Privacy Policy

We are committed to protecting your personal information and being transparent about how we handle it. This document explains our data practices in plain, honest language.

Last updated: 19 June 2025

Introduction

VIRTIS SOLUCOES EM TECNOLOGIA LTDA ("Virtis", "we", "us" or "our") operates the website virtus-ts.site and provides information technology services, infrastructure management, software solutions and technical support to clients across Brazil and internationally.

We respect your privacy and understand that personal data is an asset you entrust to us. This Privacy Policy describes the categories of personal data we collect, the purposes for which we process it, the parties with whom we may share it, the rights available to you under applicable law, and the steps we take to keep your information safe.

This policy applies to all personal data collected through our website, through any email correspondence you initiate with us, and through the delivery of our professional services. It does not apply to the internal IT systems, products or services that we manage on behalf of our corporate clients under separate data-processing agreements.

Applicable legal frameworks: This policy has been prepared to comply with the Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13,709/2018) of Brazil, the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), and any other national privacy legislation that may apply to visitors accessing this site from other jurisdictions. Where requirements overlap, we apply the stricter standard.

By continuing to use our website or contacting us through any channel listed on this site, you acknowledge that you have read and understood this policy. If you do not agree with the practices described herein, please refrain from using this website.

Information We Collect

We collect only the personal data that is reasonably necessary for the purposes described in this policy. We distinguish between information you actively provide to us and information collected automatically when you use our website.

2.1 — Information You Provide Directly

When you choose to reach out to us via the contact details published on this website (email, phone or postal address), you may provide us with:

  • Full name — so we can address you properly in correspondence.
  • Business email address — to respond to your enquiry.
  • Company name and professional role — to understand the context of your enquiry and route it to the right member of our team.
  • Phone number — if you provide one voluntarily when contacting us by email.
  • Content of your communication — the subject matter, questions, or documents you share with us in the course of a pre-sales or client-support conversation.

We do not operate any online forms or portals on this website. All contact is initiated by you through external channels (email, phone, or in person).

2.2 — Information Collected Automatically

When you visit virtus-ts.site, our hosting infrastructure and analytics tools automatically record certain technical information:

  • IP address — used to diagnose server issues and generate aggregated geographic statistics.
  • Browser type and version, operating system — to ensure the site renders correctly across devices.
  • Referring URL and exit page — to understand how visitors discover and navigate our site.
  • Pages visited and time spent on each page — to measure content relevance and identify technical issues.
  • Device type (desktop, tablet, mobile) — to prioritise responsive design improvements.
  • Cookie identifiers and session tokens — described in detail in Section 4.

This technical data is collected passively and is generally non-identifying on its own; however, in combination with other data it may constitute personal data under LGPD and GDPR, and we treat it accordingly.

How We Use Your Information

We process personal data only when we have a lawful basis to do so. Depending on the nature of the processing activity, we rely on one or more of the following legal bases: your consent, the performance of a contract or pre-contractual steps at your request, compliance with a legal obligation, or our legitimate interests — provided those interests are not overridden by your rights.

Specifically, we use the information we collect for the following purposes:

  • Responding to enquiries: We use your name, email address and communication content to provide timely, accurate responses to questions about our services, pricing, and technical capabilities. Our legal basis is legitimate interests (responding to commercial enquiries) and, where applicable, pre-contractual steps.
  • Service delivery and client onboarding: Where our correspondence progresses toward a service engagement, we use contact and company information to prepare proposals, service agreements and onboarding documentation. Our legal basis is the performance of a contract.
  • Website analytics and improvement: We use aggregated, pseudonymised technical data to understand how our website is used, identify underperforming pages, and prioritise development efforts. Our legal basis is legitimate interests, provided the analysis does not identify individual users without their consent.
  • Security and fraud prevention: IP addresses and access logs are reviewed when we detect unusual patterns that may indicate malicious activity, automated scraping, or attempted intrusions against our infrastructure. Our legal basis is legitimate interests and, where applicable, legal obligation.
  • Legal and regulatory compliance: We may process and retain data to fulfil obligations under Brazilian corporate law, tax regulations, labour law, or in response to lawful orders from public authorities.
  • Direct marketing communications: Only if you have explicitly requested to receive updates from us. We do not send unsolicited marketing emails, and every such communication includes a clear unsubscribe mechanism.
We do not use your personal data to build behavioural profiles for third-party advertising, nor do we sell your data to any data broker, advertising network or marketing platform. Our business model is built on professional services — not on monetising visitor data.

Cookies & Tracking Technologies

Cookies are small text files stored on your device by your browser when you visit a website. They enable core functionality, help us understand how the site is used, and allow third-party tools to operate correctly. We use the following categories of cookies on virtus-ts.site:

  • Strictly necessary cookies: These are essential for the website to function and cannot be disabled. They do not store any personally identifiable information. Examples include session identifiers that maintain the integrity of your browsing session and security tokens that protect against cross-site request forgery.
  • Analytical / performance cookies: We use Google Analytics (operated by Google LLC) to collect pseudonymised data about how visitors interact with our pages — including which pages are viewed most frequently, session duration, and approximate geographic region. Google Analytics sets cookies (including _ga, _gid and _gat) that persist for up to 24 months. Data is transferred to Google servers; where EU/EEA data subjects are involved, Standard Contractual Clauses apply. You may opt out of Google Analytics across all websites using the Google Analytics Opt-out Browser Add-on.
  • Functionality cookies: These remember preferences such as language or region settings to improve your experience on repeat visits. They do not track you across other websites.
  • Third-party cookies (advertising measurement): If we run Google Ads campaigns, Google may set conversion-measurement cookies on your device after you click an advertisement. These cookies help us measure whether a click led to a meaningful interaction with our site. They do not create advertising profiles or follow you across unrelated websites. You can control ad personalisation through Google's Ad Settings or through your browser's cookie management tools.

Managing your cookie preferences: Most modern browsers allow you to view, block or delete cookies through your browser settings. Disabling strictly necessary cookies may affect the functionality of this website, but disabling analytical or advertising cookies will have no impact on the information presented to you. You may also use the following mechanisms:

  • Your browser's built-in privacy settings (Chrome, Firefox, Safari, Edge all offer cookie management interfaces).
  • The Network Advertising Initiative opt-out page at optout.networkadvertising.org.
  • The Digital Advertising Alliance's opt-out tool at aboutads.info/choices.
  • The European Interactive Digital Advertising Alliance tool at youronlinechoices.eu.

Do-Not-Track (DNT) signals transmitted by browsers are noted by our system; however, as there is no universal standard for interpreting DNT signals, our response may vary. We encourage users who wish to limit tracking to use the cookie controls described above.

Sharing With Third Parties

We do not sell, rent or trade your personal data. We share personal data with third parties only in the limited circumstances described below, and always subject to contractual data-protection obligations consistent with LGPD and GDPR requirements.

  • Technology and hosting providers: Our website and business systems are hosted on infrastructure operated by contracted third parties (including cloud hosting providers). These providers process data on our behalf as data processors and are bound by data-processing agreements that prohibit them from using your data for their own purposes.
  • Google LLC (analytics and advertising measurement): As described in Section 4, Google Analytics and Google Ads measurement tools may receive pseudonymised usage data. Google acts as a data processor for analytics purposes and as an independent data controller for its own advertising platform. Google's privacy policy is available at policies.google.com/privacy.
  • Professional advisors: We may share data with our legal counsel, external accountants or auditors where necessary to obtain professional advice or to comply with legal requirements. These parties are bound by confidentiality obligations.
  • Regulatory and law-enforcement authorities: We will disclose personal data to competent courts, regulators (including the Brazilian Autoridade Nacional de Proteção de Dados — ANPD), law enforcement agencies, or other governmental bodies when required to do so by law, or when we have a good-faith belief that disclosure is necessary to protect the rights, property or safety of Virtis, our clients or the public.
  • Business transactions: If Virtis undergoes a merger, acquisition, corporate restructuring or sale of assets, personal data held by us may be transferred to the successor entity as part of that transaction. In such an event, we will notify affected individuals and ensure the successor is bound by obligations at least as protective as those described in this policy.

Any third party that receives personal data from us is required to implement appropriate technical and organisational measures to protect that data, and to use it only for the specific purpose for which it was shared.

Data Retention

We retain personal data for no longer than is necessary to fulfil the purpose for which it was collected, or to comply with our legal, accounting and regulatory obligations. Our general retention guidelines are as follows:

  • Pre-sales correspondence (enquiries that did not lead to a contract): Retained for up to 24 months from the date of last contact, after which it is securely deleted or anonymised, unless a longer period is required by law.
  • Client correspondence and service-delivery records (active or concluded contracts): Retained for a minimum of 5 years following the end of the contractual relationship, in accordance with Brazilian civil law (Lei No. 10,406/2002) and tax record-keeping obligations.
  • Financial and invoicing records: Retained for 10 years to meet Brazilian tax authority requirements under the Código Tributário Nacional.
  • Website server logs and IP addresses: Retained for up to 12 months for security and diagnostic purposes, consistent with Article 15 of Brazil's Marco Civil da Internet (Law No. 12,965/2014).
  • Analytics data (Google Analytics): Pseudonymised data is retained at the analytics platform level for up to 26 months before automatic deletion, as configured in our Google Analytics account settings.
  • Marketing consent records: Where you have consented to receive communications from us, a record of that consent is retained for the duration of the marketing relationship and for 36 months after withdrawal of consent, to demonstrate compliance.

At the end of the applicable retention period, personal data is either permanently deleted, securely destroyed, or irreversibly anonymised so that it can no longer be linked to an identifiable individual.

Data Security

As an information technology company, data security is not merely a compliance requirement for us — it is a professional standard we hold ourselves to at the highest level. We implement a layered set of technical and organisational measures to protect personal data against unauthorised access, accidental loss, disclosure, alteration or destruction.

  • Encryption in transit: All data exchanged between your browser and virtus-ts.site is protected by TLS 1.2 or higher (HTTPS). We enforce HSTS (HTTP Strict Transport Security) to prevent protocol downgrade attacks.
  • Encryption at rest: Personal data stored on our systems and on contracted cloud infrastructure is encrypted at rest using industry-standard algorithms.
  • Access control and least-privilege principles: Access to systems and data is granted only to employees and contractors who require it to perform their job functions. All access is authenticated via multi-factor authentication (MFA) and logged for audit purposes.
  • Vulnerability management: We operate regular patch cycles, conduct periodic security reviews of our own infrastructure and website, and employ firewall, intrusion-detection and endpoint-protection technologies.
  • Employee training: All Virtis personnel who handle personal data receive privacy and information-security training at onboarding and on a regular ongoing basis.
  • Incident response: We maintain a documented data-breach response procedure. In the event of a security incident that poses a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority (ANPD and/or applicable EU data-protection authority) within 72 hours of becoming aware, and will notify affected individuals without undue delay where required by law.
Despite our best efforts, no method of electronic transmission or storage is completely secure. While we strive to apply commercially reasonable and technically sophisticated protections, we cannot guarantee absolute security. If you believe your personal data may have been compromised through any interaction with us, please contact us immediately at contato@virtus-ts.site.

Your Rights

Depending on your country or region of residence, you have specific rights over your personal data. Under Brazil's LGPD (Article 18) and the EU's GDPR (Articles 15–22), individuals are entitled to the rights summarised below. We are committed to honouring all valid requests in a timely and transparent manner.

Right of Access

You may request confirmation of whether we hold personal data about you, and a copy of that data, together with information about how and why it is processed.

Right to Rectification

If the personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected or supplemented without undue delay.

Right to Deletion (Erasure)

You may request the deletion of your personal data where it is no longer necessary for the purpose collected, where consent has been withdrawn, or where processing lacks a lawful basis. Note that certain legal obligations may require us to retain specific records.

Right to Object

Where we process your data on the basis of legitimate interests, you may object to that processing. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Right to Restriction

In certain circumstances (e.g., while the accuracy of data is contested), you may request that we restrict active processing of your data while retaining it.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may request receipt of your data in a structured, machine-readable format for transfer to another controller.

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right Not to Be Subject to Automated Decisions

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. This right is therefore not materially engaged by our current processing activities.

How to exercise your rights: To submit a request to exercise any of the rights listed above, please contact our privacy team by email at contato@virtus-ts.site, with the subject line "Privacy Rights Request". Please include your full name, the email address associated with your data, and a clear description of the right you wish to exercise. We will respond within 15 business days (LGPD standard) or 30 calendar days (GDPR standard), with the possibility of a single 60-day extension where requests are complex or numerous, in which case we will inform you of the extension and the reasons for it.

You also have the right to lodge a complaint with a supervisory authority. In Brazil, this is the Autoridade Nacional de Proteção de Dados (ANPD)www.gov.br/anpd. In the EU/EEA, you may contact the data-protection authority of your member state of habitual residence.

We will never penalise you for exercising your privacy rights, nor will we charge a fee for responding to reasonable requests unless a request is manifestly unfounded or excessive, in which case we will explain the applicable fee or our decision to refuse before acting.

Children's Privacy

Our website and services are directed exclusively at businesses and professionals. We do not knowingly collect, process or store personal data relating to individuals under the age of 18 (or the applicable age of digital consent in the user's jurisdiction, which under LGPD is 12 years for certain processing activities).

If you are a parent or guardian and you believe that a minor has provided us with personal data without appropriate consent, please contact us immediately at contato@virtus-ts.site. Upon verification, we will promptly delete any such data from our records.

We do not design features, marketing communications or content specifically intended to attract minors, and we do not knowingly engage in any commercial transaction with individuals under 18 years of age.

Changes to This Policy

We review and update this Privacy Policy periodically to reflect changes in our business practices, applicable law, regulatory guidance or technological developments. When we make material changes — meaning changes that substantively affect your rights or how we process your data — we will:

  • Update the "Last updated" date at the top of this page;
  • Where feasible, notify existing contacts by email at least 14 days before the updated policy takes effect;
  • Ensure the previous version remains accessible for reference upon request.

For non-material changes (such as corrections to typographical errors, clarifications of existing practices, or administrative updates), we will update the page without prior notice. We encourage you to review this policy periodically. Your continued use of our website after any revised policy is posted constitutes your acknowledgement of those changes.

The current version of this policy always supersedes all prior versions. If any part of this policy conflicts with a previous version, the current version governs.

Contact Us

If you have any questions, concerns or requests relating to this Privacy Policy or our personal data processing practices, please do not hesitate to get in touch. Our team is committed to responding promptly and transparently to all privacy-related enquiries.

For requests related to your data rights under LGPD or GDPR, please use the subject line "Privacy Rights Request" so we can route your message to the appropriate person and begin the formal response timeline.

Data Controller — Contact Details

VIRTIS SOLUCOES EM TECNOLOGIA LTDA
Registered company in Brazil
CNPJ: Available upon request for verification purposes
Privacy & Data Protection enquiries:
contato@virtus-ts.site
Website:
virtus-ts.site
We aim to acknowledge all privacy-related enquiries within 2 business days and to provide a substantive response within the statutory deadlines described in Section 8.

This Privacy Policy was prepared in English and is the authoritative version. Any translation provided is for convenience only; in the event of conflict, the English version prevails.