Privacy policy
Last updated: September 25, 2026
This policy explains how Surf Academy handles the personal data of Students, guardians, Teachers and Staff of the schools that use the app and the web panel, under Brazil's General Data Protection Law (Lei 13.709/2018 — LGPD).
1. Who the controller is
[LEGAL NAME], CNPJ [CNPJ], [ADDRESS] (“Surf Academy”, “we”).
Data Protection Officer (DPO): [DPO NAME] — [PRIVACY EMAIL].
Each surf school that uses Surf Academy also decides about its Students' and Staff's data; where that applies, the school is the controller and Surf Academy the processor.
2. What data we process
- Account: name, email, password (stored only as a hash), optional photo, passkeys, two-factor (2FA) and language.
- Student profile: birth date, level, goal, preferred spot and, for minors, the guardian's name and consent date.
- Training documents you upload, which may include an ID document, transcript and medical certificate (sensitive health data).
- Lessons: bookings, attendance, lesson plan, sea conditions, evaluations, teacher notes, feedback and progress by skill.
- Lesson photos and videos uploaded by the Teacher or by you.
- Chat messages with the school and Teachers, including attachments.
- Purchases and lesson packages: amount, payment method (Pix, card or boleto), installments and transaction reference.
- Technical data: IP address and browser/device of the session, audit records of account actions and the device's push notification token.
3. Why we use it and on what legal basis
- Providing the service (booking, media, progress, chat, payments): performance of a contract (art. 7, V).
- Account security, fraud prevention and audit records: legitimate interest (art. 7, IX) and legal obligation (art. 7, II).
- Use of your image in lesson photos and videos: consent (art. 7, I), which you can withdraw in the app at any time.
- Medical certificates and other health data: specific consent or protection of life and physical safety in sports practice (art. 11).
- Children's and teenagers' data: processed in the minor's best interest, with consent from a parent or guardian (art. 14).
- Notifications (lesson reminders, published media, messages): performance of a contract; you can turn them off in the app or on the device.
4. Device permissions
- Camera and photos: only when you record or pick a clip, photo or document to send, and to save lesson media to your gallery.
- Face ID / biometrics: optional, to unlock the app. Biometrics stay on the device; we only store whether the lock is on.
- Notifications: for reminders and school notices.
- We do not use your location.
5. Who we share it with
We do not sell personal data. We only share it with processors that help us run the service, under contract:
- Cloudflare (app and API hosting, storage of photos, videos and documents, email delivery and technical logs).
- Neon (PostgreSQL database).
- Expo and Google Firebase Cloud Messaging (push notification delivery and app updates).
- Resend (email delivery, as a fallback).
- The surf school you are enrolled in, and its Teachers, see the data needed for your lessons.
- If you connect an AI assistant (for example via MCP), it only accesses what your School Role allows, and only after you authorise it.
6. International transfers
Some processors handle data outside Brazil (for example in the United States and the European Union). In those cases we rely on the safeguards in art. 33 of the LGPD, such as contractual clauses.
7. How long we keep it
We keep data while your account is active or while it is needed for the purposes above. Purchase records may be kept in anonymised form for the period required by tax law. Access logs are kept for at least 6 months (Marco Civil da Internet, art. 15).
8. Your rights
At any time you can: confirm whether we process your data, access it, correct it, ask for anonymisation, blocking or deletion, portability, information about sharing, and withdraw consent (art. 18).
In the app, under Profile → Privacy, you can download a copy of your data, request deletion and manage image use. You can also write to [PRIVACY EMAIL]. We reply within 15 days. You may also complain to Brazil's data protection authority (ANPD).
9. Cookies
On the website we only use essential session and sign-in security cookies. We do not use advertising or analytics cookies. Your choice in the cookie notice is saved in your browser.
10. Security
We use encrypted connections (HTTPS), hashed passwords, optional passkeys and 2FA, short-lived media links and audit records. No system is 100% secure; if a relevant incident happens, we will notify you and the ANPD.
11. Changes
We may update this policy. The date at the top shows the current version; relevant changes will be announced in the app.