Baristta | NETWORK OPERATIONS CENTER
PAGE VERIFICATION · FTP MONITORING · BACKUPS · INCIDENTS

Data Protection & GDPR

General Data Protection Regulation (GDPR) & Brazil's LGPD

Last updated: April 14, 2026

Effective date: April 14, 2026

1. Introduction

Baristta is committed to complying with applicable data protection regulations, including the European Union's General Data Protection Regulation (GDPR) and Brazil's Lei Geral de Proteção de Dados (LGPD - Law No. 13.709/2018). This document describes how we process data in the context of our web infrastructure monitoring services, the roles of each party involved and the rights of data subjects.

2. Roles in Data Processing

Data Controller

The Client

The Client using the Baristta platform is the Data Controller for any personal data that may exist in the monitored systems (FTP servers, websites, databases). The Client decides which data is monitored and for what purpose.

Data Processor

Baristta

Baristta acts as the Data Processor, processing data exclusively according to the Client's instructions and for the provision of contracted services.

3. Legal Basis for Processing

Data processing by Baristta is based on the following legal grounds:

  • Contract performance (GDPR Art. 6(1)(b) / LGPD Art. 7, V): processing necessary for the provision of services contracted by the Client
  • Legitimate interest (GDPR Art. 6(1)(f) / LGPD Art. 7, IX): for platform security maintenance and fraud prevention
  • Legal obligation (GDPR Art. 6(1)(c) / LGPD Art. 7, II): when required by applicable law or regulation

4. Personal Data Processed

4.1. Directly Collected Data

Directly collected personal data, purposes and legal bases
Data Purpose Legal Basis
Company name Account identification Contract
Registration email Authentication and communication Contract
Notification email Sending alerts and incidents Contract
Country and timezone Service regionalization Contract
System credentials (encrypted) Monitoring and backup execution Contract

4.2. Indirectly Processed Data

In the course of its operations, Baristta may indirectly process data that exists in the Client's systems, such as web page content, files on FTP servers and data in databases. This data may include personal data of the Client's own customers. In this case:

  • The Client is the Data Controller for this data and is responsible for the legal basis of its processing
  • Baristta acts as the Data Processor, processing data according to the Client's instructions
  • Baristta does not use this data for any purpose other than the provision of contracted services

5. Security Measures

Baristta implements appropriate technical and organizational measures to protect personal data (GDPR Art. 32 / LGPD Art. 46):

  • Encryption: AES-256 for credentials, TLS for data transmission
  • Access control: principle of least privilege across all infrastructure
  • Secure storage: cloud backups with SHA-256 integrity verification and TLS transmission
  • Monitoring: logging of data access and operations
  • Cookies: the platform uses only session cookies; the marketing website uses Google Analytics for anonymized usage analytics

6. Retention and Deletion

  • Free plan: monitoring data retained for 30 days
  • Paid plans: data retained for the duration of the subscription
  • After cancellation: data deleted within 30 days, except when legally required to retain
  • On-demand deletion: the Client may request data deletion at any time

7. Data Subject Rights

Under GDPR (Articles 15-22) and LGPD (Article 18), data subjects have the following rights:

  • Access: confirm the existence of processing and access the data
  • Rectification: request correction of incomplete, inaccurate or outdated data
  • Erasure: request anonymization, blocking or deletion of unnecessary data
  • Portability: request data portability to another provider
  • Consent withdrawal: withdraw consent at any time
  • Objection: object to processing based on legitimate interests or for direct marketing purposes
  • Restriction: request restriction of processing under certain circumstances

For data existing in monitored systems (third-party data), the data subject should contact the Client (Data Controller). Baristta will cooperate with the Client to fulfill data subject requests.

8. International Data Transfers

Data may be processed or stored on servers located outside of Brazil or the European Economic Area for the purpose of service execution. When international transfers occur, Baristta ensures that recipients adopt adequate levels of data protection, as required by GDPR Chapter V and LGPD Article 33. We rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) where applicable.

9. Security Incidents

In the event of a security incident that may pose a risk or relevant damage to data subjects, Baristta commits to:

  • Notify the Client (Data Controller) within 72 hours of becoming aware of the incident (GDPR Art. 33)
  • Provide information about the nature of affected data, mitigation measures taken and recommendations
  • Cooperate with the Client, the ANPD (Brazil's data protection authority) and EU supervisory authorities as necessary

10. Data Protection Officer (DPO)

To exercise your rights as a data subject or for questions related to data protection, please contact our Data Protection Officer:

Data Protection Officer (DPO): Leonardo Pessatti
Email: dpo@baristta.tech
Website: baristta.tech

11. Changes to This Document

This document may be updated periodically to reflect changes in our practices or applicable legislation. Significant changes will be communicated to Clients by email or notice on the platform.