Logs and Audit Policy
Rules for recording, storing, querying, protecting and retaining the platform's audit logs.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy defines rules for the recording, storage, querying, protection and retention of audit logs.
2. Events
HABORA may log login, logout, invalid attempts, invitations, user creation, permission changes, property registration, changes, uploads, deletions, reports, AI, finance, ESG, alerts, integrations and exports.
3. Content
Logs may contain user, company, date, time, IP, device, browser, action, module, property, previous value, new value, status and origin.
4. Purpose of logs
Logs serve for auditing, security, support, fraud prevention, incident investigation, proof of acceptance, traceability and legal compliance.
5. Protection
Logs must be protected against improper alteration, unauthorized deletion and access by users without permission.
6. Access
Access to logs must be restricted to authorized profiles, such as Owner, Admin, audit, authorized technical support and Platform Admin, according to purpose.
7. Retention
Logs will be kept for the period necessary for security, auditing, defense of rights, legal compliance and the retention policy.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.