Privacy Policy global | v0.1.0 | 2026-10-05 | draft Draft — not yet effective This Policy describes personal-data processing by FLUXYR LTDA, CNPJ 47.640.746/0001-23, Avenida Engenheiro Luiz Carlos Berrini, 1376, 17th floor, São Paulo, Brazil, operating as Shpyrd ("we"). It covers our website, business contacts, accounts, billing, and support. Privacy contact: privacy@shpyrd.io. Contractual notices: legal@shpyrd.io. 1 Our role and the scope of this Policy We act as controller when deciding why and how to process personal information for our own website, customer relationships, administration, security, and legal obligations. For personal data placed by a customer in its Cloud applications, we generally process on that customer's instructions as a processor or equivalent service provider under the applicable agreement and DPA. That customer is responsible for its own notices and lawful instructions. Enterprise is installed in the customer's environment. Installing or licensing it does not give us unrestricted access to its databases. Any access granted for installation, troubleshooting, support, or license administration must be limited to the agreed purpose and governed by the applicable agreement. A customer's own processing remains its responsibility. Running the open-source core yourself does not, by itself, create a hosted account with Shpyrd. This Policy applies if you separately interact with our website, contacts, or services. It does not replace the privacy notice of an application deployed by another organization. 2 Information we process and its sources Information you or your organization provide may include name, business email, role, organization, contact details, account identifiers, authentication information, permissions, correspondence, support attachments, contractual records, and information supplied in privacy requests. Avoid sending unnecessary sensitive information, secrets, or production datasets to support. Billing information may include legal name, business or tax identifier, billing address, plan, usage records, invoice details, transaction references, and payment status. Payment providers process payment credentials within the payment flow. The information we receive depends on the chosen method and may include limited payment-method details; do not email complete card or bank credentials to us. Technical information generated by interactions may include IP address, browser and device details, timestamps, requested URLs, authentication and security events, resource identifiers, and service usage needed for operation or metering. Support and on-premise installation may involve diagnostic information that you choose or authorize us to receive. We may receive information from an organization's administrators, authorized resellers or billing contacts, payment providers, and integrated identity providers when used. We use those sources for the relevant account or transaction, not as a general authorization to collect unrelated information. 3 Purposes and legal grounds We use necessary information to create and administer accounts, authenticate users, deliver services, meter usage, invoice and collect payment, provide installation and support, and communicate about the relationship. Where applicable, grounds include performance of a contract with the individual or requested pre-contract steps. For personnel acting for an organization, legitimate interests in administering that business relationship may be the appropriate ground. We use relevant records to comply with tax, accounting, regulatory, and lawful-request obligations. We use limited technical and account information to prevent abuse and fraud, maintain security, troubleshoot, and establish or defend legal claims. Depending on the activity and applicable law, these purposes rely on legal obligations, legitimate interests subject to a balancing assessment, or the exercise of rights in legal proceedings. Optional marketing, nonessential cookies, or other optional processing requires the choices and legal basis required in the relevant jurisdiction, including consent where required. You may withdraw consent prospectively without affecting prior lawful processing. Refusing optional processing does not prevent use of unrelated essential functions. Where we rely on legitimate interests, those interests are operating a secure business service, managing customer relationships, preventing misuse, and improving reliability using proportionate information. We assess the impact on individuals and provide applicable objection rights. These are purpose-specific grounds, not interchangeable blanket permissions. 4 Cookies and local storage This legal portal stores a display-theme preference locally in your browser when you choose a theme. Its Global/Brasil document selection is represented in the URL. The portal implementation contains no advertising trackers or analytics scripts. Infrastructure may still process technical requests needed to serve and secure the website. Other Shpyrd account and product interfaces may require session or security cookies. Before introducing nonessential tracking where consent is required, we will identify the relevant technologies, purposes, providers, and duration and offer a genuine choice. You can manage browser storage through browser settings, although blocking essential storage may affect account functionality. A future change to tracking practices must be reflected in the applicable notice and controls. 5 Sharing and recipients We share information only as needed with authorized personnel and providers performing hosting, infrastructure, communications, support, identity, payment, accounting, or security functions. Their access should be limited by purpose, confidentiality, and appropriate contractual safeguards. Service-specific subprocessors for customer application data must be addressed in the applicable DPA and subprocessor disclosures. An organization's administrators and designated billing contacts may see account, membership, usage, and invoice information needed to manage that organization. We may share information with professional advisers, competent authorities where legally required, or parties to a corporate transaction subject to appropriate confidentiality and continued protection. We do not sell personal information or share it for cross-context behavioral advertising. Any future materially different practice would require an updated notice and any legally required choices before it begins. This statement does not prevent necessary disclosures to service providers acting for the purposes described here. 6 International processing Shpyrd is established in Brazil and serves customers internationally. Processing may occur in Brazil and in countries where the infrastructure and service providers selected for a service operate. An English-language contract does not guarantee storage in a particular country. Specific residency commitments must be stated in the relevant service agreement. Where restricted transfers are subject to the GDPR, UK law, LGPD, or other applicable rules, the relevant transfer must use a lawful mechanism, such as an applicable adequacy decision or appropriate contractual safeguards, together with assessments and supplementary measures where required. EU standard contractual clauses, UK transfer instruments, and Brazilian standard clauses are distinct instruments and must be selected according to the actual transfer. Contact privacy@shpyrd.io for information about destinations and safeguards relevant to your service or to request an available copy, subject to necessary redactions. This notice does not itself execute transfer clauses or a DPA. 7 Retention and deletion We keep information only for as long as needed for the stated purposes, applicable contractual obligations, legal retention, security, and the establishment or defense of claims. Retention depends on the record type and jurisdiction: active account records support the relationship; billing and tax records follow applicable legal duties; support and security records are assessed for continuing operational or evidentiary need. After account closure, we delete or de-identify information no longer needed, subject to lawful retention and restricted backups. Backup copies are removed through their applicable rotation and are not used for unrelated purposes. Litigation or regulatory holds may require restricted preservation beyond an ordinary schedule. Customer application data follows the retrieval and deletion periods in the applicable Cloud agreement or DPA. Enterprise customer data stored on customer infrastructure remains under the customer's control; copies specifically provided to Shpyrd for support remain subject to agreed handling and retention. Contact us for retention information about a particular category. 8 Security and incidents We use technical and organizational measures appropriate to the processing risks, including access restrictions and safeguards for transmission and storage appropriate to the service. No system can guarantee absolute security. Customers should manage credentials, permissions, and application security in accordance with their responsibilities. We assess suspected personal-data incidents and notify customers, affected individuals, and authorities when required by the applicable agreement or law. Contractual incident-notification obligations for customer-controlled data should be specified in the DPA; this Policy does not substitute a negotiated incident-response schedule. 9 Your rights and requests Depending on applicable law and the circumstances, you may request confirmation and access, correction, deletion, restriction, portability, information about sharing, withdrawal of consent, and objection to certain processing. Some rights have exceptions, including required retention and protection of others' rights. We explain applicable reasons if a request cannot be fulfilled. Send requests to privacy@shpyrd.io, identifying your relationship to Shpyrd and the relevant account or service. We may request proportionate verification and, for representatives, proof of authority. Do not send identity documents unless requested through an appropriate channel. We respond within applicable legal time limits; complex requests may be extended only as permitted by law. If your request concerns data controlled by a Shpyrd customer, contact that organization first. We will direct or assist with the request consistently with our processor obligations. You may also complain to your competent data protection authority without first exhausting our contact process. 10 Regional rights Brazil: where the LGPD applies, rights include confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary, excessive or unlawful data, portability as regulated, information on sharing and consent consequences, withdrawal of consent, and deletion of data processed with consent subject to legal exceptions. You may request review of decisions based solely on automated processing that affect your interests and petition the ANPD under applicable rules. EEA and United Kingdom: where the GDPR or UK GDPR applies, you may exercise applicable rights of access, rectification, erasure, restriction, portability, and objection, and withdraw consent. You may lodge a complaint with a competent supervisory authority, including in your habitual residence or workplace where permitted. You may object to direct marketing and, on grounds relating to your situation, to legitimate-interest processing subject to legal exceptions. United States: state privacy rights, including applicable California rights to know/access, correct, delete, opt out of sale or sharing, and limit certain uses of sensitive information, apply only where the relevant law covers the processing. We do not penalize you for exercising applicable rights. Authorized agents may submit requests with verification of authority. Where an applicable state law provides an appeal, request one through privacy@shpyrd.io and identify the original decision; we will explain the available process and applicable deadlines. If legally required opt-out signals become relevant to a processing activity, we will honor them as required. Other countries: local mandatory privacy rights remain available where applicable. Contact us with your country and request so we can assess the appropriate process. A Global edition does not mean that every jurisdiction's law applies to every interaction. 11 Children and automated decisions Our business services are not directed to children, and we do not knowingly solicit children's personal information for their own accounts. If you believe a child has provided information inappropriately, contact us so we can investigate and take appropriate action. Customers operating applications for children must independently assess their legal responsibilities. This Policy does not authorize solely automated decisions producing legal or similarly significant effects. If a service introduces such a process, we will provide the specific information, safeguards, and rights required before using it in that context. Routine security or fraud detection may use automated tools with appropriate review processes. 12 Updates and contact New revisions will identify their dates and, once published, their effective dates. We will provide appropriate notice of material changes and obtain consent where required. A new notice does not retroactively justify incompatible uses of previously collected data. Prior revisions remain available in the version history. Contact privacy@shpyrd.io for privacy questions and rights requests, or write to FLUXYR LTDA at the address above. The Global edition is written in English. The Brasil edition provides Portuguese wording and local provisions; mandatory privacy rights take priority over any language rule in a contract.