Privacy Policy

Version 1.4 · in force since 2026-09-15

PortuguêsEnglishEspañol

This is a courtesy translation. The Brazilian Portuguese version is the only binding one; if the two diverge, the Portuguese text prevails. Portuguese version

In short

  • Nimbos is a project time tracking system. It records what you worked on — not what you do on your computer.
  • We do not use advertising cookies. There is one measurement cookie, from Google Analytics, and it is only written if you accept — the others are there to keep you signed in and to remember your language.
  • On the public site, we measure audience in an aggregated, cookie-free way — how many visits, where they came from, which pages were opened. If you accept measurement cookies, Google Analytics also measures — then with a browser identifier. Declining takes nothing away from the site.
  • We do not capture your screen, your location, the keys you type, the sites you visit or the applications you open. That does not exist in the product and is not planned.
  • If you use Nimbos because your company hired it, the one who decides about your data is your company, not us. Requests about your data start with them.

1. Who processes your data

Nimbos is operated by Gpk4 Tecnologia e Assessoria Empresarial LTDA (CNPJ 13.283.769/0001-06). There are two different situations, and they change who you should turn to:

On the public site (this page, the home page and the sign-in screen)

You are a visitor. Here Gpk4 Tecnologia e Assessoria Empresarial LTDA is the controller of the few browsing data described below, and you deal directly with us.

Inside the system, after you sign in

You use Nimbos because the company you work for hired it. In that relationship, your company is the controller — it was your company that decided to record working hours, who sees what and for how long — and Gpk4 Tecnologia e Assessoria Empresarial LTDA is the processor: we process the data following its instructions.

Practical consequence: requests to access, correct or delete your work data must be made to your company. If you come to us directly, we forward the request and let you know.

We do not ask for your consent to record working hours, and that is on purpose: in an employment relationship consent would not be freely given. The legal basis is your company’s compliance with its labor obligations and the performance of its contract with us.

2. What data we process

From those who only visit the site

  • The language you chose, if you chose one (cookie, item 3).
  • Aggregated audience measurement: visit count, page opened, country and referring site. Without cookies and without identifying you.
  • Only with your consent: Google Analytics receives the pages you opened on this site, the referring site, a browser identifier (the _ga cookie) and some interactions with the page — how far you scrolled, clicks on links leading away from the site, site search, video and file downloads. It does not receive what you type, nor who you are. Advertising signals are switched off by our own configuration.
  • On the sign-in screen, Cloudflare’s anti-fraud service receives your IP address and browser signals (item 4).

This page and the home page are served entirely from our own domain — fonts included. The ONLY request to a third-party server is Google Analytics, and it only happens after you accept: while there is no consent, the script never reaches your browser.

The WhatsApp button on the home page is a link: nothing leaves this site until you click it. If you do, the conversation happens inside WhatsApp, under Meta's policy — and whatever you write there is handled by Gpk4 Tecnologia e Assessoria Empresarial LTDA as a sales enquiry.

From those who use the system

  • Identification and employment link: name, corporate e-mail, access profile, employee number, job title, assigned projects.
  • Working hours and time entries: hours logged by project and task, a description of what was done, the overtime flag.
  • Time clock records: scheduled, worked, balance and the day’s punches, when your company integrates the time clock with Nimbos.
  • Absences: date, duration, type (vacation, medical certificate, day off and the like) and a free-text note filled in by your company.
  • Financial data of the engagement: cost per hour and billable rate. These are visible only to those your company has expressly authorized.
  • Technical session records: IP address and browser identification at the moment you sign in, for account security.
  • Audit trail: who changed what and when, in administrative operations.

About the absence type and note: some types (a medical certificate, for example) may reveal health information, which the LGPD treats as sensitive data. We process this only to comply with your company’s labor obligations, with restricted access. The note field must not receive a diagnosis, an ICD code or any clinical detail.

3. Cookies and storage in your browser

This is the complete list. There is no advertising, social network or profiling cookie. There is one identifier-based measurement cookie, from Google Analytics — and it only exists in your browser if you have accepted. The choice itself is also stored, so we do not ask again on every page.

NameWhat it is forDurationCategory
better-auth.session_token
in production, with the __Secure- prefix
Keeps you signed in after you enter. It only exists in the system, never on the site.7 daysStrictly necessary
better-auth.stateProtects sign-in through Microsoft or Google against route hijacking during the redirect.5 minutesStrictly necessary
better-auth.two_factorLinks the password to the code from the authenticator app. Issued only during two-step verification.10 minutesStrictly necessary
NEXT_LOCALERemembers the language you chose. Written only when you click the selector — not before.1 yearFunctional
nimbos-consentimentoStores YOUR choice about measurement cookies — including a refusal. Without it, the notice would appear on every page.6 monthsStrictly necessary
_ga
and _ga_<identifier>
Google Analytics: tells one browser from another to count visitors and sessions. Written only after you accept, and advertising signals are switched off by our own configuration.2 yearsMeasurement (depends on your consent)
nimb-oculto
local storage, not a cookie
Remembers that you hid the assistant bubble. It stores only the mark that it was hidden.Does not expire on its own — it goes away when you clear the browser data or when you bring the assistant backFunctional
nimbos.menu-lateralRemembers whether you left the side menu open or closed. It stores only that choice.1 yearFunctional
nimbos.primeiros-passos
local storage, not a cookie
Remembers that you dismissed the getting-started panel. It stores only the mark that it was dismissed.Does not expire on its own — it goes away when you clear the browser dataFunctional

We do not use sessionStorage or the browser’s local database.

All of the items above are strictly necessary or functional at your own request, and for that reason they do not depend on prior consent. That is also why we do not display a cookie notice: there would be no real choice to offer. If some non-essential cookie is ever added, it will come with a request for consent, before being written.

4. Who we share with

We do not sell data and we do not share it for advertising. We use the providers below to operate the service:

ProviderWhat forWhat it receivesWhere
SupabaseDatabaseAll of the system’s dataBrazil (São Paulo)
VercelHosting and audience measurement of the siteRequests to the site and to the system; aggregated audience, without identificationProcessing in São Paulo; company in the United States
Microsoft Entra ID / Google Workspace · Google AnalyticsCorporate sign-inName, e-mail and organization, according to your company’s providerAccording to your company’s contract with the provider
Cloudflare (Turnstile)Blocking automated sign-in attemptsIP address and browser signals, on the sign-in screenUnited States
apponte.meSource of the time clock records, when your company uses itTime clock records and absences, from the clock to NimbosBrazil
ClockifyImport of the history predating NimbosOld time entriesUnited States
SentrySystem error reporting, so we can fix themError message and stack trace. Cookies, headers and user identification are stripped before sendingUnited States
Meta (WhatsApp Cloud API)Sending Nimb reminders over WhatsApp, when your company uses the channelPhone number, first name, company name and the number of pending daysUnited States
Microsoft (OneDrive/SharePoint)Second copy of the daily backupA copy of the database, with the system’s dataPer the corporate agreement with Microsoft

Cloudflare’s anti-fraud service is loaded on every visit to the sign-in screen, and not only when a sign-in fails. It exists to protect accounts against automated password attempts.

5. International transfer

The database and the processing of the pages stay in Brazil, in São Paulo. That is where the system operates day to day.

Some of the providers above are foreign companies and do process data outside the country. There are three situations, and they carry different weight:

  • Request metadata, at Vercel, and the anti-fraud of the sign-in screen, at Cloudflare — technical browsing data.
  • Error reports, at Sentry (United States). Cookies, headers and user identification are stripped before sending, but an error message may carry fragments of data.
  • The second copy of the backup, on the corporate OneDrive used by the operation. This is the most relevant of the three, which is why it is spelled out: it is a copy of the database, and the exact storage location follows the corporate agreement with Microsoft.

We say this explicitly because “data in Brazil” without that caveat would suggest an absolute that the operation does not deliver.

6. How long we keep it

  • Working hours, time clock and absence data: for as long as your company’s contract with us lasts and for the periods that labor and tax law require.
  • Cookies: for the periods in the table in item 3.
  • Audit trail: kept for as long as the record of what was changed is necessary — see the caveat in item 7.
  • Audience measurement of the site: aggregated, without identification, according to the provider’s retention period.

Once the contract ends, the client company’s data is returned or deleted according to its instruction, except for what the law requires to be kept.

7. Your rights

The LGPD guarantees you the right to confirm whether we process your data, to access it, to correct it, to request anonymization or deletion, to know who we share it with and to withdraw consent where that applies.

If you use Nimbos through your company, the request starts with them, who are the ones deciding about this data. We follow their instructions and help with whatever is technical.

A limitation we would rather state up front: the audit trail — the record of who changed what — is immutable by construction. The database refuses changes and deletions on that table, including for us. This exists so that no one can erase their own tracks, and it is what makes the audit trustworthy. As an effect, a deletion request does not remove these records; they remain for as long as necessary to comply with a legal obligation and for the regular exercise of rights.

8. How we protect it

  • Access through your company’s corporate sign-in, with two-step verification on the accounts that use a password.
  • Isolation per company in the database itself: the separation between clients is enforced by the database, not only by the program.
  • Permission checked always on the server — hiding a button is never the protection.
  • Credentials for third-party systems are stored encrypted.
  • The technical operation records use internal identifiers and do not store name or e-mail.

9. What Nimbos does not do

By product decision, and not because we have not implemented it yet:

  • it does not capture your screen or take screenshots of your computer;
  • it does not track location;
  • it does not record the keys you type;
  • it does not monitor the sites you visit or the applications you open;
  • it does not measure productivity by keyboard or mouse time;
  • it does not use your data to train artificial intelligence models.

Nimbos records what you report having worked on. Workstation surveillance is outside the scope of the product.

10. Data protection officer

Questions, requests and complaints about personal data: contato@4win.com.br

You may also turn to the Autoridade Nacional de Proteção de Dados (ANPD).

11. Changes to this policy

When we change something relevant, we publish a new version with an effective date. The version and the date appear at the top of this page.

Back to home