Data Protection

Privacy Policy

This Policy explains how Rainy Day Logic collects, uses, shares, and protects personal data in connection with its data provider services — both Client data and third-party data contained in the marketed datasets.

1. Controller and Data Protection Officer (DPO)

Controller: self-employed individual (sole proprietor), operating under the Rainy Day Logic brand. LGPD (Art. 5º, VI) admits a natural person as a data controller — the absence of CNPJ does not exempt from the law's obligations. Full civil identification (name and CPF) is provided to the Client in the contract/tax document of each engagement, not published in this document for protection of the provider's own data.

Data Protection Officer (DPO): the controller themselves, contactable at solutions.rainydaylogic@outlook.com, responsible for responding to requests related to this policy and LGPD while the operation remains individual. A dedicated DPO must be appointed if the operation is formalized as a company.

2. Two Distinct Categories of Personal Data

It is important to distinguish:

(a) Client/platform user data: registration, usage, and communication information of those who contract our services. Processed according to sections 3–7 below.

(b) Third-party data contained in the datasets: names, CPF, and professional information of individuals listed as PEP, sanctioned, or linked to disreputable companies, originating from official public sources. These data are not collected from you, nor about you — they are the object of the compliance data service provided. We process this category based on legitimate interest and/or compliance with legal obligation (see Terms of Service, section 4).

3. Information We Collect (Clients)

We collect data necessary to operate the service: registration/account information, billing data, platform usage history, and communication preferences, collected via Databricks Marketplace or direct channels.

4. Origin of Compliance Data (Third Parties)

The datasets include public information about Brazilian entities, PEPs, and sanctions lists, sourced exclusively from official publications of government bodies. We do not create, infer, or enrich these data with additional sources beyond what the primary source already publishes.

5. Use of Information

We use Client data to: enable access to datasets, process payment, send operational updates, improve the service, and comply with legal and regulatory obligations. We do not sell Client personal data to third parties. The compliance data (category "b" above) is made available to paying Clients as the very object of the contracted service, under the restricted terms and purposes described in the Terms of Service.

6. Data Sharing

We share Client data with: infrastructure providers that operate the service (e.g., Databricks), payment processors, and when required by law or court order. We do not share Client data for third-party marketing purposes without explicit consent.

7. Data Security

We adopt reasonable technical and organizational measures — access control, auditable versioning, and infrastructure best practices — to protect data under our management. No internet transmission method is completely risk-free.

8. Retention

Client registration data is maintained for the duration of the contractual relationship and for the additional period required by tax/legal obligations. Compliance datasets follow the historical retention policy declared in each listing (e.g., versioned snapshots).

9. Data Subject Rights

If you are a Client of the platform: under LGPD terms, you may request access, correction, deletion, portability, or opposition to processing of your registration data, through solutions.rainydaylogic@outlook.com. We will respond within 15 business days, according to the LGPD deadline for simple requests.

If you are a data subject included in one of the datasets (e.g., listed in PEP or sanctions list): you have the right, under Art. 18 of LGPD, to request confirmation of processing and information about the origin of the data. As we reproduce information from an official public source, corrections of merit (e.g., contestation of a sanction) should be directed to the originating body; we update our base automatically at each synchronization with the source. Requests about how your data is processed by us can be made at solutions.rainydaylogic@outlook.com.

10. International Transfer

Data may be processed by infrastructure providers with operations outside Brazil (e.g., Databricks). We adopt the contractual safeguards available with these providers. If you are a Client outside Brazil, you access the datasets under your own responsibility regarding the data protection legislation of your jurisdiction.

11. Cookies

Our website may use cookies for usage analysis. You can disable cookies in your browser. Databricks Marketplace has its own cookie policy, independent of this one.

12. Changes

We may update this Policy periodically. Relevant changes will be communicated by updating the date below and, when applicable, direct notice to active Clients.

13. Contact

To exercise data rights or questions about this Policy: solutions.rainydaylogic@outlook.com

Last updated: July 2026