Legal & Compliance

Privacy Policy

At Scurra Tecnologia we believe transparency about data is as important as the technology we build. This policy explains, in plain language, exactly what personal information we collect, why we collect it, and the choices you have over your own data — whether you are based in Brazil, the European Union, or anywhere else in the world.

Last updated: 14 July 2025

Introduction

SCURRA TECNOLOGIA LTDA. (CNPJ 18.706.934/0001-09), headquartered at Rua Adalberto Schmalz, 401, Casa 12, Glória, Joinville — SC, Brazil, operates the website scurra.site and provides technology consulting, software development, and digital infrastructure services to businesses across Brazil and internationally.

This Privacy Policy governs how we collect, store, use, and share personal data when you visit our website, request information, or otherwise interact with us. It applies to all individuals whose data we process, including visitors, prospective clients, and business contacts.

We are committed to complying with Brazil's Lei Geral de Proteção de Dados (LGPD) — Law No. 13,709/2018 — as well as the General Data Protection Regulation (GDPR) of the European Union where applicable. In any conflict between these frameworks and local law, we apply the standard that affords greater protection to individuals.

By using our website or submitting any form on it, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please do not use our website or submit your personal information through our channels. You may contact us at any time with questions using the details in Section 11.

Information We Collect

We only collect personal information that is genuinely necessary for the purposes described in this policy. We collect data in two broad ways: information you give to us directly, and information that is generated automatically when you use our website.

2.1 — Information You Provide Directly

When you fill in a contact form, request a quote, subscribe to our newsletter, or reach out through any communication channel on this site, you may provide:

  • Identity data: first name, last name, and, in the case of corporate enquiries, company name and your role within that company.
  • Contact data: email address and, where supplied voluntarily, a telephone or WhatsApp number.
  • Enquiry content: the text of your message, including any project descriptions, technical requirements, or business information you choose to share with us.
  • Communication preferences: whether you consent to receiving marketing communications from us and, if so, which topics you are interested in.

Fields marked as mandatory on our forms are the minimum required for us to respond meaningfully to your enquiry. All other fields are optional; you are never obliged to supply more information than you are comfortable sharing.

2.2 — Information Collected Automatically

Like virtually every website, ours records certain technical data automatically whenever a browser connects to our servers. This includes:

  • Log data: IP address (stored in truncated, anonymised form where technically possible), browser type and version, operating system, referring URL, pages visited, date and time of access, and HTTP response codes.
  • Device data: screen resolution, device category (desktop, tablet, or mobile), and language settings — used solely to improve how the site renders for different users.
  • Usage data: anonymised interaction metrics such as session duration, scroll depth, link clicks, and navigation paths collected via analytics tools described in Section 4.

2.3 — Information We Do Not Collect

We do not collect any special categories of personal data — such as health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, or criminal records — and we have no intention of doing so. We also do not knowingly collect data from children under the age of 16 (see Section 9).

How We Use Your Information

Every use of your personal data is tied to a specific, legitimate purpose. Under the LGPD and GDPR, each processing activity must rest on a lawful basis. The table below explains what we do with your data and why we are legally permitted to do it.

  • Responding to contact-form enquiries and quote requests. When you reach out through our website, we use the information you submit to understand your needs and prepare a relevant, personalised response. Lawful basis: performance of a pre-contractual step taken at your request (LGPD Art. 7, II; GDPR Art. 6(1)(b)).
  • Delivering contracted services. Where we enter into an engagement with you or your company, we process relevant personal data to fulfil our obligations — for example, coordinating project timelines, issuing invoices, and providing technical support. Lawful basis: performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
  • Sending marketing communications. With your explicit prior consent, we may send you information about new services, technology insights, or relevant case studies by email or WhatsApp. You can withdraw this consent at any time, free of charge, by clicking "unsubscribe" in any email or by contacting us directly. Lawful basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
  • Improving our website and service offering. Aggregated and anonymised analytics data helps us understand which pages attract the most interest, where visitors drop off, and how we can communicate more clearly. Lawful basis: legitimate interest in developing and improving our business (LGPD Art. 7, IX; GDPR Art. 6(1)(f)), balanced against your right to privacy.
  • Compliance with legal obligations. We may be required to retain or disclose certain data to comply with Brazilian tax law, labour law, or a binding order from a competent authority. Lawful basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
  • Prevention of fraud and protection of our legal interests. We may process data to detect, investigate, and prevent abusive use of our systems or fraudulent contact. Lawful basis: legitimate interest / protection of legal claims (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).

We will never use your data for purposes that are incompatible with those listed above without seeking fresh consent or establishing a new lawful basis in advance.

No automated decision-making We do not use your personal data for automated profiling or any form of automated decision-making that produces legal or similarly significant effects on you. All decisions regarding proposals, pricing, and service delivery involve human review.

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to make the site function correctly, remember your preferences, and — with your consent — measure how visitors engage with our content. A cookie is a small text file placed on your device by your browser when you visit a website; it is not a program and cannot harm your device.

4.1 — Categories of Cookies We Use

  • Strictly necessary cookies. These are essential for the site to operate — for example, cookies that maintain the state of a form you have partially completed, or that record your cookie-consent choice so we do not keep asking you. No consent is required for these cookies because they cannot be disabled without breaking core functionality.
  • Analytics cookies. With your consent, we use Google Analytics 4 (GA4) to collect aggregated, anonymised information about how visitors navigate our site — which pages are viewed most, how long sessions last, and where traffic originates. We have configured GA4 with IP anonymisation enabled, and data is processed on Google LLC's infrastructure under a Data Processing Addendum that complies with GDPR requirements.
  • Marketing and advertising cookies. If you have consented, cookies placed by Google Ads (previously Google AdWords) allow us to measure the effectiveness of advertising campaigns and to show relevant advertisements to users who have previously visited our site (remarketing). These cookies are controlled by Google LLC and governed by Google's own privacy policy.

4.2 — Managing Your Cookie Preferences

When you first visit our site, a consent banner allows you to accept or decline non-essential cookies. You can change your preferences at any time by clearing your browser's cookies and revisiting the site, or by adjusting your browser settings as described below:

  • Browser settings: All modern browsers allow you to block or delete cookies. Visit your browser's help section — for example, "Settings > Privacy" in Chrome, or "Preferences > Privacy & Security" in Firefox — and follow the instructions to manage cookies.
  • Google Analytics opt-out: You can prevent Google Analytics from collecting your data by installing the official browser add-on available at tools.google.com/dlpage/gaoptout.
  • Google Ads personalisation: You can manage or opt out of interest-based advertising by visiting adssettings.google.com.

Please note that disabling analytics or advertising cookies will not prevent you from using any part of our website — it only affects our ability to measure usage and serve relevant advertisements.

4.3 — Third-Party Embeds and External Links

Our site may contain links to third-party websites and may embed content from platforms such as YouTube or LinkedIn. When you follow a link or interact with an embedded element, you leave our data-processing environment. We have no control over how those third parties collect or use your data, and we encourage you to read their privacy policies before interacting with their services.

Sharing With Third Parties

We do not sell, rent, or trade your personal data. We share information only to the extent required to operate our business, comply with the law, or protect legitimate interests — and always subject to appropriate contractual safeguards that require our partners to handle data responsibly.

5.1 — Service Providers (Data Processors)

We engage the following categories of trusted service providers who act as data processors on our behalf and may have limited access to personal data only as needed to perform their contracted service:

  • Cloud hosting and infrastructure: Our website and associated services are hosted on servers provided by reputable cloud providers operating data centres with internationally recognised security certifications. Data stored within Brazil is preferentially kept in Brazilian data centres where offered by the provider.
  • Email and communication tools: We use transactional email services to deliver automated responses to contact-form submissions. These providers receive the recipient's email address and the content of the message; they may not use this data for their own purposes.
  • Analytics and advertising: Google LLC, through its Analytics 4 and Google Ads products, processes anonymised usage data as described in Section 4. Google acts as a data processor in relation to analytics data and as an independent data controller in relation to advertising activities on its own network.
  • Accounting and tax compliance software: We use cloud-based accounting tools to manage invoicing and tax obligations, which may process billing contact details of clients. These providers operate under strict data processing agreements.

5.2 — Legal Disclosures

We may disclose personal data to courts, regulatory authorities, or law enforcement agencies if required to do so by Brazilian law, a valid court order, or a lawful request from a competent government body. We will notify affected individuals of such disclosures where legally permitted to do so.

5.3 — Business Transfers

In the unlikely event of a merger, acquisition, or sale of all or part of our business, personal data held by us may form part of the transferred assets. We will notify affected data subjects before their data is transferred and before it becomes subject to a materially different privacy policy.

5.4 — International Data Transfers

Some of our service providers operate infrastructure outside Brazil and the European Union. When personal data is transferred internationally, we ensure adequate safeguards are in place — such as the European Commission's Standard Contractual Clauses or the ANPD-recognised equivalent mechanisms under the LGPD — so that the level of protection travels with the data.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy or to comply with legal obligations. The following guidelines govern our standard retention periods:

  • Contact-form and pre-contractual enquiries: Data from visitors who contact us but do not proceed to a commercial engagement is retained for up to 24 months from the date of last contact. This period allows us to respond to follow-up queries and demonstrate compliance with our obligations. After that period, the data is securely deleted or fully anonymised.
  • Client project data: Information related to an active or completed commercial engagement is retained for 5 years following project completion, in accordance with Brazilian civil and tax law (Código Civil, Art. 205; Lei 9.430/1996). Financial records may be retained for up to 10 years where required by fiscal authorities.
  • Marketing consent records: We retain records of your marketing consent — including the date, method, and scope of the consent — for the duration of the marketing relationship plus 2 years after you withdraw consent, so that we can demonstrate compliance in the event of a regulatory enquiry.
  • Website log data: Raw server logs are automatically purged after 90 days. Anonymised analytics data aggregated by Google Analytics 4 may be stored for up to 14 months under our GA4 data-retention settings.
  • Cookie consent logs: Records of your cookie preferences are stored for up to 12 months, after which we will ask for fresh consent.

When data is no longer required, we apply secure deletion procedures appropriate to the storage medium involved. Where complete deletion is technically impractical within the normal system lifecycle, data is rendered permanently anonymous — meaning it cannot be re-attributed to any individual.

Data Security

As a technology company, security is not an afterthought for us — it is embedded in how we operate. We apply the following technical and organisational measures to protect your personal information against accidental loss, unauthorised access, alteration, and disclosure:

  • Encryption in transit: All communications between your browser and our servers are protected by TLS 1.2 or TLS 1.3. Our domain is served exclusively over HTTPS with HSTS enabled.
  • Encryption at rest: Personal data stored in databases and cloud storage is encrypted at rest using AES-256 or equivalent standards, depending on the platform.
  • Access controls: Access to systems holding personal data is restricted on a need-to-know basis using role-based access controls and strong authentication (including multi-factor authentication for administrative accounts).
  • Vulnerability management: We keep our software dependencies and server configurations up to date and monitor security advisories relevant to the technologies we use.
  • Supplier due diligence: Before engaging a new data processor, we evaluate their security posture and require contractual commitments that meet or exceed our own standards.
  • Incident response: We maintain an internal incident-response process. In the event of a data breach that creates a significant risk to individuals, we will notify the Brazilian National Data Protection Authority (ANPD) within 72 hours of becoming aware of the incident, and we will inform affected data subjects without undue delay, as required by LGPD Art. 48.

No system connected to the public internet can be guaranteed to be 100% secure. We cannot warrant absolute security, but we do commit to applying industry-appropriate measures and to responding promptly and transparently to any security incidents that occur.

Your Rights

Depending on your country of residence, you benefit from a range of individual rights regarding your personal data. Under both the LGPD and the GDPR, you have the following rights:

Right of Access
You can ask us to confirm whether we hold personal data about you and, if so, request a copy of that data along with information about how it is processed.
Right to Rectification
If any information we hold about you is inaccurate or incomplete, you have the right to ask us to correct or complete it promptly.
Right to Erasure
You may ask us to delete your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where you object to processing based on legitimate interests and we have no overriding grounds to continue.
Right to Restriction
In certain circumstances — for example, while a dispute about data accuracy is resolved — you can ask us to suspend processing of your data without deleting it.
Right to Data Portability
Where processing is based on your consent or on contract performance, you can request that we provide your personal data in a structured, commonly used, machine-readable format so you can transfer it to another service provider.
Right to Object
You may object at any time to processing based on legitimate interests or carried out for direct marketing purposes. If you object to marketing, we will stop processing your data for that purpose immediately.
Right to Withdraw Consent
Where we rely on your consent as the lawful basis for processing, you can withdraw it at any time with immediate effect — without affecting the lawfulness of processing carried out before withdrawal.
Right Not to Be Subject to Automated Decisions
As noted in Section 3, we do not make significant decisions about you solely on the basis of automated processing — so this right is unlikely to arise in practice, but we recognise it regardless.

How to exercise your rights

To exercise any of the rights listed above, please send a written request to contato@scurra.site with the subject line "Data Rights Request." To protect your privacy, we may need to verify your identity before processing the request — for example, by asking you to confirm details we already hold.

We will respond to all valid requests within 15 business days under the LGPD, or within one calendar month under the GDPR. Where a request is complex or numerous, we may extend this period by up to two additional months and will notify you of the extension and the reasons for it.

If you are not satisfied with our response, you have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil (gov.br/anpd) or with your national supervisory authority if you are located in the European Economic Area.

Children's Privacy

Our website and services are directed exclusively at business professionals and are not designed for, or intentionally directed towards, children under the age of 16. We do not knowingly collect personal data from minors.

If you are a parent or guardian and believe that your child has submitted personal information through our website without your consent, please contact us immediately at contato@scurra.site. We will investigate the matter and, if confirmed, delete the relevant data promptly and without charge.

Should we ever wish to offer services to or collect data from children in the future, we would redesign the relevant processes to comply with all applicable child-protection requirements — including parental consent mechanisms under LGPD Art. 14 — before doing so.

Changes to This Policy

We review this Privacy Policy at least annually and whenever there are significant changes to our data-processing activities, relevant legislation, or regulatory guidance. We may update this document for any of the following reasons:

  • We introduce a new service, product, or feature that involves the collection or processing of personal data in a new way.
  • We engage a new category of third-party service provider who will access personal data.
  • Changes to LGPD, GDPR, or related regulations require us to update our practices or disclosures.
  • We receive feedback from our users, clients, or regulators that identifies a gap or ambiguity in this policy.

When we make a material change — one that meaningfully affects your rights or our data-processing activities — we will post a prominent notice on our website homepage and, where we hold your email address, send a direct notification. The "Last updated" date at the top of this page will always reflect the date of the most recent revision.

We encourage you to review this policy periodically. Your continued use of our website after a material change has been communicated constitutes acceptance of the revised policy. If you do not agree with a material change, you may exercise your data rights as described in Section 8 or stop using the site.

Version history This version (v2.0) was published on 14 July 2025 and supersedes all prior versions of the privacy notice published on scurra.site. Prior versions are available on request by contacting us at contato@scurra.site.

Contact

We welcome questions, comments, and concerns about this policy or our data-handling practices. Whether you want to exercise a data right, report a potential security issue, or simply understand more about how your information is used, please reach out — we aim to respond to all enquiries within 2 business days.

Our appointed data controller responsible for decisions about how personal data is collected and used is Scurra Tecnologia Ltda. — no separate Data Protection Officer (DPO) is currently required given the scale of our processing, but we remain fully contactable through the details below.

Scurra Tecnologia Ltda. — Data Enquiries
CNPJ: 18.706.934/0001-09
Rua Adalberto Schmalz, 401, Casa 12, Glória
Joinville — SC, 89.227-395, Brazil
Email: contato@scurra.site
Website: scurra.site

If you believe we have not handled your data rights request appropriately, you also have the right to escalate your complaint directly to the Autoridade Nacional de Proteção de Dados (ANPD) via gov.br/anpd, or to the supervisory authority in your country of residence if you are located within the European Economic Area.