Privacy Policy
Last updated: September 19, 2025
This policy describes how we collect, use, store and protect your personal information on the Pandami platform in accordance with the LGPD.
Index
1. INTRODUCTION
PandaHan (CNPJ: 60.348.853/0001-40), headquartered in Florianópolis, Santa Catarina ("we", "our" or "Company"), operates the web application Pandami (the "Service"), an innovative management and visagism platform for barbershops that uses artificial intelligence to personalize haircuts.
This Privacy Policy informs you about our practices for collecting, using, storing and protecting personal data, in compliance with:
- Brazil's General Data Protection Law (LGPD - Law No. 13,709/2018)
- the General Data Protection Regulation (GDPR - EU 2016/679)
- the Brazilian Internet Civil Framework (Law No. 12,965/2014)
IMPORTANT: Our Service is in Beta/MVP phase, with continuous improvements being implemented, including security and privacy features.
2. IMPORTANT DEFINITIONS
- "Visagism": Facial analysis technique for the aesthetic harmonization of haircuts
- "Biometric Data": Facial photographs used for analysis and simulation
- "AI": Artificial Intelligence that processes images and generates recommendations
- "Image Manipulation": Flux Azure technology used to simulate haircuts
- "Data Subject": The natural person the data refers to (end client)
- "Controller": PandaHan and/or the barbershop that decides on the processing
- "Processor": The barber who carries out the data processing
3. DATA WE COLLECT
3.1 Establishment (Barbershop) Data
- Legal and trade name
- CNPJ/CPF of the responsible party
- Full business address
- Corporate phone number and email
- Bank details for subscription payment
- Contracted plan and payment history
3.2 Professional (Barber) Data
- Full name
- CPF (when applicable)
- Email and mobile phone
- Access credentials (hashed, encrypted password)
- Access and activity logs
- History of appointments performed
3.3 End Client Data
Basic Data (Required)
- Full name
- Mobile phone number (WhatsApp)
- Email (optional)
Appointment Data
- Personalized Notes: Personal preferences (e.g. "likes soccer", "serious client")
- Visit History: Dates, cut types (1st, 2nd, 3rd cut, etc.)
- Cut Evolution: Notes on changes and adaptations
Visagism Data (Option 1 - Full Form)
- Answers to the visagism questionnaire (multiple choice)
- Identified face shape
- Hair type and characteristics
- Aesthetic preferences
- Lifestyle and profession
Simplified Appointment Data (Option 2 - No Visagism)
- Description of the desired cut (free text from the barber)
- Direct client preferences
Sensitive Biometric Data
- Facial Photographs: The client's original image
- Processed Images: AI-generated simulations
- Metadata: Date, time and device used for capture
4. LEGAL BASES AND PURPOSES
4.1 Consent (Art. 7, I and Art. 11, I of the LGPD)
Data: Facial photographs and biometric data
Purpose: Visagism analysis and generation of simulations
How we obtain it: Specific consent form at the first appointment
4.2 Contract Performance (Art. 7, V of the LGPD)
Data: Contact information, appointment history
Purpose: Provision of the management and scheduling service
4.3 Legitimate Interest (Art. 7, IX of the LGPD)
Data: Preference notes, cut evolution
Purpose: Improving service quality and client loyalty
4.4 Compliance with a Legal Obligation (Art. 7, II of the LGPD)
Data: Tax and financial data
Purpose: Compliance with tax obligations
5. HOW WE USE THE DATA
5.1 AI Visagism Process
- Capture: The barber photographs the client with a phone
- Upload: The photo is sent to a secure server
- Analysis: The AI processes the form answers
- Report Generation: The system creates personalized recommendations
- Simulation: Flux Azure generates an image with the new cut
- Storage: Data is saved to the client's profile
5.2 Simplified Process (No Visagism)
- Consultation: The barber asks about preferences directly
- Record: The cut description is logged in the system
- Photo: The current image is captured
- Processing: The AI converts the description into a simulation
- Result: An image with the suggested cut
5.3 Additional Uses
- Sending reports via WhatsApp/email (with consent)
- Appointment reminders
- Satisfaction analysis and improvements
- AI training (anonymized data)
- Technical support and troubleshooting
6. DATA SHARING
6.1 Who We Share Data With
Essential Technology Partners
- Microsoft Azure: Hosting and AI processing
- Flux: Image manipulation
- Payment Processor: Stripe Brazil
- WhatsApp Business API: Sending messages (when authorized)
Within the Platform
- Between Barbers at the Same Establishment: For continuity of service
- From the Barber to the Client: Reports and simulations
6.2 What We Do Not Share
- We never sell personal data
- We do not share data with marketing companies
- We do not build profiles for advertising
6.3 International Transfer
- Data may be processed on Microsoft Azure's global servers
- We ensure standard contractual clauses for protection
- Compliance with LGPD/GDPR requirements for transfers
7. DATA SECURITY
7.1 Technical Measures (MVP/Beta Phase)
- TLS 1.3 encryption for data in transit
- AES-256 encryption for data at rest
- Authentication with bcrypt password hashing
- Firewall and DDoS protection
- Automated daily backups
- Audit logs for traceability
7.2 Organizational Measures
- Access restricted by role (a barber only accesses their own clients)
- Employee training
- Confidentiality agreements
- Mandatory strong-password policy
- Periodic access review
7.3 Beta Phase Limitations
- System under continuous improvement
- Possible security adjustments during development
- Active monitoring to identify improvements
8. DATA RETENTION AND DELETION
8.1 Retention Periods
| Data Type | Active Period | After Cancellation |
|---|---|---|
| Basic client data | While subscription is active | 2 years |
| Photographs/Simulations | While subscription is active | 60 days |
| Cut history | While subscription is active | 2 years |
| Financial data | 5 years | 5 years (legal obligation) |
| Access logs | 6 months | Automatic deletion |
8.2 Deletion Upon Request
- Clients may request immediate deletion of photos
- Response time: up to 15 days
- Data legally required to be kept is retained per the legal deadline
9. DATA SUBJECT RIGHTS
9.1 Your Rights (LGPD + GDPR)
You have the right to:
- Confirmation and Access: Know whether we process your data and access it
- Correction: Correct incomplete or outdated data
- Anonymization/Blocking/Deletion: Of unnecessary data
- Portability: Receive your data in a structured format (JSON/CSV)
- Information: Know who we share your data with
- Revocation: Withdraw consent at any time
- Objection: Object to specific processing
- Review: Of automated AI decisions
9.2 How to Exercise Your Rights
Via the App:
Menu > Settings > Privacy > My Data
By Email:
privacidade@pandami.com.br
Response within:
- 15 days (LGPD)
- 30 days (GDPR)
9.3 No Detriment to the Service
Exercising your rights will never result in:
- Fees being charged (first request is free)
- Discrimination or detriment in service
- Unrequested cancellation
10. USE OF ARTIFICIAL INTELLIGENCE
10.1 How the AI Processes Your Data
Facial Analysis:
- Identifies face shape
- Detects features (does not identify the person)
- Suggests harmonious cuts
- Does not perform facial recognition for identification
Simulation Generation:
- Uses Flux Azure to manipulate only the hair area
- Preserves original facial features
- Does not alter other parts of the image
- Real-time processing, with no intermediate storage
10.2 Algorithmic Transparency
- AI makes suggestions; the final decision is always human
- The barber can ignore or adapt suggestions
- The client can refuse the use of AI at any time
- We explain the logic behind recommendations in the report
10.3 Limitations and Disclaimers
- Simulations are artistic approximations
- The actual result may vary
- The AI is constantly learning and improving
- Feedback helps improve accuracy
11. DATA OF MINORS
11.1 Policy for Minors
- Under 16: Requires parental/guardian consent
- 16 to 18: Minor's consent + parental awareness
- Identification: The barber should ask about age when applicable
11.2 Special Protection
- Photos of minors receive reinforced security
- We do not use minors' data for AI training
- Immediate deletion upon request from guardians
13. COMMUNICATIONS
13.1 Types of Communication
Transactional (Always Sent):
- Appointment confirmations
- Requested reports
- Security alerts
- Changes to the terms
Marketing (Requires Opt-in):
- Barbershop promotions
- Platform news
- Care tips
13.2 Channels
- WhatsApp (primary)
- Email (secondary)
- In-app notifications
13.3 Unsubscribing
- Link in all marketing messages
- Reply "STOP" on WhatsApp
- App settings
14. SECURITY INCIDENTS
14.1 Our Commitment
In the event of an incident that may pose a risk:
- Notification within 72 hours to those affected
- Notification to the ANPD when applicable
- Immediate containment measures
- Transparent report on what occurred
14.2 Your Role
- Keep your password secure and secret
- Report suspicious behavior
- Keep the app updated
15. DATA PROTECTION OFFICER (DPO)
Name: Data Protection Officer
Email: dpo@pandami.com.br
Phone: (48) 99999-9999
Hours: Monday to Friday, 9am to 6pm (Brasília time)
16. SUPERVISORY AUTHORITIES
If you are not satisfied with our response:
Brazil:
- National Data Protection Authority (ANPD)
- Website: www.gov.br/anpd
- Email: encarregado@anpd.gov.br
European Union:
- The data protection authority of the data subject's country
- List: edpb.europa.eu
17. CHANGES TO THIS POLICY
17.1 When We Make Changes
- Changes in legislation
- New features in the app
- Security improvements
- User feedback
17.2 How We Notify You
- Minor changes: Silent update
- Significant changes: 30 days' prior notice
- Notification channel: Email + in-app banner
17.3 Version History
Available at: pandami.com.br/privacidade/historico
18. GOVERNING LAW AND JURISDICTION
This Policy is governed by Brazilian law. The courts of Florianópolis, Santa Catarina are elected to resolve any disputes, with waiver of any other jurisdiction.
19. TECHNICAL GLOSSARY
- API: Application Programming Interface
- Backup: A security copy of data
- Encryption: Encoding used to protect data
- Hash: Irreversible transformation of a password
- MVP: Minimum Viable Product (initial version)
- TLS: Security protocol for the internet
20. CONTACT
PandaHan
CNPJ: 60.348.853/0001-40
Address: Florianópolis, Santa Catarina, Brazil
Support Channels:
- Privacy: privacidade@pandami.com.br
- Support: suporte@pandami.com.br
- Business: comercial@pandami.com.br
- WhatsApp: (48) 98879-3250
DECLARATION OF COMPLIANCE
This Privacy Policy was prepared in compliance with:
- General Data Protection Law (LGPD - Law No. 13,709/2018)
- General Data Protection Regulation (GDPR - EU 2016/679)
- Brazilian Internet Civil Framework (Law No. 12,965/2014)
- Consumer Protection Code (Law No. 8,078/1990)
Last legal review: 09/19/2025
Next scheduled review: 03/19/2026
PandaHan is committed to the privacy and protection of your data. This policy reflects our commitment to transparency and legal compliance.