Privacy Policy
Last updated: July 24, 2026
1. Who we are and our role
Oriente33 (oriente33.com) is a digital management platform built for Masonic Lodges. We operate as SaaS (software as a service): each Lodge subscribes to access and uses the platform over the internet.
In data-protection terms: each Lodge is the controller of its members’ data — it decides which data to enter and for what purpose. Oriente33 acts as the processor, handling that data solely on the Lodge’s instructions and within the limits of this Policy. Oriente33 is a controller only with respect to the Lodge’s own account and billing data (subscription and contact).
Questions about this policy may be sent to: privacidade@oriente33.com
2. A web system, nothing installed locally
Oriente33 is 100% web-based. No software is installed on the computers, phones or servers of the Lodge or its Brothers: all access happens through the browser, over an encrypted connection (HTTPS/TLS). This means there are no local databases, spreadsheets or files with member data scattered across individual machines — the data lives in a single, central, controlled and auditable environment, not on personal devices exposed to loss, theft or unauthorized access.
3. Data we collect
We collect only the data necessary for the service to work:
- Registration data: name, email, phone, national ID/tax number, date of birth, address and other civil data provided by the Lodge when registering a member.
- Masonic data: degree, office, initiation date, Masonic record and meeting attendance history.
- Financial data: records of dues, charges and payments of the Lodge, without storing full credit-card data (tokenized by the payment gateways).
- Usage data: access logs, actions performed on the platform (internal audit) and IP address.
- Messages: records of WhatsApp and email deliveries (recipient, date, delivery status), stored solely for the Lodge’s audit purposes.
4. How we use your data
- Providing the Masonic management service contracted by the Lodge.
- Sending dues reminders, birthday greetings and announcements via WhatsApp and email, when authorized by the Lodge.
- Generating charges and financial control for the Lodge.
- Auditing actions performed by users with administrative access.
- Technical support and continuous improvement of the platform.
We do not sell, rent or share your data with third parties for advertising purposes, and we do not use it to train artificial-intelligence systems.
5. Where your data is stored and who maintains it
The Brothers’ data is not kept on machines held by Oriente33 nor on personal equipment. It resides on managed cloud infrastructure operated by specialized, recognized providers, with encryption at rest and in transit, and with logical isolation per Lodge (one Lodge’s data is never visible to another). For security reasons, we do not publicly disclose the names and topology of the providers; we describe below the categories of processors that support the service, each contracted solely for the stated purpose:
- Managed cloud database and authentication — where the registration, Masonic and financial data reside.
- Encrypted cloud object storage — for backups and attached files (documents, photos).
- Application hosting — the web layer that serves the pages.
- Transactional email provider — reminders and notifications.
- Regulated payment gateways — processing of charges and payments. Card data is tokenized by these gateways and never travels through or is stored on our servers.
- Messaging provider — sending messages via WhatsApp when the Lodge enables that notification; the member who receives it is also subject to the terms of the respective application.
Each processor is engaged under data-processing agreements and maintains independent information-security certifications (such as SOC 2 and ISO 27001). Oriente33 remains responsible to the Lodge for the entire processing chain. The named, up-to-date list of subcontracted processors can be provided to the Lodge upon justified request, through the privacy email below.
International transfer: part of this infrastructure is located outside Brazil (primarily in the United States). This transfer is carried out with the safeguards required by applicable data-protection law (including Brazil’s LGPD, art. 33), to providers offering an adequate level of data protection.
6. Backups and recovery in the event of failure
Yes, there are backups. The platform generates automatic daily backups of all data for each Lodge, stored encrypted in the cloud, with a retention policy (recent daily copies plus weekly copies). These backups are not kept on personal machines — they stay in the same controlled, encrypted cloud infrastructure.
Recovery in the event of a server outage is provided across two independent layers:
- Provider redundancy: the database runs on infrastructure with redundancy and point-in-time recovery, managed by the provider itself.
- Oriente33’s own backups: from the encrypted daily copies, a Lodge’s state can be restored transactionally (all-or-nothing), typically within a few hours, without affecting the other Lodges.
This dual layer — the managed infrastructure plus our own encrypted backups — ensures that a server failure does not mean loss of the Brothers’ data.
7. Legal basis
Personal-data processing is carried out on the following legal bases under applicable data-protection laws (Brazil’s LGPD — Law No. 13,709/2018 — and equivalent laws such as the GDPR, where applicable):
- Performance of a contract — to provide the services contracted by the Lodge.
- Legitimate interest — for audit, security and improvement of the platform.
- Consent — for sending announcements via WhatsApp and email, which may be withdrawn at any time.
8. Data-protection compliance and Masonic confidentiality
An important clarification: there is no official government-issued “LGPD certification” in Brazil — the LGPD is a binding law, not a seal you obtain. Compliance is demonstrated through an adequacy program and verifiable technical and organizational measures, which is what we adopt. (The recognized market certifications — such as SOC 2 and ISO 27001 — are held by the infrastructure providers that support the platform, as described in section 5.)
We recognize that the data of a Masonic entity requires a level of confidentiality higher than that of an ordinary company: the mere fact that someone is a member, their degree and their Lodge is, in itself, sensitive. We therefore apply reinforced confidentiality controls:
- Isolation between Lodges: each Lodge is a logically separate environment; it is technically impossible for one Lodge to see another Lodge’s data.
- Role-based access control (RBAC): within each Lodge there are five hierarchical permission levels. Financial data and the Masonic record are kept in separate segments, inaccessible to anyone without the corresponding office.
- Minimization: we collect only what is necessary; Oriente33 does not sell, profile or expose member lists.
- Encryption: data in transit (TLS) and at rest; integration credentials and backups are encrypted.
- Audit logs: sensitive administrative actions are recorded, allowing us to trace who accessed or changed what.
- Restricted staff access: Oriente33’s technical access to the data is limited to what is strictly necessary for operation and support, and subject to confidentiality.
9. Data retention
Data is kept while the Lodge has an active account on the platform. After cancellation, data is retained for up to 90 days for backup and legal-obligation purposes, and is then permanently deleted — including from the backup copies, according to their retention cycle.
10. Your rights
Under applicable data-protection law, you have the right to:
- Confirm the existence of processing of your data.
- Access the data we hold about you.
- Correct incomplete, inaccurate or outdated data.
- Request the anonymization, blocking or deletion of unnecessary data.
- Withdraw consent at any time.
- Request data portability.
Because the Lodge is the controller of its members’ data, requests to exercise these rights should preferably be directed to your Lodge’s administrator. Oriente33, as the processor, provides the necessary technical support and can be contacted directly at: privacidade@oriente33.com
11. Security and incidents
We adopt technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, role-based access control (RBAC), isolation between Lodges, rate limiting of access attempts and monitoring of suspicious activity. No system is 100% secure; in the event of a relevant security incident, we will notify the affected Lodge and the competent data-protection authority as required by law.
12. Cookies
We use essential session cookies for user authentication. We do not use third-party tracking or advertising cookies.
13. Changes to this policy
We may update this Policy from time to time. The “last updated” date at the top indicates when the current version took effect. For significant changes, we will notify Lodges by email or through the administrative panel.
14. Contact
Oriente33
Email: privacidade@oriente33.com
Website: oriente33.com
