Privacy Policy
Last updated: 18/02/2026
1. Introduction
BIX Tecnologia ("Company", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share personal data when you use the Spire platform ("Platform"). By using the Platform, you consent to the practices described in this policy.
2. Data We Collect
We may collect the following categories of personal data: (a) Registration data: name, corporate email, phone number; (b) Employment data: position, department, manager, admission date, employment type; (c) Account data: login credentials and authentication tokens; (d) Usage data: access logs, features used, IP address, browser and device information; (e) Content data: information you or your organization input into the Platform, such as performance reviews, OKRs, survey responses, and celebrations.
3. How We Use Your Data
We use personal data to: (a) provide, maintain, and improve the Platform and its features; (b) authenticate users and enforce role-based access control; (c) send transactional communications such as notifications, reminders, and alerts; (d) send marketing communications, campaigns, and newsletters through ActiveCampaign, when you have opted in to receive them; (e) process subscription payments securely through Stripe; (f) generate analytics and reports for your organization; (g) comply with legal obligations and enforce our Terms of Use.
4. Legal Basis for Processing
We process personal data based on the following legal grounds, in accordance with the Brazilian General Data Protection Law (LGPD) and other applicable regulations: (a) performance of contract — to provide the services you subscribed to; (b) legitimate interest — to improve the Platform and ensure security; (c) consent — when explicitly given by the user; (d) legal obligation — to comply with applicable laws and regulations.
5. Data Sharing
We do not sell personal data. We may share data with: (a) cloud infrastructure providers (hosting, storage, email delivery) that process data on our behalf under strict data processing agreements; (b) analytics providers, such as PostHog and Google Analytics, which receive usage data to help us understand how the Platform is used and improve our services; (c) marketing and tag management tools, such as Google Tag Manager, which help us measure the effectiveness of our communications; (d) ActiveCampaign, a marketing automation platform used to manage email campaigns, newsletters, and marketing communications. ActiveCampaign may receive your name and email address to deliver campaigns you have opted in to receive; (e) Stripe, a payment processing platform used to securely handle subscription payments. Stripe may receive your billing information (such as name, email, and payment card details) to process transactions. Stripe is PCI-DSS compliant and handles payment data in accordance with industry security standards; (f) your organization's administrators, who have access to employee data within their tenant; (g) legal authorities when required by law or court order. All third-party providers are contractually obligated to protect your data and use it solely for the purposes we specify.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including: encryption in transit (TLS) and at rest; role-based access control; regular security assessments; isolated multi-tenant architecture ensuring that each organization's data is logically separated. While we strive to protect personal data, no method of transmission or storage is 100% secure.
7. Cookies and Tracking
The Platform uses cookies and similar technologies to enhance user experience, remember preferences, and collect usage analytics. We use the following third-party analytics and tracking tools: (a) PostHog — a product analytics platform that helps us understand how users interact with the Platform, identify usage patterns, and improve our services. PostHog may collect user identifiers, session data, pages visited, and feature interactions; (b) Google Analytics — to analyze overall Platform usage and generate statistical reports on user activity; (c) Google Tag Manager — to manage and deploy tracking tags on the Platform; (d) ActiveCampaign — a marketing automation platform that may set cookies or use tracking pixels to monitor email campaign engagement and deliver personalized marketing content. These tools may set cookies on your device. You can manage cookie preferences through your browser settings. Disabling cookies may affect some Platform functionality. For more details, see our Cookie Policy.
8. Third-Party Integrations (Optional)
The Platform offers optional third-party integrations to enhance your experience. These integrations are entirely voluntary and can be enabled or disabled at any time: (a) Google Sign-In: You may choose to sign in to the Platform using your Google account. When you do, we receive basic profile information (such as your name and email address) from Google to authenticate your identity. We do not access any other Google account data beyond what is necessary for authentication; (b) GitHub Integration: Your organization may optionally connect GitHub to the Platform to enable developer analytics for your team. When enabled, we access repository and contribution data from GitHub to generate insights about developer activity. This integration is configured by your organization's administrator and is limited to the repositories your organization authorizes; (c) Google Calendar Integration: You may optionally connect your Google Calendar to the Platform to facilitate scheduling one-on-one meetings. When enabled, we access your calendar availability to help coordinate meetings. We do not read, modify, or store the content of your calendar events beyond what is needed for scheduling. All third-party integrations use OAuth 2.0 for secure authorization. You can revoke access to any integration at any time through your account settings or through the respective third-party service's settings.
9. Contact
If you have questions or concerns about this Privacy Policy or your personal data, please contact us at [email protected].
