Introduction
This Privacy Policy describes how Pluritech Brasil Ltda ("Pluritech," "we," "us," or "our") collects, uses, stores, and protects personal information when you visit pluritech.site, request a quote, subscribe to our communications, or engage with us in any other way related to our technology, IT infrastructure, and software development services.
Pluritech Brasil Ltda is a legal entity duly incorporated under Brazilian law, registered under CNPJ 21.724.362/0001-03, with principal offices at Alameda das Princesas, 756, Sala 313, Sao Jose, Belo Horizonte — MG, Brazil. We act as the data controller for the personal data you provide or that we collect in the course of our business activities.
We encourage you to read this policy in full. By using our website or submitting any personal information to us, you acknowledge that you have read and understood these practices. If you disagree with any part of this policy, please refrain from using our website and contact us at contato@pluritech.site so we can address your concerns.
This policy applies to all personal data we process as a controller. Where Pluritech processes data on behalf of a client as a data processor, the applicable terms are set out in the relevant data processing agreement with that client.
Information We Collect
We collect personal data only to the extent necessary to provide our services, respond to your enquiries, and continually improve our website. The categories of personal data we may collect include:
- Full name and professional title
- Business email address and phone number
- Company name and sector
- Project description or enquiry details submitted via our contact or quote-request forms
- Any additional information you voluntarily provide in free-text fields
- Correspondence and attachments exchanged by email
- IP address and approximate geographic location (city/region level)
- Browser type and version, operating system, device type
- Pages visited, time on site, referral URL, and exit page
- Interactions with page elements (clicks, scroll depth)
- Cookie identifiers and analytics session data
- Google Ads click identifiers (gclid) if you arrive from a paid advertisement
We do not intentionally collect sensitive personal data (such as health information, political opinions, racial or ethnic origin, or financial account numbers) through our website. If you inadvertently include such information in a free-text field, we will treat it with heightened confidentiality and delete it if it is not relevant to your enquiry.
Legal bases (LGPD / GDPR): We collect and process your data on the basis of: (a) your consent, where requested explicitly; (b) the legitimate interest of responding to your business enquiry and providing you with information about our services; (c) compliance with a legal obligation; or (d) execution of a contract or pre-contractual steps at your request. The applicable basis is indicated per purpose in Section 3 below.
How We Use Your Information
Pluritech uses personal data for specific, explicit, and legitimate purposes. We will not process your data in a manner incompatible with those purposes without first notifying you and, where required, obtaining your consent.
Cookies & Tracking Technologies
Our website uses cookies — small text files placed on your device — and similar tracking technologies such as web beacons and pixel tags. Some cookies are essential for the website to function correctly; others help us analyse traffic or support our advertising campaigns. Where non-essential cookies are used, we request your consent before placing them.
You can manage or withdraw your cookie consent at any time by adjusting your browser settings or using our cookie preference centre (accessible via the cookie banner on your first visit). Please note that disabling certain cookies may affect the functionality of some website features.
We use Google Analytics 4 with IP anonymisation enabled, meaning that the last octet of each visitor's IP address is masked before any data is stored by Google. We have also enabled data sharing restrictions in our Google Analytics configuration to prevent Google from using our site data for its own products and services.
For more information about how Google processes data collected through its advertising and analytics services, please visit policies.google.com/privacy.
Sharing With Third Parties
Pluritech does not sell, rent, or trade your personal data to third parties. We share data only in the limited circumstances described below, and only to the extent necessary for each purpose.
Technology & service providers. We work with a small number of trusted vendors who process data on our behalf as data processors. These include our web hosting provider (servers located in Brazil and/or the EU), our email delivery platform, and Google LLC (for Analytics and Ads). Each processor is bound by a data processing agreement that prohibits them from using your data for any purpose other than providing the contracted service to Pluritech.
Professional advisors. Our legal counsel, accountants, and auditors may access client and contact data to the extent required by the relevant professional engagement and only subject to appropriate confidentiality obligations.
Legal requirements and authority requests. We may disclose personal data if required to do so by a Brazilian court order, regulatory authority (such as the ANPD — Autoridade Nacional de Proteção de Dados), or other competent authority, or if we reasonably believe that disclosure is necessary to protect the rights, property, or safety of Pluritech, our clients, or the public.
Business transfers. If Pluritech is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify you by email and/or by a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
International transfers. Some of our third-party service providers (including Google) operate servers outside Brazil. Where personal data is transferred internationally, we ensure adequate safeguards are in place — such as standard contractual clauses, adequacy decisions, or equivalent mechanisms recognised under LGPD Article 33.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Enquiry and lead data: Records of contact form submissions and related email correspondence are retained for up to 24 months from the date of last contact if no contract has resulted. This allows us to follow up appropriately without holding stale data indefinitely.
Client records: Data associated with completed projects and commercial agreements is retained for a minimum of 5 years after the end of the contract, in accordance with Brazilian tax and commercial law obligations (Lei No. 6,404/1976; Código Civil Art. 1,194).
Marketing consent records: If you have subscribed to marketing communications, we retain a record of your consent alongside your email address for as long as the subscription is active plus an additional 12 months after unsubscription, to demonstrate that we had valid consent.
Website analytics data: Google Analytics session and event data is retained for 14 months as configured in our Analytics property settings, after which it is automatically deleted by Google. Server access logs are retained for up to 90 days for security purposes.
When personal data is no longer required, we securely delete or irreversibly anonymise it so that it can no longer be linked to an identifiable individual.
Data Security
Protecting the personal data entrusted to us is a priority we take seriously. As a technology company, we hold ourselves to a high standard of information security practice.
Our website is served exclusively over HTTPS using TLS 1.2 or higher, ensuring that all data transmitted between your browser and our servers is encrypted in transit. Form submissions are processed over encrypted connections, and any email confirmations we send do not include sensitive personal data in the message body.
Access to systems that contain personal data is restricted to Pluritech employees and contractors who require it to perform their job functions. All team members with access to personal data are trained on data protection obligations and subject to confidentiality obligations. Access credentials are managed using multi-factor authentication.
Our hosting infrastructure is maintained with regular security patches, and we perform periodic vulnerability assessments. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ANPD and, where required, affected individuals within the timeframes prescribed by LGPD Article 48 (within a reasonable period, and as a guideline no longer than 72 hours of becoming aware of the incident).
While we maintain robust safeguards, no internet transmission or electronic storage system is completely secure. We encourage you to use a secure network when submitting sensitive information and to keep any credentials you use to communicate with us confidential.
Your Rights
Depending on your jurisdiction, you hold various rights regarding the personal data we hold about you. Under LGPD (Art. 18) and, where applicable, the GDPR (Art. 15–22), these rights include:
How to exercise your rights: Submit your request by email to contato@pluritech.site with the subject line "Data Subject Request." Please describe your request clearly and provide sufficient information to allow us to verify your identity (for example, the name and email address you used when contacting us). We will acknowledge receipt within 5 business days and aim to respond fully within 15 calendar days, extendable by a further 15 days in complex cases with prior notice to you. We will never charge a fee for a first request relating to any given category of data.
Children's Privacy
Pluritech's website and services are directed exclusively at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children or minors. Our contact forms, landing pages, and all commercial materials are aimed at corporate decision-makers, IT managers, and adult professionals.
If we become aware that personal data has been submitted by or on behalf of a person under the age of 18 without the appropriate legal guardian consent required by LGPD Article 14, we will take immediate steps to delete that information from our systems. If you believe that we have inadvertently collected data from a minor, please notify us immediately at contato@pluritech.site and we will act without delay.
Changes to This Policy
We review and update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and regulatory guidance. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you directly by email or by placing a prominent notice on our website homepage.
We encourage you to revisit this page periodically to stay informed about how we protect your information. Your continued use of our website after any changes are published constitutes acceptance of the revised policy. If the changes are significant and you object to them, you are entitled to exercise your right to object or to erasure as described in Section 8 above.
Previous versions of this policy are available upon request — email us at contato@pluritech.site with the subject "Privacy Policy — Previous Version" and we will provide the applicable version together with its effective date.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way Pluritech handles your personal data, please do not hesitate to reach out. Our Data Protection contact point is available to assist you.
Belo Horizonte — MG, Brazil
Supervisory Authority: If you are a Brazilian resident and you believe your rights under the LGPD have not been respected, you may file a complaint with the ANPD — Autoridade Nacional de Proteção de Dados at gov.br/anpd. If you are located in the European Economic Area, you may contact the data protection authority in your member state.