Proprelette
Back to site
LEGAL DOCUMENTS

Mobile App Privacy Policy

Last updated: July 29, 2026

Terms of Use Privacy Policy

This Privacy Policy explains how Proprelette handles personal data in the mobile applications Proprelette Hotel, Proprelette Representante, distributed through the Google Play Store and the Apple App Store. The apps are corporate and restricted-access: accounts are created by Proprelette, there is no self-registration, and use is strictly professional. We do not sell personal data and we do not use it for advertising.

On this page

  1. Who the data controller is
  2. Who this Policy applies to
  3. Data we process
  4. How we obtain this data
  5. Why we use the data and on what legal basis
  6. Device permissions
  7. Who we share data with
  8. International data transfers
  9. How long we keep the data
  10. Information security
  11. Your rights as a data subject
  12. Account and data deletion
  13. Children and adolescents
  14. Cookies and similar technologies
  15. Changes to this Policy

1Who the data controller is

The controller of personal data processed in the apps is Proprelette, Brazilian company number (CNPJ) 43.650.984/0001-69.

Channel for privacy matters and for exercising your rights: contato@proprelette.com.

This Policy complies with the Brazilian General Data Protection Law (Law No. 13,709/2018 — LGPD) and, where applicable, with the European Union General Data Protection Regulation (GDPR).

2Who this Policy applies to

This Policy applies to users of Proprelette apps, who are exclusively:

  • employees and representatives of client hotels and hotel chains;
  • commercial representatives and authorised Proprelette staff.

The apps have no public sign-up: there is no account creation screen and no user can register on their own. All accounts are created by Proprelette in its internal systems, at the request of the client hotel or by internal assignment.

The apps are not intended for hotel guests and do not collect guest data.

3Data we process

Professional account data

  • full name;
  • corporate email address and professional contact phone number;
  • job title or role and the hotel/unit or representation area the User is linked to;
  • internal user identifier and permission profile.

Authentication data

  • password stored in encrypted form (never in readable text);
  • session tokens and records of logins, logouts and access attempts.

Technical and usage data

  • IP address, date and time of access;
  • device model, operating system and app version;
  • logs of actions performed in the app, for audit, security and support purposes;
  • crash and error reports, when generated;
  • push notification identifier, if the User allows notifications.

Operational data entered in the app

  • entries, quantities, incidents, notes and attachments relating to the operation of the solution at the hotel.

Support data

  • messages, support requests and the related history of interactions.

We do not process sensitive personal data (such as health data, biometrics, racial origin, religious belief or political opinion), we do not collect data from children or adolescents, and we do not carry out automated decision-making with legal effects on the User.

4How we obtain this data

  • Provided by the client hotel or by Proprelette: account data supplied when the account is created, since there is no self-registration;
  • Provided by the User: contact updates, password, operational records and support messages;
  • Generated automatically through use: technical data, access and activity logs, necessary for the security and operation of the service.

5Why we use the data and on what legal basis

  • Enabling and controlling access to the app (authentication, permission profiles) — performance of a contract and preliminary procedures (LGPD, art. 7, V);
  • Operating features and recording operational information — performance of a contract (art. 7, V);
  • Providing technical support and customer service — performance of a contract (art. 7, V);
  • Ensuring information security, preventing fraud and maintaining audit trails — legitimate interest (art. 7, IX) and compliance with a legal obligation (art. 7, II);
  • Keeping application access logs under the Brazilian Internet Act (Law No. 12,965/2014) — compliance with a legal obligation (art. 7, II);
  • Fixing faults and improving the app using usage data and error reports — legitimate interest (art. 7, IX);
  • Sending operational notifications about the solution and how the app works — performance of a contract (art. 7, V) and, for push notifications, the consent granted in device permissions (art. 7, I);
  • Exercising rights in judicial, administrative or arbitral proceedings — art. 7, VI.

Data is not used for behavioural advertising, consumer profiling or sale to third parties.

6Device permissions

The app may request the permissions below, always for a specific purpose and only when the corresponding feature is used. All of them may be denied or revoked in the operating system settings without preventing the use of other functions:

  • Notifications: sending operational and security alerts;
  • Camera: reading codes and photographing operational incidents, where the feature is available;
  • Files and media: selecting and attaching documents or images to records and support requests;
  • Network and connectivity: communicating with our servers.

The app does not track location in the background, does not access contacts, messages or call history, and we do not use advertising identifiers.

7Who we share data with

We do not sell, rent or trade personal data. Sharing occurs only in the necessary cases below:

  • Processors and technology providers acting on our behalf and under our instructions — cloud hosting, email and notification delivery, monitoring and support — contractually bound by confidentiality and security obligations;
  • The hotel or hotel chain the User is linked to, regarding operational information and usage records for that unit;
  • Public and judicial authorities, where there is a legal request, court order or regulatory obligation;
  • Legal advisers and auditors, where necessary for the regular exercise of rights;
  • Successors, in the event of corporate reorganisation, maintaining the commitments of this Policy.

The app stores (Apple and Google) process their own data relating to download and installation, in accordance with their respective privacy policies, over which Proprelette has no control.

8International data transfers

Our infrastructure providers may store or process data on servers located outside Brazil. In those cases we adopt the safeguards required by the LGPD (arts. 33 to 36), through contractual data protection clauses and by engaging providers that ensure an adequate level of protection.

9How long we keep the data

  • Account and operational data: for as long as access and the contractual relationship with the hotel remain in force, and for up to 5 (five) years afterwards, for the defence of rights and statutory limitation periods;
  • Application access logs: for a minimum of 6 (six) months, as required by art. 15 of the Brazilian Internet Act, and longer where required by law;
  • Support history: for up to 2 (two) years after the request is closed;
  • Data subject to legal, tax or regulatory obligations: for the periods set out in the applicable legislation.

Once the periods and purposes have ended, data is securely deleted or anonymised.

10Information security

We adopt technical and administrative measures to protect personal data against unauthorised access, loss, alteration, destruction or improper processing, including:

  • encrypted traffic between the app and our servers (HTTPS/TLS);
  • passwords stored using hashing algorithms;
  • role-based access control, granting the minimum necessary permissions;
  • logging and audit trails;
  • backup and recovery routines;
  • confidentiality commitments with staff and suppliers.

No system is absolutely secure. In the event of a security incident that may result in relevant risk or damage to data subjects, we will notify the affected data subjects and the Brazilian National Data Protection Authority (ANPD), as required by art. 48 of the LGPD.

11Your rights as a data subject

Under art. 18 of the LGPD, the User may request at any time:

  • confirmation that processing exists and access to their data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
  • portability of data to another provider, subject to commercial and industrial secrecy;
  • deletion of data processed on the basis of consent;
  • information about the parties with whom we share their data;
  • information about the possibility of refusing consent and the consequences of doing so;
  • withdrawal of consent, where consent is the applicable legal basis;
  • objection to processing carried out on one of the bases that do not require consent, in the event of non-compliance with the law.

Requests should be sent to contato@proprelette.com and will be answered within 15 (fifteen) days; identity confirmation may be required. Some data may be retained where there is a legal obligation or a need to defend rights, in which case we will explain the reason.

Data subjects may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

12Account and data deletion

Since the app has no self-registration, account deletion is likewise not performed by the User inside the app: it is carried out by Proprelette upon request. The procedure is as follows:

  • send an email to contato@proprelette.com with the subject "Account and data deletion", stating your full name, the email address used to access the app and the hotel or area you are linked to; or
  • ask the administrator responsible at your hotel, who will forward the request to Proprelette.

Once identity is confirmed, the account is deactivated within 5 (five) business days and the associated personal data is deleted or anonymised within 30 (thirty) days, except for:

  • application access logs, retained for the statutory minimum of 6 (six) months (Brazilian Internet Act, art. 15);
  • data necessary to comply with legal, tax or regulatory obligations, or to defend rights in judicial, administrative or arbitral proceedings (LGPD, art. 16);
  • operational records forming part of the client hotel's contractual history, which may be retained in a form no longer linked to the User's identity.

Uninstalling the app does not by itself delete data stored on our servers — the request described above is required.

Direct link to this section, for use in the app store listings: https://proprelette.com/privacidade#data-deletion

13Children and adolescents

The apps are for professional use and are intended exclusively for users aged 18 or over. We do not knowingly collect data from children or adolescents. If we identify an account in those circumstances, access will be deactivated and the data deleted.

14Cookies and similar technologies

The apps do not use advertising cookies or tracking identifiers for marketing purposes. We only use local storage on the device to keep the session authenticated, remember language preferences and support the basic operation of the app.

On the website https://proprelette.com we use a cookie to remember the chosen language and Google reCAPTCHA to protect the contact form, subject to Google's Privacy Policy and Terms of Service.

15Changes to this Policy

This Policy may be updated due to legal, technical or feature changes. The current version is always available at https://proprelette.com/privacidade, with the date of the last update shown at the top of the page.

Material changes will be communicated by notice in the app or through the registered contact channels.

Proprelette — Company registration (CNPJ) 43.650.984/0001-69. Contact: contato@proprelette.com.

Proprelette
Terms of Use · Privacy Policy · contato@proprelette.com

© 2026 Proprelette