PRIVACY & LGPD
Executive summary.
This summary covers the points legal and security teams ask for in due diligence. The full documentation (DPA + terms of use + cookie policy) is available via email to sales@leancosts.com. LGPD is Brazil's General Data Protection Law, equivalent to GDPR.
What we collect
Billing, resource graph, log analytics (read-only). No end-customer personal data is processed. Organizational PII is limited to email, name and role of users registered in the console (operators, approvers, reviewers).
Where it lives
Hosted on Railway (the application and the Postgres database) with Cloudflare for CDN, static hosting and off-site backups. Tenant data is isolated by Postgres row-level security — every row is scoped to its organization at the database layer, not just in application code. Cloud credentials are encrypted at rest with AES-256-GCM; all traffic is TLS-encrypted in transit. The hosting region and data-residency terms are set out in the DPA.
Retention
- 36 months of historical billing (needed for MoM and YoY variance).
- 7 years of audit logs (compliance and audit).
- Within 30 days for deletion on request via DPA.
Sub-processors
- Railway — application and Postgres database hosting.
- Cloudflare — CDN, static site hosting and off-site database backups (R2).
- Paddle — card payments in USD; merchant of record for international orders.
- Asaas — card payments and NFS-e (nota fiscal) in BRL for Brazilian orders.
- Resend — transactional email (account, security and digest notifications).
- Sentry — error monitoring, when enabled for the deployment.
- AI / LLM provider — optional copilot and narrative augmentation, opt-out per organization; the specific provider is named in the DPA.
- Google Analytics — marketing-site traffic measurement, loaded only after you opt in via the consent banner.
- Google Ads & Meta — ad conversion measurement (did an ad lead to a trial signup), loaded only after the same opt-in. No personalized ads, no retargeting audiences.
Full, current list in the DPA, with contact address and geographic coverage for each sub-processor.
Cookies and tracking
This page uses Google Analytics (GA4) to measure traffic, under Google Consent Mode set to denied by default: no analytics cookies are set and Google is not contacted until you accept via the consent banner. Decline and nothing loads. The same opt-in also enables ad conversion measurement (Google Ads tag and Meta Pixel) so we can tell which ads lead to trial signups — with ad personalization kept off: we run no personalized ads and build no retargeting audiences. Decline and none of it loads. The authenticated console uses session cookies only (httpOnly, SameSite=Lax, Secure), plus the same consent-gated conversion event on the trial signup page when you arrived from the marketing site having accepted.
When you submit the demo form, we record first-party marketing attribution (campaign UTMs, ad-click ids such as gclid/fbclid, the referring page and your user agent) so we can tell which channel a request came from. Before you opt in this stays in session storage only — no cookie is written until you accept. Accepting promotes it to a first-party cookie (lc_attr, SameSite=Lax, 12 months) so attribution survives a delayed conversion. No third party receives this data; it travels only with the lead you choose to send.
Data Protection Officer (DPO)
sales@leancosts.com — reply within 5 business days for LGPD requests (access, rectification, deletion, portability, withdrawal of consent).