Version 4 · October 7, 2026
Privacy policy
This page explains what data the Convium website receives, what it is used for, where it is kept and how to request access, correction or deletion, under Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018).
This is an English translation of the Portuguese version. If the two differ, the Portuguese version prevails.
1. Who processes the data
Convium Consultoria de Tecnologia da Informação Ltda, CNPJ 69.288.092/0001-53, is the controller of the data received through the website. For any privacy matter, the channel is the email contato@convium.com.br.
2. What the website receives
- Free assessment. Your answers are kept only in your device’s browser, so you can continue where you left off and see the result. They do not reach Convium unless you request the full report.
- Full report request. Your name, your firm’s name, your email and your WhatsApp number, the assessment answers, the result and the date and time of your authorization. These four details are a condition for receiving the report: without them, Convium has no way to send it or to set up the conversation about it (art. 9, § 3). Your rights are in section 8.
- What the firm publishes. To prepare the report and the conversation, Convium may look at what the firm publishes so that clients can find it, such as its website, its Instagram and its Google Business Profile. It uses only professional, public content related to the steps of the assessment, and what it observes goes into the report.
- Conversations on WhatsApp or by email. If you contact Convium on WhatsApp or write to contato@convium.com.br, Convium receives your message and your number or email address.
- Browsing. The website does not use cookies. Cloudflare, which hosts the website, records technical access data, such as IP address, date and time, for security. To count visits, Convium uses Cloudflare Web Analytics, which does not use cookies and does not identify visitors.
3. What the data is used for
- Sending the full report to your email.
- Talking to you about the report, by email or WhatsApp, and setting up a 30-minute conversation, if you want one.
- Preparing the diagnosis conversation and a proposal, when you ask for them.
- Producing anonymous averages about architecture firms, from a copy of the answers without name or contact details (section 5).
- Replying to people who get in touch.
Convium does not sell or rent personal data and does not send third-party advertising.
4. Legal bases
- Consent, to send the report and to talk to you about it (art. 7, I). You give it by checking the box in the request and can withdraw it at any time, through contato@convium.com.br (art. 8, § 5).
- Preliminary procedures related to a contract, at your request, for the diagnosis conversation and the proposal (art. 7, V).
- Legitimate interest, for the anonymous averages, for looking at what the firm publishes when preparing the report and for replying to people who get in touch (art. 7, IX). Looking at what the firm publishes respects the reason why the firm made that information public, to be found by clients (art. 7, § 3). Everything uses only what is necessary, and you can object through the same email.
5. Anonymous averages from the assessment
When you request the report, a copy of the answers is stored separately from your contact details, without name, email, WhatsApp number, firm name, IP address or day and time (only month and year), and with typed numbers replaced by ranges. It helps Convium understand what happens at architecture firms and improve the assessment and its services. While your contact details are stored, this copy receives the same protection; once the contact details are deleted, it becomes anonymous (art. 12). Convium only shows averages based on 30 assessments or more, without any breakdown that could identify a firm.
6. Who the data is shared with and where it is kept
Only with providers that operate the technology on Convium’s behalf, under contract and solely for the purposes in section 3:
- Cloudflare, which hosts the website and receives the report request. The database where the request is stored is in the European Union, which Brazil’s data protection authority (ANPD) recognizes as providing an adequate level of protection (CD/ANPD Resolution No. 32/2026; art. 33, I).
- Convium’s email service (Zoho Mail; after the planned change, Google Workspace), through which the report is sent and the conversation takes place.
- WhatsApp (Meta), if the conversation happens there.
The email service and WhatsApp store messages on servers outside Brazil, mainly in the United States. This transfer happens because you asked for the report and the conversation through these channels, and you are informed of it before the request (art. 33, VIII and IX).
7. How long the data is kept
The contact details of people who requested the report and did not become clients are kept for up to 12 months after the last conversation and then deleted; the copy of the answers without name remains, anonymous. Client data is kept for the duration of the contract and for as long as the law requires. Technical access records stay with Cloudflare for its own retention period.
8. Your rights
You can ask for confirmation that Convium processes your data, access to it, correction, anonymization, blocking or deletion, portability, information about who it was shared with, withdrawal of consent and objection to the averages (art. 18). Requests go to contato@convium.com.br and are answered within 15 days. You can also file a complaint with Brazil’s National Data Protection Authority (ANPD).
9. Data of the clients of the firms Convium serves
When Convium implements CroquiFlow™ at a firm, the data of that firm’s clients is processed on the firm’s behalf, as the controller, and only for the firm’s own client service. The rules are in the contract for each implementation.
10. Security
The assessment database can only be accessed through Convium’s Cloudflare account, protected by two-step verification, and the website’s logs do not store the content of requests. Convium uses technical and administrative measures to protect data against unauthorized access, loss and misuse, requires the same from its providers and, if there is a security incident with relevant risk, notifies the ANPD and the people affected, as the law requires.
11. Changes to this policy
When this policy changes, the new version appears on this page with the date at the top.