Legal Document

Privacy Policy

This policy explains exactly how M2F Soluções Ltda collects, uses, stores and protects the personal data of everyone who visits our website or contacts us through any channel. We are committed to full transparency and to your rights under applicable law.

GDPR Aligned LGPD Compliant Last Updated: June 2025

Section 01

Introduction

M2F Soluções Ltda ("M2F", "we", "us" or "our") is a Brazilian limited liability company registered under CNPJ. We operate the website available at m2fsolucoes.site (the "Site") and provide technology solutions and related professional services to our clients.

We take the privacy of every person who interacts with us seriously. This Privacy Policy describes the categories of personal data we process, the legal bases on which we rely, how long we keep data, who we share it with, and what rights you can exercise over your own information.

This document has been written to comply with Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13,709/2018 — and, where applicable to visitors located in the European Economic Area or the United Kingdom, with the General Data Protection Regulation (GDPR) and its national implementations. Where both frameworks apply, we follow whichever affords stronger protection to you.

By accessing or using our Site, you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, please refrain from using the Site and contact us if you have questions.

Data controller: M2F Soluções Ltda — CNPJ. All enquiries regarding personal data can be directed to contato@m2fsolucoes.site.

Section 02

Information We Collect

We collect personal data only to the minimum extent necessary to operate our Site, communicate professionally with prospective and existing clients, and continuously improve our services. The information we collect falls into three broad categories.

2.1 Information You Provide Directly

When you contact us — whether by email, telephone, WhatsApp, or any other channel whose details appear on this Site — you may share the following personal data:

  • Identification data: full name and job title or professional role.
  • Contact data: business or personal email address, telephone number, and company name.
  • Message content: the substance of your enquiry, which may include details about a project, a technical challenge, or a request for a proposal.
  • Communication metadata: the date, time and channel through which you contacted us.

We do not ask for, nor do we wish to receive, sensitive personal data — such as health information, financial account numbers, biometric data, or information about religious or political beliefs — through any informal channel. Please do not share such data with us unsolicited.

2.2 Data Collected Automatically When You Visit Our Site

Like virtually every website on the internet, our Site automatically records certain technical information when your browser makes a request to our servers. This may include:

  • IP address (which may, in combination with other data, identify your approximate geographic location at city or regional level).
  • Browser type and version, operating system and device type (desktop, tablet, mobile).
  • Referring URL — the page you came from before arriving at our Site.
  • Pages visited, time spent on each page, and the path you followed through the Site.
  • Date and time of each request and the HTTP response code returned by our server.

This technical data is collected via server logs and through analytics tools described in Section 4 below. On its own it is typically non-identifying, but we treat it with the same care as personal data because it may, under certain circumstances, be combined with other information to identify an individual.

2.3 Data from Cookies and Similar Technologies

We use first-party and third-party cookies, web beacons and similar tracking mechanisms to understand how visitors use our Site and to serve relevant advertising. The full details of each technology we use, and how you can control them, are set out in Section 4 of this Policy.

Section 03

How We Use Your Information

We process your personal data only for specific, explicit and legitimate purposes. Below we describe each purpose along with the legal basis on which we rely under the LGPD and the GDPR.

  • Responding to your enquiries and pre-contractual communications. When you contact us about our services, we use your name, contact details and message content to prepare and send a timely, relevant response. Legal basis: execution of pre-contractual measures at your request (LGPD Art. 7, II; GDPR Art. 6(1)(b)).
  • Service delivery and contract performance. If we engage in a commercial relationship with you or your organisation, we use the personal data necessary to provide agreed services, issue invoices and fulfil our contractual obligations. Legal basis: contract performance (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
  • Site analytics and performance optimisation. We analyse aggregated and pseudonymised usage data to understand which pages are most helpful to visitors, where navigation could be improved and how our content performs. Legal basis: legitimate interests (LGPD Art. 7, IX; GDPR Art. 6(1)(f)) — specifically our interest in providing a well-functioning, useful website, balanced against your privacy interests.
  • Advertising measurement and remarketing. With your consent obtained through our cookie consent mechanism, we may use anonymised identifiers to measure the effectiveness of our advertising campaigns on platforms such as Google Ads, and to show our advertisements to users who have previously visited our Site. Legal basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
  • Legal compliance and regulatory obligations. We may process personal data as required by Brazilian law, including tax, labour and corporate regulations, or in response to a lawful request from a competent public authority. Legal basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
  • Protection of rights in legal proceedings. If necessary to establish, exercise or defend legal claims, we may process and disclose relevant data. Legal basis: legitimate interests / defence of legal claims (LGPD Art. 7, VI, IX; GDPR Art. 6(1)(f) and Art. 9(2)(f)).

We do not sell your personal data. We do not trade, rent or monetise your personal information to third-party data brokers or marketing companies, and we never use your data for purposes incompatible with those described above without first obtaining your explicit consent.

Section 04

Cookies & Tracking Technologies

Cookies are small text files stored in your browser that allow a website to recognise your device on subsequent visits or to measure how you interact with its pages. We also use web beacons (transparent pixel images embedded in pages), local storage objects and similar technologies for the purposes described below.

4.1 Essential Cookies

These cookies are strictly necessary for the Site to function correctly. They manage your session, preserve your language or accessibility preferences and ensure that our security mechanisms work. Because they are essential, they are placed without requiring your consent, but you may disable them in your browser — however, doing so will affect Site functionality. No personal data processed through essential cookies is shared with third parties.

4.2 Analytics Cookies

We use Google Analytics 4 to collect aggregated, pseudonymised data about how visitors interact with our Site. Information collected includes pages viewed, session duration, traffic source, geographic region (country or city, derived from IP address), and device type. Google Analytics anonymises IP addresses by default in our configuration. The data is processed under a data-processing agreement with Google Ireland Limited and is not used to personally identify individual users. You may opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on.

4.3 Advertising and Remarketing Cookies

Subject to your consent, we may deploy the Google Ads conversion tracking tag and the Google Ads remarketing tag. These technologies allow us to measure how many visitors who clicked on one of our advertisements subsequently took a meaningful action on our Site, and to serve relevant M2F advertisements to past visitors as they browse other sites within Google's Display Network. The data collected through these tags is processed by Google LLC in accordance with Google's own privacy policy. You can manage your Google advertising preferences at adssettings.google.com.

4.4 Managing Your Cookie Preferences

When you first visit our Site, you will be presented with a cookie consent banner that allows you to accept all cookies, accept only essential cookies, or customise your preferences by category. You can change your preferences at any time. In addition, every major browser offers built-in controls that allow you to block or delete cookies. Refer to your browser's help documentation for instructions specific to your version:

  • Google Chrome — Settings › Privacy and Security › Cookies and other site data
  • Mozilla Firefox — Settings › Privacy & Security › Cookies and Site Data
  • Apple Safari — Preferences › Privacy
  • Microsoft Edge — Settings › Cookies and site permissions

Please note that blocking all cookies may prevent certain features of our Site from functioning as intended.

Section 05

Sharing With Third Parties

We do not share your personal data with third parties except in the following limited and well-defined circumstances.

  • Service providers and data processors. We engage trusted companies to help us operate our Site and business, including cloud hosting providers, email delivery infrastructure and analytics platforms. These parties process data strictly on our behalf, under written data-processing agreements that prohibit them from using your data for any independent purpose. Current infrastructure providers include Cloudflare (CDN and security) and Google (analytics and advertising measurement).
  • Professional advisors. We may share data with our lawyers, accountants or auditors when legally necessary or when required to fulfil our obligations under Brazilian corporate law — subject always to professional confidentiality obligations binding on those advisors.
  • Public authorities. We will disclose personal data to law enforcement agencies, regulatory bodies or courts when we are legally compelled to do so by a valid judicial order, governmental directive or applicable law. We will, where legally permissible, notify you of any such disclosure.
  • Business transfers. If M2F Soluções Ltda undergoes a merger, acquisition, asset sale or restructuring, personal data held by us may be transferred to the acquiring entity. We will notify affected individuals before any such transfer takes place and ensure the recipient provides equivalent privacy protections.
  • With your explicit consent. In any other scenario not described above, we will share your personal data only if you have given us your express, informed, prior consent to do so.

We do not transfer personal data to countries outside Brazil or the European Economic Area unless the destination country ensures an adequate level of protection as recognised by the Brazilian National Data Protection Authority (ANPD) or the European Commission, or unless appropriate safeguards — such as Standard Contractual Clauses — are in place.

Section 06

Data Retention

We retain personal data for no longer than is necessary for the purposes for which it was originally collected, or as required by applicable law. Our standard retention periods are as follows:

  • Enquiry and pre-sales correspondence: up to 24 months from the date of your last communication with us, unless a contract is subsequently signed, in which case the contractual retention period applies.
  • Client and contract data: for the duration of the contractual relationship plus 5 years following its termination, to satisfy Brazilian civil and tax law requirements (including Articles 205 and 206 of the Brazilian Civil Code and applicable tax legislation under Law No. 9,430/1996).
  • Website server logs: up to 12 months, after which they are automatically deleted or irreversibly anonymised.
  • Analytics data: Google Analytics data is retained for 14 months from the date of each session, in line with our configuration in the Google Analytics platform. After that period it is automatically purged from Google's systems in relation to our property.
  • Advertising and remarketing identifiers: up to 540 days, as configured in our Google Ads account, consistent with industry standard practice for conversion attribution.

When data reaches the end of its retention period and there is no other legal basis for continued processing, we securely delete or irreversibly anonymise it. Anonymised data may be retained indefinitely for statistical and research purposes, as it no longer constitutes personal data.

Section 07

Data Security

Protecting the integrity and confidentiality of your personal data is a responsibility we take seriously. We implement a layered set of technical and organisational measures designed to safeguard data against unauthorised access, accidental loss, alteration or disclosure.

Our technical measures include:

  • All data in transit between your browser and our Site is encrypted using TLS 1.2 or TLS 1.3. Our Site enforces HTTPS exclusively and employs HTTP Strict Transport Security (HSTS).
  • Servers and databases holding personal data are protected by network-level firewalls, with access restricted to authorised personnel using multi-factor authentication.
  • Regular security patching and software updates are applied to all infrastructure components.
  • Access to production data is governed by the principle of least privilege — team members can only access data necessary for their specific role.

Our organisational measures include internal privacy and data-handling guidelines, confidentiality obligations for all personnel who access personal data, and periodic reviews of our data inventory and risk posture.

In the event of a personal data breach that poses a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority — the Brazilian ANPD and/or the applicable EU/UK data protection authority — within the legally required timeframe, and we will communicate directly with affected individuals where required by law.

No method of electronic transmission or storage is perfectly secure. While we apply industry-standard safeguards, we cannot guarantee absolute security. We encourage you to use a strong, unique password for any account you maintain with us and to alert us immediately at contato@m2fsolucoes.site if you suspect any unauthorised use of your data.

Section 08

Your Rights

Depending on your location and the legal framework applicable to you, you may hold some or all of the following rights over the personal data we hold about you. We are committed to facilitating the exercise of these rights promptly and without unnecessary bureaucracy.

Right of Access

You may request a copy of the personal data we hold about you, together with information about how we use it, who we share it with and how long we keep it.

Right of Rectification

If any personal data we hold about you is inaccurate or incomplete, you may ask us to correct or update it without undue delay.

Right of Erasure

You may ask us to delete your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw your consent and there is no other legal basis for processing.

Right to Object

You may object at any time to the processing of your personal data for purposes based on our legitimate interests or for direct marketing. We will stop processing unless we can demonstrate compelling grounds that override your interests.

Right to Restrict Processing

In certain circumstances — for example while the accuracy of your data is being contested — you may ask us to restrict how we use your personal data until the matter is resolved.

Right to Data Portability

Where processing is based on your consent or on contract performance and is carried out by automated means, you have the right to receive your data in a structured, commonly used and machine-readable format.

Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of any processing carried out before withdrawal.

Right to Lodge a Complaint

You have the right to file a complaint with the Brazilian ANPD (Autoridade Nacional de Proteção de Dados) or, for EEA/UK residents, with your local data protection supervisory authority, if you believe we have processed your data unlawfully.

How to Exercise Your Rights

To exercise any of the rights described above, please contact us in writing at contato@m2fsolucoes.site. Your request should include sufficient information to allow us to identify you and locate the relevant data — typically your full name and the email address you used when contacting us. We will respond to all valid requests within 15 business days (as required by the LGPD) or within 30 calendar days (in line with GDPR Article 12), whichever deadline is shorter in your case. If we need additional time due to complexity or volume, we will inform you promptly and explain the reason for the extension.

We will not charge a fee for fulfilling a rights request unless it is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or refuse to act, providing you with a written explanation of our decision.

Section 09

Children's Privacy

Our website is a corporate, business-to-business platform directed exclusively at adults — specifically business professionals and organisations seeking technology solutions. We do not knowingly collect personal data from children under the age of 18.

If you are a parent or guardian and you believe that a child for whom you are responsible has provided us with personal data without your consent, please contact us immediately at contato@m2fsolucoes.site. We will investigate promptly and delete any such data from our systems as quickly as possible. Under the LGPD, the processing of data belonging to children (those under 12 years of age) requires specific parental or guardian consent, which we do not solicit and do not accept through this Site.

Section 10

Changes to This Policy

We review this Privacy Policy at least annually and update it whenever there is a material change to our data-processing practices, a relevant change in applicable law, or guidance issued by the ANPD or an EU supervisory authority that affects how we operate. The date at the top of the page — marked "Last Updated" — indicates when the most recent revision was made.

If we make changes that are likely to be significant — for example, if we begin processing a new category of personal data or introduce a new purpose for processing — we will take additional steps to bring the update to your attention. Where required by law, we will seek fresh consent from those whose data is affected by the change before the updated practices take effect.

We encourage you to revisit this page periodically. Your continued use of our Site after the "Last Updated" date constitutes your acknowledgment of the revised Policy. If you disagree with any change, you should stop using the Site and may contact us to request erasure of any personal data we hold about you.

Section 11

Contact & Data Controller

If you have any question, concern or request relating to this Privacy Policy or to the way we handle personal data, please reach out to us through the details below. We aim to respond to all privacy-related correspondence within 5 business days, and to resolve matters conclusively within the statutory timeframes described in Section 8.

M2F Soluções Ltda — Data Controller

Company name: M2F Soluções Ltda

CNPJ: (registration number on file with the Receita Federal)

Privacy & Data enquiries: contato@m2fsolucoes.site

Response time commitment: Within 5 business days for general enquiries; within the statutory LGPD / GDPR deadlines for formal rights requests.

For EEA-based data subjects who wish to escalate unresolved complaints, you may contact your national supervisory authority. A full list of EU data protection authorities is available at edpb.europa.eu. For Brazilian data subjects, complaints may be submitted to the ANPD at gov.br/anpd.