Last updated: May 22, 2026
This Policy describes how Didata collects, uses, stores, shares, and protects personal data when the User accesses the educational digital application that uses Artificial Intelligence resources to generate study content and automatically evaluate activities.
| Category | Examples | Collection Method |
|---|---|---|
| Registration Data | full name, email, password | provided by the User during signup |
| Usage Data | access logs, interactions, generated content, activity results | collected automatically by the Platform |
| Device Data | browser type, operating system, IP address, device identifiers | collected through cookies and similar technologies |
| Communication Preferences | opt-in or opt-out for marketing, categories of interest | provided by the User or inferred from usage |
Note: The Platform is not intended for minors under 18 without consent from legal guardians. Irregular accounts may be blocked.
When the User chooses to connect Google Calendar, Didata requests the https://www.googleapis.com/auth/calendar.events.owned permission to create, view, change, and delete events on Google calendars owned by the User. The connection is optional and occurs only after authorization through Google's consent flow.
Didata uses data received from Google Calendar only to provide and improve the visible user-facing feature that syncs the study plan with the User's calendar. This includes creating study blocks, updating the times, descriptions, and statuses of those blocks, and removing events created by Didata when the User disables the integration, deletes a plan, or deletes the account.
Didata may store identifiers of events created in Google Calendar, start and end times, time zone, title, description, synchronization status, last synchronization date, synchronization errors, and metadata needed to match the study plan in the Platform with events in Google Calendar. Didata may also store authorization metadata needed to maintain the connection with the Google account while the integration is active.
Didata does not use Google Calendar data for advertising, retargeting, personalized ads, sale of data, credit analysis, or any purpose unrelated to study-plan synchronization. Didata does not sell data received from Google APIs and does not transfer that data to third parties except when necessary to provide or improve the feature requested by the User, comply with legal obligations, protect the security of the Platform, or with the User's explicit consent.
Human access to data received from Google Calendar is restricted to situations where the User gives affirmative authorization, where access is necessary to investigate abuse, bugs, or security incidents, to comply with legal obligations, or where the data is aggregated and used for internal operations in accordance with applicable law.
Didata's use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements .
| Legal Basis | Applicable Situation |
|---|---|
| Performance of contract | provision of educational and AI services |
| Legitimate interest | platform improvement, own-product marketing (with opt-out) |
| Consent | non-essential newsletters, profiling cookies |
| Compliance with legal obligation | retention of access logs (Brazilian Internet Civil Framework, art. 15) |
| Regular exercise of rights | defense in judicial, administrative, or arbitration proceedings |
Didata does not sell personal data or share it for third-party marketing without specific consent.
The Platform uses essential, analytics, and functional cookies. The User may configure the browser to block non-essential cookies, understanding that some features may become unavailable.
Didata adopts technical and administrative measures proportionate to the risk, including encryption of data in transit and at rest, access control with strong authentication, continuous vulnerability monitoring, periodic backups, and incident response procedures, with notice to the ANPD and data subjects when required.
Data is stored for as long as necessary to fulfill the purposes described above or comply with legal obligations. After the relationship ends or the legal term expires, data is deleted or anonymized.
Promotional messages may be sent based on legitimate interest or consent, always including an opt-out mechanism. Withdrawal does not affect essential transactional messages, such as password reset emails.
Questions or requests should be sent to contato@didata.ai.
Didata may update this Policy at any time. Material changes will be communicated through the registered email or a notice on the Platform. Continued use after publication implies acceptance.
This Policy is governed by the laws of the Federative Republic of Brazil, especially the LGPD and the Brazilian Internet Civil Framework. The courts of Belo Horizonte, Minas Gerais, are elected to settle disputes.
To review the platform's terms and conditions, see our Terms of Service.