Legal & Compliance

Privacy Policy

We believe privacy is a fundamental right, not a checkbox. This policy explains exactly what information Asper collects, why we collect it, how we protect it, and what control you have over your own data — in plain language, not legalese.

Last updated: July 1, 2025
GDPR & LGPD Compliant
Effective July 1, 2025
Section 01

Introduction

This Privacy Policy is issued by ASPER TECNOLOGIA LTDA, a company incorporated under Brazilian law (CNPJ 21.538.196/0001-42), with registered offices at Quadra SHIS QI 3 Bloco F, Pavimento Superior, S/N, Setor de Habitações Individuais Sul, Brasília — DF, Brazil (referred to throughout this document as "Asper", "we", "our" or "us").

We operate the website available at asper-us.site (the "Site") and provide technology and cybersecurity services to individuals and organizations. This policy applies to all visitors to our Site, prospective clients who contact us, and any person whose personal data we process in the course of our business activities.

We are committed to handling personal information responsibly and transparently, in full compliance with applicable data protection legislation — including the European Union's General Data Protection Regulation (GDPR), Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018), and any other applicable national or sector-specific privacy laws.

By visiting our Site or submitting your information to us, you acknowledge that you have read and understood this policy. If you disagree with any part of it, please refrain from using our Site and contact us with any questions before providing your data.

Section 02

Information We Collect

We only collect information that is relevant and necessary for the purposes described in this policy. We never collect data speculatively or beyond what is proportionate to the service being provided.

Information you provide directly

When you fill in a contact form, request a free assessment, submit a support inquiry, or otherwise reach out to us, you voluntarily supply personal data that may include:

  • Full name and professional title
  • Corporate email address and, where provided, a personal email
  • Phone number or WhatsApp contact
  • Company name, industry, and approximate size
  • A description of your technology environment or the security challenge you are facing, as written in the message field
  • Any attachments or documents you choose to submit

Providing this information is entirely voluntary. However, without certain fields (such as an email address), we may be unable to respond to your inquiry.

Information collected automatically

When you browse the Site, our web servers and third-party analytics tools automatically receive and record certain technical data, including:

  • IP address and approximate geographic location (country and city level)
  • Browser type, version, and language preference
  • Operating system and device type (desktop, tablet, or mobile)
  • Pages visited, time spent on each page, scroll depth, and navigation path
  • Referring URL — the page or search engine that directed you to our Site
  • Date and time of each visit
  • Interaction data such as button clicks and form interactions (without capturing keystrokes or unsubmitted form content)

Information from third-party advertising platforms

We run advertising campaigns on platforms including Google Ads. These platforms may share aggregated conversion signals with us when a visitor who clicked one of our advertisements subsequently completes an action on our Site (such as submitting a contact form). This data is used solely to measure campaign effectiveness and does not allow us to personally identify you beyond what you have already chosen to share through a form submission.

We do not collect sensitive personal data such as national identity numbers, financial account details, health information, biometric data, or the personal data of minors. We also do not purchase or receive mailing lists from third parties.

Section 03

How We Use Your Information

Every use of personal data requires a lawful basis. The table below explains the purposes for which we process your data, the legal basis we rely on under the LGPD and GDPR, and our legitimate interest where that basis is invoked.

Responding to inquiries and delivering services

When you contact us through the Site, we use the information you provide to understand your needs, respond to your message, schedule calls or demonstrations, and ultimately prepare and deliver proposals or services. Legal basis: Performance of a contract or pre-contractual steps at the data subject's request (LGPD Art. 7 V; GDPR Art. 6(1)(b)).

Site performance and user experience analytics

We analyze aggregated, pseudonymized behavioral data to understand which content is most useful to visitors, identify technical errors, and improve the overall quality and accessibility of the Site. Legal basis: Legitimate interests (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) — specifically our interest in maintaining a functional and informative website, balanced against the low privacy impact of anonymized analytics data.

Advertising measurement and conversion tracking

We use conversion data from Google Ads to measure the return on investment of our advertising spend. This allows us to allocate our budget responsibly and avoid over-advertising to people who have already engaged with us. Legal basis: Legitimate interests; where required, your consent via our cookie consent banner.

Legal compliance and fraud prevention

We may process or retain data where necessary to comply with a legal obligation, respond to a court order, cooperate with a regulatory inquiry, or investigate and prevent suspected fraudulent or abusive activity directed at our systems or clients. Legal basis: Compliance with a legal obligation (LGPD Art. 7 II; GDPR Art. 6(1)(c)).

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. We do not sell your data to third parties for their own marketing purposes.

Section 04

Cookies & Tracking Technologies

Our Site uses cookies and similar technologies (such as web beacons and local storage) to make the Site work properly and to help us understand how it is used. Below is a breakdown of the cookie categories we deploy.

Strictly necessary cookies

These cookies are essential for the basic functioning of the Site — for example, maintaining your cookie consent preferences and supporting secure form submissions. They do not track you across other websites and cannot be disabled without breaking core functionality. No consent is required for this category.

Analytics cookies

We use Google Analytics 4 to collect pseudonymous usage data. These cookies help us understand how many people visit the Site, which pages they find most useful, and where visitors typically exit. IP addresses passed to Google Analytics are anonymized before storage. We have configured our Google Analytics account to disable data sharing with other Google products and to respect user consent signals. Analytics cookies are only set if you accept them via our consent banner.

Advertising and measurement cookies

We use the Google Ads conversion tracking tag. When you click one of our Google advertisements and then visit our Site, a cookie is set by Google to record whether you subsequently completed a conversion action (e.g. submitting a contact form). This data is shared with us only in aggregate and does not reveal your identity. These cookies are only set with your explicit consent.

Managing your cookie preferences

When you first visit our Site, a consent banner will invite you to accept or decline non-essential cookies. You can change your preferences at any time by clicking the "Cookie Settings" link in the footer. You can also manage cookies directly in your browser by following the instructions provided in its help documentation. Note that disabling certain cookies may affect how the Site displays or functions.

For further information about the cookies Google places through our Site, please consult Google's own Privacy Policy at policies.google.com/privacy.

Section 05

Sharing With Third Parties

We do not sell, rent, or trade your personal data with any third party for their own commercial purposes. We share data only in the limited circumstances described below.

Service providers acting as data processors

We engage trusted service providers who process data on our behalf and strictly under our documented instructions. Current providers include:

  • Google LLC — analytics (Google Analytics 4) and advertising measurement (Google Ads). Google processes data in accordance with its Processor Terms and applicable Standard Contractual Clauses.
  • Cloud hosting and infrastructure providers — to host the Site and associated back-end systems. All providers are contractually bound to implement appropriate technical and organizational security measures.
  • Email delivery services — to forward contact-form submissions to our internal team. Form data is encrypted in transit and not stored by the delivery provider beyond the time needed to complete transmission.

All data processors are bound by written data processing agreements that impose obligations at least as protective as those required by the LGPD and GDPR.

Legal and regulatory disclosures

We may disclose personal data to government authorities, courts, or law enforcement agencies where we are legally required to do so, or where disclosure is necessary to protect our rights, the safety of our employees, or the public interest. We will, where legally permitted, notify you before making such a disclosure.

Business transfers

In the event of a merger, acquisition, or sale of all or part of our business assets, personal data held by Asper may be transferred to the acquiring entity. We will notify affected individuals by posting a prominent notice on our Site and, where feasible, by direct communication, before their data becomes subject to any new privacy policy.

International transfers: Some of our service providers operate servers outside Brazil and the European Economic Area. Where data is transferred to countries that do not offer an equivalent level of protection, we rely on Standard Contractual Clauses approved by the European Commission, or equivalent safeguards recognized under the LGPD, to ensure your data remains protected.

Section 06

Data Retention

We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve any disputes, and to enforce our agreements. We apply the following retention framework:

  • Contact form and inquiry data: Retained for up to 3 years from the date of last meaningful interaction. This period reflects the standard limitation period for contractual claims under Brazilian law and allows us to reference prior conversations if you re-engage as a client.
  • Active client data: Retained throughout the period of the service engagement and for 5 years thereafter, to satisfy record-keeping obligations under Brazilian tax and commercial legislation.
  • Analytics data: Google Analytics data is retained for 14 months under our account configuration, after which it is automatically aggregated or deleted by Google's systems.
  • Advertising conversion data: Conversion event data is retained for 90 days in Google Ads, consistent with Google's standard data policies and our own reporting needs.
  • Server logs: Web server access logs containing IP addresses and request metadata are retained for 90 days for security and troubleshooting purposes, then deleted automatically.

When data reaches the end of its retention period, it is either securely deleted or irreversibly anonymized, so that it can no longer be associated with any identified or identifiable individual. If you request erasure before a retention period expires, we will assess your request and delete the data unless a legal obligation requires us to maintain it — in which case we will explain that obligation to you.

Section 07

Data Security

Security is not incidental to what we do — it is the foundation of our business. We apply to the protection of personal data the same rigor we recommend to our clients. Our technical and organizational measures include:

  • All data transmitted between your browser and our Site is protected by TLS 1.2 or higher encryption (HTTPS). Our SSL/TLS configuration is regularly reviewed and maintained to current best practices.
  • Access to systems that store personal data is strictly controlled through role-based access policies. Only personnel with a documented need can access identifiable data, and all access is logged.
  • Personal data at rest in our infrastructure is encrypted using AES-256 or equivalent standards.
  • We conduct regular vulnerability assessments and penetration tests of our own infrastructure — consistent with the services we provide to clients.
  • Our team members undergo mandatory training on data handling, phishing awareness, and incident response procedures.
  • We maintain a documented data breach response plan. In the event of a breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and, where required, inform the relevant supervisory authority within 72 hours of becoming aware of the incident.

No method of electronic transmission or storage is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security. We encourage you to take care with the information you share online and to use strong, unique passwords for any accounts you hold with our service platforms.

Section 08

Your Rights

Depending on where you are located, you may have a number of rights in relation to the personal data we hold about you. Under the GDPR and Brazil's LGPD, these rights include all of the following:

Right of Access

You may request a copy of the personal data we hold about you, together with information about why we hold it, who we share it with, and how long we keep it.

Right to Rectification

If any data we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it without undue delay.

Right to Erasure

You may ask us to delete your personal data where we no longer have a legitimate or legal basis for retaining it. We will assess each request and respond within the statutory timeframe.

Right to Restrict Processing

In certain circumstances — for example, while you contest the accuracy of data we hold — you may ask us to pause processing while the matter is resolved.

Right to Data Portability

Where processing is based on consent or a contract and carried out by automated means, you may request your data in a structured, machine-readable format for transfer to another provider.

Right to Object

You may object at any time to processing based on our legitimate interests, including profiling for direct marketing purposes. We will stop unless we can demonstrate a compelling legitimate ground that overrides your interests.

Right to Withdraw Consent

Where processing is based on consent (such as analytics cookies), you may withdraw that consent at any time via the cookie settings panel or by contacting us directly. Withdrawal does not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint

If you believe we have not handled your data lawfully, you have the right to complain to your national data protection authority — in Brazil, the ANPD (Autoridade Nacional de Proteção de Dados); in the EU, the relevant supervisory authority in your member state.

How to exercise your rights

To submit a data rights request, please write to us at contato@asper-us.site with the subject line "Data Rights Request." Please include your full name, the email address used when contacting us, a description of the right you wish to exercise, and enough detail for us to locate your records. We will acknowledge your request within 5 business days and fulfill it within 15 calendar days — or within 30 calendar days for complex or multiple requests, with notification if an extension is needed.

We will not charge a fee for exercising your rights unless your requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act, and we will explain why.

Section 09

Children's Privacy

Our Site and services are directed exclusively at businesses and professionals. We do not knowingly collect, process, or store personal data relating to children under the age of 18, nor do we direct any marketing communications to individuals in that age group.

If you are a parent or guardian and you believe your child has provided personal data to us without your consent, please contact us immediately at contato@asper-us.site. We will promptly investigate and, where confirmed, delete the relevant data without undue delay.

Where local law defines the age of digital consent differently — for example, 16 in some EU member states — we will apply the higher threshold in those jurisdictions.

Section 10

Changes to This Policy

We review this Privacy Policy at least annually and whenever we make a material change to how we collect or process personal data. Changes may be prompted by updates to applicable legislation, new services we introduce, modifications to our third-party service providers, or feedback from our users.

When we make a material change, we will update the "Last updated" date at the top of this page and, depending on the significance of the change, we may also post a notice on the Site's homepage or send a direct notification to individuals on our contact list.

We encourage you to review this page periodically. Continued use of the Site after the effective date of a revised policy constitutes your acknowledgment of the changes. If you disagree with any revision, you are welcome to contact us before continuing to use our services.

Previous versions of this policy are available on request by writing to us at contato@asper-us.site.

Section 11

Contact Us & Data Controller Details

Asper Tecnologia Ltda is the data controller responsible for personal data processed in connection with our website and services. If you have any question about this Privacy Policy, wish to exercise a data right, or simply want to understand more about how we handle your information, please get in touch using the contact details below.

We aim to respond to all privacy inquiries within 5 business days. For formal data rights requests, the response timeframes described in Section 08 apply.

Data Controller

ASPER TECNOLOGIA LTDA
CNPJ: 21.538.196/0001-42
Quadra SHIS QI 3 Bloco F, Pavimento Superior, S/N
Setor de Habitações Individuais Sul
Brasília — DF, Brazil
Email: contato@asper-us.site
Use subject line: "Privacy Policy Inquiry" or "Data Rights Request"
Response time: within 5 business days for general inquiries;
within 15 calendar days for formal data rights requests.

If you have a complaint that we have not addressed satisfactorily, you may contact the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd, or, if you are located in the EU, the supervisory authority in your country of residence.