1 Introduction
This Privacy Policy applies to all personal data processed by FWC TECNOLOGIA LTDA (hereafter "FWC Tecnologia", "we", "our" or "us"), a technology company incorporated in Brazil under CNPJ 39.530.764/0001-24, with registered address at Avenida das Palmeiras, 144, Casa 98 Quadra D, Jardim Imperial, Cuiabá – MT, Brazil.
We develop custom software, automation systems, management platforms, and technology infrastructure for businesses across Brazil and internationally. In the course of delivering these services — and operating our website at fwctecnologia.site — we inevitably handle certain personal data belonging to visitors, prospective clients, current clients, and business contacts.
Our data-handling practices are governed primarily by Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) and, where applicable to individuals in the European Economic Area, the EU General Data Protection Regulation (GDPR, Regulation 2016/679). We are committed to meeting the standards set by both frameworks.
Scope: This policy covers personal data collected through our website, contact and quotation forms, email correspondence, client onboarding processes, and any analytics or advertising technologies we deploy. It does not cover the data-processing activities FWC Tecnologia carries out on behalf of its clients under separate service agreements — in those contexts, clients act as data controllers and we act as a data processor, operating under written data-processing agreements.
By using our website or submitting any form, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please refrain from using our website and contact us directly at contato@fwctecnologia.site to discuss alternative arrangements.
2 Information We Collect
We only collect personal data that is genuinely necessary for the purposes described in this policy. The categories below cover everything we may hold about you.
2.1 — Data you provide directly
When you complete a contact form, request a project quote, or email us, you may submit some or all of the following:
- Full name — so we know who we are speaking to and can address you properly.
- Business email address — our primary channel for responding to enquiries and sending project-related communications.
- Phone number — if you opt to provide it for scheduling calls or WhatsApp conversations.
- Company name, industry, and approximate size — to help us scope the right technology solution for your context.
- Description of your project or requirement — the free-text message you write in the form.
- Any attachments you choose to send — for example, specification documents or screenshots.
Providing this information is entirely voluntary. However, without a valid email address we cannot respond to your enquiry.
2.2 — Data collected automatically when you visit our website
Our web infrastructure and analytics tools collect certain technical data automatically when your browser connects to our site:
- IP address — retained in truncated form for security and geographic analytics; we do not use full IP addresses to identify individuals.
- Browser type and version, operating system, device category — for compatibility and performance monitoring.
- Referring URL — the web address you came from, so we understand which channels bring visitors to us.
- Pages visited, time on page, and click paths — aggregated to measure which content is most useful.
- Session timestamps — to understand traffic patterns and server load.
This technical data is collected via cookies and similar technologies described in detail in Section 4.
2.3 — Data from advertising platforms
If you click through to our site from a Google Ads campaign, Google may pass us aggregated, pseudonymous conversion and audience data (e.g., that a click from a particular campaign led to a form submission). We never receive your name or personal email directly from Google through ad-click tracking; the data is statistical and tied to cookie identifiers rather than identified persons.
2.4 — Data we do not collect
We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health information, biometric data, or financial account numbers. Our contact forms do not request — and we ask that you do not volunteer — any such information.
3 How We Use Your Information
Every use of your personal data is tied to a specific, documented purpose and a corresponding legal basis under both the LGPD and GDPR. We do not use your data for purposes beyond those listed here without obtaining your prior consent or notifying you of the change.
-
Responding to enquiries and providing quotations — When you contact us, we use your name, email, and project description to assess your needs and send a relevant, detailed response. Legal basis (LGPD): legitimate interest / execution of pre-contractual steps; (GDPR): Article 6(1)(b) — steps prior to entering a contract.
-
Service delivery and project management — Once engaged, we use your contact details and project information to manage deliverables, communicate updates, issue invoices, and provide technical support. Legal basis: contract performance (LGPD Art. 7 II; GDPR Art. 6(1)(b)).
-
Sending relevant follow-up communications — With your permission, we may contact you about related services, technology updates, or case studies we think would genuinely interest you. You can opt out of these communications at any time by emailing us or clicking the unsubscribe link in any such message. Legal basis: consent (LGPD Art. 7 I; GDPR Art. 6(1)(a)).
-
Website analytics and performance improvement — Aggregated usage data helps us identify slow pages, broken flows, and content gaps. No individual-level profiling takes place for this purpose. Legal basis: legitimate interest.
-
Measuring advertising effectiveness — We use conversion data from Google Ads to understand which campaigns result in genuine business enquiries, so we allocate our marketing budget responsibly. This analysis is conducted on pseudonymous data and does not result in any decisions that affect you personally. Legal basis: legitimate interest.
-
Legal, fiscal, and regulatory compliance — We retain invoices, contracts, and related correspondence to comply with Brazilian tax law (including obligations under the Receita Federal) and applicable commercial law. Legal basis: legal obligation (LGPD Art. 7 II; GDPR Art. 6(1)(c)).
-
Security and fraud prevention — Server logs and IP data are monitored to detect and respond to malicious activity, spam submissions, and attempted breaches. Legal basis: legitimate interest.
We never sell your personal data to third parties. We never use your data to make solely automated decisions that produce legal or similarly significant effects about you.
4 Cookies & Tracking Technologies
Cookies are small text files placed on your device by a website. They allow the site to remember certain information across page loads and sessions. We use cookies in a controlled, purposeful way — not to build intrusive behavioural profiles, but to keep our website functional and understand how it is used in aggregate.
Strictly necessary cookies
These are essential for the website to operate. They handle session state, form security tokens (CSRF protection), and load-balancing. They do not track you across other websites and cannot be disabled without breaking site functionality. No consent is required for these cookies under either the LGPD or GDPR.
Analytics cookies (Google Analytics 4)
We use Google Analytics 4 (GA4) to understand visitor behaviour at an aggregate level. GA4 sets cookies that assign each browser a pseudonymous identifier (the _ga cookie, which persists for 13 months by default) and tracks page views, session duration, scroll depth, and events such as form submissions. We have enabled IP anonymisation, which means the final octet of your IP address is removed before any data is stored by Google. This data is held by Google LLC on servers that may be located outside Brazil or the EEA; Google acts as a data processor under its Google Measurement Controller-Controller Data Protection Terms. You may opt out of GA4 tracking by installing the Google Analytics Opt-out Browser Add-on.
Advertising cookies (Google Ads)
If you arrive at our site via a Google Ads campaign, Google places a conversion tracking cookie to record whether you subsequently completed an action such as a form submission. This allows us to report to Google that an ad led to an enquiry, so we can measure campaign performance. The data Google receives is pseudonymous. You can manage your Google ad personalisation preferences at adssettings.google.com.
Your cookie choices: On your first visit to our site, a cookie notice gives you the ability to accept or decline non-essential cookies. You can change your preferences at any time by clearing your browser cookies and revisiting the site, or by adjusting your browser settings to block cookies. Note that disabling all cookies may affect the usability of our contact forms.
No third-party social tracking
We do not embed Facebook Pixel, LinkedIn Insight Tag, TikTok Pixel, or any other social-network tracking scripts on our website.
5 Sharing With Third Parties
We do not sell, rent, or otherwise commercially transfer your personal data to any third party. We share data only in the limited circumstances described below, and only to the extent strictly necessary.
-
Technology sub-processors: Our website is hosted on cloud infrastructure (currently using Brazilian or international data-centre services that comply with applicable security standards). Our email correspondence passes through professional business email infrastructure. Form submissions may transit through our contact-management tools. All such sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security measures.
-
Google LLC: As described in Section 4, Google receives pseudonymous analytics and advertising conversion data. Google's processing is governed by its own privacy policy and its data-processor terms with us.
-
Professional advisers: Accountants, legal counsel, and auditors may need access to business records (including invoices that contain your company name and contact details) in order to provide their services to us. They are bound by professional confidentiality obligations.
-
Legal and regulatory authorities: We will disclose personal data to a competent authority (such as the Receita Federal, ANPD, or a court) where we are required to do so by Brazilian or international law, or where such disclosure is necessary to defend our legal rights.
-
Business transfers: If FWC Tecnologia were ever to be acquired, merged, or subject to a restructuring, personal data might be transferred to the successor entity. We would notify affected individuals before any such transfer takes effect, unless prohibited by applicable law.
Where data is transferred outside Brazil to a country not recognised by the ANPD (Brazil's data-protection authority) as providing an adequate level of protection, we implement appropriate safeguards — such as standard contractual clauses or processor agreements that incorporate LGPD and GDPR-equivalent protections — before any transfer takes place.
6 Data Retention
We keep personal data only for as long as it serves the purpose for which it was collected, or as long as required by applicable law. The following retention periods reflect our current practice:
-
Enquiries that did not lead to a contract: We retain the contents of contact-form submissions and related correspondence for up to 24 months from the last interaction. This allows us to understand historical context if you reach out again. After this period, the data is securely deleted or anonymised.
-
Client contracts and project records: Once a service engagement begins, we retain the full project record — including correspondence, specifications, deliverables, and invoices — for a minimum of 5 years after project closure, in line with Brazilian tax and commercial law requirements (Código Civil, Art. 1.194; Lei 9.430/1996).
-
Tax and fiscal documents: Invoices and related fiscal records are retained for 5 years (or longer if required by specific tax obligations), as mandated by Brazilian federal revenue authority guidelines.
-
Google Analytics data: We have configured GA4 to retain user-level and event-level data for 14 months, after which Google automatically deletes it from our account.
-
Marketing communications lists: If you have consented to receive marketing messages, we retain your contact details on our list until you withdraw consent. Upon withdrawal, we remove your details within 10 business days and add your address to a suppression list to prevent accidental future contact.
-
Security and server logs: Raw server logs containing IP address data are rotated and deleted after 90 days.
When the applicable retention period expires, data is either permanently deleted from all systems (including backups) or irreversibly anonymised so that it can no longer be linked to you.
7 Data Security
Protecting the integrity and confidentiality of personal data is both a legal obligation and a professional imperative for a technology company like ours. We apply the following measures across all systems that process personal data:
- Encryption in transit: All data exchanged between your browser and our website is encrypted using TLS 1.2 or higher (HTTPS). We enforce HSTS headers to prevent protocol downgrade attacks.
- Access controls: Access to systems that hold personal data is restricted to team members who need it to perform their role. We use role-based access controls, strong unique passwords, and multi-factor authentication on all administrative accounts.
- Data minimisation: We configure our tools — including analytics platforms — to collect the minimum data necessary, using features such as IP anonymisation and data-retention limits.
- Secure email practices: Sensitive project information exchanged by email is handled with care; we advise clients to avoid including confidential personal data in unencrypted email messages and offer encrypted alternatives on request.
- Regular security reviews: As a software development company, our team conducts periodic reviews of our own web infrastructure for vulnerabilities, applying security patches promptly.
- Incident response: We maintain an internal procedure for responding to suspected data breaches. In the event of a breach that poses a risk to your rights and freedoms, we will notify the ANPD within 72 hours of becoming aware of it and, where required, contact affected individuals without undue delay.
Important note: No system connected to the public internet can be guaranteed to be 100% secure. While we work diligently to protect your data, you acknowledge that transmission of information over the internet carries inherent risks. If you suspect any misuse of your data connected to FWC Tecnologia, please contact us immediately at
contato@fwctecnologia.site.
8 Your Rights
Depending on your country of residence, you have specific legal rights over your personal data. Brazilian residents are protected under the LGPD (Articles 17–22); residents of the European Economic Area are protected under the GDPR (Articles 15–22). In practice, we apply these rights broadly to all individuals regardless of location.
🔍
Right of Access
You can request a copy of the personal data we hold about you, along with information about how and why we are using it.
✏️
Right of Correction
If any data we hold about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.
🗑️
Right of Deletion (Erasure)
You may request that we delete your personal data where it is no longer necessary, consent has been withdrawn, or processing is unlawful — subject to our legal retention obligations.
🚫
Right to Object
You can object to processing based on our legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.
⏸️
Right to Restrict Processing
In certain circumstances you may ask us to suspend the use of your data (e.g., while you contest its accuracy) without requiring full deletion.
📦
Right to Data Portability
Where processing is based on your consent or a contract, you may request your data in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
↩️
Right to Withdraw Consent
Where we rely on your consent as a legal basis (e.g., marketing emails), you can withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
⚖️
Right to Lodge a Complaint
Brazilian residents may complain to the ANPD (Autoridade Nacional de Proteção de Dados). EEA residents may approach their national data-protection supervisory authority.
How to exercise your rights: Send a written request to contato@fwctecnologia.site with the subject line "Data Subject Request". Please identify yourself clearly and specify which right(s) you wish to exercise. We will respond within 15 calendar days of receipt (or within the statutory period if local law requires a shorter timeframe). We will not charge a fee for reasonable requests; if a request is manifestly unfounded or excessive, we may decline or charge a proportionate administrative fee, and we will explain our reasoning in writing.
We may need to verify your identity before fulfilling a request to protect your data from unauthorised access. We will ask for the minimum information necessary for this purpose.
9 Children's Privacy
FWC Tecnologia provides business-to-business technology services. Our website and services are directed exclusively at adults — specifically at business owners, managers, and technology decision-makers acting in a professional capacity. We do not knowingly collect personal data from children under the age of 18.
If you are under 18, please do not submit any personal data through our website or contact forms. If we become aware that we have inadvertently collected personal data from a minor, we will delete it from all systems as promptly as possible. If you believe a minor has submitted data to us, please contact us at contato@fwctecnologia.site and we will take immediate action.
10 Changes to This Policy
We review this Privacy Policy periodically — at minimum once per year — and whenever there are meaningful changes to our data-processing activities, applicable law, or the third-party tools we use. When we make material changes, we will update the "Last updated" date at the top of this page and, if the changes significantly affect your rights or the way we handle your data, we will take additional steps to notify you — for example, by sending an email to active clients or displaying a prominent notice on our website for at least 30 days.
We encourage you to revisit this page from time to time. The version published at fwctecnologia.site/privacy-policy is always the current and effective version. Continued use of our website after a policy update constitutes acceptance of the revised terms, to the extent permitted by applicable law.
Previous versions of this policy are available on request. If you would like to see an archived version, email us and we will provide a copy within 5 business days.
11 Contact & Data Controller Details
If you have questions, concerns, or requests relating to this Privacy Policy or the way FWC Tecnologia handles your personal data, please reach out to us. We are committed to addressing all enquiries promptly and transparently.
Under the LGPD, the Data Controller responsible for decisions about how your personal data is processed is FWC TECNOLOGIA LTDA. Our designated privacy contact — who acts in the capacity of Data Protection Officer (DPO) for the purposes of the LGPD — can be reached using the details below.