MyAlva Student App - Privacy Policy

Last Updated: 24 July 2026

1. What information is included in this Privacy Policy?

In this Privacy Policy, users of the MyAlva App will find information regarding:

  • The processing of personal data carried out and its purposes;
  • The personal data required for the provision of this service;
  • Information regarding cookies;
  • The way personal data is processed;
  • The security measures used to protect personal data;
  • Information regarding the sharing of data with third parties.

Privacy and security are priorities for the MyAlva App, which is committed to transparency in the processing of its users' personal data (data subjects). Therefore, this Privacy Policy establishes how the personal data of users who access the MyAlva App is processed.

By using the MyAlva App services, the user acknowledges that their personal data may be processed and shared in the manner described in this Privacy Policy and agrees to its terms.

Pursuant to Article 5, item VI, of Law No. 13.709/2018 (LGPD), the controller is defined as the "natural person or legal entity, whether governed by public or private law, responsible for decisions regarding the processing of personal data." This is ALVA FUTURES, LDA. Registration number i NIPC nº 519.365.399 at Lisboa, Portugal contact: info@alvafutures.com

2. Purpose of Data Processing

The purpose of the processing of your personal data is to link students and consulting companies in order to file university and higher education applications.

3. Legal Basis for Processing

In accordance with the Brazilian General Data Protection Law (LGPD), personal data processing shall be carried out based on the following legal grounds:

—Article 7. The processing of personal data may only be carried out under the following circumstances:

V — When necessary for the execution of a contract or preliminary arrangements related to a contract to which the data subject is part, upon its own request. (...)

3.1 Personal Data Processed

For the purposes described above, in paragraph 2, MyAlva App may process:

  1. Student identification and contact information (such as name, email address, telephone number, date of birth and school information);
  2. Parent or guardian identification and contact information (such as name, email address and telephone number);
  3. Address and location information (such as address, city, state, postal code and country);
  4. Academic, admissions and enrollment information (such as test scores, university selections, application status, deadlines and related records);
  5. Documents uploaded to the platform by students, parents, guardians or educational consultants, which may include identification documents (such as passports), academic records, school reports, recommendation letters, essays, résumés, portfolios, financial information, medical records, enrollment documents and other supporting application materials;
  6. Platform usage and technical information (such as login information, activity logs, notification history, device information, browser or application information, IP address and security-related records).

3.2 Cookies and Similar Technologies

The MyAlva App does not use cookies. Instead, it uses local storage technologies (Local Storage on the web portal and AsyncStorage on the mobile app) to support the operation, security and functionality of the service.

Technologies Used

TechnologyPurposeProviderRetention Period
Local Storage / AsyncStorage — authentication token (access token)To maintain the user's authenticated sessionMyAlva (first party)The access token expires after 8 hours and is removed when the user logs out
Local Storage / AsyncStorage — session refresh token (refresh token)To renew the login session to prevent the user from being logged out prematurelyMyAlva (first party)The refresh token expires after 7 days and is removed when the user logs out
Local Storage — interface/application stateStore simple interface preferences (e.g. menu state)MyAlva (first party)Remains stored until the user clears the data from the browser or the application

These technologies may be used for:

  • authenticating users and maintaining active login sessions;
  • renewing sessions via refresh tokens, preventing premature logouts;
  • storing interface preferences and settings;
  • ensuring the security and integrity of the platform;
  • supporting the technical operation and performance of the service.

Third party services used by MyAlva

  • Analytics provider(s): No. MyAlva does not use analytics technologies.
  • Error monitoring provider(s): No. MyAlva does not use error monitoring technologies.
  • Other third-party technologies: Google Cloud Platform (cloud hosting and infrastructure) and SendGrid (transactional email delivery services).

Technical data processed by MyAlva

MyAlva stores and processes the following technical data:

Data categoryProcessed?Where it is heldRetention Period
Login informationYesAccount record — email address, password (stored hashed, never in plain text), last login date, account creation date.Account lifetime + 24 months
Activity logsYesAn audit log of user actions (the acting user, the action performed, the affected record, before/after values, IP address and timestamp).24 months
Notification historyYesA record of notifications sent to and received by users.24 months
IP addressesYesStored with activity-log entries, and also present in transient server request logs.90 days
Security logsYes (partial)Successful login events, password-reset requests (time requested, expiry, whether used) and password changes. Failed login attempts are not retained beyond transient request logs.90 days
Browser / application informationNot stored in our databaseThe User-Agent (browser/app and operating system) is present only in transient server request logs (our cloud hosting provider's request logs), retained for a limited period; it is not stored in the MyAlva application database.90 days
Device informationNoMyAlva does not collect or store device information (no device identifiers, model or OS fingerprinting).Not collected

4. How and for How Long Data Will Be Stored

Personal data processed through the MyAlva App will be used and stored in Brazil for as long as necessary for the provision of the contract or until the purposes described in this Privacy Policy have been fulfilled, taking into account the rights of users and the parties responsible for data processing (controllers and processors).

Once the retention period necessary for the storage of personal data has expired, such data will be deleted from our databases or anonymized, in accordance with the situations legally provided for under Article 16 of the LGPD.

This means that personal information required for compliance with legal, judicial, or administrative obligations and/or for the exercise of defense rights in judicial or administrative proceedings may be retained even after the deletion of other personal data.

5. Security of Personal Data Processing

The manner in which data is processed by the MyAlva App reflects its commitment to the security and protection of personal data in order to ensure user privacy. Appropriate technical measures and security solutions are adopted to guarantee the confidentiality, integrity, and inviolability of personal data. To maintain the protection of personal data, physical, electronic, and administrative safeguards aimed at ensuring data security and privacy are implemented.

The implementation of these safeguards takes into account the nature of the personal data processed, the context and purposes of the processing activities, as well as the risks that potential violations may pose to the rights and freedoms of data subjects.

The MyAlva App is committed to adopting best practices to prevent security incidents, in conjunction with the security policies implemented by our hosting and database storage provider, Google, and in compliance with the provisions of the LGPD.

6. User Rights (Data Subject Rights)

The MyAlva App guarantees its users the rights of personal data subjects provided under Article 18 of the Brazilian General Data Protection Law (LGPD). Therefore, users may, free of charge and at any time:

  1. confirmation that data is being processed;
  2. access to data;
  3. rectification of incomplete, inaccurate or out-of-date data;
  4. anonymization, blocking or erasure of data that is unnecessary, excessive or processed in breach of the provisions of this Act;
  5. portability of data to another service or product provider, upon express request, in accordance with the regulations of the national authority, subject to commercial and industrial secrecy;
  6. deletion of personal data processed with the data subject's consent, except in the cases provided for in Article 16 of this Law, as follows:
    1. compliance with a legal or regulatory obligation by the data controller;
    2. research by a research body, ensuring, wherever possible, that personal data is anonymized;
    3. transfer to a third party, provided that the data processing requirements set out in this Act are complied with; or
    4. exclusive use by the data controller, with access by third parties prohibited, and provided that the data is anonymized.
  7. information on the public and private entities with which the data controller has shared data;
  8. information on the possibility of withholding consent and on the consequences of refusal;
  9. withdrawal of consent, in accordance with paragraph 5 of Article 8 of this Law.

§ 1 The data subject has the right to lodge a complaint regarding their data against the controller with the national authority.

§ 2 The data subject may object to processing carried out on the basis of one of the grounds for exemption from consent, in the event of non-compliance with the provisions of this Law.

7. How to Exercise Your Rights

To exercise their rights as a user (data subject), users may contact the Data Protection Officer through the following channels, Contact: e-mail: info@alvafutures.com

8. Changes to this Privacy Policy

This version of this Privacy Policy was last updated on 07/24/2026.

The Controller reserves the right to modify these provisions at any time, especially to adapt them to improvements made to the MyAlva App, whether through the introduction of new features or the removal or modification of existing ones.

Any amendment or update to the Terms of Use or the Privacy Policy shall become effective as of the date of its publication on the service's website and must be fully observed by users.

In cases where amendments or updates to the Privacy Policy relate to the purpose, form, or duration of data processing, changes to the data controller(s), or the sharing of data, the data subject will be informed accordingly and may revoke their consent if they disagree with the changes.

9. Liability

The MyAlva App acknowledges the liability of the parties involved in personal data processing, in accordance with Articles 42 to 45 of the Brazilian General Data Protection Law (LGPD).

The MyAlva App is committed to keeping this Privacy Policy up to date, observing its provisions, and ensuring compliance with them. In addition, it undertakes to seek appropriate technical and organizational measures capable of protecting the entire data processing operation.

10. Limitation of Liability

As mentioned in Section 4, although high security standards are adopted in order to prevent incidents, no online platform is entirely free from risks. In this regard, the MyAlva App shall not be held liable for:

  1. Any consequences arising from users' negligence or lack of care regarding their own personal data. The MyAlva App is responsible only for the security of the data processing activities and for fulfilling the purposes described in this Privacy Policy. It should also be noted that the responsibility for maintaining the confidentiality of access credentials lies with the user.
  2. Malicious acts carried out by third parties, such as cyberattacks, except where negligent or intentional misconduct by the MyAlva App is proven.
  3. The accuracy of the information entered by users in the records necessary for the use of the MyAlva App services, as well as any consequences arising from false information or information provided in bad faith, which shall be the sole responsibility of the user.