Section 1
Introduction
The LGPD is Brazil’s general data protection law. This page describes how TimeNova’s practices are designed to align with LGPD principles; it is not a formal certification and does not replace the Privacy Policy or Data Processing Agreement.
Section 2
Controller and operator roles
For most workplace data, the customer organization acts as the controller ("controlador"), deciding why TimeNova is used and how monitoring is configured. TimeNova acts as the operator ("operador"), processing data under customer instructions.
Section 3
Legal bases
Customers select the legal basis appropriate to their own processing under LGPD, such as legitimate interest, contract execution, legal obligation, or consent, particularly for employee-monitoring features.
Section 4
Data subject rights
LGPD recognizes rights for data subjects, which TimeNova supports as follows:
- Confirmation of processing and access to workspace data through product features.
- Correction of incomplete, inaccurate, or outdated data by an administrator.
- Anonymization, blocking, or deletion of unnecessary or excessive data, subject to backup and legal-retention constraints.
- Portability of data to another provider, where technically feasible.
- Information about entities with which data has been shared, and the ability to revoke consent where consent is the applicable basis.
Section 5
Regulator and contact
Brazil’s data protection authority is the Autoridade Nacional de Proteção de Dados (ANPD). Questions about LGPD-related practices can be directed through official TimeNova support channels.
Section 6
International transfers
Cross-border transfer mechanisms are described on the Data Transfer Compliance page.
Section 7
Changes
TimeNova may update this page as LGPD guidance, product features, or sub-processors change.