How we protect your information
We keep reasonable administrative, technical, and physical safeguards that fit the sensitivity of the data, as U.S. state laws and PIPEDA's Safeguards principle require:
Encryption
TLS for every connection, and encryption at rest for databases, files, and backups.
Access control
Least privilege, multi-factor authentication for staff, and access reviews.
Tenant isolation
Each organization's data is separated from every other organization's.
Monitoring
Logging, alerts, and audit trails to detect and investigate misuse.
Backups
Encrypted, geographically separated backups to keep data available.
Vendors
Service providers are vetted and bound by contracts to protect data and use it only for us.
Payment card numbers never touch our servers: they go straight to PCI DSS certified processors, and we keep only the brand and the last four digits. No system is perfectly secure, so we also plan for incidents, as described below.
How long we keep information
We keep personal information only as long as we need it for the purposes we collected it for, or as the law requires. Then we delete it or de-identify it so it can no longer be linked to you.
When we process data for a graduation company, studio, school, or employer, that organization decides how long to keep it, within the limits of our contract and the law.
International transfers
Partiu is based in Brazil, and our service providers operate in several countries. Personal information about people in the United States and Canada may be stored and processed in Brazil, the United States, and other countries. Wherever it goes, we require by contract a level of protection comparable to this Privacy Center, and we encrypt it in transit and at rest. While abroad, it is subject to local law and may be accessed by courts and authorities of those countries. Before personal information about Quebec residents leaves Quebec, we carry out a privacy impact assessment.
If there is a breach
United States
We notify affected residents without unreasonable delay and within the deadline set by their state's breach notification law, and we notify state Attorneys General and other regulators where required.
Canada
When a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. We keep a record of every breach for at least 24 months.
Quebec
Confidentiality incidents that present a risk of serious injury are reported promptly to the Commission d'accès à l'information and to the people affected, and every incident goes in our register.
Our customers
When the data belongs to a graduation company, studio, school, or employer, we notify that organization without undue delay and help it meet its own obligations.
A notice tells you what happened, what information was involved, what we have done, what you can do to protect yourself, and how to reach us.
Found a security vulnerability? Please report it privately to privacidade@partiuformatura.app with the subject "Security report". We will not take legal action against good-faith research that respects people's privacy and does not disrupt the service.