Legal document · Data protection

Privacy Policy

How Kliper processes personal data on its media monitoring and institutional clipping platform, in compliance with Brazilian Law No. 13,709/2018 (LGPD), the Marco Civil da Internet and Regulation (EU) 2016/679 (GDPR).

This is a translation. The Portuguese version governs: in case of conflict, it prevails. Read the governing version

Version 1.3 Published on September 29, 2026 Effective from October 29, 2026 Original language Brazilian Portuguese

1. Who we are

1.1. The Kliper platform is operated by ARCH B TECNOLOGIA LTDA, CNPJ No. 47.384.663/0001-10, headquartered at SQS 214, Bloco F, Apt 607, Asa Sul, Brasília - DF, CEP 70.293-060.

1.2. Kliper provides continuous monitoring of print, web, radio and television media, transcription, tone classification, institutional clipping, crisis alerts and analytical reports to public bodies and private organisations.

1.3. This Policy describes how we process personal data in all these activities and forms part of the Terms and Conditions of Use.

2. Roles: controller and processor

2.1. The LGPD distinguishes the party that decides on the processing (controller) from the party that carries it out on behalf and on the instructions of another (processor). At Kliper, these roles vary according to the data:

ContextControllerProcessor
Content captured and analysed in a Client's institutional interest; monitoring parameters; data of the organisation's Users The Client (contracting public body or company) Kliper
Account registration, authentication, billing, support, security and browsing on the public pages Kliper Providers listed in section 7

2.2. In public contracts, this arrangement reproduces the data protection clause of the administrative contract: the contracting Administration is the controller and Kliper the processor, under art. 5, VI and VII, of the LGPD. Kliper processes the data exclusively to perform the contract, may not share them without the contracting party's express authorisation and may not process them in a manner incompatible with the agreed purposes and periods.

2.3. Where Kliper acts as processor, data subjects' requests concerning those data are forwarded to the controlling Client, which decides whether to fulfil them; Kliper provides the necessary technical support.

3. Personal data processed

CategoryDataSource
Registration and account Full name, institutional e-mail address, organisation and position/access profile, cryptographic hash of the password, cryptographic hash of the one-time code (OTP), its validity, the number of validation attempts and any temporary lockout, identifier of the federated login provider, e-mail verification status, preferred language and account creation date Provided by the User or by the organisation's administrator
Application access logs IP address, date and time with time zone, route accessed and result of the operation Collected automatically (art. 15 of Brazilian Law No. 12,965/2014)
Operational records History of changes to monitoring configuration, with author and date; record of alert and clipping deliveries and the corresponding evidence of delivery; record of tone reclassifications made by Users, identifying the User who made them and the date Generated by the Platform
Organisation's public registration For the CNPJ provided by the Client: corporate name, legal nature, main economic activity, municipality, provider and date of the lookup, stored in the organisation's own space. Partners, directors or any other natural person in the register are never stored (section 5.6) Lookup of the Federal Revenue Service's public register through BrasilAPI, from the CNPJ provided by the Client
Monitored content Journalistic articles and broadcasts that may contain personal data of third parties — names of public officials, journalists, columnists, sources and people mentioned, images, voice and, occasionally, health-related data mentioned in the report Media outlets and public sources
Monitoring parameters Name and position of people whose mentions the Client decides to follow, such as the organisation's leaders and spokespeople Provided by the Client
Delivery contacts E-mail address of the recipients of clippings, alerts and reports. For recipients outside the organisation: dates and number of invitations, date and form of confirmation (double opt-in by e-mail) and a record of confirmations, refusals and cancellations, which identifies the address only by a cryptographic hash with a secret key; and the list of addresses that asked not to be invited again, stored in the same way Provided by the Client; confirmations and refusals, by the recipient themselves
Connectors and integrations Identifier and e-mail address of the connected account, scopes provided for by the integration, connection and synchronisation dates. Credentials and access tokens will be stored only once there is a vault with encryption at rest. Activation of the integration by the Client
Support and communications Content of the messages exchanged, attachments and support history Sent by the User
Billing Registration data of the contracting party, the person responsible for the contract, invoices and receipts Provided by the Client

Sensitive data. The Platform does not request sensitive personal data from Users. However, articles on public health may mention health-related data of identified people. Such data are processed only as made public by the outlet, without enrichment, without cross-referencing with other databases and without use for any purpose other than institutional follow-up. Data subjects may request restriction of display as described in section 12.

4. Purposes and legal bases

PurposeLegal basis (LGPD)
Create and maintain accounts, authenticate users and control access profilesPerformance of a contract — art. 7, V and VI
Provide the monitoring, clipping, alert and report service to the ClientPerformance of a contract — art. 7, V; and, for public bodies, execution of public policies — art. 7, III, in conjunction with art. 23
Capture and organise journalistic content already made publicManifestly public data — art. 7, § 4; legitimate interest — art. 7, IX
Keep application access logsCompliance with a legal obligation — art. 7, II, in conjunction with art. 15 of Law No. 12,965/2014
Prevent fraud, abuse and incidents; keep operational recordsLegitimate interest — art. 7, IX; credit protection and security — art. 7, X
Issue tax documents and comply with accounting and accountability obligationsCompliance with a legal or regulatory obligation — art. 7, II
Handle support requests and communicate service changesPerformance of a contract — art. 7, V
Exercise rights in judicial, administrative or arbitral proceedingsArt. 7, VI
Non-essential cookies and marketing communicationsConsent — art. 7, I (revocable at any time)

4.1. Where processing relies on legitimate interest, Kliper carries out a balancing assessment between that interest, the data subject's expectations and the mitigation measures adopted. The corresponding report may be requested from the Data Protection Officer.

4.2. We do not process personal data for a purpose incompatible with those declared here, nor do we sell, rent or transfer them to third parties for advertising purposes.

5. Journalistic content and data from public sources

5.1. The core of the service is capturing content already published by media outlets and making it available to the Client in an organised way. As a rule, these are data made manifestly public by the data subject themselves or by a third party exercising freedom of journalistic information.

5.2. Under art. 7, § 4, of the LGPD, the processing of manifestly public data does not require consent, but remains subject to good faith, legitimate purpose and the principles of art. 6. Kliper observes these limits: it does not enrich profiles, does not build behavioural scores on natural persons, does not sell lists and does not use the archive for any purpose unrelated to the Client's institutional follow-up.

5.3. The journalistic activity of the monitored outlets falls outside the material scope of the LGPD, under art. 4, II, "a". Kliper does not present itself as a journalistic outlet: it acts as a monitoring service provider and, in that capacity, is fully subject to the law.

5.4. People mentioned in an article in the archive may request restriction of display, correction of incorrect metadata or deletion of a specific item by writing to admin@klipermedia.com.br. The request is assessed by weighing the data subject's right, the public interest, the right to information and any legal duty of retention; the reasoned reply is sent within 15 (fifteen) days.

5.5. Removing an item from Kliper's archive does not affect the original publication by the media outlet, which must be approached directly.

5.6. In the CNPJ lookup of the Federal Revenue Service's public register, made through BrasilAPI, Kliper neither stores nor displays the list of partners and directors (QSA), nor data of any natural person in it. The QSA is read only at the time of the lookup, to check whether the company has a single partner who is a natural person, and is discarded immediately afterwards; only the resulting classification of the organisation is kept. Where the CNPJ corresponds to a sole trader or to a company whose register identifies a natural person, the name, address and activity are neither displayed nor stored; only the legal nature is kept.

6. Automated processing and artificial intelligence

6.1. The Platform uses automatic speech recognition, natural language processing and language models to transcribe audio and video, summarise articles, classify tone as positive, neutral or negative and flag crisis situations. Audio and video transcription runs on Kliper's own infrastructure, without sending the content to third-party providers.

6.2. These operations apply to journalistic content and do not produce decisions about natural persons that affect their interests — there is no profiling for granting credit, employment, access to a service or individual assessment.

6.3. Even so, the right of review provided for in art. 20 of the LGPD is guaranteed: any automated classification may be challenged and reviewed by a natural person, on request to the Data Protection Officer or to support, with information on the criteria used, subject to commercial and industrial secrecy.

6.4. Kliper does not use Client content and data to train its own models. Only the text of the journalistic article to be summarised or classified is sent to the language model providers listed in section 7.2, never registration data of Users or recipients. The Platform sends this text only to providers that state, in their terms, that they do not use the data received to train or fine-tune their models. Part of this access is currently made through shared free-tier keys of the model gateway, and not under Kliper's own contract with the provider; this prohibition therefore currently derives from the terms published by the providers and will be guaranteed by contract once Kliper uses its own access keys.

7. Sharing and processors

7.1. We do not sell personal data. Data are shared only in the following cases:

  • Infrastructure and service processors, strictly to perform the service, under a contract imposing confidentiality, security and a prohibition on their own use;
  • With the controlling Client, as regards the data processed on its behalf and on its instructions;
  • With public authorities, on a reasoned request, court order or legal obligation, limited to what is strictly required and, where permitted, with prior notice to the data subject or to the Client;
  • With legal and accounting advisers, under a duty of confidentiality, for the regular exercise of rights.

7.2. Processors and providers currently used:

ProviderFunctionPlace of processing
Cloud infrastructure providerHosting of the application and the databaseEuropean Union
Magalu Cloud (Object Storage)Archive of media, facsimiles and clips; database backupsBrazil
Cloudflare, Inc.DNS, attack protection and content deliveryGlobal network, with edge processing
Google LLCFederated login (Google Identity Services), when enabled by the Client; news search (Google News) in the in-depth scan, which sends only the name or identifier of the organisation searchedUnited States
Resend, Inc.Transactional e-mail: sending one-time codes, clippings, alerts, invitations to recipients and configuration reminders to the organisation's administratorsBrazil (São Paulo sending region); company headquartered in the United States
Groq, Inc., through a model gateway operated on Kliper's own infrastructureSummary and tone classification of the articles' text, when the use of language models is enabledUnited States
Cloudflare, Inc. (Workers AI)Alternative to the provider above, through the same gateway, for summary and tone classification when the main provider is unavailableGlobal network, with edge processing
TypeSafe AI, Inc. (Jev classifier)Tone classification of the articles' text according to the rules defined by the organisationUnited States
BrasilAPI and ViaCEPLookup of the CNPJ and postcode (CEP) entered in the organisation's registration, to fill in the corporate name and address; BrasilAPI receives only the CNPJ looked up and ViaCEP only the postcodeBrasilAPI: the provider's cloud infrastructure, outside Brazil; ViaCEP: according to the provider's infrastructure
jsDelivrDelivery of the chart library (Chart.js) of the Platform's dashboard; receives the IP address and the technical browser data of whoever opens the dashboardGlobal content delivery network
Ahrefs Pte. Ltd. (Ahrefs Web Analytics)Aggregate audience measurement of the public pages, only after analytics cookies are acceptedOutside Brazil, according to the provider's infrastructure

7.3. The list above reflects the configuration in force on the date of this Policy and may change. Relevant changes of processor involving a new international transfer or a material change in risk are communicated to the Client at least 30 (thirty) days in advance, with the option of submitting a reasoned objection.

7.4. The up-to-date list of processors by name, with the respective contractual safeguards, can be obtained from the Data Protection Officer.

8. International data transfer

8.1. Part of the infrastructure is located outside Brazil, as described in section 7. Every international transfer complies with arts. 33 to 36 of the LGPD and has at least one of the following safeguards:

  • Standard contractual clauses approved by the Brazilian National Data Protection Authority, under ANPD Resolution CD/ANPD No. 19/2024;
  • European Union standard contractual clauses and, where applicable, adequacy decisions, for transfers involving the European Economic Area;
  • Specific contractual commitments on security, confidentiality, auditability and respect for data subjects' rights.

8.2. The main hosting is in a member country of the European Union, with a level of protection recognised as adequate under the GDPR.

8.3. Where the Client requires it by contract — a common situation in public contracts with a data sovereignty requirement — Kliper offers a configuration with processing and storage exclusively in Brazilian territory, by prior agreement.

9. Retention and deletion

DataRetention periodBasis
Application access logsMinimum of 6 (six) months, deleted automatically after at most 190 (one hundred and ninety) daysArt. 15 of Law No. 12,965/2014
Account and profile dataFor as long as the relationship lasts; after it ends, deleted by a manual process within 30 (thirty) daysPerformance of a contract
Archive of monitored content and reportsDuring the contract term and the return period; in public contracts, for the period required for retention and accountabilityContract and public archives legislation
Unconfirmed invitations to external recipientsDeleted 37 (thirty-seven) days after the invitation: 7 (seven) days of validity and 30 (thirty) additional daysMinimisation
Operational recordsDuring the contract term and for the period required for retention and accountabilityLimitation periods and accountability
Tax and accounting documents5 (five) yearsTax legislation
BackupsUp to 30 (thirty) days, with automatic rotationOperational continuity

9.1. Ending the relationship may not result in the loss or unavailability of the information produced during the term. Before deletion, the Client may obtain a full export of the archive in commonly used formats, under clause 16.3 of the Terms and Conditions.

9.2. Once the periods have expired, the data are deleted securely and irreversibly from the production and backup environments. Irreversibly anonymised data may be kept for statistical purposes, ceasing to be personal data under art. 12 of the LGPD.

10. Information security

10.1. We adopt technical and administrative measures under art. 46 of the LGPD and Decree No. 8,771/2016, among them:

  • encryption in transit by TLS on the Platform's interfaces;
  • storage of passwords exclusively by a salted cryptographic hash function, with no possibility of recovery in clear text;
  • operational secrets (service keys and passwords) kept outside the source code, in server configuration with access restricted to the operations team;
  • no storage of connector credentials and access tokens until a vault with encryption at rest is in place;
  • authentication by one-time code and support for federated login, with the code stored only as a keyed cryptographic hash, never in clear text;
  • masking of e-mail addresses, codes and tokens in the application logs;
  • access control by profile, with least privilege and segregation of duties;
  • logical isolation between organisations, with the platform's governance plane separate from the clients' plane, so that global administration is not part of the member list of any client organisation;
  • a record of changes to monitoring configuration, with author and date, and of alert and clipping deliveries;
  • automatic database backups every 12 (twelve) hours, stored in Brazilian territory (Magalu Cloud) and kept for up to 30 (thirty) days;
  • periodic images of the application server, kept by the hosting provider in the European Union, in the same location as the main hosting;
  • vulnerability management and continuous updating of dependencies.

10.2. The controls are referenced to the standards ABNT NBR ISO/IEC 27001, 27002, ISO/IEC 27701 and ISO/IEC 27018. Adopting these references is not, in itself, a statement of certification; any certifications obtained will be published with their scope.

10.3. No system is absolutely secure. Kliper maintains a process of continuous improvement and encourages responsible disclosure of vulnerabilities to admin@klipermedia.com.br.

11. Security incidents

11.1. On detecting an incident that may cause relevant risk or harm to data subjects, Kliper:

  • notifies the controlling Client electronically within 3 (three) business days of becoming aware, with the information needed to assess the risk;
  • supports the Client in notifying the Brazilian National Data Protection Authority, within the period of ANPD Resolution CD/ANPD No. 15/2024, and the affected data subjects;
  • notifies the ANPD and the data subjects directly when acting as controller;
  • takes immediate containment, eradication and recovery measures, and records the event with a root-cause analysis and an action plan.

11.2. The notification states, at a minimum: the nature of the data affected, the data subjects involved, the technical protection measures applied, the risks identified, the reason for any delay and the measures taken.

12. Data subject rights

12.1. Under art. 18 of the LGPD, the data subject may request at any time:

  • confirmation that processing exists and access to the data;
  • correction of incomplete, inaccurate or out-of-date data;
  • anonymisation, blocking or deletion of unnecessary or excessive data or of data processed in breach of the law;
  • portability to another provider, subject to commercial and industrial secrecy;
  • deletion of data processed on the basis of consent, except in the retention cases of art. 16;
  • information about the entities with which data have been shared;
  • information about the possibility of not giving consent and its consequences;
  • withdrawal of consent;
  • review of decisions taken solely on the basis of automated processing;
  • objection to processing based on one of the cases exempt from consent, in the event of non-compliance with the law.

12.2. How to exercise them. Send the request to admin@klipermedia.com.br, describing the request. We may ask for additional information to confirm your identity — a security measure that protects the data subject against fraudulent requests.

12.3. Deadlines. We reply within 15 (fifteen) days to access requests and within a reasonable period to the others, under art. 19 of the LGPD. The service is free of charge.

12.4. Where Kliper acts as processor, the request is forwarded to the controlling Client within 5 (five) business days, and the data subject is informed of the forwarding.

12.5. Requests may be refused on reasoned grounds where there is a legal obligation to retain, the regular exercise of rights, an order of a competent authority or the prevalence of the public interest and the right to information. A refusal is always reasoned in writing.

13. Cookies and similar technologies

13.1. We use the following categories:

CategoryPurposeConsent
Strictly necessaryKeeping the authenticated session, with a cookie restricted to the site itself, and preserving the consent choice, recorded in the browser's local storageNot required — the Platform does not work without them
PreferencesRemembering the chosen language, by a cookie valid for 12 (twelve) months, and filters, view mode and interface choicesNot required when stored only in the browser
AnalyticsMeasuring aggregate audience of the public pages, by the provider listed in section 7.2Required — enabled only after acceptance

13.2. We do not use behavioural advertising cookies or share identifiers with ad networks.

13.3. The notice shown on the first visit lets you accept all cookies or only the necessary ones. The choice is recorded in your browser and can be reviewed at any time through the cookie settings link in the footer of the public pages or by clearing the site's data; you can also block cookies in your browser settings, in which case some features may become unavailable.

13.4. The session token is written with security attributes and is valid for at most 24 (twenty-four) hours, expiring automatically at the end of that period.

14. Children and adolescents

14.1. The Platform is intended for professional use by people aged 18 or over and does not knowingly collect data of children and adolescents to create accounts.

14.2. Monitored journalistic articles may, exceptionally, mention minors. Such data are processed in observance of the best interest provided for in art. 14 of the LGPD and the Brazilian Statute of the Child and Adolescent, restricted to the purpose of institutional follow-up and subject to a priority request for restriction of display by the legal guardians.

14.3. If a minor's registration without authorisation is identified, the account is deactivated and the data deleted.

15. Data subjects in the European Economic Area

15.1. Where Regulation (EU) 2016/679 applies, data subjects have the rights of access, rectification, erasure, restriction of processing, portability, objection and not to be subject to automated decisions (arts. 15 to 22 of the GDPR).

15.2. The corresponding legal bases are performance of a contract (art. 6(1)(b)), compliance with a legal obligation (art. 6(1)(c)), legitimate interest (art. 6(1)(f)) and consent (art. 6(1)(a)).

15.3. Requests follow the same channel as section 12 and are answered within one month, extendable by two months in complex cases, with information to the data subject.

15.4. The right to lodge a complaint with the competent supervisory authority of the respective Member State is guaranteed.

16. Data Protection Officer and ANPD

16.1. Kliper's Data Protection Officer (encarregado), under art. 41 of the LGPD, is Flavio Froes Ribeiro de Oliva, who can be contacted at admin@klipermedia.com.br.

16.2. The Data Protection Officer receives communications from data subjects and from the authority, provides clarifications, takes measures and guides staff on data protection practices.

16.3. In public contracts, each party appoints its data protection officer or representative for communications on LGPD matters, according to the contract's data protection clause.

16.4. A data subject who does not obtain a satisfactory reply may petition the Brazilian National Data Protection Authority (ANPD), under art. 18, § 1, of the LGPD, through the official channels at gov.br/anpd.

17. Changes to this Policy

17.1. This Policy may be updated to reflect legal, regulatory or technical changes or changes in the scope of the service.

17.2. Relevant changes — in particular to purpose, legal basis, processors with international transfer or retention periods — are announced at least 30 (thirty) days in advance, by a notice on the Platform and by a message to the registered e-mail address.

17.3. Where a change depends on consent, it will be obtained again before entry into force.

17.4. Previous versions remain available on request to the Data Protection Officer.