Privacy Policy

Last updated · April 27, 2026 · v2.1

1. Who we are (data controller)

FM Solutions & Consulting USA LLC (“FM Solutions”, “we”) is a Limited Liability Company organized and registered in the state of Florida, United States of America, under:

  • Document Number: L25000331929
  • EIN (Federal Employer Identification Number): 61-2276626
  • Principal address: 2295 S. Hiawassee Rd #104, Orlando, FL 32835, USA
  • Date of formation: July 18, 2025
  • Status: Active

For the purposes of the Brazilian LGPD (Law No. 13,709/2018), we act as controller of the personal data collected through fmsolutions.ai and the services operated by FM. For the purposes of the GDPR (EU Reg. 2016/679), we act as data controller with respect to data subjects in the European Union, EEA and the United Kingdom.

When solutions operate under delegation from a B2B client (e.g. clinics using B2B tools), we act as the client’s processor, under a specific Data Processing Agreement (DPA).

Data Protection Officer (DPO) — reachable at [email protected]. The DPO receives and responds to all data subject requests within the legal deadline.

2. Data we collect

2.1 Data you provide directly

  • Identification: name, email, tax ID (CNPJ or international equivalent), phone number, job title.
  • Company / operation: legal name, size, industry, address.
  • Communication: messages via contact form, support chat and WhatsApp.

2.2 Data generated by usage

  • Platform usage: pages visited, features used, AI call metadata (credits consumed, tool executed, response time).
  • Access and audit logs: IP, user-agent, date/time, actions performed. Retained for the period set by art. 15 of the Brazilian Internet Civil Framework (Marco Civil da Internet).
  • Cookies and similar technologies: see our cookie policy.

2.3 Payment data

Card data is collected, processed and stored exclusively by the Stripe gateway. FM Solutions receives only the subscription identifier, status, date and amount. We have no access to card numbers, CVV or expiration dates.

2.4 Content submitted to AI tools

Messages, documents and uploads submitted to our tools (LeadAPI, Compliance Analyzer, Automations, FM Workplace) are processed by the model providers (Anthropic, OpenAI, Google) under DPA contracts with clauses covering:

  • No training: data sent via API is NOT used to train models (declared default of all three providers)
  • Limited retention: 30 days for abuse monitoring (default); zero-retention opt-in available on request for highly confidential use cases

2.5 Sensitive personal data (LGPD art. 5 II + 11; GDPR art. 9)

FM Solutions does not process sensitive data by design (health, biometric, religious, etc.) in its current tools (LeadAPI, Compliance Analyzer, Automations, FM Workplace). Should we launch products involving sensitive data in the future, we will apply:

  • A specific legal basis (explicit consent or an applicable hypothesis under art. 11 LGPD / art. 9 GDPR)
  • Specific contracts (HIPAA BAA, etc.) where applicable
  • A Data Protection Impact Assessment (RIPD/DPIA) before launch
  • An update to this policy with 30 days’ notice

If you voluntarily include sensitive data in any tool (e.g. describing a health condition in a WhatsApp message via LeadAPI), it will be handled with the same technical protection standard as everything else, but you acknowledge that such inclusion is optional and not requested by us.

3. Legal bases for processing

We process your data based on one of the hypotheses of art. 7 (ordinary data) and art. 11 (sensitive data) of the LGPD, and art. 6 of the GDPR. The bases we actually rely on today:

  • Performance of a contract (LGPD art. 7 V; GDPR art. 6(1)(b)) — to deliver the contracted service, process payments via Stripe and send transactional communications.
  • Compliance with a legal obligation (LGPD II; GDPR (1)(c)) — tax, accounting, regulatory and data protection obligations.
  • Legitimate interest (LGPD IX; GDPR (1)(f)) — information security, fraud prevention, abuse monitoring, transactional communication, product improvements. Always with a documented legitimate interest assessment.
  • Consent (LGPD I; GDPR (1)(a)) — newsletter, non-essential cookies, direct marketing. You may withdraw at any time without affecting the core service.
  • Protection of health (LGPD art. 11 II f) — reserved for future health products, where applicable. Not currently in use.

4. Automated decisions and artificial intelligence

FM Solutions is an AI platform. Some decisions in our tools are made automatically by models (e.g. lead triage, prescription drafting, contract analysis). Under art. 20 of the LGPD and art. 22 of the GDPR, you have the right to:

  • Know that a decision was automated and the general logic behind it
  • Human review at any time, upon request to the DPO
  • Not be subject to a solely automated decision producing legal or similarly significant effects

The automated decisions executed today (billing, credit quotas, model routing) are operational and produce no legal effects on you. In every case where a tool generates content that will be used in a legal or financial decision (Compliance contract analysis, billing Automations, etc.), the content is reviewable by a human professional before producing effects.

5. How we use your data

  • Operating the contracted service (authentication, billing, service catalog)
  • Transactional communication (invoices, critical updates, support)
  • Marketing and communications (based on consent or legitimate interest; opt-out in every email)
  • Regulatory compliance (tax, LGPD, GDPR, audit trail)
  • Aggregate usage analytics (only with explicit consent through the cookie banner)
  • Product improvement and security (abuse monitoring, fraud prevention)

6. Sharing

We do not sell your data. We share it only with the processors below, all under a valid DPA (list maintained in docs/legal/dpa/ and updated when it changes):

  • Supabase (Supabase Inc., USA) — database, authentication, edge functions
  • Vercel (Vercel Inc., USA) — site hosting and serverless functions
  • Stripe (Stripe LLC, USA / Stripe Payments Europe, Ireland) — payment processing. PCI Level 1 compliant.
  • Resend (Plus Five Five Inc., USA) — transactional email delivery
  • Anthropic (USA) — Claude model (zero-training and HIPAA-eligible where applicable)
  • OpenAI (USA) — GPT models (zero-training default since Mar 1, 2023)
  • Google Cloud / Gemini API (Google LLC, USA) — Gemini model
  • Cloudflare (USA) — DNS, DDoS mitigation, anti-bot. DPA v6.4.

Sub-processors: we maintain an up-to-date list and notify material changes by email with 30 days’ notice. In case of a legitimate client objection, we offer an alternative or termination without penalty.

We share data with public authorities only when legally required (court order or formal request from a competent authority). We pursue legal remedies before disclosing and notify the data subject when legally permitted.

7. International transfers

FM Solutions & Consulting USA LLC is registered in the state of Florida (USA), headquartered in Orlando. Our processors also process data on servers in the USA, EU and other jurisdictions. We ensure the safeguards required by the LGPD (art. 33) and GDPR (Chapter V):

  • EU Standard Contractual Clauses (SCCs) 2021/914 — signed with Vercel, Supabase, Stripe, Resend, Anthropic, OpenAI, Google and Cloudflare. Module 2 (Controller→Processor) for EU/EEA data subjects.
  • UK International Data Transfer Addendum (IDTA) — for data subjects in the United Kingdom.
  • EU-U.S. Data Privacy Framework (DPF) — several certified processors (Resend, Cloudflare, OpenAI, Vercel, Stripe).
  • Equivalent clauses for the LGPD — contracts with processors include the minimum clauses required by art. 33 of the LGPD.

8. Your rights as a data subject

The LGPD (art. 18) and the GDPR (arts. 15–22) grant you rights over your personal data. You can exercise all of them at any time, free of charge:

  1. Confirmation of processing (LGPD I) — knowing whether we process data about you
  2. Access (LGPD II; GDPR art. 15) — receiving a copy in a readable format
  3. Rectification (LGPD III; GDPR art. 16) — updating incomplete or inaccurate data
  4. Anonymization, blocking or deletion of unnecessary, excessive or non-compliant data (LGPD IV)
  5. Portability (LGPD V; GDPR art. 20) — structured, machine-readable format (JSON/CSV)
  6. Deletion of data processed on the basis of consent (LGPD VI; GDPR art. 17 — “right to be forgotten”)
  7. Information about sharing (LGPD VII) — knowing which entities we share with
  8. Information about refusing consent (LGPD VIII) — knowing the consequences of denying consent
  9. Withdrawal of consent (LGPD IX; GDPR art. 7(3))
  10. Objection to processing based on legitimate interest (LGPD § 2; GDPR art. 21)
  11. Review of automated decisions (LGPD art. 20; GDPR art. 22)

To exercise your rights: dedicated page or email [email protected]. We respond within 15 calendar days (LGPD) or 30 days (GDPR), extendable by an additional 60 days in complex cases with justification.

9. Complaints to a supervisory authority

If your request is not handled adequately, you can complain directly to the competent authority:

10. Privacy by design and by default

We apply the principles of GDPR art. 25 and LGPD art. 46 in all development:

  • Minimization: we collect only what is necessary; optional fields are truly optional
  • Protection by default: the most restrictive privacy settings are the default; non-essential cookies stay disabled until explicit consent
  • Impact assessment (RIPD/DPIA): we conduct an impact assessment before launching features that process sensitive or large-scale data. Documentation available to authorities upon request.
  • Pseudonymization: we use opaque identifiers whenever possible
  • Segregation: RLS (Row Level Security) ensures tenant isolation in the database

11. Security

  • Encryption in transit: TLS 1.3 mandatory
  • Encryption at rest: AES-256 (Supabase) and AES-XTS-128 (Cloudflare)
  • Access: full audit trail, optional multi-factor authentication, zero-trust model
  • Backups: automated daily, 30-day retention
  • Least privilege principle applied to internal access
  • Penetration testing regularly by third parties + bug bounty
  • Processor certifications: SOC 2 Type 2 (all), ISO 27001 (Cloudflare, Resend), PCI Level 1 (Stripe, Cloudflare)

12. Security incident notification

In case of an incident that may cause relevant risk or damage to data subjects, we notify:

  • ANPD: within 2 business days (LGPD art. 48; Resolution CD/ANPD No. 15/2024)
  • European data protection authority: within 72 hours (GDPR art. 33)
  • Affected data subjects: without undue delay when the incident poses a high risk to their rights (GDPR art. 34; LGPD art. 48 § 2)

Notifications include: nature of the incident, data involved, number of affected data subjects, measures taken, DPO contact.

13. Data retention

We keep your data while your account is active, plus the time required by law. Retention table:

  • Active account data: for the duration of the contractual relationship
  • Tax and accounting records: 5 years (Brazilian Decree 3,000/99 + US IRS — whichever is longer)
  • Detailed technical logs: 6 months (Marco Civil da Internet, art. 15)
  • Access audit logs: 12 months (aligned with the Cloudflare DPA)
  • Prospecting data without conversion: 12 months
  • AI call logs: 30 days for abuse monitoring (providers’ default)
  • Deletion requests: executed within 15 calendar days (LGPD) or 30 days (GDPR), except what we are legally required to retain

14. Children and adolescents

FM Solutions is a B2B platform intended for professionals and companies. We do not intentionally collect data from anyone under 18. If we identify inadvertent collection of a child’s or adolescent’s data, we delete it immediately.

Parents or guardians who identify data of minors may request deletion through the channels above. For GDPR purposes (art. 8), the age of consent varies by member state; we apply the most protective rule (16 years) by default.

FM Solutions does not serve minors directly. If our B2B tools are used by clients in contexts involving minors’ data, it is the client’s (controller’s) responsibility to obtain consent from legal guardians and comply with the applicable obligations.

15. Cookies

We detail every cookie in use (category, provider, purpose, duration) in our cookie policy. You control non-essential cookies through the consent banner or your browser settings.

16. Data Protection Officer (DPO)

For formal matters, reports, exercise of rights or contact with authorities: [email protected].

We keep a written record of processing activities (GDPR art. 30; LGPD art. 37) for all processing operations, available to authorities upon request.

17. Updates to this policy

Material changes will be communicated by email at least 30 days in advance. Non-material changes (wording fixes, links, processor version updates) take effect immediately. The current version is always available at this URL with explicit versioning (v2.1, etc.) and dates.

History of previous versions available upon request to the DPO.