Privacy Policy — MaiaWay
Your privacy is a priority for MaiaWay. This Privacy Policy describes, transparently, how we collect, use, share, and protect your personal data when you use the MaiaWay platform, accessible at maiaway.ai and its subdomains (the “Platform”), as well as our official WhatsApp communication channels.
This Policy is designed to comply, simultaneously, with the Brazilian General Data Protection Law (Lei nº 13.709/2018 — “LGPD”) and the European Union General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”). It applies to all users of the Platform regardless of location. Where the two regimes diverge, we apply the standard that is more protective of the data subject. Throughout this Policy, references to specific LGPD articles indicate, in parentheses, the corresponding GDPR articles where applicable.
By using the Platform, you acknowledge that you are aware of this Policy. If you do not agree with any of its provisions, we recommend that you do not use our services.
1. Who we are
MaiaWay is an AI-based career guidance platform offering CV and LinkedIn analysis, psychometric assessments, job-match recommendations, and human mentor follow-up. The Platform is operated by MaiaWay, as the Controller of your personal data (LGPD Art. 5, VI; GDPR Art. 4(7)).
Data Protection Officer (DPO):
Marcio El Kalay
Email: dpo@maiaway.ai
You may contact our DPO at any time to exercise your rights as a data subject or to clarify questions about this Policy. The DPO serves data subjects in Brazil and in the European Union alike.
2. Personal data we collect
- a) Account and identification data:
- full name, email, password (stored in encrypted form), phone number (when you activate WhatsApp access), date of birth (when provided), profile picture.
- b) Professional and career data:
- CV (file you upload and the structured version extracted by AI), LinkedIn profile (extracted via integration when you provide the link), professional history, academic background, certifications, languages, location, career goals, target roles and sectors.
- c) MAIA psychometric assessment data:
- answers to the 25-question questionnaire combining DISC, MBTI, and OCAI elements, and the personality report generated from them. These data may reveal inferences about personality traits — treated as sensitive personal data (LGPD Art. 5, II) and/or as special categories of personal data (GDPR Art. 9(1)) where applicable.
- d) Communication content:
- messages exchanged with our AI agents via WhatsApp or through the Platform, notes from mentor sessions, and feedback you provide.
- e) Technical and usage data:
- IP address, browser identifier, operating system, device model, language, time zone, pages visited, actions taken on the Platform, cookie identifiers (including marketing cookies such as
_fbp,_fbcfrom Meta, and_gafrom Google Analytics), and ad-click identifiers (such asfbclid,gclid,ctwa_clid). - f) Transaction data:
- when you purchase a paid plan, we process the transaction through Hotmart. We do not store credit or debit card data in our systems. We only receive confirmation of the purchase and the billing data required to issue an invoice.
3. How we collect
We collect your data:
- Directly from you, when you sign up, complete your profile, upload files, take the assessment, or chat with our agents;
- Automatically, through cookies and similar technologies, when you browse the Platform;
- From third parties, specifically Meta (when you start a conversation by clicking a WhatsApp ad), LinkedIn (via Apify, based on the public URL you provide), and social authentication providers (Google, when you choose to sign in with Google).
4. Purposes for which we use your data
- a) Provision of the contracted services:
- analyzing your CV and LinkedIn, generating career recommendations, running the psychometric assessment, identifying jobs that match your profile, enabling communication with mentors, and keeping your account functional.
- b) Personalization and experience improvement:
- tailoring content, language, and recommendations to your profile, saving your preferences, and maintaining the state of your journey on the Platform.
- c) Operational communications:
- sending transactional messages (sign-up confirmations, password recovery, updates on the status of your assessment or recommendation), and notifications about changes to the services or this Policy.
- d) Commercial and marketing communications (with your consent only):
- sending content about careers, Platform updates, and offers. You may opt out of these communications at any time without prejudice to your use of the Platform.
- e) Metrics, security, and continuous improvement:
- measuring Platform performance, identifying and preventing fraud and abuse, conducting A/B tests, and generating aggregated analytical reports (without individual identification).
- f) Compliance with legal and regulatory obligations:
- issuing tax documents, responding to requests from competent authorities, and retaining records for the periods required by law.
5. Legal bases for processing
We process your personal data on the legal bases set out in Article 7 of the LGPD and, for data subjects in the European Union, on the equivalent bases of Article 6 of the GDPR:
- Provision of the contracted services (purposes 4.a, 4.b, 4.c) — Performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
- Marketing and commercial communications (purpose 4.d) — Consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
- Metrics, security, and fraud prevention (purpose 4.e) — Legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)). For EU data subjects, we maintain a documented Legitimate Interests Assessment (balancing test), available on request to the DPO.
- Issuance of invoices and responses to authorities (purpose 4.f) — Compliance with a legal and regulatory obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
For sensitive data that may be inferred from your responses to the psychometric assessment (such as personality traits), processing takes place exclusively on the basis of specific and highlighted consent (LGPD Art. 11, I) or explicit consent (GDPR Art. 9(2)(a)), which you provide when starting the assessment. You may withdraw this consent at any time.
6. How we share your data
We do not sell your personal data. We share data with third parties only where strictly necessary. All operators/data processors listed below are bound by data processing agreements (LGPD Art. 39; GDPR Art. 28), with obligations of confidentiality, security, and use restricted to our instructions:
Infrastructure providers
- Amazon Web Services (AWS) — hosting (us-east-2 region, USA).
- Render — staging environment.
Artificial intelligence providers
- OpenAI, Anthropic, Google (Vertex AI / Gemini) — large language models for CV and LinkedIn analysis and report generation. Data is sent under contract with confidentiality and no-training-retention clauses, where this option is available.
Public-data extraction provider
- Apify — extraction of public LinkedIn data, only when you provide the URL of your profile.
Payments provider
- Hotmart — processing of paid-plan transactions. Payment data is handled directly by Hotmart under its own policy.
WhatsApp communications
- Meta (WhatsApp Business Platform) — delivery of messages between you and our AI agents.
Measurement and analytics
- Meta (Pixel + Conversions API) — conversion events for campaign optimization.
- Google Analytics 4 — Platform usage analysis.
- Microsoft Clarity — session recordings and heatmaps; fields containing personal data (email, name, phone, CV) are masked.
Public authorities: we may share data when required by law, judicial decision, or duly substantiated administrative request.
Corporate succession: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity under the same obligations as this Policy.
7. International data transfers
Part of the services we use are hosted outside Brazil and the European Economic Area (EEA) — in particular AWS (USA), AI providers (USA), and analytics tools (USA). We ensure that these international transfers take place on the basis of adequate safeguards:
- For data subjects in Brazil — under Article 33 of the LGPD, through standard contractual clauses, binding corporate rules, or processor adherence to recognized data-protection frameworks.
- For data subjects in the European Union — under Articles 44 to 49 of the GDPR, through Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914), adequacy decisions where applicable (for example, the EU-US Data Privacy Framework for certified vendors), and supplementary technical and organizational measures (encryption in transit and at rest, access controls). We conduct Transfer Impact Assessments where necessary.
Copies of the applicable SCCs and Transfer Impact Assessment documentation can be requested from the DPO.
8. How long we keep your data
- Active account data: for as long as your account remains active.
- Inactive account data: up to 24 months after your last interaction, after which your account may be anonymized or deleted.
- Communication content: up to 24 months, to preserve contextual continuity.
- MAIA assessment records: up to 36 months, to allow historical comparison.
- Transaction and invoice data: applicable legal period (minimum of 5 years for tax purposes).
- Technical and security logs: up to 12 months.
- Data after exercise of the right to erasure: removed within 15 business days (LGPD) or within one month, extendable by two additional months in complex cases (GDPR Art. 12(3)) — whichever is more favorable to you — except where retention is required by a legal obligation or for the regular exercise of rights.
After these periods, data is deleted or irreversibly anonymized.
9. Your rights as a data subject
The LGPD (Art. 18) and the GDPR (Arts. 15 to 22) guarantee you a broad set of rights over your personal data. The rights below apply to all users of the Platform. Where the GDPR grants a right with no direct equivalent under the LGPD (or vice versa), we indicate the applicable regime.
Rights common to LGPD and GDPR
- Confirmation and access to personal data being processed (LGPD Art. 18, I and II; GDPR Art. 15);
- Rectification of incomplete, inaccurate, or outdated data (LGPD Art. 18, III; GDPR Art. 16);
- Erasure of personal data (the “right to be forgotten”) (LGPD Art. 18, VI; GDPR Art. 17);
- Portability of data to another provider, in a structured, commonly used format (LGPD Art. 18, V; GDPR Art. 20);
- Restriction or blocking of processing of unnecessary, excessive, or non-compliantly processed data (LGPD Art. 18, IV; GDPR Art. 18);
- Objection to processing carried out on the basis of legitimate interest, direct marketing, or public interest (LGPD Art. 18, §2; GDPR Art. 21);
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing (LGPD Art. 8, §5; GDPR Art. 7(3));
- Review of automated decisions affecting your interests, with the right to explanation and human intervention (LGPD Art. 20; GDPR Art. 22).
Additional rights under the LGPD
- Anonymization of unnecessary or excessive data (LGPD Art. 18, IV);
- Information about the public and private entities with which we share your data (LGPD Art. 18, VII);
- Information about the possibility of withholding consent and the consequences of doing so (LGPD Art. 18, VIII).
To exercise any of these rights, contact us through the channels in Section 13. We will respond within a maximum of 15 business days (LGPD) or one month, extendable by two additional months in complex cases (GDPR Art. 12(3)) — whichever is more favorable to you.
Right to lodge a complaint
If you believe your rights have not been properly addressed:
- In Brazil — file a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD): www.gov.br/anpd.
- In the European Union — file a complaint with the supervisory authority of your Member State of habitual residence, place of work, or place of the alleged infringement (GDPR Art. 77). The official list of EU supervisory authorities is available at the European Data Protection Board (EDPB): edpb.europa.eu.
10. Automated decisions and use of artificial intelligence
MaiaWay uses AI models to generate career analyses, recommendations, and reports. This processing may qualify as automated decision-making under Article 20 of the LGPD and Article 22 of the GDPR. You have the right to:
- Request clear and adequate information about the criteria and procedures used in the automated decision (LGPD Art. 20, §1; GDPR Arts. 13(2)(f) and 15(1)(h));
- Request human review of automatically generated decisions and recommendations affecting your interests (LGPD Art. 20; GDPR Art. 22(3));
- Express your point of view and contest the decision (GDPR Art. 22(3)).
To exercise these rights, simply send a request to the DPO.
Important: AI-generated analyses and recommendations are advisory and informational in nature. They do not replace certified professional advice in human resources, psychology, labor law, or vocational counseling. Career decisions are your sole responsibility.
11. Children and adolescents
The Platform is intended for users aged 18 or older. We do not intentionally collect data from individuals under 18. This threshold exceeds the minimums established by both the LGPD (Art. 14, which requires specific parental consent for the processing of data of children and adolescents) and the GDPR (Art. 8, which sets the minimum age of consent for information-society services between 13 and 16 years, depending on the Member State). If we identify a minor’s registration without parental consent, we will remove the data immediately.
12. Cookies and similar technologies
We use cookies to: keep your session active after login (strictly necessary); remember your language preferences and settings (functionality); measure performance and aggregate usage (analytics); measure the effectiveness of advertising campaigns (marketing — with your consent only).
For users in the European Union and the United Kingdom, non-strictly-necessary cookies (analytics and marketing) are placed only after prior, granular consent, in accordance with the ePrivacy Directive and applicable local regulations (e.g., PECR in the United Kingdom, LSSI-CE in Spain).
You may manage your cookie preferences at any time through the banner shown on first access or through your browser settings. Disabling strictly necessary cookies may impair the functioning of the Platform.
13. How to exercise your rights and contact us
Data Protection Officer (DPO): Marcio El Kalay — dpo@maiaway.ai
General contact: contato@maiaway.ai
We will respond within a maximum of 15 business days (LGPD) or one month, extendable by two additional months in complex cases (GDPR Art. 12(3)) — whichever is more favorable to you.
Data subjects in the European Union may also file a complaint with the supervisory authority of their Member State — see Section 9.
14. Security
We adopt reasonable technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction (LGPD Art. 46; GDPR Art. 32), including: password encryption; HTTPS/TLS across the Platform; role-based access control (RBAC); continuous monitoring (Sentry, Microsoft Clarity); periodic backups; and ongoing vendor assessment. In the event of a security incident affecting your data, we will notify you, the ANPD, and/or the competent EU supervisory authority within the periods required by law (LGPD Art. 48; GDPR Arts. 33 and 34 — typically 72 hours to the authority).
15. Changes to this Policy
We may update this Policy from time to time. The version in force is always the one published on this page, with the date of last update and the version number indicated at the top. Material changes will be communicated at least 15 days in advance by email or by a prominent notification on the Platform.
16. Applicable law and venue
This Policy is governed by Brazilian law, in particular the Brazilian General Data Protection Law (Lei nº 13.709/2018), the Brazilian Internet Civil Framework (Lei nº 12.965/2014 — “Marco Civil da Internet”), and the Brazilian Consumer Protection Code (Lei nº 8.078/1990), where applicable.
For data subjects residing in the European Union, the processing of personal data is additionally governed by the General Data Protection Regulation (Regulation (EU) 2016/679 — GDPR) and any further data-protection rules applicable in the relevant Member State. Nothing in this Policy limits the rights guaranteed by applicable consumer-protection legislation or by mandatory jurisdiction rules in favor of the data subject.
The courts of the Judicial District of the Capital of the State of São Paulo, Brazil, are elected to resolve any matters arising from this Policy, without prejudice to the right of EU data subjects to bring proceedings in the courts of their place of domicile where applicable under mandatory local law.