Privacy Policy
Last updated: August 8, 2026This Privacy Policy explains how GNSEN Desenvolvimento e Licenciamento de Software, registered under TAX ID no. 61.088.547/0001-85, headquartered in São Paulo/SP, Brasil, processes personal data received through the GNSEN website.
For LGPD purposes, GNSEN acts as the controller of the personal data processed in the activities described in this policy.
For matters related to privacy and personal data protection, contact us through: privacy@gnsen.com.br .
Summary
This policy covers the GNSEN institutional website and the contact form available on the website.
GNSEN collects the data you provide through the contact form, as well as contextual and technical information necessary for service, security, and abuse prevention.
We use this data to respond to your contact, understand the request provided, evaluate a possible quote or engagement, protect the website against abuse, diagnose technical failures, comply with legal obligations, and exercise rights when necessary.
GNSEN does not sell personal data.
What data is collected
When filling out the contact form, you may voluntarily send us:
- name;
- company, when provided;
- email;
- message.
When the form is accessed from a service page, we may also record the service related to the request and information about the page from which the contact was initiated. This data is used to contextualize the request and understand which website content initiated the contact.
Technical data necessary for security and abuse prevention may also be processed, such as IP address, browser and runtime environment information, Cloudflare Turnstile validation results, and signals related to automated interactions.
The website may also generate technical access logs containing request date and time, IP address, accessed route, HTTP method, response code, and browser information. These logs are used for security, failure diagnosis, abuse prevention, and compliance with legal obligations.
The “message” field is free text. Therefore, do not send passwords, tokens, documents, financial data, or any other unnecessary information. Also do not send sensitive personal data, such as health data, biometrics, racial or ethnic origin, religious belief, political opinion, or union membership.
If sensitive personal data is sent without request and is not necessary for service, it may be disregarded and deleted as soon as it is identified. When its retention is indispensable, processing will occur only based on a legal basis applicable to sensitive personal data.
How we use the data
Data submitted through the form is used to:
- reply to your message;
- understand the context of the request provided;
- conduct preliminary conversations about a quote, proposal, or engagement, when applicable;
- protect the form against spam, abuse, automated attempts, and misuse;
- comply with legal or regulatory obligations, when applicable;
- exercise GNSEN's rights in judicial, administrative, or arbitration proceedings, when necessary.
Legal bases
Personal data processing may occur based on the following hypotheses provided by the LGPD, depending on the case:
- legitimate interest, to respond to contacts received, maintain the requested communication, protect the website and form against abuse, and perform technical diagnosis of failures, while observing the rights and legitimate expectations of data subjects;
- preliminary procedures related to a contract, when the message involves a request for quote, proposal, engagement, or provision of services;
- compliance with a legal or regulatory obligation, when applicable;
- regular exercise of rights in judicial, administrative, or arbitration proceedings, when necessary.
Where data is processed
Messages sent through the form are forwarded to the email contact@gnsen.com.br .
Data is also processed by internal automation systems and may be stored in the hosting infrastructure used by GNSEN.
Currently, GNSEN uses:
- Vultr, as VPS/hosting provider;
- Proton Mail, as email provider;
- Cloudflare, as DNS, proxy, CDN, network protection, and Cloudflare Turnstile provider.
Internal automation systems are self-managed by GNSEN and are not treated here as external providers with whom data is shared.
Cloudflare Turnstile
The website uses Cloudflare Turnstile to protect the form against spam and abuse. To perform this verification, Cloudflare may process technical signals such as IP address, browser and connection information, technical identifiers of the widget and its origin, as well as anti-fraud verification results.
This information is used for form security and prevention of automated or improper use.
Cookies, analytics, and advertising
The website does not use optional analytics, advertising, profiling, or commercial tracking cookies.
Cloudflare security features may use cookies or technologies strictly necessary to protect the website and prevent malicious traffic, according to the active configuration. Cloudflare Turnstile is used separately for security and abuse prevention, as described in this policy.
Data sharing
GNSEN may allow infrastructure, security, and email providers to process personal data only to the extent necessary to operate the website, deliver messages, protect the form, and maintain the technical infrastructure.
These providers currently include Vultr, Proton Mail, and Cloudflare.
We may also share or preserve information when necessary to comply with a legal obligation, respond to a request from a competent authority, or exercise GNSEN's rights.
International transfer
Some infrastructure, security, and email providers may process or store data outside Brazil.
When an international transfer of personal data occurs, GNSEN will adopt the applicable mechanism provided in art. 33 of the LGPD and in ANPD's International Data Transfer Regulation, according to the operation and destination country.
Data retention
Contact messages that do not result in a commercial relationship will be kept for up to 24 months after the last interaction.
The execution history of the self-managed n8n instance will be kept for up to 7 days, unless manually cleaned earlier.
Application access logs covered by the Brazilian Internet Civil Rights Framework will be kept confidentially and in a controlled and secure environment for the legal period of six months. GNSEN does not maintain its own backups of data submitted through the form; infrastructure, security, and email providers may keep technical copies according to their own operational cycles and applicable obligations.
When there is an engagement, dispute, legal obligation, need for accountability, or regular exercise of rights, data may be retained for the legally applicable periods or for the time necessary to meet these purposes.
After the applicable period ends, data will be deleted or anonymized, except when retention is authorized by law. Any technical copies kept by providers will remain protected and restricted to continuity, security, and recovery purposes, and will be deleted according to the contractually established cycles and mechanisms made available by those providers.
If a conversation initiated through the form results in a proposal, engagement, invoice issuance, billing, support, or provision of services, new data may be collected and processed according to documents, records, contracts, or specific notices applicable to those relationships.
Security
GNSEN adopts technical and administrative measures that are adequate and proportional to the nature of the data, the characteristics of the processing, and the risks involved, with the goal of protecting personal data against unauthorized access, loss, alteration, improper disclosure, or inadequate processing.
These measures seek to reduce risks, but no system is completely immune to incidents. If you identify any suspicion of misuse involving data submitted through the website, contact us through the privacy channel indicated in this policy.
Data subject rights
Under the LGPD, you may request, as applicable:
- confirmation of the existence of personal data processing;
- access to the personal data processed;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data under the LGPD;
- deletion of personal data processed with consent, except in legal retention cases;
- data portability, subject to applicable regulation;
- information about public and private entities with which data has been shared;
- information about the possibility of not providing consent and the consequences of refusal, when processing depends on consent;
- withdrawal of consent, when processing is based on consent;
- objection to processing carried out based on one of the consent waiver hypotheses, when there is non-compliance with the LGPD;
- review of decisions made solely based on automated processing of personal data, when applicable;
- petition before the Brazilian National Data Protection Authority (ANPD);
- filing a complaint before consumer protection bodies, when applicable.
To exercise your rights, send a request to privacy@gnsen.com.br . We may request additional information to confirm your identity and protect your data against improper access. Requests will be handled free of charge, within the legally applicable deadlines and terms. Confirmation of the existence of processing or access to data may be provided in simplified format or through a clear and complete statement.
Changes to this policy
This Privacy Policy may be updated to reflect changes to the website, internal processes, providers used, or legal and regulatory requirements.
The current version will always be the one published on this page, with the date of the last update indicated.