Privacy Policy

Last updated: March 27, 2026

1. Introduction and Data Controller Identification

This Privacy Policy describes how That's Me Ltd. (CNPJ 48.657.854/0001-71), hereinafter "That's Me", collects, uses, stores, protects, and shares the personal data of users of the platform available at app.thatsme.com.br.

That's Me operates in compliance with the Brazilian General Data Protection Law (Lei nº 13.709/2018 — LGPD) and, for users residing in the European Economic Area or the United Kingdom, with the General Data Protection Regulation (GDPR — Regulation EU 2016/679).

For questions about this Policy, please contact us at [email protected].

2. Who This Policy Covers

This Policy applies to:

3. What Data We Collect and How

3.1 Data provided directly by the user during registration

DataUser typeRequired
Full nameRecipient and IssuerRequired
Email addressRecipient and IssuerRequired
Password (bcrypt hash)Recipient and IssuerRequired if not using OAuth
Username (@nickname)RecipientRequired
Phone numberRecipient and IssuerOptional
Company nameIssuerRequired
CNPJ or business registrationIssuerOptional (KYB)
AddressIssuerOptional
CPF (Brazilian tax ID)RecipientOptional
Date of birthRecipientOptional
GenderRecipientOptional
Profile pictureRecipient and IssuerOptional
BioRecipientOptional
IndustryRecipient and IssuerOptional
LinkedIn (URL or code)RecipientOptional

3.2 Data collected via OAuth authentication (Google and LinkedIn)

When the user chooses to authenticate via Google or LinkedIn, the platform receives from the provider, with the user's consent: name, email address, profile picture, and provider unique identifier. For LinkedIn, the following may also be received: current job title and profile URL. This data is stored in an OAuth connection linked to the account.

3.3 Data generated automatically during use

3.4 Certificate recipient data (provided by Issuer)

When an Issuer issues a certificate, it provides the platform with: full name, email and, optionally, phone number of the recipient. The Issuer is the data controller for this data; That's Me acts as a data processor in the context of issuance.

3.5 Business verification data (KYB)

For organization verification, the Issuer may submit official documents (articles of incorporation, business registration, permits, etc.). These documents are stored in a private S3 bucket, accessible exclusively by the administrative team, and are never made publicly available.

3.6 Financial data

Payment data (credit card, banking information) is processed directly by Stripe and is not stored on That's Me servers. The platform only retains the Stripe customer and subscription identifiers.

4. How We Use Your Data

PurposeLegal Basis (LGPD)Legal Basis (GDPR)
Service provision (issuance, storage, and verification of certificates)Performance of contract — Art. 7, VArt. 6(1)(b)
Account authentication and securityLegitimate interest — Art. 7, IXArt. 6(1)(f)
Sending transactional notificationsPerformance of contract — Art. 7, VArt. 6(1)(b)
Processing based on explicit consent collected at registrationConsent — Art. 7, IArt. 6(1)(a)
Compliance with legal and regulatory obligationsLegal obligation — Art. 7, IIArt. 6(1)(c)
Fraud prevention and platform securityLegitimate interest — Art. 7, IXArt. 6(1)(f)
Service improvement and aggregated internal analyticsLegitimate interest — Art. 7, IXArt. 6(1)(f)

That's Me does not use personal data for marketing purposes without express consent and does not sell personal data to third parties.

5. Transactional Emails We Send

The platform sends the following transactional emails. These are not marketing messages — they are essential notifications required for the secure operation of your account:

6. Data Sharing with Third Parties

That's Me shares personal data with third parties only in the following cases:

Third PartyShared DataPurpose
Amazon Web Services (AWS) — USAAll stored dataHosting infrastructure (EC2, database, S3)
Stripe — USACustomer ID, email, organization namePayment and subscription processing
Amazon SES — USARecipient email, email contentTransactional email delivery
WhatsApp Business APIPhone number, name, certificate linkCertificate delivery via WhatsApp
BrasilAPICNPJCNPJ validation for KYB verification
LinkedIn OAuthOAuth authorization codeAuthentication via LinkedIn
Google OAuthOAuth authorization codeAuthentication via Google

All providers listed above are selected based on their security practices and compliance with applicable data-protection laws. AWS holds SOC 2 and ISO 27001 certifications and supports GDPR compliance through Standard Contractual Clauses (SCCs).

7. International Data Transfers

Data is stored primarily on AWS servers in the sa-east-1 (São Paulo) region. Transactional emails are sent via AWS SES servers. Payments are processed by Stripe on infrastructure in the USA and Europe.

For users in the European Economic Area, data transfers to the USA rely on Standard Contractual Clauses (SCCs) adopted by the European Commission under Art. 46 of the GDPR.

8. Data Security

That's Me adopts the following technical and organizational security measures:

No security measure is infallible. In the event of a material security incident, That's Me will notify affected users and the Brazilian National Data Protection Authority (ANPD) as required by Arts. 46 et seq. of the LGPD.

9. Cookies

The platform uses only strictly necessary functional cookies for the operation of the services:

CookiePurposeExpiration
thatsme:tokenJWT access token for authentication15 minutes
thatsme:refresh_tokenSession renewal token30 days (renewed on each use)
thatsme:session_idActive session identifier30 days
thatsme:companyIssuer context identificationSession

The platform does not use tracking, advertising, or third-party analytics cookies.

10. Data Retention

DataRetention Period
Active account dataAs long as the account is active
Data after deactivationUntil deletion is requested
Data after deletion request7 days (cooling-off period), then anonymized
Certificates (post-anonymization)Retained with anonymized reference
Pending invitations2 years from issuance
Expired/revoked sessionsDeleted after 30 days
Used/expired magic linksDeleted in daily cleanup
KYB documentsVerification validity + 1 year
Audit logs2 years

11. Children's Data

The platform is not intended for children under 13 years of age. For users between 13 and 18, we recommend that a parent or guardian be aware of and consent to their use of the platform, in accordance with Art. 14 of the LGPD. If we identify use by a minor without proper authorization, we will delete their data upon request.

12. Your Rights as a Data Subject

Under Art. 18 of the LGPD and Arts. 15–22 of the GDPR, you have the right to:

RightHow to exercise
Access — confirm data processing and obtain a copyEmail [email protected] or export in Settings → Account
Rectification — update incomplete or inaccurate dataDirectly in Settings → Profile
Erasure — delete personal dataSettings → Account → Delete account
Portability — receive data in JSON formatSettings → Account → Export my data
Objection — object to processing based on legitimate interestEmail [email protected]
Withdrawal of consentAt any time; does not affect prior processing
Information about sharingSection 6 of this Policy
ComplaintANPD (Brazil) · ICO (United Kingdom) · CNIL (France)

We will respond to requests within 15 (fifteen) calendar days.

13. Legal Basis for EU and UK Users

For users in the EEA and the United Kingdom, the data controller is That's Me Ltd. Our EU representative can be contacted at [email protected]. For processing based on consent, the user has the right to withdraw it at any time without affecting the lawfulness of prior processing.

14. Changes to This Policy

This Policy may be updated from time to time. If we make material changes, we will notify you by email at least 30 (thirty) days in advance. The current version is always available at thatsme.com.br/privacy/policy with the date of the latest update.

15. Contact

That's Me Ltd.
CNPJ: 48.657.854/0001-71
Belo Horizonte, Minas Gerais, Brazil
Email: [email protected]

For personal-data requests, please email us at the address above with the subject line "LGPD Request" or "GDPR Request".

Version 3.1 — March 27, 2026

Supersedes all prior versions.