Legal & Compliance

Privacy Policy

Pindorama Tecnologia LTDA is committed to handling personal data with transparency, integrity and respect for every individual whose information we process. This document explains what we collect, why, and what rights you hold — in plain language.

Last Updated 23 July 2025
Effective Date 23 July 2025
Legal Entity Pindorama Tecnologia LTDA — CNPJ 52.721.721/0001-94
Frameworks LGPD (Brazil) · GDPR (EU/EEA) · CCPA reference

Introduction §1

This Privacy Policy is published by Pindorama Tecnologia LTDA, a Brazilian technology company registered under CNPJ 52.721.721/0001-94, with its registered address at Rua Coronel Tamarindo, 08, Bloco 3 Apt 401, Gragoatá, Niterói — RJ, Brazil. We operate this website (the "Site") and develop intelligent software solutions, including our Pirilampo conversational AI platform, for clients across Brazil and internationally.

We recognise that your personal data belongs to you. The purpose of this document is to explain, with full transparency, which categories of personal information we collect when you visit our Site or engage with our services; the legal bases on which we rely to process that information; how long we keep it; with whom we share it; and the concrete rights you may exercise at any time at no charge.

This policy is written to comply with Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018) and, to the extent that we process data relating to individuals in the European Economic Area or United Kingdom, with the General Data Protection Regulation (GDPR — Regulation EU 2016/679) and its UK equivalent. Where the two regimes overlap, we apply the higher standard.

By accessing or continuing to use our Site, you acknowledge that you have read and understood this Privacy Policy. If you disagree with any part of it, you are free to discontinue use of the Site.

Information We Collect §2

We collect personal data through several channels and only to the extent genuinely necessary for the purposes described in Section 3 below. The categories are:

a) Information You Provide Directly

When you reach out to us using the contact details published on this Site — by email, telephone, or messaging — you voluntarily share information such as your name, email address, telephone number, company name, job title, and the content of your message. This data is processed for the sole purpose of responding to your enquiry and, where relevant, establishing a commercial relationship. We do not operate embedded data-collection forms on this Site; all contact is initiated by you through external channels (your email client, your phone).

b) Data Collected Automatically When You Browse

Our hosting infrastructure and analytics tools automatically record certain technical data each time a browser makes a request to our servers. This includes:

  • Your IP address (truncated to the last octet where technically feasible)
  • Browser type, version, and operating system
  • The referring URL (the page that linked you here)
  • Pages visited, time and date of visit, and session duration
  • Device type and screen resolution
  • Country or region inferred from IP geolocation (city-level precision is not retained)

This technical data is used exclusively to maintain the security and performance of the Site and to understand, in aggregate, how visitors engage with our content. It does not, by itself, allow us to identify you as a named individual.

c) Cookies and Similar Technologies

We use cookies, pixel tags, and local storage to enable certain site functions and to gather anonymised analytics. The types of cookies we deploy and your choices regarding them are explained in full in Section 4 below.

d) Business Contact Data (B2B Context)

When we enter into discussions or a contractual relationship with a company, we collect business contact information about that company's representatives — typically name, role, corporate email address, and telephone number. This processing is carried out on the basis of legitimate interest (LGPD Art. 7, X; GDPR Art. 6(1)(f)) or contract performance (LGPD Art. 7, V; GDPR Art. 6(1)(b)) and is limited strictly to individuals acting in their professional capacity.

We do not collect sensitive personal data (such as racial or ethnic origin, political opinions, religious beliefs, biometric data, or health information) through this Site. If the nature of a specific project requires the processing of special-category data on behalf of a client, that processing is governed by a separate Data Processing Agreement executed between the parties.

How We Use Your Information §3

Every use of personal data we make is tied to a specific, documented purpose and a corresponding legal basis under the LGPD and/or GDPR. We never use personal data for purposes incompatible with those stated at collection.

  • Responding to enquiries and providing information. When you contact us by email or telephone, we use the information you provide to respond accurately and promptly. Legal basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)) and, where applicable, pre-contractual measures.
  • Entering into and performing contracts. If your enquiry leads to a service agreement, we process the relevant personal and business data necessary to draft, execute, and fulfil that agreement, including invoicing and after-delivery support. Legal basis: contract performance (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
  • Site operation, security, and improvement. Automatically collected technical data is used to detect abuse, investigate security incidents, diagnose technical faults, and understand which content is most useful to visitors, so that we can improve the Site over time. Legal basis: legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)), specifically our interest in providing a secure, functional, and relevant online presence.
  • Analytics and product development. Aggregated, anonymised or pseudonymised analytics help us understand how our technology offerings are received and where we should focus development effort. No individually identifiable profiles are built for this purpose.
  • Compliance with legal obligations. Where Brazilian or applicable international law requires us to retain or disclose data — for example, for tax records under Brazilian fiscal legislation, or in response to a valid court order — we do so. Legal basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
  • Marketing communications (opt-in only). We do not send unsolicited commercial email. If you have explicitly asked to receive updates about Pindorama Tecnologia's services or the Pirilampo platform, we will contact you for that purpose. You may withdraw consent at any time by emailing us at the address in Section 11.

Cookies & Tracking Technologies §4

Cookies are small text files stored on your device by your browser when you visit a website. We use cookies and equivalent technologies for the purposes described below. You retain full control over non-essential cookies at any time through your browser settings.

Strictly Necessary Cookies

These cookies are essential for the Site to function. They do not collect personal data for marketing purposes and cannot be disabled without breaking core functionality. Examples include cookies that maintain session state or preserve your cookie-consent preference. No consent is required for these under applicable law, as they are set on the basis of legitimate interest.

Analytics Cookies

We use Google Analytics 4 (operated by Google LLC) with IP anonymisation enabled. These cookies assign a random, pseudonymous identifier to each browser session and allow us to measure aggregate traffic patterns — such as which pages attract the most visitors and how long people spend on each page. Google Analytics data is processed on servers in the United States under Google's Standard Contractual Clauses. Analytics cookies are only activated after you accept them, or if you have not yet been presented with a cookie banner (in which case only the anonymised identifier is set until consent is obtained).

You can opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout, or by adjusting your consent preferences in our cookie banner.

Advertising & Retargeting Cookies

If we run paid advertising campaigns through Google Ads, Meta Ads, or LinkedIn Ads, those platforms may place cookies on your device when you click an advertisement and arrive at our Site. These cookies allow the advertising platform to measure whether your visit was the result of an ad click and to attribute conversions. We do not use these cookies to build personal profiles for our own targeting. They are only set with your prior consent. You can manage your advertising preferences directly through:

  • Google: adssettings.google.com
  • Meta: facebook.com/privacy/policies/cookies
  • LinkedIn: linkedin.com/psettings/guest-controls/retargeting-opt-out

Your Cookie Choices

Most browsers allow you to refuse or delete cookies through their settings menu (typically found under Privacy, Security, or Advanced). Disabling analytics or advertising cookies will not prevent you from viewing any content on this Site. Disabling strictly necessary cookies may impair certain functions. Cookie preferences set in one browser are not automatically applied to other browsers or devices.

Sharing With Third Parties §5

We do not sell, rent, or trade personal data. We share personal data with external parties only in the following limited circumstances:

  • Technology infrastructure providers. Our Site and operational systems rely on reputable cloud and SaaS providers — including web hosting, email delivery, and project management tools. These vendors process data solely on our behalf under binding contracts that include data processing clauses consistent with LGPD and/or GDPR requirements. They are not permitted to use your data for their own purposes.
  • Analytics and advertising platforms. As described in Section 4, Google, Meta, and LinkedIn may receive cookie-derived, pseudonymous identifiers when you visit our Site and have consented to those technologies.
  • Professional advisors. Our lawyers, accountants, and auditors may have access to personal data when this is necessary for the provision of professional services. These parties are bound by professional confidentiality obligations and by contractual data-protection commitments.
  • Law enforcement and public authorities. We may disclose personal data when required to do so by applicable law, court order, or enforceable government request — for example, to the Receita Federal, a Brazilian court, or, in relation to EEA-based individuals, to a supervisory authority with jurisdiction. We will notify affected individuals of such requests where legally permitted to do so.
  • Business transfers. In the event of a merger, acquisition, restructuring, or sale of all or substantially all of our business assets, personal data we hold may be transferred to the acquiring entity. We will provide advance notice and ensure that the receiving party commits to equivalent or higher data-protection standards.

When we transfer personal data to recipients outside Brazil or the EEA, we ensure an appropriate legal mechanism is in place — such as the European Commission's Standard Contractual Clauses, Brazil's ANPD-approved international transfer instruments, or adequacy decisions where available.

Data Retention §6

We retain personal data for only as long as necessary to fulfil the purpose for which it was collected, unless a longer retention period is required or permitted by law. The following table summarises our standard retention periods:

Category of Data Retention Period Basis for Retention
Enquiry and contact emails 2 years from last interaction, unless a contract follows Legitimate interest; statute of limitations
Contract and commercial records 10 years from contract end date Brazilian Civil Code Art. 206 §3 / fiscal law
Tax and invoicing records 5 years (or applicable SPED retention period) Brazilian tax legislation (CTN Art. 173)
Web server access logs (raw) 90 days, then anonymised or deleted Security monitoring; Marco Civil da Internet Art. 15
Anonymised analytics data Up to 26 months (Google Analytics default) Site improvement; no personal data retained
Consent records (cookie preferences) 1 year from consent or withdrawal Accountability obligation (LGPD Art. 37)
Marketing opt-in records Duration of consent, then deleted within 30 days of withdrawal Consent

At the end of an applicable retention period, data is securely deleted or irreversibly anonymised. Deletion requests submitted by data subjects (see Section 8) may override these standard periods, subject to overriding legal obligations.

Data Security §7

We implement technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include, but are not limited to:

  • Encryption in transit: All traffic between your browser and our Site is encrypted using TLS 1.2 or TLS 1.3. We enforce HTTPS across all pages and subdomains and use HSTS headers to prevent downgrade attacks.
  • Encryption at rest: Personal data stored in our systems is encrypted at rest using AES-256 or equivalent standards wherever practicable.
  • Access controls: Access to personal data is restricted on a strict need-to-know basis. Team members who handle personal data are trained on data-protection obligations and are bound by confidentiality commitments.
  • Vendor vetting: We evaluate the security posture of third-party vendors before engaging them and include data-protection obligations in all supplier contracts.
  • Incident response: We maintain a written data-breach response procedure. In the event of a breach likely to result in risk to individuals' rights and freedoms, we will notify the relevant supervisory authority (Brazil's ANPD and/or the applicable EEA data protection authority) within 72 hours of becoming aware of the incident, as required by law, and will notify affected individuals without undue delay.

No method of data transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect personal data, we cannot guarantee its absolute security. We encourage you to use secure, up-to-date devices and browsers when communicating with us.

Your Rights §8

Under Brazil's LGPD (Chapter III) and the GDPR (Chapter III), individuals have a comprehensive set of rights with respect to personal data that concerns them. We honour these rights in full. Below is a plain-language summary:

Right of Access

You may request confirmation of whether we hold personal data about you and, if so, obtain a copy of that data along with information about how it is processed, its origin, with whom it is shared, and for how long it will be kept.

Right to Rectification

If any personal data we hold about you is inaccurate, incomplete, or out-of-date, you have the right to have it corrected or updated without undue delay.

Right to Erasure ("Right to be Forgotten")

You may ask us to delete personal data we hold about you. We will comply unless retention is required by law, necessary to fulfil a contract, or otherwise permitted by applicable regulation.

Right to Restriction of Processing

In certain circumstances — for example, while you contest the accuracy of data we hold — you may ask us to suspend processing while the matter is resolved, without requiring deletion.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV), or to have it transmitted directly to another controller where technically feasible.

Right to Object

You may object at any time to processing carried out on the basis of legitimate interest. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where the processing is necessary for legal claims.

Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd, or, for EEA residents, with the data protection authority in your country of habitual residence.

How to exercise your rights: Send a written request to [email protected] with the subject line "Data Subject Request". Please include sufficient information for us to identify your records (typically your name and the email address you used to communicate with us). We will acknowledge your request within 5 business days and fulfil it — or provide a reasoned explanation for any limitation — within 15 days for LGPD purposes and within 30 days (extendable by a further two months in complex cases, with notice) for GDPR purposes. We will not charge a fee for handling reasonable requests. If requests are manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or to decline, with written justification.

Identity verification: To protect your privacy and that of other individuals, we may ask you to verify your identity before acting on a data subject request. We will not use verification data for any other purpose.

Children's Privacy §9

This Site and our services are directed exclusively at businesses and professionals. We do not knowingly market to, or intentionally collect personal data from, children under the age of 18. Under Brazil's LGPD (Art. 14), the processing of personal data of children must be carried out in the child's best interests with specific parental or guardian consent; we have no mechanism or intention to process such data through this Site.

If you believe that a child has provided us with personal data without appropriate parental consent, please contact us immediately at [email protected] and we will take prompt steps to delete that information.

Changes to This Policy §10

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, applicable law, or regulatory guidance. When we make changes that are material — meaning changes that could meaningfully affect your rights or the way we process your data — we will update the "Last Updated" date shown at the top of this page and, where we hold your contact details, notify you directly by email at least 15 days before the revised policy takes effect.

For non-material updates (such as typographical corrections or minor clarifications that do not affect our substantive practices), we will update the date and the text without individual notification. We encourage you to review this page periodically. Continued use of the Site following the effective date of any update constitutes acceptance of the revised policy, to the extent permitted by applicable law.

Previous versions of this Privacy Policy are available on request by emailing [email protected].

Version Date Summary of Changes
1.0 Current 23 July 2025 Initial publication. Full LGPD and GDPR alignment; Google Ads landing-page compliance; cookies section including GA4 and advertising platforms.

Contact & Data Protection Officer §11

Pindorama Tecnologia LTDA is the data controller for personal data collected through this Site. If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or wish to raise a concern about our data-handling practices, please contact us using the details below. We aim to respond to all privacy-related enquiries within 5 business days.

Under the LGPD, we have designated a responsible person to act as the point of contact for data subjects and the ANPD. Requests sent to the email address below are handled directly by that responsible person or escalated without delay.

Pindorama Tecnologia LTDA — Data Privacy Contact

Legal Name Pindorama Tecnologia LTDA
CNPJ 52.721.721/0001-94
Registered Address Rua Coronel Tamarindo, 08, Bloco 3 Apt 401
Gragoatá, Niterói — RJ, Brazil
Privacy & DPO Email [email protected]
Subject Line for Rights Requests "Data Subject Request" — include your full name and the email address associated with your enquiry
Response Commitment Acknowledgement within 5 business days; substantive response within 15 days (LGPD) or 30 days (GDPR), with written notice if extension is required