Privacy and Data Security Policy

Last updated: August 2026

Trust is a prerequisite for our work: mapping an operation means accessing processes, systems and often sensitive business information. This policy describes how we handle personal data and confidential information, in line with Brazil's General Data Protection Law (LGPD, Law 13.709/2018).

1. Data we collect

We collect only what is needed to respond to a business enquiry and run a diagnostic:

  • Contact details submitted in the form: name, email, phone/WhatsApp, company, role and team size
  • The description of the operational challenge you provide
  • Browsing language and submission date
  • Basic technical access data required for the site to work securely

2. Purposes and legal bases

We use the data to answer your request, prepare diagnostic proposals, deliver contracted services and keep administrative records.

Applicable legal bases are, as the case may be: performance of a contract or preliminary procedures (art. 7, V), legitimate interest in B2B commercial contact (art. 7, IX), compliance with legal obligations (art. 7, II) and consent, when expressly requested.

We do not sell personal data and do not use it for third-party advertising.

3. Confidential company information

In consulting, integration and development projects we may access internal processes, documentation, credentials, databases and other strategic client information. In those cases we apply the following practices:

  • Non-disclosure agreements whenever requested, and confidentiality as the default even without one
  • Least-privilege access: we request only what the scope requires, for the duration of the project
  • Preference for test environments and anonymized or masked data during development
  • No confidential client data is used to train third-party AI models
  • Access revocation and return or secure deletion of materials at the end of the engagement

4. Information security

We apply technical and administrative measures proportionate to the size and risk of the operations we run:

  • Site traffic encrypted with HTTPS/TLS
  • Form submissions stored in a managed database with authorization rules controlling access
  • Credentials and keys kept in a secrets vault, never in source code
  • Multi-factor authentication on internal working tools
  • Access logging and periodic permission reviews
  • Security and auditability designed in from the start, not added at the end

5. Sharing and processors

We may use infrastructure and software vendors (hosting, database, email and productivity) acting as processors under our instructions and bound by confidentiality obligations.

We share data with third parties only when necessary to deliver the service, when legally required, or with your authorization.

6. Retention and deletion

We keep contact data for as long as the commercial relationship and applicable legal periods require. Once the purpose ends, data is deleted or anonymized.

Project data is handled according to the specific agreement, including return timelines and secure disposal.

7. Data subject rights (LGPD)

At any time you may request confirmation of processing, access, correction, anonymization, portability, information about sharing, withdrawal of consent and deletion of personal data.

8. Security incidents

In the event of an incident that may pose relevant risk to data subjects, we will notify those affected and the Brazilian data protection authority (ANPD) within a reasonable period, describing what happened and the measures taken.

9. Cookies

This site uses only resources essential to its operation. We do not use advertising or third-party tracking cookies.

To exercise your data subject rights or ask about this policy, use the contact form on this site. We reply within one business day.