Privacy Policy
Transparency about how we collect, use, and protect your personal data, in compliance with the Brazilian General Data Protection Law (LGPD).
Last updated: March 2026
Index
1. General Information
This Privacy Policy was prepared in compliance with the Brazilian General Personal Data Protection Law (Law No. 13,709/2018 - LGPD) and other applicable regulations, and aims to inform clearly and transparently how Zenie Tecnologia Ltda, registered under CNPJ No. 61.450.719/0001-19, acting as data controller, processes personal data through the Zenie platform (zenie.digital).
Zenie is an event creation and management technology platform that offers organizers tools to create event websites, sell tickets, manage attendees, schedules, speakers, sponsors, mobile apps, and many other features related to event production.
By using our services, you declare that you have read, understood, and agreed to the terms of this Privacy Policy.
2. Data We Collect
We collect different categories of personal data, as described below:
2.1. Data you provide directly
- Identification data: full name, email address, phone number, and CPF (when required by the event organizer).
- Account data: access credentials (email and encrypted password), profile photo, and configuration preferences.
- Payment data: credit card information and bank details, securely processed by our payment partner (Stripe). We do not store full card data on our servers.
- Event data: information about created events, including descriptions, images, schedules, speakers, and settings.
- Registration data: information provided when registering for events, including custom fields defined by the organizer (for example: company, role, T-shirt size).
- Sponsor data: business information, logos, contact details, and leads captured during events.
- Biometric data: facial photographs voluntarily submitted for the facial recognition feature in event photo galleries (processed via AWS Rekognition).
2.2. Data collected automatically
- Usage data: pages visited, features used, access times, and interactions with the platform.
- Device data: browser type, operating system, screen resolution, and device identifiers.
- IP address: used for security, geolocation, and fraud prevention purposes.
- Geolocation data: approximate location derived from the IP address for personalization and security.
- Cookies and similar technologies: as detailed in section 8 of this policy.
3. How We Use Your Data
We use the personal data collected for the following purposes:
- Account creation and management: enable registration, authentication (including social login via Google), and profile management on the platform.
- Event management: allow the creation, configuration, publication, and administration of events, including websites, tickets, schedules, and teams.
- Payment processing: process ticket sales, calculate fees, transfer funds to organizers via Stripe Connect or Asaas, and manage refunds.
- Communications: send registration confirmations, transactional emails, event notifications, and, with consent, marketing communications.
- Check-in and access control: generate QR codes for registrations and enable attendee check-in at events.
- Security: detect suspicious activity, prevent fraud, protect accounts with two-factor authentication (2FA), and monitor unauthorized access attempts.
- Analysis and improvement: understand how our services are used, generate analytical reports, and improve the user experience.
- Artificial intelligence: train and provide responses through the event AI assistant, using public event data to better serve attendees.
- Facial recognition: when enabled by the organizer and with the attendee's consent, identify faces in gallery photos to make it easier to find personal photos.
- Legal obligations: comply with applicable legal, regulatory, and tax obligations.
4. Legal Basis for Data Processing
The processing of personal data by Zenie is based on the following legal grounds provided in the LGPD (Art. 7):
- Consent of the data subject (Art. 7, I): for sending marketing communications, use of non-essential cookies, facial recognition in galleries, and optional custom registration fields.
- Performance of a contract (Art. 7, V): for the provision of contracted services, including event creation, registration processing, ticket sales, and financial transfers.
- Legitimate interest (Art. 7, IX): for service improvement, platform usage analysis, fraud prevention, and information security, always respecting the rights and freedoms of the data subject.
- Compliance with a legal obligation (Art. 7, II): to meet tax, fiscal, and regulatory obligations, including maintaining financial records in accordance with Brazilian law.
- Regular exercise of rights (Art. 7, VI): for the exercise of rights in judicial, administrative, or arbitration proceedings.
5. Data Sharing
We do not sell your personal data. Sharing occurs only when strictly necessary for the provision of services, in the following cases:
- Stripe: payment processing, management of connected accounts (Stripe Connect), and fraud prevention. Stripe Privacy Policy.
- Asaas: payment processing (card, PIX, boleto), management of subaccounts for transfers, and anti-fraud. Used as an alternative gateway to Stripe on events configured for Asaas. Asaas Privacy Policy.
- Brevo (Sendinblue): sending transactional emails and communications, including registration confirmations and notifications. Brevo Privacy Policy.
- Amazon Web Services (AWS): file storage (S3) and facial recognition in galleries (Rekognition). AWS Privacy Policy.
- Cloudflare: DNS management for custom event domains and protection against attacks. Cloudflare Privacy Policy.
- Google: authentication via social login (Google OAuth) and analytics services. Google Privacy Policy.
- Pinecone: vector storage for the operation of the event AI assistant. Pinecone Privacy Policy.
- Event organizers: attendee registration data is shared with the respective organizers for event management. Organizers are responsible for the proper processing of this data.
- Sponsors: leads captured during events are shared with the respective sponsors, in accordance with the attendee's consent.
- Competent authorities: when required by law, court order, or determination of a regulatory authority, including the National Data Protection Authority (ANPD).
6. Storage and Security
We adopt appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. Among the measures implemented:
- Encryption: data in transit is protected by HTTPS/TLS. Passwords are stored with bcrypt hashing, never in plain text.
- Two-factor authentication (2FA): available for all user accounts as an additional layer of security.
- Access control: access to data is restricted to authorized personnel, based on the principle of least privilege. Event teams have defined roles (owner, editor, viewer).
- Monitoring: login tracking with IP, geolocation, and device information for detecting suspicious activity.
- Payment security: payment data is processed directly by Stripe, which is PCI DSS Level 1 certified. We do not store full credit card numbers.
- Secure URLs: we use random hashes instead of sequential IDs in URLs to prevent resource enumeration.
- SSL certificates: all event domains and subdomains have automatically managed SSL certificates.
Despite our efforts to protect your data, no transmission or storage system is completely secure. If you become aware of any security vulnerability, please contact us immediately.
7. Your Rights (LGPD)
In accordance with articles 17 to 22 of the LGPD, you, as a personal data subject, have the following rights:
- Confirmation and access: confirm the existence of processing and access your personal data.
- Correction: request the correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion: request the anonymization, blocking, or deletion of unnecessary, excessive data, or data processed in non-compliance with the LGPD.
- Portability: request the portability of data to another service provider, upon express request.
- Deletion: request the deletion of personal data processed on the basis of consent.
- Information about sharing: obtain information about public and private entities with which we share your data.
- Withdrawal of consent: withdraw consent at any time, without prejudice to the legality of processing previously carried out.
- Objection: object to processing carried out on a basis other than consent, in the event of non-compliance with the LGPD.
- Review of automated decisions: request the review of decisions made solely on the basis of automated processing of personal data.
To exercise any of these rights, contact us through the channels indicated in section 17. We will respond to your request within 15 (fifteen) business days, as provided by law.
To delete your account and understand what happens to your data, visit the Account Deletion page.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to improve your experience on the platform. Cookies are small text files stored on your device when you access our services.
8.1. Types of cookies used
- Essential cookies: necessary for the basic operation of the platform, including session authentication, CSRF tokens, and security preferences. They cannot be disabled.
- Functional cookies: store user preferences, such as language, theme, and display settings, to personalize your experience.
- Analytical cookies: collect anonymized information about how users interact with the platform, allowing us to identify areas for improvement.
- Performance cookies: help monitor platform performance and identify technical problems.
8.2. Cookie management
You can manage or disable non-essential cookies through your browser settings. Note that disabling certain cookies may affect platform functionality. The main browsers allow cookie management in their privacy settings.
9. International Data Transfer
For the provision of our services, your personal data may be transferred and processed on servers located outside Brazil, specifically:
- United States: where the servers of AWS (file storage and facial recognition), Stripe (payment processing), Pinecone (AI vectors), and Cloudflare (DNS and security) are located.
- European Union: where some Brevo servers (email sending) are located.
These transfers are carried out in compliance with article 33 of the LGPD, based on the following safeguards:
- The destination countries have adequate data protection legislation or the providers adopt standard contractual clauses.
- All mentioned partners have privacy policies and security measures compatible with the standards required by the LGPD.
- Where applicable, we use encryption and anonymization to minimize risks associated with international transfer.
10. Data Retention
Your personal data is retained for as long as necessary to fulfill the purposes for which it was collected, observing the following criteria:
- Account data: retained while the account is active. After a deletion request, the data is removed within 30 (thirty) days, except where there is a legal obligation to retain it.
- Event data: retained for up to 5 (five) years after the event date, for auditing, tax obligations, and potential disputes.
- Financial and tax data: retained for a minimum period of 5 (five) years, as required by Brazilian tax law.
- Registration data: retained for the same period as the data of the associated event.
- Access logs: retained for 6 (six) months, in accordance with the Brazilian Internet Civil Framework (Law No. 12,965/2014).
- Biometric data (facial recognition): facial reference images are deleted within 90 (ninety) days after the conclusion of the event, unless a prior request is made by the data subject.
- Deleted events: events moved to the trash are permanently deleted after 30 (thirty) days.
At the end of the retention period, the data is securely deleted or anonymized for statistical purposes.
11. Minors
The Zenie platform is not intended for those under 18 (eighteen) years of age. We do not intentionally collect personal data from children or adolescents without the consent of their parents or legal guardians.
If an event organizer needs to collect data from minors for event registration, it is the organizer's responsibility to obtain appropriate consent from the parents or legal guardians, as required by article 14 of the LGPD and the Statute of the Child and Adolescent (ECA).
If we become aware that we have collected data from a minor without appropriate consent, we will take immediate measures to delete such information.
12. Use of Data by the Zenie Platform
It is important to distinguish the use of data by Zenie (as a technology platform) from the use of data by the event organizers who use the platform.
12.1. Data used by Zenie
Zenie may use user data for the following purposes:
- Account creation and management on the platform: enable user registration, authentication, and account maintenance on the Zenie platform.
- Sending institutional communications: inform about platform updates, changes to the terms of use, privacy policies, and other operational communications.
- Sending recommendations: recommend relevant events, content, and services based on the user's profile and interactions on the platform.
- Product and experience improvements: analyze platform usage to improve features, fix problems, and develop new resources.
Legal basis: consent of the data subject (Art. 7, I of the LGPD) and, where applicable, legitimate interest (Art. 7, IX of the LGPD), always guaranteeing the user the right to opt out.
12.2. Data used by event organizers
Event organizers who use the Zenie platform are responsible for processing the personal data of the attendees of their events, including registration data, custom fields, and information collected during the event. Zenie acts as a data processor in these situations, processing the data according to the organizer's (controller's) instructions.
13. Automatic Account Creation
When registering for events on the Zenie platform, the user may have an account created automatically, linked to the data provided during the purchase or registration process. This account allows the user to access their tickets, registration history, and other platform features.
Automatic account creation is based on the performance of a contract (Art. 7, V of the LGPD), being necessary for the provision of the services contracted by the user when purchasing a ticket or registering.
14. Platform Communications
With consent, Zenie may send communications about events, content, products, and platform news. These communications may include personalized event recommendations, newsletters about new features, and special offers.
Consent to receive these communications may be given during registration on the platform, when registering for an event, or in the user's account settings. Transactional communications (such as registration confirmations and payment receipts) do not depend on consent, as they are necessary for the performance of the contract.
15. Communication Opt-out
The user may, at any time, cancel the receipt of communications through the links available in the emails or in their account settings. The cancellation will be processed within 5 (five) business days.
Opting out of promotional communications does not affect the sending of transactional and operational communications essential for the operation of the contracted services, such as registration confirmations, updates on events the user is registered for, and account security alerts.
16. Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in our data processing practices, new platform features, or changes in applicable legislation.
In the event of substantial changes, we will notify you through:
- A prominent notice on the platform;
- Email communication to the address registered in your account;
- Updating the "last updated" date at the top of this page.
We recommend that you review this policy periodically. Continued use of the platform after the publication of changes constitutes acceptance of the modifications made.
17. Contact and Data Protection Officer (DPO)
If you have questions, concerns, or wish to exercise your rights under the LGPD, contact us:
Controller: Zenie Tecnologia Ltda
CNPJ: 61.450.719/0001-19
Email for privacy matters: contato@zenie.digital
Platform: zenie.digital
Our Data Protection Officer (DPO) can be contacted at the email above. We are committed to responding to all requests within the legal period of 15 (fifteen) business days.
If you believe that the processing of your personal data violates current legislation, you also have the right to file a complaint with the National Data Protection Authority (ANPD), through the website www.gov.br/anpd.