° Privacy Policy
How 36T SOLUCOES CONSULTORIA EM TI LTDA handles your personal data under the Brazilian General Data Protection Law (LGPD – Law 13.709/2018)
Last updated: 15 September 2026
1. Who the controller is
The controller of the personal data processed on this website is 36T SOLUCOES CONSULTORIA EM TI LTDA, CNPJ 65.085.463/0001-49, a Brazilian IT consultancy.
Our data protection officer (DPO) is Victor Nishiguchi, who can be reached at [email protected].
2. What data we collect
We only collect the data needed to answer your enquiry and run the website:
- Contact form: name, company, position, e-mail and message. Optionally, industry, company size and areas of interest. We also record the language the form was submitted in.
- WhatsApp: if you choose to talk to us via WhatsApp, your number and the content of the messages are also processed by Meta Platforms under the WhatsApp privacy policy.
- Technical data: your IP address is kept for a few minutes, in memory only, to limit abusive form submissions. It is not stored with your message.
- Usage statistics: we use Rybbit, a self-hosted analytics tool that uses no cookies and collects only aggregated, anonymised data (pages visited, referrer, browser and device type, country).
- Cookies: only technically essential cookies, described in the Cookie Policy.
3. Why we use the data and on which legal basis
We process personal data for the purposes below, on the legal bases set out in article 7 of the LGPD:
- Answering your enquiry, preparing proposals and conducting commercial negotiations – performance of a contract or of preliminary procedures at the data subject's request (art. 7, V).
- Keeping a record of the contact in our CRM to continue the business relationship – legitimate interest (art. 7, IX).
- Protecting the website against abuse and keeping it secure – legitimate interest (art. 7, IX).
- Meeting legal and regulatory obligations – compliance with a legal obligation (art. 7, II).
4. Who we share it with
We do not sell or transfer personal data to third parties for marketing purposes. Form data is stored in the website database and in our CRM system (Odoo), both operated by 36T.
We rely on processors for hosting, e-mail and infrastructure, which handle the data exclusively on our behalf and under our instructions. Our servers are currently hosted in the European Union (Germany and Finland), so form data is subject to an international transfer. That transfer takes place under article 33 of the LGPD and the ANPD regulations, with contractual clauses ensuring a level of protection equivalent to this policy.
Data may also be disclosed where required by law, court order or a competent authority.
5. How long we keep it
Contact data is kept for as long as the commercial negotiation lasts and, afterwards, for the period needed to meet legal obligations and to exercise our rights. Contacts that do not lead to a business relationship are deleted or anonymised within 24 months of the last interaction. You may request deletion earlier (see section 6).
6. Your rights
Under article 18 of the LGPD you may, at any time and upon request, obtain:
- Confirmation that processing takes place and access to your data.
- Correction of incomplete, inaccurate or outdated data.
- Anonymisation, blocking or deletion of data that is unnecessary, excessive or processed unlawfully.
- Portability of your data to another provider, subject to ANPD regulations.
- Information about the entities with which we have shared your data.
- Information about the option of not giving consent and its consequences, and withdrawal of consent where that is the legal basis.
- Objection to processing based on legitimate interest.
7. How to exercise your rights
Send your request to [email protected], identifying yourself and describing what you need. We answer as quickly as possible, normally within 15 days. We may ask for additional information to confirm your identity.
If you believe the processing violates the LGPD, you may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).
8. Security
We adopt technical and organisational measures to protect personal data against unauthorised access and accidental or unlawful events, including encrypted transmission (HTTPS), restricted access to our systems and rate limiting of form submissions. In the event of a security incident that may cause significant risk, we will notify the ANPD and the affected data subjects in accordance with article 48 of the LGPD.
9. Changes to this policy
This policy may be updated to reflect legal changes or changes to our services. The current version is always the one published on this page, with the date of the last update shown above.