Introduction
STRATEGIA RASTREAMENTO SOFTWARE E TELEMETRIA LTDA (registered under CNPJ 14.669.235/0001-85, with offices at Rua João Câmara, 17, Sala B, Novo Aleixo, Manaus — AM, Brazil) operates the website estrategiasoftware.site and provides vehicle tracking, fleet telemetry, and related software services. Throughout this policy, the terms "Strategia," "we," "us," and "our" refer to this legal entity.
This Privacy Policy governs the collection, storage, use, and disclosure of personal data obtained through our website, our communications channels, and our service delivery activities. It has been drafted to comply with Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018) and, where applicable to visitors located in the European Economic Area or the United Kingdom, with the General Data Protection Regulation (GDPR — EU 2016/679).
By visiting our website or engaging our services, you acknowledge that you have read and understood this policy. If you do not agree with any term herein, please discontinue use of our website and contact us directly at contato@estrategiasoftware.site to discuss how your data is handled in the context of any existing contractual relationship.
Plain-language summary: We collect only the data we genuinely need to provide and improve our services, respond to your inquiries, and comply with the law. We do not sell your personal information to third parties. We give you real control over your data.
Information We Collect
We collect personal data through several channels, and the type of information varies depending on how you interact with Strategia. Below is a detailed breakdown.
2.1 — Information you provide directly
When you reach out to us via email, telephone, or our published contact details, we may collect:
- Full name — to identify who we are communicating with.
- Business or corporate email address — to correspond with you and send requested materials.
- Phone number — when provided voluntarily for telephone support or follow-up.
- Company name, industry, and fleet size — to understand your operational context and tailor our service recommendations appropriately.
- Message content — the subject matter of your inquiry, including any attachments you may send.
- Billing and invoicing details — for clients under contract, including registered business name, CNPJ, and address, as required by Brazilian fiscal law (NF-e compliance).
2.2 — Information collected automatically
When you visit estrategiasoftware.site, our web infrastructure and analytics tools automatically record certain technical data. This includes:
- IP address — recorded by our hosting provider's server logs and used for security monitoring and geographic analytics.
- Browser type and version — to optimize page rendering and identify compatibility issues.
- Operating system — recorded as part of the HTTP User-Agent string.
- Referring URL — the page or search engine result from which you navigated to our site.
- Pages visited, session duration, and click paths — collected via analytics cookies to understand how visitors use the site.
- Device type and screen resolution — used for responsive design improvements.
- Date and time stamps — each server request is logged with a timestamp.
2.3 — Tracking and advertising data
Where you have consented to marketing cookies, advertising platforms such as Google Ads may collect pseudonymous identifiers (cookie IDs, hashed device signals) that allow them to attribute ad clicks to website visits and to build audience segments. This data is controlled partly by us and partly by the platform — see Section 5 for details.
2.4 — Data from service delivery
For clients who subscribe to our vehicle tracking and fleet management platform, we process operational data including vehicle GPS coordinates, engine telemetry, driver identification codes, and route history. This operational data is governed by our Master Services Agreement and is processed on your behalf as a data processor — you remain the data controller for that information.
How We Use Your Information
Every use of your personal data at Strategia is grounded in a specific legal basis. We do not repurpose data in ways you would not reasonably expect. Here is how we use the information we collect, and the legal basis under which we do so:
- Responding to inquiries and providing pre-sales support — when you contact us, we use your name, email, and message content to respond accurately and in a timely manner. Legal basis: legitimate interest (LGPD Art. 7, X; GDPR Art. 6(1)(f)), and in some cases, steps toward a contract.
- Delivering contracted services — for active clients, we use billing, account, and operational data to provision and support our tracking platform. Legal basis: performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
- Sending service-related communications — system maintenance notices, security alerts, and service updates are sent to registered clients using their account contact email. Legal basis: legitimate interest and contract performance.
- Marketing communications — with your prior, specific consent, we may send news about new features, industry insights, or promotional offers. You can withdraw this consent at any time. Legal basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
- Analytics and site improvement — aggregated, largely anonymized data from analytics tools is used to identify which content and pages perform well and to make evidence-based improvements to the site experience. Legal basis: legitimate interest.
- Fraud prevention and security — server logs and security monitoring tools help us detect unauthorized access attempts and protect our systems and our clients' data. Legal basis: legitimate interest and legal obligation.
- Legal and regulatory compliance — we may retain and process certain data to comply with applicable Brazilian laws, tax regulations, and any court or regulatory authority orders. Legal basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
No automated decision-making with legal effect: We do not subject individuals to fully automated decisions — including profiling — that produce legal or similarly significant effects, without human review.
Sharing With Third Parties
We do not sell, rent, or trade your personal information to third parties for their own commercial purposes. However, we do share certain data with trusted partners and service providers who help us operate our business and our website. Each of these relationships is governed by a data processing agreement or equivalent safeguard.
Categories of recipients include:
- Cloud infrastructure and hosting providers — our website and backend systems are hosted on cloud infrastructure. Servers are located in Brazil or other jurisdictions that provide adequate data protection guarantees.
- Analytics platforms (Google LLC) — we share anonymized browsing data with Google Analytics under Google's Data Processing Terms. IP addresses are anonymized before being stored. Google acts as our data processor for this purpose.
- Advertising networks (Google LLC, Meta Platforms Inc.) — where applicable, we share conversion event data and audience segments with Google Ads and Meta Ads for the purpose of measuring campaign effectiveness and serving relevant advertising. These platforms may receive pseudonymous identifiers; they do not receive names or direct contact details through this channel.
- Email and communication tools — transactional emails (e.g., confirmation messages, support correspondence) may be routed through a third-party email service provider. That provider processes sender and recipient addresses solely to deliver messages.
- Accounting and legal advisors — we may share billing data and, when necessary, personal data with our certified accountants (contadores), legal counsel, and tax consultants to fulfill our obligations under Brazilian fiscal and commercial law. These professionals are bound by professional confidentiality obligations.
- Law enforcement and regulatory authorities — if required by applicable law, court order, or a binding request from a government authority, we may disclose personal data. We will, where legally permissible, notify you of such a request before disclosing.
- Business transfers — in the event of a merger, acquisition, or sale of substantially all assets, personal data may be transferred to the successor entity. You will be notified by email or a prominent site notice before your data becomes subject to a different privacy policy.
International transfers: Where we transfer personal data outside Brazil (for example, to Google's or Meta's servers in the United States), we rely on standard contractual clauses or the recipient's certification under a recognized framework to ensure an adequate level of protection, in accordance with LGPD Art. 33 and GDPR Chapter V.
Data Retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer required, we securely delete or anonymize it.
The following retention periods apply as a general guideline:
- Pre-sales inquiries and contact records — retained for up to 24 months from the date of last contact, unless the inquiry converts to a contract, in which case the data is retained under the client record period below.
- Client account and contractual data — retained for the duration of the service contract and for a minimum of 5 years thereafter, in compliance with Brazilian civil code statutes of limitation (Código Civil, Art. 206) and tax record-keeping obligations.
- Fiscal and invoicing records (NF-e) — retained for a minimum of 5 years as required by the Receita Federal and SEFAZ.
- Website server logs — retained for up to 6 months for security monitoring purposes, then deleted. In the event of an incident under investigation, relevant logs may be preserved for longer.
- Analytics data (Google Analytics) — configured with a data retention window of 14 months. User-level and event data is deleted automatically after this period.
- Marketing consent records — retained for as long as you remain a subscriber plus 3 years, to demonstrate compliance with the consent requirement. Opt-out records are retained indefinitely to honor your withdrawal.
When a retention period expires, data is deleted from production systems and purged from backups within the subsequent backup rotation cycle, typically within 90 days.
Data Security
Protecting the personal data entrusted to us is a responsibility we take seriously and address through a combination of technical controls, organizational policies, and ongoing staff training. Our current security measures include, but are not limited to:
- TLS/HTTPS encryption — all data transmitted between your browser and our website is encrypted in transit using Transport Layer Security (TLS 1.2 or higher). Our SSL certificate is maintained and renewed proactively.
- Access controls — internal systems are protected by role-based access control (RBAC). Only employees with a demonstrable need-to-know can access personal data, and each access is logged.
- Multi-factor authentication (MFA) — privileged accounts accessing infrastructure and customer data systems require MFA in addition to strong passwords.
- Encrypted storage — sensitive data at rest, including client credentials and identifiable records, is stored using industry-standard encryption.
- Regular security assessments — we conduct periodic vulnerability scans and review our security posture, remedying identified weaknesses promptly.
- Vendor security review — before engaging any data processor, we evaluate their security practices and enter into appropriate contractual protections.
- Incident response procedure — in the event of a confirmed data breach affecting your personal data, we will notify the relevant authority (ANPD in Brazil) within 72 hours where feasible, and notify affected individuals without undue delay, in accordance with LGPD Art. 48.
Important: No method of electronic transmission or storage is entirely infallible. While we implement strong safeguards, we cannot provide an absolute guarantee of security. If you suspect any unauthorized access to your data, please contact us immediately at contato@estrategiasoftware.site.
Your Rights
Under Brazil's LGPD (Art. 18) and, where applicable, the GDPR (Art. 15–22), you hold a meaningful set of rights in relation to personal data we hold about you. These rights are not absolute — in some cases they are subject to legal exceptions — but we are committed to fulfilling them promptly and transparently.
Right of Access
You may request confirmation of whether we process your personal data, and if so, receive a copy of that data along with contextual information about how it is used.
Right to Correction
If any personal data we hold about you is inaccurate or incomplete, you may request that we correct or update it without undue delay.
Right to Deletion
You may ask us to erase personal data that is no longer necessary for the purpose collected, processed unlawfully, or where consent has been withdrawn and no overriding legal ground exists.
Right to Object
Where we process your data based on legitimate interest, you may object at any time. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Restrict Processing
In certain circumstances — such as while you contest the accuracy of data or an objection is being assessed — you may request that we limit how we use your information.
Right to Data Portability
Where technically feasible, you may request that personal data you provided to us be transferred to you or to another controller in a structured, machine-readable format.
Right to Withdraw Consent
Where processing is based on your consent (e.g., marketing emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to Lodge a Complaint
You have the right to file a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) or, for EEA residents, with your national supervisory authority, if you believe your rights have been infringed.
How to exercise your rights: Submit your request in writing to contato@estrategiasoftware.site, using the subject line "Data Rights Request — [Your Name]." Include sufficient information to allow us to identify you (for example, the email address associated with our records). We will acknowledge your request within 5 business days and respond substantively within 15 calendar days, extendable to 30 days in complex cases with prior notice.
We will not charge a fee for processing your request, unless it is manifestly unfounded or repetitive, in which case we may either charge a reasonable fee or decline to respond, explaining our reasons.
Children's Privacy
Our website and services are directed exclusively at businesses and working professionals. We do not knowingly market to, solicit, or collect personal data from individuals under the age of 18 years.
If you believe that a minor has provided us with personal data without appropriate parental or guardian consent, please notify us immediately at contato@estrategiasoftware.site. Upon confirmation, we will take prompt steps to delete that data from our systems and, where a third-party service provider is involved, request deletion from them as well.
Under no circumstances do we use the personal data of minors for advertising, profiling, or any commercial purpose.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, the services we offer, applicable law, or regulatory guidance from the ANPD or other authorities. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Post a notice on our website homepage for a minimum of 30 days highlighting the nature of the change.
- Where we hold your email address and the change meaningfully affects your rights, send you a direct notification summarizing what has changed and why.
We encourage you to review this page periodically. Your continued use of our website or services after a material change takes effect constitutes your acknowledgment of the updated policy. If a change reduces your rights or alters how we process data for which we rely on your consent, we will seek fresh consent before the change applies to you.
Archived versions of this policy are available upon request — contact us and we will provide the version applicable on any given date within our retention window.
Contact & Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please reach out to us. We treat all privacy-related correspondence as a priority and endeavour to provide clear, complete answers.
As required under the LGPD, we have designated a responsible officer (Encarregado de Dados) who serves as the primary point of contact for data subjects and the ANPD. All privacy inquiries addressed to the contact below will be directed to that officer.
Strategia Rastreamento Software e Telemetria Ltda
Our data protection team is available on business days, Monday through Friday, 08:00–18:00 BRT.
If you are not satisfied with our response, or if you believe we are processing your personal data in a manner inconsistent with applicable law, you have the right to lodge a complaint directly with Brazil's national supervisory authority:
- Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd
EEA-based individuals may alternatively contact their local data protection authority. A list of EEA supervisory authorities is maintained at edpb.europa.eu/about-edpb/board/members.