Privacy

Privacy Policy

This Policy explains how Graal Solutions handles personal data and the principles used to protect information under applicable Brazilian law.

1. Purpose

Graal Solutions LTDA, a private legal entity headquartered in Florianópolis, Santa Catarina, Brazil, recognizes the importance of privacy and the protection of personal data belonging to clients, partners, employees and visitors to its digital channels.

This Privacy Policy explains, in a clear and transparent manner, how personal data processed by Graal Solutions may be collected, used, stored and shared, in accordance with Brazilian Law No. 12,965/2014 (Marco Civil da Internet), Law No. 13,709/2018 (General Data Protection Law — LGPD) and other applicable legislation.

This Policy applies when you access our website, use our IT support services or interact with us through our communication channels.

2. Personal data we collect

Graal Solutions seeks to collect only personal data necessary for IT support services, client relationships and institutional communication.

2.1 Information provided directly by the data subject

  • Full name.
  • Email address.
  • Contact telephone number(s).
  • Company or organization.
  • Messages sent through email, telephone, WhatsApp, or other service channels made available by Graal.
  • Data required to perform IT support agreements.

2.2 Information collected automatically

When you access our website, information may be collected automatically, including:

  • IP address with connection date and time.
  • Approximate geolocation data.
  • Device and browser type.
  • Pages visited and interactions performed.
  • Cookies and similar technologies, when used, to improve the browsing experience.

3. Purposes of processing

  • Respond to requests submitted through our contact channels.
  • Provide IT support services efficiently and appropriately.
  • Maintain communications regarding service updates, commercial proposals and technical support.
  • Comply with legal and regulatory obligations.
  • Analyze performance and continuously improve our services and website.
  • Conduct advertising or informational communications when legally authorized.

4. Sharing of personal data

Graal Solutions does not sell personal data.

Personal data may be shared when necessary with:

  • Hosting and cloud-service providers required for information security and availability.
  • Technical and commercial partners when essential to contract performance or service improvement.
  • Public authorities when required by law or court order.
  • Auditors and specialized consultants supporting information-security compliance.

5. International data transfers

Although our infrastructure is primarily based in Brazil, international data transfers may occur when cloud services or technology tools use servers located in other countries.

Where applicable, Graal adopts contractual and technical safeguards intended to maintain the level of protection required by Brazilian law.

6. Data retention

Personal data is retained only for the period necessary to fulfill the relevant processing purposes, subject to applicable legal requirements and the principles of necessity, purpose and data minimization under the LGPD.

Retention periods may vary according to the nature of the data and applicable legal basis. In general, Graal applies the following criteria:

  • Client and contract data: up to 10 years after the end of the commercial relationship, subject to applicable legal requirements.
  • Employee and former employee data: up to 5 years after termination of the employment relationship, subject to labor and social-security requirements.
  • System access records and logs: generally 6 months to 1 year, according to applicable requirements and operational needs.
  • Job applicant data: up to 1 year after the recruitment process.
  • Data processed on the basis of consent: until consent is withdrawn, unless another legal basis requires retention.

7. Security of personal data

Graal adopts technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, destruction or improper disclosure.

These measures are aligned with our ISO/IEC 27001 and ISO/IEC 27701 management systems and include, where applicable:

  • Multi-factor authentication (MFA).
  • Encryption for sensitive information in transit and at rest where applicable.
  • Least-privilege access controls.
  • Periodic access reviews.
  • Corporate credential-vault practices.
  • Logical network and environment segregation.
  • Centralized monitoring and security alerts.
  • Encrypted backup practices.
  • Confidentiality policies and agreements.
  • Formal security and privacy incident-response procedures.

Security limitations

No system is completely invulnerable. Graal therefore also encourages good digital-security practices, including strong passwords, protection of credentials and caution regarding suspicious communications.

8. Data-subject rights

Under the LGPD, data subjects may exercise rights provided by law, including:

  • Confirm whether processing exists.
  • Access personal data.
  • Correct incomplete, inaccurate or outdated data.
  • Request anonymization, blocking or deletion where legally applicable.
  • Request data portability where applicable.
  • Withdraw consent where consent is the legal basis.
  • Request information regarding data sharing.

9. Data Protection Officer (DPO)

The DPO is responsible for receiving requests from data subjects and communications with Brazil's National Data Protection Authority (ANPD).

  • DPO: Juliano Pedroso de Andrade.
  • Email: dpo@graalsolutions.tech.
  • Address: Madison Center, Suite 709, Avenida Desembargador Vitor Lima, 260 — Trindade, Florianópolis — SC, 88040-400, Brazil.
  • General contact: contact@graalsolutions.tech.
  • Telephone: +55 (48) 3204-8709.

10. Changes to this Policy

Graal Solutions may update this Privacy Policy as necessary due to legal, regulatory or internal process changes. The most recent version will be made available on our website. Where applicable, material changes requiring additional consent will be communicated appropriately.

11. Governing law and forum

This Policy is governed by Brazilian law, particularly the LGPD. Disputes are subject to the courts of Florianópolis, Santa Catarina, Brazil, subject to any mandatory legal provisions to the contrary.