Skip to main content
Privacy

Privacy Policy

Last updated: 29 August 2026. This page explains, in plain language, how NOI handles the personal data of anyone who signs up — as a candidate or as a company — in compliance with Brazil's General Data Protection Law (Law 13.709/2018).

What data we collect

  • Account data: name, email and password (stored hashed, never in plain text).
  • Company data (where applicable): legal name and CNPJ (Brazilian company registration number).
  • Assessment answers: the questionnaire answers used to calculate archetype, axes and recommendations.
  • Résumé: the file you upload (PDF, DOC, DOCX or TXT) and the skills and experience read from it.
  • Access logs: technical records of when assessment and report data is accessed, for security and audit purposes.

What we use this data for

Your data is used solely to produce your professional archetype assessment and the recommendation report — and, for candidates linked to a company, so that this company can see the assessment result as part of a hiring process. We do not sell or share your data with third parties for advertising.

Legal basis

Processing is based on your consent, given explicitly at sign-up (art. 7, I of the LGPD), and on carrying out the assessment and hiring process you asked for yourself (art. 7, V). You can withdraw consent at any time — see "Your rights" below.

Who your data is shared with

If you sign up as a candidate and are linked to a hiring company, that company can see your assessment result (archetype, fit and risk level) and your interpreted résumé — never your password. Beyond that, your data is not shared with third parties.

Your rights

At any time, from your profile screen, you can:

  • Export a complete copy of everything we hold about you, in an open format (JSON).
  • Delete your account — this disables your access immediately and removes your assessment from any linked company's dashboard. For the first 30 days the deletion is reversible: the data is kept in case you change your mind. After that, it is erased automatically and cannot be recovered. If you want it removed for good before the 30 days are up, ask us at the email address at the end of this page.

Go to my profile to exercise these rights directly.

How long we keep your data

The LGPD sets no single retention period: it requires data to be erased as soon as the purpose of processing ends (arts. 15 and 16). The periods below are the shortest we can defend for each category — and two of them are imposed by another law, not chosen by us.

  • Closed account — 30 days: profile, assessment answers, résumé and company links are erased 30 days after you delete your account. The window exists so you can change your mind; after it, the purge is automatic.
  • Well-being check-in — erased at once: because it is sensitive health data, check-in answers are erased immediately when you withdraw consent. They wait for no retention period at all.
  • Contact through the website form — 12 months: if you ask us to get in touch and do not become a customer, the record is erased after twelve months.
  • Naming a colleague — 12 months: when someone names you as a person who helps them deliver, that entry is deleted after a year. It is the only data here that someone else produces about you — and a support network from a year ago no longer describes today's team.
  • Technical access records — 6 months: this is a mandatory minimum: Brazil's Internet Civil Framework (Law 12.965/2014, art. 15) requires application providers to keep these records for six months. Once the period is over, we erase them.
  • Record of consents and requests — 5 years: we keep proof that we honoured your requests (export, deletion, withdrawal) for five years, as a demonstration of compliance (art. 37). This record is kept anonymised after the account purge: it shows the request was honoured, without identifying you again.

Cookies

We only use cookies that are essential to running the platform:

  • Session cookie: keeps you securely signed in after login. It is protected against JavaScript access (HttpOnly) and expires automatically.
  • Preference cookie: remembers whether the sidebar is open or collapsed, so your navigation preference is preserved.

We use no tracking, advertising or behavioural analytics cookies, and we share no cookies with third parties. Because they are strictly necessary, these cookies require no consent (art. 7, V and IX of the LGPD) — but we tell you about them on your first visit, for transparency.

Security

Passwords are stored with Argon2id hashing (never in plain text), the session uses cookies protected against JavaScript access (HttpOnly), and all communication between the app and the server must go over HTTPS in production.

Infrastructure and processors

The platform and the database are hosted at Hostinger, which acts as a data processor under the LGPD: it provides the hosting infrastructure but neither accesses nor uses the data for its own purposes. Sensitive data (such as the Real Life Module answers) is stored encrypted, so not even the hosting provider can read it. Any processor engaged in the future will be held to the same level of protection this policy requires.

Data Protection Officer (DPO)

The data protection officer for Midas Solutions Corp, under art. 41 of the LGPD, is Josiane Almeida. She receives complaints and communications from data subjects, provides clarifications, and acts as the point of contact with Brazil's National Data Protection Authority (ANPD).

You can reach the data protection officer through the same channel given below: privacidade@midassolutionscorp.com.

Contact

Questions about this policy or about how your data is handled can be sent to privacidade@midassolutionscorp.com.