Legal & Compliance

Privacy Policy

We take your privacy seriously. This document explains exactly what data we collect, why we need it, and how it is protected — in plain, straightforward language.

Last updated: June 17, 2025
01

Introduction

HW Sistemas TI USA ("we", "us" or "our") is an information technology services company committed to protecting the privacy of every individual who interacts with our website at hwsistemastiusa.com. This Privacy Policy explains in full detail how we collect, process, store, disclose, and safeguard personal information in connection with your use of our website and our business communications.

This policy has been prepared to comply with applicable privacy legislation including the General Data Protection Regulation (GDPR — EU Regulation 2016/679), Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018), and relevant provisions of U.S. state privacy laws. Where those legal frameworks overlap, we apply the most protective standard.

By visiting or using this website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any aspect of it, please refrain from using the site and contact us directly at the address provided in Section 11. This policy applies solely to information collected through this website and does not govern practices of any third-party websites that may be linked herein.

Plain-language summary: We collect only what we genuinely need to serve you, we never sell your data, and we give you clear, practical tools to control your own information.

02

Information We Collect

We collect personal data through two broad channels: information you provide to us voluntarily and information gathered automatically when you interact with our website. We take care to limit collection to what is strictly necessary for the purposes described in this policy.

Information You Provide Directly

When you reach out to us via the contact details published on this site — whether by email, telephone, or messaging applications — you may voluntarily supply personal information such as your full name, professional title, company or organization name, email address, telephone number, and the content of your enquiry or message. We use this information only to respond to you and, where relevant, to fulfil the services you request.

Information Collected Automatically

When you browse hwsistemastiusa.com, our web server and third-party analytics tools automatically record certain technical data. This includes:

  • Your device's Internet Protocol (IP) address (truncated or anonymized where technically feasible)
  • Browser type, version, and language preferences
  • Operating system and device category (desktop, mobile, tablet)
  • Referring URL — the page or search result that brought you to our site
  • Pages viewed, time spent on each page, and navigation path through the site
  • Date, time, and duration of each visit session
  • General geographic location derived from IP address (city or region level, not precise)
  • Interaction events such as link clicks, scroll depth, and button interactions as captured by analytics scripts

Business-Context Information

If you represent a business that engages HW Sistemas TI USA for technology services, we may collect additional professional information necessary for service delivery — including billing contact details, technical environment specifications, and service-level correspondence. Such information is governed both by this Privacy Policy and by the applicable service agreement between the parties.

03

How We Use Your Information

We process personal information only when we have a valid legal basis for doing so — such as your consent, our legitimate business interests, compliance with a legal obligation, or the performance of a contract. Each of the purposes listed below is tied to one or more of these legal bases.

  • Responding to enquiries and communications: We use contact details you supply to answer your questions, provide requested information about our IT services, and maintain ongoing business correspondence.
  • Delivering and improving our services: When engaged for technology services, we use relevant information to configure, deploy, and support the solutions we provide, and to measure quality outcomes against agreed benchmarks.
  • Website analytics and performance optimization: Automatically collected usage data helps us understand how visitors navigate the site, which content is most useful, and where technical or usability problems may exist — enabling us to continuously improve the experience.
  • Security and fraud prevention: IP addresses and session logs are reviewed, where necessary, to identify abnormal access patterns, prevent unauthorized use, and protect the integrity of our digital infrastructure.
  • Legal and regulatory compliance: We retain and process certain records as required by Brazilian, U.S., and international law, including tax and accounting obligations, contractual performance documentation, and responses to lawful government requests.
  • Marketing and service information — with consent only: If you have specifically opted in to receive service updates or news from us, we may send relevant communications to your email address. You may withdraw this consent at any time by contacting us.

We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals, and we do not build individual profiles for the purpose of selling, renting, or otherwise monetizing your data to third parties.

04

Cookies & Tracking Technologies

Our website uses cookies — small text files stored on your device — and related tracking technologies to enable certain functions and gather the analytics data described in Section 2. Below we describe each category of cookie we use.

Strictly Necessary Cookies

These cookies are essential for the basic operation of the website. They enable navigation between pages, maintain session continuity, and ensure security controls function correctly. No consent is required for these cookies, as they cannot be disabled without fundamentally breaking the site. They do not store any personally identifiable information beyond what is technically required for the current session.

Analytics & Performance Cookies

We use Google Analytics (operated by Google LLC) to collect aggregated, anonymized data about how visitors use our website. Google Analytics sets cookies that track session duration, page views, traffic sources, and general user behavior. Where legally required, IP addresses are anonymized before being transmitted to Google's servers. This data is processed under our legitimate interest in understanding website performance. You may opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on.

Advertising & Remarketing Cookies (Google Ads)

We may use Google Ads conversion tracking and remarketing tags. These technologies help us understand whether visitors who clicked our advertisements went on to take meaningful actions on the site, and to show relevant advertisements to people who have previously visited our website. Google Ads cookies are set only with your consent, which can be given or withdrawn through our cookie consent banner.

Functional Cookies

Functional cookies remember your preferences — such as language settings or previously accepted cookie choices — to provide a more personalized experience on return visits. They do not track behavior across other websites.

Managing Your Cookie Preferences

You can control cookies through your browser settings at any time. Most browsers allow you to refuse new cookies, delete existing cookies, or receive a warning before a cookie is stored. Disabling analytics or functional cookies will not prevent you from using the website but may reduce the quality of your experience. For detailed browser-specific instructions, visit allaboutcookies.org.

Third-party cookie notice: Google LLC processes analytics and advertising data on servers that may be located in the United States or other countries outside Brazil and the EU. Google operates under Standard Contractual Clauses and its own privacy framework. See google.com/policies/privacy for full details.

05

Sharing With Third Parties

We do not sell, trade, rent, or otherwise transfer personal information to unaffiliated third parties for their own marketing or commercial purposes. We share data only in the limited circumstances described below, and in each case we require that the recipient provides adequate data protection guarantees.

  • Service providers and processors: We engage carefully selected companies to assist us with IT infrastructure, website hosting, cloud services, cybersecurity monitoring, and business productivity tools. These providers access personal data only to the extent necessary to perform their contracted functions and are bound by data processing agreements that prohibit further use or disclosure.
  • Analytics and advertising platforms: As described in Section 4, we share anonymized or pseudonymized usage data with Google LLC for analytics and, where consented, for advertising measurement purposes.
  • Legal and regulatory authorities: We may disclose personal information to government bodies, courts, or law-enforcement agencies when required to do so by applicable law, regulation, court order, or other mandatory legal process. In such cases, we share only the minimum information required and, where permissible, notify the affected individual in advance.
  • Business transfers: In the event of a merger, acquisition, corporate restructuring, or sale of assets, personal data held by HW Sistemas TI USA may be transferred to the successor entity. Affected individuals will be notified of any such transfer and of any material changes to this Privacy Policy that result from it.
  • Professional advisors: Our legal counsel, accountants, and auditors may have access to records containing personal data in the course of their professional engagement, under duties of confidentiality.

All international transfers of personal data — including transfers from Brazil or the European Economic Area to the United States — are conducted using appropriate legal mechanisms such as Standard Contractual Clauses, adequacy decisions, or binding corporate rules, in compliance with LGPD Article 33 and GDPR Chapter V.

06

Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our general retention periods are as follows:

  • Contact and enquiry records: Correspondence and related contact data are retained for up to 24 months from the date of last interaction, unless a business relationship continues beyond that point or the data is needed for legal proceedings.
  • Service delivery records: Documentation related to contracted IT services is retained for a minimum of 5 years following contract termination, in accordance with Brazilian civil law limitations (Lei No. 10,406/2002) and applicable tax regulations.
  • Website analytics data: Aggregated and anonymized analytics data is retained for up to 26 months in line with Google Analytics' default retention window. This data does not directly identify individuals.
  • Server and security logs: Access logs and security event records are retained for 12 months for the purpose of security monitoring and incident investigation, after which they are securely deleted.
  • Legal and compliance records: Where a statutory retention obligation applies — such as accounting, tax, or labor records — data is retained for the period mandated by the relevant legislation, which typically ranges from 5 to 10 years in Brazil.

When data is no longer required, we securely destroy or irreversibly anonymize it using methods appropriate to the sensitivity of the information and the medium on which it is stored.

07

Data Security

As an IT services company, information security is central to what we do — not an afterthought. We implement a multi-layered set of technical and organizational controls designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction.

Technical Measures

  • TLS/SSL encryption for all data transmitted between your browser and our servers
  • Encryption of sensitive data at rest using AES-256 or equivalent industry-standard algorithms
  • Multi-factor authentication required for all administrative and system access
  • Regular automated vulnerability scanning and patch management across all infrastructure
  • Network segmentation, firewalls, and intrusion detection systems
  • Continuous security monitoring with defined incident response procedures

Organizational Measures

  • Access to personal data is granted on a strict need-to-know basis and reviewed regularly
  • All staff and contractors handling personal data receive privacy and security training
  • Data processing agreements are in place with all vendors who access personal data on our behalf
  • Internal policies covering data classification, acceptable use, and breach response are maintained and regularly updated

Data breach notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (ANPD in Brazil; the applicable EU supervisory authority) within the timeframe required by law, and will directly notify affected individuals where required or appropriate.

While we apply industry-leading security practices, no method of electronic transmission or storage is completely infallible. We continuously review and strengthen our controls to minimize risk to an acceptable level. If you suspect any unauthorized use of your personal data, please notify us immediately using the contact details in Section 11.

08

Your Rights

Depending on your jurisdiction, you hold a meaningful set of rights over your personal data. We respect and actively support the exercise of these rights. Under GDPR and Brazil's LGPD, the following rights apply — though some are subject to legal limitations and exceptions:

Right of Access

You may request a copy of the personal data we hold about you, along with information about how it is processed and on what legal basis.

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you may ask us to correct or supplement it without undue delay.

Right to Erasure

In certain circumstances, you may request deletion of your personal data. We will comply unless retention is required by law or is necessary for legitimate interests.

Right to Restriction

You may ask us to pause processing of your data while accuracy is contested, or while we assess an objection you have raised.

Right to Portability

Where processing is based on consent or contract, you may request your personal data in a structured, machine-readable format for transfer to another controller.

Right to Object

You may object at any time to processing based on legitimate interests or for direct marketing purposes. We will stop unless compelling grounds override your interests.

Right to Withdraw Consent

Where we rely on your consent to process data, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint

If you believe your rights have been violated, you may file a complaint with Brazil's ANPD or, if you are in the EU, with the supervisory authority of your member state.

How to Exercise Your Rights

To exercise any of the rights listed above, please contact our Data Protection Officer (DPO) directly by email at [email protected] with the subject line "Privacy Rights Request." Please include sufficient detail to identify yourself and describe the right you wish to exercise. We will respond within 15 business days (as required by LGPD) or within one calendar month for GDPR-covered requests, extendable by a further two months where necessary due to complexity, with prior notice.

We do not charge a fee for handling routine privacy rights requests. Where requests are manifestly unfounded or excessive, we may charge a reasonable administrative fee or decline to act, in accordance with applicable law.

09

Children's Privacy

hwsistemastiusa.com is a business-to-business corporate information site directed exclusively at adults and business professionals. We do not knowingly collect personal information from individuals under the age of 18, and our services are not intended for use by minors.

If you are a parent or guardian and believe that a minor has provided personal data to us without appropriate consent, please contact us immediately using the details in Section 11. We will promptly investigate and, where confirmed, delete any such information from our systems without delay.

In compliance with LGPD Article 14, any processing of data belonging to children or adolescents — should it ever occur in connection with contracted services — will only take place with the prior, specific, and highlighted consent of at least one parent or legal guardian.

10

Changes to This Policy

Privacy law, business practices, and the technologies we use continue to evolve. We therefore reserve the right to update this Privacy Policy at any time. When we make material changes — those that meaningfully affect your rights or the way we handle your personal data — we will take reasonable steps to notify you, including by prominently posting a notice on our homepage and updating the "Last updated" date at the top of this page.

We encourage you to review this policy periodically. Your continued use of hwsistemastiusa.com following the publication of changes constitutes your acknowledgment of those changes. If we are required by applicable law to obtain your renewed consent for any new processing activity, we will do so before commencing that activity.

Previous versions of this Privacy Policy may be obtained by contacting us directly. We maintain an internal archive of superseded versions for a minimum of five years.

11

Contact & Data Protection Officer

If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please reach out to us. We have designated a Data Protection Officer (DPO) who is responsible for overseeing compliance with this policy and applicable privacy law.

You can expect an initial acknowledgment of your communication within 2 business days and a substantive response within the statutory timeframes described in Section 8. We prefer to resolve privacy matters directly and informally where possible, but will always escalate to formal processes if required.

Get in Touch — Privacy & Data Enquiries

Company HW Sistemas TI USA
Email (DPO & General Privacy) [email protected]
Phone Available upon request by email
Registered Address United States — full address available upon request for verified data subjects
Brazilian Registration (CNPJ) CNPJ on file — available upon request for LGPD compliance inquiries

If you are located in the European Union and are unsatisfied with our response to a privacy complaint, you also have the right to lodge a complaint with the supervisory authority in your country of residence. In Brazil, the competent authority is the Autoridade Nacional de Proteção de Dados (ANPD), reachable at gov.br/anpd.