Introduction
USINA INTELIGENCIA ARTIFICIAL LTDA (CNPJ 67.993.093/0001-73), trading as Usina.Ia, is a company headquartered at Rua Rocha Lagoa, 92, Sala 01, Cachoeirinha, Belo Horizonte — MG, Brazil. We develop and commercialise artificial intelligence solutions, automation pipelines, and strategic AI consulting services for businesses across Brazil and abroad.
This Privacy Policy governs the collection, use, storage, and disclosure of personal data by Usina.Ia through our institutional website at usinaia.site and any related sub-pages. It applies to visitors, prospective clients, partners, and any other individual whose data reaches us through their interaction with our online presence.
We are committed to full compliance with Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018), the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), and any other applicable data-protection legislation. Where the two frameworks overlap, we apply the higher standard of protection.
By accessing our website, you acknowledge that you have read and understood this policy. If you do not agree with any of its terms, please discontinue use of the site and contact us at the address provided in Section 11 with any questions before proceeding.
Information We Collect
We collect personal data only to the extent strictly necessary for the purposes described in this policy. The categories of data we may process are outlined below, together with the context in which each arises.
We do not collect sensitive personal data (also known as special-category data under GDPR and LGPD), such as health records, biometric identifiers, racial or ethnic origin, religious beliefs, or political opinions. We also do not purchase third-party data lists or compile user profiles from external sources.
How We Use Your Information
Every piece of personal data we hold is used only for a defined, legitimate purpose. The table below maps data categories to the purposes we pursue and the legal basis under which we process them (Article 6 GDPR; Articles 7–10 LGPD):
Responding to enquiries and communications: When you contact us by email or any equivalent channel, we use the data you provide to understand your enquiry and reply in a timely, relevant manner. Legal basis: performance of a pre-contractual measure at your request; legitimate interest.
Assessing service suitability: Contact data and any project details you share allow our team to evaluate whether our AI solutions match your needs and to prepare an appropriate initial response or proposal. Legal basis: legitimate interest; pre-contractual steps.
Improving website performance and user experience: Aggregated analytics data helps us understand which content is valuable, identify navigation problems, and continually refine the site. Legal basis: legitimate interest (where data is anonymised or pseudonymised).
Marketing and advertising measurement: We use Google Ads conversion tracking to understand which campaigns bring qualified visitors to our site. This allows us to allocate our marketing budget responsibly and avoid irrelevant outreach. Legal basis: consent (where required by law); legitimate interest.
Legal compliance and record-keeping: We may be required by law or regulatory authority to retain certain records — for example, communication logs relevant to a dispute or a regulatory enquiry. Legal basis: compliance with a legal obligation.
Security and fraud prevention: IP address logs and server data are retained for a short period to detect and respond to suspicious activity, brute-force attempts, or other threats to site integrity. Legal basis: legitimate interest; legal obligation.
We will never use your personal data for automated decision-making that produces legal or similarly significant effects on you, nor will we use it for purposes incompatible with those stated here without first obtaining your explicit consent or another valid legal basis.
Cookies & Tracking Technologies
Cookies are small text files placed on your device by a web server when you visit a site. They help the site function correctly, remember your preferences, and gather aggregated information about how visitors use the site. We use the following categories of cookies on usinaia.site:
| Category | Purpose | Examples | Consent required? |
|---|---|---|---|
| Strictly necessary | Enable core site functionality and security. The site cannot work properly without these cookies. | Session management, CSRF protection | No — cannot be disabled |
| Performance & analytics | Collect anonymised data about how visitors use the site — page views, time on page, traffic sources — so we can improve the experience. | Google Analytics (_ga, _gid, _gat) | Yes |
| Marketing & advertising | Track conversions from Google Ads campaigns and enable remarketing to visitors who have shown interest in our services. | Google Ads (_gcl_au, _gcl_aw) | Yes |
| Preferences / functional | Remember choices you have made (such as cookie consent status or display preferences) so you are not repeatedly prompted. | Cookie consent flags | No — functional only |
Google Analytics is configured with IP anonymisation enabled, which means the last octet of your IP address is masked before any processing occurs within Google's infrastructure. We do not use the User ID feature and have disabled data sharing with Google signals for advertising personalisation by default.
Google Ads conversion tracking places cookies when a user arrives at our site from a Google Ads advertisement, allowing us to measure whether that visit results in a meaningful action (such as navigating to our contact page). The data is reported in aggregate and is not linked back to identifiable individuals on our end.
Managing cookies: You may at any time change your browser settings to refuse all cookies, accept only specific categories, or delete cookies already stored on your device. Please note that disabling performance or marketing cookies may affect how you experience the site and may reduce the relevance of any advertising you see elsewhere. Detailed instructions for managing cookies are available from your browser's help documentation (Chrome, Firefox, Safari, Edge).
Sharing With Third Parties
We do not sell, rent, or trade your personal data to any third party. We will never share your information with companies seeking to market unrelated products or services to you. We do, however, share data with a small number of carefully selected sub-processors and service providers that are essential to operating this website:
All third-party processors are bound by data-processing agreements that require them to process personal data only on our documented instructions, maintain appropriate security measures, and not engage additional sub-processors without our prior consent.
Beyond the providers listed above, we may disclose personal data if and to the extent required by applicable law, a binding court order, or a request from a competent public authority — in which case we will, where legally permitted, notify you before complying. We may also disclose data to enforce our legal rights or to protect the safety and security of our users, staff, or systems.
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity, provided that the successor is bound by equivalent privacy protections. We will notify you of any such change via a prominent notice on this website.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required to meet legal, regulatory, or contractual obligations. Our default retention periods are as follows:
Contact enquiry data (name, email, message content) is retained for up to 24 months from the date of last meaningful interaction. This timeframe allows us to maintain continuity in business conversations, refer back to prior discussions, and fulfil any contractual obligations that may arise. If no business relationship develops within this period, the data is securely deleted or anonymised.
Website analytics data collected via Google Analytics is governed by the retention settings we have configured within Google's platform — currently set to 14 months for user-level and event-level data, after which it is automatically purged. Aggregated, anonymised reporting data may be retained indefinitely as it cannot be linked to any individual.
Server logs containing IP addresses and request metadata are retained for 90 days for security purposes, after which they are deleted. Logs associated with identified security incidents may be retained for up to 12 months in connection with investigations.
Cookie consent records are retained for 12 months or until you withdraw consent, in order to demonstrate compliance and avoid repeatedly showing consent prompts to returning visitors.
At the end of each applicable retention period, data is either securely and irreversibly deleted from active systems and backups, or anonymised such that it can no longer be linked to any identified or identifiable individual. You may also request deletion at any time, subject to the exceptions described in Section 8.
Data Security
We implement a combination of technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures are reviewed and updated as technology and risk landscapes evolve.
In transit: All data transmitted between your browser and our web server is encrypted using TLS 1.2 or higher (HTTPS). Our email infrastructure enforces opportunistic TLS for message delivery between servers. We do not transmit unencrypted personal data over public networks.
At rest: Data stored on our hosting infrastructure is protected by access controls that restrict it to authorised personnel only, on a strict need-to-know basis. We do not store payment card data or government-issued identification numbers on our own systems at any point.
Organisational controls: Access to systems holding personal data is limited to Usina.Ia team members whose role specifically requires it. All such personnel are bound by confidentiality obligations and receive awareness training on data-protection responsibilities.
Incident response: In the unlikely event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority (ANPD in Brazil; the competent EU authority where applicable) within 72 hours of becoming aware of the breach, and will inform affected individuals without undue delay where the risk is assessed as high. Our incident-response procedures are documented and tested on a regular basis.
Your Rights
Depending on your country of residence, applicable law grants you a number of rights in relation to the personal data we hold about you. Under both the LGPD (Article 18) and the GDPR (Articles 15–22), these rights include:
Right of Access
You may request a copy of the personal data we hold about you, along with information about how it is being processed and the legal basis for doing so.
Right to Rectification
If any data we hold about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.
Right to Erasure
You may request the deletion of your personal data where it is no longer necessary, where consent has been withdrawn, or where processing is unlawful — subject to legal retention obligations.
Right to Restriction
You may ask us to restrict the processing of your data — for example, while we investigate a dispute about its accuracy or the lawfulness of our processing.
Right to Portability
Where processing is based on consent or contract and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format.
Right to Object
You may object at any time to processing based on legitimate interest, including processing for direct marketing purposes. Upon receiving an objection, we will cease processing unless we demonstrate compelling legitimate grounds.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority — the ANPD (anpd.gov.br) in Brazil, or your relevant EU data-protection authority — if you believe we are processing your data unlawfully.
How to exercise your rights: To make a rights request, please send an email to contato@usinaia.site with the subject line "Data Subject Request" and include: your full name, the email address associated with your data, a clear description of your request, and — if we need to verify your identity — a means by which we can do so. We will acknowledge your request within five business days and respond fully within 30 days (extendable by a further 60 days in complex cases, with notice). There is no fee for making a rights request unless it is manifestly unfounded or excessive.
Please note that certain rights are not absolute. For example, we may be unable to delete data that we are legally required to retain, or that is necessary to establish, exercise, or defend legal claims. We will always explain clearly if and why an exemption applies to your specific request.
Children's Privacy
Usina.Ia's website and services are directed exclusively at businesses and adult professionals. We do not knowingly collect, process, or store personal data from individuals under the age of 18. Our content is not targeted at minors, and we take no deliberate steps to attract or engage with children under this age threshold.
If you are a parent or guardian and believe that a minor for whom you are responsible has provided us with personal data — for instance, by emailing our contact address — please notify us immediately at contato@usinaia.site. Upon verification, we will promptly delete any such data from our systems. We process data relating to children, where it incidentally comes to our attention, on the basis of a legal obligation and solely for the purpose of deletion.
Under the LGPD, the processing of personal data of children requires the specific and highlighted consent of at least one parent or legal guardian, and must occur in the child's best interest. This site is not designed or intended to serve children in any capacity, and no product or service offered by Usina.Ia is directed at individuals under 18.
Changes to This Policy
We may revise this Privacy Policy from time to time to reflect changes in our data processing practices, updates to applicable law, new services or website features, or feedback from supervisory authorities. When we make material changes, we will update the "Last updated" date at the top of this page and, where the changes are significant, we will provide a more prominent notice — such as a banner on the homepage or, where we have your email address and it is appropriate to do so, a direct notification.
We encourage you to review this page periodically. Continued use of usinaia.site after any revisions have been published constitutes your acknowledgement that you have had the opportunity to review the updated policy. If you disagree with any changes, please discontinue use of the site and contact us as described in Section 11.
Previous versions of this Privacy Policy are available upon request. Please email contato@usinaia.site with the subject line "Previous Privacy Policy Version" and we will provide the applicable historical version for your reference.
Contact & Data Controller
The data controller responsible for your personal data under this Privacy Policy is USINA INTELIGENCIA ARTIFICIAL LTDA. If you have questions about this policy, wish to exercise your rights, or have concerns about how your data is being handled, please reach out to us through the details below. We aim to respond to all privacy-related enquiries within five business days.
Data Controller Details
If you are located in the European Union and are unsatisfied with our response to a privacy complaint, you have the right to escalate the matter to the supervisory authority in your country of residence. A list of EU data-protection authorities is available at edpb.europa.eu. If you are located in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at anpd.gov.br.