Last updated: June 15, 2025

Privacy Policy

STAK TECNOLOGIA LTDA is committed to handling your personal data with transparency, responsibility, and respect. This policy explains exactly what information we collect, why we collect it, how it is used, and the rights you hold over your own data — whether you are located in Brazil, the European Union, or elsewhere in the world.

Section 01

Introduction

This Privacy Policy is published by STAK TECNOLOGIA LTDA, a legal entity incorporated under Brazilian law (CNPJ 67.979.603/0001-58), with registered offices at Rua 25 de Julho, 843, Apt 02, Nova Parobé, Parobé-RS, Brazil. Throughout this document the terms "STAK", "we", "us" and "our" refer to STAK TECNOLOGIA LTDA.

This policy governs all personal data processing activities associated with our corporate website (stak-us.site) and any ancillary digital channels through which we communicate with current or prospective clients, partners, and suppliers. It is intended to comply with Brazil's Lei Geral de Proteção de Dados (Law No. 13,709/2018 — LGPD) and, to the extent applicable to our European visitors, with the European Union's General Data Protection Regulation (EU 2016/679 — GDPR), as well as any other relevant national data protection legislation.

By visiting our website or communicating with us through any of the contact channels listed herein, you acknowledge that you have read and understood the practices described in this policy. If you do not agree with any part of it, please discontinue your use of our site and refrain from submitting personal information to us.

Our commitment: We collect only what we genuinely need, retain it only as long as necessary, and never sell or trade your personal information to third-party advertisers or data brokers.

Section 02

Information We Collect

We collect personal data through several distinct channels, each described below. We only collect information that serves a legitimate, documented business purpose.

Information You Provide Directly

When you choose to get in touch with us — whether by sending an email to contato@stak-us.site, calling the phone numbers listed on this site, or reaching out via professional networking platforms such as LinkedIn — you voluntarily share personal information with us. The data you typically submit includes:

  • Your full name and, where relevant, your professional title or role within your organisation
  • Your business or personal email address
  • Your telephone or mobile number, if provided
  • The name of the company or institution you represent
  • The subject matter and content of your enquiry or message
  • Any documents or attachments you voluntarily include in your correspondence

We use this information exclusively to respond to your enquiry and, where relevant, to move forward with a business relationship. We do not add you to any marketing list without your explicit consent.

Data Collected Automatically

Like virtually every website on the internet, our site collects certain technical data automatically when you visit. This data is gathered through server logs and analytics tools and includes:

  • Your Internet Protocol (IP) address and approximate geographic location derived from it (country and city level)
  • The type and version of browser and operating system you are using
  • The referring URL — the page from which you arrived at our site, if applicable
  • The specific pages within our site that you visited and the order in which you visited them
  • The date, time and duration of your visit
  • Device identifiers, screen resolution and language settings
  • Click-path behaviour and scroll depth on individual pages

This technical data is used in aggregate form to understand how our site performs, where visitors come from, and how we can improve the experience. Where individual identifiers (such as IP addresses) are involved, we treat them as personal data and apply appropriate protections.

Data We Receive From Third Parties

We may occasionally receive business contact information from publicly available professional directories, commercial databases, or introductions facilitated by existing clients or partners. When this occurs, we use such information only to initiate a relevant professional conversation and we always inform the individual promptly of how we obtained their details and of their right to have them removed from our records.

Section 03

How We Use Your Information

We process personal data only where we have a clear, lawful basis for doing so. For each purpose below, we have identified the corresponding legal basis under both the LGPD and the GDPR.

Responding to Enquiries & Managing Client Relationships

When you contact us, we use the information you provide to understand your needs, prepare a considered response, and where appropriate, progress to a commercial proposal or engagement. This processing is based on the performance of a pre-contractual or contractual arrangement (LGPD Art. 7, II; GDPR Art. 6(1)(b)) and, where no contract exists, on our legitimate interest in operating a professional services business.

Improving Our Website and Services

Anonymised and aggregated analytics data helps us understand which content is most useful, how visitors navigate the site, and where improvements are needed. This is processed on the basis of our legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)) and does not result in decisions affecting individual visitors.

Compliance With Legal Obligations

We may be required by law, regulation, court order, or government authority to process and disclose certain personal data. In such cases, processing is based on compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)). We will always seek to limit such disclosure to the minimum extent required and, where legally permissible, will notify the data subject.

Marketing Communications

We will only send direct marketing communications — such as newsletters, service updates, or invitations to events — to individuals who have expressly opted in to receive them. Every such communication includes a straightforward and permanent opt-out mechanism. We do not purchase or rent marketing lists. We do not engage in behavioural advertising targeting or real-time bidding with personal data obtained through our website.

We never use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you without first obtaining your explicit consent.

Section 04

Cookies & Tracking Technologies

Cookies are small text files stored on your browser or device when you visit a website. We use cookies and similar tracking technologies (including web beacons and local storage) to ensure our site functions correctly, to understand how it is used, and to measure the effectiveness of our marketing channels.

Types of Cookies We Use

The table below outlines the categories of cookies active on our site, their purpose, and their typical retention period. We rely on Google Analytics for web analytics and may use Google Ads conversion tracking where paid advertising campaigns are active.

Your Cookie Choices

When you first visit our site, a consent banner allows you to accept or decline non-essential cookies. You can change your preferences at any time by clearing your browser cookies and revisiting the site, or by adjusting your browser settings to block or delete cookies. Please note that blocking essential cookies may impair the functionality of certain pages. Instructions for managing cookies are available in the help section of all major browsers.

You can also opt out of Google Analytics tracking directly at tools.google.com/dlpage/gaoptout, and manage your Google Ads personalisation preferences at adssettings.google.com. Neither of these tools requires you to share personal data with us.

Section 05

Sharing With Third Parties

STAK TECNOLOGIA LTDA does not sell, rent, or trade your personal information to any third party for their own commercial purposes. We may share limited personal data with the categories of recipient described below, and only to the extent strictly necessary.

Technology & Infrastructure Providers

We use carefully vetted third-party technology providers to host our website, deliver analytics, and manage email communications. These providers act as data processors on our behalf, bound by data processing agreements that prohibit them from using your data for any purpose beyond providing the contracted service. Current categories of sub-processor include:

  • Web hosting & CDN: Cloud infrastructure providers operating under ISO 27001-certified security programmes
  • Analytics: Google Analytics 4, operated by Google LLC, with data processing terms that include Standard Contractual Clauses for transfers outside the EEA/Brazil
  • Email delivery: Transactional email services used to route replies to enquiries from our mailbox
  • Advertising measurement: Google Ads conversion tracking, used solely to measure campaign performance — not for retargeting or profiling

Professional Advisors

Lawyers, accountants, auditors, and other professional advisors may process limited personal data where necessary to provide advice to STAK and are bound by professional confidentiality obligations in addition to any contractual protections.

Public Authorities

We will disclose personal data to Brazilian regulatory authorities (including the Autoridade Nacional de Proteção de Dados — ANPD), law enforcement agencies, courts, or other public bodies where we are legally compelled to do so. We will only disclose the minimum amount of information required and will seek to inform the individual in advance unless prohibited by law.

Business Transfers

In the event that STAK TECNOLOGIA LTDA undergoes a merger, acquisition, corporate restructuring, or sale of substantially all of its assets, personal data held by us may be transferred to the acquiring or successor entity. In such circumstances, we will provide advance notice on this page and ensure that the successor entity is bound by privacy commitments no less protective than those described in this policy.

International transfers: Some of our technology providers are headquartered outside Brazil. Where personal data is transferred internationally, we ensure adequate safeguards are in place — including Standard Contractual Clauses (for GDPR purposes) and the mechanisms recognised by ANPD under the LGPD.

Section 06

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to comply with our legal and contractual obligations, and to resolve any disputes or enforce our agreements. The specific retention periods we apply are as follows:

  • Enquiry and correspondence records: Retained for five years from the date of last contact, reflecting the standard limitation period under Brazilian civil law for contractual claims, and allowing us to reconstruct the history of any business relationship.
  • Active client data: Retained for the duration of the engagement plus five years following its conclusion, or longer where required by specific regulatory obligations applicable to the sector involved.
  • Analytics data: Aggregated and anonymised data is retained indefinitely as it no longer constitutes personal data. Individual-level event data in Google Analytics is retained for a maximum of 14 months.
  • Marketing consent records: Retained for the lifetime of the consent plus three years after withdrawal, to demonstrate compliance in the event of a regulatory inquiry.
  • Cookie consent logs: Retained for 12 months, after which a fresh consent will be sought.
  • Tax and financial records containing personal data: Retained for the period mandated by Brazilian tax law, currently a minimum of five years from the fiscal year to which they relate.

When the applicable retention period expires, personal data is securely and permanently deleted from our active systems and any backup copies are overwritten within the next scheduled backup cycle. Where complete deletion is not technically feasible (for example, in archived backup media), the data is isolated and protected from any further active processing.

Section 07

Data Security

Protecting the personal data entrusted to us is a core operational responsibility at STAK TECNOLOGIA LTDA. We implement a layered security architecture that reflects the sensitivity of the data involved and the current state of technology. Our measures include, but are not limited to:

  • Encryption in transit: All data exchanged between your browser and our web server is encrypted using TLS 1.2 or higher (HTTPS). We enforce HTTP Strict Transport Security (HSTS) to prevent protocol downgrade attacks.
  • Encryption at rest: Sensitive data stored on our servers and those of our hosting providers is encrypted at the storage layer using industry-standard algorithms.
  • Access controls: Access to systems containing personal data is restricted to personnel with a documented need to know. We apply the principle of least privilege, with role-based access controls and mandatory multi-factor authentication for administrative accounts.
  • Vendor security assessments: Before engaging any third-party sub-processor, we assess their security posture, review their data processing terms, and verify the existence of relevant certifications (such as ISO 27001 or SOC 2 Type II).
  • Incident response procedures: We maintain a documented incident response plan. In the event of a data breach that poses a risk to individuals' rights and freedoms, we will notify the ANPD within 72 hours of becoming aware of it, and will inform affected individuals without undue delay, in accordance with Article 48 of the LGPD and Article 33 of the GDPR.
  • Staff training: All team members who handle personal data receive regular training on data protection obligations and secure data handling practices.

While we make every reasonable effort to protect your data, no security system is impenetrable. We encourage you to use secure and unique passwords for any accounts you hold and to contact us immediately at contato@stak-us.site if you suspect any unauthorised use of your information in connection with our services.

Section 08

Your Rights

Brazilian law (LGPD Art. 18) and European law (GDPR Chapter III) grant you a comprehensive set of rights over your personal data. We are committed to honouring these rights promptly and without unnecessary barriers. The rights available to you are set out below:

Right of Access

You may request confirmation of whether we process your personal data and, if so, obtain a copy of the data we hold, along with information about how it is used, where it came from, and with whom it has been shared.

Right to Rectification

If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to request that we correct it without undue delay.

Right to Erasure

You may request the deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent, or where we have no overriding legitimate grounds for continued processing.

Right to Restriction

In certain circumstances — for example, while a correction request is being verified — you may ask us to restrict the processing of your data so that it is stored but not actively used.

Right to Data Portability

Where processing is based on your consent or a contract and is carried out by automated means, you may request that we provide your data in a structured, commonly used, machine-readable format, or transmit it directly to another controller where technically feasible.

Right to Object

You may object at any time to the processing of your personal data based on our legitimate interests, or to the use of your data for direct marketing purposes. Where you object to marketing, we will cease processing for that purpose immediately and permanently.

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal. We will action consent withdrawals within five business days.

Right to Lodge a Complaint

If you believe we have not respected your data protection rights, you have the right to lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd, or with the supervisory authority of your EU member state if you are based in Europe.

How to Exercise Your Rights

To exercise any of the rights listed above, please send a written request to contato@stak-us.site with the subject line "Data Rights Request". To protect you from unauthorised requests, we may need to verify your identity before processing the request — typically by asking you to confirm details already held on file. We will respond to all verified requests within 15 calendar days, extendable by a further 30 days in cases of complexity or high volume, with written notification of any extension.

There is no fee for exercising your rights, unless a request is manifestly unfounded or repetitive, in which case we reserve the right to charge a reasonable administrative fee or refuse to act on the request, notifying you accordingly.

Section 09

Children's Privacy

Our website and services are directed exclusively at businesses, professionals, and adults. We do not knowingly collect, process, or retain personal data from children under the age of 18. Our services have no feature, content, or commercial purpose that would attract or be directed at minors.

If we become aware that personal data belonging to a child under the age of 18 has been submitted to us — whether directly or through a third-party source — we will take immediate steps to delete that information from our records and, where relevant, to notify the child's parents or legal guardians. We will not process or retain such data for any purpose.

If you have reason to believe that a child has provided us with personal information without appropriate parental consent, please contact us at contato@stak-us.site and we will investigate and act within five business days.

Section 10

Changes to This Policy

We review this Privacy Policy at least once per year and update it whenever our practices change in a material way — for example, when we begin using a new analytics tool, onboard a new category of sub-processor, or when changes in applicable law require adjustments to how we describe our processing activities.

When we make material changes, we will update the "Last updated" date at the top of this page. Where a change is significant — meaning it materially affects the rights or expectations of data subjects — we will take additional steps to notify affected individuals directly, such as by email, where we hold their contact details and where the change concerns data they have submitted to us.

We encourage you to check this page periodically so you remain informed about how we protect your information. Continued use of our site following the publication of a revised policy constitutes your acknowledgement of the updated terms, subject always to your legal rights to object or withdraw consent where applicable.

All previous versions of this Privacy Policy are archived and can be made available upon request by emailing contato@stak-us.site.

Section 11

Contact & Data Controller Details

For any questions, concerns, or requests related to this Privacy Policy or to the processing of your personal data by STAK TECNOLOGIA LTDA, please reach out to us using the details below. We aim to acknowledge all data-related enquiries within two business days and to provide a substantive response within the timeframes set out in Section 08.

STAK TECNOLOGIA LTDA

We are the data controller for all personal information processed in connection with our website and corporate activities. If you have a privacy-related question or wish to exercise any of your legal rights, our team is ready to assist.

Company STAK TECNOLOGIA LTDA
CNPJ 67.979.603/0001-58
Address Rua 25 de Julho, 843, Apt 02, Nova Parobé, Parobé-RS, Brazil
Subject Please use "Privacy Enquiry" or "Data Rights Request" in your subject line for faster routing