Stammia

Privacy Policy

Last updated: 2026-08-01

This policy explains how Stammia collects and processes personal data, in line with the LGPD (Lei 13.709/2018) and the GDPR.

1. Controller and contact

Controller: Stammia (stammia.com), operating from Brasil / Brazil.

Data protection contact (DPO): [contact email — to be provided].

2. Data we collect

Account data: name, email, password hash, language preference, profile photo.

Content data: portfolio, landing pages, media kit, projects, files and media you upload.

Commercial data: leads, bookings, contracts, financial entries you record.

Billing data: subscription status, invoices and payment identifiers from Stripe. Card numbers are never received or stored by us.

Usage data: page views, device type, referrer, approximate country and clicks on your public pages.

3. Why we process it

To provide the contracted service (LGPD art. 7, V — contract performance).

To bill, prevent fraud and comply with tax and accounting duties (legal obligation / legitimate interest).

To send service, security and billing notices. Marketing emails only with consent, revocable at any time.

To produce aggregate analytics that help you understand your audience.

4. Sharing

We share data only with processors needed to run the platform: hosting and database infrastructure, email delivery, and Stripe for payments. Each acts under contract and on our instructions.

We never sell personal data. International transfers rely on standard contractual clauses and equivalent safeguards.

5. Retention

Account and content data are kept while your account is active and for up to 30 days after deletion, except tax and billing records kept for 5 years as required by Brazilian law.

6. Your rights

You may request confirmation, access, correction, anonymisation, portability, deletion, information on sharing, and revocation of consent.

Send requests to [contact email — to be provided]; we answer within 15 days. You may also complain to the ANPD or your local supervisory authority.

7. Security

Data is encrypted in transit (TLS) and at rest by our infrastructure provider. Access is restricted by row-level authorisation rules so each user only reaches their own records. Passwords are hashed and checked against known breach lists.