Privacy Policy
Last updated: 26 August 2026
1. Who is responsible
emitforge is operated by FLUXIUM LTDA, a company registered in Brazil under CNPJ 60.123.373/0001-81. Contact for any privacy matter, including exercising your rights: contato@fluxium.pro.
2. Our two roles — please read this one
We handle personal data in two distinct capacities, and the difference decides who is responsible for what:
- As a processor (GDPR Art. 4(8) / LGPD Art. 5, VII) for the templates and data payloads you send us to render. You are the controller of that content. We act only on your instruction, which is the API request itself.
- As a controller for your account and billing data, and for the technical logs we keep to run and secure the Service.
3. What we handle
| Category | What it includes |
|---|---|
| Account data | Name, email address, API keys |
| Billing data | Received from Paddle: country, tax status, transaction history. We never see or store your full card details |
| Technical data | IP address, user agent, timestamps, endpoint called, response status, render duration |
| Your content | The template and data payload you submit, and the file we produce from them |
4. Why, and on which legal basis
| Purpose | GDPR Art. 6 | LGPD Art. 7 |
|---|---|---|
| Providing the Service and rendering your files | Contract — 6(1)(b) | Contract — V |
| Account management and support | Contract — 6(1)(b) | Contract — V |
| Security, abuse prevention, rate limiting, logging | Legitimate interests — 6(1)(f) | Legitimate interests — IX |
| Accounting and tax records | Legal obligation — 6(1)(c) | Legal obligation — II |
| Product emails you opted into | Consent — 6(1)(a) | Consent — I |
Our legitimate interest in the security purposes above is keeping the Service available and preventing abuse. You may object to that processing at any time, and we will assess the objection on its merits.
We do not send marketing to people whose details reach us through Paddle. Paddle passes buyer data for fulfilment, order processing, fraud prevention and support only. If we ever run a mailing list, it will use consent collected by us, directly.
5. How long we keep it
Retention is short by design. It reduces what can be exposed, and it is simpler to promise something specific than something vague.
| Data | Retention |
|---|---|
| Template and data payload | Not persisted beyond processing the request |
| Generated file | Deleted automatically 24 hours after creation |
| Request logs — metadata only, never the payload body | 30 days |
| Account data | For the life of the account, then 30 days after closure |
| Tax and accounting records | As required by law. Paddle holds most of these as Merchant of Record |
6. Who else processes data
We use a small number of providers. Each is bound by a data processing agreement and, where data leaves the EEA, by Standard Contractual Clauses.
| Provider | Role | Where |
|---|---|---|
| Paddle | Payments, invoicing, tax, fraud prevention | UK / EU |
| Vercel | Hosting and request execution | United States |
| Supabase | Database, authentication, file storage | EU region |
We do not sell personal data, and we do not share it with anyone for advertising.
7. International transfers
We are established in Brazil and use providers in the United States and the European Union. Transfers out of the EEA rely on Standard Contractual Clauses (GDPR Arts. 44–49); a copy can be requested from us. Transfers under the LGPD rely on Art. 33, on the same contractual safeguards.
8. Your rights
Wherever you are, you may ask us to give you access to your data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting what came before.
Under the LGPD (Art. 18) you may additionally ask us to confirm the existence of processing, to tell you with whom data has been shared, and to review decisions taken solely by automated means (Art. 20). We do not make automated decisions that produce legal effects — rendering a file is not one.
Write to contato@fluxium.pro and we answer within one month.
You also have the right to complain to a supervisory authority — the data protection authority of the country where you live or work, or the ANPD in Brazil.
On the Brazilian data protection officer: as a small-scale agent under ANPD Resolution CD/ANPD No. 2/2022, we are not required to appoint a formal DPO, provided we publish a channel for data subjects to reach us. That channel is the email address above.
9. Cookies
This website sets no cookies and runs no third-party analytics. There is nothing to consent to and no banner to dismiss. If that changes, we will ask for consent before setting anything that is not strictly necessary, and we will update this section first.
10. Children
The Service is intended for professional use and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, write to us and we will delete it.
11. Security
Data is encrypted in transit with TLS and at rest by our storage providers. Access to production systems is restricted and authenticated. Generated files sit behind signed, expiring URLs rather than public paths.
We describe what we actually do and no more: this is a small operation without a formal security certification, and we are not going to imply otherwise.
12. Changes
When this policy changes, the date at the top changes with it. For material changes affecting active customers, we give notice by email before they take effect.