Privacy Policy

Version 2026-09-02 · Effective 2 September 2026

1. Controller and contact

Ember Engenharia Ltda, Brazilian registration CNPJ 31.044.905/0001-97, at Av. Monteiro Tourinho 1415, Atuba, Curitiba, PR, 82600-000, Brazil, controls the personal data described here. Privacy requests and complaints: contact@ganterlab.com.

This Policy covers ganterlab.com and your Ganter Lab account — registration, hosted sign-in, subscriptions, checkout, transactional email, and website security. What the installed desktop application keeps on your station, and the limited sign-in and licence calls it makes, are described in the separate Desktop Privacy Policy. It is written as a global notice with regional rights in section 13.

2. Our privacy design

  • Analytics and advertising cookies stay off until you choose: accept, reject non-essential cookies, or configure — and change your mind anytime from "Cookie preferences" in the footer.
  • Refusing analytics or marketing never blocks access, downloads, sign-up, or purchase, and we never sell personal data for money.
  • Commercial email is optional and opt-in; every message unsubscribes in one click, with no open-tracking pixel or per-recipient click profiling.
  • Necessary cookies (sign-in, security, language, theme) always run so the site works.
  • Card details go directly to Stripe and never reach our servers.
  • Account export and deletion are available through the account pages.

3. Data we handle

Category Examples Source
Account and identity Email, password hash, email-confirmation state, Google identifier and basic profile if selected You; Google
Legal evidence Accepted document versions, date/time, and international-transfer consent You; our site or app
Subscription Stripe customer/subscription identifiers, plan, seat count, status, renewal dates Stripe
Checkout Name, billing address/country, optional tax identifier, payment status You; Stripe
Station licence Random station ID, station name, assigned seat, last licence check Your station
Commercial email Authorization state, date, text version and origin; preferred language; approximate first/last authenticated desktop contact; unsubscribe records You; your station
Support Support requests and any contact details or files you email us You
Integrator public listing If you list your company in the integrator directory: company name, description, website, contact email, phone, city, state, country, the map pin coordinates, your public integrator code, and the showcase images you upload. All of it is published to any visitor, and the images are reviewed before they appear You
Security and operations IP address, user agent, request time, authentication and security events, short-lived server logs Your browser; our systems
Preferences Necessary cookies for sign-in, antiforgery, language, and theme Your browser
Analytics and advertising With your consent only: pseudonymous cookie/identifier, device and browser data, pages viewed, referral and campaign parameters, and conversion events (no name, email, phone, or account id) Your browser; Google; advertising platforms

We do not receive card numbers, plant/process configuration, recorded process data, or continuous desktop telemetry. What the installed application handles on the station, and the optional crash reports and feedback it can send by your choice, are covered by the Desktop Privacy Policy. Please do not place personal or confidential plant data in messages you send us unless it is necessary.

We infer an approximate region from the network address of your request to pre-select a country and a currency on the pricing page and in the integrator directory. That inference happens on our own server, before any cookie choice, because the page cannot be written without it; the address itself is read for that single answer and not stored for this purpose.

We use data to create and secure accounts; provide licences and subscriptions; process and document transactions; deliver email and support; with your consent, measure website use and the effectiveness of our advertising and build remarketing audiences; prevent abuse; diagnose an issue you choose to report; meet tax, accounting, privacy, consumer, sanctions, and legal duties; and establish or defend claims.

Depending on the jurisdiction, the basis is performance of a contract, steps requested before a contract, compliance with law, our legitimate interests in operating and securing the service, or consent. Consent applies, where required, to analytics and marketing cookies and the identifiers they set, to a separately presented international transfer of account data (and, in the desktop application, to optional crash reports and feedback). You may withdraw consent prospectively, including from "Cookie preferences" in the footer.

Commercial email (optional)

With your separate, opt-in authorization — a choice distinct from the Terms and this Policy, off by default — we send occasional commercial email about the product, its features, and licence offers. Refusing or later withdrawing it changes nothing about your account, the free trial minutes, the download, or any feature; account, security, and billing messages are always sent regardless, and none hides promotional content.

To choose who receives a given message we build audiences at send time from data we already hold: your account email and whether it is confirmed, your preferred language, your current authorization, your subscription situation, and the approximate first and last time an authenticated desktop contacted our server. That contact time never means you ran a test, spent time in the app, or used a feature — only that a signed-in desktop reached the server; we add no usage telemetry to form these audiences.

Commercial email is delivered through the same email provider named in section 5. Every commercial message carries a one-click unsubscribe link that works without signing in and takes effect immediately; you can also change the preference under Account → Manage. We keep the authorization state, its date, the text version, and its origin while the account exists, and we record an unsubscribe only to enforce your choice — never as an engagement metric. There is no open-tracking pixel and no per-recipient link or click profiling; only aggregate, non-identifying campaign parameters are used for analytics.

5. Providers and recipients

Recipient/processor Purpose Data Processing locations
Stripe Checkout, payment, tax and subscription administration Checkout, billing, transaction and subscription data Stripe's disclosed global infrastructure
Google (only if selected) External sign-in Email, provider ID, basic profile and authentication result Google's disclosed global infrastructure
Google (Tag Manager, Analytics 4) Website analytics and tag management, only with your analytics consent Pseudonymous analytics identifiers, device/browser data, pages viewed, campaign parameters, conversion events Google's disclosed global infrastructure
Advertising platforms (Google Ads, Meta, LinkedIn, and others) Advertising and remarketing, only with your marketing consent Pseudonymous advertising identifiers and conversion events Each platform's disclosed global infrastructure
Hostinger International Ltd. (server in Boston, United States) and Cloudflare, Inc. (United States, network proxy) Website, database, backups, security and operational logs Account, legal evidence, subscription links, network and operational data Brazil and the United States
Google LLC (Google Workspace) Account, transactional, and commercial email Email address, delivery metadata and message contents Brazil and the United States
OpenStreetMap Foundation Map tiles for the integrator directory, loaded only when the map is displayed Visitor IP address, user agent, and the map-tile coordinates requested OpenStreetMap Foundation's disclosed global infrastructure

Vetted professional advisers and authorities may receive the minimum necessary data for law, audit, tax, fraud prevention, or claims. We require processors to follow instructions, protect data, keep it confidential, assist with rights and incidents, and delete or return it when the service ends. We do not sell personal data for money. Only with your marketing consent do advertising cookies share online identifiers with the platforms above to build remarketing audiences; some US state laws treat this as a "sale" or "share", and you can opt out at any time (section 13).

6. International transfers

The controller is in Brazil and the providers above (including Google and, with marketing consent, the advertising platforms) may process data in Brazil and the United States. Depending on origin, safeguards may include an adequacy decision, Brazil's approved transfer mechanisms, EU Standard Contractual Clauses, the UK International Data Transfer Addendum/Agreement, contractual and security controls, or separate consent where local law requires it.

For a user subject to China's PIPL or Korea's PIPA, the separate transfer statement identifies the recipient categories, purposes, data, destinations, method, and retention described in this Policy. Refusing or withdrawing a transfer that is necessary for the hosted account can prevent that account from operating; the local desktop free mode does not upload plant data.

7. Retention and deletion

  • Account, legal-evidence, station, and active-subscription data: while the account exists.
  • Commercial-email authorization, its evidence, and unsubscribe records: while the account exists; an unsubscribe is retained to keep enforcing the preference.
  • Closed-account authentication and station links: deleted or de-identified within 90 days, except protected backups that roll off within 180 days.
  • Transaction, invoice, refund, and tax records: for the period required by Brazilian tax/accounting law and applicable local law, normally at least 5 years.
  • Security and operational logs: normally 30 days; longer only for an investigated incident or legal claim.
  • Support communications: normally 24 months after closure; de-identified records may be retained.

Deletion may be delayed where law, fraud prevention, chargebacks, security, or a legal claim requires a limited record. We then isolate it and use it only for that purpose.

8. Security and incidents

We use password hashing, TLS in transit, access controls, least privilege, protected backups, dependency updates, secrets management, logging, and processor due diligence. No system is perfectly secure.

We investigate suspected incidents, contain them, document the assessment, and notify affected people and authorities within the deadlines required by applicable law when the risk threshold is met.

9. Your universal controls and rights

We offer the following request process to everyone, subject to identity verification and lawful exceptions: confirmation and access; a portable copy; correction; deletion; restriction; objection; withdrawal of consent; information about sharing and transfers; and review or appeal of a denied request. We do not discriminate because you exercised a right.

Use Account → Manage → Personal data for export/deletion or email contact@ganterlab.com. State the right and country/state involved. We respond within the applicable deadline; where no shorter deadline applies, our target is 30 days. You may use an authorized agent where local law permits. You may complain to your local privacy authority.

We use necessary first-party cookies for authentication, antiforgery protection, language, and theme; these always run because the site cannot work without them. One more joins them only when you start a purchase: ganter_dl carries the single word "checkout_started" for up to 30 minutes, so the page you come back to can count that step. It holds no identifier of any kind and is deleted the moment it is read. With your consent we also use:

  • Analytics — Google Analytics 4, loaded through Google Tag Manager, to understand navigation and conversions.
  • Marketing — advertising and remarketing identifiers for Google, Meta, LinkedIn, and other platforms.

Analytics and marketing are denied by default: until you choose, nothing is stored in your browser and no data that identifies you is used. On your first visit a banner lets you accept all, reject non-essential cookies, or configure each category; accepting analytics does not enable marketing. Your choice is stored in your browser and you can change or withdraw it at any time from Cookie preferences in the footer, which stops new collection and removes that category's known cookies. Refusing never limits access, downloads, sign-up, or purchase. We do not make solely automated decisions that create legal or similarly significant effects, and we do not use personal data to train public AI models.

11. Children

Ganter Lab is a professional and industrial tool, not directed to children. Accounts require the legal capacity to enter a contract and are not knowingly offered to anyone under 18. Tell us if a child supplied data so we can investigate and delete it.

12. Changes

We will post a new version and effective date before material changes take effect and provide additional notice where law requires it. Consent is requested again if a change requires new consent.

13. Regional notices

Brazil — LGPD and consumer law

The controller is identified in section 1. LGPD rights include confirmation, access, correction, anonymization/blocking/deletion, portability, information about sharing, withdrawal of consent, opposition, and review of automated decisions. You may complain to the ANPD and consumer authorities. International transfers use an LGPD-permitted mechanism.

European Union / EEA — GDPR

Contract, legal obligation, legitimate interests, and consent are the bases listed in section 4. You may access, rectify, erase, restrict, port, object, and complain to your supervisory authority. Where legitimate interests apply, they are service security, fraud prevention, support, and improvement without behavioural tracking. EU transfers rely on adequacy or the European Commission's Standard Contractual Clauses plus supplementary measures where needed. EU representative for Article 27 matters: Not appointed yet; contact the controller at contact@ganterlab.com.

United Kingdom — UK GDPR

The same rights and bases apply under UK GDPR and the Data Protection Act 2018. Restricted transfers rely on UK adequacy regulations, the UK Addendum, or the International Data Transfer Agreement. You may complain to the ICO. UK representative: Not appointed yet; contact the controller at contact@ganterlab.com.

United States — state privacy laws

For California and similar state laws, categories collected, sources, purposes, and recipients are in sections 3–5. Only with your marketing consent do advertising cookies share online identifiers for cross-context behavioural advertising, which some state laws treat as a "sale" or "share"; we do not sell personal information for money and do not use sensitive personal information for an unrelated purpose. Eligible residents may request know/access, correction, deletion, portability, opt-out of sale/share, restriction/limit where applicable, non-discrimination, and appeal. Opt out at any time through Cookie preferences or a recognized browser opt-out signal, which we honour. Consumer requests go to the contact in section 9.

Canada and Quebec — PIPEDA and Law 25

We follow accountability, identified purposes, appropriate consent, minimization, safeguards, access, and correction. Canadian users may complain to the Office of the Privacy Commissioner or the applicable provincial regulator. Quebec users receive the French contractual/privacy version before choosing to contract in English, and may contact the person responsible for personal-information protection at contact@ganterlab.com.

China — PIPL

We process only the minimum data needed for the stated purposes. Data leaving mainland China may go to the controller in Brazil and the providers/destinations in sections 5–6. Before an outbound transfer where PIPL requires it, we present a separate consent describing recipient categories, contact route, purposes, method, data categories, retention, and how to exercise rights. You may request access/copy, correction, deletion, restriction, explanation, or withdraw consent. We will complete the required security assessment, certification, standard contract, or other transfer measure if the applicable volume/activity threshold requires it. Representative in China for PIPL matters: Not appointed yet; contact the controller at contact@ganterlab.com.

Japan — APPI

We specify purposes, apply security controls, supervise processors, and respond to disclosure, correction, cessation, and deletion requests. Foreign processing and third-party provision are described in sections 5–6, including destinations and safeguards. You may complain to Japan's Personal Information Protection Commission.

South Korea — PIPA

The categories, purposes, retention, processors, destinations, timing/method, and safeguards for domestic and overseas processing appear in sections 3–7. We obtain separate overseas-transfer consent when consent is the required basis and provide a method to refuse or withdraw it. Eligible users may access, correct, delete, suspend processing, withdraw consent, and complain to the Personal Information Protection Commission or another competent body.

India — Digital Personal Data Protection Act and Rules

The clear purposes and data are in sections 3–4. Consent can be withdrawn as easily as it is given, without affecting prior lawful processing. You may request access/correction/erasure, use the grievance route at contact@ganterlab.com, and nominate another person where the law provides. We use reasonable security safeguards and give breach notices required by the Act and Rules.

Mexico — LFPDPPP

This Policy is the privacy notice for Mexico. The controller, purposes, data, transfers, and means to limit use/disclosure are stated above. You may exercise ARCO rights (access, rectification, cancellation, opposition), revoke consent, or limit use/disclosure through contact@ganterlab.com. Necessary processor and legal transfers do not require consent; other transfers use the consent and notice required by the LFPDPPP.

14. Contact

contact@ganterlab.com
Ember Engenharia Ltda · Brazilian registration CNPJ 31.044.905/0001-97 · Av. Monteiro Tourinho 1415, Atuba, Curitiba, PR, 82600-000, Brazil