1. Scope and controller
This policy covers fidencepath.org, its Personal Unit registry, Group Unit directory, authentication, invitations, reports, and related participation tools. During the formative period, Elieser Bitencourt acts as the data controller. Fidence Path does not yet have a separate legal personality.
2. Information collected
Registration uses an email address, country, age range, chosen Fidence Path name and identifier, authentication identifiers, verification timestamps, and account preferences. Group participation may add preferred contact methods, contact times, meeting availability, memberships, invitations, meeting format, language, location, and intentionally published details. Reports may contain the reporter’s email, target identifier, description, urgency, status, and resolution notes.
For minors, the site may also record a parent or legal guardian’s name, email, consent timestamp, and supervision confirmation. The site does not request a child’s legal name, exact birth date, government document, or biometric data.
3. Purposes and legal grounds
Data is used to authenticate accounts; prevent duplicate identities and abuse; operate Personal and Group Units; enable voluntary contact; protect participants; answer requests; investigate reports; maintain security; comply with law; and defend rights. Depending on the activity, processing relies on consent, performance of the requested service, legitimate interests compatible with participants’ expectations, protection of life or physical safety, and legal or regulatory obligations. Children’s and adolescents’ best interests prevail.
4. Public and private information
Account email, country, age range, guardian information, authentication data, private requests, group-member contact information, contact times, and availability are not public. A current group manager may access contact and availability supplied specifically for that group. Public information is limited to fields deliberately enabled for publication, such as a Personal Unit name, identifier, Group Unit listing, approximate location, meeting information, public contact link, or public constitution.
5. Service providers and international processing
The site uses specialized providers for hosting and security, database and authentication, email delivery, CAPTCHA protection, and—when chosen by the user—Google authentication. These providers process only the information needed for their function and may process it outside Brazil under their own security and transfer mechanisms. Fidence Path does not sell personal data or use it for behavioral advertising.
6. Retention
Deleting a Personal Unit removes its active registry and group data. A minimal authentication record may remain with the authentication provider until its own deletion process is completed; request complete account erasure through the contact channel. Deletion may otherwise be delayed only for backups, fraud prevention, safety, unresolved disputes, legal claims, or mandatory retention. When possible, retained records are minimized or separated from active use.
7. Your rights
You may ask whether data is processed; request access, correction, portability where applicable, information about sharing, review of consent, anonymization, blocking, or deletion; object to unlawful processing; and revoke consent. Requests may be sent to fidencepath@gmail.com. Identity may be verified proportionately before a request is completed. You may also petition Brazil’s National Data Protection Authority.
8. Minors
A child under 13 may have a Personal Unit only when a parent or legal guardian completes the registration through an account they control and gives specific, highlighted consent. A participant aged 13–17 may create a minimal Personal Unit, but group participation, public meetings, and direct participant contact require recorded guardian consent and continuing supervision. Public profiles for minors should remain disabled unless the guardian knowingly enables them in the minor’s best interest.
The current age-assurance method uses a self-declared age range plus guardian attestation because the service is small, noncommercial, and designed to minimize data. It deliberately avoids collecting identity documents or biometrics. This method will be reviewed as Brazilian guidance on proportionate age assurance develops.
9. Security and incidents
Access controls, authenticated management, CAPTCHA, data minimization, limited public fields, and provider security controls reduce risk but cannot guarantee absolute security. A relevant incident will be assessed and communicated to affected people and the competent authority when legally required.
10. Changes
Material changes will be dated and presented transparently. A change will not retroactively convert private information into public information without a new deliberate choice.