Software.Com.Br

Privacy Policy

At Software.Com.Br we believe transparency is the foundation of trust. This document explains, clearly and completely, what personal data we collect, why we collect it, how we protect it, and what rights you have over it — in full compliance with Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13,709/2018) and the European General Data Protection Regulation (GDPR).

Last updated: 18 June 2025 LGPD & GDPR compliant Version 3.1

1 Introduction

This Privacy Policy applies to all websites, digital platforms, and services operated by SOFTWARE.COM.BR TECNOLOGIA E CONSULTORIA LTDA. (CNPJ 09.240.519/0001-11), a technology and consulting company headquartered at Avenida Paulista, 2064, Andar 7 Bloco B, Bela Vista, São Paulo – SP, Brazil. For the purposes of this Policy, "Software.Com.Br", "we", "us", and "our" all refer to that legal entity.

We are the data controller for all personal information processed through this website and through the professional services we deliver to clients. We recognize that your personal data belongs to you, and we are committed to handling it with the care, transparency, and legal rigor that Brazilian and international privacy law demands.

Please read this Policy carefully before using our site, submitting a contact form, or engaging with our services. By continuing to use our platforms after reviewing this document, you acknowledge that you have been informed of our data-processing practices. Where processing requires your consent, we will request it separately and explicitly — and you may withdraw it at any time.

Who this Policy covers. This Policy applies to visitors to our website, prospective clients who reach out via our contact channels, current clients whose personal data we process as part of service delivery, and any individuals whose information is submitted to us on behalf of a business entity.

2 Information We Collect

We collect only the personal data that is necessary for a specific, legitimate purpose. We do not collect data "just in case." Below is a precise breakdown of the categories of data we may process and the source of each.

Data you provide directly

When you fill in one of the contact or quote-request forms on our website, send us an email, or communicate with us by telephone or messaging platform, you may share:

  • Full name — used to address you properly and to identify the individual making an enquiry.
  • Email address — our primary channel for responding to enquiries and sending service-related communications.
  • Telephone or WhatsApp number — collected only when you voluntarily provide it; used to follow up on complex technical or commercial discussions.
  • Company name, industry and role — helps our consultants understand your business context before an initial meeting.
  • Project description or message content — the free-text information you include in contact forms or emails, which may contain details about your technical needs, budget range, timelines, or organisational challenges.
  • CNPJ or CPF (where applicable) — collected only when we advance to a formal commercial proposal or contractual engagement, not at the initial contact stage.

Data collected automatically when you visit our site

When you access our website, our servers and third-party analytics tools automatically record certain technical information. This includes:

  • IP address — recorded by our hosting infrastructure for security monitoring and approximate geolocation (city/region level only).
  • Browser type and version, operating system, and device category — used to ensure our website renders correctly across different environments.
  • Pages visited, time spent on each page, and navigation path — collected via Google Analytics to help us understand which content is most useful and where visitors encounter friction.
  • Referrer URL — the address of the page or search result from which you arrived, helping us assess the effectiveness of our marketing channels.
  • Click events and scroll depth — aggregated behavioural data used to improve page layout and call-to-action placement.
  • Google Ads click and conversion data — when you arrive via a paid advertisement, Google may pass a click identifier (GCLID) that we associate with a subsequent conversion event (e.g. a form submission) to measure campaign performance. This data is processed under Google's own privacy terms as well as ours.

Data we receive from third parties

In limited circumstances, we may receive basic professional information about you from publicly available sources — for example, your name and role as listed on your company's website or LinkedIn profile — when conducting preliminary research before a scheduled business meeting you have already agreed to attend. We do not purchase mailing lists or obtain personal data from data brokers.

3 How We Use Your Information

Every use of your personal data is tied to a specific legal basis under LGPD and, where applicable, the GDPR. We do not use your data for purposes incompatible with those for which it was originally collected.

  • Responding to your enquiry (legitimate interest / contract performance). When you submit a contact form or send us an email, we use the information you provide solely to understand and respond to your request. If you ask for a proposal, we use your project details to prepare one.
  • Managing client relationships (contract performance). Once an engagement begins, we process contact and project-related data to deliver the agreed services — software development, systems integration, IT consulting, or any other scope — and to manage invoicing, support requests, and project communications.
  • Improving our website and content (legitimate interest). Aggregated and anonymised analytics data helps us identify which pages are most helpful, which services generate the most interest, and where the user experience can be improved. No individual is targeted or profiled based on browsing behaviour.
  • Measuring advertising performance (legitimate interest / consent). We run paid search campaigns via Google Ads. We measure whether a user who clicked an ad subsequently submitted a contact form, so that we can allocate our marketing budget responsibly. This involves Google's conversion tracking functionality and is governed by our cookie consent mechanism.
  • Sending service-related communications (contract performance / legitimate interest). We may contact you by email or telephone about the status of an ongoing project, a renewal of a service contract, or a material change to our terms. We do not send unsolicited promotional emails to people who have not explicitly opted in.
  • Complying with legal obligations (legal obligation). Brazilian tax and corporate law requires us to retain certain financial records, including invoice data that may contain personal information, for defined periods. We retain only what is legally necessary.
  • Protecting our systems and preventing fraud (legitimate interest). We monitor server logs and access patterns to detect and block malicious activity, brute-force attacks, and unauthorised access attempts.

We never sell your personal data. We never use it for automated decision-making that produces legal or similarly significant effects on you without human review. We never use it to build behavioural advertising profiles for third-party advertisers.

4 Cookies & Tracking Technologies

Our website uses cookies — small text files placed on your device — as well as similar tracking technologies such as web beacons and JavaScript tags. We categorise these technologies as follows:

Strictly necessary cookies

These cookies are essential for the website to function. They do not collect any information about you that could be used for marketing or to remember what pages you have visited. Examples include session identifiers that keep you logged in during a single visit and security tokens that prevent cross-site request forgery. These are activated automatically and cannot be disabled without breaking site functionality.

Analytics cookies (require consent)

We use Google Analytics 4 (GA4) to understand how visitors use our website in aggregate. GA4 sets cookies (including _ga and _ga_[ID]) that distinguish unique users and sessions. The data collected — page views, session duration, traffic source, country — is pseudonymised and sent to Google's servers. We have configured GA4 with IP anonymisation enabled and have entered into a Data Processing Agreement with Google. Google may process this data in countries outside Brazil and the EU; it does so under the EU Standard Contractual Clauses.

Advertising & conversion cookies (require consent)

When you arrive at our website via a Google Ads advertisement, Google may set cookies (including _gcl_au and the GCLID parameter) to attribute your visit to a specific campaign and to record whether you subsequently complete a conversion action such as a form submission. This tracking is strictly for internal campaign measurement — we use it to understand return on advertising spend and to avoid wasting budget on underperforming keywords. We do not use this data to serve you personalised ads elsewhere on the internet.

Managing your cookie preferences

When you first visit our website, a consent banner gives you the option to accept or decline non-essential cookies. You may change your preferences at any time by clicking the "Cookie Settings" link in our site footer. You may also manage or delete cookies directly through your browser settings; please consult your browser's help documentation for instructions. Note that disabling analytics cookies will not affect your ability to use the website, but will prevent us from improving it based on usage data.

Do Not Track (DNT). Some browsers offer a "Do Not Track" signal. At present there is no industry-wide standard for responding to DNT signals; however, our analytics implementation already applies IP anonymisation and minimal data collection by default, regardless of DNT status.

5 Sharing With Third Parties

We do not sell, rent, or trade your personal data to any third party. We share it only in the limited circumstances described below, and only with parties that are contractually bound to protect it to at least the same standard we apply ourselves.

  • Service providers and sub-processors. We engage carefully selected technology partners to operate our business infrastructure — these include our cloud hosting provider (for website and email hosting), our CRM platform (for managing client relationships), and communication tools. Each provider operates under a data processing agreement and is permitted to process your data only to deliver the specific service we have contracted them for.
  • Google LLC. As described in the Cookies section, Google processes analytics and advertising attribution data on our behalf under a Data Processing Agreement. Google's privacy policy is available at policies.google.com/privacy.
  • Legal and regulatory authorities. If we are required to disclose data by a valid court order, regulatory demand, or applicable law — including requests from the Brazilian Autoridade Nacional de Proteção de Dados (ANPD) — we will comply. Where legally permissible, we will notify you before disclosing.
  • Professional advisors. Our lawyers, accountants, and auditors may access client-related data in the course of providing advice or conducting audits. They are bound by professional confidentiality obligations.
  • Business transfers. If Software.Com.Br is involved in a merger, acquisition, or sale of business assets, your data may be transferred to the successor entity. We will notify you of any such transfer and your rights in relation to it before it takes effect.

Where data is transferred outside Brazil to countries that do not offer an equivalent level of data protection, we ensure appropriate safeguards are in place — including Standard Contractual Clauses, binding corporate rules, or the data subject's explicit consent — as required by LGPD Article 33.

6 Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes described in this Policy, or as required by applicable law. Below are the specific retention periods that govern our main data categories:

  • Contact form submissions and pre-sales enquiries — retained for up to 24 months from the date of your last communication with us. After this period, data is deleted or anonymised unless it has transitioned into a client engagement.
  • Active client project data — retained for the duration of the contractual relationship plus 5 years thereafter, in accordance with Brazilian civil law limitation periods (Código Civil, Art. 206).
  • Financial and invoicing records — retained for a minimum of 5 years as required by Brazilian tax legislation (Lei 9,430/1996 and related regulations).
  • Website analytics data — Google Analytics data is retained at the property level for 14 months (the minimum configurable retention period in GA4 for session-level data), after which it is automatically deleted by Google.
  • Server access logs — retained for up to 90 days for security monitoring purposes, then purged.
  • Consent records — records of when and how you provided or withdrew cookie consent are retained for 3 years, so that we can demonstrate compliance if challenged.

When the applicable retention period expires, data is securely deleted or irreversibly anonymised. Requests for early deletion are handled in accordance with the Your Rights section below.

7 Data Security

Protecting your data from unauthorised access, loss, or misuse is a core operational priority for us — not an afterthought. As a technology company, we apply the same rigorous security standards to our own systems that we recommend to our clients.

  • Encryption in transit. All data transmitted between your browser and our servers is encrypted using TLS 1.2 or TLS 1.3. Our website enforces HTTPS across all pages, including form endpoints.
  • Encryption at rest. Databases and file storage systems containing personal data are encrypted at rest using AES-256.
  • Access controls. Personal data is accessible only to employees and contractors who have a legitimate need to process it in the performance of their duties. Access is governed by the principle of least privilege and reviewed quarterly. All staff with access to personal data are bound by confidentiality obligations.
  • Multi-factor authentication. Administrative access to any system that stores personal data requires multi-factor authentication. We do not permit password-only access to production environments.
  • Regular security assessments. We conduct periodic vulnerability assessments and patch management reviews of our own infrastructure. Material security findings are addressed on a risk-prioritised basis.
  • Incident response. We maintain an internal incident response procedure. In the event of a data breach that is likely to result in risk to individuals' rights and freedoms, we will notify the ANPD and, where required, affected data subjects within the timeframes stipulated by LGPD.

No system connected to the internet can guarantee absolute security. While we apply industry-standard safeguards, we encourage you to use strong, unique passwords when creating accounts on any platform, and to contact us immediately at contato@softwares-us.site if you suspect that your interaction with our services has been compromised.

8 Your Rights

Under the LGPD and, where applicable, the GDPR, you have meaningful rights over your personal data. We are committed to honouring these rights promptly and without unnecessary bureaucracy. Below is a plain-language explanation of each right and how it works in practice.

Right of Access (Confirmation & Copy)

You may ask us to confirm whether we hold personal data about you and to provide a copy of that data in a clear, structured format. We will respond within 15 days of a verified request.

Right of Correction

If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to ask us to correct it. We will update our records promptly upon verification.

Right to Erasure (Deletion)

You may request deletion of personal data that was collected on the basis of your consent, or that is no longer necessary for the purpose for which it was collected. Note that data we are legally required to retain cannot be deleted early, but we will clearly explain what we can and cannot delete and why.

Right to Withdraw Consent

Where processing is based on your consent — for example, analytics or advertising cookies — you may withdraw that consent at any time through our cookie settings panel or by contacting us. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

Right to Data Portability

You may request a copy of personal data you have provided to us in a commonly used, machine-readable format (such as JSON or CSV) so that you can transmit it to another service provider.

Right to Object

You have the right to object to processing carried out on the basis of our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is necessary for legal claims.

Right to Restriction

In certain circumstances — for example, while a dispute about data accuracy is being resolved — you may ask us to restrict processing of your data to storage only, without actively using it.

Right to Lodge a Complaint

If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil, or with the supervisory authority in your country of residence if you are located in the EU/EEA.

How to exercise your rights

To exercise any of the rights listed above, please send a written request to contato@softwares-us.site with the subject line "Data Subject Request." Please include your full name, the email address associated with your interaction with us, and a clear description of the right you wish to exercise. We may ask you to verify your identity before processing the request — this is to protect you against third parties making unauthorised requests in your name.

We will acknowledge your request within 5 business days and provide a substantive response within 15 business days. If the complexity of your request requires additional time, we will notify you within the initial 15-day window and provide a revised timeline of no longer than a further 15 business days.

9 Children's Privacy

Our website and services are directed exclusively at business professionals and organisations seeking technology consulting and software development services. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18.

If you are a parent or guardian and you believe that a minor has submitted personal data to us — for example, by completing a contact form — please contact us immediately at contato@softwares-us.site. We will promptly investigate and, where confirmed, delete the relevant data without undue delay.

In the unlikely event that we become aware that we have inadvertently collected data from a child, we will take immediate steps to delete it and, where required by applicable law, notify the relevant authorities.

10 Changes to This Policy

Privacy law evolves, and so do our services. We review this Privacy Policy at least once a year, and we update it whenever our data-processing practices change in a material way — for example, if we introduce a new analytics tool, change a sub-processor, or expand the types of services we offer.

When we make substantive changes, we will update the "Last updated" date at the top of this page and, where the changes are significant enough to affect data subjects' rights or reasonable expectations, we will publish a notice on our website homepage for at least 30 days and, where feasible, send a notification to active clients by email.

We encourage you to revisit this page periodically. The version published on our website supersedes all previous versions. Archived versions of this Policy are available upon request by contacting us at the details below.

11 Contact & Data Protection Officer

If you have any questions about this Privacy Policy, wish to exercise a data subject right, want to report a potential data security issue, or simply need clarification on how we handle a particular category of data, please reach out to us using the details below. We take all enquiries seriously and commit to a substantive, human response — not an automated reply.

Company
SOFTWARE.COM.BR TECNOLOGIA E CONSULTORIA LTDA.

CNPJ
09.240.519/0001-11

Registered address
Avenida Paulista, 2064, Andar 7 Bloco B
Bela Vista, São Paulo – SP, Brazil

Privacy & data protection enquiries
contato@softwares-us.site

Expected response time
We acknowledge all data-related enquiries within 5 business days and aim to resolve straightforward requests within 15 business days.

If you are located in the European Union or European Economic Area and believe that your rights under the GDPR have not been respected, you also have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EU/EEA supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu. For complaints related to LGPD, the competent authority is the Autoridade Nacional de Proteção de Dados (ANPD), accessible at gov.br/anpd.