VISU Privacy Policy
Version 3.0 | Published on September 4, 2026 | Effective from September 4, 2026
This Privacy Policy explains how VISU Network Ltda (CNPJ 54.954.885/0001-97), R 1500, no. 820, Sala 2003 F55, Edif Sky Business Center, Centro, Balneário Camboriú/SC, Brazil, ZIP 88.330-526 (“VISU”, “we”) collects, uses, stores, shares, and protects personal data in the VISU app and rewards platform, including the app pages at visu.to, VisuLink pages, the rewards experience, VISU Replay at Partner Venues, and the VISU mobile apps (together, the “Service”).
This Policy is designed to provide information required by applicable privacy laws, including the Brazilian LGPD (Brazilian General Data Protection Law), the UK and EU GDPR where applicable, California privacy laws, and other regimes that may apply depending on your location. It works together with our Terms of Use and our Cookie and Tracking Policy.
Scope. This Policy governs the processing of personal data in the Service across all of its surfaces: the web app at visu.to, the visu.network website, including the institutional blog published on WordPress at that address, VisuLink pages, public clip links, VISU Local, VISU Replay, and the VISU mobile apps. The same version of this Policy is made available on VISU's official surfaces.
Summary of changes in this version. This version describes VISU Replay, including video capture at Partner Venues and the rights of filmed individuals who are not VISU users; identity document verification with encryption at rest and duplicate detection; device signals and clustering for fraud prevention; push notifications; product analytics events; consent in mobile apps; maps and location-based discovery; and a retention schedule in table form. This version also unifies the scope of the Policy across all VISU surfaces, including the visu.network website; incorporates the purposes previously described in a separate section into the section on legal bases and purposes; adds Cloudflare to the sub-processor table; and updates the clip retention period, now enforced by an active purge routine.
1. Controller and privacy contact
VISU Network Ltda is the controller responsible for the personal data described in this Policy, except where another party acts as an independent controller of its own services.
For VISU Replay, VISU and the Partner Venue where the camera is installed act as joint controllers of the shared capture, clip generation and clip delivery operations, because they jointly decide on the purposes and the essential elements of that processing. Joint controllership is limited to those VISU Replay operations: for its own processing, each party remains an independent controller. The venue is responsible for on-site signage, for the authorizations collected at enrollment and check-in, for informing students, guardians and visitors, and for its own commercial records. VISU is responsible for operating the platform, for storage and technical controls, for retention periods, for clip moderation and publication, for the clip contest, and for account data, fraud prevention and platform analytics. The responsibilities of VISU and of the Partner Venue are those described in this Policy. Specific partnership instruments may detail the operational allocation between the parties, without reducing the rights of the data subject and without removing responsibilities provided for by law.
In general terms, the Partner Venue is responsible for on-site signage, for the authorizations collected at enrollment, and for informing visitors. VISU is responsible for operating the platform, for storage, and for the technical controls described in this Policy.
Data subject requests relating to VISU Replay may be directed to [email protected] or to the Partner Venue's reception. We will forward the request to the other party where that is necessary to handle it.
VISU Network Ltda
CNPJ 54.954.885/0001-97
Balneário Camboriú/SC, Brazil
Privacy requests, data protection contact, and DPO contact: [email protected]
2. Data we collect
We collect personal data in the following categories.
2.1 Data you provide
Account and profile data: name, username, email address, phone number, password stored in an encrypted and irreversible form, profile details, language preference, and account settings.
Login data: if you sign in with Google or Apple, we receive identifiers and account information made available by those providers, such as email, name, and the provider account ID.
Identity and KYC data: where needed for verification, for uses and programs where available, fraud prevention, sanctions screening, or compliance, we may collect an identity document, CPF or CNPJ, tax identification, related documents, date of birth, address, and verification information. Processing of this data is detailed in section 2.5.
Wallet, rewards, and transaction data: reward balances, pending rewards, conversions, withdrawals, payment records, Wallet information, token-related records, and related transactional or compliance metadata.
Content and links: VisuLink pages, links, profile content, Campaign content, referral data, messages, and other content you create, upload, or submit through the Service.
VISU Replay content: Clips you create, trim, publish, share, or export, along with votes and contest participation. Details in section 5.
Support and communications: messages you send us, support requests, feedback, complaints, and communication preferences.
2.2 Data collected automatically
Technical data: IP address, browser type, app version, device type, operating system, device identifiers, network information, language, region, time zone, and diagnostic information.
Usage data: pages and features used, QR Code scans, link openings, clicks, impressions, Campaign interactions, referrals, reward activity, local discovery, timestamps, session events, and browsing patterns.
Product analytics events: we record events that measure the use of specific features, including Replay clip views, export downloads, subscription and paywall screen events, and acquisition-origin events such as inbound channel and campaign variant. A session identifier may correlate the same session across web and native app, and ad events may be correlated per ad unit to measure performance and revenue. Clip view and export download events are recorded without IP address, without user-agent, and without any identifier of the person viewing. View counting uses a short in-memory deduplication window that is not stored permanently.
Referral and attribution data: referral codes, campaign parameters, utm_* parameters, source, medium, campaign data, and related first-party attribution signals.
Approximate location: approximate country or region inferred from IP address, network, or request headers.
Precise location and maps: local discovery features may prioritize content near you. If you choose to use location-based features, we may request browser or device location permission. Precise location is used only for the requested feature and is not retained beyond what is reasonably necessary for that feature, security, or compliance. Place maps are rendered by a third-party map provider, which receives the map requests needed to display the map.
Security and anti-fraud signals: device, account, usage, location, referral, campaign, and behavioral signals used to detect abuse, multiple accounts, automation, spoofing, reward fraud, account takeover, and platform manipulation. Details in section 6.
Push notifications: if you allow notifications, we store a device push token provided by the platform messaging service, along with basic device information and the token activation status. You can revoke notification permission at any time in your operating system settings, and we may deactivate invalid or unused tokens.
Cookies and similar technologies: cookies, local storage, pixels, SDKs, tags, and similar technologies, as described in the Cookie and Tracking Policy.
2.3 Third-party data
We may receive data from login providers such as Google and Apple; analytics providers, where permitted by your consent and region; advertising and mediation partners; payment, withdrawal, wallet, KYC, sanctions, fraud prevention, and compliance providers; offerwall providers, which confirm offer completions so rewards can be credited; an IP geolocation provider, used to enrich anti-fraud signals with approximate country, region, and city; Campaign partners, merchants, advertisers, and referral sources; and public or lawfully available databases for fraud, sanctions, and compliance purposes.
2.4 Consent and acceptance records
When you are logged in, we keep immutable, timestamped records of cookie and tracking consent choices. Each record may contain the essential, analytics, and advertising categories; the region class and country; the state of GPC and DNT signals; the policy version and the consent schema version; the source of the choice; the IP address and user-agent; and the client choice time and the server write time.
These records are append-only, never updated or deleted, and are used as evidence of consent, compliance, support, and audit history. They are available to authorized staff when needed and are not sold.
2.5 Identity document: encryption, duplicates, and masking
When you submit a document such as a CPF or CNPJ, the number is not stored in plain text. The number is normalized, encrypted at rest, turned into an irreversible reference, and reduced to a masked reference showing the last digits.
That irreversible reference lets us detect when different accounts submit the same document. This duplicate detection is used solely for fraud prevention, reward integrity, and legal compliance, and may create a review case for authorized staff.
Administrative screens and change logs display only the masked reference. Document changes generate an audit record with no plain-text values.
3. Legal bases and purposes
Depending on your location and the context, we rely on one or more legal bases, including performance of a contract, consent, legitimate interests, legal obligation, and protection against fraud or abuse.
We process personal data for the following purposes:
Providing the Service.
We use Account, login, profile, VisuLink, rewards, Wallet, and Replay data to operate the Service. Legal basis: performance of a contract.
Rewards and payments.
We use rewards, Wallet, transaction, activity, and eligibility data to calculate, validate, withhold, reverse, convert, redeem, or pay rewards. Legal basis: performance of a contract, legitimate interests, and legal obligation.
The Service works with two distinct balances, and the data for each is handled separately. VISU is an internal-use credit, obtained through rewarded and mediated ads, achievements, missions and the daily QR Code scan. VISU may be used exclusively within the Service, in the forms that are actually made available at any given time and indicated in the app before each operation is confirmed. It is not withdrawable, is not transferable between accounts, and is not converted into money or into $VISU. $VISU is a separate balance, used on the platform to create and fund advertising Campaigns, and may be obtained by purchase by the user, via Pix or cryptocurrencies, through the conversion of amounts confirmed by offer partners, and through other activities indicated on the platform.
There is no withdrawal of any kind in the Service, neither in fiat currency nor in cryptocurrencies, for VISU or for $VISU. We process $VISU purchase data, including the amount, the recorded quote, the Pix or cryptocurrency transaction identifier and the receipt submitted, in order to verify the payment, credit the balance, meet accounting and tax obligations and prevent fraud and money laundering. Verification of Pix payments is performed manually by authorized VISU personnel.
Identity verification and KYC.
We use identity, document, sanctions, wallet, fraud, and compliance data to verify eligibility and meet legal or platform requirements. Legal basis: legal obligation, performance of a contract, and legitimate interests.
Security and anti-fraud.
We use device, account, usage, location, referral, campaign, and behavioral signals, including device clustering and duplicate document detection, to detect abuse, prevent multiple accounts, protect accounts, and maintain reward integrity. Legal basis: legitimate interests and legal obligation.
Video capture at Partner Venues.
We use image, video, and recording metadata to operate VISU Replay. Legal basis: performance of a contract for users who request the feature, and the legitimate interests of VISU and the Partner Venue for on-site camera operation, balanced by visible notice and the right to object described in section 5.
Analytics.
We use analytics data to measure and improve the Service. Legal basis: consent where required, or legitimate interests where permitted by applicable law.
Advertising and measurement.
We use advertising and measurement data to deliver, measure, cap, and improve ads. Legal basis: consent or an opt-out model, depending on your region and applicable law.
Notifications and service communications.
We use push tokens, contact details, and preferences to send service, security, and account notices. Legal basis: performance of a contract and legitimate interests, and consent where system permission is required.
Referral and attribution.
We use referral codes, campaign parameters, and attribution signals to credit referrals, validate Campaigns, and operate rewards. Legal basis: performance of a contract and legitimate interests.
Marketing communications.
We may use contact and preference data to send newsletters, offers, or promotional messages. Legal basis: consent or legitimate interests where permitted by law.
Legal compliance.
We use data to meet tax, accounting, regulatory, sanctions, dispute, and legal obligations. Legal basis: legal obligation.
Customer support.
We use Account, contact, and support history data to provide support, respond to requests, and handle complaints. Legal basis: performance of a contract and legitimate interests.
Consent records.
We keep records of privacy, cookie, and policy choices for audit and compliance purposes. Legal basis: legal obligation and legitimate interests.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before the withdrawal.
4. Consent, region, cookies, and standing privacy signals
Cookie and tracking choices are region-sensitive.
In the EEA, the United Kingdom, and Switzerland, analytics and advertising technologies require prior consent where required by law.
In Brazil, analytics and advertising technologies start disabled and only operate after your consent. In other regions not subject to prior consent, those technologies may operate under a notice and opt-out model, depending on the category and legal basis.
In California and other opt-out regimes, applicable opt-out rights and signals may apply.
Global Privacy Control (GPC) and Do Not Track (DNT) signals, where detected and applicable, are treated as standing privacy signals. They force advertising to remain off even if the advertising control appears available or was previously enabled.
A permissive choice made in an opt-out region does not automatically unlock analytics or advertising in a region that requires prior consent. In that case, we may ask you to choose again.
You can manage available choices through the consent banner, the manage panel, the “Your Privacy Choices” link, or other privacy controls made available in the Service. Details are in the Cookie and Tracking Policy.
Essential technologies needed for security, login, fraud prevention, Account operation, reward integrity, and legal compliance may continue to function even if analytics or advertising are denied.
5. Video capture at Partner Venues (VISU Replay)
VISU Replay is a recording service at partner sports venues. This section explains how it handles images of people.
5.1 How it works
Cameras installed at Partner Venues record continuously while the venue is operating. The recording feeds a temporary buffer that enables live streaming and retrieval of recent footage. This buffer is circular and overwrites itself, and Clips can only be generated from the last 7 days of footage. From that buffer, users can generate Clips, thumbnails, and export files, and Clips can receive public links, take part in contest voting, and display creator credit and view counts.
Today, watching, downloading, and sharing a Clip is free. Where the rewarded ad requirement is active for a given Clip, watching the ad unlocks access to that Clip, which includes replaying, downloading, and sharing it. The Replay rewarded ad does not generate VISU or any other balance. The data processed in that interaction is the data described in sections 2.2 and 9 for advertising and measurement.
5.2 Who is filmed
The cameras capture people who are on the court. This includes VISU users and also people who do not have a VISU Account, including companions, bystanders within the frame, and, where the venue allows minors on site, children and adolescents. A person may be identifiable by their image even without a VISU Account.
5.3 On-site notice and division of roles
The Partner Venue is responsible for maintaining visible on-site notice that the area is monitored and recorded by VISU Replay, before entry into the playing area. The venue is also responsible for collecting the enrollment authorizations and for informing visitors about the recording.
VISU is responsible for operating the platform, for storage, and for the controls described in this Policy.
In the shared VISU Replay operations, VISU and the venue are joint controllers and answer to you and to the ANPD within the limits of the division agreed between them; for each party's own processing, each answers separately as an independent controller. You may exercise your rights against either of them, and the party you contact will forward the request to the other where needed. The contractual division of responsibilities between VISU and the Partner Venue organizes the work between the two; it does not reduce the rights of the data subject and does not remove responsibilities assigned by law to either party.
To exercise rights, use [email protected] or the Partner Venue's reception.
5.4 Rights of non-users
If you appear in a recording and do not have a VISU Account, you have the same rights described in section 12, including access, objection, and erasure, to the extent applicable law grants them.
To request removal of a Clip, use the report button available on the Clip itself, which opens a case in the moderation queue, or write to [email protected]. To help us locate the recording, tell us the venue, the date, and the approximate time. We may request additional information to confirm that you are the person depicted, and we may decline requests we cannot verify or that would affect the rights of others.
On receiving a valid request, we may remove the Clip, disable the public link, or restrict access. Recordings in the temporary buffer expire automatically according to the schedule in section 10.
5.5 Children and adolescents
VISU Accounts are intended for people aged 18 or over. Even so, children and adolescents may be captured by the cameras at Partner Venues, whether as players or as companions or bystanders within the frame.
Basis for the capture. The capture of images of children and adolescents relies on the enrollment agreement entered into between the Partner Venue and the legal guardian, which must contain a specific and highlighted authorization. That authorization must clearly cover live streaming, DVR buffer recording, the generation of Clips by platform users, downloading, sharing, display on a public profile, contest participation, and the possibility of wide distribution of the content. Added to this are the visible on-site signage and the notice to visitors, both the responsibility of the venue. There is no clip-by-clip consent collection.
In all cases, the best interest of the child and the adolescent prevails over other purposes. Article 14 of the LGPD requires that the processing of children's and adolescents' data be carried out in their best interest, and ANPD Enunciado 1 recognizes that such processing may rely on legal bases other than the guardian's consent, provided it is preceded by an assessment of the best interest in the specific case.
Separate purposes. The operation of VISU Replay, that is, streaming, recording, and allowing participants to generate and share Clips of their own matches, is a purpose distinct from promotional use. Using a child's or adolescent's image in promotional material, an advertising Campaign, or a marketing piece by VISU or by the venue depends on the legal guardian's own authorization, collected separately and specifically for that purpose. The functional license that the creator of a Clip grants to VISU, described in Section 12.7 of the Terms of Use, does not authorize that promotional use, and no one grants rights over the image of other people who appear in the Clip.
VISU's commitments. VISU will not use profiling, behavioral data or inferred characteristics to target commercial advertising at children or adolescents. We do not use facial recognition and we do not generate biometric templates from the recordings. We do not commercialize biometric data. Removal requests involving children and adolescents are handled with priority over others.
The legal guardian, or the adolescent themselves, may request removal of the content through the channels in section 5.4. Once the request is granted, we remove the content from the surfaces VISU controls, which includes the Clip, the public link, the thumbnail, and its display on a profile or in a contest. VISU cannot erase copies that third parties have already downloaded or redistributed outside the platform, but we cooperate with the requester in identifying and notifying those copies as far as possible.
Specific legislation. Lei 15.211/2025, known as the Digital Statute of the Child and Adolescent, has been in force since 17 March 2026 and was amended by Lei 15.352/2026. It applies to services likely to be accessed by children and adolescents and requires risk mapping and an impact report covering that processing. As verifiable commitments, VISU maintains a reporting channel with priority for requests involving children and adolescents, a challenge procedure for anyone whose content has been taken down, and a record of each takedown or retention decision in an audit trail.
5.6 Facial recognition
VISU does not use facial recognition and does not generate biometric identification templates from VISU Replay recordings.
6. Security, anti-fraud, device signals, and automated review
To protect users, advertisers, partners, and the rewards system, we process security and anti-fraud signals, including device, account, usage, location, referral, and campaign data.
6.1 Device signals and clustering
We record a device identifier in irreversible form, along with IP address, user-agent, action type, authentication method, and approximate location derived from the IP. These records are clustered to identify when multiple accounts share the same device or the same network.
Where a cluster indicates a strong likelihood that distinct accounts belong to the same person, the system may flag a likely common owner for review by authorized staff. This inference is used only for fraud prevention and reward integrity. It is not used for advertising and does not constitute advertising consent. Legal basis: legitimate interests in fraud prevention and, where applicable, legal obligation.
6.2 Automated review
Some fraud and reward-integrity decisions may be automated or semi-automated, including reward blocking, Account suspension, or a requirement for additional verification. Where required by applicable law, you may request human review or contest a decision by contacting [email protected] or the support channels.
Anti-fraud processing is separate from advertising consent.
7. Advertising and consent on web and app
7.1 Web
On the web, advertising and analytics follow the categories, region logic, and standing privacy signals described in section 4 and in the Cookie and Tracking Policy.
7.2 Mobile apps
In the mobile apps, we use Google's User Messaging Platform (UMP) to collect or renew the advertising consent required in your region.
On iOS, the system displays the App Tracking Transparency (ATT) prompt. If you do not allow it, we do not use the device advertising identifier for personalized advertising, and the ads shown may be contextual or non-personalized.
On Android, the app declares the advertising identifier permission so the ads system can operate according to your choices and system settings. You can reset or limit the advertising identifier in your operating system settings.
Our ads are served through Google AdMob, which may use mediation partners to fill ad slots. The mediation partners currently integrated in the app are Unity Ads and Liftoff Monetize, also known as Vungle. These partners may process device identifiers and ad data under their own policies and according to your consent state.
You can also control advertising identifiers and privacy settings through iOS or Android settings. VISU respects applicable platform controls and privacy signals.
8. Sharing and disclosure
We do not sell your personal data for money.
We may share personal data with trusted providers and partners where needed to operate the Service, as listed in the sub-processor table in section 9, and also with professional advisers, auditors, lawyers, and compliance providers; Campaign partners, merchants, advertisers, or referral partners where needed to operate Campaigns, validate rewards, or prevent fraud; Partner Venues, with respect to VISU Replay, under the division of roles described in section 5; authorities, regulators, courts, law enforcement, or other parties where required by law or necessary to protect rights, safety, fraud prevention, or legal claims; and successors in connection with a merger, acquisition, financing, reorganization, sale, or asset transfer.
Some privacy laws define “sale”, “sharing”, or “targeted advertising” broadly. Where those laws apply, VISU will honor applicable opt-out rights and recognized signals such as GPC, as described in this Policy and in the Cookie and Tracking Policy.
Content you make public, such as a Clip with a public link or a public profile, may be accessed by anyone who has the link.
9. Sub-processors and third parties
The table below lists the categories of third parties that process personal data on VISU's behalf or receive data in the context of the Service.
| Third party | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (S3, SES, SQS, Translate) | Hosting, media storage with signed URLs, email delivery, queues, and offer content translation | Content, Replay media, logs, account data, email address |
| Cloudflare | Replay media storage, content delivery, protection and country-level geolocation at the edge | Replay media, IP address, approximate country, request headers |
| Google AdMob and Google User Messaging Platform | In-app advertising and advertising consent collection | Device and advertising identifiers, ad data, consent state |
| Unity Ads | In-app advertising mediation | Device and advertising identifiers, ad data |
| Liftoff Monetize (Vungle) | In-app advertising mediation | Device and advertising identifiers, ad data |
| Google Analytics and Google Tag Manager (when active) | Usage analytics, subject to consent | Pseudonymized identifiers, usage events |
| Firebase Cloud Messaging | Push notification delivery | Push token, basic device information |
| Google and Apple | Social login and platform services | Account identifiers, email, name |
| Apple | App Tracking Transparency and in-app purchases | ATT authorization state, transaction data |
| Stripe | Payment and subscription processing | Payment and transaction data |
| NOWPayments | Processing of $VISU purchases in cryptocurrencies | Payment identifier, wallet address and network, transaction amount and status |
| KlinkLabs, Torox, ayeT-Studios | Offerwall and offer completion confirmation | Pseudonymized user identifier, completion events |
| AppsPrize, CPX Research, RevU, Wannads *(integration inactive)* | Discontinued offerwall. No data is shared today | None |
| Admitad (when active) | Coupon catalog and affiliate offers | Offer and click metadata |
| MapTiler | Place maps in discovery | Map requests, approximate coordinates |
| ip-api.com | Anti-fraud signal enrichment via IP geolocation | IP address, approximate country, region, and city |
| WordPress | Institutional blog at visu.network | Blog browsing data |
Pix purchases do not go through a third-party processor: payment is received into a VISU bank account and checked manually by authorized personnel, and receipt data is handled internally. Additional payment, withdrawal, wallet, KYC, sanctions, and fraud prevention providers may be used as needed to operate these flows and meet legal obligations. An offerwall provider may be added or removed based on commercial availability, and the list above reflects the providers integrated as of this date.
10. Target retention periods
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
The periods in the table below are target periods, not guarantees of deletion on a fixed date. Content and records may be kept for as long as they are necessary to provide the Service, to investigate disputes, to prevent fraud, or to comply with legal obligations.
| Data category | Target retention period |
|---|---|
| Continuous camera recording (DVR buffer) | The raw recordings used as an operational buffer are kept for a reduced period, normally up to 24 hours, or for a shorter period depending on the infrastructure and the storage capacity of the venue. The content is automatically overwritten or deleted. Clips that are created or saved have their own retention periods. |
| Generated clips | Period of 7 days. Clips that are favorited, exported, or entered in a contest are protected from purge, with a 3-day grace period after the contest. The purge deletes the files and keeps a residual control record. |
| Clip thumbnails | Thumbnail records removed within 48 hours by a daily routine already active; the thumbnail itself follows the corresponding clip |
| Export files | For as long as the source clip exists. The download link is signed and expires within minutes |
| Paid clip access entitlement | For the period stated in the feature. When expiry enforcement is not active, access may remain available for a longer period. |
| Account and profile data | While the account exists, plus any applicable legal, security, or compliance period |
| Identity document and KYC | As required for compliance, fraud prevention, and sanctions, often 5 to 10 years |
| Wallet, rewards, payments, and transactions | As required for accounting, tax, legal, and compliance purposes |
| Cookie consent records | Append-only, kept while the account is active, plus the legal evidence period. The consent record is valid for 365 days: after that, the choice is treated as unanswered and we ask you to choose again. This period is the validity of the choice, not the deletion of the record |
| Device and anti-fraud signals | As long as needed for security, abuse prevention, legal claims, and compliance. City, region, and coordinates derived from the IP are anonymized within 90 days, and login attempts are removed within 30 days, by weekly and daily routines already active |
| Consent and engagement audit records | 365 days, applied by a routine already active |
| Administrative audit records | 365 days, applied by a monthly routine already active. Records older than 365 days are deleted |
| Product analytics events | Events that are linkable to a person or pseudonymized are retained for 24 months and are subject to a scheduled purge routine. Data that is truly aggregated and anonymized, with no possibility of re-identification, is not subject to this limit. |
| Reports and content moderation | Report origin identifiers, such as IP address and device hashes, have a target period of 90 days. The email address of a reporter without an account has a target period of 90 days after the case is closed. The corresponding automated routine still depends on activation and validation, so these periods are targets and not deletions already being applied. The core of the case, which brings together the report record, the decisions, the actions applied, the communications, the appeals, and the audit trail, is kept for the period necessary to handle the case, to allow an appeal, to comply with legal obligations, and to exercise or defend rights. |
| Push notification tokens | While the token remains valid and active, deactivated when invalid or revoked |
| Support communications | As needed for support, legal, and audit purposes |
| Technical and security logs | Operational, security, debugging, and compliance periods |
When retention is no longer necessary, we securely delete, anonymize, aggregate, or archive the data. Some signals, such as IP addresses, may be truncated or anonymized earlier where appropriate.
11. International transfers
VISU is based in Brazil, and our service providers may process data in Brazil, the United States, the European Economic Area, or other countries.
Where required, we use appropriate safeguards for international transfers, such as contractual protections, Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms.
12. Your rights
Depending on your location and applicable law, you may have the right to confirm whether we process your data; access your personal data; correct incomplete, inaccurate, or outdated data; request erasure or anonymization; request portability; restrict or object to certain processing; withdraw consent; request information about sharing; opt out of certain advertising, sale, sharing, or profiling activities where applicable; request review of certain automated decisions where required by law; and lodge a complaint with a data protection authority.
These rights also apply to people filmed by VISU Replay who do not have a VISU Account, as described in section 5.4.
In Brazil, you may contact the ANPD. In the EU/EEA, you may contact your local data protection authority.
Account deactivation. You can deactivate your Account directly in the Service, without contacting support. Deactivation ends access, removes the profile from public surfaces, and deactivates associated Campaigns. It is not, in itself, a permanent erasure: we keep records associated with the Account, such as email address, username, balances and Wallet history, and media already generated, so that the Account can be restored and so that we can meet retention obligations. Deactivation makes your password unusable: the previous password no longer authenticates. A deactivated Account can be restored by signing in with Google or Apple, or by asking support.
The Account may be restorable for a period after deactivation, including by signing in again with Google or Apple.
You can request the erasure of specific data, not only the deactivation of your Account. Write to [email protected] describing what you want erased. Each request is assessed case by case, weighing the right to erasure against the legal retention duties that fall on VISU, among them fraud prevention, tax and accounting obligations, sanctions screening, and defense in disputes. We will grant the request to the extent that no legal basis requires the data to be kept, and we will explain what had to be kept and why. Records retained for those reasons follow the periods in section 10 and are then deleted or anonymized.
To exercise rights, contact [email protected]. We may need to verify your identity before responding. We handle requests without undue delay and, where immediate handling is not possible, within the periods of art. 18 of the LGPD. The complete declaration confirming the existence of processing, or giving access to the data, is provided within 15 days, as required by art. 19 of the LGPD. Under the GDPR, the general response period is 30 days, unless another legal deadline applies.
13. Security and internal access
We use technical and organizational measures designed to protect personal data, including encryption in transit using SSL/TLS; encryption at rest for identity documents; irreversible or pseudonymized identifiers where appropriate; signed, time-limited URLs for media access; access controls and least-privilege permissions; and regular security and privacy reviews.
Staff access to sensitive data, including identity documents, IP addresses, user-agents, consent history, and fraud cases, is restricted to authorized personnel, requires an elevated administrative role, and is recorded in an audit trail. Document changes are logged without plain-text values.
We assess security incidents involving personal data in order to measure the risk and the potential harm to data subjects. Where an incident may cause risk or relevant damage, we notify the ANPD and the affected data subjects within the applicable deadline, including the 3 working day deadline set by Resolução CD/ANPD 15/2024 where it applies to the case. We keep an internal register of incidents, with the measures adopted, for the legal period, of at least 5 years.
No method of transmission or storage is completely secure. We work to protect your data, but we cannot guarantee absolute security.
14. Children and adolescents
VISU Accounts are intended for users aged 18 or over. We do not knowingly collect personal data from children and adolescents for account purposes. VISU will not use profiling, behavioral data or inferred characteristics to target commercial advertising at children or adolescents.
Children and adolescents may be captured in VISU Replay recordings made at Partner Venues. Section 5.5 sets out the full regime that applies, including the basis for the capture, the separation between Replay operation and promotional use, VISU's commitments, and how to request removal.
If you believe a minor has provided personal data to VISU, or that an image of a minor needs to be removed, contact [email protected] and we will take appropriate steps.
15. Third-party links and services
The Service may contain links to third-party websites, apps, merchants, advertisers, wallets, exchanges, or services. We do not control their privacy practices. Those third parties' privacy policies and terms apply.
When you use Google, Apple, payment providers, wallet providers, advertising partners, offerwall providers, or other third-party services, those parties may process your data under their own policies.
16. Changes to this Policy
We may update this Policy from time to time. The effective date will be shown above.
For material changes, we may provide additional notice and, where required, request renewed acceptance or consent. Minor changes take effect when published.
Each version is dated and versioned.
17. Contact
Privacy requests, data rights, and DPO: [email protected]
Removal of your image from a VISU Replay recording: use the report option on the Clip or write to [email protected].
Supervisory authorities: Brazil: ANPD, www.gov.br/anpd. EU/EEA: your local data protection authority.
VISU Network Ltda. CNPJ 54.954.885/0001-97. Balneário Camboriú/SC, Brazil.
© 2026 VISU Network. All rights reserved.
Version 3.0 · Effective September 4, 2026