Who handles your data
IdeaInSite is a project of ALEF SERVIÇOS DE PUBLICIDADE E COMUNICACAO LTDA, trade name ALEF HOLDING, CNPJ 50.651.259/0001-70, located at Rua das Ubaranas, 347, EMPR2000 Building, suite 501, Amaralina, Salvador/BA.
The company is responsible for decisions about data of visitors, prospects and account holders of IdeaInSite. When we provide support on behalf of a client, that client defines the purposes for processing its own visitors’ data, and we act according to its instructions and the contracted service.
What information may be processed
- When browsing: IP address, access date and time, requested pages and technical browser information recorded in operation and security logs.
- When a technical failure occurs: sanitized error type and message, file path, line, column, page and timestamp. The report does not include form content, name, email, phone, cookies or URL parameters.
- When contacting us: your name, phone number, email and any message you choose to send.
- In your account: identification, email, protected login credentials, sessions and activity records.
- To create your website: business information, services, hours, contact details, copy, images and preferences you provide, along with project versions and approvals.
- In customer service and contracting features, when enabled: questions, answers, authorized contact details, proposals, acceptance records and payment identifiers and statuses.
Do not send passwords, verification codes, medical records or other sensitive information through conversations. The service is not intended to collect children's data. If inappropriate information is sent, contact us so we can review its removal.
Why we use this information
We use the information needed to answer questions, prepare requested proposals, manage accounts, build and maintain contracted services, handle support requests and protect the system against failures and misuse.
Depending on the circumstances, processing relies on a contract or requested pre-contract steps, legal obligations, the exercise of rights or legitimate security interests, taking the individual's rights into account. When an activity requires consent, we will request it specifically, and you may withdraw it.
Reading this page does not constitute consent to advertising or general authorization for new uses of your data.
Who may have access
Internal access is limited to authorized people who need the data to support customers and operate the service. Our current infrastructure uses Oracle Cloud.
When you choose to contact us on WhatsApp, you use a Meta service that is also subject to that provider's privacy rules. The website button opens that channel; it does not automatically connect your personal conversations to our platform.
The Asaas payment integration is being tested. Public sign-up for paid services is not yet open. When commercial operations are enabled, the information needed to process payment will be sent to the provider identified at checkout. Do not send card details in messages.
Information may also be provided to comply with a legal obligation or a valid order from a competent authority, within the applicable scope. We do not sell lists of our users' personal information.
Artificial intelligence and services in preparation
The fifth element, focused on customer service, is in preparation. Test features include predefined answers, conversation history and human handoff. This does not mean that an external AI is automatically serving visitors to this website.
Content-generation tools may process information sent to them in enabled workflows, including through external providers such as Anthropic. The customer-service AI integration is not active in this version. Before new channels or data uses become available, their terms and this policy must reflect how they work.
Depending on the provider and infrastructure region, processing may take place outside Brazil. New operations must take account of the safeguards and international transfer mechanisms required by applicable law. We do not use conversations to train our own model in this version.
How we protect and retain data
We use HTTPS, access controls, protected credentials and backups. Security measures are reviewed during development. No system eliminates every risk, and this policy is not a security certification.
To detect and fix failures, the website sends sanitized technical reports to IdeaInSite's own server. This operational tracking does not use cookies, require analytics consent or send these reports to Google Analytics. Records have restricted access and scheduled rotation, with operational retention of up to 30 days.
We retain information for as long as needed for the stated purposes, contracted services, legal obligations or the defense of rights. Information no longer needed must be deleted or anonymized. At this stage, deletion requests and retention periods are reviewed with assistance; there is no single automatic deletion deadline for every category.
Historical backups may retain data longer than the active system, with restricted access for recovery and legally permitted purposes. Deletion requests must consider those copies and possible restoration. Incidents will be assessed and, where required, reported to affected individuals and the appropriate authority.
You have control and can request clarification
You may request confirmation of processing, access to your data, corrections, information about sharing and, where applicable, anonymization, restriction, deletion, portability, objection to processing, review of decisions made solely by automated means and withdrawal of consent.
Requests are free. We may ask only for the information needed to confirm your identity and avoid disclosure to someone else. If information must be retained or a request cannot be fulfilled immediately, we will explain why and the next steps, following applicable legal deadlines.
For information processed on behalf of a business customer, we may forward your request to that business. You may also submit a petition to ANPD if you cannot exercise your rights with the data controller.
How to discuss privacy
Use our contact channel on WhatsApp: +55 (71) 98100-5890 and let us know your request concerns personal data. You do not need to send documents or sensitive information in your first message.
You can also email contato@ideainsite.com.br. External email delivery is still being validated; for urgent requests, use WhatsApp until that validation is complete.
Policy updates
This policy was first published on , version 1.0. It will be updated when there are material changes to the service or data processing. Material changes should be communicated accessibly; new processing that requires consent is not authorized simply by updating this text.
References: Brazilian General Data Protection Law and ANPD guidance for individuals.