Privacy Policy

DEVIO SOFTWARES INTELIGENTES LTDA is committed to protecting your personal data with transparency and care. This policy explains exactly what we collect, why we collect it, how we protect it, and the rights you hold under applicable privacy law — including Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) and the European General Data Protection Regulation (GDPR, Regulation 2016/679).

Last updated: 14 July 2025

01

Introduction

DEVIO SOFTWARES INTELIGENTES LTDA ("Devio," "we," "our," or "us") is a Brazilian technology company registered under CNPJ 32.973.740/0001-09, headquartered at Avenida Pref. Osmar Cunha, 416, Sala 1108, Centro, Florianópolis – SC, Brazil. We develop bespoke software solutions, artificial-intelligence products, and digital infrastructure for businesses across multiple industries.

This Privacy Policy applies to all personal data processed through our website at devio-us.site (the "Site"), our contact forms, email communications, and any other digital touchpoint we operate. It governs how we handle data relating to visitors, prospective clients, current clients, and anyone else who interacts with our online presence.

By using the Site or submitting information to us, you acknowledge that you have read and understood this policy. If you disagree with any part of it, please refrain from using the Site or providing us with your personal information. We encourage you to revisit this page periodically, as we update it whenever our practices change or applicable law requires.

Governing law. Devio's primary legal framework for data protection is Brazil's LGPD (Lei n.º 13.709/2018). Where we process data belonging to residents of the European Economic Area (EEA) or the United Kingdom, we apply the corresponding requirements of the GDPR and UK GDPR respectively. In either case, the stricter rule prevails.

02

Information We Collect

We collect personal information only when there is a clear and legitimate reason to do so. The categories below cover everything we may gather during normal operation of the Site.

Information you give us directly

  • Contact-form submissions: When you fill in our contact or project-inquiry form you provide your name, email address, phone number (optional), company name (optional), and a free-text description of your project or question. We also record the date and time of submission and the referral source (e.g., a Google Ads campaign) for our own records.
  • Email correspondence: If you email us directly at contato@devio-us.site, we receive and store the content of that message, any attachments, and the metadata attached to the email (sender address, timestamp, subject line).
  • Commercial conversations: During discovery calls, video meetings, or proposal exchanges we may take notes containing professional details you share, such as your role, organisation, budget range, and project timeline. These notes are treated as personal data where they relate to an identifiable individual.

Information collected automatically

  • Log data: Our web servers automatically record your IP address, browser type and version, operating system, referring URL, pages viewed, time spent on each page, and the date and time of each request. These logs are retained for security and operational purposes.
  • Analytics data: We use Google Analytics 4 (with IP anonymisation enabled) to understand how visitors navigate the Site. This generates aggregated behavioural data — session counts, device categories, geographic region (country/region level), and event data such as button clicks and form interactions.
  • Advertising signals: If you arrive via a Google Ads campaign, Google's conversion-tracking pixels may record that you visited the Site after clicking an ad. This allows us to measure campaign effectiveness. See Section 4 (Cookies & Tracking) for full details.
  • Cookie data: Cookies and similar technologies store small identifiers on your device. Their precise purpose is described in Section 4.

Information we do not collect

We do not collect payment card numbers, government-issued ID numbers, health data, or any other sensitive special-category data through the Site. We have no user-account system, so we do not store passwords.

03

How We Use Your Information

Every use of your personal data is grounded in at least one lawful basis under the LGPD and GDPR. The table below maps our purposes to the applicable legal basis.

  • Responding to enquiries and proposals (Legitimate Interest / Contract): When you contact us through the form or by email, we use your name and contact details to reply, schedule calls, send proposals, and — if you become a client — to execute the contract for software services. Without this processing, we simply cannot engage with you.
  • Understanding how our Site performs (Legitimate Interest / Consent): We analyse aggregated analytics data to identify pages that underperform, optimise load times, and improve the overall user experience. Where analytics cookies require consent under applicable law, we ask for it before placing them.
  • Running and measuring advertising campaigns (Legitimate Interest / Consent): We use Google Ads conversion data to evaluate which campaigns generate genuine business enquiries and allocate our marketing budget responsibly. Retargeting (showing Devio ads to past visitors on other sites) is activated only with your prior consent via our cookie-consent mechanism.
  • Keeping the Site secure (Legal Obligation / Legitimate Interest): Server logs and IP address records help us detect and respond to intrusion attempts, DDoS attacks, and abusive scraping activity.
  • Complying with legal obligations (Legal Obligation): We may process or retain data to satisfy tax reporting requirements, to respond to a valid court order, or to cooperate with a regulatory authority acting within its jurisdiction.
  • Occasional follow-up communications (Consent / Legitimate Interest): If you contact us about a project and we have not yet engaged, we may send a brief follow-up message to check whether you still need help. We do not add you to marketing lists or newsletters without explicit consent.

We never sell your personal data, use it for purposes unrelated to the operation of Devio, or subject it to solely automated decision-making that produces legal or similarly significant effects.

04

Cookies & Tracking Technologies

Cookies are small text files placed on your device by a website. We also use closely related technologies — pixel tags and JavaScript snippets — to collect and transmit similar information. Here is a plain-language breakdown of every category we use:

Strictly necessary cookies

These are essential for the Site to function. They manage your session, remember cookie-consent choices, and protect against cross-site request forgery (CSRF). They are placed without requiring your consent because the Site cannot operate correctly without them. They are deleted when you close your browser or within 24 hours, whichever comes first.

Analytics cookies (require consent)

Google Analytics 4 places cookies (principally _ga and _ga_<ID>) that persist for up to two years. They assign an anonymous identifier to your browser session so we can count unique visitors, measure engagement, and understand which content resonates. IP anonymisation is enabled so that the last octet of your IP address is masked before any data reaches Google's servers. You can opt out of Google Analytics tracking across all sites using Google's official opt-out browser add-on at tools.google.com/dlpage/gaoptout.

Advertising & conversion cookies (require consent)

Google Ads places a conversion-tracking cookie (_gcl_aw) when you arrive from one of our ad campaigns. This cookie (30-day lifespan) tells us whether a visitor who clicked an ad later submitted a contact form, without identifying you personally. If you consent to personalisation cookies, Google may also serve you Devio ads on third-party websites through the Google Display Network — a feature called remarketing. You can manage your Google ad personalisation settings at adssettings.google.com.

Managing your cookie preferences

When you first visit the Site, a consent banner lets you accept or decline each category of non-essential cookie individually. You can revoke or update your choices at any time by clicking the "Cookie Preferences" link in the Site footer. Most browsers also allow you to block or delete cookies directly through their settings — consult your browser's help documentation for instructions specific to your browser and operating system. Blocking certain cookies may degrade your experience of the Site.

05

Sharing With Third Parties

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We share data with external parties only in the following circumstances, and only to the extent strictly necessary:

  • Technology service providers: Our website is hosted on infrastructure whose providers may process server-log data on our behalf. We use email delivery services to route contact-form notifications to our team. These providers act as data processors bound by data-processing agreements and are not permitted to use your data for their own purposes.
  • Google LLC: As described in Section 4, Google Analytics and Google Ads receive anonymised analytics and conversion-signal data. Google operates as both a data processor (Analytics) and, in the context of ad measurement, an independent data controller (Ads). Google is certified under the EU–US Data Privacy Framework, providing an adequate basis for international data transfers from the EEA.
  • Professional advisers: Our lawyers, accountants, and auditors may occasionally access personal data in the course of providing professional services. They are bound by confidentiality obligations.
  • Legal authorities: We will disclose personal data to courts, law-enforcement agencies, or regulatory bodies when required by law or a binding legal process, or when we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Devio, our clients, or the public.
  • Business transfers: If Devio undergoes a merger, acquisition, or sale of substantially all its assets, personal data may be transferred to the successor entity. We will notify affected individuals before their data becomes subject to a materially different privacy policy.

When we transfer personal data across international borders we ensure adequate safeguards are in place — such as standard contractual clauses approved by the European Commission, binding corporate rules, or adequacy decisions — in accordance with GDPR Chapter V and LGPD Article 33.

06

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to maintain accurate business records, or to satisfy legal, accounting, or regulatory requirements. Our specific retention periods are as follows:

  • Contact-form and email enquiries (no contract formed): Records are kept for 12 months from the date of last meaningful communication. If you do not reply to our follow-up within 90 days of first contact, we remove your data from our active CRM and archive it for the remaining period before permanent deletion.
  • Client project records (contract formed): Data related to a completed engagement — contracts, deliverables, project correspondence — is retained for five years after project closure to meet Brazilian tax and commercial law requirements (Código Civil Art. 206, §3.º, V; Lei nº 6.404/76).
  • Server access logs: Retained for 90 days for security and incident-response purposes, then automatically deleted.
  • Google Analytics data: Retention is set to 14 months within Google Analytics, after which it is automatically purged from Google's systems. You can request earlier deletion via the process described in Section 8.
  • Advertising conversion records: Aggregated campaign metrics (clicks, conversions) are kept indefinitely for business-planning purposes, but these are not linked to identifiable individuals.

When a retention period expires, data is permanently and securely deleted or rendered definitively anonymous in accordance with the procedures described in Section 7.

07

Data Security

Protecting the personal data you entrust to us is a core operational priority, not an afterthought. We implement a layered set of technical and organisational measures proportionate to the nature of the data and the risks involved:

  • Encryption in transit: All data exchanged between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HSTS (HTTP Strict Transport Security) so that browsers always use the secure protocol.
  • Encryption at rest: Personal data stored in our databases and backup systems is encrypted using AES-256 or equivalent industry-standard algorithms.
  • Access control: Internal access to systems containing personal data is restricted on a strict need-to-know basis. All team members use unique credentials, multi-factor authentication is mandatory, and access privileges are reviewed quarterly.
  • Secure deletion: When data reaches the end of its retention period, electronic records are overwritten or cryptographically erased in a manner that prevents recovery.
  • Vendor due diligence: Before engaging any third-party service provider that handles personal data, we review their security practices and require appropriate contractual data-protection commitments.
  • Incident response: We maintain a documented procedure for identifying, containing, and reporting data breaches. In the event of a breach that triggers a statutory notification obligation, we will notify the relevant supervisory authority within the legally required timeframe and contact affected individuals without undue delay.

No system is infallible. While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to acting swiftly and transparently in the event of any incident affecting your data.

08

Your Rights

Under the LGPD and GDPR you hold a meaningful set of rights regarding personal data we hold about you. We honour all of these rights without exception. Below is a plain-language description of each one:

Right of Access

You may ask us to confirm whether we hold personal data about you, and if so to provide a copy of that data along with information about how it is being used.

Right to Correction

If any personal data we hold is inaccurate or incomplete, you have the right to have it corrected or updated without undue delay.

Right to Deletion

You may request that we erase your personal data where it is no longer necessary for the purpose it was collected, where consent has been withdrawn, or where processing was unlawful.

Right to Portability

Where we process your data by automated means on the basis of consent or a contract, you can request that we provide it to you — or transmit it directly to another controller — in a structured, machine-readable format.

Right to Object

You may object at any time to processing based on our legitimate interests. We will stop unless we can demonstrate compelling grounds that override your interests, or the processing is necessary for legal claims.

Right to Restrict

In certain circumstances — such as while you contest the accuracy of data, or while we assess an objection — you may ask us to suspend active use of your data without deleting it.

Right to Withdraw Consent

Where we process your data on the basis of consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to Complain

You have the right to lodge a complaint with a supervisory authority: in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); within the EEA, the data-protection authority of your member state.

How to exercise your rights. Send a written request to contato@devio-us.site with the subject line "Data Rights Request." Please include your full name and the email address associated with any communications you have had with us, so we can locate your records efficiently. We will acknowledge your request within five business days and provide a substantive response within 30 days (extendable by a further 60 days for complex requests, with notice). We do not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we may decline it or charge a proportionate administrative fee, and we will explain our reasoning.

09

Children's Privacy

The Site and our services are directed exclusively to business professionals and organisations. We do not knowingly collect personal data from children under the age of 18. Our contact forms, project-inquiry workflows, and all commercial interactions are intended for adults acting on behalf of themselves or their companies.

If you are a parent or guardian and believe that a minor has submitted personal information to us without your knowledge, please contact us immediately at contato@devio-us.site. We will investigate and, if confirmed, delete the relevant data as quickly as operationally possible.

10

Changes to This Policy

Privacy law evolves, and so does the way we operate. We may update this Privacy Policy from time to time to reflect changes in our data-processing activities, new legal requirements, or guidance from supervisory authorities. All changes take effect as soon as the revised policy is published on this page.

The "Last updated" date at the top of this page will always reflect the most recent revision. For material changes — those that significantly affect your rights or the scope of our data collection — we will make reasonable efforts to bring the revision to your attention, such as by placing a prominent notice on the Site's homepage or, if we hold your email address, by sending a direct notification.

Your continued use of the Site after a policy update constitutes acceptance of the revised terms. If you do not agree with a change, you should discontinue use of the Site and, if desired, contact us to exercise your deletion rights.

11

Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way Devio handles your personal data, please reach out. We take every inquiry seriously and will respond promptly and in plain language.

Under the LGPD, Devio is the data controller responsible for the personal data described in this policy. We have not formally designated a separate Data Protection Officer (DPO), as Brazilian law does not currently mandate one for companies of our size; however, data-protection matters are handled directly by our leadership team, who are familiar with the applicable obligations and can be reached through the contact details below.

Data Controller — Contact Details

Company
DEVIO SOFTWARES INTELIGENTES LTDA
CNPJ
32.973.740/0001-09
Address
Avenida Pref. Osmar Cunha, 416, Sala 1108
Centro, Florianópolis – SC, Brazil
Privacy email
contato@devio-us.site
Subject line: Privacy Policy Inquiry or Data Rights Request
Response time
We aim to acknowledge all privacy-related messages within 5 business days and resolve them fully within 30 days.

You also have the right to contact Brazil's national data-protection authority directly. The Autoridade Nacional de Proteção de Dados (ANPD) can be reached via its official portal at www.gov.br/anpd. If you are located in the EEA, you may contact the supervisory authority in your country of residence or place of work.