VarcoVARCO

Documentation Center

Guides for using the Varco web portal

Version: v1.19.0Commit: c9e44b1eDate: 2026-10-05T03:52:02.393Z

Privacy Policy

Last updated: September 29, 2026

This Privacy Policy explains how F Camargo Tecnologia LTDA ("Varco", "we", "us") collects, uses, shares, and protects personal data when you visit varco.io or use the Varco management portal, the client applications (desktop and command line), the varco-device agent, tunnels, and EasyConnect (together, the "Service").

We process personal data in accordance with the Brazilian General Data Protection Law (Law No. 13,709/2018, "LGPD"), the Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet, Law No. 12,965/2014), and other applicable laws. Use of the Service is also governed by our Terms of Service.

1. Who we are and how to reach us

  • Controller: F Camargo Tecnologia LTDA, CNPJ 45.524.516/0001-73, headquartered at Curitiba/PR.
  • Data Protection Officer (Encarregado): Felipe Camargo, at contato@fcamargo.tech.
  • General contact: contato@fcamargo.tech.

2. Our role: controller or processor

Businesses ("Customers") use Varco to manage their own equipment and teams, so we act in two different roles:

  • As a controller, we process user account data, access and security records, our communications with you, and browsing data on our website.
  • As a processor, we process, on the Customer's behalf, the data the Customer enters or generates in the Service: devices, telemetry, logs, commands, files, Debug AI conversations, and data about users the organization invites. In these cases the Customer is the controller and decides the purposes of processing; we follow the Customer's instructions and this Policy.

If you are a user of a customer organization and want to exercise rights over data that organization controls, please contact your organization's administrator first. If you contact us directly, we will forward your request to the responsible Customer.

3. Data we process

3.1 Account data

  • Name, email, organization, preferred language, roles, and permissions.
  • Password, stored only as a cryptographic hash (bcrypt). We never store your password in plain text.
  • Phone number, if you choose to receive verification codes over WhatsApp.
  • If you sign in with Google: your Google account identifier and the associated email. We never receive your Google password.
  • API keys you generate.

3.2 Authentication and security data

  • IP address, browser, operating system, and approximate location (city or region estimated from the IP) of each sign-in.
  • Sign-in history and attempts (success, failure, and two-factor verification), used for your activity history and for auditing.
  • Two-factor settings: the authenticator app secret (stored encrypted), recovery codes (stored as hashes), and one-time codes sent by email or WhatsApp (stored as hashes and valid for a few minutes).
  • Active sessions and trusted browsers (hashed identifier, IP address, and usage dates).
  • Attempt counters used for brute-force protection and temporary lockouts.

3.3 Device data (on the Customer's behalf)

  • Device identifiers (UUID, name, group, and organization) and the fingerprint of the certificate's public key. The device's private key stays on the device.
  • Connection IP address, internet provider, and approximate location estimated from the IP, or a location set manually by the Customer.
  • Connection history: connect and disconnect times, disconnect reason, data volume, and availability.
  • Telemetry, logs, and callback data sent by the device or by the Customer's scripts. The content depends on the Customer's configuration and may include personal data if the Customer so decides.

3.4 Remote actions, files, and credentials (on the Customer's behalf)

  • Commands scheduled or run on devices and their output.
  • Files uploaded to the file manager for distribution to devices.
  • SSH credentials (password, private key, passphrase, and certificate) provided for remote actions or for Debug AI, stored encrypted with AES-256-GCM.

3.5 Tunnels and EasyConnect

  • TCP and UDP tunnels: the edge server only relays bytes between the client and the device. We do not inspect or store this content. When the protocol is end-to-end encrypted (for example, SSH), we have no access to the content.
  • HTTP tunnels (EasyConnect): to deliver the device's web interface to your browser with a valid certificate, the edge server terminates the browser's HTTPS connection and forwards requests to the device. Content passes through server memory only while it is being forwarded; we do not record request or response content.
  • We keep metadata: times, data volume, source IP and, when a device group requires email authentication, the authorized email, IP address, and browser used for the tunnel access session.

3.6 Debug AI

When you use Debug AI, we store the conversation, the commands the agent runs, and their results. To generate responses, the conversation history and tool results (for example, log excerpts, command output, and telemetry) are sent to language model providers (see section 5). SSH credentials are not sent to AI providers. Avoid pasting personal data or secrets into the conversation.

3.7 Support and diagnostics

  • Conversations with our support team through the portal chat. Your name, email, and organization are shared with the chat tool to identify you.
  • Portal error and performance reports, which may include the user's email, the page visited, the browser, and technical error details. When session replay is enabled, text, form fields, and media are masked by default.
  • Internal server performance metrics (response times and errors), without tunnel content.

We do not use advertising tools and we do not sell personal data.

PurposeExamplesLegal basis (LGPD)
Providing the ServiceCreating accounts, connecting devices, opening tunnels, running actions, and showing dashboardsPerformance of a contract (art. 7, V)
Security and fraud preventionTwo-factor verification, brute-force protection, CAPTCHA, sign-in alerts, and auditingLegitimate interest (art. 7, IX)
Legal obligationsKeeping application access records for 6 months (Marco Civil, art. 15) and responding to requests from authoritiesLegal obligation (art. 7, II)
Service communicationsVerification codes, invitations, password resets, security and maintenance noticesPerformance of a contract and legitimate interest
SupportAnswering requests and investigating issuesPerformance of a contract and legitimate interest
Improving the ServiceFixing bugs and measuring performanceLegitimate interest (art. 7, IX)
Defending our rightsJudicial, administrative, or arbitration proceedingsRegular exercise of rights (art. 7, VI)

We do not make decisions based solely on automated processing that produce legal effects on you.

5. Who we share data with

We share data only as needed with vendors that help us operate the Service (sub-processors):

VendorPurposeLocation
Oracle Cloud InfrastructureHosting of servers, database, and file and log storageBrazil (São Paulo)
Twilio SendGridTransactional email deliveryUnited States
TwilioWhatsApp verification codesUnited States
GoogleSign in with Google, when you choose that optionUnited States
Cloudflare (Turnstile)Bot verification (CAPTCHA) on suspicious sign-in attemptsGlobal
SentryPortal error and performance monitoringUnited States
ChatwootSupport chat in the portalOutside Brazil
Vercel (AI Gateway) and AI model providers such as OpenAIProcessing Debug AI conversationsUnited States
ip-api.comApproximate location from IP addressesOutside Brazil
OpenStreetMap and NominatimMaps and address search; map tiles are loaded directly by your browserOutside Brazil

We may also share data:

  • With your organization: administrators can see your account information and activity records, according to the permissions assigned to them.
  • With authorities: when required by law, regulation, or court order.
  • In corporate transactions: such as a merger, acquisition, or consolidation, with the protections of this Policy preserved.

6. International data transfers

Our main servers are in Brazil, but some of the vendors listed above process data abroad. These transfers rely on the mechanisms set out in article 33 of the LGPD and in the regulations of the Brazilian National Data Protection Authority (ANPD), and we choose vendors whose security measures are consistent with this Policy.

7. Cookies and local storage

We only use cookies and local storage that are needed for the Service to work securely:

NameTypePurposeDuration
varco_refreshEssential cookie (HttpOnly)Keep you signed inUp to 7 days of inactivity, 14 days maximum
varco_deviceEssential cookie (HttpOnly)Recognize a trusted browser180 days
varco_oauthEssential cookie (HttpOnly)Protect single sign-on, such as Sign in with Google10 minutes
varco_tunnel_authEssential cookie (HttpOnly)Keep authorized access to an email-protected tunnelUntil the browser is closed; the session expires after 24 hours on the server
token and userLocal storageShort-lived access token and basic session dataUntil you sign out; the token expires after 1 hour
i18nextLngLocal storageRemember your preferred languageUntil cleared

When CAPTCHA, support chat, or error monitoring are active, the respective vendors (Cloudflare, Chatwoot, and Sentry) may set their own cookies or local data for those functions.

We do not use advertising or cross-site tracking cookies. You can delete cookies in your browser, but essential cookies are required to sign in.

8. How long we keep data

DataDefault period
Account and profileWhile the account is active; after deletion it is removed or anonymized, unless the law requires otherwise
Access records (IP, date, and time) and audit eventsAt least 6 months, as required by the Marco Civil da Internet, and while the organization remains active, for auditing
Sign-in sessionsUp to 14 days
Trusted browsersUp to 180 days or until revoked; revoked records are deleted after 30 days
Verification codes and sign-in challengesFrom a few minutes up to 1 day
Tunnel access sessions (EasyConnect)24 hours
Device telemetry, logs, and callbacks45 days by default (adjustable)
Internal performance metricsFrom 24 hours to 90 days, depending on granularity
Debug AI conversations, action output, and filesFor as long as the Customer keeps them in the Service

After the contract ends, Customer Data is deleted or anonymized as described in the Terms of Service, except where retention is required by law.

9. How we protect data

  • Device connections authenticated with per-device certificates and mutual TLS (mTLS).
  • Traffic between browsers, applications, and our servers protected by TLS.
  • Passwords stored as bcrypt hashes; SSH credentials and two-factor secrets encrypted with AES-256-GCM.
  • Two-factor verification, per-organization sign-in policies, brute-force protection, role-based access control (RBAC), and isolation between organizations.
  • Audit records, and our team's access to production data limited to what is needed to operate and support the Service.

No system is completely secure. If a security incident may create relevant risk or harm to data subjects, we will notify those affected, the Customer, and the ANPD, as required by article 48 of the LGPD.

10. Your rights

Under article 18 of the LGPD, you may request:

  • confirmation that we process your data and access to it;
  • correction of incomplete, inaccurate, or outdated data;
  • anonymization, blocking, or deletion of unnecessary or excessive data, or data processed unlawfully;
  • portability of your data to another provider, subject to ANPD regulations;
  • deletion of data processed based on consent, where applicable;
  • information about the entities we share your data with;
  • information about the possibility of not giving consent and its consequences;
  • withdrawal of consent, where applicable;
  • objection to processing carried out in breach of the law;
  • review of decisions made solely through automated processing.

You can exercise some of these rights directly in your account settings, such as editing your profile, changing your password, managing two-factor verification, reviewing your sign-in history, and revoking trusted browsers. For other requests, email contato@fcamargo.tech. We may ask for information to verify your identity and will respond within 15 days. You may also file a complaint with the ANPD at gov.br/anpd.

11. Children and teenagers

The Service is intended for businesses and professionals and is not directed at anyone under 18. We do not knowingly collect data from children or teenagers.

12. Changes to this Policy

We may update this Policy to reflect changes to the Service or to the law. The last-updated date appears at the top of this page. We will announce material changes by email or through a notice in the portal.

13. Contact

Questions about this Policy or how we handle your data: contato@fcamargo.tech.


This Policy is available in Portuguese and English. If the versions differ, the Portuguese version prevails.