Home

Last updated on

Privacy Policy

This policy explains, in plain language, what personal data Plare collects, why we collect it, who we share it with and what your rights are — including how to request deletion of your information.

In effect since

Translation notice

This is a courtesy translation, provided so that English-speaking users can understand the document. The Portuguese version is the legally binding one: if anything here diverges from the Portuguese text, the Portuguese text prevails.

This Privacy Policy describes how Plare BIM Inc. (“Plare”, “we”) processes personal data on the plare.app website and in the Plare desktop application, in accordance with the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD).

1. Who we are

Plare is CAD/BIM software for architects and engineers. We are the controllers of the personal data processed on our properties — that is, we are responsible for the decisions about how that data is processed.

2. What data we collect

We collect only what is necessary to deliver the product. The data depends on how you interact with us:

  • Beta waiting list: your email address and where the signup came from (for example, “hero” or “cta-final”).
  • User account: email, password stored as a hash (never in plain text) and, where provided, a display name.
  • Application usage data: installed version, operating system, errors and usage events — used to fix defects and prioritise improvements.
  • Browsing on the site: IP address, user agent, pages visited and time on page, collected by audience measurement tools when you authorise it.
  • Communication: messages and attachments you send us through support channels.

We do not collect sensitive data (such as racial origin, health, biometrics or religious beliefs) and we do not ask for personal documents to use the Beta.

3. What we use your data for

  • Sending the Closed Beta invitation and communicating product news.
  • Creating and authenticating your account, including validating credentials.
  • Keeping the software working: detecting errors, fixing defects and measuring how features perform.
  • Understanding how the site is used, to decide what to write on the blog and what to improve on the conversion page.
  • Complying with legal obligations and responding to requests from competent authorities.
  • Preventing abuse and fraud, protecting the integrity of the platform.

Each processing activity above rests on one of the bases in art. 7 of the LGPD:

  • Consent (art. 7, I): sending marketing communications and using audience measurement cookies. You may withdraw it at any time.
  • Performance of a contract (art. 7, V): creating the account, authentication and providing the contracted service.
  • Legitimate interest (art. 7, IX): error telemetry, platform security and product improvement, always limited to what is strictly necessary.
  • Compliance with a legal obligation (art. 7, II): retaining records required by law and responding to authorities.

5. Cookies and analytics

We use cookies and similar technologies for two purposes:

  • Strictly necessary: keeping the session authenticated and remembering your theme choice (light/dark) and your consent choice. Without them the site does not work correctly.
  • Audience measurement: Google Analytics 4 (and/or Google Tag Manager), which shows us in aggregate which pages are visited.

Audience measurement is only enabled after you consent through the banner shown on your first visit. Until then, Google is loaded in consent-denied mode, which means no advertising or analytics cookies are written.

You can withdraw consent at any time by clearing the site data in your browser — the banner appears again and your choice is respected. You can also block cookies directly in your browser settings.

6. Who we share it with

We do not sell personal data. We share it only with suppliers that make the service possible, always under contract and bound by confidentiality:

  • Hosting and database (cloud infrastructure for the site and user accounts).
  • Deployment platform for the site and the API functions.
  • Google (Analytics 4 and Tag Manager), for audience measurement, when authorised.
  • Transactional email providers, to send the Beta invitation.
  • Public authorities, where there is a legal obligation.

7. International transfer

Some of our suppliers keep infrastructure outside Brazil. In those cases we adopt standard contractual clauses and assess the adequacy of the destination country, as required by arts. 33 to 36 of the LGPD, so as to maintain a level of protection compatible with this policy.

8. Retention and disposal

We keep data for as long as necessary for the purpose it was collected for:

  • Waiting list: until the invitation is sent or until you ask us to remove it.
  • Account: for as long as the account exists. After a deletion request, the data is anonymised or erased within 30 days, except for records we are required by law to retain.
  • Technical logs: a short period, generally 30 to 90 days, for diagnostics and security.

9. Security

We adopt technical and administrative measures appropriate to the scale of the product: encryption in transit (HTTPS/TLS), passwords stored with hashing and salt, role-based access control and logging of security events. No system is absolutely secure, but we review our practices periodically and fix vulnerabilities as soon as we identify them.

10. Your rights

Under art. 18 of the LGPD, you have the right to:

  • confirm that processing exists;
  • access your data;
  • correct incomplete, inaccurate or out-of-date data;
  • anonymise, block or erase unnecessary data;
  • port your data to another provider;
  • erase data processed on the basis of consent, except where retention is legally required;
  • obtain information about sharing;
  • withdraw consent;
  • object to processing based on legitimate interest, where applicable.

To exercise any of these rights, write to [email protected]. We reply within 15 days, with a final deadline as set out in ANPD regulation.

11. Children and adolescents

Plare is a professional tool and is not intended for anyone under 18. We do not knowingly collect data from children or adolescents. If we identify an account in that situation, it will be removed.

12. Changes to this policy

We may update this policy to reflect changes in the product or in legislation. Where a change is relevant, we will let you know by email or by a notice on the site, with reasonable notice. The date of the last update is always at the top of this page.

13. Contact and data protection officer

Questions, requests and complaints about privacy should be sent to [email protected]. You may also contact the Brazilian National Data Protection Authority (ANPD) if you believe the processing has not been handled properly.