Legal & Privacy

Privacy Policy

We are committed to handling your personal information with transparency, care, and full respect for your rights. This policy tells you exactly what data we collect, why we collect it, how we protect it, and the choices you have at every step.

Company: GONCALVES WEB DESIGN LTDA CNPJ: 67.876.737/0001-43 Jurisdiction: Brazil & International
Last Updated: June 20, 2025

Introduction

GONCALVES WEB DESIGN LTDA — operating publicly as Aruana Digital — is a web design and digital solutions company registered in Brazil under CNPJ 67.876.737/0001-43, with its principal place of business at Avenida Paulista, 91, Conjunto 905, Bela Vista, São Paulo – SP. When you visit our website (the "Site"), contact us, or engage with our content, you entrust us with information about yourself. We take that responsibility seriously.

This Privacy Policy explains, in plain language, what personal data we collect through the Site and through direct communications, the lawful bases on which we process it, how long we keep it, who we may share it with, and how you can exercise the rights granted to you under the European Union's General Data Protection Regulation (GDPR), Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018), and any other applicable privacy legislation.

By accessing and using this Site, you acknowledge that you have read and understood this policy. If you disagree with any part of it, please discontinue use of the Site and contact us directly so we can address your concerns.

A note on scope: This policy covers the Aruana Digital website and any direct communications between you and our team. If we develop a website, digital product, or campaign on behalf of a client, the privacy practices governing that property are the responsibility of the respective client as the data controller, and are governed by their own privacy documentation.

Information We Collect

We collect personal data in two ways: information you actively provide to us, and information collected automatically when you browse the Site.

2.1 — Information You Provide Directly

When you reach out to us via email or through our published contact details, you may voluntarily share information such as your name, professional email address, company name, phone number, and a description of your project or inquiry. We collect only what is necessary to respond meaningfully and provide the service or information you are seeking.

  • Contact inquiries: name, email address, phone number (optional), company name, and the content of your message.
  • Business communications: email correspondence, attachments, and meeting notes exchanged during a client engagement or pre-engagement conversation.
  • Service delivery: when you engage our services, we may collect billing details, project briefs, brand assets, and account credentials (e.g., hosting or CMS logins) strictly for the purpose of delivering the agreed work.

We never ask for sensitive categories of personal data — such as health information, political opinions, religious beliefs, or financial account numbers — unless a specific and explicit reason arises during a professional engagement, in which case we will seek your explicit consent and explain the purpose at that time.

2.2 — Information Collected Automatically

Like virtually every website, ours collects a set of technical and behavioural data when you visit. This data helps us understand how the Site performs, diagnose errors, and improve the user experience. It includes:

  • Log data: your IP address, browser type and version, operating system, referring URL, pages visited, time of visit, and session duration. This data is collected by our hosting infrastructure automatically.
  • Device information: screen resolution, device type (desktop, tablet, mobile), and language settings as reported by your browser.
  • Analytics data: aggregated, pseudonymised data about page-level engagement — such as scroll depth, click patterns, and time-on-page — collected via Google Analytics 4 (see Section 4 for full detail).
  • Cookie data: small text files stored on your device that enable certain site functions and support our analytics. A full breakdown is provided in Section 4.

How We Use Your Information

We process your personal data only for specified, explicit, and legitimate purposes. We will never use your data in a way that is incompatible with the reason for which it was originally collected. Below is a breakdown of each processing purpose and the lawful basis we rely on.

  • Responding to contact inquiries (Legitimate Interest / Contract): When you write to us, we use your contact details and message content to respond. If your inquiry leads to a project engagement, processing your data becomes necessary for the performance of a contract.
  • Delivering contracted services (Contract): Any personal or business data collected during an active client project is used exclusively to plan, execute, test, and deliver the agreed digital services. This includes web design, development, content production, and digital strategy work.
  • Site performance and improvement (Legitimate Interest): Aggregated, anonymised analytics data — with IP addresses truncated — helps us identify slow-loading pages, broken links, and content that fails to serve visitors well. No personally identifiable profiles are built for this purpose.
  • Compliance with legal obligations (Legal Obligation): We retain certain financial and contractual records as required by Brazilian tax and commercial law. In these cases, processing is mandatory regardless of your preferences.
  • Security and fraud prevention (Legitimate Interest): Server logs and IP data may be reviewed if we detect unusual activity, attempted intrusions, or abuse of our website infrastructure.

We do not sell, rent, or trade your personal data. We do not build advertising profiles from your visit to this Site, and we do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.

Cookies & Tracking Technologies

Cookies are small text files placed on your device when you visit a website. They serve different purposes — some are essential for the site to function, others help us understand how the site is used, and some support advertising. Below we describe every category of cookie we use and, where consent is required, how to manage your preferences.

4.1 — Strictly Necessary Cookies

These cookies are required for the basic operation of the website. Without them, the site cannot load securely or remember your session. They do not collect personal data for marketing purposes and do not require your consent under GDPR or LGPD. Examples include session-management tokens issued by our hosting provider and security cookies that protect against cross-site request forgery (CSRF).

4.2 — Analytics Cookies (Google Analytics 4)

We use Google Analytics 4 (GA4), operated by Google Ireland Limited (and, for users in Brazil, Google LLC as the relevant entity), to collect aggregated data about how visitors interact with the Site. GA4 uses first-party cookies (prefixed _ga and _ga_<ID>) to distinguish unique visitors and sessions. We have configured GA4 with the following privacy measures:

  • IP anonymisation is enabled — the final octet of IPv4 addresses is zeroed before storage.
  • Data sharing with Google advertising products is disabled.
  • Data retention is set to 14 months, after which it is automatically deleted from Google's servers.
  • We do not use GA4's User-ID feature, so no data is linked to authenticated accounts.

GA4 analytics cookies are only placed with your consent (where required by applicable law). You can opt out at any time by adjusting your cookie preferences via the banner displayed on your first visit, or by installing the Google Analytics Opt-out Browser Add-on.

4.3 — Advertising & Remarketing Cookies

If we run Google Ads campaigns that use this Site as a landing page, Google's ad-serving infrastructure may set cookies (such as _gcl_au) to measure campaign conversions. These cookies track whether a visitor who clicked our ad went on to take a meaningful action on the Site (for example, clicking an email link). We do not use personalised remarketing lists that track individuals across unrelated websites without consent. Any advertising cookies require your explicit consent before being set.

4.4 — Managing Your Cookie Preferences

You can control cookies through multiple channels. Our cookie consent banner, shown on your first visit, allows you to accept or reject non-essential categories. You can also manage or delete cookies directly in your browser settings — the support pages for Chrome, Firefox, and Safari provide step-by-step instructions. Please be aware that disabling strictly necessary cookies will impair site functionality.

Sharing With Third Parties

We do not share, sell, license, or disclose your personal data to third parties for their own commercial purposes. We may, however, share data with the limited categories of parties described below, and only to the extent strictly necessary.

  • Hosting and infrastructure providers: Our website is hosted on cloud infrastructure (including services such as Hostinger or equivalent). These providers process server logs and may temporarily store request data on our behalf. They act as data processors under binding agreements that include data protection clauses consistent with LGPD and GDPR requirements.
  • Google LLC (Analytics and Ads): As described in Section 4, Google receives pseudonymised analytics data and — where applicable — ad conversion signals. Google's privacy practices are governed by the Google Privacy Policy. For GDPR compliance, Google Ireland Limited acts as the relevant data processor, and Standard Contractual Clauses are in place for any data transferred outside the EEA.
  • Email and communication tools: When you contact us by email, your message is received and stored by our email service provider. We use reputable business email infrastructure that does not scan message content for advertising purposes.
  • Professional advisers: In limited circumstances, our legal, accounting, or tax advisers may access data relevant to a specific matter (for example, a contract dispute or tax audit). These advisers are bound by professional confidentiality obligations.
  • Legal and regulatory authorities: We will disclose personal data to public authorities — including Brazilian courts, the Autoridade Nacional de Proteção de Dados (ANPD), or law enforcement agencies — where we are legally compelled to do so, or where disclosure is necessary to protect our rights, the safety of users, or the public.
  • Business transfers: If Goncalves Web Design Ltda is acquired, merged, or substantially reorganised, personal data held at that time may be transferred to the successor entity, subject to the same level of protection described in this policy. We will notify you of any such change before your data is transferred.

Whenever we share data with a third-party processor, we maintain written data processing agreements that require the processor to handle data only on our documented instructions, implement appropriate technical and organisational security measures, and assist us in responding to data subject requests.

Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, to comply with applicable legal obligations, and to resolve disputes or enforce our agreements. The following table summarises our principal retention periods.

  • Contact inquiry data (name, email, message): retained for up to 24 months from the date of last communication. If an inquiry leads to an ongoing client relationship, data is retained for the duration of the engagement and then for a further five years to satisfy statutory record-keeping requirements.
  • Client project data (briefs, files, correspondence): retained for 5 years after project completion in line with Brazilian commercial and tax law (Código Civil, Art. 206 and Lei 9.430/96 equivalents).
  • Server log files (IP addresses, request logs): retained for 90 days for security and diagnostic purposes, then automatically deleted or anonymised.
  • Google Analytics data: retained for 14 months on Google's servers as configured in our GA4 property, after which it is automatically purged. Aggregated, non-identifiable trend reports may be retained indefinitely.
  • Cookie consent records: retained for 12 months from the date of your consent, after which we will re-request your preferences.

When retention periods expire, data is deleted from active systems, scrubbed from backups on a rolling schedule, or irreversibly anonymised so that it can no longer be associated with any individual.

Data Security

Protecting the integrity and confidentiality of personal data is a core part of how we operate. We implement a layered set of technical and organisational measures calibrated to the nature and volume of data we handle.

  • Encryption in transit: All data transmitted between your browser and our Site is encrypted using TLS 1.2 or higher. We enforce HTTPS across every page and maintain HTTP Strict Transport Security (HSTS) headers.
  • Access controls: Access to any system or tool that stores personal data is restricted to authorised personnel on a need-to-know basis. We use strong, unique passwords managed through a password vault, and multi-factor authentication is required for all administrative logins.
  • Hosting security: Our hosting environment is configured with automated vulnerability scanning, firewall rules, and regular software patching to mitigate known attack vectors.
  • Internal policies: Team members are trained on data protection responsibilities. We review our security practices periodically and following any material change in our technical environment.
  • Incident response: In the event of a data breach that poses a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority (the ANPD in Brazil, or the appropriate EU DPA for affected EU residents) within the legally required timeframes, and we will notify affected individuals without undue delay where required.

Important: No system connected to the internet is completely immune to security risks. While we take all reasonable precautions, we cannot guarantee absolute security. We encourage you to use strong, unique passwords for any accounts you hold and to contact us immediately at [email protected] if you suspect any security issue related to our Site.

Your Rights

Both the GDPR (for individuals in the European Economic Area and United Kingdom) and Brazil's LGPD (for individuals in Brazil) grant you meaningful rights over your personal data. We respect these rights regardless of your location and will respond to any verified request within the timeframes required by applicable law — generally 30 days for GDPR requests and the equivalent period under the LGPD, with the possibility of a single extension where requests are complex or numerous.

Right of Access

You may request a copy of the personal data we hold about you, together with information about how and why we process it, who we share it with, and how long we keep it.

Right to Rectification

If any data we hold about you is inaccurate, incomplete, or out of date, you have the right to ask us to correct or complete it promptly.

Right to Erasure

In certain circumstances — such as when data is no longer needed for its original purpose or when you withdraw consent — you may ask us to delete your personal data. We will honour valid requests subject to any overriding legal obligation to retain data.

Right to Restriction

You may ask us to pause or limit our processing of your data while an objection or accuracy dispute is being resolved — for example, while you contest the accuracy of data we hold.

Right to Data Portability

Where we process your data by automated means on the basis of consent or contract, you may request that we provide it to you in a structured, commonly used, machine-readable format (such as CSV or JSON), or transmit it directly to another controller where technically feasible.

Right to Object

You have the right to object at any time to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.

Right to Withdraw Consent

Where our processing is based on your consent (for example, analytics cookies), you can withdraw that consent at any time through the cookie preferences banner or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the relevant supervisory authority — the ANPD in Brazil, or your EU member state's data protection authority.

How to Exercise Your Rights

To submit a data subject request, send an email to [email protected] with the subject line "Privacy Rights Request." Please include your full name, the email address under which you may have contacted us previously, a description of your request, and, if you wish, any relevant project reference. We will acknowledge receipt within five business days and provide a substantive response within the legally required period. We may ask for reasonable identification verification before fulfilling a request to protect against unauthorised disclosures.

There is no charge for submitting a request. If a request is manifestly unfounded or excessive (for example, repetitive in nature), we reserve the right to charge a reasonable administrative fee or decline to act on it, as permitted by law. We will explain our reasoning in writing if we take either step.

Children's Privacy

The Aruana Digital website is directed exclusively at business professionals and individuals aged 18 or over who are seeking commercial digital services. We do not knowingly market to, solicit, or collect personal data from children under the age of 13 (or under 16 where stricter national law applies, including under the LGPD's provisions concerning minors).

If we discover or are informed that we have inadvertently received personal data from a minor, we will delete that information promptly from our records. If you are a parent or guardian and believe your child may have submitted personal data to us — for example, through an unsupervised email inquiry — please contact us immediately at [email protected] and we will take swift remedial action.

Changes to This Policy

We review this Privacy Policy at least annually and whenever there is a material change to our data processing activities, applicable law, or the tools and services we use. When we make changes that are not merely editorial or typographical, we will update the "Last Updated" date at the top of this page. Where changes are significant — for example, a new category of personal data being collected, or a new third-party processor being introduced — we will take additional steps to bring the changes to your attention, such as displaying a notice on the Site or, where we hold your contact details and the law requires it, sending you a direct notification.

We encourage you to revisit this page periodically to remain informed about how we protect your information. Your continued use of the Site after a policy update constitutes acceptance of the revised terms to the extent permitted by applicable law. If a change materially and negatively affects your rights and you do not agree to the updated policy, you are entitled to contact us to exercise your rights as described in Section 8 before continuing to use the Site.

Previous versions of this policy are available upon written request to [email protected].

Contact & Data Protection Officer

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a concern about how we have handled your personal information, please contact us using the details below. We are committed to addressing all privacy-related inquiries promptly and constructively.

For all privacy-related matters, including data subject access requests and complaints, the responsible contact within our organisation also serves as our designated Data Protection point of contact (DPC) for the purposes of LGPD Article 41. You may reach us through the channels below:

Legal Name GONCALVES WEB DESIGN LTDA
Trading As Aruana Digital
CNPJ 67.876.737/0001-43
Registered Address Avenida Paulista, 91, Conjunto 905, Bela Vista, São Paulo – SP, Brasil
Privacy & DPC Email [email protected]
Response Time We aim to acknowledge all privacy inquiries within 5 business days and provide a full response within 30 calendar days, or earlier where required by law.

If you are located in the European Economic Area and wish to contact the supervisory authority responsible for overseeing our compliance with the GDPR, you may do so through your local data protection authority. A directory of EU data protection authorities is available on the European Data Protection Board website. For Brazil, the supervisory authority is the Autoridade Nacional de Proteção de Dados (ANPD).

We always prefer the opportunity to resolve any concern directly and informally before you escalate to a supervisory authority, so please do reach out to us first — we are genuinely committed to getting this right.

Questions or Requests

Your privacy matters — let's talk

Whether you want to understand how we use your data, request a copy of what we hold, or simply have a question about our practices — we're here and happy to help. No automated responses, no runaround: a real person will reply.

Or email us directly at [email protected]