Privacy Policy

Last updated: June 2025 Governs engesoftware.site and all related digital services

1. Introduction

Engesoftware Tecnologia S/A ("Engesoftware," "we," "us," or "our") is a Brazilian technology company registered under CNPJ 00.681.946/0001-60, headquartered at Setor Scia Quadra 13, Conjunto 04, Lotes 01 e 02, Guará, Brasília–DF. We develop and implement software solutions, managed IT services, cybersecurity infrastructure, and digital transformation programs for public-sector entities and private organizations throughout Brazil.

This Privacy Policy explains, in plain language, what personal data we collect through our website at engesoftware.site and any related sub-domains, contact forms, and digital communications channels; why we collect it; how we store and protect it; with whom we may share it; and what rights you have over it.

This document is written in compliance with Brazil's General Data Protection Law — Lei Geral de Proteção de Dados Pessoais (LGPD), Law No. 13,709/2018, and with the requirements of the EU General Data Protection Regulation (GDPR, Regulation 2016/679) to the extent it applies to interactions originating from the European Economic Area. It also satisfies the landing-page transparency requirements set out by Google's Advertising Policies.

By accessing our website or submitting information through any of our forms, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please do not use the site or submit personal information. Your continued use of the site following any material change to this policy constitutes acceptance of the revised terms.

2. Information We Collect

We collect personal data only to the extent necessary to provide our services, respond to enquiries, and improve the user experience on our site. The categories below describe exactly what we collect, how it is collected, and on what legal basis.

2.1 Information You Give Us Directly

When you fill out a contact form, request a quote, sign up for a newsletter, or send us an email, you voluntarily provide us with some or all of the following:

  • Full name — so we can address you correctly in our responses.
  • Corporate email address — our primary channel for replying to your enquiry.
  • Phone number (optional) — if you prefer a call-back rather than an email reply.
  • Company or organisation name — to understand the context of your needs.
  • Role or job title (optional) — helps us route your request to the right specialist.
  • Message content — the substance of your enquiry, question, or service request.
  • CNPJ or CPF — only collected when required to proceed with a formal proposal or contract; never required to make an initial contact.

Submitting a contact form does not establish a contractual relationship; it is simply the start of a conversation. We will never use the contact details you provide to send unsolicited marketing communications unless you have expressly given consent for that purpose.

2.2 Data Collected Automatically

Like virtually all professionally operated websites, our server and analytics tools automatically record certain technical data whenever a browser requests a page. This includes:

  • IP address — used for security monitoring, fraud prevention, and aggregate geographic analysis. We do not link IP addresses to individual identities.
  • Browser type and version — helps us ensure the site renders correctly across common browsers.
  • Operating system and device type — used for responsive-design optimisation.
  • Referring URL — the page or search result you came from before landing on our site.
  • Pages visited and click paths — which sections of the site you viewed and in what order.
  • Session duration and bounce rate — aggregate engagement metrics that tell us which content is most useful.
  • Date and time of visits — logged for security and performance analysis.

This data is collected in pseudonymous or aggregated form wherever technically feasible. We rely on it to maintain website performance and to understand, in broad terms, how visitors discover and use our digital presence.

2.3 Data From Professional Networks and Referrals

We may receive limited personal data — typically a name, job title, and corporate email — when a colleague or partner refers you to us, or when you interact with our official profiles on business networks such as LinkedIn. In those cases, the data is treated identically to information submitted through our own forms and is used solely to follow up on the commercial or professional matter for which it was shared.

We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health information, biometric data, or financial account details through this website. If any such information is ever needed in the context of a formal engagement, it will be subject to a separate, specific data-processing agreement.

3. How We Use Your Information

We process personal data only for specific, explicit, and legitimate purposes. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you. The table below maps each processing activity to its purpose and legal basis under both the LGPD and GDPR.

Processing Activity Purpose Legal Basis (LGPD) Legal Basis (GDPR)
Responding to contact-form submissions Replying to enquiries about our services, providing quotes, scheduling meetings Art. 7, VI — Legitimate interest; Art. 7, V — Contract performance Art. 6(1)(b) — Steps prior to contract; Art. 6(1)(f) — Legitimate interest
Service delivery and project management Executing contracted software, IT, or consulting engagements Art. 7, V — Contract performance Art. 6(1)(b) — Contract performance
Website analytics Understanding aggregate usage patterns to improve content and performance Art. 7, IX — Legitimate interest Art. 6(1)(f) — Legitimate interest
Marketing communications Sending newsletters or case studies to contacts who have opted in Art. 7, I — Consent Art. 6(1)(a) — Consent
Legal compliance Meeting tax, accounting, labour, and regulatory obligations under Brazilian and applicable foreign law Art. 7, II — Legal obligation Art. 6(1)(c) — Legal obligation
Security and fraud prevention Detecting and mitigating abuse, attacks, or unauthorised access to our systems Art. 7, IX — Legitimate interest Art. 6(1)(f) — Legitimate interest

We will not repurpose your data for any activity incompatible with the original purpose for which it was collected. If we ever need to do so, we will inform you and, where required, seek your consent before processing begins.

4. Cookies & Tracking Technologies

Our website uses cookies and similar client-side storage mechanisms to enable core functionality, measure performance, and — where you have consented — to deliver relevant advertising. A cookie is a small text file placed on your device by your browser at a website's request. It does not give us access to your computer or any personal data beyond what you choose to share with us.

4.1 Types of Cookies We Use

Category Examples Purpose Consent Required?
Strictly Necessary Session cookies, CSRF tokens, load-balancer cookies Keep the site functioning securely; these cannot be turned off without breaking core features No — essential
Performance & Analytics Google Analytics 4 (_ga, _gid, _gat) Measure page views, session length, traffic sources, and error rates on an anonymised basis Yes
Functional Language preference, form-state cookies Remember your preferences so you do not have to re-enter them on return visits Yes
Advertising & Re-marketing Google Ads (_gcl_au), Google Tag Manager Measure ad conversions; support re-marketing campaigns on Google Display and Search networks Yes

4.2 Google Analytics and Advertising Services

We use Google Analytics 4 to understand how visitors interact with our site in aggregate. We have enabled IP anonymisation so that no full IP address is transmitted to Google's servers. The data collected by Google Analytics is subject to Google's Privacy Policy. We have also enabled Google Ads conversion tracking to measure enquiries and other meaningful actions that result from our advertising campaigns — this lets us spend our marketing budget responsibly and avoids showing ads to people who have already engaged with us.

Google may combine cookie data with data it holds from other sources and other sites if you are signed into a Google account. You can opt out of Google's use of cookies for advertising purposes at any time via Google's Ads Settings or by installing the Google Analytics Opt-out Browser Add-on.

4.3 Managing Your Cookie Preferences

When you first visit our site, a cookie-consent banner allows you to accept or decline non-essential cookies. You can update your preferences at any time by clicking the "Cookie Settings" link in our site footer. Additionally, most browsers provide controls to block or delete cookies at the browser level — please consult your browser's help documentation for instructions. Note that disabling certain categories of cookie may affect site functionality.

We do not use cookies to track users across third-party websites or to build personal advertising profiles without explicit consent.

5. Sharing With Third Parties

Engesoftware does not sell, rent, or trade personal data. We share data only in the circumstances described below, and only to the minimum extent necessary for each purpose.

5.1 Technology and Service Providers (Sub-processors)

To operate our website and run our business, we engage carefully vetted third-party service providers who process data on our behalf as data processors. Each is bound by a data-processing agreement that limits their use of personal data to the specific services they provide to us.

  • Google LLC — Analytics, Ads conversion tracking, Google Workspace (corporate email and documents). Google's services may involve data transfers to the United States; these are covered by Google's Binding Corporate Rules and Standard Contractual Clauses.
  • Hosting infrastructure provider — Our website is hosted on servers located in Brazil (or within the AWS São Paulo region), ensuring personal data collected through the site remains principally within Brazilian territory.
  • CRM platform — Contact enquiry data may be stored in a customer-relationship management system to allow our sales team to track follow-up activity. We use platforms that offer LGPD-compliant data-processing agreements.
  • Email delivery services — Transactional email (e.g., auto-replies to form submissions) is routed through a third-party SMTP provider operating under a sub-processing agreement.

5.2 Legal Obligations and Protection of Rights

We may disclose personal data to government authorities, courts, tax authorities (Receita Federal), or law-enforcement agencies when we are legally required to do so, or when disclosure is necessary to protect the rights, property, or safety of Engesoftware, our clients, or the public. In every such case we will, where permitted by law, notify the data subject before disclosure occurs.

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or a substantial part of Engesoftware's assets, personal data held by us may be transferred to the acquiring entity. We will notify affected individuals via the email address on file and give them a reasonable opportunity to request deletion of their data before any transfer is completed, subject to legitimate business and legal constraints.

5.4 What We Never Do

  • We do not sell personal data to data brokers, advertising networks, or any other commercial third party.
  • We do not share your information with competitors or unrelated businesses.
  • We do not provide data to third parties for their own independent marketing purposes without your explicit prior consent.

6. Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, to comply with legal obligations, and to resolve any disputes or enforce our agreements. The retention periods below are our standard defaults; specific contractual relationships may be governed by longer periods imposed by applicable law.

Data Category Retention Period Reason
Contact-form submissions (no contract signed) 24 months from last interaction Allows us to follow up and manage the sales relationship; deleted or anonymised thereafter unless you have asked to be kept on our mailing list.
Client contact data (active or recently concluded contract) 5 years after contract end Compliance with Brazilian civil law (statute of limitations) and Receita Federal record-keeping rules under Law 9,430/1996.
Invoice and financial records 10 years Mandatory retention under the Brazilian Código Tributário Nacional and bookkeeping regulations.
Google Analytics cookies Up to 14 months (per GA4 default) Statistical analysis of site usage; Engesoftware does not extend beyond GA4's default retention window.
Website server logs (raw IP logs) 90 days Security monitoring; deleted on a rolling basis unless a specific incident under investigation requires preservation.
Email communications 3 years from last message Operational records; subject to legal-hold extension where relevant to ongoing proceedings.

When a retention period expires, data is either securely deleted or, where deletion is technically impractical (e.g., backup tapes), anonymised such that no individual can be identified from it. Anonymised, aggregate statistical data derived from personal data is not subject to these retention limits.

7. Data Security

As a technology company whose core business includes cybersecurity and IT infrastructure, Engesoftware applies rigorous technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. Security is not an afterthought — it is embedded in how we build and operate all of our systems.

7.1 Technical Measures

  • Encryption in transit: All data exchanged between your browser and our website is protected by TLS 1.2 or TLS 1.3. We enforce HTTPS across the entire domain and use HSTS headers to prevent protocol downgrade attacks.
  • Encryption at rest: Databases and file storage containing personal data are encrypted at the storage layer using AES-256.
  • Access controls: Personal data is accessible only to Engesoftware employees who need it to do their jobs. Access is granted on a least-privilege basis and reviewed quarterly. All administrative access requires multi-factor authentication.
  • Firewalls and intrusion detection: Our infrastructure is protected by next-generation firewalls, web-application firewalls, and continuous intrusion-detection monitoring.
  • Vulnerability management: We conduct regular automated and manual security assessments, including penetration testing by qualified internal specialists, and apply security patches promptly.
  • Secure development practices: Our development teams follow secure-coding standards aligned with OWASP guidelines; code changes undergo peer review and automated static analysis before deployment.

7.2 Organisational Measures

  • All employees and contractors who handle personal data undergo LGPD and information-security awareness training at onboarding and at least annually thereafter.
  • We maintain a formal data-breach response procedure. In the event of a breach likely to cause risk or harm to data subjects, we will notify the Brazilian Data Protection Authority (ANPD) and the affected individuals within the legally prescribed timeframes.
  • Physical access to our offices and server infrastructure is controlled by electronic badge systems and monitored by CCTV.

Despite our best efforts, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. If you believe your personal data has been compromised as a result of any interaction with us, please contact us immediately at contato@engesoftware.site so we can investigate and take appropriate action.

8. Your Rights

Brazilian law (LGPD, Art. 18) grants every natural person a comprehensive set of rights over their personal data. Residents of the European Economic Area benefit from equivalent and, in some cases, additional rights under the GDPR. Engesoftware respects and upholds all of the following rights regardless of your nationality or place of residence.

Right of Access

You have the right to request confirmation of whether we hold personal data about you and, if so, to receive a copy of that data together with information about how it is being processed.

Right of Correction

If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to request that we correct or update it without undue delay.

Right of Erasure

You may ask us to delete personal data that is no longer necessary for the purpose it was collected, or where you have withdrawn consent and there is no other legal basis for processing. Note that legal retention obligations may prevent immediate deletion in some cases.

Right to Object

Where we process your data on the basis of legitimate interest, you have the right to object. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as CSV or JSON), and to transmit it to another controller, where technically feasible.

Right to Withdraw Consent

Where we process data on the basis of your consent (for example, marketing emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before it was withdrawn.

Right to Restriction of Processing

In certain circumstances (for example, while we verify a correction request), you may ask us to restrict processing of your data — meaning we hold it but do not actively use it until the matter is resolved.

Right to Lodge a Complaint

If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd, or, if you are in the EEA, with your local supervisory authority.

How to Exercise Your Rights

To exercise any of the rights above, please send a written request to contato@engesoftware.site with the subject line "Data Subject Rights Request". Please include your full name, the email address associated with your data, a description of the right you wish to exercise, and — if you are requesting access or erasure — sufficient information for us to verify your identity. We will not process a request we cannot authenticate, as doing so could risk your data being disclosed to, or deleted by, someone other than you.

We will acknowledge your request within 5 business days and fulfil it (or provide a reasoned response where fulfilment is not possible) within 15 business days — extendable by a further 15 business days in complex cases, with notification. There is no charge for exercising these rights.

9. Children's Privacy

Our website and services are designed for business professionals and are directed exclusively at adults aged 18 and over. We do not knowingly collect, process, or retain personal data from children under 18 years of age.

Our contact forms, mailing-list sign-ups, and proposal-request workflows do not include age-verification mechanisms because the nature of our services — enterprise software development, managed IT infrastructure, cybersecurity consulting — makes it highly implausible that a minor would be submitting a genuine commercial enquiry. Nonetheless, if you are a parent or guardian and believe that your child has inadvertently submitted personal data to us, please contact us immediately at contato@engesoftware.site. We will investigate promptly and, if confirmed, delete the data from our systems without undue delay.

We take our obligations under LGPD Article 14 (which affords heightened protection to children's data) seriously, and we are committed to ensuring our digital channels remain appropriate and compliant.

10. Changes to This Policy

The digital landscape and the regulatory environment governing data privacy are both continually evolving. We review this Privacy Policy at least annually and update it whenever our data-processing activities change materially, a significant new regulation comes into force, or guidance from the ANPD or GDPR supervisory authorities requires it.

When we make substantive changes — for example, adding a new category of data we collect, engaging a new third-party processor in a significant capacity, or altering how long we retain your information — we will provide prominent notice. For registered contacts or newsletter subscribers, this notice will be sent by email to the address we hold for you at least 30 days before the changes take effect. For general site visitors, we will post a clearly visible notice on the homepage and update the "Last updated" date shown at the top of this page.

We will also maintain an accessible version history of this policy so you can review past versions and understand precisely what changed and when. If, after receiving notice of a material change, you continue to use our website or interact with our services, that will be taken as acceptance of the updated terms. If you do not agree with a change, you have the right to request deletion of your data before the new terms take effect.

Minor updates — such as corrections to typos, clarification of existing language without any change to processing activities, or updating a reference to a third-party service's privacy documentation — will not be separately notified but will be reflected in the revised "Last updated" date.

11. Contact Us

If you have any question, concern, or complaint regarding this Privacy Policy or the way Engesoftware processes your personal data, please do not hesitate to reach out. We have an internal point-of-contact responsible for data-protection compliance who will handle your enquiry confidentially and promptly.

When contacting us about a privacy matter, please include as much context as possible — the specific concern, your relationship with us (e.g., website visitor, current client, former client), and the data involved. This allows us to investigate efficiently and give you a useful, substantive response rather than a generic acknowledgement.

ENGESOFTWARE TECNOLOGIA S/A

CNPJ: 00.681.946/0001-60  ·  Data Controller

Setor Scia Quadra 13, Conjunto 04, Lotes 01 e 02,
Guará, Brasília – DF, Brazil
Privacy & data-protection enquiries: contato@engesoftware.site
Website: engesoftware.site
We commit to acknowledging all privacy-related correspondence within 5 business days and resolving it within 15 business days (extendable where complexity warrants it, with notification).
For complaints that cannot be resolved directly with us: You may file a complaint with Brazil's national data-protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), through the official government portal at www.gov.br/anpd. If you are located in an EU/EEA member state, you may alternatively contact your local supervisory authority.