Legal & Compliance

Privacy Policy

At M.IA SOLUÇÕES EM INTELIGÊNCIA ARTIFICIAL LTDA, we take privacy seriously. This policy explains exactly what personal data we collect when you visit our website or contact us, how and why we use it, with whom we share it, and what rights you have over your own information. We've written this document to be clear and direct — not a wall of impenetrable legalese.

Last updated June 2025
Effective date June 1, 2025
Jurisdiction Brazil · LGPD / GDPR-aligned
Section 01

Introduction

This Privacy Policy applies to the website operated by M.IA SOLUÇÕES EM INTELIGÊNCIA ARTIFICIAL LTDA, a Brazilian limited-liability company registered under CNPJ 67.971.350/0001-76, with registered offices at Rua República do Iraque, 40, Jardim Oswaldo Cruz, São José dos Campos — SP, Brazil. Throughout this document we refer to ourselves as "M.IA," "we," "our," or "us."

Our website is a purely informational corporate site. We do not operate an e-commerce platform, we do not process payments online, and we do not offer any user account or client portal on this domain. The personal data we handle is limited to information you provide voluntarily when reaching out to us, together with standard technical and analytical data generated by your browser as you navigate the site.

This policy is drafted in compliance with Brazil's Lei Geral de Proteção de Dados (LGPD) — Law No. 13,709/2018 — and is aligned with the principles of the European Union's General Data Protection Regulation (GDPR) (EU 2016/679). Where visitors access our website from the European Economic Area (EEA), United Kingdom, or other jurisdictions with robust data-protection frameworks, we extend the same rights and protections outlined herein.

By accessing our website, you acknowledge that you have read and understood this policy. If you disagree with any part of it, please refrain from submitting your personal data to us.

Section 02

Information We Collect

We collect only the minimum information necessary to respond to your inquiries and to operate this website responsibly. The data we may receive falls into two broad categories: information you give us directly, and information collected automatically.

Information You Provide Directly

When you reach out to us via email or telephone — contact details are published as static text on our Contact page — you may share:

  • Your full name and professional title
  • Your business email address and/or telephone number
  • The name and sector of the company you represent
  • A description of your query, project brief, or the subject matter of your inquiry
  • Any additional information you voluntarily include in your message

We do not operate any contact form on this website. All communication is initiated by you through your own email client or by calling the number listed on our Contact page. We have no technical mechanism to intercept or store data submitted through third-party email services — that data is governed by the privacy policy of the email provider you choose to use.

Information Collected Automatically

When you visit our website, certain technical data is generated automatically by your browser and our hosting infrastructure. This includes:

  • Internet Protocol (IP) address and approximate geographic location derived from it (typically city/region level)
  • Browser type, version, and the operating system you are using
  • The referring URL — the page you were on immediately before arriving at our site
  • Pages visited, time spent on each page, and the sequence in which you navigate the site
  • Date and time of each page request and standard HTTP status codes
  • Device type (desktop, tablet, or mobile) and screen resolution

This technical data is collected primarily through server logs and analytics cookies. Individually, most of these data points are not personally identifiable; however, when combined they can constitute personal data under LGPD and GDPR, and we treat them as such.

We do not collect special categories of sensitive personal data (such as health information, racial or ethnic origin, political opinions, biometric data, or financial account details) through this website. Please do not send us such information via email.

Section 03

How We Use Your Information

Every use we make of your personal data has a specific, documented purpose and a lawful basis under both LGPD and GDPR. We never repurpose your data in ways inconsistent with the reason it was collected.

  • Responding to your inquiry. When you email or call us, we use the contact details and context you provide to reply promptly and accurately. The lawful basis is the legitimate interest of both parties in establishing a business dialogue (LGPD Art. 7, X; GDPR Art. 6(1)(f)).
  • Preparing and delivering proposals. If your inquiry progresses toward a potential engagement, we may use your professional details to prepare a tailored service proposal. This processing is carried out on the basis of pre-contractual steps taken at your request (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
  • Improving website performance. Aggregated, anonymised analytics data helps us understand which content is most useful, identify pages with technical issues, and plan future improvements. This serves our legitimate interest in maintaining an effective online presence.
  • Legal and compliance obligations. In certain circumstances we may be required to retain or disclose personal data to comply with applicable law, a court order, or a request from a competent public authority. The lawful basis is legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
  • Protecting the security of our systems. Server log data is retained briefly for intrusion detection, fraud prevention, and resolving technical incidents affecting site reliability.

We do not use your personal data for automated individual decision-making or profiling that produces legal or similarly significant effects. We do not sell, rent, or barter personal data to third parties for their own marketing purposes under any circumstances.

Section 04

Cookies & Tracking Technologies

Cookies are small text files stored in your browser when you visit a website. We use a limited set of cookies, described below. Where applicable law requires your prior consent before non-essential cookies are set — for instance, when you access our site from within the EEA — we seek that consent through a cookie preference mechanism before placing anything beyond strictly necessary cookies.

Strictly Necessary Cookies

These cookies are essential for the website to function and cannot be switched off. They include session-security tokens and load-balancing indicators set by our hosting provider. They do not collect any information about you that could be used for marketing. No consent is required for these cookies under either LGPD or the ePrivacy Directive.

Analytics Cookies

We use Google Analytics (operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to collect aggregate data about visitor behaviour — page views, session duration, traffic sources, and device types. Google Analytics sets persistent cookies in your browser (typically lasting 24 months) to distinguish unique visits and track navigation paths. We have enabled IP anonymisation so that the last octet of your IP address is masked before the data leaves our server, meaning Google never processes a complete IP address on our behalf.

We have also activated the Data Processing Amendment required under GDPR and the equivalent contractual terms required under LGPD, designating Google as a data processor acting on our instructions. Aggregate analytics data is retained within Google's systems in accordance with Google's own privacy policy; we retain reports derived from that data for a maximum of 26 months.

Managing Your Cookie Preferences

You can withdraw consent for non-essential cookies at any time by adjusting your browser settings to refuse or delete cookies, or by using the cookie preference panel on this site. Note that disabling analytics cookies will not affect your ability to use any part of this website. Your browser documentation describes how to manage cookies for the most popular browsers; further guidance is available from the privacy regulator in your country.

Other Tracking Technologies

We do not currently use pixel tags, web beacons, fingerprinting scripts, or behavioural advertising technologies on this site. Should this change in a future update to our technology stack, we will revise this section and notify visitors through the mechanism described under Section 10 (Changes to This Policy).

Section 05

Sharing With Third Parties

We do not sell or trade personal data. We share limited personal data only with the categories of third parties described below, and only to the extent necessary for the specific purpose stated.

  • Hosting and infrastructure providers. Our website is served through cloud hosting infrastructure. Our provider may process server log data (including IP addresses) as part of delivering and securing the service. They act as a data processor under a written agreement and may not use this data for their own purposes.
  • Analytics services. As described in Section 4, we share anonymised usage data with Google Analytics. Google acts as a data processor. Processed data may be stored on servers located outside Brazil, including in the United States. We rely on the EU Standard Contractual Clauses and equivalent transfer mechanisms recognised by Brazil's ANPD to legitimise international transfers.
  • Professional advisors. We may share information with our legal counsel, auditors, or accountants where required for compliance, corporate governance, or dispute resolution. These advisors are bound by professional confidentiality obligations.
  • Law enforcement and regulatory authorities. If required by a valid court order, subpoena, legal process, or a binding request from a competent authority such as Brazil's ANPD (Autoridade Nacional de Proteção de Dados), we may disclose personal data to the extent strictly required. Where legally permissible, we will notify you of such a request before disclosing.
  • Corporate transactions. In the unlikely event of a merger, acquisition, or sale of all or substantially all of our business assets, personal data we hold may be transferred to the successor entity. We will provide notice before any such transfer occurs and your data will remain subject to at least equivalent protections.

Outside the categories above, no personal data is disclosed to any third party. We impose contractual obligations on all processors that require them to protect data to the same standard we apply ourselves.

Section 06

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. The following retention schedules reflect our current practice:

  • Email correspondence and inquiry records. Messages received by email, together with any personal data contained within them, are retained for up to 5 years from the date of last meaningful contact. This period allows us to refer back to prior discussions when a prospective client returns after an extended period, and satisfies the civil limitation period applicable under Brazilian law.
  • Active client records. Where an inquiry converts to a business engagement, personal data related to that engagement is retained for 10 years after the contract concludes, in line with Brazilian tax and corporate record-keeping requirements.
  • Server access logs. Raw server log files, which may contain IP addresses, are retained for a maximum of 90 days and then automatically purged. Aggregated statistical summaries derived from logs may be retained longer.
  • Analytics data. Within Google Analytics, data associated with individual sessions is retained for 26 months, after which it is deleted automatically per our account configuration. We review this setting periodically.
  • Records of consent. Where we rely on your consent as a lawful basis, we retain a record of that consent — including the date, mechanism, and version of the policy in force at the time — for as long as we continue to process data on that basis, plus 12 months thereafter.

At the end of the applicable retention period, personal data is either securely deleted or irreversibly anonymised. If you request erasure before a retention period expires, we will assess whether an overriding legal obligation requires us to retain the data; if not, we will fulfil the erasure request within 30 days.

Section 07

Data Security

We implement technical and organisational measures appropriate to the nature of the data we handle and the risks posed by its processing. Our current security practices include:

  • Transport Layer Security (TLS 1.2 minimum) for all data in transit between your browser and our servers, indicated by the padlock icon in your address bar
  • Encrypted storage for databases and file systems holding personal data at rest
  • Access controls that restrict personal data to employees and contractors who have a demonstrable need for access in order to perform their duties
  • Regular security patching and vulnerability scanning of our hosting environment
  • Multi-factor authentication requirements for all internal systems that store or process personal data
  • Annual internal review of data handling practices and access privileges

No system connected to the internet can guarantee absolute security. In the event we become aware of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (Brazil's ANPD and/or the competent EEA authority where applicable) within 72 hours of becoming aware, and will inform affected individuals without undue delay where the breach is likely to result in a high risk to those individuals.

Your role in security matters too. If you communicate sensitive business information to us by email, we recommend using encrypted email where possible. We are not responsible for the security of data while it is in transit through third-party email networks.

Section 08

Your Rights

Under Brazil's LGPD (Art. 18) and the GDPR (Arts. 15–22), you hold a meaningful set of rights over your personal data. We respect and honour all of these rights. Below is a plain-language summary of each right and what it means in practice when dealing with M.IA.

Right of Access

You may request confirmation of whether we hold personal data about you, and if so, receive a copy of that data along with information about how it is being used, with whom it is shared, and for how long it will be kept.

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. We will action verified correction requests within 15 business days.

Right to Erasure

Also known as the "right to be forgotten." You may ask us to delete personal data we hold about you. We will comply unless retention is required by law or is necessary to defend a legal claim.

Right to Restriction

You may ask us to restrict processing of your data — for example, while you contest its accuracy or while an objection is pending. During restriction, we store the data but do not actively process it.

Right to Portability

Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, machine-readable format so that it can be transferred to another controller.

Right to Object

You may object at any time to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling grounds that override your interests, rights, and freedoms, or that the processing is necessary for a legal claim.

Right to Withdraw Consent

Where we rely on your consent as the lawful basis for processing (e.g., non-essential analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

If you believe we have mishandled your personal data, you have the right to lodge a complaint with Brazil's ANPD (www.gov.br/anpd) or, for EEA residents, the supervisory authority in your country of residence.

How to Exercise Your Rights

To exercise any of the above rights, please contact us by email at contato@getmia-us.site with the subject line "Privacy Rights Request." Please include sufficient information to allow us to identify you — typically your full name and the email address associated with your previous correspondence with us. We do not require you to create an account or fill in any form.

We will acknowledge your request within 5 business days and respond substantively within 30 calendar days of receipt. In complex cases we may extend this deadline by a further 30 days; if we do so, we will notify you of the extension and the reasons for it before the initial deadline expires. We will not charge a fee for reasonable requests; however, we reserve the right to charge a reasonable administrative fee if requests are manifestly unfounded or excessive in nature.

We may need to verify your identity before we can action a request. We will do this in the least intrusive way possible and will not retain any verification documents longer than necessary for that purpose.

Section 09

Children's Privacy

This website is directed exclusively at business professionals and corporate decision-makers. Our services are designed for organisations and are not intended for, and have no relevance to, individuals under the age of 18. We do not knowingly collect personal data from children.

If we become aware that we have inadvertently received personal data from a person under 18, we will delete that information from our records without delay. If you are a parent or guardian and believe that your child has sent us a message or provided personal information, please contact us at contato@getmia-us.site and we will take immediate action.

Under Brazil's LGPD (Art. 14), processing of personal data belonging to children requires the specific and highlighted consent of at least one parent or legal guardian. We do not engage in any such processing and have no mechanism on this site to do so.

Section 10

Changes to This Policy

Our business evolves, and privacy law continues to develop. We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable regulation, or best-practice guidance from supervisory authorities. When we do, we will revise the "Last Updated" date at the top of this page.

For material changes — those that meaningfully affect how we handle your personal data or that reduce your rights — we will take additional steps to notify affected individuals. Where we have your email address, we will send a direct notification. We will also maintain an accessible summary of the nature of significant changes at the top of this page for a period of at least 30 days following publication.

We encourage you to review this policy periodically. Your continued engagement with our company after a revised policy has been published constitutes acknowledgement of that update. If you have concerns about any change, please contact us before you continue to share personal data with us.

Prior versions of this policy are available on request by emailing contato@getmia-us.site.

Section 11

Contact & Data Controller Details

Questions, concerns, or requests relating to this Privacy Policy or to our handling of your personal data should be directed to us using the details below. As a company that processes personal data, we act as the data controller in respect of the personal data described in this document. We are in the process of formally designating a Data Protection Officer (DPO) as required under LGPD Art. 41; enquiries of a privacy-law nature addressed to the email below will be handled by the person responsible for data protection within our organisation until that designation is complete.

Company M.IA SOLUÇÕES EM INTELIGÊNCIA ARTIFICIAL LTDA
CNPJ 67.971.350/0001-76
Address Rua República do Iraque, 40, Jardim Oswaldo Cruz, São José dos Campos — SP, Brazil
Subject Privacy Rights Request — or — Privacy Policy Enquiry
Response Within 5 business days (acknowledgement); 30 days (substantive response)

If you are located in Brazil and are dissatisfied with our response, you may escalate your complaint to the Autoridade Nacional de Proteção de Dados (ANPD) via its official portal at www.gov.br/anpd. If you are located in the European Economic Area or the United Kingdom, you may contact the data protection supervisory authority in your country of residence or establishment.