OSS365.APP Privacy Policy
OSS365.APP Privacy Policy
Version: 2.0
Effective date: July 19, 2026
This Policy explains how OSS365 APLICATIVOS INTEGRADOS DE GESTÃO PARA ESPORTES LTDA, CNPJ No. 48.686.576/0001-80, with registered office at Ribeiro No. 357, suite 202, Pilares, Rio de Janeiro/RJ, ZIP 20.750-092 ("OSS365"), processes personal data on the website, in the OSS365 Aluno and OSS365 Gestão applications, in portals, APIs, customer support, and related services.
This Policy is a transparency notice. Acknowledgment of it does not constitute generic consent. When the law requires consent — especially for optional purposes and sensitive data — it will be requested in a specific, prominent, and revocable manner.
1. Roles of OSS365 and academies
For data that an academy, school, club, or professional ("Client") registers and uses to manage students, guardians, instructors, staff, and its activity, the Client is, as a rule, the controller, because it defines the purposes and the essential elements of the processing. OSS365 acts as a processor, carrying out lawful instructions through the Platform.
OSS365 acts as a controller to administer its own clients and accounts, bill the subscription, provide support, protect the Platform, prevent fraud, comply with legal obligations, communicate changes, and improve the service within permitted limits.
Requests relating to data controlled by an academy may be forwarded to it. OSS365 will assist the Client in accordance with the LGPD and the contract.
2. To whom this Policy applies
It applies to website visitors, Client representatives and contacts, owners and managers, instructors and staff, students, parents or guardians, people who request a demonstration, support, or exercise rights, and users of public or authenticated areas.
3. Data we may process
Depending on the feature used and the Client's choices, we may process:
- identification and contact: name, email, phone, date of birth, identification document when necessary, photo, academy, and relationship;
- account and authentication: user identifier, password protected by hash, login provider, sessions, tokens, trusted devices, and access attempts;
- minors' and guardians' data: relationship, identity and contacts of the guardian, authorizations, and representation records;
- sports and academic data: modality, belt or rank, attendance, check-in, classes, schedules, performance, XP, achievements, ranking, assessments, and history;
- health: PAR-Q responses, restrictions, notes, and medical records entered in the appropriate feature;
- biometrics: biometric template or representation and records of consent and check-in attempts, if the Client enables the feature;
- financial and contractual: plan, subscription, invoices, charges, payments, PIX data, discounts, and related accounting records;
- content: photo, video, technique, post, comment, private lesson objective, file, and communication sent;
- support and communication: messages, tickets, preferences, notifications, emails, and service records;
- usage and security: IP address, date and time, route, event, logs, technical identifiers, errors, audit trails, and browser or application information;
- website analytics, after applicable preference: pseudonymous session identifier, page, referrer, device type, browser family, time zone, and approximate geolocation derived from the IP; the current inventory does not provide for storing a user ID in that flow.
We do not intentionally collect data beyond what is necessary. The Client and Users should avoid entering sensitive information in free-text fields or files when there is no need and legal basis.
4. Purposes and legal bases
We may process data to:
| Purpose | Usual legal bases, as applicable |
|---|---|
| create account, authenticate, provide features and support | performance of a contract or pre-contractual procedures |
| manage students, classes, attendance, progression, and payments under Client instruction | basis defined by the Client; performance of a contract and other applicable hypotheses |
| bill, account for, and retain mandatory documents | performance of a contract and compliance with a legal/regulatory obligation |
| security, audit, fraud prevention, and defense of rights | legitimate interest, performance of a contract, legal obligation, and regular exercise of rights |
| send transactional, legal, and security communications | performance of a contract, legal obligation, and legitimate interest |
| non-essential marketing and analytics | consent or another valid basis, with a preference mechanism when applicable |
| health, PAR-Q, and biometrics | specific and prominent consent or another hypothesis of art. 11 LGPD applicable to the case |
| image, video, ranking, and public profile | consent or another adequate basis defined with transparency; best interests for minors |
| respond to rights and authorities | compliance with a legal obligation, regular exercise of rights, and corresponding legal hypotheses |
| produce statistics and improve the service | legitimate interest, where appropriate, or effectively anonymized data |
Legitimate interest will be used only after assessment of purpose, necessity, balancing, and safeguards, and will not prevail over the data subject's rights and freedoms.
5. Children and adolescents
Processing must observe and give precedence to the best interests of the child and adolescent. We use language and controls appropriate to the context, limit data to what is necessary, and provide legal guardian flows.
The Client must verify the guardian and define the legal basis for each activity. Public or optional features — such as photo, video, ranking, social profile, and biometrics — require enhanced review and, when applicable, specific and verifiable consent from the guardian. We do not condition the minor's sports participation on the provision of unnecessary data.
Guardians may request access, correction, review of permissions, or removal of public exposure through the academy's or OSS365's channels, depending on who is the controller.
6. Health and PAR-Q
Health data are sensitive and receive restricted access. The PAR-Q is an informational screening, not a diagnosis or medical opinion. Processing must be limited to what is necessary for the stated purpose and use a hypothesis of art. 11 LGPD. When based on consent, it will be specific and prominent and may be revoked, without invalidating prior acts or preventing legally required retentions.
7. Biometrics
Biometrics are optional and should only be activated after assessment of necessity, proportionality, risk, and an alternative check-in method. The Platform records consent when that is the basis used, restricts access, and provides for elimination of the template in the deletion flow, subject to legal obligations. OSS365 does not sell biometric templates or use them for advertising.
8. Images, videos, ranking, and public areas
Image, voice, videos, publications, profile, and performance may be visible to other Users or to the public according to the applicable configuration and authorization. The corresponding screen must inform the scope before publication.
Ranking and public profile should include only those who have a valid basis for participation. The data subject or guardian may withdraw authorization or exercise objection when applicable; future display will be stopped within a reasonable time, although copies lawfully made by third parties outside OSS365's control may persist.
9. Cookies, local storage, and analytics
The website and applications may use local storage, cookies, tokens, and similar technologies for authentication, security, language, preferences, operation, metrics, and performance.
Strictly necessary technologies may operate without consent when permitted. Non-essential analytics or advertising should only be activated after the applicable choice. On the website, the user may accept, reject, or customize categories and change the choice. Blocking necessary technologies may prevent login or essential functions.
The website's own analytics retains, by default, pseudonymous events for up to 90 days, according to the current configuration. OSS365 does not declare cross-app and third-party website tracking for behavioral advertising in its native applications.
10. Sharing and sub-processors
We may share data, to the extent necessary, with:
- the Client controller and authorized Users of the same academy;
- providers of cloud, database, storage, email, notifications, authentication, security, payments, analytics, and support;
- consultants, auditors, and advisors subject to confidentiality;
- authorities, courts, and third parties when there is a legal obligation, valid order, or need to exercise rights;
- successors in reorganization, investment, acquisition, or transfer of the business, with adequate safeguards.
Providers receive only the data necessary and contractual protection obligations. The updated list or categories of sub-processors may be requested at privacidade@oss365.app. We do not sell personal data.
11. International transfer
Providers may process or store data outside Brazil. In such cases, we will adopt mechanisms and safeguards compatible with the LGPD and ANPD regulation, considering the country, the recipient, the contract, and the nature of the data.
12. Retention and elimination
We retain data only for as long as necessary for the purposes, the contract, the Client's valid instructions, security, and legal obligations. Criteria include the nature of the data, risk, statute of limitations, tax/accounting obligation, and Client configuration.
As current operational parameters:
- tokens follow their technical periods, and revoked sessions may be eliminated after 90 days;
- inactive push devices may be eliminated after 180 days;
- notifications may be retained for 90 days;
- website analytics is retained by default for 90 days;
- temporary exports are eliminated after the link expires;
- consents, acceptances, audit trails, and academic and financial records may be retained for proof, legal obligation, and exercise of rights, with minimization or anonymization when possible;
- biometric templates, relationships, preferences, and personal files are eliminated or dissociated in the applicable flow, subject to legal exceptions and backups in a secure cycle.
The Client may adopt its own periods for data under its control. Account deletion does not mean immediately erasing every record when retention is mandatory or necessary for rights; the data subject will be informed of the retained categories when applicable.
13. Security and incidents
We adopt measures proportionate to the risk, including access control, logical segregation by Client, authentication, encryption in transit, logs, backups, monitoring, vulnerability management, and response procedures.
In an incident that may cause relevant risk or harm, the controller will assess and carry out the communications required by the LGPD and ANPD regulation. When OSS365 is the processor, it will notify the Client controller without undue delay, with the available information, to support its decision. Incident records will be kept for the regulatory period.
Suspicions should be reported to support@oss365.app and privacidade@oss365.app.
14. Data subject rights
Within the limits of the LGPD, the data subject may request:
- confirmation of processing and access;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or elimination of unnecessary, excessive, or irregular data;
- portability, subject to regulation and commercial and industrial secrets;
- information about sharing and about consent;
- revocation of consent and elimination of data processed on that basis, subject to legal exceptions;
- objection to irregular processing;
- review of a decision made solely by automated processing that affects their interests;
- petition before the ANPD and consumer protection bodies, when applicable.
Authenticated users may use the available privacy and export features. It is also possible to write to privacidade@oss365.app. We may request additional data strictly necessary to confirm identity and prevent fraud. If the academy is the controller, we will forward or coordinate the request with it.
15. Automated decisions
The Platform may offer rules, indicators, gamification, ranking, and support automations. These features are not intended to decide, without adequate human review, on health, physical safety, fitness, sanctions, or relevant rights. When there is a solely automated decision that affects interests, the data subject may request information and review under the terms of the LGPD.
16. Communications and marketing
We send messages necessary for the account, contract, security, billing, and support. Promotional communications will respect the legal basis and offer unsubscribe. Withdrawal from marketing does not prevent essential transactional messages.
17. Data Protection Officer and privacy channel
OSS365 provides the channel privacidade@oss365.app for data subjects, Clients, and the ANPD. The identity and details of the Data Protection Officer (encarregado), when formally designated or required, will be published clearly. Any classification as a small-sized agent does not waive principles, data subject rights, or security measures.
18. Changes
We may update this Policy due to legal, operational, technical, or product changes. Material changes will be communicated by reasonable means. New consent will be requested when the change alters a purpose based on consent or when the law requires it. The public page will indicate version and effective date.
19. Contact
- OSS365 APLICATIVOS INTEGRADOS DE GESTÃO PARA ESPORTES LTDA
- CNPJ No. 48.686.576/0001-80
- Ribeiro No. 357, suite 202, Pilares, Rio de Janeiro/RJ, ZIP 20.750-092
- Privacy and LGPD: privacidade@oss365.app
- Support and incidents: support@oss365.app
- General contact: contato@oss365.app
- Website: https://oss365.app