Privacy Policy

At Breyon Tech, we believe trust is the foundation of every client relationship. This Privacy Policy explains, in plain language, exactly what personal data we collect, why we collect it, how we protect it, and the rights you can exercise at any time. We are committed to full compliance with the Brazilian Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018) and the European Union's General Data Protection Regulation (GDPR), as well as applicable global best practice.

01

Introduction

This Privacy Policy is published by Cabral e Ferreira Desenvolvimento de Programas de Computador Ltda, registered under CNPJ 67.853.429/0001-00, with registered offices at Avenida Brigadeiro Faria Lima, 1572, Edifício Barão de Rothschild, Sala 1022, Jardim Paulistano, São Paulo — SP, Brazil ("Breyon Tech", "we", "us" or "our"). We operate the website accessible at this domain (the "Site") as an informational, corporate brochure site describing our software development and technology consulting services.

When you visit our Site, we may collect certain information automatically through cookies and analytics tools, and you may choose to contact us directly using the e-mail address or telephone number we publish. This Policy covers all such data collection and processing activities, including those carried out by service providers acting on our behalf.

By continuing to use this Site, you acknowledge that you have read and understood this Policy. Where your rights under Brazilian law or EU law grant you specific controls over your personal data, this document explains how to exercise those rights free of charge and without undue delay.

02

Information We Collect

We collect only the minimum personal information necessary to operate our Site, understand how visitors use it, and respond to legitimate enquiries. We do not run e-commerce, subscription services, user accounts, or property/job listing platforms; accordingly, the scope of data collection is deliberately narrow.

Information you provide directly

If you reach out to us by e-mail ([email protected]) or telephone, we receive whatever information you include in that communication — typically your name, professional e-mail address, company name, and the content of your message. We use this information solely to respond to your enquiry and, where relevant, to follow up in connection with a potential engagement. We do not add this information to marketing lists without your explicit consent.

Information collected automatically

When you browse our Site, certain technical data is collected automatically by our servers and third-party analytics tools. This includes:

  • Log data: Your IP address (which may be anonymised before storage), the URL of the page you requested, the referring URL, HTTP status code, browser type and version, operating system, and the date and time of the request. Log files are retained for security monitoring and are not used for individual profiling.
  • Device information: General device characteristics such as screen resolution and viewport size, used in aggregate to inform responsive design decisions. This data is not linked to a personal identity.
  • Usage data: Pages visited, time spent on page, scroll depth, and navigation paths, collected through Google Analytics 4 with IP anonymisation enabled. This data helps us understand which content is most useful and identify technical issues.
  • Cookie data: Small text files stored on your browser as described in detail in Section 4 below.

Information we do not collect

We do not collect sensitive personal data (such as health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, or financial account details) through this Site. We do not knowingly collect personal data from children under 16. We do not purchase, rent, or source personal data from third-party data brokers.

03

How We Use Your Information

We process personal data only for clearly defined purposes and always on the basis of a recognised lawful ground under the LGPD and, where applicable, the GDPR. The table below summarises each processing activity.

  • Responding to enquiries: When you contact us by e-mail or phone, we process your contact details and message content to provide a timely, accurate response. Lawful basis: Legitimate interest (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) — specifically, our interest in communicating with prospective and existing clients.
  • Site operation and security: Server log data and technical metadata are processed to detect and prevent malicious activity, diagnose errors, and maintain service availability. Lawful basis: Legitimate interest in keeping our systems secure and our Site accessible.
  • Analytics and site improvement: Aggregated, anonymised usage data collected via Google Analytics helps us understand visitor behaviour and continuously improve our content and technical performance. Lawful basis: Consent — we request your agreement via the cookie consent mechanism before placing non-essential analytics cookies.
  • Legal compliance: Where applicable law requires us to retain or disclose data — for example, in response to a valid court order or regulatory request — we will process personal data to fulfil that obligation. Lawful basis: Legal obligation (LGPD Art. 7 II; GDPR Art. 6(1)(c)).

We will never sell your personal data. We will never use your personal data to make automated decisions that produce significant effects on you. We do not engage in targeted behavioural advertising using data collected through this Site.

04

Cookies & Tracking Technologies

Cookies are small text files that a website places on your device to remember information about your visit. We use a limited set of cookies, categorised below. You can control or withdraw your consent to non-essential cookies at any time through your browser settings or our cookie preference mechanism.

Managing your cookie preferences

You can prevent cookies being set by adjusting your browser settings. Instructions are available for Google Chrome, Mozilla Firefox, and other major browsers through their respective help centres. Please note that disabling all cookies may affect the Site's ability to remember your preferences. Because this Site does not use cookies for advertising or third-party profiling, no participation in industry opt-out schemes (such as NAI or DAA) is currently necessary; however, you may also opt out of Google Analytics measurement across all websites by installing the Google Analytics Opt-out Browser Add-on.

Third-party content and embedded services

This Site does not embed social media widgets, third-party video players, or other external content that would set additional cookies without your awareness. Should we add any such features in future, this Policy will be updated and consent mechanisms updated accordingly before those features go live.

05

Sharing With Third Parties

We do not sell, rent, or trade personal data. We share data only in the limited circumstances described below, and only with recipients who are bound by contractual obligations at least as protective as this Policy.

  • Infrastructure and hosting providers: Our Site is hosted on infrastructure provided by reputable cloud providers operating data centres in the Americas and/or Europe. These providers act as data processors under our instruction and may not use personal data for their own purposes.
  • Google Analytics (Google LLC): Anonymised usage data is shared with Google LLC for analytics processing. Google's privacy policy governs this processing; data is subject to Google's Standard Contractual Clauses for international transfers. No advertising features are activated in our Google Analytics configuration.
  • Professional advisors: Our legal counsel, auditors, and accountants may access data where strictly necessary to fulfil their professional obligations to us, and are bound by professional confidentiality duties.
  • Regulatory and legal authorities: We may disclose personal data if required by applicable law, a court order, or a government body with jurisdiction over our activities in Brazil or elsewhere. We will always aim to notify you of such a request to the extent permitted by law.
  • Corporate transactions: In the event of a merger, acquisition, or sale of substantially all of our assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections. We will provide notice of any such transfer through this Policy.

Where personal data originating from the European Economic Area is transferred to a country that has not received an adequacy decision from the European Commission (which includes Brazil at the time of this Policy's effective date), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, before making any such transfer.

06

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, comply with legal obligations, and resolve any disputes that may arise. Our specific retention schedules are as follows:

  • Direct contact communications (e-mail / phone): Retained for up to three (3) years from the date of last substantive interaction with the enquirer. This period reflects the general limitation period for civil obligations under Brazilian law. After this period, data is securely deleted unless we are under a legal obligation to retain it further.
  • Server log files: Retained for a maximum of ninety (90) days for security incident investigation purposes. Logs older than ninety days are automatically purged.
  • Google Analytics data: We have configured Google Analytics with a data retention period of fourteen (14) months. After this period, Google automatically deletes the event-level data from their servers. Aggregated reports derived from this data may be kept indefinitely as they contain no personally identifiable information.
  • Cookie consent records: Retained for a period of five (5) years to demonstrate regulatory compliance, in line with LGPD accountability obligations.

When data reaches the end of its retention period, we ensure it is either securely deleted, anonymised beyond any reasonable possibility of re-identification, or, where physical media is involved, destroyed in a manner consistent with industry standards for secure data disposal.

07

Data Security

Protecting the personal data entrusted to us is a professional and ethical priority. We implement a layered set of technical and organisational security measures appropriate to the nature and volume of data we process:

  • Encryption in transit: All communication between your browser and our Site is encrypted using TLS 1.2 or higher. We enforce HTTPS site-wide and have HTTP Strict Transport Security (HSTS) enabled to prevent protocol downgrade attacks.
  • Access controls: Personal data held in our systems is accessible only to team members who require it for the specific purpose for which it was collected. Access is granted on a least-privilege basis and reviewed regularly.
  • Vendor security standards: We select technology partners who maintain recognised security certifications (such as ISO 27001 or SOC 2 Type II) and we review the security posture of key processors when they are onboarded and periodically thereafter.
  • Incident response: We maintain a documented data breach response procedure. In the event of a breach likely to result in a risk to individuals' rights and freedoms, we will notify the Brazilian Autoridade Nacional de Proteção de Dados (ANPD) within the timeframe required by the LGPD (generally 2 business days of becoming aware of the breach) and, where required, affected individuals directly.

Please be aware that no method of electronic transmission or storage is 100% secure. While we employ strong measures and continuously review them, we cannot guarantee the absolute security of information transmitted to our Site over the public internet. We encourage you to exercise appropriate care when sharing personal information electronically.

08

Your Rights

Depending on your country of residence, you hold specific rights regarding personal data that we hold about you. Brazilian residents are protected under the LGPD; data subjects in the European Economic Area are protected under the GDPR. In practice, we apply the higher standard of protection to all individuals who exercise rights with us, regardless of jurisdiction.

Right of Access

You may request a copy of the personal data we hold about you and information about how we process it. We will respond within fifteen (15) days of a verified request (LGPD Art. 18 I & II; GDPR Art. 15).

Right to Rectification

If personal data we hold about you is inaccurate or incomplete, you can ask us to correct or complete it. We will action confirmed corrections without delay (LGPD Art. 18 III; GDPR Art. 16).

Right to Deletion / Erasure

You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent, or where processing is unlawful. Requests are subject to our legal retention obligations (LGPD Art. 18 VI; GDPR Art. 17).

Right to Object

Where we rely on legitimate interests as our lawful basis, you may object to that processing. We will assess whether our legitimate interests override your individual interests, rights and freedoms and cease processing if they do not (LGPD Art. 18 IX; GDPR Art. 21).

Right to Restriction

In certain circumstances — for example, while we verify the accuracy of data you have contested — you can ask us to restrict active processing of your data without deleting it (LGPD Art. 18 IV; GDPR Art. 18).

Right to Data Portability

Where technically feasible and where processing is based on your consent or a contract, you may request that we provide your personal data in a structured, commonly used, machine-readable format so you can transfer it to another controller (LGPD Art. 18 V; GDPR Art. 20).

Right to Withdraw Consent

Where processing is based on consent (e.g., analytics cookies), you may withdraw that consent at any time via your browser cookie settings or our preference mechanism. Withdrawal does not affect the lawfulness of prior processing (LGPD Art. 8 §5; GDPR Art. 7(3)).

Right to Lodge a Complaint

If you believe we have mishandled your data, you have the right to lodge a complaint with the Brazilian ANPD (gov.br/anpd) or, for EEA residents, your local supervisory authority. We encourage you to contact us first so we can attempt to resolve the issue directly.

How to exercise your rights

To exercise any of the rights described above, please send a written request to [email protected] with the subject line "Data Subject Request". Please include sufficient information for us to verify your identity (such as your full name and the e-mail address from which you previously contacted us). We will not charge a fee for processing rights requests unless they are manifestly unfounded or excessive. We aim to respond to all verified requests within fifteen (15) calendar days; in complex cases, this may be extended by a further thirty (30) days, of which we will inform you promptly.

09

Children's Privacy

This Site is directed exclusively at business professionals and corporate decision- makers evaluating technology services. It is not intended for, and does not knowingly collect or process personal data from, children under the age of 16 (or such higher age threshold as may apply in a particular jurisdiction).

If we become aware that we have inadvertently received personal data from a child under the applicable minimum age, we will take prompt steps to delete that information from our records. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at [email protected] so that we can investigate and remediate the situation immediately.

10

Changes to This Policy

We review this Privacy Policy at least annually, and also whenever we introduce new services, change our data processing practices, or become aware of a relevant change in applicable law. When we make substantive changes — meaning changes that expand the categories of data we collect, alter the purposes for which data is used, or materially affect your rights — we will update the "Last Updated" date at the top of this page and, where we hold your contact details and the change is significant, we may notify you directly by e-mail.

We encourage you to revisit this page periodically to stay informed about how we protect your information. Your continued use of the Site after the effective date of any revised Policy constitutes your acknowledgement of the changes, to the extent permitted by law. Where applicable law requires fresh consent for a material change, we will obtain that consent before the change takes effect.

Previous versions of this Policy are available on request by contacting us at the details below.

11

Contact & Data Protection Officer

If you have any questions, concerns, or requests relating to this Privacy Policy or to the way we handle your personal data, please reach out to us using any of the contact details below. We are committed to responding promptly and transparently. The LGPD requires us to designate a Data Protection Officer (Encarregado de Dados); enquiries addressed to that role should be directed to the same contact details and will be routed to the responsible person within our organisation.

Get in touch with us

Legal entity: Cabral e Ferreira Desenvolvimento de Programas de Computador Ltda CNPJ: 67.853.429/0001-00 Registered address: Avenida Brigadeiro Faria Lima, 1572, Edifício Barão de Rothschild, Sala 1022, Jardim Paulistano, São Paulo — SP, Brazil General & Privacy enquiries: [email protected] Response commitment: We aim to acknowledge all privacy-related enquiries within two (2) business days and to provide a substantive response within fifteen (15) calendar days of receiving a verifiable request.

Where you consider that our response to your privacy concern is unsatisfactory, you retain the right to escalate your complaint to the Autoridade Nacional de Proteção de Dados (ANPD) — Brazil's data protection supervisory authority — via their official portal at gov.br/anpd. EEA residents may contact their local data protection authority; a directory of EU supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu.