Privacy policy
How Vault Recovery handles your personal data.
This policy explains which data we collect when you use recovery.vaultcapital.com.br, the assessment form and the booking calendar, why we use it, who we share it with and how to exercise your rights under the Brazilian General Data Protection Law (Law 13,709/2018, LGPD).
Data controller
Vault Ltda. (Vault Recovery), São Paulo, SP, Brazil.
CNPJ: company registration (CNPJ) shown in the site footer.
Privacy contact: the official email address published in the site footer.
Content updated September 28, 2026.
1. Never send secrets
Seed phrases, private keys, passwords, passphrases and wallet files must never be sent through the form, by email, by message or in any initial contact. The form has no field for this data and Vault never requests it before verifying identity and ownership and formalising the engagement. When technical work requires sensitive material, it is requested only through the channel agreed in the contract and limited to the minimum the case needs.
2. Data we collect
- Assessment form: full name, email, phone number, preferred language, category of the access problem, wallet type or name (if provided), the material you still have, approximate value range, an optional short description and your confirmation that you own the assets or hold legal authorisation.
- Booking: name, email, chosen date and time, booking identifier and the anti-bot verification token (Cloudflare Turnstile). The call takes place on Google Meet and the invitation is sent to the email provided.
- Technical data: IP address, browser type and access logs, used for security, fraud prevention and, when measurement is enabled, aggregate site usage statistics.
- Engagement data: information you share during the assessment and, if the case is accepted, the identity and ownership documents and technical material defined in the contract.
3. Purposes and legal bases
- Screening and technical assessment of your case and contact to schedule or hold the call: pre-contractual steps at your request (LGPD art. 7, V).
- Identity and ownership verification before technical work: legitimate interest and fraud prevention (art. 7, IX) and compliance with legal obligations (art. 7, II).
- Delivery of the recovery service, invoicing of the success fee and tax and accounting duties: contract performance and legal obligation.
- Security of the site and booking systems: legitimate interest.
- Audience measurement with Google Tag Manager and analytics tools, when enabled: consent, which you may refuse or withdraw through your browser settings.
4. Who we share data with
We do not sell personal data. We share it only with processors needed to deliver the service:
- Google (Google Workspace, Calendar and Meet) for scheduling, invitations and video calls; and Google Tag Manager or Analytics when measurement is enabled.
- Cloudflare for hosting, attack protection and anti-bot verification (Turnstile).
- Email and infrastructure providers of our booking system.
- Public authorities when required by law or court order.
5. International transfers
Some processors (Google, Cloudflare) may process data on servers outside Brazil. These transfers rely on the mechanisms of LGPD arts. 33 to 36, such as standard contractual clauses and provider certifications.
6. Retention
- Screening and booking data without a contract: up to 12 months after the last contact so the case can be resumed; then deleted or anonymised.
- Data from contracted cases: for the duration of the contract and, after it ends, for as long as needed to meet legal obligations and defend legal claims, generally 5 years.
- Sensitive technical material used in the recovery (files, backups, password or seed fragments): permanently deleted once the case is closed, with confirmation to the client.
- Site access logs: up to 6 months, as required by the Brazilian Internet Framework Law.
7. Your rights
Under LGPD art. 18 you may request at any time:
- Confirmation that we process your data and access to it.
- Correction of incomplete, inaccurate or outdated data.
- Anonymisation, blocking or deletion of unnecessary or non-compliant data.
- Portability to another provider, subject to trade and industrial secrets.
- Information about the parties we share your data with.
- Withdrawal of consent and objection to processing based on legitimate interest.
8. How to exercise them
Send your request to the official email address published in the site footer with the name and email used in the form. We may ask for information to confirm your identity before replying. We respond within 15 days. If you believe your request was not handled properly, you may file a complaint with the Brazilian Data Protection Authority (ANPD).
9. Security
We apply data minimisation at every step. Recovery attempts run offline on equipment controlled by Vault, with access restricted to the specialists in charge. The site is served over HTTPS only and the booking flow uses anti-bot verification and idempotency keys to prevent duplicate reservations. No measure removes all risk; if we identify a relevant incident we will notify affected individuals and the ANPD as the law requires.
10. Cookies and local storage
The site works without tracking cookies. The booking system uses browser session storage only to follow an in-progress reservation, without any details of your case. If audience measurement is enabled, Google Tag Manager may set analytics cookies; you can block them in your browser without affecting the site.
11. Changes
We may update this policy to reflect changes in the service or the law. The current version is always the one published on this page, with the update date shown below.