Terms of Use
Last updated: September 19, 2026
This document is a draft under legal review and is not yet in force.
These Terms of Use (“Terms”) are a binding agreement between you and BreezeAuth. Please read them carefully. By using the Service you accept these Terms in full.
1. Who we are
BreezeAuth is operated by Breeze Tecnologia LTDA, enrolled with the Brazilian corporate taxpayer registry (CNPJ) under no. 69.212.422/0001-27, with registered offices at RUA RIO GRANDE DO NORTE, 1436, SALA 813 - SAVASSI, BELO HORIZONTE - MG, 30130-138 (“BreezeAuth”, “we”, “us”).
Contact for matters relating to these Terms: [email protected].
2. Acceptance of these Terms
2.1 By creating an account, creating or joining an Organization, or otherwise accessing or using the BreezeAuth platform (the “Service”), you agree to these Terms and to our Privacy Policy, which forms an integral part of this agreement.
2.2 If you accept these Terms on behalf of a company or another legal entity, you represent that you are duly authorised to bind that entity, and “you” refers to that entity.
2.3 If you do not agree with any provision of these Terms, you must not use the Service.
2.4 The Service is designed and offered for professional and business use. Where, exceptionally, the relationship qualifies as a consumer relationship under the Brazilian Consumer Protection Code (Law no. 8.078/1990), the rights afforded by that law prevail over any conflicting provision of these Terms.
3. Definitions
- Service: the BreezeAuth identity platform, including the administrative console, the end-user portal, the authentication endpoints and the related documentation.
- Organization: the workspace created in the Service by a Customer, within which users, groups, applications and policies are managed.
- Customer: the individual or legal entity that creates an Organization and is responsible for it.
- Administrator: a user holding an administrative role in an Organization (Owner, Administrator, Helpdesk, Auditor or Billing).
- End User: an individual who authenticates through the Service as a member of an Organization.
- Managed Account: an End User account whose e-mail address belongs to a domain verified by the Organization, and which is therefore subject to the Organization’s policies and administrative control.
- Guest Account: an End User account on an unverified domain, which is not subject to the Organization’s password, multi-factor authentication and session policies.
- Customer Data: all data submitted to, stored in or generated by the Service on behalf of an Organization, including user records, groups, application configuration and audit logs.
- Free Plan: the plan made available at no charge, under the conditions of these Terms.
- Paid Plan: any plan subject to a fee, under the conditions published at the time of subscription.
- LGPD: the Brazilian General Data Protection Law (Law no. 13.709/2018).
4. The Service
4.1 BreezeAuth is an identity provider. It allows an Organization to centralise authentication and to grant access to third-party and internal applications through single sign-on using the SAML 2.0 and OpenID Connect protocols.
4.2 The Service includes, according to the contracted plan, user and group management, domain verification, application registration and assignment, attribute and claim mapping, multi-factor authentication, passkeys, password and session policies, network and country access restrictions, incident response controls and audit logs.
4.3 The Service does not include the third-party applications that you connect to it. Your use of those applications is governed by your agreements with their respective providers.
4.4 We may evolve, add, modify or discontinue features of the Service. Where a change materially reduces a core function of a Paid Plan, we will give you reasonable prior notice.
5. Registration and accounts
5.1 To use the Service you must provide true, accurate and complete information, and keep it up to date.
5.2 You are responsible for safeguarding your credentials and authentication factors, and for all activity carried out under your account. We strongly recommend enabling multi-factor authentication on every administrative account.
5.3 You must be at least 18 years old, or otherwise legally capable of entering into this agreement.
5.4 You must notify us without undue delay, through the channels published on our website, of any unauthorised use of your account or any other suspected breach of security.
5.5 We may refuse, suspend or cancel a registration that violates these Terms or applicable law.
6. Organizations, Administrators and End Users
6.1 The person who creates an Organization is assigned the Owner role and holds full control over it, including the ability to appoint and remove other Administrators.
6.2 Administrators may, according to their role, manage users, groups, applications, security policies and billing, read audit logs, terminate active sessions, force password changes and lock access to applications. The Customer is responsible for assigning administrative roles only to trusted individuals.
6.3 When an Organization verifies a domain, accounts whose e-mail address belongs to that domain become Managed Accounts and are subject to the Organization’s administrative control and policies. Guest Accounts retain greater autonomy.
6.4 The Customer is solely responsible for informing its End Users, in a clear and adequate manner, that their accounts are administered by the Organization, and for obtaining any consent or providing any notice required by applicable law.
6.5 Any dispute between an Organization and its Administrators or End Users is the Organization’s responsibility. We are not a party to such disputes and have no obligation to mediate them.
7. Acceptable use
7.1 You agree to use the Service lawfully and in accordance with these Terms, and not to:
- violate any applicable law or regulation, or infringe the rights of third parties;
- access, or attempt to access, accounts, systems, data or networks without authorisation;
- interfere with or disrupt the integrity, security or performance of the Service, including through load testing, denial-of-service attempts or automated mass requests, without our prior written consent;
- circumvent or attempt to circumvent usage limits, security measures, rate limits or authentication mechanisms;
- reverse engineer, decompile or attempt to extract the source code of the Service, except to the extent such restriction is prohibited by law;
- resell, sublicense or make the Service available to third parties outside your Organization, unless expressly agreed with us in writing;
- upload or process content that is unlawful, defamatory, or that contains malicious code;
- use the Service to send unsolicited communications or to carry out phishing or credential-harvesting activities.
7.2 You are responsible for the Customer Data you submit and for the configuration you apply, including attribute and claim mapping, signing certificates, entitlements and access restrictions. Incorrect configuration may grant or deny access improperly, and we are not liable for the consequences of configuration choices made by you.
8. Plans, fees and payment
8.1 The Free Plan is made available at no charge and is subject to the usage limits published on our website, which may include limits on the number of users, applications, audit log retention and request volume.
8.2 We may change the limits of the Free Plan or discontinue it, in whole or in part, at any time, giving reasonable prior notice through the Service or by e-mail where practicable.
8.3 Paid Plans are billed according to the conditions presented at the time of subscription, including the price, billing period and payment method. Prices are stated in Brazilian reais unless otherwise indicated and do not include taxes, which will be added where applicable.
8.4 Late payment may result in the suspension of access to the Organization, after prior notice, without prejudice to the charges due. Applicable interest and penalties follow the conditions presented at the time of subscription and the limits set by law.
8.5 We may change the prices of Paid Plans with at least thirty (30) days’ prior notice, effective from the next billing period. You may terminate before the new price takes effect.
8.6 Amounts already paid for a period in progress are not refundable, except where a refund is required by applicable law or expressly stated in the plan conditions.
9. Support, availability and service levels
9.1 Free Plan — no service level and no real-time support. The Free Plan is provided free of charge, “as is” and “as available”, and is expressly not covered by any service level agreement (SLA). In particular, on the Free Plan:
- there is no real-time support of any kind, including no telephone support, no live chat, no on-call or 24x7 support, and no dedicated point of contact;
- there is no guaranteed response time and no guaranteed resolution time; requests are answered, if at all, on a best-effort basis, during our business hours, and in the order in which they are received;
- there is no availability or uptime commitment, no credit, refund or indemnity of any kind for unavailability, degradation, data loss or interruption;
- support is limited to the self-service documentation and to the asynchronous channels published on our website, and we may change or discontinue those channels at any time.
9.2 By choosing the Free Plan you expressly acknowledge and accept the conditions of clause 9.1, and you accept the risks inherent in using a service provided at no charge.
9.3 Because of clause 9.1, the Free Plan should not be used as the sole authentication mechanism for critical systems unless you maintain your own contingency access to those systems (for example, a local administrative account not dependent on the Service). You are solely responsible for defining and testing such contingency measures.
9.4 Real-time support, priority support, guaranteed response times and any availability commitment are offered only on the Paid Plans that expressly provide for them, in the terms and to the extent stated in the respective plan description or in a separate service level agreement.
9.5 We do not warrant that the Service will operate without interruption or free of errors. Scheduled maintenance, emergency maintenance, failures of third-party providers, incidents affecting internet connectivity and events beyond our reasonable control may affect availability. We will endeavour to give prior notice of scheduled maintenance whenever practicable.
9.6 We may apply rate limits and other technical protections to preserve the stability and security of the Service for all customers.
10. Protection of personal data (LGPD)
10.1 Roles of the parties. In relation to the personal data of End Users and to the other Customer Data processed within an Organization, the Customer acts as controller and BreezeAuth acts as processor, as those roles are defined in article 5 of the LGPD. In relation to the data we collect for our own purposes — including registration of the contracting party, billing, prevention of fraud and abuse, platform security and compliance with legal obligations — BreezeAuth acts as controller.
10.2 Instructions. We will process personal data on behalf of the Customer only to provide, maintain and secure the Service, in accordance with these Terms, with the documented instructions given by the Customer through the functions of the Service, and with applicable law. If we are required by law to process data beyond those instructions, we will inform the Customer in advance unless the law prohibits it.
10.3 Legal basis and lawfulness. The Customer represents and warrants that it has an appropriate legal basis under the LGPD for the processing it carries out through the Service, that it has provided the required information to data subjects, and that its instructions do not cause us to breach the LGPD or any other applicable legislation.
10.4 Purpose limitation. We will not use the Customer’s personal data for our own purposes, nor sell it, nor share it for commercial purposes unrelated to the provision of the Service.
10.5 Sub-processors. We may engage sub-processors — in particular cloud infrastructure, e-mail delivery, monitoring and payment providers — to support the provision of the Service. We impose on each sub-processor data protection obligations equivalent to those set out in this clause 10 and we remain responsible to the Customer for their performance. The current list of sub-processors is available on request and, where published, on our website. We will notify the Customer of the addition of a new sub-processor with reasonable prior notice.
10.6 Security measures. We adopt technical and administrative security measures appropriate to the risk, in accordance with article 46 of the LGPD, including encryption in transit and at rest, access control based on the principle of least privilege, segregation of environments, logging of administrative access and periodic review of our controls. The specific measures are described in our Privacy Policy and may be updated to maintain or raise the level of protection.
10.7 Security incidents. Upon becoming aware of a security incident that may result in relevant risk or damage to data subjects, we will notify the Customer without undue delay, providing the information reasonably available to us so that the Customer, as controller, may meet its obligations under article 48 of the LGPD, including any communication to the Brazilian Data Protection Authority (ANPD) and to the affected data subjects. Such notification does not constitute an acknowledgement of fault or liability.
10.8 Rights of data subjects. Requests from data subjects under article 18 of the LGPD must be addressed to the Customer, as controller. We will provide the Customer with the functions of the Service and, where necessary, reasonable assistance so that it can respond within the legal time limits. If a data subject contacts us directly in relation to data processed on behalf of an Organization, we will refer the request to the Customer and inform the data subject accordingly.
10.9 Confidentiality. Our personnel and any third parties with access to personal data processed on behalf of the Customer are bound by confidentiality obligations and receive access only to the extent necessary to perform their duties.
10.10 Deletion and return. Upon termination of the agreement, the Customer may export its Customer Data using the functions available in the Service. After the end of the retention period stated in our Privacy Policy, we will delete or anonymise the personal data processed on behalf of the Customer, except where retention is required to comply with a legal or regulatory obligation, or for the regular exercise of rights in judicial, administrative or arbitral proceedings, under article 16 of the LGPD.
10.11 International transfers. The Service may use infrastructure located outside Brazil. Where personal data is transferred internationally, we will ensure that the transfer complies with articles 33 to 36 of the LGPD, adopting the applicable safeguards and contractual instruments.
10.12 Records and demonstration of compliance. Upon reasonable written request, and no more than once per calendar year except where required by the ANPD or by law, we will provide the Customer with the information reasonably necessary to demonstrate compliance with this clause 10, preserving our own confidentiality obligations and the security of the Service.
10.13 Data protection officer. Our data protection officer (“encarregado”, article 41 of the LGPD) may be contacted at [email protected].
10.14 Internet records. We keep the records of application access required by the Brazilian Civil Rights Framework for the Internet (Law no. 12.965/2014) for the periods established therein.
11. Confidentiality
11.1 Each party undertakes to keep confidential the non-public information of the other party to which it has access as a result of this agreement, and to use it solely for the purposes of the Service.
11.2 This obligation does not apply to information that is or becomes public without fault of the receiving party, that was already lawfully known to it, that it develops independently, or whose disclosure is required by law or by a competent authority, in which case the disclosing party will be informed in advance whenever permitted.
11.3 This obligation survives the termination of the agreement for five (5) years, and indefinitely in the case of personal data and trade secrets.
12. Intellectual property
12.1 The Service, including its software, interfaces, design, trademarks, documentation and any derived materials, is owned by BreezeAuth or its licensors and is protected by applicable intellectual property law.
12.2 Subject to these Terms and to payment of the applicable fees, we grant you a non-exclusive, non-transferable, revocable licence, valid for the term of the agreement, to use the Service for your own internal purposes.
12.3 No provision of these Terms transfers to you any ownership right in the Service. All rights not expressly granted are reserved.
12.4 The Customer retains all rights in the Customer Data. The Customer grants us a limited licence to host, process and transmit the Customer Data solely to the extent necessary to provide the Service.
12.5 If you send us suggestions or feedback, we may use them freely and without restriction or compensation, without acquiring any right in your confidential information.
13. Suspension and termination
13.1 You may terminate this agreement at any time by ceasing to use the Service and deleting your Organization, without prejudice to amounts already due.
13.2 We may suspend or limit access to the Service, in whole or in part, where: (a) there is a breach of these Terms; (b) there is a relevant risk to the security, integrity or availability of the Service or of third parties; (c) payment is overdue; or (d) it is required by law or by a competent authority. Except where the risk requires immediate action, we will give prior notice and, where applicable, an opportunity to remedy.
13.3 We may terminate this agreement, with respect to the Free Plan, upon reasonable prior notice, including in the event of the discontinuation of that plan.
13.4 Upon termination, access to the Service ceases and the Customer Data is handled as described in clause 10.10. It is the Customer’s responsibility to export its data before the effective date of termination.
14. Warranties and disclaimers
14.1 We provide the Service with the technical diligence expected of a professional supplier, in accordance with these Terms and the description of the contracted plan.
14.2 Except as expressly stated in these Terms or in the description of a Paid Plan, and to the maximum extent permitted by applicable law, the Service is provided “as is”, without warranties of any kind, whether express or implied, including any warranty of fitness for a particular purpose, uninterrupted availability, absence of errors, or that the Service will meet specific requirements of the Customer.
14.3 We do not warrant that the Service will prevent every unauthorised access attempt. Authentication security also depends on the configuration, policies and practices adopted by the Customer and its End Users.
15. Limitation of liability
15.1 To the maximum extent permitted by applicable law, neither party is liable for indirect damages, loss of profits, loss of revenue, loss of business opportunity, loss of data other than that caused by proven fault, or reputational harm.
15.2 To the maximum extent permitted by applicable law, our aggregate liability arising out of or in connection with this agreement, in any twelve (12) month period, is limited to the total amount actually paid by the Customer for the Service in the twelve (12) months preceding the event giving rise to the claim.
15.3 For Organizations on the Free Plan, as no amount is paid for the Service, our liability is limited to the maximum extent permitted by applicable law, and no credit, refund or indemnity is due for unavailability, degradation or interruption of the Service.
15.4 The limitations in this clause 15 do not apply to liability for wilful misconduct, nor to any liability that cannot be limited or excluded under applicable law.
15.5 The limitations in this clause 15 do not exclude the obligations of each party under clause 10, which are governed by the LGPD and by the applicable liability rules.
16. Indemnification
The Customer agrees to hold BreezeAuth harmless against third-party claims arising from: (a) the Customer Data or its content; (b) the use of the Service in breach of these Terms or of applicable law; (c) the configuration applied by the Customer; or (d) the relationship between the Customer and its End Users, provided that we give the Customer prompt notice of the claim and reasonable cooperation in the defence.
17. Changes to these Terms
17.1 We may amend these Terms to reflect changes in the Service, in our practices or in applicable law.
17.2 Material changes will be communicated at least thirty (30) days in advance through the Service or by e-mail to the address registered by the Customer. Non-material changes take effect upon publication.
17.3 Continued use of the Service after the effective date of the change constitutes acceptance of the amended Terms. If you do not agree, you may terminate the agreement before that date.
17.4 The date of the last update is shown at the top of this page.
18. General provisions
18.1 Assignment. You may not assign this agreement without our prior written consent. We may assign it in the event of a corporate reorganisation, merger or sale of assets, provided that the level of protection of the Customer Data is preserved.
18.2 Force majeure. Neither party is liable for failure to perform caused by events beyond its reasonable control, including acts of God, force majeure, general failures of telecommunications or energy, governmental acts and large-scale cyberattacks.
18.3 Independence of the parties. This agreement does not create any employment relationship, partnership, joint venture or agency between the parties.
18.4 Severability. If any provision of these Terms is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision will be replaced by a valid one that most closely reflects the original intent.
18.5 Waiver. Failure to exercise a right does not constitute a waiver of it.
18.6 Notices. Notices to the Customer will be sent to the e-mail address registered in the Organization. Notices to us must be sent to the address stated in clause 1.
18.7 Entire agreement. These Terms, together with the Privacy Policy and the description of the contracted plan, constitute the entire agreement between the parties in relation to the Service and supersede any prior understanding on the same subject.
18.8 Language. These Terms are made available in Portuguese, English and Spanish. In the event of any discrepancy, the Portuguese version prevails.
19. Governing law and venue
19.1 These Terms are governed by the laws of the Federative Republic of Brazil.
19.2 The parties elect the courts of the district of Belo Horizonte, State of Minas Gerais as the competent venue to settle any dispute arising out of this agreement, to the exclusion of any other, however privileged, without prejudice to the right of a consumer, where clause 2.4 applies, to bring proceedings in the courts of their domicile.
20. Contact
Questions about these Terms may be sent to [email protected]. Matters concerning personal data may be sent to our data protection officer at [email protected].