Safeguards

Security, Retention, and Breaches

How we protect personal information, how long we keep it, where it is processed, and what we do if something goes wrong.

How we protect your information

We keep reasonable administrative, technical, and physical safeguards that fit the sensitivity of the data, as U.S. state laws and PIPEDA's Safeguards principle require:

Encryption

TLS for every connection, and encryption at rest for databases, files, and backups.

Access control

Least privilege, multi-factor authentication for staff, and access reviews.

Tenant isolation

Each organization's data is separated from every other organization's.

Monitoring

Logging, alerts, and audit trails to detect and investigate misuse.

Backups

Encrypted, geographically separated backups to keep data available.

Vendors

Service providers are vetted and bound by contracts to protect data and use it only for us.

Payment card numbers never touch our servers: they go straight to PCI DSS certified processors, and we keep only the brand and the last four digits. No system is perfectly secure, so we also plan for incidents, as described below.

How long we keep information

We keep personal information only as long as we need it for the purposes we collected it for, or as the law requires. Then we delete it or de-identify it so it can no longer be linked to you.

InformationKept for
Account and profileWhile your account is active. After closure, deleted or de-identified, except what the law makes us keep.
Contracts, payments, and invoicesUp to 5 years after the contract ends, for tax, accounting, and legal claims.
Event photos and videosFor the period agreed with the studio or organization, or until you delete them.
Facial recognition dataSee the retention schedule in the Biometric Data Policy (search selfies are discarded within seconds).
Privacy requestsAt least 24 months, the record-keeping period the CCPA regulations require.
Security logsUp to 12 months, unless needed for an ongoing investigation.
Website analyticsUp to 14 months, and only if you accepted analytics cookies.
Marketing preferencesYour opt-out is kept for as long as needed to keep honoring it.

When we process data for a graduation company, studio, school, or employer, that organization decides how long to keep it, within the limits of our contract and the law.

International transfers

Partiu is based in Brazil, and our service providers operate in several countries. Personal information about people in the United States and Canada may be stored and processed in Brazil, the United States, and other countries. Wherever it goes, we require by contract a level of protection comparable to this Privacy Center, and we encrypt it in transit and at rest. While abroad, it is subject to local law and may be accessed by courts and authorities of those countries. Before personal information about Quebec residents leaves Quebec, we carry out a privacy impact assessment.

If there is a breach

United States

We notify affected residents without unreasonable delay and within the deadline set by their state's breach notification law, and we notify state Attorneys General and other regulators where required.

Canada

When a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. We keep a record of every breach for at least 24 months.

Quebec

Confidentiality incidents that present a risk of serious injury are reported promptly to the Commission d'accès à l'information and to the people affected, and every incident goes in our register.

Our customers

When the data belongs to a graduation company, studio, school, or employer, we notify that organization without undue delay and help it meet its own obligations.

A notice tells you what happened, what information was involved, what we have done, what you can do to protect yourself, and how to reach us.

Found a security vulnerability? Please report it privately to privacidade@partiuformatura.app with the subject "Security report". We will not take legal action against good-faith research that respects people's privacy and does not disrupt the service.

Last updated: September 21, 2026