Procurement · Security · Legal

Security, privacy and compliance at Glim

Glim runs your branded corporate store, which means handling employee data, delivery addresses and payment information every day. This page gathers, in plain language, what your Security, Legal and Procurement teams need to assess Glim as a vendor. If a document is missing, our sales team sends it on request.

Go to the security FAQ

Personal data and data protection (LGPD)

In running the store, Glim acts as Processor and your company as Controller: you define the purpose, Glim handles the data to deliver the service. For data collected on Glim's own website (forms, browsing), Glim is the Controller.

  • DPA available on request, to attach to the contract.
  • Data Protection Officer: Igor Montella — privacidade@glim.com.br. The same channel handles data-subject requests (access, correction, deletion, portability).
  • Data handled in the operation: employee identification, work email, delivery address, size or item preference and order history — the minimum needed to produce, invoice and deliver.
  • Retention as set out in Glim's Privacy Policy: operational and tax data are retained for the applicable legal or tax period (as a rule, 5 years) after the contractual relationship ends; other personal data are deleted or anonymised, unless the law requires a longer period.
  • Self-service portability: export your operation's data at any time, without raising a ticket.
  • Cloud hosting. Glim does not guarantee that storage sits within Brazilian territory; the controls protecting that data are the ones described in the sections below (encryption, RBAC, audit trails), and the sub-processor list is available to your team.

Access and identity

  • Native SSO via SAML with Microsoft Entra ID, Okta and Google Workspace — live in production, not roadmap.
  • SCIM for automatic provisioning and deprovisioning: anyone removed from your directory loses store access.
  • RBAC: different access profiles and catalogues by area, role, site or group.
  • Single-level approval on order and redemption flows, automatic or manual as you configure it.
  • Cost centres: limits and budgets by user, department, cost centre, period and product (SKU), with the allocation carried into billing.
  • Invite-only access: for restricted campaigns, only the emails your company enables through the platform get in.
  • Audit trails across access and operations.
  • Multi-tenant with per-tenant isolation: your store and your data never mix with another client's.

Availability and support

  • 99.9% uptime.
  • Support SLA by severity: Critical in 4h, High in 8h, Medium in 24h.
  • Custom contractual SLA on the Enterprise plan, negotiated in the contract.
  • Backup and a disaster recovery plan.
  • Business continuity plan and insurance, plus insured freight on deliveries.
  • Trilingual support (Portuguese, English and Spanish), serving the end employee directly, without going through your HR team.
  • Dedicated Customer Success on the Enterprise plan.

Application security

  • Encryption in transit and at rest.
  • Our own pentest of the application.
  • Practices aligned with SOC2 and GDPR, without formal certification. Glim holds neither SOC2 nor ISO 27001 certification and claims otherwise in no commercial document.
  • Multi-tenant architecture with per-tenant isolation.
  • Documented REST API and webhooks — the webhooks cover the whole flow, from a new user entering to delivery completion. ERP, HRIS and CRM integrations are built per project on that foundation; they do not ship ready-made.
  • Privacy by default: minimal collection, traceable consent and access logs.

Vendors, sub-processors and due diligence

Glim works with production, transport and financial-services suppliers. What your team receives during vendor approval:

  • NDA signed before any sensitive information is exchanged.
  • Vendor due diligence: Glim responds to the client's process and applies its own to production and logistics partners.
  • Sub-processors used in running the store: carriers, the e-invoicing provider and the payment gateway. The named list is available to your team during vendor approval.
  • Continuity plan and insurance, plus insured freight.
  • Customer references on request.
  • Intellectual property: designs and artwork created for your store belong to the client.

Tax model

Glim issues the invoices. That removes the tax registration, the e-invoicing and the fiscal operation of the gifting, kit and uniform programme from the client's side.

  • An NF-e issued by Glim on every order, with freight on the same invoice as the product — never charged separately.
  • Employee buying with their own money: Glim is the seller and the invoice is issued directly to the employee. Your company does not buy, does not resell and records no sales revenue.
  • Company-funded credits: topping up the wallet generates a simple invoice to the company; at redemption, the treatment depends on how the programme is designed. A voucher or credit the employee spends in the store is invoiced by Glim to the employee; a campaign or batch paid for by the company (200 year-end kits, say) is a different operation — a sales invoice to the company plus delivery shipments to the recipients.
  • Flexible billing: a consolidated invoice with cost-centre allocation, or separate invoices by area, with an NF-e per order and a consolidated report.
  • Billing in foreign currency or through an overseas entity, depending on your structure.

The structure simplifies tax treatment because the invoice goes straight to the employee, without a round trip through the company's books. Every company has its own tax context, and the Glim team aligns the details with your tax and accounting people. This content is informational and is not tax advice.

Security and compliance FAQ

Does Glim hold SOC2 or ISO 27001 certification?

No. Glim holds no formal certification. Our practices are aligned with SOC2 and GDPR: encryption in transit and at rest, RBAC, audit trails, multi-tenant architecture with per-tenant isolation, our own pentest, backup and disaster recovery. Documentation of those practices, the NDA and the DPA go to your security team during vendor approval.

Is Glim the Controller or the Processor of our employees' data?

The Processor. In running the store your company is the Controller — it defines the purpose of processing — and Glim handles the data to deliver the service: produce, invoice and deliver. The DPA is available on request. For data collected on Glim's own website, such as contact forms, Glim is the Controller.

Where is the data stored?

In the cloud. Glim does not guarantee storage within Brazilian territory, so protection rests on technical controls: encryption in transit and at rest, RBAC, audit trails, per-tenant isolation and a defined sub-processor list — carriers, the e-invoicing provider and the payment gateway — available to your team during vendor approval.

Do you support SSO and automatic deprovisioning?

Yes. Native SSO via SAML with Microsoft Entra ID, Okta and Google Workspace, and SCIM to provision and deprovision users automatically: anyone removed from your directory loses store access. ERP, HRIS and CRM are integrated via REST API and webhooks, configured per project — not off-the-shelf integrations.

What are the support and availability SLAs?

Support with response times by severity — Critical in 4h, High in 8h and Medium in 24h — and 99.9% uptime. Enterprise clients get a custom contractual SLA negotiated in the contract, plus dedicated Customer Success. Support is trilingual (Portuguese, English and Spanish) and also serves the end employee, directly through the store.

How can we approve Glim if our internal process is long?

Start with the Test Store: a one-off amount, no long contract and no prior legal review, restricted to the people you name. Formal vetting — NDA, DPA, security questionnaire and due diligence — runs in parallel, and the test store becomes the official store once the process closes.

Need the DPA, the NDA or a security questionnaire answered?

Our sales team sends the documentation and follows the vendor-approval process alongside your Security, Legal and Procurement teams.