Skip to main content

Our Commitment to Privacy and the Right to Be Forgotten

Pipefy is fully committed to protecting the privacy and data of all its customers, in strict compliance with global data protection laws such as LGPD (General Data Protection Law - Brazil) and GDPR (General Data Protection Regulation - European Union).

Product Team avatar
Written by Product Team
Updated today

🛡️ Our Core Promise on Data Usage

We do not use your customer data to train our core AI models.
Your business data, including the content of your cards, forms, and processes, belongs to you. It is used exclusively to power your automations and Assistants within your own Pipefy environment. It is never used to train or improve any public or shared AI models.


Your Right to Be Forgotten

We fully support your right to request the deletion of your personal data.
When you submit a valid request, here’s what we commit to doing:

🗑️ What We Will Delete

  • All direct, identifiable records (e.g., user profiles, card data, form submissions)

  • Associated tokens, credentials, and access keys

  • Data from active backups during our next standard rotation cycle


↗️ Process for Requesting Deletion

To exercise your right to be forgotten, please contact our Support Team or our Data Protection Officer (DPO) at dpo@pipefy.com.

  1. Request & Verification:
    We will acknowledge your request and verify your identity to ensure data protection.

  2. Execution:
    We will permanently delete all your identifiable data from our active systems.

  3. Confirmation:
    You will receive a formal confirmation once the process is complete.


🔐 Post-Contract Data Handling

Upon termination of your contract with Pipefy, we initiate the process to permanently delete all your customer data within a maximum of 180 days, in accordance with our data retention policy.


💡 Note on Anonymized and Derived Data

In the course of providing and improving our services, some data may be processed in a way that makes it permanently non-identifiable.
This is similar to how a website might use aggregated traffic patterns to improve performance without tracking individual visitors.

What this means:

Certain data points may be converted into anonymous, aggregated statistics or system metrics
(e.g., average card completion time, general feature usage patterns).

Why it matters for deletion:

Once data is transformed into these anonymous aggregates,
it becomes mathematically impossible to isolate or delete a single user’s information,
as it no longer exists as a unique, identifiable record.

⚠️ Importantly, this process:

  • Is designed for system health and performance analysis

  • Does not involve using your specific business content (like card titles or form answers) to train AI models

  • Produces information that cannot be traced back to you or your users


Final Assurance

Our commitment to your privacy is unwavering. All our data handling practices and subprocessors are bound by strict agreements to ensure full compliance with GDPR, LGPD, and our own high standards of data protection.

Did this answer your question?