Politique de confidentialité
Transparence totale sur la collecte et l'utilisation de vos données.
1. Information We Collect
We collect various categories of information when you use our website and services: Personal Identification Information: When you fill out contact forms, subscribe to our services, or communicate with us, we collect your name, email address, phone number, postal address, company name, and job title. Account Credentials: If you create an account, we collect your username and a securely hashed password. We may also collect OAuth tokens if you choose to authenticate via third-party services. We never store passwords in plain text. Usage Data: We automatically collect information about how you interact with our website, including pages viewed, time spent on each page, click patterns, navigation paths, features used, and referral URLs. Device Information: We collect data about the device you use to access our services, including browser type and version, operating system, IP address, device type, screen resolution, language preferences, and time zone. Communication Data: We collect records of your communications with us, including WhatsApp messages, email correspondence, contact form submissions, and any other messages you send us through any channel. Payment Information: When you purchase services, payment processing is handled entirely by our third-party payment processors. We do not store, process, or have access to your full credit card numbers, bank account details, or other sensitive financial information. We may store limited billing information such as the last four digits of your card and billing address. Social Media Integration: If you interact with our social media pages or use social login features, we may receive information from the social media platform, including your public profile information, friends list, and any other data you have authorized the platform to share. Cookies and Tracking Technologies: We use cookies, web beacons, pixel tags, and similar tracking technologies as described in Section 8 of this policy.
2. How We Use Your Information
We use the information we collect for the following purposes: Service Delivery and Account Management: To create and maintain your account, process transactions, provide the services you have requested, and send service-related communications including technical notices, updates, security alerts, and support messages. Communication and Support: To respond to your inquiries, provide customer support, handle complaints, and communicate with you about your account or our services. Personalization and Recommendations: To customize your experience on our website, recommend services or content that may interest you, and tailor the presentation of our website to your preferences. Analytics and Improvement: To analyze usage patterns, diagnose technical issues, improve our website and services, conduct research, and develop new features and offerings. Security and Fraud Prevention: To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful or illegal activity, and to protect the rights and property of our users and our company. Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests, and to enforce our Terms of Service and other legal agreements. Marketing and Communications: With your explicit consent where required by law, we may use your information to send you marketing communications, newsletters, promotional offers, and information about our services. You may opt out at any time.
3. Legal Basis for Processing (LGPD/GDPR)
We process your personal information on the following legal bases, in accordance with the Brazilian Lei Geral de Protecao de Dados (LGPD - Law No. 13,709/2018) and the European General Data Protection Regulation (GDPR) where applicable: Consent (LGPD Art. 7, I and GDPR Art. 6(1)(a)): We process your data based on your freely given, specific, informed, and unambiguous consent. This includes processing for marketing communications, non-essential cookies, and certain data sharing activities. You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Contract Performance (LGPD Art. 7, V and GDPR Art. 6(1)(b)): We process your data as necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes processing required to deliver our services, process payments, and provide customer support. Legal Obligation (LGPD Art. 7, II and GDPR Art. 6(1)(c)): We process your data when necessary to comply with a legal obligation to which we are subject, including tax and accounting requirements, regulatory compliance, and lawful requests from public authorities. Legitimate Interests (LGPD Art. 7, IX and Art. 10, and GDPR Art. 6(1)(f)): We process your data for our legitimate interests or the legitimate interests of third parties, provided that such interests do not override your fundamental rights and freedoms. This includes processing for security, fraud prevention, analytics, and service improvement. We conduct a balancing test to ensure your interests are protected. Credit Protection (LGPD Art. 7, X): We may process your data for the protection of credit, as permitted by law. Health Protection (LGPD Art. 7, VII): When necessary to protect the life or physical safety of the data subject or a third party. We will identify the specific legal basis for each processing activity at the time of data collection and document it in our Records of Processing Activities.
4. Data Sharing and Disclosure
We do not sell, rent, trade, or lease your personal information to third parties. We may share your information only in the following circumstances: Service Providers: We engage trusted third-party service providers who process your data on our behalf to support our business operations. These include: - Cloud Infrastructure: Supabase (database hosting and authentication), Vercel (web hosting and deployment) - Analytics Services: Google Analytics and other analytics platforms for understanding website usage - Communication Tools: Email service providers, WhatsApp Business API, and live chat platforms - Payment Processors: Third-party payment gateways for processing transactions (we do not store payment card data) - Customer Relationship Management (CRM) platforms All service providers are contractually bound to process your data only in accordance with our instructions, to implement appropriate security measures, and to comply with applicable data protection laws. Legal Requirements: We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to: - Comply with a legal obligation, court order, or governmental request - Protect and defend our rights, property, or safety, or the rights, property, or safety of our users or others - Investigate, prevent, or take action regarding suspected or actual illegal activities, fraud, or security issues - Enforce our Terms of Service or other agreements Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your information. With Your Consent: We may share your information for any other purpose with your explicit consent. We NEVER sell your personal information to third parties for their own marketing purposes.
5. International Data Transfers
Your personal information may be transferred to, stored in, and processed in countries other than your own, including Brazil and other jurisdictions where our service providers operate. Data Storage Locations: Our primary data infrastructure is hosted with Supabase and Vercel, which may maintain servers in multiple regions including the United States, the European Union, and South America. Your data may be processed in any of these locations. Safeguards for International Transfers: When we transfer your data to countries that have not been deemed to provide an adequate level of data protection under Brazilian LGPD or European GDPR standards, we implement appropriate safeguards, including: - Standard Contractual Clauses (SCCs) as approved by the European Commission and recognized by the ANPD - Binding Corporate Rules where applicable - Data Processing Agreements that require recipients to protect your data to standards equivalent to those required by applicable data protection laws - Technical and organizational security measures to protect your data during transfer Adequacy Decisions: We rely on adequacy decisions where available, recognizing that certain countries provide an adequate level of data protection. Your Rights Regarding International Transfers: You have the right to request information about the safeguards we have implemented for international transfers of your personal data. You may exercise this right by contacting us at contato@gabrieltoth.com.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention Periods by Data Category: - Account Information: Retained for the duration of your account's existence plus 12 months after account closure or termination, unless a longer retention period is required by law. - Communication Data (contact form submissions, emails, WhatsApp messages): Retained for up to 24 months from the date of the last communication. - Usage Data and Analytics: Retained in a personally identifiable form for up to 12 months. Aggregated and anonymized data may be retained indefinitely for analytical purposes. - Transaction Records: Retained for 5 years to comply with tax and accounting legal obligations (Brazilian Tax Code). - Marketing Communications Data: Retained until you withdraw your consent or opt out of marketing communications. - Cookie Data: Retained according to the specific cookie's lifespan as described in Section 8. Criteria for Determining Retention Periods: We consider the following factors when determining retention periods: - The amount, nature, and sensitivity of the data - The potential risk of harm from unauthorized use or disclosure - The purposes for which we process your data and whether we can achieve those purposes through other means - Applicable legal, regulatory, tax, accounting, and reporting requirements - The existence of legal proceedings or anticipated litigation Data Deletion: When data is no longer required for the identified purposes or the permitted retention period has expired, your personal information will be securely deleted or anonymized so that it can no longer be associated with you. We use secure deletion methods that render the data irrecoverable.
7. Your Rights (LGPD and GDPR)
Under the Brazilian Lei Geral de Protecao de Dados (LGPD) and, where applicable, the European General Data Protection Regulation (GDPR), you have the following rights regarding your personal information: 1. Confirmation of Processing (LGPD Art. 18, I): You have the right to confirm whether we process your personal data. 2. Access (LGPD Art. 18, II - GDPR Art. 15): You have the right to access your personal data and obtain a copy of the information we hold about you. 3. Correction (LGPD Art. 18, III - GDPR Art. 16): You have the right to request the correction of incomplete, inaccurate, or outdated personal data. 4. Anonymization, Blocking, or Deletion (LGPD Art. 18, IV): You have the right to request anonymization, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance with the LGPD. 5. Data Portability (LGPD Art. 18, V - GDPR Art. 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another data controller, subject to our legitimate interests and trade secrets. 6. Deletion of Data Processed with Consent (LGPD Art. 18, VI - GDPR Art. 17): You have the right to request the deletion of personal data processed with your consent. 7. Information About Data Sharing (LGPD Art. 18, VII): You have the right to be informed about the public and private entities with which we have shared your data. 8. Information About the Possibility of Denying Consent (LGPD Art. 18, VIII): You have the right to be informed about the consequences of denying consent. 9. Withdrawal of Consent (LGPD Art. 8, Section 5 - GDPR Art. 7(3)): You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. 10. Objection to Processing (GDPR Art. 21): Where we process your data based on legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. 11. Automated Decision-Making (GDPR Art. 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. 12. Complaint to Regulatory Authority (LGPD Art. 18, Section 2): You have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD) or, where applicable, with the relevant European data protection supervisory authority. How to Exercise Your Rights: To exercise any of these rights, please contact us at contato@gabrieltoth.com or through any of the channels listed in Section 12. We will respond to your request within 15 days as required by LGPD (Law No. 13,709/2018, Art. 19) or within one month under GDPR, extendable by up to two months for complex requests. We may need to verify your identity before processing your request. There is no charge for exercising your rights, unless your request is manifestly unfounded or excessive.
8. Cookies and Similar Technologies
Our website uses cookies, web beacons, pixel tags, and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. What Are Cookies: Cookies are small text files that are stored on your device (computer, tablet, or mobile) when you visit a website. They allow the website to recognize your device and store information about your preferences or past actions. Types of Cookies We Use: Essential/Necessary Cookies: These cookies are strictly necessary for the functioning of our website and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as setting your privacy preferences, logging in, or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site may not work properly. Examples include session cookies and CSRF tokens. Analytics and Performance Cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. This includes cookies from Google Analytics and similar analytics providers. Functional Cookies: These cookies enable the website to provide enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, some or all of these services may not function properly. Marketing and Targeting Cookies: These cookies may be set through our site by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. They do not store directly personal information but are based on uniquely identifying your browser and internet device. We use these only with your prior consent. Specific Cookies We May Use: - Supabase authentication cookies (for session management) - Vercel analytics cookies - Google Analytics (_ga, _gid, _gat) - Session cookies (server-side generated) - Preference cookies (language selection, theme preferences) Third-Party Cookies: Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. You should check the respective privacy policies of these third parties for information about their use of cookies. Managing Cookies: You can control and manage cookies in various ways: - Browser Settings: Most browsers allow you to view, block, or delete cookies through their settings. Please consult your browser's help documentation for instructions. - Privacy Preference Center: When available, you can manage your cookie preferences through our cookie consent banner or privacy preference center. - Opt-Out Tools: You can opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on (tools.google.com/dlpage/gaoptout). Please note that blocking or deleting cookies may affect the functionality of our website and your user experience.
9. Data Security
We implement comprehensive technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, accidental loss, destruction, or damage. Technical Measures: - Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL (Transport Layer Security) protocols, ensuring that information cannot be read during transmission. Data at rest is encrypted using industry-standard encryption algorithms (AES-256). - Access Controls: We implement strict access controls, including role-based access control (RBAC), multi-factor authentication (MFA) for administrative access, and the principle of least privilege, ensuring that only authorized personnel have access to personal data and only to the extent necessary for their job functions. - Network Security: We use firewalls, intrusion detection and prevention systems (IDPS), and regular vulnerability scanning to protect our network infrastructure. - Secure Development: We follow secure coding practices, conduct code reviews, and perform regular security testing, including penetration testing and vulnerability assessments. - Authentication: Passwords are hashed and salted using strong cryptographic algorithms (bcrypt or similar). We never store passwords in plain text. - Monitoring and Logging: We maintain comprehensive logging of system access and activities, with automated monitoring for suspicious behavior and security incidents. Organizational Measures: - Data Protection Policies: We maintain written information security policies and procedures that are reviewed and updated regularly. - Employee Training: All employees and contractors who handle personal data undergo regular privacy and security training. - Incident Response Plan: We have established a detailed incident response plan to promptly address any data breaches or security incidents, including notification procedures for affected individuals and regulatory authorities as required by law. - Vendor Management: We conduct security assessments of our third-party service providers and ensure they maintain appropriate security standards through contractual obligations. - Regular Audits: We conduct periodic internal and external audits to verify the effectiveness of our security measures and ensure ongoing compliance with applicable standards. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority (ANPD) within the timeframes required by applicable law, including details of the nature of the breach, likely consequences, and measures taken to address it.
10. Children's Privacy
Our website and services are not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children without verifiable parental consent. Age Restrictions: - Under 13: We do not knowingly collect or solicit personal information from children under 13 years of age. - Under 16 in the EU: In compliance with GDPR, we do not knowingly collect personal information from children under 16 in European Union member states without parental consent. - Under 18 in Brazil: In compliance with the Estatuto da Crianca e do Adolescente (ECA - Law No. 8,069/1990) and LGPD, we do not knowingly collect personal information from minors under 18 without the consent of their parents or legal guardians. If We Discover Collection: If we become aware that we have collected personal information from a child without appropriate parental consent, we will take steps to delete that information as soon as possible. If you believe that a child may have provided us with personal information without parental consent, please contact us immediately at contato@gabrieltoth.com. Parental Rights: Parents or legal guardians have the right to review, request deletion of, or refuse further collection of their child's personal information.
11. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal obligations, or regulatory requirements. Notification of Changes: We will notify you of material changes to this Privacy Policy through one or more of the following methods: - Posting the updated Privacy Policy on our website with a revised "Last updated" date - Sending an email notification to the email address associated with your account (if applicable) - Displaying a prominent notice on our website Effective Date: Changes to this Privacy Policy become effective on the date they are posted on our website, unless otherwise specified. Material changes that significantly affect your rights will be notified in advance to allow you to review the changes before they take effect. Your Continued Use: Your continued use of our website and services after any changes to this Privacy Policy constitutes your acknowledgment and acceptance of the revised policy. If you do not agree with the changes, you should discontinue use of our services and request deletion of your data. Historical Versions: We will maintain an archive of previous versions of this Privacy Policy for your reference. You may request a copy of any prior version by contacting us. This policy was last updated on July 23, 2026.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, the processing of your personal data, or if you wish to exercise any of your data protection rights, please contact us through the following channels: Data Protection Officer (DPO): Gabriel Toth Goncalves - Email: contato@gabrieltoth.com - WhatsApp: +55 11 99331-3606 - Website: www.gabrieltoth.com - Address: Sao Paulo, SP, Brazil Response Commitment: We are committed to responding to your requests and inquiries within the timeframe required by applicable law: - Under LGPD: Within 15 days from the date of your request (Art. 19 of Law No. 13,709/2018) - Under GDPR: Within one month, extendable by up to two additional months for complex or voluminous requests When submitting a request, please provide sufficient information to allow us to verify your identity and understand the nature of your request. We may require additional information to process your request. If you believe that we have not adequately addressed your privacy concerns, you have the right to file a complaint with: - Brazil: National Data Protection Authority (ANPD) - www.gov.br/anpd - European Union: Your local data protection supervisory authority We take all privacy concerns seriously and will make every effort to resolve any issues promptly and fairly.
This policy complies with the Brazilian General Data Protection Law (LGPD - Lei No. 13.709/2018), the European General Data Protection Regulation (GDPR - Regulation EU 2016/679), and other applicable data protection regulations.