Privacy Policy
Last updated: September 29, 2026
This Privacy Policy explains how F Camargo Tecnologia LTDA ("Varco", "we", "us") collects, uses, shares, and protects personal data when you visit varco.io or use the Varco management portal, the client applications (desktop and command line), the varco-device agent, tunnels, and EasyConnect (together, the "Service").
We process personal data in accordance with the Brazilian General Data Protection Law (Law No. 13,709/2018, "LGPD"), the Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet, Law No. 12,965/2014), and other applicable laws. Use of the Service is also governed by our Terms of Service.
1. Who we are and how to reach us
- Controller: F Camargo Tecnologia LTDA, CNPJ 45.524.516/0001-73, headquartered at Curitiba/PR.
- Data Protection Officer (Encarregado): Felipe Camargo, at contato@fcamargo.tech.
- General contact: contato@fcamargo.tech.
2. Our role: controller or processor
Businesses ("Customers") use Varco to manage their own equipment and teams, so we act in two different roles:
- As a controller, we process user account data, access and security records, our communications with you, and browsing data on our website.
- As a processor, we process, on the Customer's behalf, the data the Customer enters or generates in the Service: devices, telemetry, logs, commands, files, Debug AI conversations, and data about users the organization invites. In these cases the Customer is the controller and decides the purposes of processing; we follow the Customer's instructions and this Policy.
If you are a user of a customer organization and want to exercise rights over data that organization controls, please contact your organization's administrator first. If you contact us directly, we will forward your request to the responsible Customer.
3. Data we process
3.1 Account data
- Name, email, organization, preferred language, roles, and permissions.
- Password, stored only as a cryptographic hash (bcrypt). We never store your password in plain text.
- Phone number, if you choose to receive verification codes over WhatsApp.
- If you sign in with Google: your Google account identifier and the associated email. We never receive your Google password.
- API keys you generate.
3.2 Authentication and security data
- IP address, browser, operating system, and approximate location (city or region estimated from the IP) of each sign-in.
- Sign-in history and attempts (success, failure, and two-factor verification), used for your activity history and for auditing.
- Two-factor settings: the authenticator app secret (stored encrypted), recovery codes (stored as hashes), and one-time codes sent by email or WhatsApp (stored as hashes and valid for a few minutes).
- Active sessions and trusted browsers (hashed identifier, IP address, and usage dates).
- Attempt counters used for brute-force protection and temporary lockouts.
3.3 Device data (on the Customer's behalf)
- Device identifiers (UUID, name, group, and organization) and the fingerprint of the certificate's public key. The device's private key stays on the device.
- Connection IP address, internet provider, and approximate location estimated from the IP, or a location set manually by the Customer.
- Connection history: connect and disconnect times, disconnect reason, data volume, and availability.
- Telemetry, logs, and callback data sent by the device or by the Customer's scripts. The content depends on the Customer's configuration and may include personal data if the Customer so decides.
3.4 Remote actions, files, and credentials (on the Customer's behalf)
- Commands scheduled or run on devices and their output.
- Files uploaded to the file manager for distribution to devices.
- SSH credentials (password, private key, passphrase, and certificate) provided for remote actions or for Debug AI, stored encrypted with AES-256-GCM.
3.5 Tunnels and EasyConnect
- TCP and UDP tunnels: the edge server only relays bytes between the client and the device. We do not inspect or store this content. When the protocol is end-to-end encrypted (for example, SSH), we have no access to the content.
- HTTP tunnels (EasyConnect): to deliver the device's web interface to your browser with a valid certificate, the edge server terminates the browser's HTTPS connection and forwards requests to the device. Content passes through server memory only while it is being forwarded; we do not record request or response content.
- We keep metadata: times, data volume, source IP and, when a device group requires email authentication, the authorized email, IP address, and browser used for the tunnel access session.
3.6 Debug AI
When you use Debug AI, we store the conversation, the commands the agent runs, and their results. To generate responses, the conversation history and tool results (for example, log excerpts, command output, and telemetry) are sent to language model providers (see section 5). SSH credentials are not sent to AI providers. Avoid pasting personal data or secrets into the conversation.
3.7 Support and diagnostics
- Conversations with our support team through the portal chat. Your name, email, and organization are shared with the chat tool to identify you.
- Portal error and performance reports, which may include the user's email, the page visited, the browser, and technical error details. When session replay is enabled, text, form fields, and media are masked by default.
- Internal server performance metrics (response times and errors), without tunnel content.
We do not use advertising tools and we do not sell personal data.
4. Why we use data and legal bases
| Purpose | Examples | Legal basis (LGPD) |
|---|---|---|
| Providing the Service | Creating accounts, connecting devices, opening tunnels, running actions, and showing dashboards | Performance of a contract (art. 7, V) |
| Security and fraud prevention | Two-factor verification, brute-force protection, CAPTCHA, sign-in alerts, and auditing | Legitimate interest (art. 7, IX) |
| Legal obligations | Keeping application access records for 6 months (Marco Civil, art. 15) and responding to requests from authorities | Legal obligation (art. 7, II) |
| Service communications | Verification codes, invitations, password resets, security and maintenance notices | Performance of a contract and legitimate interest |
| Support | Answering requests and investigating issues | Performance of a contract and legitimate interest |
| Improving the Service | Fixing bugs and measuring performance | Legitimate interest (art. 7, IX) |
| Defending our rights | Judicial, administrative, or arbitration proceedings | Regular exercise of rights (art. 7, VI) |
We do not make decisions based solely on automated processing that produce legal effects on you.
5. Who we share data with
We share data only as needed with vendors that help us operate the Service (sub-processors):
| Vendor | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Hosting of servers, database, and file and log storage | Brazil (São Paulo) |
| Twilio SendGrid | Transactional email delivery | United States |
| Twilio | WhatsApp verification codes | United States |
| Sign in with Google, when you choose that option | United States | |
| Cloudflare (Turnstile) | Bot verification (CAPTCHA) on suspicious sign-in attempts | Global |
| Sentry | Portal error and performance monitoring | United States |
| Chatwoot | Support chat in the portal | Outside Brazil |
| Vercel (AI Gateway) and AI model providers such as OpenAI | Processing Debug AI conversations | United States |
| ip-api.com | Approximate location from IP addresses | Outside Brazil |
| OpenStreetMap and Nominatim | Maps and address search; map tiles are loaded directly by your browser | Outside Brazil |
We may also share data:
- With your organization: administrators can see your account information and activity records, according to the permissions assigned to them.
- With authorities: when required by law, regulation, or court order.
- In corporate transactions: such as a merger, acquisition, or consolidation, with the protections of this Policy preserved.
6. International data transfers
Our main servers are in Brazil, but some of the vendors listed above process data abroad. These transfers rely on the mechanisms set out in article 33 of the LGPD and in the regulations of the Brazilian National Data Protection Authority (ANPD), and we choose vendors whose security measures are consistent with this Policy.
7. Cookies and local storage
We only use cookies and local storage that are needed for the Service to work securely:
| Name | Type | Purpose | Duration |
|---|---|---|---|
varco_refresh | Essential cookie (HttpOnly) | Keep you signed in | Up to 7 days of inactivity, 14 days maximum |
varco_device | Essential cookie (HttpOnly) | Recognize a trusted browser | 180 days |
varco_oauth | Essential cookie (HttpOnly) | Protect single sign-on, such as Sign in with Google | 10 minutes |
varco_tunnel_auth | Essential cookie (HttpOnly) | Keep authorized access to an email-protected tunnel | Until the browser is closed; the session expires after 24 hours on the server |
token and user | Local storage | Short-lived access token and basic session data | Until you sign out; the token expires after 1 hour |
i18nextLng | Local storage | Remember your preferred language | Until cleared |
When CAPTCHA, support chat, or error monitoring are active, the respective vendors (Cloudflare, Chatwoot, and Sentry) may set their own cookies or local data for those functions.
We do not use advertising or cross-site tracking cookies. You can delete cookies in your browser, but essential cookies are required to sign in.
8. How long we keep data
| Data | Default period |
|---|---|
| Account and profile | While the account is active; after deletion it is removed or anonymized, unless the law requires otherwise |
| Access records (IP, date, and time) and audit events | At least 6 months, as required by the Marco Civil da Internet, and while the organization remains active, for auditing |
| Sign-in sessions | Up to 14 days |
| Trusted browsers | Up to 180 days or until revoked; revoked records are deleted after 30 days |
| Verification codes and sign-in challenges | From a few minutes up to 1 day |
| Tunnel access sessions (EasyConnect) | 24 hours |
| Device telemetry, logs, and callbacks | 45 days by default (adjustable) |
| Internal performance metrics | From 24 hours to 90 days, depending on granularity |
| Debug AI conversations, action output, and files | For as long as the Customer keeps them in the Service |
After the contract ends, Customer Data is deleted or anonymized as described in the Terms of Service, except where retention is required by law.
9. How we protect data
- Device connections authenticated with per-device certificates and mutual TLS (mTLS).
- Traffic between browsers, applications, and our servers protected by TLS.
- Passwords stored as bcrypt hashes; SSH credentials and two-factor secrets encrypted with AES-256-GCM.
- Two-factor verification, per-organization sign-in policies, brute-force protection, role-based access control (RBAC), and isolation between organizations.
- Audit records, and our team's access to production data limited to what is needed to operate and support the Service.
No system is completely secure. If a security incident may create relevant risk or harm to data subjects, we will notify those affected, the Customer, and the ANPD, as required by article 48 of the LGPD.
10. Your rights
Under article 18 of the LGPD, you may request:
- confirmation that we process your data and access to it;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary or excessive data, or data processed unlawfully;
- portability of your data to another provider, subject to ANPD regulations;
- deletion of data processed based on consent, where applicable;
- information about the entities we share your data with;
- information about the possibility of not giving consent and its consequences;
- withdrawal of consent, where applicable;
- objection to processing carried out in breach of the law;
- review of decisions made solely through automated processing.
You can exercise some of these rights directly in your account settings, such as editing your profile, changing your password, managing two-factor verification, reviewing your sign-in history, and revoking trusted browsers. For other requests, email contato@fcamargo.tech. We may ask for information to verify your identity and will respond within 15 days. You may also file a complaint with the ANPD at gov.br/anpd.
11. Children and teenagers
The Service is intended for businesses and professionals and is not directed at anyone under 18. We do not knowingly collect data from children or teenagers.
12. Changes to this Policy
We may update this Policy to reflect changes to the Service or to the law. The last-updated date appears at the top of this page. We will announce material changes by email or through a notice in the portal.
13. Contact
Questions about this Policy or how we handle your data: contato@fcamargo.tech.
This Policy is available in Portuguese and English. If the versions differ, the Portuguese version prevails.
