Data Protection — LGPD, GDPR and United States laws
Last updated: July 26, 2026
This page details how we process personal data and what your rights are under the legislation applicable to you. It complements our Privacy Policy and Cookie Policy, which remain fully in force.
1. Who processes your data
The Lounge Secreto service is operated by ALAS TECHNOLOGY LLC (EIN 93-3927200), a company incorporated in the United States of America, which acts as the controller of the personal data processed on this platform — that is, the party that decides the purposes and the means of the processing. For privacy matters, including the exercise of any right described on this page, the official channel is our support, which forwards the request to the data protection officer.
2. Which laws apply to you
This page applies to all of our users, but your concrete rights depend on where you are. If you are in Brazil, the Brazilian General Data Protection Law (LGPD, Law No. 13.709/2018) applies. If you are in the European Economic Area, the United Kingdom or Switzerland, the General Data Protection Regulation (GDPR) and the equivalent local rules apply, because we offer the service to data subjects in those regions. If you reside in the United States, state consumer privacy laws apply, among them California's (CCPA, as amended by the CPRA). In the event of a conflict, we always apply the rule most protective of the data subject.
3. What data we process and for what
We process registration data — name, e-mail, phone, date of birth, identification document and country; data required to issue and activate the pass — address, holder details with the program operator and the result of the identity verification; payment data — amount, currency and transaction identifiers, without the customer's full card number being stored by us; support data — messages sent through support, form or assistant; and technical data — IP address, browser identifier, pages visited and access source. Each category is used only for the purpose that justifies it: to perform the contract, verify identity, process payment, prevent fraud, provide support and, when you consent, measure and improve campaigns.
4. Sensitive data: we do not collect it
We do not collect sensitive personal data — racial or ethnic origin, religious belief, political opinion, trade union membership, data concerning health or sex life, genetic or biometric data. The identity verification required to issue the card linked to the pass is carried out by a specialized partner, which acts as a processor; we receive from it the result of the verification and the necessary registration data, not the biometric material. We also do not request and do not store credentials of pre-existing Priority Pass™ accounts.
5. On what legal basis we process
Performance of the contract justifies the processing of registration, pass-issuance and payment data — without them the service cannot be provided. Compliance with a legal and regulatory obligation justifies keeping financial and tax records. Legitimate interest justifies fraud prevention, platform security and service improvement, always balanced against your rights and freedoms. Consent, freely given and revocable at any time, justifies non-essential cookies, the measurement of advertising campaigns and marketing communications. Under the LGPD these grounds correspond to art. 7; under the GDPR, to art. 6.
6. Artificial intelligence assistant
We offer an assistant that answers questions about the service. What you write in it is recorded to provide continuity of support and is sent, together with the recent history of the conversation, to a provider of artificial intelligence infrastructure that generates the reply — always from our servers, never from your browser. The content of the conversations is anonymized after 90 days. The assistant does not make automated decisions that produce legal effects or significantly affect you: when the topic is sensitive — price, refund, contractual terms — or when there is not enough documentary basis, it does not improvise and forwards the matter to a person. The knowledge base that feeds the assistant is shared among users and, for that reason, automatically rejects the inclusion of data from individual cases. Even so, we ask that you do not write in the assistant data that is not necessary, such as card number, password or document.
7. Cookies, pixels and tracking
We use strictly necessary cookies to authenticate you, remember the language and protect the site against abuse — these do not depend on consent, because without them the service does not work. Analytics and marketing cookies and pixels are only activated if you consent in the banner, and consent may be withdrawn at any time, with the same ease with which it was given. We record the date, the version of the notice and the choice made, as auditable proof. The details of each cookie are in the Cookie Policy.
8. With whom we share
We do not sell personal data. We share the minimum necessary with processors that carry out part of the service on our behalf and under contract: payment processors, identity verification partner, issuer of the card linked to the pass, the VIP lounge program operator, hosting and infrastructure providers, transactional e-mail sending provider, error monitoring provider and, when you consent, advertising platforms. Some partners are identified by category, and not by name, because they involve commercially sensitive information; the specific identification is provided to the data subject who exercises the right of access.
9. International transfers
The controller is based in the United States and part of our infrastructure and of our processors is located outside Brazil and the European Economic Area, so that your data may be transferred to and processed in other countries. We carry out these transfers on the basis of contractual safeguards that impose on the recipient confidentiality and security obligations compatible with the applicable legislation, and we limit the transfer to what is strictly necessary for the purpose. Under the LGPD this corresponds to art. 33; under the GDPR, to Chapter V.
10. How long we keep it
We keep each piece of data only for as long as it is necessary. Financial and tax records — purchases, payments, refunds and transactions — are kept for at least 5 years, by legal obligation, and cannot be deleted on request. The content of conversations with the assistant is anonymized after 90 days. Technical and telemetry records are eliminated after about 18 months. Consent records are preserved for as long as they are necessary as proof. Registration data is kept for the duration of the relationship and, afterwards, for the period necessary to defend rights.
11. Account deletion: what we erase and what remains
You may request the deletion of your account at any time. The request reaches only the data under our responsibility at Lounge Secreto — it does not affect the account you hold with the VIP lounge program operator, which is governed by its terms and must be closed directly with it. When processing the request, we remove or anonymize your registration and support data and delete sessions, login links and browsing records. The following remain, by legal obligation or by stated legitimate interest: financial records for a minimum period of 5 years; the record of consent, as proof; the audit record of administrative actions; and, in proven cases of fraud, abuse or default, the identifiers strictly necessary to prevent the recreation of the account. Once the deletion is completed, the account cannot be restored.
12. Your rights
Regardless of where you are, you may know whether we process data about you and access it; obtain a copy in a machine-readable format; correct incomplete or outdated data; request its elimination, within the limits of the previous section; withdraw consent; object to processing based on legitimate interest; and be informed of with whom we share. You will never be treated in a discriminatory manner for exercising any of these rights.
13. If you are in Brazil (LGPD)
The LGPD ensures, in art. 18, the rights to confirmation of the existence of processing; access; correction of incomplete, inaccurate or outdated data; anonymization, blocking or elimination of unnecessary or excessive data or data processed in non-compliance; portability to another provider; elimination of data processed on the basis of consent; information about the entities with which we share; information about the possibility of not consenting and the consequences thereof; and revocation of consent. You may also petition directly to the Autoridade Nacional de Proteção de Dados, the Brazilian data protection authority.
14. If you are in the European Union, the United Kingdom or Switzerland (GDPR)
The GDPR ensures the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), portability (art. 20) and objection (art. 21), as well as the right not to be subject to a solely automated decision with significant effects (art. 22) — which, as explained above, we do not carry out. You may withdraw consent at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal, and you have the right to lodge a complaint with the supervisory authority of your country.
15. If you are in the United States (CCPA/CPRA and state laws)
You have the right to know which categories of personal information we collect, where they come from, what they are used for and with whom they are shared; to obtain a copy; to request correction; and to request deletion, subject to the legal exceptions. We do not sell personal information for money. Sharing with advertising platforms for targeted advertising may be classified as sharing under the CPRA and, for that reason, only occurs if you have accepted the marketing category in the banner — refusing or withdrawing that consent amounts to exercising the opt-out. We do not use sensitive personal information to infer characteristics, and we do not discriminate against those who exercise their rights.
16. How to exercise your rights
You may obtain a copy of your data and request the deletion of the account through the logged-in area, and cancel marketing communications through the unsubscribe link present in all of our e-mails or through the unsubscribe page. For any other request — including correction, objection or information about sharing — contact our support, which forwards it to the officer. We may request additional information to confirm your identity before responding, precisely so as not to hand data to someone who is not the data subject. We respond within 15 days for requests under the LGPD; within 1 month for requests under the GDPR, extendable by a further 2 months in complex cases, with prior notice; and within 45 days for requests under United States legislation, extendable by a further 45.
17. Children and adolescents
The service is intended for persons over 18 years of age and is not directed at children or adolescents. We do not intentionally collect data from minors. If we identify that a registration was made by a minor, or if a guardian informs us, we eliminate the data and close the account.
18. Information security
We adopt technical and organizational measures proportionate to the risk: encryption of sensitive data at rest, passwords stored only as a cryptographic derivation, traffic protected by TLS, role-based access control with an audit record of administrative actions, rate limiting, anti-automation protection and error monitoring. Our controls follow the international standards ISO/IEC 27001, on information security management, and ISO/IEC 27701, on privacy information management. No system is infallible, and for that reason we also maintain an incident response plan.
19. Security incidents
If a security incident occurs that may entail relevant risk or harm to the data subjects, we notify the competent authority and the affected data subjects, describing the nature of what occurred, the data involved, the measures adopted and the applicable recommendations. Under the GDPR, notification to the supervisory authority is made without undue delay and, whenever possible, within 72 hours.
20. Changes to this page
We may update this page to reflect changes in the service, in technology or in legislation. When the change is relevant, we notify through our channels and, when required, request new consent. The date of the last update is shown at the top of this page.