Legal & Compliance

Privacy Policy

We are committed to protecting your personal data with transparency and care. This policy explains exactly what information we collect, why we collect it, how we use it, and what rights you hold — in plain language, without legal jargon.

Last updated: 15 June 2025

Introduction

Paipe Tecnologia e Inovação is a brand operated by GOVER TECH TO EMPOWER LTDA, a company incorporated under the laws of Brazil (CNPJ 19.876.161/0001-71), with its registered address at Rua Tupi, 752, Térreo, Rio Branco, Novo Hamburgo — RS. When we say "Paipe," "we," "our," or "us" in this document, we mean that legal entity.

We build AI-powered software products and provide technology consulting services. In doing so, we operate the website paipe-us.site and related digital assets (collectively, the "Services"). This Privacy Policy describes how we process personal data collected through those Services and through direct business interactions with clients, partners, and prospective customers.

This policy is designed to comply with applicable privacy law, including Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Lei nº 13.709/2018) and, where relevant to individuals located in the European Economic Area, the EU General Data Protection Regulation (GDPR — Regulation 2016/679). For the purposes of the LGPD, GOVER TECH TO EMPOWER LTDA acts as the controlador (data controller) of personal data processed under this policy.

Please read this document carefully before using our Services. By continuing to use our website or submitting your information to us, you acknowledge that you have read and understood this policy.

Information We Collect

We only collect the personal data that is genuinely necessary for the purposes described in this policy. The categories of information we collect depend on how you interact with us.

Information you provide directly

When you fill in our contact form, request a demo, subscribe to our newsletter, or enter into a service agreement with us, you may provide:

  • Full name and professional title or role within your organisation
  • Business email address and, where given, telephone number
  • Company name, website URL, and industry sector
  • The content of messages you send us — including questions, project briefs, support requests, and feedback
  • Billing and invoicing information (where you become a paying client), including tax identification numbers required under Brazilian fiscal law

Providing this information is entirely voluntary. However, certain fields are required for us to respond to your request or to fulfil a contract with you; those fields are clearly marked on our forms.

Information collected automatically when you visit our site

Like virtually every website on the internet, our servers and third-party analytics tools automatically collect certain technical data when you navigate to and around our pages:

  • IP address and approximate geolocation derived from it (city/country level; we do not collect precise GPS coordinates)
  • Browser type, version, and language settings
  • Operating system and device type (desktop, mobile, tablet)
  • The URL of the page you visited, the page you came from (referrer), and the pages you viewed during your session
  • Date, time, and duration of your visit
  • Interactions such as clicks on links, buttons, and calls-to-action
  • UTM parameters and other campaign identifiers carried in URLs from advertising platforms

This data is collected primarily through cookies, pixels, and similar technologies — described in detail in Section 4 below.

Information from third-party sources

We may occasionally receive limited data about potential business contacts through LinkedIn or other professional networks, where users have made their information publicly available or have explicitly shared it with us. We do not purchase marketing lists or engage in any form of data brokering.

How We Use Your Information

We process your personal data only for specific, legitimate purposes and on a valid legal basis. The table below sets out our principal processing activities.

Responding to enquiries and delivering services

When you contact us through our website or directly by email, we use your name, email address, and the information in your message to understand your needs and provide a meaningful, personalised response. Where you enter into a services contract with us, we process the data necessary to perform that contract — including project communication, invoicing, and technical support. Legal basis (LGPD / GDPR): contract performance; legitimate interests.

Marketing and business development communications

With your consent, we may send you emails about our services, industry insights, product updates, and invitations to events or webinars. Every marketing email contains a clearly visible, one-click unsubscribe link. We will never send you unsolicited commercial messages or share your contact details with third parties for their own marketing purposes. Legal basis: consent; legitimate interests (for B2B communications where permitted by applicable law).

Website improvement and analytics

We analyse aggregated and, where necessary, pseudonymised visitor data to understand how people use our site, which content is most useful, and where we can improve the user experience. This informs decisions about site structure, content strategy, and performance optimisation. Legal basis: legitimate interests.

Advertising measurement

We run paid advertising campaigns on platforms such as Google Ads and LinkedIn Ads. We use conversion tracking to measure which campaigns lead to enquiries or other defined goals, so that we can allocate our advertising budget responsibly. This processing involves cookies and pixels described in Section 4. Legal basis: consent (collected via our cookie consent mechanism); legitimate interests.

Legal and regulatory compliance

We may process and retain personal data to the extent required by Brazilian law — for example, to comply with fiscal obligations under the tax authorities, to respond to lawful requests from courts or regulatory bodies, or to exercise or defend legal claims. Legal basis: legal obligation; legitimate interests.

We do not sell your personal data. We do not profile you for automated decision-making that produces legal or similarly significant effects. We do not use your data to train third-party AI models without your explicit consent.

Cookies & Tracking Technologies

Cookies are small text files placed on your device when you visit a website. We also use similar technologies including web beacons (pixels), local storage objects, and session identifiers. This section describes the types we use and how you can manage them.

Categories of cookies we use

Category Purpose Examples Consent required?
Strictly necessary Enable core site functions — navigation, form submission, security tokens. The site cannot function properly without these. Session ID, CSRF token No
Analytics & performance Collect anonymised/pseudonymised data on how visitors interact with our pages — page views, session duration, bounce rate. We use this to improve content and usability. Google Analytics 4 (_ga, _gid) Yes
Marketing & advertising Track conversions from ad campaigns, enable remarketing audiences, and measure ad effectiveness across platforms. Google Ads (_gcl_au), LinkedIn Insight Tag (li_fat_id) Yes
Functional / preferences Remember your cookie consent choice and any language or display preferences you have set. Consent cookie (paipe_consent) No (stores your own preference)

Managing your cookie preferences

When you first visit our site, a cookie consent banner gives you granular control over each category above. You can accept all, reject non-essential cookies entirely, or select individual categories. Your choice is stored for 12 months, after which we will ask again.

You can change your preferences at any time by clicking the "Cookie Settings" link in our website footer. You may also manage or delete cookies at browser level through your browser's settings — instructions vary by browser but are available from your browser provider's help pages. Please note that disabling certain cookies may affect website functionality.

For Google Analytics specifically, you may opt out via the Google Analytics Opt-out Browser Add-on. For interest-based advertising, you can manage preferences at youronlinechoices.com (EU) or through the relevant platform's ad settings.

Google Ads and conversion tracking

Our site uses the Google Ads conversion tag to measure when users who clicked one of our advertisements subsequently complete a defined action on our website (such as submitting a contact form). This data is used solely to measure the effectiveness of our own advertising spend and is processed in accordance with Google's privacy terms. We have enabled IP anonymisation and do not share personally identifiable audience lists with third parties outside this arrangement.

Sharing With Third Parties

We do not sell, rent, or trade your personal data. We share information with third parties only in the limited circumstances described below, and only to the extent necessary.

Service providers (data processors)

We engage carefully selected third-party companies to provide infrastructure and operational services on our behalf. These providers access personal data solely to perform tasks we direct them to, under written agreements that bind them to confidentiality and data protection standards consistent with this policy. Our current service provider categories include:

  • Cloud hosting & infrastructure — our website and internal systems are hosted on reputable cloud platforms operating under Standard Contractual Clauses or equivalent safeguards for international transfers.
  • Email delivery — transactional and marketing emails are sent via a third-party email service provider that processes recipient addresses and delivery metadata on our behalf.
  • Analytics — we use Google Analytics 4. Data is processed by Google under an analytics-specific data processing agreement, with IP anonymisation enabled.
  • Advertising platforms — Google Ads and LinkedIn Ads receive pseudonymised conversion event data as described in Section 4.
  • CRM software — contact records for leads and clients are managed in a cloud-based CRM. Access is restricted to Paipe staff with a legitimate need.
  • Video conferencing — where we conduct online meetings with prospective or current clients, platform providers process connection data under their own privacy policies.

Legal and regulatory disclosures

We may disclose personal data to courts, law enforcement agencies, the Brazilian National Data Protection Authority (ANPD), or other regulatory bodies where we are required to do so by applicable law, or where disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our staff and third parties.

Business transfers

If GOVER TECH TO EMPOWER LTDA were ever involved in a merger, acquisition, asset sale, or restructuring, personal data held by us might form part of the assets transferred. We would notify affected individuals before their data became subject to a different privacy policy, and we would ensure any successor entity treats your data with equivalent protections.

No international transfers without safeguards

Some of our service providers operate servers outside Brazil. In those cases, we ensure that appropriate transfer mechanisms are in place — such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or contractual clauses consistent with ANPD guidance — before any transfer takes place.

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our general retention schedules are as follows:

  • Contact form enquiries that do not result in a commercial relationship — retained for up to 24 months from the date of the last interaction, then securely deleted or anonymised. This period allows us to follow up meaningfully without holding data indefinitely.
  • Client and contractor records (contracts, communications, invoicing data) — retained for 5 years after the conclusion of the relevant engagement, in line with Brazilian civil and commercial law obligations, and for up to 10 years where required by Brazilian tax law (Lei nº 10.406/2002; Lei nº 5.172/1966).
  • Marketing subscriber data — retained until you unsubscribe or withdraw consent, plus a short additional period (90 days) to process the opt-out and maintain suppression records so that we do not inadvertently contact you again.
  • Analytics data — Google Analytics data is retained at session level for 14 months under our GA4 configuration, after which it is automatically aggregated and de-identified.
  • Cookie consent records — retained for 3 years to demonstrate compliance with our consent obligations.

At the end of each retention period, data is either permanently deleted using secure deletion methods, anonymised so that it can no longer be attributed to an identifiable individual, or archived in a restricted environment solely for the purpose of resolving legal disputes that may arise.

Data Security

Protecting your personal data against unauthorised access, accidental loss, destruction, or disclosure is a serious operational responsibility that we take seriously. Our security programme includes the following measures:

  • Encryption in transit — all communications between your browser and our website are encrypted using TLS 1.2 or higher (HTTPS). You can verify this by the padlock icon in your browser address bar.
  • Encryption at rest — databases and file storage systems containing personal data are encrypted at rest, ensuring that physical access to storage media alone is insufficient to expose personal data.
  • Access controls — access to systems containing personal data is restricted on a least-privilege basis. Staff members can only access the data they genuinely need to fulfil their job functions. Access is authenticated with strong, unique credentials and multi-factor authentication where technically available.
  • Regular security reviews — we perform periodic assessments of our systems, data flows, and vendor security posture. Known vulnerabilities in our technology stack are patched promptly.
  • Staff training — all Paipe team members who handle personal data receive training on data protection obligations and secure data-handling practices, both at onboarding and on an ongoing basis.
  • Incident response — we maintain a documented incident response plan. In the event of a personal data breach that is likely to result in risk to affected individuals, we will notify the ANPD and, where required, the affected individuals, within the timeframes specified by the LGPD (72 hours for high-risk incidents under GDPR; reasonable timeframe under LGPD).

No security system is impenetrable, and we cannot guarantee the absolute security of data transmitted over the internet. However, we implement industry-standard safeguards and continually work to strengthen them. If you have reason to believe that your interaction with us has been compromised, please contact us immediately at the address in Section 11.

Your Rights

Depending on your country of residence, you hold specific rights regarding your personal data under the LGPD and/or the GDPR. We respect these rights unconditionally and have built processes to honour them promptly. Below is a plain-language summary.

Access

Request a copy of the personal data we hold about you and information about how we process it.

Correction

Ask us to correct inaccurate or incomplete personal data without undue delay.

Deletion

Request erasure of your personal data where there is no legitimate reason for us to continue processing it.

Objection

Object to processing based on legitimate interests or for direct marketing, including profiling for marketing purposes.

Restriction

Ask us to pause processing of your data in certain circumstances — for example, while a correction request is being assessed.

Portability

Receive a structured, machine-readable copy of personal data you provided to us, so you can transfer it to another service if you wish.

Withdraw Consent

Where processing is based on your consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Non-discrimination

Under the LGPD, you have the right not to be discriminated against for exercising your data protection rights.

How to exercise your rights

To make a request, please email us at contato@paipe-us.site with the subject line "Data Rights Request". Include your full name and the email address associated with your data so that we can locate your records. For security purposes, we may need to verify your identity before acting on your request — we will not use this verification step as a barrier to obstruct you.

We will acknowledge your request within 5 business days and aim to fulfil it within 15 days. Where the nature of the request requires more time, we will inform you and provide a clear revised timeline. There is no fee for reasonable requests; we reserve the right to charge a modest administrative fee only for manifestly excessive or repetitive requests, as permitted by applicable law.

Right to lodge a complaint. If you are dissatisfied with our response or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD, gov.br/anpd). EEA residents may also complain to their local supervisory authority.

Children's Privacy

Our Services are designed exclusively for business users and professionals. They are not directed at, and are not intended for use by, individuals under the age of 18. We do not knowingly collect or solicit personal data from minors.

If we become aware that we have inadvertently collected personal data from a person under 18 without appropriate parental or guardian consent, we will take immediate steps to delete that data from our records. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at contato@paipe-us.site and we will address the matter promptly.

Changes to This Policy

Data protection law and our business practices evolve over time, and we will update this Privacy Policy periodically to reflect those changes. When we make revisions, we update the "Last updated" date at the top of this page. For material changes — those that significantly affect how we use your data or your rights in relation to it — we will take additional steps to notify you, which may include a prominent notice on our website homepage or, where we hold your email address and the change directly concerns you, direct communication by email.

We encourage you to review this page periodically. Continued use of our Services after a revised policy has been published constitutes your acknowledgement of the updated terms, to the extent permitted by applicable law. Where law requires fresh consent for a material change in processing purposes, we will obtain it before proceeding.

Previous versions of this policy are available upon request by emailing us at the address below.

Contact & Data Controller Details

If you have any questions about this Privacy Policy, wish to exercise your rights, want to understand more about a specific processing activity, or have a concern about how your data is being handled, please reach out to us directly. We are committed to responding in a helpful, timely manner.

Data Controller

GOVER TECH TO EMPOWER LTDA (trading as Paipe Tecnologia e Inovação)

CNPJ: 19.876.161/0001-71

Rua Tupi, 752, Térreo, Rio Branco
Novo Hamburgo — RS, Brazil

Privacy & Data requests: contato@paipe-us.site

General enquiries: contato@paipe-us.site

We aim to acknowledge all privacy-related correspondence within 5 business days and to resolve requests within 15 business days. For complex or high-volume requests we will communicate a revised timeline as early as possible.

Questions or Concerns?

We're Here to Help

Privacy and trust are at the core of everything we build at Paipe. If anything in this policy is unclear, or if you'd like to discuss how we handle your data, our team is ready to assist.