Privacy Policy
1. Who the controller is
The controller of your data is HYPEFLOW SOLUCOES B2G LTDA, trading as HYPEFLOWHUB, Brazilian company ID (CNPJ) 67.303.476/0001-72, registered at R Francisco Lindner, 534 — Centro, Joaçaba/SC, ZIP 89.600-000, Brazil. Contact for any privacy matter: contato@melook.app.
2. What data we collect
We collect the minimum needed to deliver the diagnosis:
- Email — given by you in the form or collected by Stripe at payment. It is where the dossier goes.
- Analysed domain — the site address you submit.
- Analysis result — score, evidence and prescriptions generated from the domain.
- Payment data — processed entirely by Stripe. We never receive or store card numbers.
- Access logs — IP address, date and time, used for security and to limit abuse.
3. What we use it for, and on what legal basis
Brazilian law requires a declared legal basis for each purpose. These are ours:
- Performing the service you contracted — running the analysis and sending the dossier. Legal basis: performance of a contract (art. 7, V).
- Processing payment and issuing invoices. Legal basis: performance of a contract and legal obligation (art. 7, II and V).
- Security, fraud prevention and usage limits. Legal basis: legitimate interest (art. 7, IX).
- Messages about the service you contracted. Legal basis: performance of a contract.
- News and content, when you ask for it. Legal basis: consent (art. 7, I), revocable at any time.
4. Who we share it with
We do not sell personal data. We share only with the providers needed to run the service, each under contract and with a limited purpose:
- Supabase — the database holding analyses and orders.
- Stripe — payment processing. It receives the email and the card data; we never see the card.
- Resend — delivery of the dossier and transactional email.
- Large language model provider — receives the public content of the analysed site to generate the diagnosis. It does not receive your email.
5. International transfer
Our infrastructure providers are outside Brazil, mainly in the United States. That means your data may be transferred and processed outside national territory. The transfer follows art. 33 of the LGPD and happens only with the providers listed above, all under contractual data protection commitments.
6. How long we keep it
- Dossier and analysis — while the account exists and for up to 12 months after, so you can consult the history.
- Payment data and invoices — 5 years, the tax and legal period.
- Access logs — 6 months, under art. 15 of the Brazilian Internet Civil Rights Framework.
- Contact email — until you request deletion, respecting the periods above.
7. Your rights
Brazilian law grants you, at any time and at no cost: confirmation that we process your data, access to it, correction of incomplete or outdated data, anonymisation or deletion of unnecessary data, portability, information about who we share it with, and withdrawal of consent. To exercise any of these, write to contato@melook.app. We reply within 15 days.
8. Security
Database access happens only from the server, with a service credential never exposed to the browser. Traffic is encrypted over HTTPS. Access to your dossier is proven by a single-use link sent to your email — there is no password to leak.
9. Cookies
We use a single cookie, to remember your chosen language. It does not identify people and is not used for advertising. We do not use third-party trackers for profiling.
10. Data protection officer (DPO)
Under art. 41 of the LGPD, the officer responsible for personal data processing at Melook is: [NAME TO BE DEFINED] — contato@melook.app. The officer is the channel between you, Melook and the Brazilian data protection authority.
11. Changes to this policy
When this policy changes materially we notify you by email before the change takes effect and update the date at the top. The version in force is always the one published on this page.
Terms of Use →