Privacy Policy
This Policy clearly explains how Arvoris collects, uses, shares, stores, and protects personal data across its digital channels.
Version 2.0 · Effective as of August 02, 20261. Controller and scope
Arvoris, which is responsible for arvoris.com.br, acts as the controller of personal data processed to operate this website, respond to inquiries, receive business requests, and handle privacy rights. This Policy applies to the website, forms, cookie preferences, and communications initiated through those channels. When providing services to clients, Arvoris may also act as a processor under each client’s instructions and contract.
The controller’s privacy and contact channel is contato@arvoris.com.br. Data subject requests may also be submitted through the Data Rights page.
2. Personal data we may process
Depending on your interaction, we may process:
- identity and contact details, such as your name, email address, and WhatsApp number;
- professional and business details, such as your company, product or service, website, social media profile, sales model, goals, estimated investment range, and meeting preferences;
- content you provide, including messages, questions, business context, and privacy request details;
- navigation and security data, such as your IP address, date and time, requested pages, source, UTM parameters, browser, device, and technical logs;
- consent data, including a pseudonymous browser identifier, selected categories, notice version, selection method, date, and source page; and
- reference numbers, service history, and records required to document our response.
3. How we obtain data
We receive data directly from you when you submit a form, contact us, request a meeting, change preferences, or exercise a right. Certain technical data is generated automatically to deliver pages, maintain security, and record operational events. When you provide a public business website or profile, we may review that address solely to understand the context of your request.
4. Purposes and legal grounds
We process data for specific purposes under an appropriate legal ground:
- answering messages, preparing meetings, and taking requested steps before a possible engagement: steps prior to entering into a contract and legitimate interests;
- preparing proposals, delivering services, and managing the client relationship: performance of a contract;
- operating, securing, and improving digital channels, preventing abuse, investigating failures, and keeping access records: legitimate interests and compliance with legal obligations;
- complying with tax, regulatory, judicial, or administrative duties and exercising or defending rights: legal obligations and the exercise of legal rights;
- recording and answering data subject requests: compliance with the LGPD and the exercise of legal rights;
- enabling analytics, campaign measurement, or advertising, when available: prior, specific, and revocable consent by category.
When relying on legitimate interests, we limit processing to what is necessary and consider the data subject's reasonable expectations, rights, and freedoms.
5. Required and optional information
Fields marked as required are needed to identify the request, prevent abuse, and provide a response. Without them, we may be unable to complete the submission or provide assistance. Unmarked fields are optional. Refusing optional cookies or technologies does not prevent access to content or form submission.
6. Sharing and processors
We may share strictly necessary data with providers that support hosting, databases, security, backups, email, communications, technical support, and, where consent is required, analytics and advertising measurement. Provider categories may include cloud infrastructure, email services, and platforms such as Google, Meta, and TikTok when their integrations are enabled.
Providers must follow our instructions, contracts, and confidentiality and security obligations. We may also share information with authorities or third parties when required by law, a valid order, or the need to exercise legal rights. Arvoris does not sell personal data.
7. International transfers
The website's primary infrastructure uses resources located in Brazil. Certain technology, communication, analytics, or advertising providers may store or access data in other countries. Where an international transfer occurs, we use a mechanism allowed by the LGPD and ANPD regulations, together with contractual and security safeguards appropriate to the risk and purpose.
8. Retention and deletion
We retain data only as long as necessary for the stated purpose and applicable legal or regulatory obligations:
- application access logs: 6 months, subject to the Brazilian Civil Rights Framework for the Internet;
- inquiries and opportunities that do not result in an engagement: generally up to 24 months after the last interaction;
- client and contractual relationship data: for the duration of the relationship and the applicable legal, tax, and limitation periods;
- consent, data subject request, audit, and legal defense records: for the period required to demonstrate compliance and protect rights, generally up to 5 years after the matter is closed;
- browser technologies: for the periods stated in the Cookie Policy.
Periods may be extended because of legal obligations, orders from authorities, or the need to preserve evidence. Once the purpose ends and there is no lawful reason to retain the data, it is deleted or anonymized. Backups remain isolated and stop containing the data as they are securely replaced.
9. Cookies and similar technologies
The website uses local storage, session storage, and, where applicable, cookies for operation, security, and preferences. Analytics and marketing remain disabled until you make an affirmative choice. Categories, identifiers, durations, and controls are described in the Cookie Policy and Cookie Preferences page.
10. Information security
We use technical and organizational measures proportionate to the risks, including HTTPS, access restrictions, authenticated administration, service segregation, audit records, abuse controls, backups, and component updates. No environment is infallible, so we maintain procedures to investigate incidents and, where required, notify affected individuals and the ANPD.
11. Children and teenagers
The website and Arvoris business services are intended for people with legal capacity to enter into contracts and are not directed to children. We do not knowingly request children's data. A parent or guardian who identifies an improper submission may request deletion through the privacy channel. Matters involving teenagers will be assessed under the best-interest principle and applicable law.
12. Automated decisions
Arvoris does not use data collected through these channels to make solely automated decisions that produce legal effects or significantly affect an individual's interests. If that practice is introduced, we will provide the required information and a way to request review and an explanation of the criteria used.
13. Data subject rights
Under the LGPD, you may request confirmation of processing, access, correction, anonymization, blocking or deletion of improperly processed data, portability when regulated, deletion of consent-based data where applicable, information about sharing and the consequences of refusing consent, withdrawal of consent, objection to unlawful processing, and review of solely automated decisions.
14. How to exercise rights
Use the Data Rights page or email contato@arvoris.com.br. Requests are free and receive a reference number. To protect the individual, we may request additional information through a secure channel when there is reasonable doubt about identity or authority. Confirmation and simplified access are provided immediately where possible; complete statements are provided within 15 days, and other requests follow applicable legal and regulatory timeframes. If an action cannot be taken immediately, we explain why.
15. Changes to this Policy
We may update this Policy to reflect legal, technical, or operational changes. The current version, update date, and any relevant notices will be published on this page. Where a change requires new consent, the previous choice will not be used for the new purpose.
16. Contact and applicable law
Questions, complaints, or data requests may be sent to contato@arvoris.com.br or through the Data rights page. Processing under this Policy is primarily governed by Brazil's General Data Protection Law (Law No. 13,709/2018), the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014), and ANPD regulations. Individuals may also petition ANPD and, where applicable, consumer protection authorities. This English text is provided for accessibility; the Portuguese version prevails for interpretation under Brazilian law, without limiting mandatory rights under other applicable laws.

