Privacy Policy

Effective as of: 12/06/2026|Version 1.2

This Privacy Policy explains how FXO Serviços em Informática Ltda. ("FXO", "we") collects, uses, shares and protects personal data in connection with the Wi-Fi.now platform and our websites (together, the "Service"). It incorporates by reference the Website Terms of Use, the Platform Terms of Use and, with respect to data processed on behalf of customers, the Data Processing Agreement (DPA). In case of divergence on personal data matters, this Policy prevails, and in the Controller-Processor relationship, the DPA prevails.

1.Two roles: data we control and data we process

We process personal data in two distinct capacities, and this difference defines who is responsible for what:

Data we control. Information about Administrators (customers who operate the platform) and visitors to our websites is processed by FXO as Controller (art. 5, VI, of the LGPD), for our own purposes: providing the Service, billing, support, ensuring security and communicating with you. This Policy governs that processing.

Data we process for our customers. When an Administrator uses the Service to offer Wi-Fi to its Visitors, the Administrator is the Controller of the Visitors' personal data, as it decides the purposes and means of processing, and FXO acts exclusively as Processor (art. 5, VII, of the LGPD), processing that data on the Administrator's behalf, in accordance with its instructions and the DPA. If you are a Visitor of a Wi-Fi network, the Controller of your data is the establishment operating the network; direct your requests to it. We will provide the establishment with the necessary support, as Processor, without prejudice to the responsibilities that the law directly attributes to FXO in that capacity.

2.What information we collect

Information you provide. When you sign up, contract our services, or contact us: name, email, password, establishment name, network equipment model, billing and contact details, and the content of your communications with us.

Information collected automatically. When you access the Service or our websites: IP address, device and browser information, connection data, date and time of access, pages visited and equivalent logs, including through cookies and similar technologies (Section 4).

Information from third parties. We may receive information from service providers, partners and public sources, combining it with information we already have, to operate and improve the Service and our communications.

Visitor data processed for Administrators. Through the captive portal, and on the Administrator's behalf, the Service processes the minimum necessary to authenticate Visitors and comply with legal obligations: authentication identifiers (phone number, or basic OAuth profile data: account identifier, name and email), consent records and session records (accounting: assigned IP, MAC address, start and end, duration). Collection is minimal by design.

What we never do: we do not require or store Visitor passwords; we do not log browsing history, visited websites, URLs or consumed content; we do not use Visitor data for behavioral marketing, profiling or personas; and we do not sell personal data.

3.How we use information and under what legal bases

We use the data we control for the purposes below, each supported by a legal basis under art. 7 of the LGPD:

PurposeLegal basis (LGPD, art. 7)
Creating and managing accounts; providing, operating and improving the Service; supportPerformance of a contract or preliminary procedures (item V)
Billing, accounting, auditingPerformance of a contract (V) and compliance with a legal obligation (II)
Service security, fraud and incident preventionLegitimate interest (IX), balanced against your rights, and compliance with a legal obligation (II)
Operational and transactional messages (registration, security, billing)Performance of a contract (V)
Marketing communications to AdministratorsLegitimate interest (IX), with guaranteed opt-out (Section 10), or consent (I), as applicable
Production of aggregated and anonymized dataLegitimate interest (IX); irreversibly anonymized data ceases to be personal data
Compliance with legal obligations and exercise of rights in proceedingsCompliance with a legal obligation (II) and regular exercise of rights (VI)

Visitor data is processed exclusively to provide the Service to the Administrator and to comply with legal obligations, under the legal basis adopted by the Administrator as Controller, in accordance with the DPA. We do not make solely automated decisions that produce legal effects on data subjects.

4.Cookies and tracking technologies

We use cookies and similar technologies to operate our websites, remember preferences, measure usage and improve performance. Non-essential cookies are used only with your consent, when required, manageable through the site's banner and your browser settings, including to refuse or delete them. Blocking certain cookies may affect functionality. The captive portal shown to Visitors does not use advertising cookies.

5.Who we share with

We do not sell personal data. We may share personal data with: (i) service providers (hosting, payment processing, message delivery, including SMS and WhatsApp gateways); (ii) companies within our corporate group, for the purposes of this Policy; (iii) authorities and third parties, when disclosure is required by law, court order or request from a competent authority, strictly to the extent of the order received, or when necessary to investigate fraud, protect rights and safety, or enforce our contracts; and (iv) other recipients, with your authorization.

OAuth identity providers (Google, LinkedIn, Microsoft) and telecom carriers act as independent data processing agents in the direct relationship they maintain with you, under their own terms and policies.

6.International transfers and data residency

The default residency of Visitor data is Brazil, and the Service can be configured, on plans offering this feature, so that Visitor data does not leave the chosen region. When personal data is transferred to another country, for example to a service provider, we will adopt safeguards compatible with the regime of arts. 33 et seq. of the LGPD and with current ANPD regulations, including, where applicable, standard contractual clauses recognized by it.

7.Retention

We retain personal data only for as long as necessary for the purposes of this Policy, unless a longer period is required or permitted by law:

CategoryPeriod
Visitor session records (accounting)12 months from the end of each session, in line with the retention duties of the Marco Civil da Internet, when applicable to the Controller, and with the regular exercise of rights in judicial, administrative or arbitration proceedings (LGPD, art. 7, VI); thereafter, automatic and permanent purge, in accordance with the DPA
Visitor consent recordsFor as long as necessary to evidence the processing and for the regular exercise of rights
Administrator registration and financial dataFor the duration of the contractual relationship and for the applicable legal, regulatory and statute-of-limitations periods
Browsing data on our websites and cookiesFor the periods indicated in the cookie banner, depending on the category
Backup copies (encrypted)Its own overwrite cycle, detailed in the DPA, not exceeding 90 days after deletion from the active database

When data is no longer necessary, it is permanently deleted or irreversibly anonymized.

8.Security

We adopt technical and administrative safeguards consistent with the state of the art, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrators, logical segregation per customer, monitoring and periodic testing. No transmission or storage method is completely secure; the security of your account also depends on the confidentiality of your credentials. Security incidents that could pose a relevant risk or harm will be communicated in accordance with the LGPD, ANPD regulations and, regarding processed data, the DPA.

9.Your rights and how to exercise them

Under art. 18 of the LGPD, you may request: confirmation of the existence of processing; access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary, excessive data or data processed in non-compliance; portability, subject to applicable regulations; information on disclosures made; information on the possibility of not consenting and its consequences; withdrawal of consent; and review of decisions made solely on the basis of automated processing, where they exist. You may also file a complaint with the ANPD.

How to exercise them: send your request to the Data Protection Officer (Section 12). For your protection, we may request information confirming your identity before fulfilling the request; we will respond within the periods set by law and ANPD regulations. If you are a Visitor of a network operated by one of our customers, direct your request to the establishment operating the network, the Controller of your data; we will provide it with the necessary support, as Processor, in accordance with the DPA.

10.Marketing communications

Operational and transactional messages (registration, security, billing) are necessary for the provision of the Service and cannot be opted out of. Other communications, such as news and materials, can be cancelled at any time via the link included in the message itself or through the channel in Section 12. We do not send marketing to Visitors of our customers' networks.

11.Children and adolescents

The Service is intended for individuals over 18 years of age and for legal entities, and is not directed at children; we do not knowingly collect data from children. The texts displayed on each establishment's captive portal are defined by the Administrator, who is responsible for observing art. 14 of the LGPD when its audience includes children and adolescents.

12.Data Protection Officer and contact

FXO's Data Protection Officer (DPO) can be contacted at [email protected]. We will respond to communications within the legal and regulatory deadlines.

13.Changes to this Policy

We may update this Policy by publishing the new version with its effective date and maintaining a version history. Material changes will be communicated prominently and with at least 30 (thirty) days' notice; within that period, an Administrator who does not agree with the new version may terminate the contract without penalty, subject to obligations already accrued. This Policy may be made available in other languages as a courtesy; in the event of a discrepancy between versions, the Portuguese-language version shall prevail for all purposes.