2. Scope
This Policy applies to all personal data processing activities carried out by Nocera InfoSec® in connection with:
- The nocerainfosec.com.br website and its subdomains;
- Contact and quote request forms;
- Communications by email, telephone or social media;
- Information security service contracts;
- Pentest, red team, digital forensics, incident response, OSINT, dark web monitoring and the other services we offer.
In the course of providing technical services (e.g. pentest, digital forensics, red team), we may access personal data of third parties present in the client's systems. In these cases, we act solely as Processors under the client's documented instructions (Controller), as per the contract and the approved scope.
3. Data Collected
3.1 Data provided directly by you: full name, job title and company; contact or proposal form; company CNPJ/CPF and billing address; content of the messages you send.
3.2 Data collected automatically: data for security and abuse prevention on the form; browser and operating system (User-Agent); compatibility data and, only with your consent (cookie banner), basic usage statistics for site improvement (aggregated analytics).
We do not collect, unless otherwise stated: payment data (credit card, bank details), which are processed by third parties through PCI-DSS certified platforms; sensitive data (health, biometrics, religion, etc.) without a specific legal basis; or data from individuals under 18 (see section 12).
4. Purposes of Processing
- Responding to requests, quotes and post-service support;
- Delivery of the contracted services (pentest, red team, digital forensics, incident response, OSINT, etc.);
- Issuance of invoices and financial management;
- Prevention of fraud, abuse and unauthorized access to the website;
- Compliance with Brazilian tax, accounting and regulatory obligations;
- Aggregated analysis of website usage for continuous improvement;
- Sending newsletters and educational content, only with explicit consent.
We do not use your data for purposes incompatible with the purposes stated at the time of collection.
5. Legal Basis (LGPD)
We process your data based on the following hypotheses of art. 7 of the LGPD: performance of a contract (item V); compliance with a legal or regulatory obligation (item II); legitimate interests, such as security and fraud prevention (item IX); preliminary procedures related to a contract, at the data subject's request (item V); and the data subject's consent (item I), when applicable (e.g. newsletter).
6. Data Sharing
Nocera InfoSec® does not sell, rent or otherwise commercialize personal data. Sharing occurs only in the following situations:
- Essential service providers (hosting, corporate email, management tools), always under adequate confidentiality and data protection agreements;
- Competent authorities, when required by law, court order or a request from a regulatory authority (e.g. ANPD, Federal Police, Interpol under formal cooperation);
- With your consent, in any other situation not covered above;
- Protection of rights, when necessary to exercise or defend the rights of Nocera InfoSec® in judicial or administrative proceedings.
All outsourced vendors are assessed for their security practices before engagement.
7. Retention and Deletion
Retention periods vary according to the nature of the data and the applicable legal basis, including legal obligation (Civil Code, art. 206, for contractual data and reports) and tax requirements for invoices and tax documents. Once the retention period has ended, the data is securely deleted (multiple overwriting or certified destruction of physical media) or anonymized for statistical purposes.
8. Data Security
We apply technical and organizational measures adequate to the state of the art in information security, including:
- Encryption in transit: TLS 1.2+ on all web communications;
- Access control: least privilege principle and multi-factor authentication on internal systems;
- Network segmentation: production environments isolated from development and testing;
- Code review: security analysis of web applications and APIs that process personal data;
- NDAs: all employees and providers with access to personal data sign confidentiality agreements;
- Incident response: a documented plan for handling data leaks and security incidents.
In the event of a data breach that may cause relevant risk or damage to data subjects, we will notify the ANPD and the affected data subjects within a maximum of 72 hours from becoming aware of the incident, as per art. 48 of the LGPD.
9. Your Rights as a Data Subject
Under art. 18 of the LGPD, you have the following rights:
- Confirmation and access: know whether we process your data and obtain a copy of it;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary data or data processed in non-compliance with the LGPD;
- Portability in a structured and interoperable format;
- Deletion of data processed based on consent;
- Information about with whom we share your data;
- Revocation of consent at any time;
- Opposition to processing based on legitimate interest;
- Review of automated decisions.
To exercise your rights, contact us at contato@nocerainfosec.com.br. We will respond within 15 business days. You may also file a petition with the ANPD if you believe your right has been violated.
10. Cookies and Tracking
Our website does not use behavioral tracking, advertising or third-party analytics cookies (e.g. Google Analytics, Meta Pixel) at this time. On entry, the cookie banner lets you accept, reject or customize the categories; your choice and other preferences (such as the top notice you dismissed and the Pentest Scope Builder settings) are stored only in your browser (localStorage), are not sent to us and can be changed at any time through the Cookie preferences link in the footer. Without your consent for the Metrics category, no metrics script is loaded. To prevent spam on the contact form, we use Cloudflare Turnstile, which verifies that the submission was made by a person without using tracking cookies; it is governed by the Cloudflare Privacy Policy.
The Pentest Scope Builder is optional. If you provide your own Gemini API key, the text you type is sent by your browser directly to Google for processing, under the Google Privacy Policy; nothing passes through Nocera InfoSec® servers.
11. International Transfers
Some of our essential service providers (e.g. email servers, hosting) may be located outside Brazil. In that case, we ensure that transfers are made to countries with an adequate level of protection recognized by the ANPD, based on standard data protection contractual clauses, or with specific guarantees under art. 33 of the LGPD.
In services involving international cooperation (e.g. investigations involving Interpol or foreign authorities), sharing occurs exclusively upon formal legal request and within the applicable legal limits.
12. Minors
Our services are intended exclusively for legal entities and professionals in a B2B context. We do not intentionally collect personal data from individuals under 18. If we identify that we have collected data from a minor without the consent of the legal guardian, we will delete such data immediately.
13. Changes to This Policy
We may update this Policy periodically to reflect changes in our practices, services or applicable legislation. The "last updated" date at the top of this document indicates when the most recent version took effect.
Material changes will be communicated at least 15 days in advance by email (to active clients) or through a prominent notice on our website. Continued use of our services after the communication constitutes acceptance of the changes. Previous versions of this Policy may be requested by email at the address below.
14. Contact and DPO
For questions, requests related to your rights or to report a privacy concern:
Data protection officer (DPO): Guilherme Nocera
Email: contato@nocerainfosec.com.br
You also have the right to lodge a complaint with the Brazilian Data Protection Authority (ANPD).