Section 01
Introduction
Aplico Tecnologia Ltda ("Aplico Tecnologia", "we", "us", or "our") is a Brazilian technology company registered under CNPJ and headquartered in Brazil. We develop and deliver software solutions, custom systems integration, and technology consulting services for businesses across multiple industries.
This Privacy Policy applies to all personal data we process through our corporate website at aplicartecnologia.site and through any direct communication channels we operate — including email and telephone. It governs our practices as a data controller under Brazil's General Data Protection Law (Lei Geral de Proteção de Dados Pessoais — LGPD, Law No. 13,709/2018) and, where applicable to visitors from the European Economic Area, under the General Data Protection Regulation (GDPR, Regulation EU 2016/679).
By accessing our website or communicating with us, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please do not use our website or provide us with your personal information.
This is an institutional brochure website. We do not sell products, operate a client portal, or process payments online. Personal data we collect is limited to that which you voluntarily share with us and the technical data automatically generated by your browser when you visit.
Section 02
Information We Collect
We collect only the information that is necessary to pursue the legitimate purposes described in this policy. The categories of personal data we may hold are described below.
Information you provide directly
When you contact us by email or telephone — for instance, to request a project proposal, ask a question about our services, or engage in a business discussion — you may share personal information with us. This can include:
- Your full name and the name of your organisation
- Professional email address and telephone number
- Job title or role within your company
- The nature of your enquiry and any details you choose to provide about a project or requirement
- Any additional information you voluntarily include in correspondence
We collect this data solely to respond to your enquiry and to pursue any subsequent business relationship. We do not ask for, and ask that you do not send us, sensitive personal data such as government identification numbers, health data, financial account details, or similar information unless it is specifically required for a contracted engagement and protected by a separate confidentiality agreement.
Information collected automatically
When you visit our website, our web server and analytics tools automatically record certain technical information. This data does not directly identify you as an individual but may constitute personal data under applicable law because, in combination, it could be linked to a device or person. Automatically collected data may include:
- Internet Protocol (IP) address (stored in truncated or anonymised form where possible)
- Browser type, version, and language preference
- Operating system and device type (desktop, tablet, mobile)
- Referring URL — the page or search result that led you to our site
- Pages visited, time and duration of visits, and click paths within the site
- Date and time of each request to our server
- HTTP status codes and bandwidth consumed
This technical information is used exclusively to maintain the stability and security of our systems, to diagnose errors, and to understand in aggregate how visitors interact with our content so that we can improve it.
Cookies and similar technologies
We use cookies and similar tracking technologies. A full explanation of what cookies we deploy, their purpose, duration, and how you can control them is provided in Section 04 of this policy.
Section 03
How We Use Your Information
We process personal data only when we have a lawful basis for doing so. Under the LGPD, our lawful bases include your consent, the performance of or preparation for a contract, compliance with a legal obligation, and our legitimate interests where those interests are not overridden by your rights. Under the GDPR, equivalent grounds apply (Art. 6 GDPR). The specific purposes for which we use data are:
- To respond to your enquiries and communications. When you reach out to us, we use your contact details and the substance of your message solely to provide you with a timely, relevant response. This processing is necessary either for the performance of pre-contractual steps at your request or based on our legitimate interest in conducting our business.
- To deliver our services. If we enter into a commercial relationship with you or your organisation, we process the personal data of relevant contacts to fulfil our contractual obligations, manage the project, issue invoices, and communicate about deliverables.
- To improve our website and communications. We analyse aggregated, anonymised website usage data to understand what content is most useful to visitors, to fix technical problems, and to refine the structure and presentation of our site. This processing is based on our legitimate interest in maintaining an effective online presence.
- To comply with legal obligations. We may retain certain data — such as invoicing records and contractual correspondence — for the periods required by Brazilian fiscal and commercial law, including the requirements of the Brazilian Internal Revenue Service (Receita Federal).
- To protect our legal rights and prevent fraud. We may process data to the extent necessary to establish, exercise, or defend legal claims, or to detect and prevent fraudulent access to or misuse of our systems.
- To send service-related communications. If you are an existing client, we may contact you with information that is directly relevant to the services we provide to you. We do not send unsolicited marketing emails.
We do not make automated decisions that produce legal or similarly significant effects about individuals, nor do we use your personal data to build individual behavioural profiles for advertising purposes.
Section 05
Sharing With Third Parties
We do not sell, rent, or trade your personal data. We do not share your personal data with third parties for their own marketing purposes. We may disclose personal data to third parties only in the following circumstances:
Technology and hosting providers
Our website is hosted on third-party infrastructure. The hosting provider may have access to technical log data (including IP addresses) as part of delivering the hosting service. Our hosting and infrastructure providers are contractually required to protect the data they process on our behalf and to use it only for the purpose of providing services to us, acting as data processors.
Analytics providers
As described in Section 04, we use Google Analytics. Google processes anonymised analytics data on our behalf under the terms of Google's data processing agreements. Google may transfer data to servers in the United States; such transfers are governed by Google's standard contractual clauses and compliance with applicable international data transfer frameworks.
Professional advisers and auditors
We may share personal data with our lawyers, accountants, auditors, and insurers where necessary to obtain professional advice or in connection with disputes, audits, or legal proceedings. These parties are bound by professional obligations of confidentiality.
Legal and regulatory authorities
We may disclose personal data to government bodies, law enforcement agencies, courts, or regulators when required to do so by law, court order, or regulatory directive, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or other illegal activity.
Business transfers
In the event of a merger, acquisition, sale of all or a portion of our assets, or other business restructuring, personal data we hold may be transferred to the successor entity. We will notify affected individuals and, where required, obtain consent before such a transfer takes place, and we will ensure the successor is bound by privacy obligations at least as protective as those in this policy.
No cross-border transfers without safeguards: Where we transfer personal data outside Brazil or the European Economic Area, we implement appropriate safeguards — such as standard contractual clauses approved by the relevant supervisory authority — to ensure that your data remains protected to a standard equivalent to that required by applicable law.
Section 06
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, to resolve disputes, and to enforce our agreements. The following retention guidelines reflect our current practices:
- Enquiry and pre-contract correspondence: Retained for up to 2 years from the date of the last communication, unless that enquiry results in a contract, in which case the contractual retention periods below apply.
- Client and contractual records (including project documentation, invoices, and related correspondence): Retained for 5 years from the end of the fiscal year in which the relevant services were rendered, in compliance with Brazilian tax law (particularly the requirements of the Receita Federal regarding corporate income tax and service invoices).
- Website analytics data: Aggregated analytics data is retained for up to 26 months within Google Analytics, after which it is automatically deleted. Raw server log files are retained for no more than 90 days for security purposes.
- Cookie consent records: Retained for the duration of the consent plus 1 year to allow us to demonstrate compliance in the event of a complaint.
- Legal claims and dispute records: Where personal data is relevant to actual or anticipated legal proceedings, we may retain it until those proceedings are concluded and all rights of appeal are exhausted.
When data is no longer required and there is no legal basis for its continued retention, we delete or anonymise it in a secure manner. Anonymised or aggregated data — from which it is no longer possible to identify any individual — may be retained indefinitely for statistical and business analysis purposes.
Section 07
Data Security
The security of your personal data is important to us. We implement a layered set of technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include:
- Encryption in transit: All data transmitted between your browser and our website is encrypted using TLS (Transport Layer Security), as indicated by the padlock icon in your browser's address bar.
- Access controls: Access to personal data held on our internal systems is restricted on a need-to-know basis. Employees and contractors who handle personal data are required to keep it confidential and are trained on their obligations under applicable data protection law.
- Infrastructure security: We use reputable cloud hosting providers that maintain industry-standard physical and logical security controls, including firewalls, intrusion detection, and regular security patching.
- Vendor due diligence: Before engaging any third-party service provider that will process personal data on our behalf, we assess their security practices and enter into data processing agreements that impose appropriate security obligations.
- Incident response: We maintain internal procedures for detecting, reporting, and responding to personal data breaches. In the event of a breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (the Autoridade Nacional de Proteção de Dados — ANPD — in Brazil, or the appropriate EEA supervisory authority where GDPR applies) and, where required, affected individuals, within the timeframes stipulated by applicable law.
While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and any transmission of personal data is at your own risk. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately using the details in Section 11.
Section 08
Your Rights
Depending on your location and the applicable law (LGPD or GDPR), you hold a number of rights regarding the personal data we hold about you. We are committed to honouring these rights promptly and without undue restriction. A summary of your rights is set out below.
Right of Access
You have the right to request a copy of the personal data we hold about you and to receive information about how it is being processed, including the purposes of processing, the categories of data, and the recipients to whom it has been disclosed.
Right to Rectification
If the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it without undue delay.
Right to Erasure
You may request the deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where the processing has no other lawful basis. This right is subject to exceptions, such as where retention is required by law.
Right to Object
You have the right to object to the processing of your personal data where that processing is based on our legitimate interests. If you object, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for legal claims.
Right to Restriction
In certain circumstances — for example, while a dispute about the accuracy of your data is being resolved — you may request that we restrict processing so that we may only store the data and not otherwise use it.
Right to Data Portability
Where processing is based on consent or a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, but we will cease the specific processing going forward.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil, or with the supervisory authority of your country of residence if you are located in the EEA.
How to exercise your rights
To exercise any of the rights described above, please send a written request to us at contato@aplicartecnologia.site. Please include your full name and, if possible, sufficient detail to allow us to locate the personal data you are referring to. We will respond within 15 days of receiving your request, or within the period required by applicable law if shorter or longer. We will not charge a fee for honouring your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to comply, giving you our reasons.
We may need to verify your identity before acting on your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Section 09
Children's Privacy
Our website and services are directed exclusively at business professionals and corporate clients. We do not knowingly collect personal data from individuals under the age of 18. Our website contains no content that is designed to attract minors, and we do not take any steps to verify that website visitors are adults because we have no reasonable expectation that minors would seek out a B2B technology services company.
If we become aware that we have inadvertently collected personal data from a person under 18 without the appropriate parental or guardian consent required by applicable law, we will delete that data from our records as quickly as reasonably practicable. If you believe that we may have collected data from or about a minor, please contact us immediately at contato@aplicartecnologia.site so that we can take prompt corrective action.
Section 10
Changes to This Policy
The privacy landscape evolves continuously — driven by changes in technology, our services, applicable law, and regulatory guidance. We therefore reserve the right to update or modify this Privacy Policy at any time. When we make changes, we will revise the "Last updated" date at the top of this page.
For material changes — those that significantly alter how we collect, use, or share personal data, or that meaningfully affect your rights — we will take additional steps to notify you. These may include posting a prominent notice on our website, or, where we have your contact details and it is proportionate to do so, notifying you directly by email.
We encourage you to review this policy periodically so that you remain informed about how we protect your information. Your continued use of our website after the posting of a revised policy constitutes your acknowledgement of the changes. If you do not agree with a revised policy, you should discontinue your use of our website and, if applicable, notify us so that we can address any data already held.
Previous versions of this policy are available on request by contacting us at the address below.
Section 11
Contact & Data Controller
Aplico Tecnologia Ltda is the data controller responsible for the personal data described in this policy. If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a concern about how we handle your personal data, please contact us using the details below. We are committed to resolving all enquiries and complaints promptly and in good faith.
Company Name: Aplico Tecnologia Ltda
Trading as: Aplico Tecnologia
CNPJ: On file — available upon written request
Privacy & Data Protection Contact: contato@aplicartecnologia.site
Website: aplicartecnologia.site
We aim to respond to all privacy-related enquiries within 15 business days. For urgent matters concerning a suspected data breach or unlawful processing, please mark your message URGENT — DATA PROTECTION in the subject line and we will prioritise your contact.
If you are not satisfied with our response to a privacy enquiry or complaint, you have the right to escalate your concern to the Autoridade Nacional de Proteção de Dados (ANPD) — the Brazilian national data protection authority — at gov.br/anpd. EEA residents may contact the supervisory authority in their country of habitual residence, place of work, or the place of the alleged infringement.