Skip to content
GRICCO.
PRIVACY AND LGPD

How we handle your data.

This policy explains, in plain language, how GRICCO collects, uses, and protects personal data in line with Brazil's Data Protection Law (Law 13.709/2018, LGPD).

Last updated: June 2026.

PURPOSE

Confidentiality is not a detail. It is the basis of our work.

GRICCO manages legal compliance projects. Handling data with rigor is part of that responsibility. This policy applies to our website and commercial contact channels. The processing of employee data is governed by separate internal policies.

1

Data controller

The controller of the data processed on this website is GRICCO Soluções Integradas Ltda., Tax ID (CNPJ) 53.765.584/0001-52, based in Macaé/RJ, Brazil.

International contracts and relationships may be signed by GRICCO International (Wyoming, USA), the international arm of the GRICCO ecosystem. When GRICCO International acts as controller, the same principles set out in this policy apply.

2

Data we collect

We collect only what is needed to respond to you and manage the commercial relationship:

  • Data you provide: name, company, business email, phone/WhatsApp, and the context you describe in forms or by email.
  • Navigation data: IP address, device type, browser, and pages visited, collected in aggregate by analytics tools.
  • Cookies and identifiers: as described in the cookies section.

We do not collect sensitive personal data through the website, and we ask that you not include such data in open form fields.

3

Purposes and legal bases

We process personal data for specific purposes and under the legal bases set out in Article 7 of the LGPD:

Respond to diagnostic and contact requests
Preliminary procedures prior to a contract, at the data subject's request (Art. 7, V).
Manage the commercial relationship and send proposals
Performance of a contract and legitimate interest (Art. 7, V and IX).
Measure and improve the website experience
Legitimate interest, with balancing and minimization (Art. 7, IX).
Comply with legal and regulatory obligations
Compliance with a legal or regulatory obligation (Art. 7, II).
4

Data sharing

We do not sell personal data. We share data only when necessary and with safeguards:

  • Operators and technology providers (email, hosting, analytics), bound by contract with data protection clauses.
  • GRICCO International, when the relationship is handled through the international structure.
  • Public authorities, upon a legitimate request or legal requirement.

No operator is allowed to use the data for its own purposes or to train AI models.

5

International transfer

Some providers may store data outside Brazil. When this happens, we require adequate safeguards under Article 33 of the LGPD — preferring countries with an adequate level of protection or standard clauses recognized by the ANPD.

6

Data retention

We keep data only for as long as each purpose requires:

  • Commercial requests: for the duration of the relationship and the applicable legal periods after the last contact.
  • Navigation and metrics data: in aggregate form, for limited periods defined in the analytics tools.
  • Legal obligations: for the period required by applicable law.

Once the purpose ends, data is deleted or anonymized, except where legal retention applies.

7

Cookies

We use essential cookies for the website to function and analytics cookies to understand how pages are used. Analytics cookies depend on your consent, where applicable.

You can manage or block cookies in your browser settings. Blocking essential cookies may affect parts of the website.

8

Data subject rights

As a data subject, you have the rights set out in Article 18 of the LGPD:

  • Confirm the existence of processing and access your data.
  • Correct incomplete, inaccurate, or outdated data.
  • Request the anonymization, blocking, or deletion of unnecessary or excessive data.
  • Request data portability, under ANPD rules.
  • Withdraw consent and be informed about the sharing of your data.

To exercise your rights, contact our Data Protection Officer (DPO). The service is free and answered within 15 days.

9

Security

We adopt technical and administrative measures to protect data, including encryption in transit (TLS), least-privilege access control, and segregation of duties.

In the event of a security incident with relevant risk, we act on containment, assess the risk, and notify the ANPD and affected data subjects as required by the LGPD. Incidents should be reported to the DPO.

10

Changes to this policy

We may update this policy to reflect legal, technological, or operational changes. The last-updated date at the top indicates the current version. We recommend reviewing it periodically.

CONTACT

Contact our Data Protection Officer (DPO).

For questions, rights requests, or incident reports, please contact our Data Protection Officer.

Data Protection Officer (DPO)
dpo@gricco.com.br
Controller
GRICCO Soluções Integradas Ltda. · Tax ID (CNPJ) 53.765.584/0001-52 · Macaé/RJ, Brazil