Privacy Policy

Last updated: September 6, 2026

1. Who controls your data

This policy describes how Reley Tecnologia LTDA, a Brazilian company registered under CNPJ 47.145.220/0001-77 and based in Cotia, Sao Paulo, operating the GPUBrazil platform, collects, uses, shares and protects personal data. It applies to our website, customer dashboard and API.

For any matter concerning personal data, including exercising your rights, write to support@gpubrazil.com.

2. What data we collect

Account data. Name, email address, phone number, tax identification number and a password, which we store only as a cryptographic hash — never in readable form. If you sign in with Google or GitHub, we receive your account identifier on those services and your email address.

Billing data. Legal name, full address, city, state, country and postal code, required to issue invoices. For customers outside Brazil, identification document type and number, such as a passport.

Payment data. We do not store your full card number. It is processed directly by the payment operator. We keep only the card brand, the last four digits and a payment method identifier generated by that operator, plus your transaction, deposit and balance history.

Technical service data. The public SSH keys you register, the IP addresses and ports of the instances you rent, records of instance creation, start, stop and deletion, and the usage we bill you for. We also keep an access audit record noting whether the instance responded and whether the access we announced to you actually worked — this is what lets us demonstrate, in a dispute, that the service was delivered.

API keys. If you generate an API key we store only its hash. The key itself is shown once and cannot be recovered by us.

Browsing data. IP address, browser type, pages visited and traffic source, collected through cookies and analytics tools.

What we do NOT collect: we do not access, copy or inspect the content you process inside the instances you rent — your models, weights, datasets, prompts or outputs. The instance is yours for as long as you rent it. We never sell personal data to anyone, under any circumstances.

3. How we use it

4. Legal basis

We process personal data under Brazil's General Data Protection Law (LGPD, Law 13.709/2018):

5. Who we share it with

We share only what is necessary, with the following categories of third parties:

6. International data transfers

Please read carefully. The GPU compute capacity we offer runs in data centers located outside Brazil, across the Americas, Europe and Asia-Pacific. This means that data you send into a GPU instance, as well as the technical data needed to create it, is processed and stored abroad. The same applies to the payment, email and analytics operators listed above, which run international operations.

These transfers are carried out under article 33 of the LGPD, on the basis of performing the contract with you and under contractual clauses with the providers involved. By purchasing the service you acknowledge that processing takes place outside Brazil.

Our dedicated CPU offering is the exception: it runs in a data center located in Sao Paulo, Brazil.

If your use case requires that certain data never leaves Brazil, do not send that data to GPU instances. Talk to us before purchasing.

7. How long we keep it

8. Your rights

The LGPD grants you the right, at any time and free of charge, to:

To exercise any of these, write to support@gpubrazil.com. We respond within 15 days. We may ask for information confirming your identity before acting, so that we do not hand your data to someone else.

Some data cannot be deleted even at your request, where the law requires us to keep it — such as tax records of payments already made.

9. Cookies

We use strictly necessary cookies, which keep your session authenticated and without which the dashboard does not work, and analytics and advertising cookies set by Google Analytics, Google Tag Manager and Google Ads, which show us how the site is used and measure our campaign results.

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from logging in.

10. Security

Passwords are stored only as hashes. API keys are stored only as hashes. Traffic between you and the platform is encrypted with TLS. Database access is restricted and backups are encrypted.

No system is immune to incidents. Should a security incident occur with relevant risk to your data, we will notify you and Brazil's National Data Protection Authority, as required by article 48 of the LGPD.

11. Minors

The service is intended for people aged 18 or over. We do not knowingly collect data from children or adolescents. If we identify such an account, it will be closed and the data deleted.

12. Changes to this policy

We may update this policy. The date of the latest update is always shown at the top of this page. Material changes will be communicated by email to active customers with reasonable notice.

13. Contact

Questions, requests or complaints about privacy and data protection:

← Back to home