Institutional document

Privacy Policy

This document explains how personal data is processed throughout the OpereBem ecosystem.

1. Controller and scope

Where OpereBem determines the purposes and means of processing, the controller is Mateus Teixeira, who is responsible for operating the OpereBem brand, hereinafter “OpereBem”. Mateus Teixeira also acts as the data protection contact and person in charge.

This Policy covers Terminal OpereBem, Portal OpereBem, Diário OpereBem, the Community, OpereBem ID, authorised APIs, institutional websites, help pages, documentation, status, support, recruitment and other features that refer to this document.

Third-party services may process data under their own policies. Commercial partners have a separate contractual relationship; this Policy covers only the data OpereBem processes in that relationship or makes available in an operational area.

2. Processing contexts

  • OpereBem ID: registration, authentication, account recovery, sessions, profile, plan and product integration.
  • Terminal: tools, preferences, plans, purchased features, market data and usage records.
  • Portal: educational content, enrolments, progress, assessments, certificates, materials and support.
  • Diário: trades, user-entered trading accounts, imports, images, notes, checklists, setups, goals, analytics and self-assessments concerning discipline, satisfaction or anxiety.
  • Community: profile, Discord or equivalent integration, posts, messages escalated to moderation, benefits and security records.
  • Websites and support: browsing, forms, tickets, WhatsApp messages, surveys, recruitment, partnerships and Service communications.

Diário self-assessments are intended for the user's personal organisation. They are not a diagnosis, medical record or medical advice and must not be used for health emergencies.

3. Personal data processed

We process only the categories compatible with the relevant Service and interaction:

CategoryExamples
Identity and contactName, email, phone, country, date of birth and Brazilian CPF where required for billing, verification or a legal duty.
Account and securityIdentifiers, hashed password, tokens, sessions, codes, API keys, plan, permissions, IP address, browser, device and access attempts.
Purchase and paymentPlan, interval, status, history, amounts and provider identifiers. Complete card data remains with the payment provider.
Use and contentPages and features used, preferences, progress, assessments, tickets, messages, files, posts and error events.
Trading and DiárioAssets, trades, results, dates, strategies, notes, goals, checklists, charts and user-entered self-assessments.
CommunityUsername, identifier, avatar, posts and moderation or security records.
Recruitment and partnersCV, experience, professional links, application, identifiers and the partner's own operational data.
Measurement and communicationReferrer, language, time zone, visited pages, campaign parameters, preferences and message history.

We do not request banking passwords, broker credentials or complete card data in ordinary fields. Users must not enter sensitive data or third-party data in notes, messages or uploads without need and permission.

4. Data sources

Data may be provided by the data subject; generated through Service use; received from integrations enabled by the user; supplied by a partner in a legitimate relationship; or received from authentication, payment, hosting, analytics, support and community providers.

Anyone importing or submitting information about another person confirms that they have permission or another valid legal basis and must limit the information to what is necessary.

5. Purposes and legal bases

PurposeLegal basis normally used
Create and manage OpereBem ID and provide requested features, content, support and integrations.Performance of a contract or pre-contractual procedures.
Process charges and subscriptions and comply with tax, accounting or regulatory duties.Performance of a contract and legal or regulatory obligation.
Protect accounts, prevent fraud and abuse, investigate incidents and defend rights.Legitimate interests, legal obligation and establishment, exercise or defence of legal claims.
Generate metrics and maintain, personalise and improve products and infrastructure.Performance of a contract and legitimate interests, or consent where required.
Send marketing and enable advertising or optional technologies.Consent or another basis permitted for the context, with an opt-out or withdrawal option where applicable.
Respond to contacts, assess applications and negotiate a purchase, hire or partnership.Pre-contractual procedures and legitimate interests.

Where we rely on legitimate interests, we assess purpose, necessity, the person's expectations, impact and safeguards. Consent may be withdrawn without affecting prior lawful processing.

6. Cookies, analytics and current technologies

Cookies and similar technologies are used for authentication, security, sessions, preferences, operation, measurement and analytics. Necessary technologies may operate to provide and protect the Services.

Group, Terminal, Portal and Diário provide a binary analytics choice: “Accept” or “Do not accept”. On those surfaces, Google Analytics loads only after acceptance. Refusal does not prevent access to a page, registration, login, checkout, subscription or any necessary feature. The choice can be reviewed or withdrawn at any time through “Cookie preferences”; withdrawal stops new transmissions and removes reachable optional cookies.

When accepted, Google Analytics measures source, campaign, eligible pages, clicks, movement between products, registration, checkout, the first paid subscription and the product-use journey. This journey may include modules visited in Terminal and Diário; course, book, material and indicator catalogues and items in Portal; access attempts and their outcomes; confirmed downloads; course starts and completions; and predefined generic actions such as open, start, import, export, download or complete.

Values sent use closed lists and controlled keys. We do not send email address, name, phone number, CPF, free text, full URLs or URL parameters, internal account identifiers, trading or journal content, account, balance, position, broker, emotion, answers, files, lesson details, watch time, progress percentage or credentials to Analytics. Administrative areas, APIs, internal routes and unknown routes are structurally excluded from Analytics. For eligible authenticated journeys, Terminal, Portal and Diário may use a dedicated pseudonymous analytics identifier that differs from the account's internal identifier. Advertising and ad-personalisation signals remain disabled, and event and user data are retained for up to 14 months.

Bio OpereBem: by decision of the controller, Bio uses analytics automatically and does not display the cookie notice. Collection is limited to navigation, source, campaign, clicks and destination, without free text or full URLs, and may be blocked by browser settings or extensions.

Google reCAPTCHA and equivalent technologies may load to prevent fraud, spam and abuse, regardless of analytics preferences. Fonts, videos, charts, market widgets and third-party links may also receive IP address, browser and technical data needed for delivery.

7. Persons under 18

The Services are not intended for persons under 18, and we do not knowingly collect their data to create accounts. If we identify a minor's account, we may restrict access, request verification and delete data that need not be retained. A parent or guardian may report the matter through the Help Center.

8. Sharing and providers

OpereBem does not sell personal data. Depending on the feature actually used, we may share the minimum necessary with:

  • Hostinger, Vercel and infrastructure providers: hosting, delivery, databases, logs, security and availability;
  • Stripe: payments, billing, fraud prevention and Stripe Connect where applicable;
  • Google: Analytics, reCAPTCHA, fonts and technical resources;
  • Discord: Community access, identity and operation;
  • WhatsApp/Meta and email providers: support and communications;
  • TradingView and other market providers: charts, widgets, quotes and embedded content;
  • OpenAI and AI providers: generation or editorial assistance in identified features. Focus AI currently uses public/editorial Focus Bulletin data, not private Diário data or support messages;
  • internal OpereBem ecosystem services: authentication, APIs, plans, support and product integration;
  • professionals bound by confidentiality, authorities where legally required and successors to a reorganisation of the operation.

The list reflects the current operation and may change with the infrastructure. Each provider receives data compatible with its role and may act as a processor or an independent controller, as applicable.

Partners receive only their own operational data and information that is aggregated, masked or necessary to attribute links and codes. They do not receive private Diário content, support content or private messages merely by participating in the programme.

9. International transfers

Some providers may process data in the United States or other countries where they maintain infrastructure or teams. Transfers may involve hosting, security, analytics, payment, communications, community, market data and AI for the time required by the purposes and retention criteria in this Policy.

OpereBem assesses the provider's role, security measures and applicable legal mechanism, such as an adequacy decision, contractual clauses or another mechanism permitted by the LGPD and ANPD. Available details about the provider, purpose, destination and safeguards may be requested through the Help Center, subject to trade secrets and security requirements.

10. Retention, account closure and export

We retain data while necessary to provide the Service and fulfil the stated purpose. We consider account and contract duration, legal periods, billing, fraud prevention, security, audit, support, disputes and the exercise of rights.

Account closure must be requested through the Help Center. After confirmation and resolution of pending matters, we disable sessions and access, cancel renewals and delete or anonymise data with no remaining purpose. Financial, anti-fraud, security and legal-defence data may be retained where permitted or required by law. Backups are replaced on technical cycles and remain protected while they exist.

Export of available data is also requested through support. Format and content depend on the product, confirmed identity, third-party rights and technical feasibility.

11. Security and incidents

We adopt technical and administrative measures proportionate to our operation and risk, such as access control, authentication, credential protection, secure connections, permission segregation, security records, updates, backups and provider assessment. No system is absolutely secure.

Incidents are assessed and contained. Where they may cause relevant risk or harm, OpereBem will notify the ANPD and affected data subjects in accordance with applicable regulations.

12. Data subject rights

Under the LGPD and where applicable, data subjects may request confirmation and access; correction; anonymisation, blocking or deletion; portability; sharing information; withdrawal of consent; objection; review of automated decisions; and petition to the ANPD or consumer-protection bodies.

Requests must be submitted through the Help Center, by ticket or WhatsApp, stating “Privacy and LGPD”. We may request information to confirm identity. Responses follow legal time limits and may be restricted by retention duties, third-party rights, security or trade and industrial secrets.

13. Automation, AI and financial data

Terminal, Diário and related tools may calculate metrics, alerts, classifications and analyses from user-provided or imported data. Those results are informational, educational or organisational and do not make a legal decision about the data subject.

Features that use artificial intelligence are identified where applicable. AI output may contain errors. If OpereBem begins sending users' private data to a new AI provider or implements solely automated decision-making that affects interests, this Policy and the feature notices will be updated before or when that processing begins, as required.

14. Person in charge and support

Controller and person in charge: Mateus Teixeira, responsible for operating the OpereBem brand

Channel: terminal.operebem.com.br/help, by ticket or WhatsApp message

15. Updates and languages

We may update this Policy to reflect legal, technical or operational changes. The version and effective date will remain on this page, and material changes will be notified through an appropriate channel.

The Portuguese and English versions are intended to have the same meaning. If an unavoidable interpretation conflict arises, the Portuguese version prevails.