Legal & Compliance

Privacy Policy

At Usina Inteligência Artificial, protecting the privacy of everyone who interacts with our website and services is not a legal checkbox — it is a core responsibility we take seriously. This policy explains precisely what personal data we collect, why we collect it, how we use and safeguard it, and what rights you hold over it.

Last updated: 18 July 2025
Effective date: 18 July 2025
Applies to: usinaia.site
01

Introduction

USINA INTELIGENCIA ARTIFICIAL LTDA (CNPJ 67.993.093/0001-73), trading as Usina.Ia, is a company headquartered at Rua Rocha Lagoa, 92, Sala 01, Cachoeirinha, Belo Horizonte — MG, Brazil. We develop and commercialise artificial intelligence solutions, automation pipelines, and strategic AI consulting services for businesses across Brazil and abroad.

This Privacy Policy governs the collection, use, storage, and disclosure of personal data by Usina.Ia through our institutional website at usinaia.site and any related sub-pages. It applies to visitors, prospective clients, partners, and any other individual whose data reaches us through their interaction with our online presence.

We are committed to full compliance with Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018), the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), and any other applicable data-protection legislation. Where the two frameworks overlap, we apply the higher standard of protection.

This is an institutional website. We do not operate an e-commerce store, a client portal, or any application that requires you to create an account. Personal data collected through this site is strictly limited to what is necessary for us to communicate with you and improve the website experience.

By accessing our website, you acknowledge that you have read and understood this policy. If you do not agree with any of its terms, please discontinue use of the site and contact us at the address provided in Section 11 with any questions before proceeding.

02

Information We Collect

We collect personal data only to the extent strictly necessary for the purposes described in this policy. The categories of data we may process are outlined below, together with the context in which each arises.

Contact & enquiry data Provided directly by you
When you reach out to us by email or through any contact channel listed on this site, we receive your name, email address, telephone number (if provided), the name of your company or organisation, and the content of your message. We may also receive data attached to that communication — for example, a brief describing a project you wish to discuss.
Technical & device data Collected automatically
When you visit usinaia.site, our web server and analytics tools automatically record your IP address (truncated where possible), browser type and version, operating system, referring URL, device type (desktop, tablet, mobile), screen resolution, preferred language settings, and the pages you visit together with the time and duration of each visit.
Cookie & tracking data Collected automatically
We use cookies and similar technologies to understand how visitors navigate the site, measure the effectiveness of marketing campaigns, and personalise content where appropriate. Specific cookies and their purposes are described in detail in Section 4. You may manage cookie preferences through your browser settings at any time.
Analytics & usage data Collected via third-party tools
Aggregated data about how visitors interact with our pages — such as which sections attract the most attention, which CTAs are clicked, and how users flow through the site — is collected through Google Analytics and Google Ads conversion tracking. This data is predominantly anonymised and is used exclusively to improve site quality and marketing relevance.

We do not collect sensitive personal data (also known as special-category data under GDPR and LGPD), such as health records, biometric identifiers, racial or ethnic origin, religious beliefs, or political opinions. We also do not purchase third-party data lists or compile user profiles from external sources.

03

How We Use Your Information

Every piece of personal data we hold is used only for a defined, legitimate purpose. The table below maps data categories to the purposes we pursue and the legal basis under which we process them (Article 6 GDPR; Articles 7–10 LGPD):

Responding to enquiries and communications: When you contact us by email or any equivalent channel, we use the data you provide to understand your enquiry and reply in a timely, relevant manner. Legal basis: performance of a pre-contractual measure at your request; legitimate interest.

Assessing service suitability: Contact data and any project details you share allow our team to evaluate whether our AI solutions match your needs and to prepare an appropriate initial response or proposal. Legal basis: legitimate interest; pre-contractual steps.

Improving website performance and user experience: Aggregated analytics data helps us understand which content is valuable, identify navigation problems, and continually refine the site. Legal basis: legitimate interest (where data is anonymised or pseudonymised).

Marketing and advertising measurement: We use Google Ads conversion tracking to understand which campaigns bring qualified visitors to our site. This allows us to allocate our marketing budget responsibly and avoid irrelevant outreach. Legal basis: consent (where required by law); legitimate interest.

Legal compliance and record-keeping: We may be required by law or regulatory authority to retain certain records — for example, communication logs relevant to a dispute or a regulatory enquiry. Legal basis: compliance with a legal obligation.

Security and fraud prevention: IP address logs and server data are retained for a short period to detect and respond to suspicious activity, brute-force attempts, or other threats to site integrity. Legal basis: legitimate interest; legal obligation.

We will never use your personal data for automated decision-making that produces legal or similarly significant effects on you, nor will we use it for purposes incompatible with those stated here without first obtaining your explicit consent or another valid legal basis.

04

Cookies & Tracking Technologies

Cookies are small text files placed on your device by a web server when you visit a site. They help the site function correctly, remember your preferences, and gather aggregated information about how visitors use the site. We use the following categories of cookies on usinaia.site:

Google Analytics is configured with IP anonymisation enabled, which means the last octet of your IP address is masked before any processing occurs within Google's infrastructure. We do not use the User ID feature and have disabled data sharing with Google signals for advertising personalisation by default.

Google Ads conversion tracking places cookies when a user arrives at our site from a Google Ads advertisement, allowing us to measure whether that visit results in a meaningful action (such as navigating to our contact page). The data is reported in aggregate and is not linked back to identifiable individuals on our end.

Managing cookies: You may at any time change your browser settings to refuse all cookies, accept only specific categories, or delete cookies already stored on your device. Please note that disabling performance or marketing cookies may affect how you experience the site and may reduce the relevance of any advertising you see elsewhere. Detailed instructions for managing cookies are available from your browser's help documentation (Chrome, Firefox, Safari, Edge).

Do-Not-Track signals: Our website currently does not alter its behaviour in response to browser Do-Not-Track headers, as there is no universally agreed standard for how websites should interpret these signals. If this changes, we will update this section accordingly.
05

Sharing With Third Parties

We do not sell, rent, or trade your personal data to any third party. We will never share your information with companies seeking to market unrelated products or services to you. We do, however, share data with a small number of carefully selected sub-processors and service providers that are essential to operating this website:

Google LLC
Provider of Google Analytics (audience measurement) and Google Ads (campaign performance). Data is transferred to Google's servers pursuant to Standard Contractual Clauses and Google's Data Processing Terms. Google is certified under the EU–US Data Privacy Framework. Privacy policy: policies.google.com/privacy.
Hosting provider
Our website is hosted on infrastructure managed by a third-party cloud provider. Server logs — including truncated IP addresses and request metadata — are processed on their servers. We select hosting partners that offer appropriate technical and contractual data-protection guarantees.
Email service provider
Emails you send to contato@usinaia.site are received and stored through our email infrastructure provider. Message content and your contact details are transmitted over encrypted channels (TLS) and retained only as long as necessary to handle your enquiry.

All third-party processors are bound by data-processing agreements that require them to process personal data only on our documented instructions, maintain appropriate security measures, and not engage additional sub-processors without our prior consent.

Beyond the providers listed above, we may disclose personal data if and to the extent required by applicable law, a binding court order, or a request from a competent public authority — in which case we will, where legally permitted, notify you before complying. We may also disclose data to enforce our legal rights or to protect the safety and security of our users, staff, or systems.

In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity, provided that the successor is bound by equivalent privacy protections. We will notify you of any such change via a prominent notice on this website.

06

Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required to meet legal, regulatory, or contractual obligations. Our default retention periods are as follows:

Contact enquiry data (name, email, message content) is retained for up to 24 months from the date of last meaningful interaction. This timeframe allows us to maintain continuity in business conversations, refer back to prior discussions, and fulfil any contractual obligations that may arise. If no business relationship develops within this period, the data is securely deleted or anonymised.

Website analytics data collected via Google Analytics is governed by the retention settings we have configured within Google's platform — currently set to 14 months for user-level and event-level data, after which it is automatically purged. Aggregated, anonymised reporting data may be retained indefinitely as it cannot be linked to any individual.

Server logs containing IP addresses and request metadata are retained for 90 days for security purposes, after which they are deleted. Logs associated with identified security incidents may be retained for up to 12 months in connection with investigations.

Cookie consent records are retained for 12 months or until you withdraw consent, in order to demonstrate compliance and avoid repeatedly showing consent prompts to returning visitors.

At the end of each applicable retention period, data is either securely and irreversibly deleted from active systems and backups, or anonymised such that it can no longer be linked to any identified or identifiable individual. You may also request deletion at any time, subject to the exceptions described in Section 8.

07

Data Security

We implement a combination of technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures are reviewed and updated as technology and risk landscapes evolve.

In transit: All data transmitted between your browser and our web server is encrypted using TLS 1.2 or higher (HTTPS). Our email infrastructure enforces opportunistic TLS for message delivery between servers. We do not transmit unencrypted personal data over public networks.

At rest: Data stored on our hosting infrastructure is protected by access controls that restrict it to authorised personnel only, on a strict need-to-know basis. We do not store payment card data or government-issued identification numbers on our own systems at any point.

Organisational controls: Access to systems holding personal data is limited to Usina.Ia team members whose role specifically requires it. All such personnel are bound by confidentiality obligations and receive awareness training on data-protection responsibilities.

Incident response: In the unlikely event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority (ANPD in Brazil; the competent EU authority where applicable) within 72 hours of becoming aware of the breach, and will inform affected individuals without undue delay where the risk is assessed as high. Our incident-response procedures are documented and tested on a regular basis.

Important: No method of electronic transmission or storage is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and secure connections when communicating with us.
08

Your Rights

Depending on your country of residence, applicable law grants you a number of rights in relation to the personal data we hold about you. Under both the LGPD (Article 18) and the GDPR (Articles 15–22), these rights include:

🔍

Right of Access

You may request a copy of the personal data we hold about you, along with information about how it is being processed and the legal basis for doing so.

✏️

Right to Rectification

If any data we hold about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.

🗑️

Right to Erasure

You may request the deletion of your personal data where it is no longer necessary, where consent has been withdrawn, or where processing is unlawful — subject to legal retention obligations.

⏸️

Right to Restriction

You may ask us to restrict the processing of your data — for example, while we investigate a dispute about its accuracy or the lawfulness of our processing.

📦

Right to Portability

Where processing is based on consent or contract and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format.

🚫

Right to Object

You may object at any time to processing based on legitimate interest, including processing for direct marketing purposes. Upon receiving an objection, we will cease processing unless we demonstrate compelling legitimate grounds.

🔔

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

⚖️

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority — the ANPD (anpd.gov.br) in Brazil, or your relevant EU data-protection authority — if you believe we are processing your data unlawfully.

How to exercise your rights: To make a rights request, please send an email to contato@usinaia.site with the subject line "Data Subject Request" and include: your full name, the email address associated with your data, a clear description of your request, and — if we need to verify your identity — a means by which we can do so. We will acknowledge your request within five business days and respond fully within 30 days (extendable by a further 60 days in complex cases, with notice). There is no fee for making a rights request unless it is manifestly unfounded or excessive.

Please note that certain rights are not absolute. For example, we may be unable to delete data that we are legally required to retain, or that is necessary to establish, exercise, or defend legal claims. We will always explain clearly if and why an exemption applies to your specific request.

09

Children's Privacy

Usina.Ia's website and services are directed exclusively at businesses and adult professionals. We do not knowingly collect, process, or store personal data from individuals under the age of 18. Our content is not targeted at minors, and we take no deliberate steps to attract or engage with children under this age threshold.

If you are a parent or guardian and believe that a minor for whom you are responsible has provided us with personal data — for instance, by emailing our contact address — please notify us immediately at contato@usinaia.site. Upon verification, we will promptly delete any such data from our systems. We process data relating to children, where it incidentally comes to our attention, on the basis of a legal obligation and solely for the purpose of deletion.

Under the LGPD, the processing of personal data of children requires the specific and highlighted consent of at least one parent or legal guardian, and must occur in the child's best interest. This site is not designed or intended to serve children in any capacity, and no product or service offered by Usina.Ia is directed at individuals under 18.

10

Changes to This Policy

We may revise this Privacy Policy from time to time to reflect changes in our data processing practices, updates to applicable law, new services or website features, or feedback from supervisory authorities. When we make material changes, we will update the "Last updated" date at the top of this page and, where the changes are significant, we will provide a more prominent notice — such as a banner on the homepage or, where we have your email address and it is appropriate to do so, a direct notification.

We encourage you to review this page periodically. Continued use of usinaia.site after any revisions have been published constitutes your acknowledgement that you have had the opportunity to review the updated policy. If you disagree with any changes, please discontinue use of the site and contact us as described in Section 11.

Previous versions of this Privacy Policy are available upon request. Please email contato@usinaia.site with the subject line "Previous Privacy Policy Version" and we will provide the applicable historical version for your reference.

11

Contact & Data Controller

The data controller responsible for your personal data under this Privacy Policy is USINA INTELIGENCIA ARTIFICIAL LTDA. If you have questions about this policy, wish to exercise your rights, or have concerns about how your data is being handled, please reach out to us through the details below. We aim to respond to all privacy-related enquiries within five business days.

Data Controller Details

🏢
Company name USINA INTELIGENCIA ARTIFICIAL LTDA
🪪
CNPJ 67.993.093/0001-73
📍
Registered address Rua Rocha Lagoa, 92, Sala 01, Cachoeirinha, Belo Horizonte — MG, Brazil
✉️
Privacy enquiries & data requests contato@usinaia.site
⏱️
Response time We endeavour to acknowledge all privacy-related correspondence within 5 business days and to resolve requests fully within 30 days.

If you are located in the European Union and are unsatisfied with our response to a privacy complaint, you have the right to escalate the matter to the supervisory authority in your country of residence. A list of EU data-protection authorities is available at edpb.europa.eu. If you are located in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at anpd.gov.br.