Introduction
ATOS IA & PERFORMANCE LTDA ("ATOS", "we", "our" or "us") is a technology and performance consulting company registered under CNPJ 67.849.238/0001-67, with principal offices at Alameda Araguaia, 2190, Alphaville Industrial, Barueri, State of São Paulo, Brazil. We operate the website at getatosusa.com and any associated sub-domains (collectively, "the Site").
This Privacy Policy describes how we collect, use, store, share and protect personal data in connection with your use of the Site and our business services. It applies to all visitors, prospective clients, business partners and any other individual whose data we handle as a data controller.
Our practices are designed to comply with Brazil's Lei Geral de Proteção de Dados (LGPD — Federal Law 13.709/2018), the European Union General Data Protection Regulation (GDPR — Regulation 2016/679), and any other applicable data protection legislation in the jurisdictions in which we operate. Where the LGPD and GDPR impose similar obligations, we apply the higher standard.
By using the Site, you acknowledge that you have read and understood this policy. If you have any questions before proceeding, please contact us at the details provided in Section 11 before using the Site further.
Information We Collect
We collect personal data through several distinct channels. The categories below describe the data we receive, the circumstances in which we receive it, and the legal basis applicable under the LGPD and GDPR.
2.1 — Data You Provide Directly
When you reach out to us by email, telephone or any other direct channel displayed on the Site, you voluntarily share information. This typically includes:
-
Identity data Your full name and, where relevant, job title and the company you represent.
-
Contact data Business or personal email address and telephone number, as provided in your message to us.
-
Message content The substance of any inquiry, proposal description, or other communication you send, which may include information about your business needs, project scope or budget.
-
Commercial data If discussions progress toward an engagement, we may collect additional data such as billing addresses, contract counterparty details and CNPJ/VAT numbers in accordance with our contractual obligations.
The legal bases for processing this data are: the execution of or preparation for a contract (LGPD Art. 7, VI; GDPR Art. 6(1)(b)); our legitimate interest in responding to and maintaining records of commercial inquiries (LGPD Art. 7, IX; GDPR Art. 6(1)(f)); and, where applicable, compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
2.2 — Data Collected Automatically When You Browse the Site
Like virtually every website on the internet, our Site automatically collects certain technical data when your browser connects to our servers. This is necessary for the site to function and for us to understand how it is used. Such data includes:
-
Device & browser data IP address (which may be truncated or anonymised where applicable law requires), browser type and version, operating system, device type and screen resolution.
-
Usage & navigation data Pages visited, time spent on each page, scroll depth, links clicked, referring URL (the page that brought you here) and exit page.
-
Session data Date and time of access, session duration, and unique session identifiers assigned by our analytics tools.
-
Approximate geolocation Derived from your IP address — typically accurate to city or metropolitan area level. We do not collect GPS or precise device location.
This data is collected via first-party server logs and third-party analytics services (Google Analytics 4 and, where active, Google Ads conversion tracking). The legal basis is our legitimate interest in maintaining a functioning, secure website and understanding aggregate user behaviour to improve our content (LGPD Art. 7, IX; GDPR Art. 6(1)(f)), supplemented by your consent for non-essential cookies where required.
2.3 — Data Received From Third-Party Sources
We may receive limited professional data about prospective business contacts from publicly available sources such as LinkedIn, business registries, or industry directories — for example, if a colleague or partner introduces us to your company. Any such data is handled under the same standards described in this policy. We do not purchase personal data from data brokers or list vendors.
How We Use Your Information
We process personal data only for clearly defined, legitimate purposes. We do not sell, rent or monetise your personal data in any form. The table below summarises our processing activities and the purpose behind each:
-
Responding to inquiries and managing pre-contractual relationships When you contact us, we use your name, email and message content to evaluate your inquiry, reply appropriately, and — if discussions advance — prepare proposals, agreements and service scopes.
-
Delivering contracted services Once an engagement begins, we process relevant business data to plan, execute and report on the AI, analytics and performance work we carry out on your behalf.
-
Site performance and improvement Aggregated, largely anonymised analytics data helps us understand which content is most useful, identify technical issues, and optimise page load speeds and navigation.
-
Advertising effectiveness measurement Where we run Google Ads campaigns to promote our services, conversion tracking cookies help us measure which campaigns led to meaningful site interactions. This data is used solely for campaign optimisation and is not used to profile individual visitors.
-
Security and fraud prevention Server log data is retained for a limited period to detect and investigate unauthorised access attempts, bot traffic or other security threats.
-
Legal and regulatory compliance We may retain and process personal data to the extent required by tax law, corporate governance obligations, court orders or regulatory directions applicable to our business in Brazil and other jurisdictions where we operate.
Cookies & Tracking Technologies
Cookies are small text files placed on your device by websites you visit. They serve a variety of functions — from keeping a site working correctly, to helping owners understand aggregate usage patterns. We use four categories of cookies on this Site:
Managing and withdrawing consent
When you first visit the Site, a cookie consent banner will appear giving you the choice to accept or decline non-essential cookies. You may change your preference at any time by clicking the "Cookie Preferences" link in the site footer. Your choice is stored for 12 months, after which we will ask again.
You can also control cookies directly through your browser settings. Most browsers allow you to view, block or delete cookies. Please note that blocking all cookies may affect the functioning of some parts of the Site. Useful guidance on managing browser cookies is available at www.allaboutcookies.org.
Google Analytics and data minimisation
We have configured Google Analytics 4 with IP anonymisation enabled, data-retention periods set to the minimum available (14 months for user-level data), and advertising features turned off unless you have consented to advertising cookies. We do not enable User ID tracking or cross-device linking for website visitors.
Third-party pixels and embeds
If the Site includes embedded content such as YouTube videos or LinkedIn widgets, those providers may set their own cookies when you interact with that content. Their data practices are governed by their own privacy policies, not this one. We recommend reviewing the privacy policies of Google (youtube.com/privacy) and LinkedIn (linkedin.com/legal/privacy-policy) for further detail.
Sharing With Third Parties
We do not sell, rent, trade or otherwise transfer your personal data to outside parties for their own marketing or commercial purposes. We share data only in the following specific, controlled circumstances:
-
Service providers (data processors) We engage trusted technology and infrastructure suppliers who process data strictly on our behalf and under our documented instructions. These include our web hosting provider, email delivery infrastructure, analytics platforms (Google LLC, operating under Google's Data Processing Addendum and Standard Contractual Clauses where applicable), and project management tools. All processors are contractually bound to appropriate data protection terms.
-
Professional advisors Our legal counsel, accountants and auditors may access personal data to the limited extent necessary to provide their professional services, subject to strict confidentiality obligations.
-
Legal obligations and authority requests We may disclose personal data if required to do so by applicable law, court order, or the legitimate request of a governmental or regulatory authority (e.g. the Brazilian Autoridade Nacional de Proteção de Dados — ANPD — or tax authorities). We will, where legally permitted, notify affected individuals before complying with such requests.
-
Business transfers If ATOS IA & PERFORMANCE LTDA is involved in a merger, acquisition, restructuring or sale of all or part of its business, personal data may be transferred to the acquiring entity as part of that transaction. We will notify affected individuals via prominent notice on the Site and, where required, seek consent before any transfer occurs.
International data transfers
Some of our service providers — including Google — are headquartered or operate infrastructure in countries outside Brazil and the European Economic Area. Where personal data is transferred to a country that does not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission and, for LGPD purposes, equivalent contractual mechanisms recognised or accepted by the ANPD. You may request a copy of the relevant transfer safeguards by contacting us at the details in Section 11.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law. Our retention standards are as follows:
-
Inquiry and pre-contractual data Correspondence related to inquiries that did not result in an engagement is retained for up to 24 months from the last interaction, after which it is securely deleted. This allows us to maintain continuity if you reconnect with us.
-
Contractual and client data Data related to completed client engagements — including contracts, project records and correspondence — is retained for a minimum of 5 years after the end of the engagement, in line with Brazil's statute of limitations for civil obligations (Código Civil, Art. 206) and fiscal record-keeping requirements. In some circumstances, specific records may be held for longer if required by law.
-
Analytics data Aggregated analytics data in Google Analytics is configured to a 14-month retention window. Server access logs are retained for up to 90 days for security purposes.
-
Cookie consent records Records of your consent preference are retained for 12 months and then refreshed.
At the end of each retention period, personal data is either securely deleted (for digital records, using methods that prevent recovery) or anonymised so that it can no longer be linked to any individual, in which case the anonymised data may be retained indefinitely for statistical purposes.
Data Security
ATOS IA & PERFORMANCE LTDA takes the security of your personal data seriously. We have implemented a range of technical and organisational measures appropriate to the sensitivity of the data we hold and the risks associated with its processing, including:
-
Encryption in transit All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. Our Site is served exclusively over HTTPS.
-
Encryption at rest Databases and file storage containing personal data are encrypted at rest using industry-standard algorithms.
-
Access controls Access to personal data is restricted on a strict need-to-know basis. All internal accounts use strong authentication and activity logging.
-
Vendor due diligence We assess the security practices of all third-party processors before engaging them and review these assessments periodically.
-
Incident response We maintain a documented data breach response procedure. In the event of a breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (ANPD and/or appropriate EU data protection authority) within the timeframes required by law and will notify affected individuals without undue delay.
Your Rights
Depending on your location and the applicable law, you may have some or all of the following rights with respect to your personal data. Both the LGPD and the GDPR confer broadly similar rights, and we apply these to all data subjects regardless of location:
Right of Access (Confirmation & Access)
You have the right to confirm whether we hold personal data about you, and to receive a copy of that data along with information about how it is used. We will respond within 15 days (LGPD) or one month (GDPR).
Right to Rectification (Correction)
If the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it without undue delay.
Right to Erasure (Deletion)
You may request deletion of your personal data in certain circumstances — for example, where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent and we have no other lawful basis to retain it. This right is subject to our legal obligations to retain certain records.
Right to Restriction of Processing
In certain circumstances, you may ask us to restrict processing of your data — for instance, while you contest its accuracy or object to our use of it.
Right to Object
Where we process your data on the basis of legitimate interests, you have the right to object. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or processing is necessary for legal claims.
Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you may request that we provide your data in a structured, commonly used, machine-readable format so you can transfer it to another controller.
Withdrawing consent
Where our processing is based on your consent — for example, non-essential cookies — you have the right to withdraw that consent at any time without affecting the lawfulness of any processing carried out before the withdrawal. You can withdraw cookie consent via the Cookie Preferences link in the site footer.
How to exercise your rights
To exercise any of the rights above, please submit a written request by email to [email protected] with the subject line "Data Subject Rights Request". Please include sufficient information for us to verify your identity before processing the request — we do this to protect your data from unauthorised disclosure. We will acknowledge your request within 5 business days and respond substantively within the timeframe required by applicable law. There is no charge for exercising your rights, unless requests are manifestly unfounded or excessive.
Right to lodge a complaint
If you are unsatisfied with how we have handled your personal data or responded to a rights request, you have the right to lodge a complaint with a supervisory authority. In Brazil, the competent authority is the Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd. If you are located within the European Economic Area, you may also approach the data protection authority of your EU member state.
Children's Privacy
This Site and the services offered by ATOS IA & PERFORMANCE LTDA are directed exclusively at adults conducting or evaluating professional and commercial engagements. We do not knowingly collect, solicit or process personal data from individuals under the age of 18.
If you believe that a minor has submitted personal data to us without appropriate parental or guardian consent, please contact us immediately at [email protected]. Upon verification, we will promptly delete any such data from our records.
Under Brazil's LGPD, the processing of children's data requires specific consent from a parent or legal guardian and additional safeguards (LGPD Art. 14). We have no legitimate purpose under this Site or our services to collect data from minors, and we rely on our site being commercially oriented to support this position.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable law, or guidance from supervisory authorities. Any changes we make will become effective when we publish the revised policy on this page, along with an updated "Last updated" date at the top of this document.
Where changes are material — meaning they significantly affect your rights or the way we process your data — we will take additional steps to inform you. This may include displaying a prominent notice on the Site, updating the cookie consent banner to draw your attention to the revision, or where we hold your contact details, sending a direct notification by email.
We encourage you to review this page periodically to stay informed about how we are protecting your information. Your continued use of the Site after any changes to this policy constitutes your acknowledgment of the revised terms, to the extent permitted by applicable law.
All previous versions of this Privacy Policy are available upon request from our data protection contact identified below.
Contact & Data Controller
ATOS IA & PERFORMANCE LTDA is the data controller responsible for the personal data described in this policy. If you have any questions, concerns or requests relating to your privacy or this policy, please contact us through any of the means below. We are committed to responding to all privacy-related enquiries within 5 business days of receipt.
ATOS IA & PERFORMANCE LTDA
For formal data subject rights requests, please use the subject line "Data Subject Rights Request" to ensure your message is routed to the appropriate person without delay. We may ask you to verify your identity before processing the request in order to protect your data from being disclosed to an unauthorised third party.
For complaints or escalations that we have not resolved to your satisfaction, you are entitled to contact the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil or the relevant supervisory authority in your country of residence.