Legal
Privacy Policy
Last updated: September 2025
Central IT Tecnologia S/A ("Central IT", "we" or "our"), registered under CNPJ no. 07.171.299/0001-96, is committed to protecting the privacy and personal data of its users, clients, suppliers and partners.
This Policy describes how we process personal data in compliance with the Brazilian General Data Protection Law (Law 13,709/2018, the LGPD) and other applicable legislation.
1. Data we collect
We collect personal data in the following situations:
- Identification data: full name, job title, company, business e-mail and phone number, provided when filling in contact, demonstration request or newsletter forms.
- Browsing data: IP address, device type, browser, pages visited, session duration and traffic source, collected automatically via cookies and similar technologies.
- Communication data: messages exchanged through chat, forms or support e-mail.
- Product usage data: for clients of the CITSmart X² platform, we collect operational data in accordance with the service agreements signed.
2. Purposes of processing
We use your data for the following purposes:
- Respond to contact, demonstration or support requests;
- Send marketing communications about our products and services (subject to consent);
- Improve the browsing experience on the Site and the performance of our pages;
- Comply with legal and contractual obligations;
- Prevent fraud and ensure the security of operations;
- Carry out market analyses and improve our products and services.
3. Legal basis for processing
The processing of personal data by Central IT rests on the following legal bases of the Brazilian data protection law:
- Consentimento (art. 7º, I): for sending marketing communications and using non-essential cookies.
- Performance of a contract (art. 7, V): for the performance of contracts with clients and suppliers.
- Compliance with a legal obligation (art. 7, II): to meet legal and regulatory requirements.
- Legitimate interest (art. 7, IX): for site security, fraud prevention and product improvement.
4. Data sharing
We do not sell personal data. We may share it in the following situations:
- Service providers: companies that assist us with operations such as hosting, e-mail marketing, data analysis and CRM, bound by confidentiality agreements.
- Technology partners: to enable integrations contracted by the client.
- Competent authorities: when required by law, court order or applicable regulation.
- Group companies: with companies in the Central IT group, under the same protection conditions set out in this Policy.
5. International data transfers
Some of our service providers may process data on servers located outside Brazil. In those cases, we adopt the safeguards set out in the data protection law, including standard contractual clauses and an assessment of the level of protection in the recipient country.
6. Storage and retention
We store your personal data for as long as necessary to fulfill the purposes described in this Policy or to meet legal obligations. Once the retention period ends, the data is securely deleted or anonymized.
Indicative periods:
- Leads and contact forms: up to 3 years after the last contact;
- Contractual data: for the applicable limitation period (generally 5 years);
- Browsing data (logs): up to 6 months, unless a legal obligation applies;
- Support communications: up to 2 years after the ticket is closed.
7. Data subject rights
Under the Brazilian data protection law, you may at any time ask our DPO for:
- Confirmation that your data is being processed;
- Access to the data we hold about you;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary or excessive data;
- Portability of your data to another provider;
- Deletion of data processed on the basis of consent;
- Information about the entities with which we share your data;
- Withdrawal of consent, without prejudice to prior processing.
We will respond to requests within 15 (fifteen) business days, as required by the Brazilian data protection law.
8. Security
We adopt appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction. Among the measures adopted:
- Encryption in transit (TLS/HTTPS) and at rest for sensitive data;
- Role-based access controls (RBAC) with multi-factor authentication;
- Continuous security monitoring and incident response;
- Periodic staff training on information security and data protection law;
- Periodic security reviews and vulnerability testing.
In the event of a security incident that may pose a risk to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) and the affected data subjects within the legal deadlines.
9. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through the Site, highlighted by the last-updated date. Continued use of the Site after changes are published constitutes acceptance of the new version.
10. Cookies
For detailed information about how we use cookies and how you can manage your preferences, see our Cookie Policy.
11. Data Protection Officer (DPO)
Our Data Protection Officer (DPO) is responsible for receiving communications from data subjects and from the ANPD, as well as advising Central IT on compliance with the data protection law.
Controller: Digital Startups Proteção de Dados Ltda.
CNPJ: 45.409.514/0001-33
Encarregada: Érica Alessandra
E-mail: encarregado@centralit.com.br
Telefone: (61) 3030-4000
Address: Setor Hoteleiro Norte Quadra 2 Bloco F, Ed. Executive Office Tower, 17th floor
CEP 70702-906, Brasília/DF