Pentagrama Consultoria & Sistemas

Legal & Compliance

Privacy Policy

Last updated: 14 July 2025  ·  Applies to: pentagrama.site and all associated digital services operated by PENTAGRAMA CONSULTORIA E SISTEMAS LTDA

This Privacy Policy explains what personal data PENTAGRAMA CONSULTORIA E SISTEMAS LTDA collects, why we collect it, how long we keep it, and the rights you hold over it — whether you are located in Brazil (protected under Lei Geral de Proteção de Dados, Law No. 13,709/2018, "LGPD") or in the European Economic Area (protected under the General Data Protection Regulation, "GDPR"). Please read this document carefully before submitting any information through our website or contacting us via email.

Introduction

PENTAGRAMA CONSULTORIA E SISTEMAS LTDA (hereinafter referred to as "Pentagrama," "we," "us," or "our") is a technology consulting and enterprise systems company registered in Brazil under CNPJ 03.660.397/0001-36, with its principal office at Avenida do Contorno, 3257, Sala 501, Santa Efigênia, Belo Horizonte – MG, Brazil.

We provide information-technology consulting, systems integration, ERP implementation, software development, and related managed services to corporate clients across Brazil. As part of delivering these services and operating our public website at pentagrama.site, we necessarily process certain personal data about website visitors, prospective clients, and business contacts.

We take privacy seriously. Our default position is to collect the minimum data necessary to fulfill the stated purpose, to hold it no longer than needed, and to give you meaningful control over your information at every stage. This policy describes those practices in clear, plain language, consistent with our obligations under the LGPD, the GDPR (where applicable), and guidelines issued by Brazil's National Data Protection Authority (ANPD).

By visiting our website or submitting information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please discontinue use of our website and refrain from submitting personal data to us.

Information We Collect

We collect personal data through two principal channels: information you actively provide to us, and information collected automatically as you browse our website. We do not purchase data from third-party brokers or compile profiles from social-media scrapers.

A — Contact Form & Enquiry Submissions

When you complete any contact, enquiry, or service-request form on our website, we collect the data you choose to enter. This typically includes your full name, professional email address, telephone number (optional), company or organisation name, job title or role, and the content of your message or project description. Providing this data is entirely voluntary; however, without it we cannot respond to your enquiry or evaluate a potential engagement.

B — Email Correspondence

If you contact us directly at contato@pentagrama.site or any related address, we will hold the content of that exchange, the metadata associated with the email (timestamp, sender address, headers), and any documents or files you choose to attach. This data is kept in our secure email infrastructure and CRM system solely for the purpose of managing your enquiry and maintaining a coherent communication record.

C — Technical & Usage Data (Automatic Collection)

When you visit pentagrama.site, our web server and analytics tools collect certain technical data automatically. This includes your IP address (which may be pseudonymised depending on your consent settings), browser type and version, operating system, referring URL, the pages you visit on our site, time and duration of visits, and device type. This data is processed in aggregated or pseudonymised form and is used exclusively to maintain site performance and understand how visitors navigate our content. We do not use this data to build individual behavioural profiles for advertising purposes without your explicit consent.

D — Cookie-Stored Data

Our website uses cookies and similar technologies. The categories of data stored or accessed via cookies — and your options for managing them — are described in detail in Section 4 (Cookies & Tracking Technologies) below. Strictly essential cookies are deployed without consent because they are required for the website to function; all other cookies require your prior, freely given agreement.

We do not knowingly collect sensitive personal data (such as health information, racial or ethnic origin, religious beliefs, political opinions, biometric data, or financial account details) through our website. If the nature of a specific engagement later requires us to handle sensitive data, we will obtain explicit consent and apply enhanced safeguards before doing so.

How We Use Your Information

Every use of your personal data is grounded in a specific, documented legal basis. We rely on the following bases, as recognised by both the LGPD (Art. 7) and the GDPR (Art. 6): consent, legitimate interest, contractual necessity, and compliance with a legal obligation. Below is a concrete account of each purpose for which we process your data:

  • Responding to enquiries: When you submit a contact form or send us an email, we use the information you provide to assess your needs, prepare a response, and, where relevant, produce a commercial proposal. Legal basis: pre-contractual steps taken at your request (LGPD Art. 7-V; GDPR Art. 6(1)(b)).
  • Contract management: Once a client relationship is established, we process business-contact data to coordinate projects, send deliverables, issue invoices, and fulfil our contractual obligations. Legal basis: contract performance and legitimate interest.
  • Website analytics and improvement: Aggregated and pseudonymised usage statistics allow us to identify which content is most relevant to visitors, fix technical issues, and improve overall site quality. Legal basis: legitimate interest (with privacy-protecting defaults such as IP anonymisation). We balance this interest against visitor rights and conclude the impact is minimal given the aggregated nature of the data.
  • Marketing communications (where consented): If you have explicitly opted in, we may send you relevant content such as articles, case studies, product announcements, or invitations to events related to enterprise technology. You may withdraw consent at any time using the unsubscribe link in any such email or by contacting contato@pentagrama.site. Legal basis: consent.
  • Legal and regulatory compliance: We may process and retain data where required by Brazilian law (e.g., fiscal record-keeping obligations under the Código Tributário Nacional) or to respond to a lawful request from a competent authority. Legal basis: legal obligation.
  • Fraud prevention and site security: Server logs and access data are monitored to detect and respond to malicious traffic, denial-of-service attempts, and other security threats. Legal basis: legitimate interest in maintaining service integrity.

We will never sell, rent, or trade your personal data to third parties for their own marketing purposes. We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.

Cookies & Tracking Technologies

Cookies are small text files placed on your device when you visit a website. We also use web beacons (single-pixel images) and similar technologies in some contexts. The table below explains the categories of cookies we deploy, the specific purposes each serves, and the legal basis that justifies them.

Managing your cookie preferences: Upon your first visit to pentagrama.site you will be presented with a consent banner that allows you to accept, reject, or configure non-essential cookies by category. You can change your preferences at any time by clicking the "Cookie Settings" link in our website footer. Additionally, all major browsers allow you to block or delete cookies through their settings menus. Please be aware that disabling certain categories of cookies may impair some website functionality.

Google Analytics: We use Google Analytics 4, operated by Google LLC. Data is processed on Google's servers in accordance with Google's privacy policy. We have activated IP anonymisation so that full IP addresses are never stored. We have also executed a Data Processing Agreement with Google as required by the LGPD and GDPR. For opt-out options beyond our consent manager, you may install the Google Analytics Opt-out Browser Add-on.

Google Ads: Where marketing cookies are accepted, we may use Google Ads conversion tracking and remarketing to measure the effectiveness of advertising campaigns and to display relevant advertisements on Google's partner network. No personally identifiable information is transmitted to Google through these tags; only pseudonymous identifiers are used.

Sharing With Third Parties

We do not disclose your personal data to outside parties except in the specific, controlled circumstances described below. In each case we apply appropriate contractual, technical, and organisational safeguards to protect the data in transit and at the recipient's end.

  • Service providers (data processors): We engage a small number of trusted vendors who process personal data on our behalf and under our instructions. These currently include our web hosting and cloud infrastructure provider, our email delivery platform, our CRM system, and our website analytics provider (Google Analytics). Each vendor is bound by a Data Processing Agreement (DPA) that prohibits them from using your data for any purpose other than providing the agreed service to us.
  • Professional advisors: Our legal counsel, auditors, and accountants may have incidental access to personal data in the course of providing advisory services. All are bound by professional confidentiality obligations.
  • Law enforcement and regulatory authorities: We will disclose personal data to police, courts, or regulators where we are legally compelled to do so by a court order, judicial authority, or applicable law. We will, where legally permitted, notify affected individuals of such disclosures.
  • Business transfers: In the event of a merger, acquisition, corporate restructuring, or sale of all or part of Pentagrama's business, your personal data may be transferred to the successor entity. We would notify you of any such transfer in advance and inform you of your rights in that context.

We do not transfer personal data to recipients outside Brazil or the European Economic Area without ensuring adequate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses (SCCs) approved by the relevant authority, or binding corporate rules. Where such transfers occur — for instance, because a service provider operates infrastructure in another jurisdiction — we document them in our data transfer records and make the relevant safeguards available upon request.

Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our general retention schedule is as follows:

  • Enquiry and pre-sales contact data: Retained for up to 2 years from the date of last contact. If an enquiry does not progress to a client relationship within 12 months and there is no ongoing correspondence, we review and delete or anonymise the record.
  • Client and contract-related data: Retained for a minimum of 5 years after the termination or expiry of the contractual relationship, consistent with Brazilian civil and tax law obligations (including the requirement to retain fiscal documents for 5 years under the CTN).
  • Email correspondence: Retained for up to 3 years, unless the correspondence forms part of a contractual record (in which case the contractual retention period applies) or we are required to retain it longer by law.
  • Website analytics data: Session and event data retained for up to 13 months before automatic deletion or aggregation at the analytics platform level. Anonymised aggregated statistics may be retained indefinitely.
  • Cookie consent records: Retained for 3 years as evidence of consent, in compliance with LGPD audit requirements.
  • Marketing opt-in records: Retained for the duration of the subscription plus 3 years after unsubscription, to document the existence and withdrawal of consent.

When personal data reaches the end of its retention period, we delete it securely or anonymise it so that it can no longer be associated with an identifiable individual. Our records management procedures are reviewed annually.

Data Security

As a technology company, data security is not merely a compliance obligation for Pentagrama — it is central to our professional identity. We implement a layered set of technical and organisational security measures proportionate to the nature and volume of personal data we process:

  • Encryption in transit: All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher. Our web server enforces HTTPS and implements HTTP Strict Transport Security (HSTS).
  • Encryption at rest: Personal data stored in our databases and CRM systems is encrypted at rest. Backups are encrypted before transmission to off-site storage.
  • Access control: Access to personal data is restricted on a strict need-to-know basis. We use role-based access control (RBAC), and all internal systems are protected by strong authentication, including multi-factor authentication (MFA) for administrative accounts.
  • Vendor security assessments: We assess the security practices of all data processors before engaging them and periodically review their compliance throughout the relationship.
  • Staff training: All employees who handle personal data receive privacy and information-security training upon joining and at regular intervals thereafter.
  • Incident response: We maintain a documented data-breach response procedure. In the event of a breach that poses a risk to individuals' rights and freedoms, we will notify the ANPD within 72 hours (as required by LGPD Art. 48) and, where required, notify affected individuals without undue delay.

No method of data transmission over the internet or electronic storage is completely secure. While we strive to use commercially robust means to protect your personal data, we cannot guarantee its absolute security. In the event you have reason to believe your interaction with us is no longer secure, please contact us immediately at contato@pentagrama.site.

Your Rights

Depending on your location, you hold various rights over your personal data. The rights below are granted under the LGPD (for data subjects in Brazil) and substantially mirrored by the GDPR (for data subjects in the EEA). We honour all of them regardless of where you are based.

Right of Access

You may request confirmation of whether we process personal data about you and, if so, a copy of that data along with details of how it is used, stored, and shared.

Right to Correction

If any personal data we hold about you is inaccurate or incomplete, you may ask us to correct or supplement it without undue delay.

Right to Deletion

You may request the erasure of personal data we process on the basis of your consent, or data that is no longer necessary for the purpose for which it was collected. Exceptions apply where retention is required by law or to defend legal claims.

Right to Restriction

You may ask us to suspend the active processing of your data while a dispute about its accuracy or our legal basis for processing it is being resolved.

Right to Portability

Where processing is based on consent or contract, you may request your data in a structured, commonly used, machine-readable format, or ask us to transmit it directly to another controller where technically feasible.

Right to Object

You may object at any time to the processing of your personal data where we rely on legitimate interest as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Right to Withdraw Consent

Where you have given consent to processing (e.g., for marketing emails or non-essential cookies), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right Not to Be Subject to Automated Decisions

You have the right not to be subject to decisions based solely on automated processing — including profiling — that produce legal effects or similarly significant outcomes. We do not conduct such processing; if this changes, we will seek explicit consent.

How to exercise your rights: Submit a written request by email to contato@pentagrama.site with the subject line "Data Rights Request." To protect your privacy and verify your identity before actioning requests, we may ask you to provide basic identifying information. We will respond within 15 calendar days for routine requests, consistent with LGPD Art. 19, and will inform you if a complex request requires additional time (up to a maximum of 30 days).

If you believe we have failed to handle your personal data in accordance with this policy or applicable law, you have the right to lodge a complaint with Brazil's National Data Protection Authority (ANPD — Autoridade Nacional de Proteção de Dados, www.gov.br/anpd). EEA residents may also complain to their local supervisory authority.

Children's Privacy

Our website and services are directed exclusively at business professionals and corporate entities. We do not knowingly solicit or collect personal data from individuals under the age of 18. If you are a parent or guardian and believe that a minor has submitted personal data to us without appropriate parental consent, please contact us immediately at contato@pentagrama.site. We will investigate promptly and delete any such data from our systems.

Where any future service or offering may potentially engage with younger audiences, we will implement age-verification measures and obtain verifiable parental consent as required by the LGPD (Art. 14) before collecting any personal data from children or adolescents.

Changes to This Policy

We review this Privacy Policy at least annually and update it whenever our data practices change materially — for example, if we begin using a new analytics platform, add a new form to our website, or alter our data-sharing arrangements. The "Last updated" date at the top of this page reflects the most recent revision.

When changes are material — meaning they significantly affect your rights or how your data is processed — we will make reasonable efforts to notify you proactively. This may include placing a notice on our homepage, updating the consent banner on our website, or sending an email notification to contacts in our CRM system who have previously provided their address. For minor, non-material changes (such as corrections to spelling or structural reorganisation that does not alter substance), we will update the document without separate notification.

Your continued use of our website following the posting of changes constitutes acceptance of those changes. If you do not agree with a revised policy, please discontinue use of our website and exercise your right to request deletion of any personal data we hold about you.

Contact & Data Protection Officer

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by Pentagrama, please contact us using the details below. We take all privacy enquiries seriously and will respond within the timeframes set out in Section 8.

Company
PENTAGRAMA CONSULTORIA E SISTEMAS LTDA

CNPJ
03.660.397/0001-36

Registered Address
Avenida do Contorno, 3257, Sala 501
Santa Efigênia, Belo Horizonte – MG, Brazil

Privacy & Data Enquiries
contato@pentagrama.site

Please include "Privacy Policy" or "Data Rights Request" in your subject line so your message is routed promptly to the right team.

In accordance with LGPD Art. 41, Pentagrama designates a Data Protection Officer (Encarregado de Dados) responsible for acting as the point of contact between the company, data subjects, and the ANPD. Contact details for the DPO are available at the email address above; please mark your message for the attention of the DPO.