Privacy

Privacy

How we handle your data while you browse and contact Tailored Coding.

Responsibility for Processing

Tailored Coding Projetos de TI Ltda., registered under CNPJ 51.553.102/0001-75, is responsible for processing personal data received through this website. Our office is at Av. das Américas, 8.585, suite 465, Barra da Tijuca, Rio de Janeiro, RJ, Brazil, 22793-081.

This notice covers the institutional website and communications received by Tailored Coding. Data processing within contracted projects and services is also governed by the relevant agreements and instructions: depending on the activity, we may act as a processor on behalf of our clients. Those operations have their own scope, access rules and conditions.

For questions about your data or privacy requests, use the contact form and select Privacy and Personal Data Protection.

Browsing and Audience Measurement

Your browser may store your light or dark theme preference. The current tab’s history retains the page and reading position to support back, forward and resumed navigation. These features do not store the contact form’s text or attachment.

We use a widely adopted audience-measurement service to understand which content visitors read and improve website navigation and performance. The analysis serves a statistical purpose. Advertising personalization signals are disabled in this website’s configuration, and submitting a message does not subscribe you to mailing lists.

This service may process pages visited, interactions, referring sources, approximate location and browser and device characteristics. Cookies and technical identifiers distinguish visits and, when combined with other information, may identify a person. Names, email addresses, phone numbers and messages from the contact form are not sent to the measurement service.

The contact page does not load this service. You can block or delete cookies in your browser settings and still use the contact form. Deleting cookies does not erase records of earlier visits held by the service.

Privacy and Security by Design

Privacy and security guide decisions across this website: its structure, available features, choice of technology services, data use and maintenance. We apply privacy by design and security by design from initial design through ongoing operation, including the contact form.

The website uses protected connections and controls over the resources each page loads. Audience measurement serves a statistical purpose, with advertising personalization signals disabled in the site’s configuration. The contact page does not load the measurement service, and its fonts, images and form components are served by the website itself.

One example is the contact form, which includes the Whistleblowing Channel with specific protections for receiving reports. It encrypts content before sending, verifies recipient keys and uses fixed message destinations. Sending credentials are protected on the server. Selecting Whistleblowing Channel removes the identification requirement and stops the application from collecting visitor metadata for the report.

Anti-spam protection operates without external tracking services. It uses random, single-use challenges, temporary replay controls and security counters. To limit abuse, including in the Whistleblowing Channel, the server uses temporary identifiers derived from the network address with secret keys unique to each site. These counters do not store the IP address in plaintext, message content or browser data; they are not used to track browsing or correlate visitors across sites. Events expire after one hour; keys rotate hourly and are removed after up to two hours. Automatic cleanup runs every five minutes and during use; an operational failure may delay removal and requires correction. Typed text is not saved in browser storage. If sending fails, the message and selected file remain in the contact form for another attempt or removal using Clear.

Contact and Message Protection

Contact Form

You can use the contact form for software, artificial intelligence, infrastructure and security projects, proposals, partnerships, licensing, formal notices and institutional inquiries, privacy requests, complaints and suggestions. We use the information to review your message, direct it to the responsible team, respond and follow up.

For ordinary contacts, name, email address, purpose and message are required; a phone number is optional. The encrypted content includes the website and form identity, form language and version, and the date and time reported by the browser. To provide context, protect the service and prevent abuse, it may also include:

  • IP address observed by the server and an available referring page, without query parameters or fragments;
  • Browser and device characteristics, such as languages, platform, time zone, screen resolution and browser-reported capabilities;
  • Approximate browser identifier calculated from those characteristics using SHA-256;
  • Audience-measurement identifiers already present in cookies used by the website, without creating a new identifier for the submission.

This information depends on browser settings and availability and does not prove the sender’s identity. The contact form does not test images, audio or installed fonts to generate the technical identifier. Please send only information needed for the matter.

Sending Files

Every contact option, including the Whistleblowing Channel, allows one JPG, PNG, DOCX, PPTX, XLSX or PDF file smaller than 2 MB (2,000,000 bytes). The file and its name are encrypted with the message and used to address your inquiry.

Review the file before sending: documents and images can contain author information and other metadata. The contact form checks format and size but does not perform antivirus scanning.

Whistleblowing Channel

Use this channel exclusively to report suspected wrongdoing. Selecting it clears and disables the name, email and phone fields. Only the message is required; a file is optional. If you wish to identify yourself or receive a response, include your name or contact details in the report itself.

In this mode, the application does not collect or add to the report an IP address, referrer, browser fingerprint, measurement identifiers, contact details, location, browser language or submission time. The received message contains only the report, any attachment and fixed labels identifying the company, form and channel.

Hosting and email services still process technical information needed for connection and delivery, such as network addresses and times in service logs, as well as sender, recipient and other email headers. The application does not include these records in the report. Dispensing with identification in the contact form does not guarantee absolute anonymity across internet infrastructure.

Files and Identifying Information

A file can identify you through its name, contents or original metadata: author details, comments, revision history, document properties or a photograph’s location, for example. The file is delivered with these details inside the encrypted message.

You are responsible for reviewing the file and its metadata before sending. We do not remove this information or assume responsibility for identification resulting from data the sender includes in a file or its metadata. This responsibility does not exclude our legal obligations to safeguard the data we receive.

If you are unsure, submit text only. You can include an email address solely to receive our communications and request a secure file-sharing and collection link. After reviewing the request, our team will send the link and instructions; you can continue responding through the contact form without replying by email.

Choose the address carefully, as it may also identify you. A secure link protects sharing but does not remove identifying information from the file.

End-to-End Encryption

Contact form content is encrypted end to end, from the browser to the receiving mailboxes. The message, contact details, any included metadata and the attachment with its name are encrypted before leaving the browser. The email’s presentation and images are also covered.

The contact form uses OpenPGP, with AES-256 to encrypt content and the receiving mailboxes’ Curve25519 public keys to protect the session key for each recipient. The application verifies these keys; the private keys needed to read the message are not held on the website server. Connections use HTTPS and TLS, with TLS 1.2 or later and certificate validation for SMTP delivery.

Intercepting traffic alone does not reveal the message: the content remains encrypted and requires the corresponding private key. The sending server receives already encrypted content and does not store messages or field data in a local database. In the mailboxes, content remains stored under cryptographic protection and is opened by authorized recipients. The subject, addresses and other delivery headers do not receive the body’s end-to-end protection.

Protection also depends on the security of your device and browser, the integrity of the website and the receiving accounts. After reading, copies and forwarded messages require care appropriate to the content’s confidentiality.

Providers, Access and Retention

The form uses TC | Safe Sender, a secure-communication service developed and operated by Tailored Coding Projetos de TI Ltda., registered in Brazil under CNPJ No. 51.553.102/0001-75. Hosting, audience-measurement and email providers support website operation and message delivery. Access to content and forwarding are restricted to those handling, investigating or acting on the matter, as well as situations involving legal obligations or the exercise of rights, subject to applicable confidentiality obligations.

These services may use infrastructure outside Brazil, involving international data transfers subject to the LGPD. You can request information about the providers and processing arrangements through the contact form, using the privacy option.

We retain data for the time needed to handle and follow up on the matter, taking account of legal and regulatory obligations and the protection of rights. The period varies with the nature of the communication. After that period, data is deleted or anonymized, except where retention is legally permitted. Infrastructure access logs have their own purposes and retention periods, including those required by Brazil’s Internet Civil Framework where applicable.

Purposes and Legal Grounds

We use data for the purposes below, under the corresponding grounds in Brazil’s General Data Protection Law — LGPD.

Inquiries and Requests

Data and purpose: Names, contact details, messages and any attachments are used to answer questions, requests for information, complaints and suggestions, direct the matter to the responsible team and follow up.

Legal ground: Legitimate interests in assisting people who contact Tailored Coding, under articles 7(IX) and 10 of the LGPD. Use is limited to the request and related action.

Proposals, Negotiations and Contracts

Data and purpose: Contact details and information about technical needs, service proposals and documents are used to assess opportunities, conduct negotiations requested by the individual and perform or manage contracts.

Legal ground: Pre-contractual steps at the individual’s request and performance of a contract to which they are a party, under article 7(V). Data about company representatives is processed on the basis of legitimate interests in communications and managing the business relationship, under articles 7(IX) and 10.

Audience Measurement

Data and purpose: Pages visited, interactions, referring sources, approximate location, technical characteristics and cookie identifiers are used to produce statistics and improve website content, navigation and performance.

Legal ground: Legitimate interests in evaluating and improving the website, under articles 7(IX) and 10. Measurement does not receive form content or serve advertising personalization on this site. You can block cookies in your browser without losing access to the contact form.

Security and Abuse Prevention

Data and purpose: For ordinary contacts, IP addresses, available referring sources, browser characteristics and approximate identifiers, and existing audience identifiers help contextualize submissions and assess signs of abuse. Temporary challenges and limits per network source and channel protect the service against automated submissions. The Whistleblowing Channel does not include visitor metadata in the message. The temporary security controls described above also protect that channel, separately from the submitted content.

Legal ground: Legitimate interests in protecting the website and its users, under articles 7(IX) and 10. Legally required retention of access logs relies on article 7(II).

Receiving and Investigating Reports

Data and purpose: Reports and any attachments are used to assess suspected wrongdoing, investigate the facts and take appropriate action. Personal information in those materials is limited to what is needed for this work.

Legal ground: Legitimate interests in preventing and internally investigating wrongdoing, under articles 7(IX) and 10. Compliance with a specific legal or regulatory duty relies on article 7(II); use in judicial, administrative or arbitral proceedings relies on article 7(VI).

Sensitive data: Such information in a report or attachment is processed only where indispensable to a legal or regulatory obligation or the exercise of rights, under article 11(II)(a) and (d). Legitimate interests are not used as a ground for sensitive data. Please avoid including information unrelated to the reported facts.

Privacy Requests and Legal Obligations

Data and purpose: Information needed to locate records, confirm identity or representation and handle requests is used to respond to the exercise of data-protection rights. Information is also retained or provided to meet legal or regulatory duties or orders from competent authorities.

Legal ground: Compliance with a legal or regulatory obligation, under article 7(II), including the rights set out in article 18 of the LGPD.

Exercise of Rights in Proceedings

Data and purpose: Relevant communications and documents are used or retained to establish, exercise or defend rights in judicial, administrative or arbitral proceedings.

Legal ground: Article 7(VI); for sensitive data indispensable to this purpose, article 11(II)(d).

For processing based on legitimate interests, we limit use to necessary data, taking account of the individual’s expectations, rights and freedoms. Sending a message does not constitute blanket consent or authorize inclusion in advertising campaigns.

Your Rights

You can request access to your data, corrections, information about sharing and, where provided by the LGPD, portability, anonymization, blocking or deletion. You can also withdraw consent, object to processing and petition the data-protection authority.

Use the contact form and select Privacy and Personal Data Protection. Describe your request and provide the information needed to locate the relevant records. To protect your data, we may confirm your identity or your authority to represent another person. Reports without identification or contact details may prevent a response or later association with their author.

Links to publications and other websites open external services only when selected. Their data processing is governed by their own privacy information.