Privacy Policy

Transparency and LGPD compliance

Last updated: December 16, 2025

1. Introduction

Universo Pet ("we", "our" or "Platform") is committed to protecting your privacy and personal data. This Privacy Policy has been prepared in accordance with the General Data Protection Law (LGPD - Law No. 13.709/2018) and transparently describes how we collect, use, store, share and protect your personal information when using our Dr. Paws veterinary consultation services, training guides and pet health management. By creating an account or using the Platform, you expressly agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.

2. Data Controller and Data Protection Officer (DPO)

Under the LGPD, the controller of your personal data is: Legal Name: Universo Pet Tecnologia Ltda. Address: Esplanada, Bahia, Brazil Corporate Email: studio.kodaai@gmail.com Data Protection Officer (DPO): For questions related to data protection, you can contact our DPO via email: studio.kodaai@gmail.com

3. Data Collected

We collect different categories of personal data to provide our services efficiently and personalized:

3.1. Registration Data

• Full name • Email (main means of communication) • Password (stored with cryptographic hash via Firebase Authentication) • Phone (optional, for urgent notifications) • Profile photo (optional) • Account creation date

3.2. Pet Data

• Pet name • Species (dog, cat, birds, reptiles, rodents and others) • Breed • Age or date of birth • Weight • Gender • Pet photos (stored in Firebase Storage) • Basic medical history (vaccines, surgeries, chronic conditions) • Behavior observations (for training)

3.3. Dr. Paws Consultation Data

• Complete history of conversations with Dr. Paws • Questions asked and answers provided • Images and videos sent during consultations (symptom photos, exams, etc.) • Consultation date and time • Triage classification (green/yellow/red) generated at the end of each consultation • Guided Physical Exam data (photos of examined areas, owner observations) • Home Care Checklist tasks (generated tasks, completion status, owner notes) • Health Score ratings (history of calculated scores) • Quality feedback (optional ratings)

3.4. Usage and Navigation Data

• IP address (anonymized for analytics) • Device type and browser • Operating system • Pages visited on the Platform • Time spent • Actions taken (clicks, scrolls, navigation) • Technical error logs (for improvements)

3.5. Payment Data

• Billing information: name, CPF/CNPJ • Credit card data (processed exclusively by Stripe, we never store complete card numbers) • Transaction history (subscriptions, renewals, cancellations) • Country and currency

3.6. Pet Health Data

• Vaccine and deworming history • Medication records (name, dosage, times) • Surgery and veterinary consultation history • Configured health reminders

5. Data Processing Purposes

We use your personal data exclusively for the following legitimate purposes:

5.1. Service Provision

• Create and manage your Platform account • Enable Dr. Paws veterinary consultations • Provide personalized training guides • Manage pet registrations and health • Process subscription payments

5.2. Communication

• Send registration confirmations, transactions and cancellations • Notify about important Platform updates • Respond to questions and support requests • Send newsletters (only if you expressly consent)

5.3. Improvements and Analytics

• Analyze usage patterns to improve features • Train and optimize technology models (anonymized) • Conduct satisfaction surveys • Develop new features based on feedback

5.4. Security and Compliance

• Prevent fraud, abuse and illegal activities • Protect Platform and user security • Comply with legal and regulatory obligations • Respond to legal proceedings or authority requests

6. Data Sharing

We do not sell your personal data to third parties. However, we share data with the following partners, exclusively to enable our services:

6.1. Infrastructure Providers

Firebase (Google Cloud): Data storage (Firestore), authentication (Firebase Auth), file storage (Storage) and hosting. Privacy policy: https://firebase.google.com/support/privacy • Stripe: Payment processing. Stripe is PCI-DSS Level 1 certified. Policy: https://stripe.com/privacy

6.2. Technology Services

Google Gemini (Vertex AI): Dr. Paws veterinary consultation processing. Data is sent to Google Cloud servers to generate responses. Policy: https://ai.google.dev/gemini-api/terms

6.3. Analytics Tools

Google Analytics 4: Usage analysis (anonymized data). You can disable analytical cookies in settings.

6.4. Legal Authorities

We may share personal data if required by law, court order, government authority or to protect the rights, property or security of Universo Pet, our users or the public.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, except if there is a legal obligation to retain for a longer period: • Registration data: While your account is active + 5 years after deletion (tax/legal obligation). • Dr. Paws consultation history: 2 years after last consultation (for pet medical history purposes). • Payment data: 5 years (tax requirement and Consumer Protection Code). • Access logs: 6 months (Brazilian Internet Civil Rights Framework). • Pet health data: While account is active + 1 year after deletion. After retention periods, data will be anonymized or permanently deleted.

8. Data Subject Rights (LGPD Art. 18)

You have the following rights guaranteed by the LGPD, which can be exercised at any time via email studio.kodaai@gmail.com: a) Confirmation and Access (Art. 18, I and II): Confirm the existence of processing and access your personal data. b) Correction (Art. 18, III): Correct incomplete, inaccurate or outdated data. c) Anonymization, Blocking or Deletion (Art. 18, IV): Request anonymization, blocking or deletion of unnecessary, excessive or non-compliant data. d) Portability (Art. 18, V): Request portability of your data to another service or product provider, upon express request. e) Deletion of Consent-Based Data (Art. 18, VI): Delete data whose processing was based on consent. f) Information about Sharing (Art. 18, VII): Obtain information about public and private entities with which we share your data. g) Information about Consent Refusal (Art. 18, VIII): Know the consequences of not providing consent. h) Consent Revocation (Art. 18, IX): Revoke consent at any time (may limit functionality). Response Time: We will respond to requests within 15 calendar days. In complex cases, we may extend for an additional 15 days, with prior notice.

9. Data Security

We adopt rigorous technical and organizational measures to protect your data against unauthorized access, loss, destruction or alteration: • Encryption: Sensitive data (passwords, tokens) are encrypted at rest and in transit (TLS 1.3). • Secure Authentication: Firebase Authentication with optional two-factor authentication (2FA). • Access Control: Only authorized employees have access to personal data, under confidentiality. • Firewall and Monitoring: Protection against DDoS attacks, SQL injection and other threats. • Regular Backups: Automated daily backups with 30-day retention. • Audits: Periodic security and LGPD compliance reviews. Despite our efforts, no system is 100% secure. In case of a security incident that may pose a risk to your rights, we will notify you and ANPD as required by LGPD.

10. Cookies and Similar Technologies

We use cookies and similar technologies to improve your experience on the Platform. For detailed information about which cookies we use, their purposes and how to manage them, see our complete Cookie Policy at: /cookies Types of Cookies:Strictly Necessary: Essential for Platform operation (login, session). • Functional: Remember preferences (language, theme). • Analytical: Google Analytics 4 for usage metrics (anonymized). You can manage cookies through your browser settings.

11. Minors' Data

Universo Pet is not directed to minors under 18 years of age. We do not intentionally collect personal data from children or adolescents without the consent of parents or legal guardians, as required by Art. 14 of the LGPD. If we identify that we have collected data from minors without authorization, we will delete this information immediately. If you believe a minor has provided data without consent, contact: studio.kodaai@gmail.com

12. International Data Transfer

Your personal data may be transferred and stored on servers located outside Brazil, especially in the United States (Firebase/Google Cloud, Stripe). These transfers are carried out in accordance with Art. 33 of the LGPD and include adequate protection guarantees, such as: • Standard Contractual Clauses (SCC): Contracts approved by the European Commission. • Certifications: Partners certified in international data protection standards (ISO 27001, SOC 2). • Adequacy: Countries with adequate level of data protection recognized by ANPD. You can request more information about specific safeguards through the DPO email.

13. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legislation or services. When we make material changes, we will notify you by email or through a prominent notice on the Platform, with at least 15 days' advance notice. Last update date: December 16, 2025 We recommend reviewing this page regularly to stay informed about how we protect your data.

14. Contact and Data Protection Officer

For questions, requests or exercise of rights related to this Privacy Policy and the LGPD, contact: DPO Email: studio.kodaai@gmail.com Subject: "LGPD - [Your Name] - [Request Type]" Physical Address: Universo Pet Tecnologia Ltda. Esplanada, Bahia, Brazil Related Pages: • Terms of Use: /termos • Cookie Policy: /cookies • Legal Notice: /aviso-legal We are available to clarify any questions about how we process your personal data.