Governance

Policies & Privacy

Last updated:

This page describes how Perstein Labs (“Perstein”, “we”) operates as a remote-first company, how we handle personal data, and which regional rules apply in the European Union (with focus on Portugal, France and Spain), Brazil and the United States. It covers our public website, contact forms, product surfaces and related services.

Back to home

1. Scope and controller

Controller: Perstein Labs. Public contact for privacy requests: [email protected]. Commercial contact: [email protected].

These policies apply to visitors of perstein.com, people who contact us, candidates, customers, and users of Perstein Cloud, CLI, Desktop, Orbit Workspace and related services, unless a customer contract states otherwise for tenant-controlled data.

When a customer uses Perstein to process data of their own end users or employees, that customer is typically the controller of that content; Perstein acts as processor under the applicable agreement and data processing terms.

2. Work & remote policy

Perstein is remote-first. Day-to-day work, delivery and collaboration happen online. We do not require daily or weekly office attendance.

We maintain optional hubs in Braga (Portugal) and São Paulo (Brazil) for workshops, onboarding, team gatherings and in-person collaboration when it adds value. Presence at a hub is optional, never a routine control mechanism.

Hiring and employment follow the applicable law of the engagement (local labor rules, contracts and tax residency). Time zones are coordinated explicitly; async-first communication is the default, with scheduled sync when needed.

  • Default workplace type: Remote
  • Optional hubs: Braga, Portugal · São Paulo, Brazil
  • No mandatory office days as a company policy

3. Personal data we collect

Depending on how you interact with us, we may process:

  • Identity and contact data (name, email, phone, company, role)
  • Communication content (messages, support tickets, meeting notes)
  • Technical data (IP address, device/browser signals, approximate location derived from IP, logs)
  • Usage and product telemetry needed to operate, secure and improve the service (with privacy filters where applicable)
  • Account and authentication data when you use signed-in product surfaces
  • Billing and contract data for customers (invoicing entity, tax IDs when required)
  • Candidate data when you apply or interview with us

4. Purposes and legal bases

We process personal data to respond to inquiries, provide and secure the service, fulfill contracts, meet legal obligations, improve product quality with evidence (not unchecked profiling), and communicate about Perstein when permitted.

Legal bases depend on the region and context: consent (for example marketing or optional cookies), contract performance, legitimate interests balanced against your rights (security, product improvement, B2B outreach where lawful), and legal obligation (tax, accounting, regulatory requests).

5. Sharing and processors

We do not sell personal data. We share data with processors that help us run infrastructure, email, analytics, payments and support — under contracts that require confidentiality and appropriate security.

We may disclose data when required by law, to protect rights and security, or in a corporate transaction with safeguards. Tenant content remains under the customer’s instructions except where law requires otherwise.

6. Retention and security

We keep data only as long as needed for the purpose, contract and legal retention rules, then delete or anonymize it.

Security follows a Zero Trust posture: encryption in transit and at rest where applicable, least privilege, tenant isolation, auditability, and minimization of sensitive data in logs. No security measure is absolute; report suspected issues to [email protected] or [email protected].

7. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, objection to certain processing, and withdrawal of consent. You may also lodge a complaint with a supervisory authority.

To exercise rights, email [email protected] with enough detail to verify your request. We respond within the timelines required by the applicable regime (for example GDPR / LGPD).

8. European Union — Portugal, France and Spain (GDPR)

For people in the EEA/UK, processing is governed by the GDPR (and UK GDPR where applicable). Portugal, France and Spain apply GDPR through their national authorities and complementary local rules.

Supervisory authorities (examples)

You may contact your local data protection authority, including:

  • Portugal — Comissão Nacional de Proteção de Dados (CNPD)
  • France — Commission Nationale de l’Informatique et des Libertés (CNIL)
  • Spain — Agencia Española de Protección de Datos (AEPD)

International transfers

When personal data leaves the EEA/UK, we use appropriate safeguards such as adequacy decisions or Standard Contractual Clauses (SCCs), plus transfer assessments where required.

Special categories and automated decisions

We do not seek special-category data via the marketing site. We do not make solely automated decisions with legal or similarly significant effects about website visitors without a lawful basis and required safeguards.

9. Brazil — LGPD

For processing subject to Brazilian law, we follow the Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018).

Data subjects in Brazil may exercise LGPD rights (confirmation, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent, among others) via [email protected].

You may also contact the Autoridade Nacional de Proteção de Dados (ANPD). Our optional hub in São Paulo does not change the remote-first operating model nor expand data collection beyond what is described here.

10. United States — state privacy laws

Depending on your state of residence, laws such as the California Consumer Privacy Act (CCPA) as amended by the CPRA, and similar state statutes, may grant rights to know, delete, correct, and opt out of certain sharing or targeted advertising.

Perstein does not sell personal information as “sale” is commonly defined. If we ever engage in “sharing” for cross-context behavioral advertising, we will provide a clear opt-out. We do not knowingly discriminate against you for exercising privacy rights.

US residents can submit requests to [email protected]. We will verify identity as required and respond within statutory timelines. Authorized agents may submit requests where the law allows, with proof of authorization.

11. Cookies and similar technologies

We use strictly necessary cookies and similar technologies to operate the site and remember essential preferences (for example locale). Analytics or marketing technologies, if enabled, are used under the consent rules of your region.

You can control cookies through your browser settings. Blocking some cookies may affect site functionality.

12. Children

Perstein services are directed to professionals and organizations. We do not knowingly collect personal data from children under the age required by local law (for example under 13 in the US, or the digital consent age in the EU). If you believe a child provided data, contact [email protected] so we can delete it.

13. Changes

We may update this page to reflect product, legal or operational changes. The “Last updated” date at the top will change. Material changes that require notice or new consent will be communicated as required by law.

Consent version reference used in contact capture: privacy-2026-07.

Privacy contact

For privacy requests, DPO-style inquiries, or questions about this page, email us. We treat these requests as first-class operational work.

Email: [email protected]

Commercial: [email protected]