Scope and roles
This policy applies to the DOMOD Admin and DOMOD Cliente applications, the APIs that serve them, and the integrations used in those journeys. The institutional website and its demo-request form have their own notice at the point of collection and are outside this policy's scope.
DOMOD provides the platform. The developer or project operator defines project information, offers, sales, payment conditions, and contracts. We may also process organization membership, permissions, and operational activity needed to administer a project. Depending on the activity, DOMOD and the project operator may have different roles under applicable data protection law. Questions about a purchase or contract may be directed to the project operator.
Data we process
Depending on the product and enabled features, we may process:
- account and access data, including name, email, authentication data, session identifiers, language, IP address, and device information;
- identification and contact data for buyers, owners, and signers, including phone, address, and an identification document when required by the project or contract;
- company, tax-registration, or other business details provided by an organization or project operator;
- development, unit, floor-plan, room, option, choice, value, configured payment-condition, and journey-progress data;
- documents, contracts, signature status, signing links, and signer data;
- appointments, availability, date and time, time zone, unit, buyer, architect, and appointment participants;
- support requests, feedback, and technical data for security, diagnostics, performance, and errors.
How we use data
We use data to authenticate users, enforce permissions, show projects and options, save choices and configured values, support checkout, generate and track documents and signatures, create and manage appointments, answer support requests, protect the services, comply with duties, and exercise rights.
The legal basis for each activity depends on its purpose and on the role of the project operator. Where consent is required, it will be requested for a specific purpose and may be withdrawn as allowed by law.
Google Calendar data
This section is the complete description of the optional Google Calendar integration in DOMOD Admin. An authorized organization user, usually a project or calendar administrator, starts the connection and must have authority to connect the organization's calendar. A buyer using DOMOD Cliente does not grant Google OAuth access.
Data accessed
We may access:
- the email address of the Google account used to connect the organization;
- the available calendar list, including names, IDs, and metadata needed to select and display a calendar;
- availability and scheduling-conflict information; and
- events and metadata needed to create, update, remove, and reconcile appointments.
The OAuth permissions are
https://www.googleapis.com/auth/calendar.calendarlist.readonly,
https://www.googleapis.com/auth/calendar.events,
https://www.googleapis.com/auth/calendar.freebusy, and
https://www.googleapis.com/auth/userinfo.email.
Appointment events may contain buyer and professional names and email addresses, project and unit, start and end time, time zone, attendees, title, and summary. During synchronization, descriptions and attendees may be read to reconcile records; we retain only metadata needed for the appointment record.
Use, sharing, and limited use
We use Google data to list calendars, read free/busy availability, create, update, and delete scheduling events, synchronize relevant event metadata, receive change notifications, avoid conflicts, and refresh an authorized token when needed to keep the connection working.
Data is sent to Google for authorized operations and may be available to the organization and authorized users who manage appointments. We may use infrastructure providers needed to host and protect DOMOD. We do not use Google data for advertising, sale, data brokerage, credit, lending, unrelated profiling, or training artificial-intelligence models. Human access by DOMOD personnel is limited to a user's affirmative agreement, security or abuse prevention, legal requirements, or aggregated/anonymized operations. This use follows the Google API Services User Data Policy.
Storage, retention, and revocation
Access and refresh tokens are protected and stored encrypted. We store the account email, available calendar list and metadata, event identifiers, synchronization status, and appointment data needed to provide the service. We keep those records while needed for the organization, appointments, security, or legal duties. Appointment records may remain as project history after an external event is canceled.
Disconnecting Google Calendar in DOMOD stops new synchronization and connection monitoring and removes the local tokens and integration. A deletion request sent to contato@domod.com.br removes DOMOD-held connection data and calendar metadata when no legal, contractual, security, or dispute-retention exception applies. We confirm the result or explain the exception. This does not automatically revoke authorization in Google or delete events already held there.
Cookies, storage, and security
We use necessary session and language cookies, browser storage for preferences and continuity in certain journeys, and technical information for performance, errors, and security. We use access controls, protection in transit, and organizational and technical measures appropriate to the risks. No internet-connected service is completely risk-free.
Retention, deletion, and rights
We retain each category of data for as long as needed for its purpose, contract, legal duties, security, and dispute handling. Operational telemetry is configured for retention of up to 30 days. Other records may remain as long as needed for the project relationship or required records. Where permitted, data is deleted, anonymized, or no longer used.
Subject to applicable law, a person may request confirmation of processing, access, correction, sharing information, deletion or anonymization where available, portability, consent withdrawal, and other applicable rights. Send requests to contato@domod.com.br and identify the related project or product.
Contact and updates
Questions about this policy or data processing can be sent to contato@domod.com.br. We may update this document when services, integrations, or legal duties change. The date at the top identifies the current version.