Breccia

Legal · Privacy

Privacy Policy

This Policy transparently explains how BRECCIA handles personal data and information related to its website, platform, and integrations such as Google Drive.

Last updated
September 5, 2026

1. Introduction

BRECCIA is a B2B applied intelligence platform for the construction industry. This Privacy Policy describes the categories of information that may be processed, the purposes of processing, the parties with whom information may be shared, and the choices and rights available to users.

By using the institutional website, creating or using an account, providing documents, or connecting an integration, the user acknowledges the processing described in this Policy. When an organization contracts BRECCIA and manages access for its professionals, that organization's own rules may also apply.

2. Who BRECCIA is and who controls the data

BRECCIA develops and provides software that organizes construction information and makes it useful for search, analysis, and artificial intelligence features.

Depending on the context, BRECCIA may act as a controller for website, commercial relationship, and account administration data, or as a processor on behalf of a customer organization when handling content added or connected to that organization's workspace. In the latter case, the customer organization may determine the purposes and essential means of processing.

TODO: preencher antes da publicação. Add the legal name, Brazilian company registration number (CNPJ), and address of the entity responsible for BRECCIA.

3. Scope of this Policy

This Policy applies to BRECCIA's public website, commercial contacts, platform, and user-facing features, including integrations with external services. It does not replace third-party policies or the privacy obligations undertaken directly by a customer organization.

4. Categories of data we process

Depending on how BRECCIA is used, we may process:

  • identity, contact, professional profile, and organization affiliation data;
  • account, authentication, permission, and preference data;
  • work documents and content, including contracts, proposals, designs, budgets, progress claims, spreadsheets, and technical files;
  • information received from integrations authorized by the user or their organization;
  • contact-form messages and commercial relationship information;
  • technical data, activity logs, device and browser information, IP address, and security events; and
  • cookies and similar technologies, as described in this Policy.

5. Data provided directly by the user

We may receive data when a user completes a form, requests contact, creates or updates an account, participates in a demonstration, sends a message, or makes files and information available through the platform. Users must only provide data they are authorized to use and share.

Documents may contain personal data concerning employees, customers, suppliers, and other third parties. The organization responsible for providing this information must follow applicable law and its own policies.

6. Account and authentication data

To create, protect, and administer access, BRECCIA may process information such as name, work email, organization, role, account identifiers, protected credentials, authentication methods, permissions, and access records. When sign-in uses an external provider, we receive the data covered by the authorization and needed to authenticate or link the account.

7. Data from integrations

The platform may allow users to voluntarily connect external services. By authorizing an integration, the user allows BRECCIA to access and process information needed to perform the requested features, according to the permissions displayed by the relevant service.

Availability, operation, and rules for integrations also depend on external providers. A user may choose not to connect an integration, although related features may then be unavailable.

8. Data from Google APIs

When a user connects their Google Account or Google Drive to BRECCIA, the platform may access information and files covered by the permissions granted by that user. This data is used to provide user-requested features, such as finding information, organizing content, consulting documents, and using them as context within platform features.

Access occurs only after express authorization through Google's interface. BRECCIA uses and transfers data received from Google APIs only as needed to provide or improve visible, user-requested features, maintain security, comply with law, and operate related services.

BRECCIA's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

BRECCIA does not claim to be certified, approved, sponsored, or verified by Google. Google and Google Drive are trademarks and services of their respective owners.

Google API Services User Data Policy

9. Google Drive

The Google Drive integration may allow authorized documents to be found, organized, consulted, and used as context in BRECCIA. Relevant categories may include files and associated information, such as names, identifiers, folder structure, and other metadata covered by the granted permissions.

The actual extent of access is the extent shown to the user on Google's consent screen. BRECCIA does not become the owner of connected files, and connecting the service does not transfer intellectual property rights in that content.

10. How we use data

We use information to provide, personalize, maintain, and protect the website and platform; authenticate users; administer accounts and permissions; organize and retrieve documents; operate integrations; respond to requests; provide support; communicate material changes; prevent abuse and fraud; comply with legal obligations; and develop and improve features consistently with the purposes described.

Data connected by an organization is used to provide services to that organization and its authorized users, subject to applicable settings and permissions.

11. Use of information in artificial intelligence features

Information and documents provided or connected by a user may be processed to provide search, summarization, organization, analysis, comparison, and contextual answer generation. This may include documents from Google Drive when the integration has been authorized.

This processing is performed to provide features to the user or their organization and must remain tied to BRECCIA's functionality. We may use technology providers needed to operate these features, subject to appropriate protection and confidentiality obligations.

Artificial intelligence results may contain errors or omissions. Information relevant to costs, contracts, standards, designs, safety, and construction decisions must be validated by responsible professionals.

TODO: confirmar com responsável técnico/jurídico antes da publicação the policy applicable to the use of customer data for training or improving models.

13. Sharing with service providers

We may share data with providers supporting hosting, storage, authentication, email communication, scheduling, customer support, security, observability, integrations, and artificial intelligence functionality. Sharing is limited to what is needed to provide the contracted services and is subject to data protection obligations.

We may also share information when required by law or a competent authority, to protect rights and safety, as part of a legitimate corporate transaction, or as instructed by a customer organization. We do not grant third parties ownership rights in user documents.

Information received from Google APIs is not used for personalized advertising, data sales, or advertising profiles. Its use and transfer remain limited to purposes permitted by the Google API Services User Data Policy and Limited Use.

14. Security

BRECCIA adopts reasonable technical and organizational measures to protect information from unauthorized access, loss, alteration, or improper disclosure. These measures may include access controls, authentication, permission management, credential protection, monitoring, and internal procedures appropriate to the risk.

No system is completely secure. Users and organizations must also protect their credentials, manage permissions correctly, and promptly report suspected misuse.

15. Retention

Data is retained for as long as needed to provide the services, while an account or integration remains active, in accordance with customer organization instructions, and as needed to comply with legal obligations, protect rights, prevent fraud, and resolve disputes, as applicable.

After the relationship ends or a valid request is received, certain data may be deleted or anonymized. Some records may be kept longer where required by law, security needs, abuse prevention, exercise of rights, or reasonable technical limitations in backups.

16. Data deletion and account closure

A user may request deletion of data associated with their account or closure of the account by emailing contato@breccia.ai. Requests will be verified and handled under applicable law, the contract, and instructions from the organization responsible for the workspace.

Deletion may not be immediate or complete where retention is required to meet a legal obligation, preserve evidence, exercise rights, protect security, or follow legitimate customer organization instructions.

TODO: confirmar com responsável técnico/jurídico antes da publicação whether the application offers a self-service path and add the exact instructions here.

17. Disconnecting and revoking integrations

A user or authorized administrator may disconnect an integration through controls available in the platform, where offered, or request assistance at contato@breccia.ai. Disconnecting prevents new access under that authorization but does not automatically delete data already processed and retained consistently with this Policy.

18. Revoking Google Account access

A user may revoke BRECCIA's access at any time through the security and third-party connection settings in their own Google Account. Following revocation, BRECCIA will no longer make new accesses using that authorization.

To also request deletion of integration-related data under BRECCIA's responsibility, email contato@breccia.ai. Revoking access through Google and requesting deletion from BRECCIA are separate actions and may be used together.

19. Cookies and similar technologies

The website and platform may use cookies or similar technologies needed for operation, security, preferences, authentication, and performance measurement. Third-party features opened at the user's choice, such as scheduling, may also use their own technologies under their respective policies.

Users can control cookies through their browser, but blocking strictly necessary items may impair some functionality.

TODO: confirmar com responsável técnico/jurídico antes da publicação the final inventory of cookies and measurement tools used in production.

20. Technical and security logs

We may record access and usage events, IP address, browser, device, timestamps, administrative actions, errors, and security signals. These records help operate the service, investigate failures, prevent abuse, respond to incidents, and preserve platform integrity.

21. International transfers

Some technology providers may process data in other countries. Where an international transfer occurs, BRECCIA will seek to use mechanisms and safeguards consistent with applicable law, considering the nature of processing and the customer organization's role.

22. Data subject rights

Under applicable law and according to BRECCIA's role in processing, a data subject may request confirmation of processing, access, correction, anonymization, restriction or deletion of unnecessary or unlawfully processed data, portability where applicable, information about sharing, and review of applicable decisions.

These rights are not absolute and may depend on identity verification, the customer organization's authority, legal obligations, and other statutory limits. Where BRECCIA acts as a processor, the request may be referred to the controller organization.

23. Brazilian General Data Protection Law (LGPD)

BRECCIA processes personal data subject to Brazil's General Data Protection Law — Law No. 13,709/2018 (LGPD) — and observes principles including purpose, adequacy, necessity, transparency, security, and accountability.

Where processing relies on consent, the data subject may withdraw it under the LGPD. To exercise rights or ask questions, email contato@breccia.ai and provide enough information to identify the relevant relationship without sending excessive personal documents in the first message.

TODO: preencher antes da publicação. Add the privacy officer's identity and contact channel, if applicable.

24. Children and adolescents

BRECCIA is intended for professional business use and is not directed to children. If we identify improper processing of data concerning a child or adolescent, we will take steps appropriate to the law and context to assess and address the situation.

25. Changes to this Policy

We may update this Policy to reflect changes to the platform, law, or processing practices. The current version will be published on this page with its update date. If a change is material, we may also notify users or organizations through appropriate additional means.

26. Contact

Privacy questions, rights requests, deletion requests, and integration communications may be sent to contato@breccia.ai.

This Policy was last updated on September 5, 2026.

TODO: preencher antes da publicação. Confirm the legal name, CNPJ, address, and privacy officer details, if applicable.