Legal & Compliance

Privacy Policy

We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard it. This policy explains our practices in plain, honest language.

Document Privacy Policy
Entity Vitor Brandelero Desenvolvimento de Software Ltda
Last updated June 18, 2025
Effective date June 18, 2025
Section 01

Introduction

Vitor Brandelero Desenvolvimento de Software Ltda (CNPJ 68.434.347/0001-86), headquartered at Rua Visconde do Rio Branco, 1488, Conjunto 909, Andar 09, Condomínio Universe Life Square — Bloco Comercial, Centro, Curitiba-PR, Brazil ("we," "our," or "the Company"), operates the website brandelero.site and related digital properties.

We respect your privacy. This Privacy Policy describes what personal data we collect when you visit our website or interact with us, the lawful bases under which we process it, how long we retain it, and the rights you hold under Brazil's General Data Protection Law (Lei Geral de Proteção de Dados Pessoais — LGPD, Law nº 13.709/2018) and, where applicable, the European Union's General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), as well as other applicable privacy legislation.

Please read this document carefully. By using our website you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of our website and services. This policy covers only data we process ourselves or through the processors described herein; it does not cover third-party websites or services that may be linked from our pages.

We act as the data controller for all personal information you share with us directly. Where we engage third-party service providers, those parties act as data processors under contracts that bind them to appropriate security and confidentiality obligations.

Section 02

Information We Collect

We collect two broad categories of information: data you provide to us voluntarily, and data we collect automatically when you use our website.

Information you provide directly

  • Contact inquiries. When you reach out via email or phone, we receive your name, email address, phone number, company name, and the content of your message. We use this solely to respond to your request and, where you have consented, to send relevant follow-up communications.
  • Business correspondence. If you correspond with us by post, email, or other means in a commercial context, we may retain those records as part of our operational records to the extent required by law or legitimate business need.
  • Employment applications. If you apply for a position with us by emailing your CV or portfolio, we collect your name, contact details, professional history, and any other information you voluntarily include. We retain this for six months after the process concludes unless you consent to a longer period.

Information collected automatically

  • Log data. Our web servers automatically record your IP address, browser type and version, operating system, referring URL, pages visited on our site, time spent on each page, and the date and time of your visit. This data is retained in aggregated, pseudonymized form for up to 12 months for security monitoring and infrastructure optimization.
  • Device information. We may infer your general device category (desktop, tablet, mobile), screen resolution, and preferred language setting to improve how our website renders for different visitors. This is not linked to any personally identifiable information.
  • Analytics data. We use Google Analytics (see Cookies section) to understand aggregate traffic patterns, popular content, and referral sources. This data is pseudonymized and processed under Google's data processing terms.
  • Advertising interaction data. If you arrive at our site through a Google Ads campaign, Google may share aggregated conversion signals with us (e.g., that a click led to a page visit). No personally identifiable information is shared with us through this mechanism.

We do not collect sensitive personal data (such as health information, biometric data, racial or ethnic origin, political opinions, religious beliefs, financial account numbers, or social security / CPF numbers) through this website. Please do not send us sensitive data via email unless expressly requested as part of a specific engagement.

Section 03

How We Use Your Information

We process personal data only when we have a lawful basis to do so. For each purpose, we identify the applicable legal basis under the LGPD and, where relevant, the GDPR.

  • Responding to inquiries — We use contact information you submit to reply to your questions, provide requested information about our software solutions, and follow up on potential engagements. Lawful basis: performance of pre-contractual steps at your request (LGPD Art. 7, II; GDPR Art. 6(1)(b)).
  • Operating and improving our website — Log and analytics data allow us to identify technical errors, optimize page-load performance, and understand which content is most useful to visitors. Lawful basis: legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)), balanced against visitor privacy interests.
  • Security and fraud prevention — IP addresses and server logs help us detect and investigate unauthorized access, denial-of-service attempts, and other security threats. Lawful basis: legitimate interest in protecting our infrastructure and users (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
  • Compliance with legal obligations — We may retain or disclose data to comply with court orders, tax authorities, or other applicable legal requirements. Lawful basis: compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
  • Marketing communications — Where you have explicitly opted in (e.g., by requesting to be kept informed about our products), we may send periodic updates about Brandelero's software offerings. You may withdraw consent at any time by emailing us. Lawful basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
  • Measuring advertising effectiveness — Aggregated, non-identifiable signals help us evaluate which Google Ads campaigns generate genuine interest in our services, enabling efficient allocation of our marketing budget. Lawful basis: legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).

We do not sell, rent, or otherwise commercialize your personal data to any third party. We do not use automated profiling or make legally significant decisions about you based solely on automated processing.

Section 04

Cookies & Tracking Technologies

Our website uses cookies — small text files stored in your browser — and analogous technologies such as web beacons and JavaScript tracking pixels. Some cookies are strictly necessary for the website to function; others are used for analytics and advertising measurement purposes and are only set with your consent, where required by applicable law.

When you first visit our website you will be presented with a cookie consent banner. You may accept all cookies, accept only strictly necessary cookies, or configure your preferences granularly. You can change your choice at any time by clearing your browser's cookies and revisiting the site, or by adjusting browser-level settings.

For comprehensive information about Google's data practices, please consult policies.google.com/privacy. To opt out of Google Analytics across all websites, you may install the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

Our website does not currently use fingerprinting techniques, session-recording tools, or heatmap technologies that capture personally identifiable behaviour.

Section 05

Sharing With Third Parties

We do not share personal data with third parties except in the following limited circumstances, each subject to appropriate contractual or regulatory safeguards:

  • Service providers (data processors). We engage reputable technology vendors to support our website and internal operations — including cloud hosting providers, email delivery services, and analytics platforms. Each processor is bound by a data processing agreement that restricts their use of your data to the specific purpose for which it was shared, prohibits onward disclosure, and mandates appropriate technical and organizational security measures.
  • Google LLC. As described in the Cookies section, Google processes pseudonymized analytics and advertising measurement data on our behalf under Google's data processing terms, which incorporate standard contractual clauses for international transfers where applicable.
  • Legal and regulatory authorities. We will disclose personal data when required to do so by a valid court order, subpoena, regulatory demand, or to comply with applicable law — in particular under Brazilian tax, commercial, and cybercrime legislation. We will, where permitted, notify affected individuals before complying with such demands.
  • Corporate transactions. In the event of a merger, acquisition, restructuring, or sale of substantially all our assets, personal data may be transferred to the acquiring entity. We will provide notice before your personal data is subject to a different privacy policy as a result of such a transaction.
  • With your explicit consent. In any other circumstance not described above, we will share your data with a third party only if you have given clear, informed, and specific consent for that disclosure.

When personal data is transferred internationally — for example, to Google's servers located outside Brazil — we ensure that such transfers are protected by one or more of the following mechanisms: adequacy decisions where applicable, standard contractual clauses approved by the relevant supervisory authority, or other lawful transfer mechanisms recognized under the LGPD and GDPR.

Section 06

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to satisfy applicable legal, accounting, or reporting requirements, or to defend against legal claims. The table below summarises our standard retention periods:

  • Contact inquiry records — retained for up to 3 years from last contact, consistent with Brazilian contractual limitation periods under the Civil Code, after which they are securely deleted or irreversibly anonymized.
  • Email correspondence — retained for up to 5 years in line with commercial record-keeping obligations under Brazilian commercial law (Lei nº 10.406/2002).
  • Web server logs — retained in pseudonymized form for up to 12 months for security and infrastructure monitoring; raw logs containing full IP addresses are purged after 30 days.
  • Google Analytics data — configured with a data-retention setting of 14 months at the property level; after this period Google automatically deletes user-level and event-level data.
  • Recruitment applications — retained for 6 months after the conclusion of the relevant recruitment process, or for up to 24 months if you consent to us keeping your profile on file for future opportunities.
  • Cookie consent records — retained for 5 years as evidence of lawful processing, in line with regulatory guidance from Brazil's ANPD (Autoridade Nacional de Proteção de Dados).

When the applicable retention period expires, we permanently delete the data or render it irreversibly anonymous so that it can no longer be associated with any identified or identifiable person. Anonymized, aggregated statistical data may be retained indefinitely for historical trend analysis.

Section 07

Data Security

Protecting the confidentiality and integrity of your information is a core responsibility we take seriously. We implement a layered set of technical and organizational security measures proportionate to the nature of the data we hold and the risks involved.

  • Encryption in transit. All communication between your browser and our servers is protected using Transport Layer Security (TLS 1.2 or higher). We enforce HTTPS site-wide and employ HTTP Strict Transport Security (HSTS) headers.
  • Access control. Access to systems that store personal data is restricted on a strict need-to-know basis, enforced through role-based access control and multi-factor authentication for all administrative accounts.
  • Vendor security standards. We select cloud infrastructure and SaaS providers that hold recognized security certifications (such as ISO 27001 or SOC 2 Type II) and we review their security posture as part of our procurement process.
  • Incident response. We maintain documented procedures for detecting, containing, and reporting personal data breaches. In the event of a breach likely to cause risk to individuals' rights and freedoms, we will notify the ANPD within 72 hours of becoming aware of the breach (or the competent EU supervisory authority where GDPR applies), and will communicate with affected individuals without undue delay.
  • Employee awareness. Team members with access to personal data receive training on data protection principles and are bound by confidentiality obligations.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. We encourage you to use secure, up-to-date browsers and to contact us immediately if you suspect any unauthorized use of information you have shared with us.

Section 08

Your Rights

Depending on your location and the applicable law, you have several rights regarding your personal data. Below we describe the rights guaranteed under Brazil's LGPD (Article 18) and, where additional or equivalent rights exist under the GDPR, we note them accordingly. We honor these rights in full, regardless of your country of residence.

Right to Confirmation & Access

You may ask us to confirm whether we process your personal data and, if so, receive a copy of the data we hold about you along with information about how it is used.

Right to Correction

If any personal data we hold is inaccurate, incomplete, or out of date, you have the right to request that we correct or update it without undue delay.

Right to Anonymization, Blocking & Deletion

Where data is unnecessary, excessive, or processed in violation of the law, you may request that we anonymize, block, or delete it. This right also corresponds to the GDPR's right to erasure ("right to be forgotten").

Right to Data Portability

You may request that we provide your data in a structured, commonly used, machine-readable format so that you can transfer it to another data controller.

Right to Object & Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You may also object to processing based on legitimate interests.

Right to Information About Sharing

You have the right to know which public and private entities we have shared your data with, and the basis for those disclosures.

Right to Non-Discrimination

Exercising any of your data protection rights will never result in any penalty, disadvantage, or discriminatory treatment in the services or information we provide.

Right to Lodge a Complaint

You have the right to file a complaint with Brazil's ANPD (www.gov.br/anpd) or, where the GDPR applies, with the competent EU supervisory authority in your member state.

How to exercise your rights. To make a rights request, contact our data protection contact (see Section 11 below) by email at [email protected] with the subject line "Data Rights Request." Please include your full name, a means to verify your identity (such as your email address on file), and a clear description of the right you wish to exercise. We will acknowledge your request within 5 business days and respond substantively within 15 calendar days. In complex cases we may extend this by a further 15 days, with prior notice and explanation. We will not charge a fee for reasonable requests.

Section 09

Children's Privacy

Our website and services are directed exclusively at businesses and professionals. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18 (or the applicable age of majority in their jurisdiction). Our website does not contain content intended to attract minors, nor do we design any feature to engage or profile children.

If we become aware that personal data has been inadvertently collected from a minor without verifiable parental or guardian consent, we will delete that information promptly. If you believe a minor has submitted personal data to us, please contact us immediately at [email protected] and we will take appropriate corrective action without undue delay.

Parents and legal guardians who believe their child has provided us with personal information are encouraged to exercise their rights on the child's behalf using the process described in Section 08 above.

Section 10

Changes to This Policy

We review and update this Privacy Policy periodically to reflect changes in our practices, the services we offer, applicable law, or regulatory guidance issued by the ANPD or relevant EU supervisory authorities. When we make material changes — for example, changes to the types of data we collect, new sharing arrangements, or new processing purposes — we will post the revised policy on this page with an updated "Last updated" date at the top of the document.

For significant changes that materially affect how we process your data or your rights, we will make reasonable efforts to provide more prominent notice — for example, by placing a notice on our homepage or, where we have your contact details, by sending you an email notification. The updated policy will become effective on the date indicated unless we state otherwise.

We encourage you to review this page periodically to stay informed about our data protection practices. Your continued use of our website after a revised policy takes effect constitutes acceptance of the updated terms to the extent permitted by applicable law. If any update reduces your rights or expands how we use your data, we will seek fresh consent where required.

Prior versions of this policy are available on request by emailing [email protected] with the subject line "Privacy Policy — Previous Version."

Section 11

Contact & Data Protection

If you have questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact us using the details below. We are committed to resolving all legitimate enquiries in a timely, fair, and transparent manner.

You may also contact us to request a copy of the records of processing activities we maintain under Article 37 of the LGPD, or to ask for clarification on any aspect of this document. Our team will respond within the timeframes set out in Section 08.

Company & Data Contact
Legal Entity Vitor Brandelero Desenvolvimento de Software Ltda
CNPJ 68.434.347/0001-86
Registered Address Rua Visconde do Rio Branco, 1488, Conjunto 909, Andar 09
Condomínio Universe Life Square — Bloco Comercial
Centro, Curitiba — PR, Brazil
Email — Data & Privacy [email protected]
Subject Line Please use "Privacy Policy Enquiry" or "Data Rights Request" for priority routing.

If you are located in the European Union and are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your EU member state. If you are located in Brazil and are not satisfied with our response, you may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.