Privacy Policy

Last updated: July 10, 2026

Who we are

This Privacy Policy explains how HDZ Desenvolvimento Ltda. ("Dimmy Tools", "we", "us" or "our") collects, uses, shares and protects personal data when you visit our storefront, create an account, purchase and activate our software, or otherwise interact with us.

Data controller: HDZ Desenvolvimento Ltda., registered under CNPJ No. 67.232.292/0001-69.

For any privacy request or question, contact our Data Protection Officer at support@dimmytools.com.

This policy is referenced by, and complements, our Terms of Use and Software License. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA) and other applicable U.S. state privacy laws. Brazilian users should read the Portuguese-language version, written to comply with Lei nº 13.709/2018 (LGPD).

Scope

This policy applies to personal data we process about: visitors to our storefront; customers who buy and activate licenses; people who create a customer-portal account; and administrators/staff who use our back-office dashboard. Our software is a professional tool for stage-lighting technicians and is not directed to consumers, amateurs or children.

Personal data we collect

Account and identity data. Your name, email address, preferred language, and a securely hashed password (we never store your password in plain text). If you enable two-factor authentication, we store the related secret and backup codes.

Billing and tax data. For orders billed in Brazilian Reais (processed by Asaas), we collect your tax identifier (CPF or CNPJ), phone number and full billing address (street, number, complement, postal code, neighborhood, city, state and country). For orders billed in US Dollars (processed by Stripe) we collect your name and email; Stripe collects payment and address details directly on its own checkout page.

Order and payment data. Your order history (items, amounts, currency, coupons, dates and status), the chosen payment method and installment plan, and the identifiers returned by our payment processors (Stripe and Asaas customer, checkout and payment IDs). We do not collect or store full credit-card numbers — card data is handled entirely by the payment processor on its own secure environment.

License and device data. The license codes we issue to you; the serial number of the USB hardware key (dongle) to which a license is bound; and, when you activate, re-validate or run the software, the IP address of the device, the software version, activation timestamps and security tokens. We keep an activation audit trail and may receive best-effort diagnostic events (for example crash or launch events) tied to the license code and dongle serial. This data is used to deliver the license, enforce the license terms and detect cloning or fraud.

Technical and security data. When you sign in we record the IP address and browser/device user-agent associated with your session, plus session tokens. We use this for authentication, security and abuse prevention.

Cookies, analytics, advertising and usage data. Strictly necessary cookies that keep you signed in and protect against fraud; your cookie-consent choice; and, only if you consent, Google Analytics measurement cookies and identifiers and Meta (Facebook/Instagram) advertising cookies and identifiers. When you have accepted advertising cookies, we also measure our advertising server-side by sending Meta a limited set of purchase and event data — including hashed contact details (such as email and phone number), your IP address and browser user-agent — through Meta’s Conversions API. See “Cookies and similar technologies” below.

Communications. The content of support requests and the transactional emails we send you (order confirmations, license delivery, email verification and password resets).

How we collect personal data

We collect data directly from you (when you create an account, check out, edit your profile or contact support); automatically (through your use of the storefront and software — sessions, activations, diagnostic events and cookies); and from our payment processors (who confirm payment status and return the identifiers listed above).

Why we use your data and our legal bases

We process personal data on the following legal bases (GDPR Article 6; LGPD Article 7):

Performance of a contract: to create and manage your account, process orders, issue and deliver licenses, enable downloads and provide customer support.

Legal obligation: to comply with tax, accounting and consumer-protection law — for example retaining invoicing data and the tax identifier (CPF/CNPJ) for the periods required by Brazilian law.

Legitimate interests: to secure our service and accounts, prevent fraud and abuse, enforce our license terms and detect cloning of the software (for example by comparing dongle serials, IP addresses and rotating activation tokens), keep audit trails, and improve our products. Where we rely on legitimate interests, we balance them against your rights and freedoms.

Consent: for non-essential cookies — including analytics and advertising/remarketing cookies — and for any optional marketing communications. You may withdraw consent at any time without affecting prior processing.

Cookies and similar technologies

We use strictly necessary cookies that are required to run the storefront — for example to keep you signed in, remember your language/currency and cart, store your cookie-consent choice and protect against fraud and bots. These do not require consent.

We use analytics cookies (Google Analytics) only after you accept them in our cookie banner. Until you accept, no analytics cookies are set and no analytics scripts load. You can change or withdraw your choice at any time through the cookie banner; rejecting analytics does not affect your ability to browse or buy.

We use advertising cookies (Meta Pixel) only after you accept them in our cookie banner. These allow us to measure the results of our advertising campaigns and to show you relevant ads on Meta platforms (Facebook and Instagram), including re-engaging visitors who have shown interest in our products (“remarketing”). Until you accept, the Meta Pixel does not load and no advertising cookies are set. Analytics and advertising are enabled together only after you accept them in the cookie banner; if you choose essential-only, neither loads. You can change or withdraw your choice at any time through the cookie banner; rejecting advertising cookies does not affect your ability to browse or buy. We set the related first-party cookies (for example _fbp and _fbc) on our own domain and — only with your consent — also send the corresponding events to Meta from our servers through the Meta Conversions API, so measurement works even when in-browser scripts are blocked. When you enter your details at checkout, we may also pass a hashed version of your email and phone number to Meta to improve ad measurement.

How we share your data

We do not sell your personal data. We share it only with service providers ("processors") who handle it on our behalf and under contract, and where required by law:

Payment processors — Stripe (orders in US Dollars) and Asaas (orders in Brazilian Reais, including PIX and credit card). They receive the data needed to process your payment (such as name, email and, for Asaas, tax ID, phone and address).

Cloud infrastructure — Cloudflare, which hosts our application, database, file storage, email-sending and bot-protection (Turnstile).

Analytics — Google (Google Analytics), only with your consent.

Advertising and measurement — Meta Platforms (Facebook and Instagram), only with your consent, to measure the performance of our advertising and to show you relevant ads and re-engage visitors (remarketing). This is done both through the Meta Pixel in your browser and, server-to-server, through Meta’s Conversions API, to which — only with your consent — we send event data including hashed contact details (email, phone, name, city, state, postal code, country and a customer identifier), your IP address and browser user-agent, and purchase details (such as order value, currency and the products purchased). Meta uses the hashed identifiers only to match events to accounts for measurement and ad delivery.

Fonts — Adobe (Adobe Fonts / Typekit), which serves the website’s typefaces. Loading a font sends your IP address to Adobe; Adobe Fonts does not set cookies.

Authorities and third parties when necessary to comply with the law, a legal process or a lawful request, or to protect our rights, safety or property.

A current list of our key sub-processors is available on request from support@dimmytools.com.

International data transfers

We are based in Brazil and some of our processors (such as Stripe, Cloudflare, Google and Meta) are located in or transfer data to the United States and other countries. Where personal data is transferred internationally, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and equivalent mechanisms for transfers out of Brazil under the LGPD — to ensure your data remains protected.

How long we keep your data

We keep personal data only as long as necessary for the purposes described above. Account and order data are retained for the duration of your relationship with us and afterwards for the periods required by tax, accounting and consumer-protection law (which in Brazil can reach several years). Security and audit logs are kept for as long as needed to investigate incidents and meet our legal obligations. When you ask us to delete your account we apply a soft-delete that suspends your licenses; some records are retained where the law requires or to defend legal claims, after which they are deleted or anonymised. Where you have consented to advertising cookies, the advertising and measurement identifiers we capture at checkout (such as the _fbp and _fbc cookie values, your IP address and browser user-agent) are stored with the corresponding order and retained for the same period as the order record.

How we protect your data

We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), hashing of passwords, two-factor authentication for staff, role-based access controls, scoped API access, bot protection and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the competent authority of a breach where the law requires.

Your rights

Subject to applicable law, you have the right to:

–    access the personal data we hold about you, and obtain confirmation of whether we process it;

–    rectify inaccurate or incomplete data (you can edit much of your profile and billing data directly in your account);

–    erase your data ("right to be forgotten"), subject to legal retention obligations;

–    restrict or object to certain processing, including processing based on legitimate interests;

–    data portability — receive your data in a structured, machine-readable format;

–    withdraw consent at any time (for example for analytics cookies, advertising cookies or marketing);

–    not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and

–    lodge a complaint with a supervisory authority.

To exercise any of these rights, email support@dimmytools.com. We may need to verify your identity. We respond within the timeframes required by applicable law and do not charge a fee unless your request is manifestly unfounded or excessive. EU/EEA users may complain to their local Data Protection Authority; Brazilian users may complain to the Autoridade Nacional de Proteção de Dados (ANPD).

Automated decisions

We use automated checks to detect license cloning and fraud (for example comparing dongle serials, IP addresses and rotating tokens). These checks may flag suspicious activity, but we do not suspend or revoke a license solely by automated means — a human reviews the case before any decision with a significant effect on you. You may request human review of, and contest, any such decision.

United States — your privacy rights

If you are a resident of California or another U.S. state with a comprehensive privacy law, you have rights to know, access, correct, delete and obtain a portable copy of your personal information, and to be free from discrimination for exercising those rights.

When you consent to advertising cookies, we may "share" your personal information — such as online identifiers, hashed contact details, device and connection information (IP address and user-agent), purchase details, and your activity on our storefront — with Meta for cross-context behavioural advertising, as those terms are defined under California and other U.S. state privacy laws. You have the right to opt out of this "sharing" at any time: you can do so by rejecting or withdrawing consent to advertising cookies in our cookie banner. We do not sell your personal information for monetary consideration, and we do not use sensitive personal information for purposes that require an opt-out.

The categories of personal information we collect, our purposes and the third parties we disclose to are described in the sections above. To exercise your rights, contact support@dimmytools.com; you may use an authorised agent where the law allows.

Children

Our storefront and software are professional tools intended for adults working in stage lighting. They are not directed to children, and we do not knowingly collect personal data from anyone under 18 (or the age of majority in your jurisdiction). If you believe a minor has provided us data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date above and, where the change is material, take additional steps required by law to inform you. Your continued use of our services after an update means you have read the current policy.

Contact us

Questions, requests or complaints about this policy or your personal data: support@dimmytools.com.