Privacy
Privacy Policy
This page describes how we handle business contact data submitted through the contact and quote forms, received through official channels, and technically logged by our hosting, in accordance with the LGPD (Brazilian General Data Protection Law).
Courtesy translation. This English version is provided for convenience only; the Portuguese version is the official, legally binding text and prevails for all legal purposes. Preliminary version: the controller's registration data and the channel for exercising rights are already listed on this page; the text will still undergo final legal review before publication on the definitive domain.
1. Controller and scope of this version
Controller: Rosit Cloud Consultoria Ltda (trade name Rosit Cloud), CNPJ 50.197.505/0001-66, headquartered at Avenida Ayrton Senna, 2500, Bloco 2, Sala 326 — Barra da Tijuca, Rio de Janeiro/RJ, CEP 22775-003. Contact for privacy matters and exercise of rights: comercial@rosit.cloud. This is a preliminary version, published for transparency while the Rosit Cloud institutional site is being prepared. It describes how we handle personal business contact data submitted through the contact and quote forms, plus technical browsing information. The practices described will be confirmed, complemented with the controller's registration data, and legally validated before go-live. This policy does not govern service contracts, which have their own data protection and confidentiality clauses.
2. Collection in this version of the site
The site has two active forms: consultative contact (/contato) and quote request (/cotacao). Submitted data is stored in a private database, accessible only by the application server, and forwarded to Rosit Cloud's sales team for a response. Along with each submission we also log the originating page, referrer, campaign (UTM) parameters present in the URL, browser information, and a non-reversible identifier derived from the IP address, used exclusively to contain automated submissions and abuse. Contact may also occur through official channels (email, phone, and business WhatsApp), and data shared in those conversations is used only to respond to the request.
3. Data collected by the forms
The forms only collect business contact data voluntarily provided: name of the responsible person, company, corporate email, optional phone number, subject and message (contact) or category, description of the need, quantity, desired timeframe, city/state, installation scope, manufacturer/model reference, and remarks (quote). We do not request sensitive data, personal documents, or payment information through the site.
4. Intended purpose
The intended purpose of this data is to respond to the request, prepare technical and commercial proposals, and maintain a record of the commercial interaction. There is no sale, rental, or transfer of data to third parties for advertising purposes, planned or otherwise.
5. Intended legal basis
The legal basis for processing is the consent given upon submission of the form and, where applicable, the performance of preliminary procedures related to a contract, under Brazilian Law No. 13,709/2018 (LGPD). The legal basis for each operation will be confirmed in the legally validated version.
6. Cookies and measurement (Google Analytics 4)
We do not use advertising cookies or social media pixels. The site's only measurement tool is Google Analytics 4 (GA4), used to understand page usage and measure commercial conversions (clicks on WhatsApp, email, and phone, and starting/submitting the contact and quote forms). GA4 is only loaded after explicit consent in the privacy notice: those who decline receive neither the script nor any measurement event. We do not send GA4 any name, email, phone, company, message, quoted item, city, request reference code, or any content typed into the forms — only the page visited and the type of interaction. Google's advertising and personalization features remain disabled. Besides GA4, we keep only a local record in your browser of your consent choice, which is essential to respecting it.
7. Intended sharing
Data may be processed by infrastructure and communication providers strictly necessary for operating the site and providing commercial support, limited to the original purpose. In quote processes, technical information about the request may be shared with channels and suppliers only to the extent necessary to obtain the requested conditions. The list of processors and their respective safeguards will be detailed in the final version of this policy.
8. Retention
The intended criterion is to keep data for the period necessary to handle the request and comply with applicable legal obligations, with deletion or anonymization once no longer needed. Specific retention periods will be defined and published in the final version of this policy.
9. Data subject rights
The LGPD guarantees data subjects the right to request confirmation of processing, access, correction, anonymization, portability, deletion, and revocation of consent. Requests should be sent to comercial@rosit.cloud, identifying the data subject and the request. Should a named Data Protection Officer (DPO) be designated, that information will be published on this page.
10. Security
Data submitted through the forms travels over an encrypted (HTTPS) connection and is stored in a database with restricted access: there is no public or anonymous reading of the records. Validation also occurs on the server, with size limits, submission-volume controls per origin, and silent mechanisms against automated submissions. The IP identifier is stored only in a non-reversible derived form.
11. Updates
This policy is preliminary and may be revised at any time until the final version. The version in force is always the one published on this page.