Privacy Policy
Last updated: May 6, 2026
1. Introduction
Yowpi Tech Ltda, enrolled with the Brazilian company registry (CNPJ) under No. 48.579.987/0001-77, headquartered in São Paulo/SP, Brazil ("Yowpi Tech", "we", "us" or "our"), is the controller responsible for the processing of the personal data described in this Privacy Policy.
This policy explains how we collect, use, store, share, and protect your personal data when you access our website or use our systems engineering consulting services.
This document was drafted in compliance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados — LGPD, Law No. 13,709/2018), the Brazilian Internet Civil Framework (Marco Civil da Internet — Law No. 12,965/2014), and other applicable rules of the Brazilian legal system.
2. Data We Collect
2.1 Data you provide
When you fill out the contact form on our website, you voluntarily provide us with the following data:
- Identification data: full name, email address, and phone number.
- Company data: company name, size (number of employees), and website (optional).
- Project data: budget range, project stage (new or existing), and a descriptive message (optional).
- Attachments: files you upload (up to 10 files, maximum of 10 MB each) in PDF, image (PNG, JPEG, WebP), Office document (Word, Excel, PowerPoint), ZIP, and plain-text formats.
- Scheduling: the date and time chosen for the diagnostic session.
- Consent: confirmation that you have read and agree to this Privacy Policy and our Terms of Use.
2.2 Data collected automatically
When you access our website and submit the contact form, we automatically collect:
- IP address (anonymized): we store only a partial cryptographic hash (SHA-256, 32 characters) of your IP address. We do not store the full IP.
- User-Agent: information about the browser and operating system used to access the website.
- UTM parameters: traffic-source data (source, medium, and campaign), when present in the access URL.
3. Purposes of Processing
We use your personal data for the following purposes:
- Scheduling and conducting the diagnostic session: your identification and contact data are used to schedule, prepare, and conduct the consulting session.
- Preparing the diagnostic: company and project data allow us to understand your context before the session, ensuring a more relevant service.
- Reviewing materials: the attachments you send are reviewed internally as part of the preparation for the diagnostic session.
- Communication: we send scheduling confirmation emails and, when necessary, follow-up related to the requested session.
- Security and fraud prevention: the IP hash and User-Agent are used to identify abuse, prevent spam (honeypot mechanism), and safeguard the integrity of the service.
- Traffic-source analysis: UTM parameters help us understand which marketing channels are most effective, without identifying you individually.
4. Legal Bases
Your personal data is processed on the following legal bases provided for in Article 7 of the LGPD:
- Consent (Art. 7, I): by filling out the contact form and checking the consent box, you expressly authorize the processing of the data provided for the purposes described in this policy. You may withdraw this consent at any time.
- Performance of a contract or preliminary procedures (Art. 7, V): data processing is necessary to enable the provision of the consulting service you requested.
- Legitimate interest of the controller (Art. 7, IX): we use technical data (IP hash, User-Agent) for security, fraud prevention, and service improvement purposes, always respecting your fundamental rights and freedoms.
5. Sharing with Third Parties
To deliver our services, we share your data with the following processors (service providers):
- Supabase Inc. (USA): cloud database and storage platform. Stores your registration data and the files attached to the form.
- Cal.com Inc. (USA): scheduling platform. Receives your name, email, phone number, and company data to create and manage the session booking.
- Resend Inc. (USA): email delivery service. Processes the sending of scheduling confirmation emails and internal notifications.
- Vercel Inc. (USA): website hosting platform. Processes web requests and has access to request headers (including IP and User-Agent) during processing.
All processors listed act under our instructions and are contractually required to protect your personal data. We do not sell or share your data with third parties for marketing purposes.
6. International Data Transfers
The processors listed in the previous section are headquartered in the United States of America. Your personal data is therefore transferred internationally to servers located outside Brazil.
This transfer is carried out in compliance with Article 33 of the LGPD and relies on the following safeguards:
- Encryption in transit (TLS/HTTPS) for all communications.
- Contractual clauses requiring the processors to maintain a level of protection compatible with the LGPD.
- Exclusive use of providers with public privacy policies and recognized security certifications.
7. Data Retention
Your personal data is retained for the period necessary to fulfill the purposes described in this policy, subject to the following timeframes:
- Lead data (contact form): retained for up to 2 (two) years from the date of collection, after which it will be deleted from our database.
- Attachments (uploaded files): retained for the same period as lead data. Temporary access URLs to the files expire automatically after 7 (seven) days.
- Technical data (IP hash, User-Agent): retained with the lead record, for the same 2-year period.
At the end of the retention period, or upon a valid deletion request, the data will be removed securely and permanently, except where there is a legal obligation to retain it.
8. Data Security
We adopt technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in transit: all traffic between your browser and our servers is protected by HTTPS/TLS.
- Partial IP anonymization: your IP address is converted into a partial cryptographic hash before storage. The hash cannot be reversed to obtain the original IP.
- Database access control: Row Level Security policies restrict access to the records.
- Signed URLs for attachments: uploaded files can only be accessed through temporary URLs valid for 7 days, preventing direct public access.
- Segregated access keys: database administration credentials are not exposed to the user's browser.
- Spam protection: honeypot mechanism to detect and discard automated submissions.
9. Data Subject Rights
Under the LGPD, you have a series of rights regarding your personal data, including the right to access, correct, delete, and request the portability of your data.
For a complete description of your rights and instructions on how to exercise them, see our LGPD page.
10. Cookies and Tracking Technologies
Our website does not use cookies for tracking or behavioral analytics.
The only local storage technology we use is the browser's localStorage, exclusively to save your visual theme preference (light or dark mode). This information stays on your device only and is not transmitted to our servers or shared with third parties.
We do not use tracking pixels, third-party analytics scripts, or any fingerprinting technologies.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices or in legal obligations. When that happens, the "last updated" date at the top of this page will be revised.
We recommend that you review this page periodically. Continued use of the website after changes are published constitutes your awareness of and agreement to the updated version.
12. Contact
To exercise your rights, ask questions, or make requests related to the processing of your personal data, contact our Data Protection Officer (DPO):
- Officer: Marlon Trettin
- Email: contact@yowpi.com
- Company: Yowpi Tech Ltda — CNPJ 48.579.987/0001-77
- Headquarters: São Paulo/SP, Brazil