Last updated: 2026-07-26
This Policy explains how bvault (BVasconcelos) collects, uses and protects personal data, in compliance with Brazil's General Data Protection Law (LGPD, Law 13.709/2018).
The data controller is BVasconcelos. Data Protection Officer (DPO) contact: contato@bvasconcelos.com.
We collect company registration data (legal name, tax ID, contact), administrator identity data via Microsoft Entra (email and identifier), and usage data required for the storage service.
We use data to provide the service, bill, support and comply with legal obligations. We do not sell personal data.
We share data only with processors necessary to the service (e.g. storage provider and payment gateway), under contract and to the extent necessary.
You may request access, correction, portability or deletion of your data, and revoke consent, by writing to contato@bvasconcelos.com.
We use encryption at rest and in transit, per-company isolation and immutable retention (WORM) to protect data.
We retain data for as long as needed for the purposes and legal obligations; afterwards it is deleted or anonymized.
The bvault app for Android and iPhone accesses the files your company already stores in the service, always through corporate Microsoft Entra sign-in — we create no separate password or profile. Access to your photo library and device files happens only when you choose to upload a photo or document, and only the selected item is sent; the app does not request camera or microphone access. Biometric unlock is handled by the device's own system: we receive only the confirmation that it succeeded, never your fingerprint or face image. The session token is stored encrypted on the device — Keystore on Android, Keychain on iPhone — and the app does not allow your data to be backed up off it. There is no advertising, third-party tracking or sale of data. Uninstalling the app erases local data; your files remain in your company's service.