Privacy Policy
OSIT Tecnologia da Informação (Brazilian taxpayer ID 54.339.752/0001-00), headquartered at Avenida Queiroz Júnior, 135, 4th floor, Suite 01, Itabirito/MG, Brazil (“OSIT”, “we”, “us”), acts as the Data Controller for personal data processed through this website and related channels. We comply with Brazilian Federal Law 13.709/2018 — the General Data Protection Law (LGPD) — and apply GDPR-grade practices for international visitors.
This Policy explains, in plain language, what data we process, on what legal basis, for which purposes, how long we keep it, with whom we share it, how we secure it, and how you can exercise your rights.
1. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Sensitive personal data: data on racial or ethnic origin, religious belief, political opinion, union membership, health, sex life, genetic or biometric data.
- Data subject: the natural person to whom the personal data relates.
- Processing: any operation performed on personal data (collection, storage, use, sharing, deletion, etc.).
- Controller: the party that decides on the processing — in this case, OSIT.
- Processor: the party that processes data on behalf of the Controller.
- DPO (Data Protection Officer): the contact between Controller, data subjects and the Brazilian Data Protection Authority (ANPD).
2. Data we collect
2.1 Standard personal data
- Identification and contact: name, email, phone, company, role.
- Message content: information sent through contact forms, WhatsApp or email.
- Browsing data: IP address, device identifiers, OS, browser, pages visited, referrer, date/time, anonymous usage metrics.
- Contractual and tax data (clients and suppliers): legal name, taxpayer ID, banking details, invoices, contracts.
2.2 Sensitive data
As a rule, OSIT does not collect sensitive data through this website. Where sensitive data is required for specific corporate projects (e.g., biometrics for physical access control), processing relies on a specific legal basis under Article 11 of the LGPD, governed by contract and reinforced security controls, with OSIT acting as Processor for the client Controller.
2.3 Children and minors
This website is intended for a corporate (B2B) audience and is not directed to children or adolescents. We do not knowingly collect data from anyone under 18. Any incidental processing will occur solely in the minor's best interest and only with specific, prominent consent from a parent or legal guardian. Guardians may request immediate deletion via the channel in section 9.
3. Purposes and legal bases
- Responding to commercial inquiries and support — legal basis: pre-contractual steps and legitimate interest (B2B leads).
- Performance of contracts and service delivery — legal basis: contract performance and compliance with legal/regulatory obligations (tax, labor, corporate).
- Analytics cookies and usage metrics (Google Analytics) — legal basis: consent, captured via the cookie banner. Not active without consent.
- Strictly necessary cookies (session, preferences, security) — legal basis: legitimate interest, essential to operate the site.
- Information security, fraud and abuse prevention (access logs, IP, user-agent) — legal basis: legitimate interest and legal obligation (Brazilian Internet Civil Framework, art. 15 — 6-month log retention).
- Marketing and content communications — legal basis: consent, revocable at any time via unsubscribe link.
- Defense in administrative, judicial or arbitral proceedings — legal basis: regular exercise of rights.
4. Retention
- Commercial inquiries: up to 24 months after last contact.
- Contractual and tax data: minimum 5 years after contract termination, per Brazilian tax and civil law.
- Access logs: 6 months (Brazilian Internet Civil Framework).
- Analytics cookies: per provider policy (Google Analytics — up to 14 months by default).
- Consent-based data: until revocation, except when retention is required by law.
After the retention period, data is securely deleted or anonymized.
5. Sharing with third parties
OSIT does not sell personal data. We share only with vendors under written confidentiality, security and LGPD-compliance obligations:
- Cloud infrastructure and hosting providers (with adequate cross-border safeguards).
- Analytics tools (Google Analytics — consent-based).
- Transactional email and communication services.
- Bot/abuse mitigation (Cloudflare Turnstile).
- Internal CRM/ERP systems.
- Public, regulatory or judicial authorities, when legally required.
- Partners directly involved in delivering contracted services.
5.1 International transfers
Some processors may be located outside Brazil. Transfers occur only to countries with an adequate level of protection or under safeguards set forth in Article 33 of the LGPD (Standard Contractual Clauses, binding corporate rules, or specific consent where applicable). For EEA/UK visitors, transfers rely on GDPR Article 46 SCCs where applicable.
6. Cookies
Cookie usage is detailed in our Cookie Policy. You can accept, reject or customize preferences any time via the “Cookie settings” button in the site footer.
7. Security
OSIT is a cybersecurity and critical infrastructure firm and applies the same standards we deliver to clients, aligned with ISO/IEC 27001, NIST CSF and CIS Controls:
- Encryption in transit (HTTPS/TLS 1.2+) and at rest for sensitive data.
- Role-based access control (RBAC), least privilege, multi-factor authentication (MFA).
- Environment segregation (development, staging, production).
- 24/7 monitoring, vulnerability management and timely patching.
- 3-2-1 backup strategy and documented BCP/DRP.
- Server hardening, next-gen firewalls and DDoS protection.
- Audit trails with the minimum legal retention.
- Recurring security awareness training.
- NDAs with employees and vendors.
8. Security incidents
If an incident is likely to cause relevant risk or harm to data subjects, OSIT will notify affected subjects and the ANPD within a reasonable timeframe under ANPD Resolution CD/ANPD 15/2024, including the information required by the authority (data nature, subjects affected, technical safeguards and mitigation measures).
9. Your rights
Under LGPD Article 18 — and consistent with GDPR Articles 15–22 — you may, free of charge:
- Confirm the existence of processing.
- Access your data.
- Correct incomplete, inaccurate or outdated data.
- Request anonymization, blocking or deletion of unnecessary or non-compliant data.
- Port data to another provider (subject to trade secret protections).
- Delete consent-based data.
- Be informed about entities with which data was shared.
- Be informed about the option to withhold consent and its consequences.
- Withdraw consent at any time.
- Request review of automated decisions, where applicable.
How to exercise: email privacidade@ositcorp.com.br with your full name, contact email and a description of your request. We will respond within 15 days, and may request additional information to verify your identity.
10. Data Protection Officer (DPO)
OSIT has appointed a DPO, reachable at dpo@ositcorp.com.br. Postal address: Avenida Queiroz Júnior, 135, 4th floor, Suite 01, Itabirito/MG, ZIP 35450-000, Brazil — Attn: Data Protection Officer.
11. Brazilian Data Protection Authority
If you believe your request has not been properly addressed, you may file a complaint with the ANPD at gov.br/anpd.
12. Changes to this policy
This Policy may be updated to reflect legal, regulatory or operational changes. The current version is the one published on this page, with the last-updated date shown at the top. Material changes will be highlighted on the site.
13. Contact
General inquiries: contato@ositcorp.com.br · Privacy: privacidade@ositcorp.com.br · DPO: dpo@ositcorp.com.br.
