Privacy and data protection
Privacy Policy
This policy explains how Dinn handles personal data on its website, its platform, and Dinn Pharma Stock for ChatGPT.
Version in effect since September 14, 2026.
Unofficial translation, provided for convenience. The Portuguese (Brazil) version is the sole official, legally binding text; it governs in case of any conflict.
1. Scope and identification
This Privacy Policy applies to Dinn's website, the Dinn platform, and Dinn Pharma Stock, a read-only integration made available on ChatGPT through a remote MCP server. "Dinn," "we," or "our" refer to Dinn Tecnologia Ltda., registered under Brazilian taxpayer ID (CNPJ) 57.639.944/0001-20, headquartered at Rua Dona Francisca, 8300, Bloco Agora, Sala 5, Distrito Industrial, Joinville/SC, CEP 89219-600, Brazil, responsible for the service presented at dinn.ai.
Dinn may act as data controller for the data needed to manage accounts, security, support, and its website, or as data processor following a business customer's instructions. The applicable contract defines these roles when processing is carried out on a customer's behalf.
2. Data we may process
Account, authentication, and authorization
- name, email, account identifiers, and company affiliation;
- profile, portfolio, contracted features, and permissions;
- OAuth authentication events, consents, and access expiration or revocation.
Use of the platform and Dinn Pharma Stock
- the query or command sent to the tool and the parameters needed to fulfill it;
- product, SKU, retail network, period, state, city, region, and selected filters;
- operational data on availability, stock-outs, execution, and points of sale;
- tax ID, phone number, and business address of the point of sale when authorized for the account;
- address, coordinate, or area provided to locate nearby products and calculate distances.
Dinn does not need to receive the full conversation history from ChatGPT. We receive the arguments ChatGPT sends to the MCP tool and return only the result necessary for the authorized request.
Technical, website, and support data
- IP address, date and time, user agent, accessed route, errors, and security events;
- strictly necessary cookies and, when enabled, navigation and performance metrics;
- messages, attachments, and contact data provided in support requests.
3. What we use the data for
- authenticate the user and apply the correct company, portfolio, and permissions;
- answer queries about availability, stock-outs, rankings, points of sale, and location;
- operate interactive components and present understandable business context;
- provide support, investigate errors, and protect accounts, customers, and infrastructure;
- measure and improve performance, reliability, and usability;
- comply with contracts, legal obligations, and valid requests from authorities;
- prevent fraud, abuse, unauthorized access, and data exfiltration.
4. Legal bases and customer instructions
Depending on the context, processing may rely on the performance of a contract or pre-contractual steps, compliance with a legal or regulatory obligation, the regular exercise of rights, legitimate interest after a necessity and impact assessment, or consent when required. This policy describes our practices under Brazilian law (LGPD) as the officially reviewed legal text; it does not itself list rights or bases under other jurisdictions' data protection laws (such as the EU's GDPR or the US's state privacy laws). If you are located outside Brazil and have questions about how a different regime applies to you, contact us using the details in Section 9.
When acting as processor, we follow the documented instructions of the controlling customer and the applicable data processing agreement.
6. International transfers
Some providers may process data outside Brazil. In such cases, Dinn adopts contractual, technical, and organizational mechanisms compatible with the LGPD and considers the country, the provider, the purpose, and the nature of the data. Business customers may request information about the providers applicable to their environment.
7. Retention and deletion
We retain data for the period necessary for the purposes described, the applicable contract, security, and legal obligations. Access tokens expire or may be revoked; technical logs are kept for as long as necessary for security, audit, and diagnostics. When the purpose or the contractual relationship ends, data is deleted, anonymized, or retained only when there is a legal basis for doing so.
8. Security and tenant isolation
We apply authentication, authorization, per-company segregation, encryption in transit, event logging, and limited access controls. In Dinn Pharma Stock, identity, company, and portfolio come from the authenticated token, never from free-form parameters supplied by the user. No method of transmission or storage, however, fully eliminates risk.
9. Data subject rights
Under the LGPD and as applicable, data subjects may request confirmation and access, correction, anonymization, blocking or deletion, portability, information about sharing and consent, withdrawal of consent, objection, and review of automated decisions.
To exercise rights or contact the Data Protection Officer, write to vinicius.silva@diwe.com.br. We may request proportional information to confirm identity and legitimacy. When Dinn acts as processor, the request may be forwarded to the controlling customer.
Data subjects may also file a complaint with Brazil's National Data Protection Authority (ANPD), through the channels it publishes.
11. Children and teenagers
Dinn's business services and Dinn Pharma Stock are not directed at children or teenagers. We do not knowingly collect data from this audience through the plugin.
12. Changes to this policy
We may update this policy to reflect legal, technical, or operational changes. The page will indicate the date of the version in effect. Material changes will be communicated through means appropriate to the context and the contract.