed to honour your preference.
- End-Customer Data (as processor): retained for as long as our customer instructs, and deleted or returned on termination as described in section 8.
Where data no longer needs to be retained, we securely delete or anonymise it.
8. How we handle Customer Data as a processor
When we process End-Customer Data on behalf of our customers, we:
- process it only on the customer's documented instructions, including for international transfers, unless required otherwise by law;
- ensure that persons authorised to process it are under appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures (see section 10);
- engage sub-processors only under written terms and with the authorisation reflected in the applicable data processing agreement;
- assist the customer, taking into account the nature of processing, in responding to data subject rights requests and in meeting their security, breach-notification, and impact-assessment obligations; and
- on termination, delete or return End-Customer Data as instructed, except where retention is required by law.
End-Customers wishing to exercise their rights over data held by a HexTrack customer should contact that customer, who is the controller. We will support the customer in responding.
9. Your rights under the UK GDPR and DPA 2018
Where we act as controller, you have the following rights:
- Right to be informed — about how we use your personal data (this Policy).
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — to have your data deleted in certain circumstances.
- Right to restrict processing — to limit how we use your data in certain circumstances.
- Right to data portability — to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object — to processing based on legitimate interests, and to direct marketing at any time.
- Rights relating to automated decision-making and profiling — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as permitted by law.
- Right to withdraw consent — where processing is based on consent, at any time.
To exercise any of these rights, contact us at contato@hextrack.com.br. We will respond within the time limits set by the UK GDPR (generally one month, extendable in complex cases). We may need to verify your identity. There is normally no charge, unless your request is manifestly unfounded or excessive.
Complaints
You have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO) — https://ico.org.uk, helpline 0303 123 1113. We would, however, appreciate the chance to address your concerns first, so please consider contacting us at contato@hextrack.com.br.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include encryption in transit, access controls, authentication, network protections, logging and monitoring, and staff confidentiality obligations. No system is completely secure, so we cannot guarantee absolute security; you are responsible for keeping your credentials safe and for maintaining backups of important Customer Data.
If a personal data breach occurs, we will notify the ICO and affected individuals where and as required by the UK GDPR, and (where we act as processor) notify the affected customer without undue delay.
11. Children
The Service is not directed at children and is intended for business use. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact contato@hextrack.com.br and we will take appropriate steps.
12. Cookies
We use cookies and similar technologies. For details of the cookies we use and how you can manage your preferences, please see our Cookie Policy.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or in-app notice and update the effective date above. We encourage you to review this Policy periodically.
14. Contact
- ÓRUS DIGITAL
- Data protection contact / DPO: contato@hextrack.com.br
- General contact: contato@hextrack.com.br