TindariPrivacy Policy

Privacy and Data Protection Policy

Last updated: July 21, 2026

1. Identification of the Controller and Regulatory Coverage

The processing of personal data within the platform is carried out by Tindari Inc., a C-Corporation incorporated under the laws of the State of Delaware, United States, with registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, privacy contact email: legal@tindari.com. This policy has been drafted rigorously to simultaneously comply with the data protection regulations applicable in your country, the General Data Protection Regulation (GDPR - EU Regulation 2016/679) for the European market, and the Lei Geral de Proteção de Dados (LGPD - Law No. 13,709) for the Brazilian market.

2. Strict Delimitation of Legal Roles (Controller vs. Processor)

For the correct application of international privacy regulations, the parties agree to the following division of legal responsibilities:

3. Types of Data Processed

The platform collects and processes four specific categories of technical and commercial information:

4. Processing of Sensitive Data and Aesthetic Care Records

In the field of comprehensive aesthetics, cosmetology and micropigmentation, it is common to store operational notes revealing skin conditions, allergies, medical contraindications or prior physiological conditions. The Client acknowledges that Tindari is a general-purpose technological storage environment and does not constitute an approved public-health medical record system. The Client assumes the absolute legal obligation to obtain the prior, express, informed and written consent of their end clients and patients to record any data of a sensitive nature, fully releasing Tindari Inc. from any infringement arising from the automated custody of such information on its servers.

5. Legal Purposes of Processing

Tindari Inc. lawfully processes personal data on the bases of contractual performance, legitimate interest and compliance with legal obligations, for the following purposes:

6. Use of Processors and Authorized Sub-processors

To ensure the optimal operation of a cloud platform (SaaS), Tindari Inc. subcontracts infrastructure from world-leading technology providers that meet the highest international privacy standards, acting as sub-processors:

7. International Data Transfers and Safeguard Mechanisms

By using Tindari, the Client acknowledges and expressly authorizes that the personal data collected and the databases uploaded will be transferred internationally for processing on servers located outside your country, the European Union and Brazil, physically located in the data centers of our cloud infrastructure providers in the United States of America. Tindari Inc. ensures that its international sub-processors offer levels of protection equivalent to those required by the GDPR and the LGPD through the signing of Standard Contractual Clauses (SCC) and the maintenance of robust data protection certifications in cloud environments.

8. Rigid Information Security Protocols

Tindari Inc. declares that it implements technical, organizational and logical security measures proportional to the risk to safeguard the confidentiality of the information:

9. Retention Period and 90-Day Purge Policy

Data linked to the commercial account and the end-client databases will be kept actively in the systems as long as the contractual relationship remains in force and the Client pays their subscription fees. Following the voluntary cancellation of the service or the termination of the contract for non-payment, Tindari Inc. will initiate a technical security retention period for a maximum non-extendable term of ninety (90) consecutive days. During this period, the data will remain inactive but safeguarded to allow the Client to resolve billing disputes or reactivate their commercial account. Once day ninety (90) has elapsed, Tindari Inc. will proceed with the irreversible, definitive and total deletion of all information from the production servers and backups, or its complete anonymization for statistical purposes, in accordance with the GDPR's data minimization guidelines.

10. Rights of the Data Subject (Access Rights and Portability)

Data subjects (both the Client with respect to their account, and end users with respect to their operational records) enjoy the fundamental rights of Access, Rectification, Cancellation/Deletion ("Right to be Forgotten"), Objection, Restriction of Processing and Portability of information. For requests exercised by end clients or patients of the aesthetic sector, requests must be channeled directly to the owner of the commercial establishment (the Client), as the original Data Controller. Tindari Inc. will provide the Client with the technical tools to comply with such requirements. Direct requests from account holders may be sent in writing to legal@tindari.com together with proof of legitimate identity.

11. Local Storage Device Policy (Cookies)

The software platform and its public booking web pages use technical cookies necessary to keep the user session active, ensure interface stability and prevent code injection vulnerabilities. Additionally, and subject to the user's express consent through the initial interactive banner, web analytics cookies (such as Google Analytics) may be deployed exclusively for the collection of anonymous usage metrics to optimize operational flows. The user retains the ability to block or delete these technologies through their internet browser settings.

12. Ownership of Information and Right of Export

The Client retains at all times the exclusive, inalienable and absolute ownership of all personal data, operational histories and transactional information that they incorporate into the platform. To ensure transparency and mitigate the risk of vendor lock-in, the Client is entitled to perform or request the complete export of their transactional database in standard structured formats in common use (comma-separated values - CSV or JSON) autonomously at any time during the term of their subscription, and especially mandatorily before the technical retention period following the closure of their account expires.