Legal & LGPD

CoguPlanner legal documentation

Terms, policies, and contracts that govern the use of CoguPlanner as SaaS. This content is a draft reviewable by a lawyer and does not constitute legal advice.

01 · SaaS terms and policies

Terms of use

These Terms of Use ("Terms") govern access to and use of the CoguPlanner platform ("Platform"), operated by the company responsible for CoguPlanner ("CoguPlanner", "we", or "our"). By creating an account or using the Platform, you ("User", "you") agree in full with these Terms.

The Platform is software as a service (SaaS) that offers visual planning tools, mushroom cultivation organization, production tracking, and sales management. The Platform is intended for growers, cultivators, mentors, and other professionals in the mushroom cultivation industry.

1. Acceptance of Terms. By registering, clicking "I accept", or using the Platform in any way, you declare that you have read, understood, and accepted these Terms and the Privacy Policy. If you do not agree, do not use the Platform.

2. Definition of Service. CoguPlanner provides digital tools for registering blocks, shelves, species, tasks, log batches, production calendar, cultivation guide, social network (CoguRede), mentorships, and workspace management. Feature availability varies according to the contracted plan.

3. User Obligations. You agree to: (a) provide true and up-to-date information during registration; (b) maintain the confidentiality of your access credentials; (c) not use the Platform for unlawful, fraudulent activities or those that violate third-party rights; (d) not attempt to access restricted areas, perform reverse engineering, or bulk extract data without authorization; (e) be responsible for all content you enter into the Platform.

4. Acceptable Use. It is prohibited to: (a) cultivate illegal or regulated species without due authorization; (b) publish offensive, defamatory content that violates Brazilian law; (c) use bots or automated scripts without prior authorization; (d) share your account with third parties, except in cases provided for collaborative workspaces.

5. Intellectual Property. The Platform, its code, design, trademarks, logos, and content produced by CoguPlanner are protected by copyright and other intellectual property laws. Data entered by the User (cultivation records, blocks, species, etc.) remains the property of the User, under the terms of the Privacy Policy.

6. Suspension and Termination. CoguPlanner may suspend or terminate accounts that violate these Terms, upon prior notice, except in cases of serious violation or urgency. You may terminate your account at any time through the Platform settings. After termination, your data will be handled in accordance with the Retention and Deletion Policy.

7. Limitation of Liability. The Platform is provided "as is". To the extent permitted by law, CoguPlanner is not liable for: (a) cultivation decisions made based on Platform data; (b) production losses due to technical failures, unavailability, or errors; (c) indirect damages, lost profits, or data loss. CoguPlanner's liability is limited to the amount paid by the User in the 12 (twelve) months prior to the event.

8. Changes to Terms. CoguPlanner may modify these Terms at any time, notifying Users by email or through the Platform. Continued use after the change implies acceptance. The current version will always be available on this page with the update date.

9. Applicable Law. These Terms are governed by Brazilian law. The forum of the judicial district of the User's domicile is elected to resolve any disputes.

Privacy policy

This Privacy Policy describes how CoguPlanner collects, uses, shares, and protects Users' personal data, in compliance with the General Data Protection Law (Law No. 13.709/2018, "LGPD").

1. Data Collected. We collect: (a) registration data: name, email, optional phone; (b) production data: records of blocks, species, shelves, tasks, batches, harvests, sales; (c) payment data: billing information processed by payment providers (we do not store card numbers); (d) usage data: IP address, browser type, pages visited, timestamps; (e) workspace data: members, invitations, permissions.

2. Legal Basis. The processing of personal data is based on: (a) consent (Art. 7, I, LGPD) for registration and usage data; (b) contract performance (Art. 7, V, LGPD) for production and payment data; (c) legal obligation (Art. 7, II, LGPD) for tax and accounting data; (d) legitimate interest (Art. 7, IX, LGPD) for usage and security data.

3. Purpose. The data is used for: (a) provision and maintenance of the Platform; (b) payment processing and subscription management; (c) communication about updates, support, and news; (d) Platform improvement, including development of AI features based on aggregated and anonymized data; (e) compliance with legal obligations.

4. Sharing. We do not sell personal data. We may share data with: (a) infrastructure providers (Cloudflare, Neon) acting as operators; (b) payment providers (Stripe) for subscription processing; (c) email providers (Resend) for communication; (d) authorities, when required by law or court order. The list of subprocessors is available in the "Subprocessor registry" section.

5. Data Subject Rights. You may exercise, at any time, the following rights: (a) confirmation of the existence of processing; (b) access to data; (c) correction of incomplete, inaccurate, or outdated data; (d) anonymization, blocking, or erasure of unnecessary or excessive data; (e) data portability; (f) erasure of personal data processed with consent; (g) information about sharing; (h) revocation of consent. To exercise your rights, use the channel described in the "Channel for data subjects" section.

6. Data Protection Officer (DPO). CoguPlanner's Data Protection Officer can be contacted via email at [EMAIL]. The DPO contact is also available in the channel for data subjects.

7. Cookies and Technologies. We use essential cookies for authentication and operation of the Platform, and analytical cookies to understand usage patterns. You can manage your cookie preferences in your browser settings. We do not use third-party advertising cookies.

8. International Transfer. Some infrastructure providers are located outside Brazil (USA and Europe). International data transfer is carried out with adequate safeguards, under Art. 33 of the LGPD, and standard contractual clauses. Details in the "International clauses for foreign suppliers" section.

9. Security. We adopt technical and organizational measures to protect personal data, including: encryption in transit (TLS), encryption at rest for sensitive data, role-based access control, security monitoring, and periodic audits.

10. Retention. Data is retained for the period necessary to fulfill the collection purpose, respecting legal deadlines. Details in the "Retention and deletion control" section.

11. Changes. This Policy may be updated periodically. We will notify Users about significant changes by email or through the Platform. The current version will always be available on this page.

Subscription contract

This Subscription Contract regulates the relationship between CoguPlanner and Users who contract paid plans of the Platform. By subscribing to a plan, you agree to the terms below.

1. Subject. This contract has as its subject the provision of CoguPlanner subscription services, according to the plan chosen by the User, granting access to the features described in the "Plan descriptions" section.

2. Term. The subscription is valid for an indefinite period, with recurring billing according to the chosen frequency (monthly or annual). The term begins at the moment of payment confirmation.

3. Price and Payment. The subscription price is the one in effect on the plans page at the time of contracting. Payment is processed by a third-party payment provider (Stripe). The invoice is generated automatically at the beginning of each billing cycle.

4. Price Adjustment. CoguPlanner may adjust prices annually, based on IPCA or an equivalent index. The adjustment will be communicated with a minimum of 30 (thirty) days' notice. Users with annual subscriptions will have the price maintained until the end of the current cycle.

5. Renewal. Monthly subscriptions are renewed automatically at the end of each cycle. Annual subscriptions are renewed automatically at the end of the 12 (twelve) month period. The renewal will be billed to the registered payment method.

6. Termination. Either party may terminate the contract: (a) by the User: at any time, through the account settings, with effects at the end of the current paid cycle; (b) by CoguPlanner: for just cause, violation of the Terms of Use, or non-payment, upon notice with 15 (fifteen) days' advance notice.

7. Trial Period. CoguPlanner may offer a free trial period, during which the User has access to premium features. At the end of the trial period, the subscription is automatically converted to the paid plan, unless cancelled in advance. There is no charge during the trial period.

8. Downgrade and Upgrade. The User may change their plan at any time. Upgrades take effect immediately, with proportional billing. Downgrades take effect at the end of the current cycle.

Plan descriptions

CoguPlanner offers the following subscription plans. The features and limits of each plan are described below. Current prices are available on the Platform's plans page.

Free plan: intended for users who are just starting out. Includes: (a) up to 10 registered blocks; (b) up to 2 shelves; (c) basic task management; (d) access to the cultivation guide; (e) access to CoguRede (read-only). Does not include: log yard, advanced reports, mentorships, or collaborative workspaces.

Grower plan: intended for small producers. Includes: (a) up to 100 blocks; (b) unlimited shelves; (c) log yard; (d) full production calendar; (e) basic reports; (f) buyer management; (g) CoguRede with posting; (h) 1 workspace. Does not include: mentorships or additional workspaces.

Producer plan: intended for established producers. Includes everything in the Grower plan, plus: (a) unlimited blocks; (b) advanced reports and analytics; (c) up to 3 workspaces; (d) access to mentorships (as mentee); (e) data export in CSV/JSON; (f) priority support.

Mentor plan: intended for mentors and consultants in the industry. Includes everything in the Producer plan, plus: (a) unlimited workspaces; (b) ability to create mentorships; (c) workspace sharing with mentees; (d) mentee dashboard; (e) early access to new features.

Trial Period: the Grower plan offers 14 (fourteen) days of free trial, with no credit card required. At the end of the period, the account reverts to the Free plan, unless upgraded in advance.

Usage Limits: the limits of each plan (blocks, shelves, workspaces) are enforced automatically by the Platform. Upon reaching the limit, the User is notified and may upgrade to continue registering new items.

Cancellation policy

This policy describes the conditions and procedures for cancelling CoguPlanner subscriptions.

1. How to Cancel. Cancellation can be done at any time through the account settings on the Platform, in the "Subscription" section. Cancellation is effective immediately, but access to the paid plan remains active until the end of the current billing cycle.

2. Deadlines. There is no minimum stay period. The User may cancel at any time, with no penalty or cancellation fee. Cancellation does not require justification.

3. Effects of Cancellation. After cancellation: (a) the subscription is not renewed in the following cycle; (b) the account reverts to the Free plan at the end of the paid cycle; (c) the User's data is kept for 90 (ninety) days and may be reactivated with a new subscription; (d) after 90 days without a subscription, the data may be deleted in accordance with the Retention Policy.

4. Early Cancellation of Annual Subscription. Users with an annual subscription may cancel early. In this case, access remains active until the end of the already paid period. There is no proportional refund for the unused period, except in the cases provided for in the Refund Policy.

5. Cancellation by CoguPlanner. CoguPlanner may cancel subscriptions in the event of: (a) violation of the Terms of Use; (b) non-payment exceeding 15 (fifteen) days; (c) Platform shutdown, with 60 (sixty) days' prior notice. In the event of Platform shutdown, annual subscriptions will receive a proportional refund for the unused period.

6. Confirmation. After cancellation, a confirmation is sent by email. If you do not receive it, contact the support channel.

Refund policy

This policy describes the conditions for requesting a refund for CoguPlanner subscriptions.

1. 7-Day Guarantee. Under the Consumer Protection Code (Art. 49), the User has the right of withdrawal within 7 (seven) calendar days from the initial subscription. In this case, the refund is full, regardless of Platform usage.

2. Refund for Technical Failure. If the Platform is unavailable for more than 48 (forty-eight) consecutive hours due to a failure attributable to CoguPlanner, the User may request a proportional refund for the unavailability period.

3. Refund for Platform Shutdown. In the event of definitive Platform shutdown by CoguPlanner, annual subscriptions will receive a proportional refund for the unused period, calculated from the effective shutdown date.

4. Exceptions. There is no right to a refund in the following cases: (a) monthly subscription after the 7-day period from initial contracting; (b) annual subscription after the 7-day period, except in the cases of items 2 and 3; (c) cancellation due to violation of the Terms of Use; (d) free trial periods (there is no charge to refund).

5. Procedure. To request a refund, the User must contact via email at [EMAIL], providing: (a) account name and email; (b) reason for the request; (c) date of contracting. The refund will be processed within 10 (ten) business days, through the same payment method used at contracting.

6. Chargeback. The chargeback is performed directly by the payment provider (Stripe) on the credit card or account used. The time for the chargeback to appear may vary depending on the card issuer and may take up to 2 (two) billing statements.

02 · Data operations and LGPD

Operator/suboperator contract

This document establishes the conditions of the data processing contract between CoguPlanner (as controller) and its operators and suboperators, in compliance with Art. 39 of the LGPD.

1. Role Definition. CoguPlanner acts as the controller of its Users' personal data. Service providers that process data on behalf of CoguPlanner act as operators. Operators that subcontract third parties must ensure they act as suboperators, with the same obligations.

2. Operator Obligations. The operator agrees to: (a) process personal data exclusively according to CoguPlanner's documented instructions; (b) ensure data confidentiality; (c) adopt technical and organizational security measures; (d) notify CoguPlanner of any security incident immediately; (e) support CoguPlanner in fulfilling data subjects' rights; (f) not use the data for its own purposes; (g) ensure that authorized personnel have a confidentiality commitment.

3. Subcontracting. The operator may subcontract third parties (suboperators) only with prior and express authorization from CoguPlanner. The operator is responsible for ensuring that suboperators comply with the same obligations provided in this contract. The list of authorized suboperators is in the "Subprocessor registry" section.

4. Security Measures. The operator must implement, at minimum: (a) encryption in transit and at rest for sensitive data; (b) role-based access control; (c) access and audit logs; (d) regular backups; (e) incident response plan; (f) annual security review.

5. International Transfer. If the operator is located outside Brazil or transfers data abroad, it must ensure adequate safeguards under Art. 33 of the LGPD, including standard contractual clauses or equivalent certification.

6. Termination. Upon contract termination, the operator must: (a) return or destroy the personal data, according to CoguPlanner's instruction; (b) certify the destruction in writing; (c) keep destruction records for 5 (five) years, as a legal obligation.

7. Audit. CoguPlanner may conduct audits on the operator, with 15 (fifteen) days' prior notice, to verify compliance with this contract. The operator must provide access to facilities and relevant records.

Subprocessor registry

This section lists the subprocessors (operators and suboperators) that process personal data on behalf of CoguPlanner. The list is updated periodically and Users are notified about additions or replacements with 30 (thirty) days' notice.

  • Cloudflare, Inc. — CDN, DNS, and edge computing infrastructure. Location: USA. Purpose: application hosting and delivery.
  • Neon Database — serverless PostgreSQL database provider. Location: USA. Purpose: storage of production and account data.
  • Stripe, Inc. — payment processing. Location: USA. Purpose: subscription billing. Access limited to billing data.
  • Resend, Inc. — transactional email provider. Location: USA. Purpose: sending notification, invitation, and support emails.
  • Better Auth — authentication provider (self-hosted). Location: Brazil (hosted on CoguPlanner's infrastructure). Purpose: session and credential management.

Change Notification. Before adding or replacing a subprocessor, CoguPlanner will notify Users by email with 30 (thirty) days' notice. The User may object to the use of the new subprocessor, this being the only grounds for contract termination without penalty.

Compliance Verification. Each subprocessor is evaluated for: (a) compliance with the LGPD or equivalent legislation; (b) security certifications (ISO 27001, SOC 2, or equivalent); (c) data protection contractual clauses; (d) data location and jurisdiction.

Incident procedure

This procedure defines the steps for responding to security incidents that may compromise personal data, in compliance with Art. 48 of the LGPD.

1. Classification. Incidents are classified into three levels: (a) Low: affects non-sensitive data, with no risk to data subjects (e.g., temporary unavailability); (b) Medium: affects personal data with limited risk (e.g., unauthorized access to registration data); (c) High: affects sensitive data or a large volume of data, with relevant risk to data subjects (e.g., leak of production or payment data).

2. Containment. Immediately after detection: (a) isolate affected systems; (b) revoke compromised accesses; (c) preserve evidence for investigation; (d) activate the incident response team.

3. Notification to ANPD. Medium and High level incidents must be reported to the National Data Protection Authority (ANPD) within 3 (three) business days, under Art. 48 of the LGPD. The notification includes: (a) description of the nature of the affected data; (b) description of the consequences; (c) measures taken; (d) mitigation measures.

4. Communication to Data Subjects. For High level incidents, affected data subjects are notified within 5 (five) business days, by email, informing: (a) the affected data; (b) potential risks; (c) measures taken; (d) recommendations for protection (e.g., password change).

5. Investigation and Report. After containment, an investigation is conducted to identify the root cause. A post-incident report is prepared within 15 (fifteen) days, including: (a) timeline; (b) root cause; (c) affected data; (d) corrective measures; (e) prevention plan.

6. Logging. All incidents, regardless of level, are logged internally with: date, description, classification, actions taken, and outcome. The log is kept for 5 (five) years.

7. Reporting Channel. Users who suspect a security incident must report it immediately via email at [EMAIL]. CoguPlanner investigates all reports within 48 (forty-eight) hours.

Retention and deletion control

This policy defines the retention periods and data deletion procedures in CoguPlanner.

1. Principle. Personal data is retained only for the period necessary to fulfill the collection purpose, respecting applicable legal deadlines. After this period, data is deleted or anonymized.

2. Deadlines by Data Type:

  • Registration data (name, email): kept while the account is active. Upon closure, deleted within 90 days, unless legal obligation.
  • Production data (blocks, shelves, tasks): kept while the account is active. Upon closure, deleted within 90 days.
  • Payment data: transaction metadata kept for 5 years (tax obligation, Art. 46 of the CTN). Card numbers never stored.
  • Usage data (logs, IP): kept for 12 months for security and audit purposes.
  • Workspace data (members, invitations): deleted together with the workspace or when the member is removed.
  • Mentorship data: kept while the mentorship is active. Upon closure, deleted within 90 days.
  • Backups: kept for 30 days. After this period, automatically overwritten.

This policy defines the retention periods and data deletion procedures in CoguPlanner.

1. Principle. Personal data is retained only for the period necessary to fulfill the collection purpose, respecting applicable legal deadlines. After this period, data is deleted or anonymized.

2. Deadlines by Data Type:

3. Automatic Deletion. The Platform performs automatic deletion of expired data periodically. Deletion is permanent and irrecoverable, except for data present in backups within the 30-day period.

Channel for data subjects

CoguPlanner provides a dedicated channel for data subjects to exercise their rights under the LGPD (Art. 18).

1. Exercisable Rights. Through this channel, you may request: (a) confirmation of the processing of your data; (b) a copy of your data; (c) correction of data; (d) anonymization or blocking; (e) portability; (f) erasure; (g) information about sharing; (h) revocation of consent.

2. Contact Methods:

  • Email: [EMAIL] (Data Protection Officer/DPO)
  • Form: available on the Platform, in the "Support > Privacy" section
  • Mail: physical address to be defined after CNPJ registration

CoguPlanner provides a dedicated channel for data subjects to exercise their rights under the LGPD (Art. 18).

1. Exercisable Rights. Through this channel, you may request: (a) confirmation of the processing of your data; (b) a copy of your data; (c) correction of data; (d) anonymization or blocking; (e) portability; (f) erasure; (g) information about sharing; (h) revocation of consent.

2. Contact Methods:

3. Response Time. Requests are answered within 15 (fifteen) calendar days, under Art. 19 of the LGPD. In complex cases, the deadline may be extended, with justification communicated to the data subject.

Account access rules

This section defines the rules for access and security of User accounts in CoguPlanner.

1. Authentication. Access to the Platform is protected by password. CoguPlanner offers: (a) email and password authentication; (b) optional social authentication (Google, GitHub); (c) optional two-factor authentication (2FA), recommended for accounts with collaborative workspaces.

2. Account Holder's Responsibility. The User is responsible for: (a) maintaining the confidentiality of their password; (b) not sharing credentials, except in cases provided for workspaces; (c) immediately notifying CoguPlanner of any unauthorized use; (d) keeping their email up to date for account recovery.

3. Suspected Compromise. In case of suspected compromise: (a) the User should change their password immediately; (b) CoguPlanner may temporarily suspend access for protection; (c) active sessions may be revoked; (d) CoguPlanner investigates the origin of the suspected access.

4. Support Access. CoguPlanner's support team may access the User's account only: (a) upon express request from the User; (b) with the User's consent; (c) for a time limited to resolving the problem; (d) with access logging. Support never asks for passwords.

5. Collaborative Workspaces. In workspaces, the workspace administrator may: (a) invite members; (b) assign permissions; (c) revoke access. Members with access to the workspace may view and edit data according to their permissions. The administrator is responsible for managing access.

6. Access Termination. Upon account closure: (a) all sessions are revoked; (b) access to the Platform is blocked; (c) data is handled according to the Retention Policy; (d) the associated email cannot be reused for a new account for 90 (ninety) days.

7. Passwords. CoguPlanner stores passwords using salted hashing (bcrypt or equivalent). Plain-text passwords are never stored. Password recovery is done via a temporary link sent to the registered email.

03 · Specific relationships

Contract for mentors and workspace sharing

This contract regulates the relationship between mentors, mentees, and CoguPlanner in the context of workspace sharing for mentorship purposes in mushroom cultivation.

1. Mentor Role. The mentor is a User with a Mentor plan who uses the Platform to: (a) create mentorships; (b) share workspaces with mentees; (c) track mentee production; (d) provide technical guidance. The mentor acts as controller of the data they enter and as operator of the mentee's data within the shared workspace.

2. Permissions. The mentor may: (a) view the mentee's production data within the workspace; (b) add comments and guidance; (c) view the calendar and tasks; (d) generate reports. The mentor may not: (a) change the mentee's registration data; (b) access the mentee's payment data; (c) delete the mentee's data without consent.

3. Shared Data. When sharing a workspace, the following mentee data becomes accessible to the mentor: (a) records of blocks, shelves, and species; (b) tasks and calendar; (c) production history; (d) notes. Payment and credential data is never shared.

4. Mentor Responsibilities. The mentor agrees to: (a) treat the mentee's data with confidentiality; (b) not use the data for purposes other than mentorship; (c) not share access with third parties; (d) respect the technical guidance and not interfere beyond what is agreed with the mentee.

5. Mentee Responsibilities. The mentee: (a) authorizes the sharing of their production data with the mentor; (b) may revoke access at any time; (c) retains ownership of their data; (d) is responsible for the accuracy of the data entered.

6. Mentorship Termination. Upon terminating the mentorship: (a) the mentor's access to the workspace is revoked; (b) the mentee's data remains in their account; (c) the mentor may keep copies of reports generated during the mentorship, provided they are anonymized; (d) the mentor's comments and guidance may be kept by the mentee at their discretion.

7. CoguPlanner's Responsibility. CoguPlanner acts as a platform and not as a party to the mentorship relationship. CoguPlanner is not responsible for: (a) technical guidance given by the mentor; (b) cultivation results; (c) conflicts between mentor and mentee. CoguPlanner provides the tools and ensures the security of data sharing.

Data processing addendum for B2B clients

This addendum establishes the specific conditions for processing personal data of B2B clients (companies, cooperatives, institutions) that contract CoguPlanner for use by multiple employees or members.

1. Roles. The B2B client acts as controller of the personal data of its employees/members who use the Platform. CoguPlanner acts as operator of the data entered by the B2B client and as controller of usage and billing data.

2. Employee Data. The B2B client is responsible for: (a) obtaining consent or verifying the legal basis for processing its employees' data; (b) ensuring employees are aware of the Platform's use; (c) managing access and permissions within the workspace; (d) notifying employees of their rights as data subjects.

3. Purpose. Data entered by the B2B client is processed for: (a) provision of the Platform; (b) workspace and permission management; (c) reports and analytics; (d) support. CoguPlanner does not use the B2B client's data for its own purposes, except for aggregated and anonymized data for Platform improvement.

4. Processing Instruction. CoguPlanner processes the B2B client's data according to documented instructions. Any change in the purpose or scope of processing must be agreed in writing.

5. Employee Rights. The B2B client's employees may exercise their rights directly with CoguPlanner or with the B2B client. CoguPlanner forwards to the B2B client any requests involving data under the client's control.

6. B2B Contract Termination. Upon termination: (a) CoguPlanner exports the client's data in a structured format (CSV/JSON); (b) data is deleted within 90 days, unless the client instructs otherwise; (c) the client must inform its employees of the termination and data deletion.

7. Confidentiality. CoguPlanner maintains confidentiality regarding the B2B client's data, including: production data, employee data, commercial data. This obligation persists after contract termination.

International clauses for foreign suppliers

This section establishes the clauses applicable to suppliers and subprocessors located outside Brazil, to ensure compliance with the LGPD (Art. 33) and GDPR (where applicable).

1. International Transfer. The transfer of personal data to foreign suppliers is carried out only when: (a) the destination country offers an adequate level of data protection; or (b) adequate safeguards are adopted, such as standard contractual clauses (SCCs); or (c) the data subject's specific consent is obtained.

2. LGPD Safeguards. For suppliers in countries without an adequate level of protection: (a) contracts with data protection clauses equivalent to LGPD requirements are signed; (b) the supplier agrees to notify incidents according to CoguPlanner's procedure; (c) the supplier submits to Brazilian jurisdiction for data protection matters.

3. GDPR Safeguards. For suppliers subject to GDPR (European Union): (a) Standard Contractual Clauses (SCCs) approved by the European Commission are adopted; (b) a Transfer Impact Assessment (TIA) is conducted when applicable; (c) the supplier agrees to support CoguPlanner in fulfilling data subjects' rights under GDPR.

4. Current Suppliers. The foreign suppliers currently used by CoguPlanner are located in the USA (Cloudflare, Neon, Stripe, Resend). For these: (a) CoguPlanner maintains contracts with data protection clauses; (b) the suppliers hold security certifications (SOC 2, ISO 27001, or equivalent); (c) data is processed according to CoguPlanner's instructions.

5. Location Change Notification. If a supplier changes the data location to a country without an adequate level of protection, it must notify CoguPlanner with 30 (thirty) days' notice. CoguPlanner evaluates the change and may terminate the contract if the safeguards are not maintained.

6. Data Subject Rights. Foreign suppliers agree to: (a) support CoguPlanner in fulfilling data subjects' rights; (b) not obstruct the exercise of rights; (c) cooperate with the ANPD and other data protection authorities.

7. Termination and Return. Upon termination of the contract with a foreign supplier: (a) data is returned or destroyed, according to CoguPlanner's instruction; (b) destruction is certified in writing; (c) data is not retained by the supplier, except under local legal obligation.

04 · Contractual definitions

Roles and responsibilities

This section defines the roles, data ownership, export, and account closure in CoguPlanner.

1. Who is the Controller. CoguPlanner is the controller of the personal data collected directly from Users (registration, usage, billing data). For B2B clients, the client is the controller of their employees' data, and CoguPlanner acts as operator.

2. Who is the Operator. Infrastructure, payment, and email providers (Cloudflare, Neon, Stripe, Resend) act as CoguPlanner's operators, processing data exclusively according to documented instructions. In mentorship relationships, the mentor acts as operator of the mentee's data within the shared workspace.

3. Data Ownership. Data entered by the User (cultivation records, blocks, species, tasks, sales, notes) is owned by the User. CoguPlanner owns the Platform, the code, the design, and the aggregated and anonymized data derived from usage. Usage data (logs, metrics) is owned by CoguPlanner.

4. Export Capability. The User may export their data at any time in a structured format (CSV or JSON), through the account settings. The export includes: records of blocks, shelves, species, tasks, batches, production history, and sales. Usage data and logs are not included in the export.

5. Account Closure. The User may close their account at any time. Before closure, exporting the data is recommended. After closure: (a) data is kept for 90 days for possible reactivation; (b) after 90 days, data is permanently deleted, subject to legal retention obligations; (c) CoguPlanner is not responsible for data loss after closure.

6. Retention by Legal Obligation. Data subject to a legal retention obligation (tax records for 5 years, security logs for 12 months) is kept even after account closure. After the legal period, it is automatically deleted.

Infrastructure and availability

This section defines CoguPlanner's commitments regarding backups, availability, and retention by legal obligation.

1. Backups. CoguPlanner performs daily database backups. Backups are: (a) stored in a secure location separate from the main infrastructure; (b) kept for 30 (thirty) days; (c) encrypted at rest; (d) periodically tested to ensure recoverability. CoguPlanner does not guarantee point-in-time restoration, but rather restoration of the last valid backup.

2. Availability (SLA). CoguPlanner seeks to keep the Platform available 24/7, except for: (a) scheduled maintenance, communicated with 48 (forty-eight) hours' notice; (b) unavailability of third-party providers; (c) force majeure events. The target SLA is 99.5% monthly uptime. If the SLA is not met, Producer and Mentor plan Users may request proportional credit.

3. Retention by Legal Obligation. Data subject to legal retention is kept regardless of account status:

  • Tax and accounting records: 5 years (Art. 46 of the CTN).
  • Access and security logs: 12 months for audit purposes.
  • Security incident records: 5 years (Art. 48 of the LGPD).
  • Contracts and accepted terms: during the term + 5 years after closure.

This section defines CoguPlanner's commitments regarding backups, availability, and retention by legal obligation.

1. Backups. CoguPlanner performs daily database backups. Backups are: (a) stored in a secure location separate from the main infrastructure; (b) kept for 30 (thirty) days; (c) encrypted at rest; (d) periodically tested to ensure recoverability. CoguPlanner does not guarantee point-in-time restoration, but rather restoration of the last valid backup.

Limits and data usage

This section defines the liability limits, AI data usage, support access, and data deletion.

1. Liability Limits. CoguPlanner's liability is limited to the amount paid by the User in the 12 (twelve) months prior to the damaging event. CoguPlanner is not liable for: (a) cultivation decisions made based on Platform data; (b) production, harvest, or sales losses; (c) indirect damages or lost profits; (d) temporary unavailability not attributable to intent or gross negligence of CoguPlanner; (e) content published by Users on CoguRede.

2. AI Data Usage. CoguPlanner may use aggregated and anonymized data for: (a) developing artificial intelligence features (harvest forecasting, management recommendations); (b) Platform improvement; (c) usage analytics. Identifiable personal data is not used to train AI models. Individual production data may be processed by AI to provide features to the User themselves, but not to train generalizable models without consent.

3. Support Access. CoguPlanner's support team may access User data only: (a) upon request and consent from the User; (b) for a time limited to resolving the problem; (c) with access logging; (d) without access to passwords or payment data. Support never asks for passwords. In security incident investigations, access may be expanded, with logging and justification.

4. Data Deletion. Data deletion may be requested by the User at any time. Deletion: (a) is processed within 15 (fifteen) days; (b) is permanent and irrecoverable, except for data in backups within the 30-day period; (c) respects legal retention obligations; (d) includes production, registration, and usage data. After deletion, the account cannot be reactivated.

5. Automatic Deletion. Data from inactive accounts (no login for 12 months) may be anonymized or deleted, with 30 (thirty) days' prior notice to the registered email. The User may prevent deletion by logging in within the period.

6. Right to be Forgotten. The User may request the deletion of all their data (right to be forgotten, Art. 18, VI, LGPD). CoguPlanner fulfills the request, subject to legal retention obligations. Deletion is irreversible.