Legal document

Privacy Policy

Learn how Certifee processes personal data on the website, in forms, communications, courses and online purchases.

Last updated:

Introduction

This Privacy Policy explains how Certifee processes personal data from individuals who access and use the websitecertifee.com.br, fill out forms, request contact, ask for a quote, interact through WhatsApp, email or phone, access content, express interest in courses, training, consulting, audits, programs, protocols or other services, purchase open-enrollment courses or otherwise interact with Certifee through digital channels.

This policy applies to visitors, leads, customers, buyers, company representatives, students, individuals interested in open-enrollment courses, individuals interested in in-company training, professionals, managers, form users, checkout users, communication subscribers and other natural persons who interact with the website or with Certifee's digital channels.

Certifee operates mainly in Brazil in the field of consulting, auditing and training in food quality and food safety, covering areas such as food, feed, pet food, packaging, laboratories, transport, distribution, sustainability, due diligence, proprietary programs and risk solutions.

This policy was prepared with a focus on transparency, clarity and compliance with the Brazilian General Personal Data Protection Law, Law No. 13,709/2018, known as the LGPD.

Who controls the data

For purposes of this Privacy Policy, the controller of the personal data processed on the website is:

Trade name
Certifee
Legal name
CERTIFEE CONSULTORIA LTDA
CNPJ
07.378.424/0001-33
Domain
certifee.com.br
Address
Rua Appel, 1639, Apt. 202, Nossa Senhora de Fátima, Santa Maria/RS, Postal Code 97015-030, Brazil

Certifee is responsible for defining the purposes and essential means of processing personal data collected in the context of the website and the digital interactions described in this policy.

When this policy applies

This policy applies to the processing of personal data arising from interactions with Certifee's website and related digital features, including:

  • access to institutional pages, areas of practice, consulting services, programs, protocols, clients, team, news and insights;
  • searching, viewing and browsing open-enrollment course pages and in-company training pages;
  • use of contact forms, commercial forms, quote request forms and message fields;
  • interaction through the WhatsApp button, contact links, email or phone;
  • buyer registration, cart, checkout, payment, order confirmation and basic order lookup;
  • receipt of institutional, operational or commercial communications;
  • browsing technical content, articles, informational materials and campaign pages;
  • use of cookies, pixels, tags, analytics tools and similar technologies, when used;
  • access to and operation of the administrative area by authorized users, when applicable.

This policy does not govern third-party websites, platforms, applications or services that have their own policies, even if they can be accessed through links or integrations available on Certifee's website.

What personal data may be collected

The personal data processed by Certifee may vary depending on how the user interacts with the website. Certifee seeks to process only data that is compatible with the stated purposes and necessary for service, relationship management, security, purchases, website operation and compliance with legal or contractual obligations.

Website browsing

When browsing the website, technical and usage data may be processed, such as:

  • IP address;
  • date and time of access;
  • pages accessed;
  • traffic source;
  • browsing events;
  • browser type;
  • operating system;
  • device type;
  • online identifiers, when applicable;
  • information about interactions with pages, buttons, searches, forms, cart and checkout;
  • cookie preferences and records of consent or settings, when there is a cookie banner or cookie preference center.

This data may be used to keep the website running, improve performance, security and browsing experience, understand how pages are used, measure conversions and assess the effectiveness of content, campaigns and digital journeys.

Contact and quote request forms

When filling out forms on the website, the user may provide data such as:

  • name;
  • email;
  • phone;
  • company;
  • job title or role, when there is a specific field;
  • course, training, consulting, audit, program or service of interest;
  • message submitted in a free-form field;
  • other information voluntarily provided in the context of the request.

Free-form fields should be used only for information necessary to handle the requested service. The user should avoid entering excessive personal data, third-party data without authorization or sensitive data, unless that information is strictly necessary to analyze the request.

Open-enrollment courses and purchase flow

In the context of open-enrollment courses, cart, checkout, payment, confirmation and basic order lookup, data such as the following may be processed:

  • buyer or participant name;
  • email;
  • phone;
  • company, when applicable;
  • CPF or CNPJ Brazilian tax identification number, when necessary for purchase, billing, identification, tax invoicing or fraud prevention;
  • billing address, when applicable;
  • course purchased or of interest;
  • order data;
  • purchase status;
  • information necessary to confirm the order and provide related support;
  • payment data processed by the payment gateway;
  • technical records of the purchase flow.

Certain payment data may be processed directly by the payment gateway, according to the terms, policies and technical flows of the respective provider.

In-company training and consulting services

For requests related to in-company training, consulting, audits, advanced programs, protocols, sustainability, due diligence, risk solutions and other consulting services, the following data may be processed:

  • requester's name;
  • professional email;
  • phone;
  • company;
  • job title or role;
  • area of activity;
  • reported need;
  • course, service or topic of interest;
  • message and context of the request;
  • commercial information necessary to prepare a response, proposal, quote or continue the service process.

In B2B interactions, company data may be processed together with personal data of representatives, managers, buyers, technical contacts or other contact persons.

Support through WhatsApp, email or phone

When the user contacts Certifee through WhatsApp, email, phone or contact links available on the website, the following data may be processed:

  • name;
  • phone number;
  • email;
  • company;
  • job title or role, when provided;
  • content of messages;
  • service history necessary to continue the conversation;
  • information about courses, orders, quotes, services or related requests.

The use of WhatsApp and other communication platforms is also subject to those platforms' own terms and policies.

Commercial communications

Certifee may process contact data and preferences to send or direct communications related to:

  • responses to requests made by the user;
  • information about open-enrollment courses;
  • in-company training;
  • consulting, audits, programs, protocols and services;
  • technical content, news, insights, events and institutional materials;
  • confirmation of registration, purchase, order or service;
  • commercial communications compatible with the relationship maintained with the data subject or with the preferences provided.

When applicable, the data subject may request to unsubscribe, object to receiving communications or change communication preferences.

Administrative area, when applicable

Authorized administrative users who access the website's internal tools may have data processed such as:

  • name;
  • email;
  • access credentials;
  • permission profile;
  • login records;
  • actions performed in the administrative panel;
  • technical data necessary for security, internal audit and permission management.

The administrative area is intended for authorized persons and must be used according to the permissions granted and good security practices.

Cookies and similar technologies

The website may collect data through cookies, pixels, tags, local storage, device identifiers and similar technologies. These resources may record preferences, enable features, measure audience, analyze performance, measure conversions and support digital campaigns, according to the website configuration and the user's preferences.

The specific cookies section of this policy explains cookie types and management options.

Sensitive data

Certifee's website is not intended to intentionally collect sensitive personal data, such as data about health, racial or ethnic origin, religious belief, political opinion, union membership, genetic data, biometric data, sexual life or other data classified as sensitive under the LGPD.

The user should avoid sending sensitive data in free-form fields in forms, messages, WhatsApp or emails, unless such information is strictly necessary for the requested service. If sensitive data is sent spontaneously, Certifee may process it only to the extent necessary to analyze, respond, discard, protect rights or comply with applicable obligations.

Purposes of processing

Certifee may process personal data for the following purposes:

  • to enable browsing and website operation;
  • to respond to contacts, questions, requests and messages sent by the user;
  • to send requested information about courses, training, consulting, audits, programs, protocols and services;
  • to organize, qualify and respond to commercial or quote requests;
  • to process purchases, registrations, payments, orders and confirmations related to open-enrollment courses;
  • to enable buyer registration, cart, checkout, payment, confirmation and basic order lookup;
  • to provide support before, during and after a purchase, registration or request;
  • to maintain relationship records and history necessary to continue service;
  • to send operational, institutional or commercial communications, when appropriate;
  • to promote courses, training, content, events, services and opportunities compatible with the relationship maintained with the data subject;
  • to improve website browsing, usability, performance and security;
  • to perform technical SEO, access analysis, conversion measurement and assessment of digital campaigns;
  • to measure interactions such as WhatsApp clicks, form submissions, course searches, checkout starts and completed purchases, when those measurements are configured;
  • to protect the website against unauthorized access, fraud, incidents, abuse of features and improper use;
  • to comply with legal, regulatory, tax, accounting, contractual and administrative obligations;
  • to respond to requests from public authorities, when necessary;
  • to exercise rights in administrative, judicial or arbitral proceedings;
  • to maintain internal controls, technical records and documentation necessary for governance, security and compliance.

Cookies and similar technologies

What cookies are

Cookies are small files or identifiers stored in the user's browser or device when the user accesses a website. They may enable features to work, remember preferences, maintain browsing security, measure audience, understand how pages are used and support digital marketing activities.

In addition to cookies, the website may use similar technologies, such as pixels, tags, scripts, online identifiers, localStorage, sessionStorage and event measurement tools.

What cookies may be used for

Cookies and similar technologies may be used to:

  • enable basic website features;
  • keep the cart, checkout and purchase steps working correctly;
  • remember user preferences;
  • record cookie preferences, when there is a banner or preference center;
  • analyze performance, stability and page usage;
  • understand traffic source and browsing journey;
  • measure conversions, such as form submission, WhatsApp click, checkout start and completed purchase;
  • support campaigns, remarketing, ads and media measurement, when marketing tools are configured;
  • detect failures, improper use, incidents and anomalous behavior.

Necessary

Essential for the website to work: browsing, security, loading, forms, cart, checkout, fraud prevention, session and privacy preferences. Disabling them may impair or prevent features.

Functional

Help remember user preferences, such as language, display settings and adjustments that make the website easier to use.

Analytics or performance

Allow understanding which pages receive more visits and which flows generate more interaction. They may involve Google Analytics, Google Tag Manager or equivalent technologies, if configured.

Marketing or advertising

Support campaign measurement, audience creation, conversions and remarketing. They may involve Meta Pixel, Google Tag Manager, conversion tags or equivalent tools, if configured.

Similar technologies

Pixels, tags, scripts, measurement APIs, local storage and online identifiers may work similarly to cookies. They may be used to record events, measure conversions, load integrations, maintain preferences, improve performance and support website features.

How to manage cookie preferences

The user may manage cookies and similar technologies in the following ways:

  • adjusting preferences in the cookie banner or cookie center, when available;
  • configuring the browser to block, delete or limit cookies;
  • using privacy features of the device or browser;
  • reviewing preferences on third-party platforms, when applicable.

Some non-essential cookies may depend on the user's consent or specific settings. If the user rejects or blocks analytics, functional or marketing cookies, certain non-essential features may be limited and the measurement of performance, campaigns and conversions may be reduced.

Disabling necessary cookies may affect website operation and prevent proper use of features such as cart, checkout, forms or privacy preferences.

Sharing data with third parties

Certifee may share personal data with third parties when this is necessary to operate the website, provide services, handle requests, enable purchases, comply with legal obligations, maintain security, carry out communications or protect rights.

Sharing may occur with categories of third parties such as:

  • providers of infrastructure, hosting, database, DNS, CDN, storage, authentication, security and technical support;
  • payment gateway and service providers involved in transaction processing;
  • email services, transactional email, notification sending and customer service;
  • analytics tools, tags, pixels, conversion measurement and digital campaign tools;
  • communication platforms, including WhatsApp and related channels;
  • technical providers responsible for website development, maintenance, testing, support or operation;
  • accounting, legal, audit, fraud prevention, collection, administrative management or business support providers;
  • partners necessary to carry out courses, training, consulting, audits or specific requests, when applicable;
  • public authorities, regulators, government entities or third parties when there is a legal obligation, valid order, legitimate request or need to defend rights.

Certifee seeks to limit sharing to what is necessary for the stated purposes and expects providers and partners to adopt compatible data security and protection measures.

Payments

Purchases of open-enrollment courses on the website may be processed by a payment gateway, such as PagBank, when the integration is active.

During payment, data necessary for the transaction may be processed, such as buyer identification, order data, amount, transaction status, payment method and information required for authorization, fraud prevention, confirmation, refund, billing or related support.

Certifee does not ask users to send full credit card details through contact forms, email, WhatsApp or free-form fields. Full card details and other sensitive payment information, when necessary for the transaction, must be entered and processed in the environment, components or technical flows of the payment gateway.

The payment gateway may act according to its own terms, privacy policies, security rules, regulatory requirements and anti-fraud procedures. The user should review the payment provider's policies to understand how data is processed in that environment.

Certifee may retain records related to the order, purchase confirmation, payment status, service and applicable legal, tax, accounting or contractual obligations.

International data transfer

Some technology providers used to operate the website, process payments, store data, send emails, measure audience, measure campaigns, maintain security or provide support may store or process personal data outside Brazil.

When international data transfers occur, they must take place in accordance with applicable law, contracts, terms of use, providers' privacy policies and appropriate data protection mechanisms.

Certifee seeks to use providers that adopt security and data protection practices compatible with the nature of the services provided.

Data retention and deletion

Personal data is kept for as long as necessary to fulfill the purposes described in this policy, handle requests, enable purchases, provide services, maintain operational records, comply with legal, tax, accounting, regulatory and contractual obligations, prevent fraud, strengthen security and exercise rights.

Retention periods may vary according to the data category, purpose and applicable obligations.

Contact data and requests

Data submitted through forms, WhatsApp, email or phone may be kept while necessary to respond to the request, continue the relationship, record service history, prepare proposals, handle commercial demands or protect rights.

Purchase and order data

Data related to purchases, registrations, orders, payments, confirmation, billing and support may be kept for the time necessary for contractual performance, buyer support, compliance with tax, accounting and regulatory obligations and the exercise of rights.

Marketing and communication data

Data used for commercial communications may be kept while there is an applicable legal basis, relationship with the data subject, compatible legitimate interest or valid consent, when required. The data subject may request to unsubscribe, object or change preferences.

Technical logs and security data

Technical logs, access data, event records and security information may be kept for the time necessary to protect the website, investigate incidents, prevent fraud, correct failures, preserve evidence and comply with applicable obligations.

Cookies

Cookies may have different retention periods according to their purpose and configuration. The user may delete cookies through the browser or adjust preferences in the cookie center, when available.

Administrative data

Administrative user data may be kept while access is necessary and, afterward, for the period necessary for security, auditing, accountability, incident investigation and exercise of rights.

When data is no longer necessary, Certifee may delete it, anonymize it or keep it in a restricted manner when there is a legal obligation, need to preserve rights, security, auditing, fraud prevention or another applicable legal basis.

Information security

Certifee adopts reasonable and proportional technical and organizational measures to protect personal data against unauthorized access, loss, alteration, improper disclosure, misuse or other forms of improper or unlawful processing.

These measures may include, as applicable:

  • use of HTTPS and a security certificate on the website;
  • access control for administrative environments;
  • permission management by user profile;
  • restriction of access to personal data only to authorized persons;
  • use of technology providers necessary for website operation;
  • technical best practices for development, hosting and operation;
  • technical monitoring and failure verification, when applicable;
  • protection against unauthorized access and improper use;
  • technical records for security and auditing;
  • incident review and adoption of corrective measures, when necessary.

Despite the measures adopted, no digital environment is absolutely immune to risks. For this reason, the user should also adopt good security practices, such as using protected devices, avoiding credential sharing, being cautious with suspicious messages and not sending sensitive information through inappropriate channels.

Data subject rights

Under the LGPD, the data subject may exercise rights related to the processing of personal data, subject to the applicable legal conditions. These rights include:

Confirmation of processing

The data subject may request confirmation as to whether Certifee processes their personal data.

Access to data

The data subject may request access to personal data processed by Certifee, subject to trade secrets, third-party information and applicable legal limits.

Correction

The data subject may request correction of incomplete, inaccurate or outdated data.

Anonymization, blocking or deletion

The data subject may request anonymization, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD, when applicable.

Portability

The data subject may request data portability to another service or product provider, subject to applicable regulation, technical feasibility and trade and industrial secrets.

Information about sharing

The data subject may request information about public and private entities with which Certifee has shared personal data, subject to applicable legal and commercial limitations.

Information about consent

When processing depends on consent, the data subject may request information about the possibility of not providing it and about the consequences of that decision.

Withdrawal of consent

When processing is based on consent, the data subject may withdraw it at any time, without affecting the validity of processing previously carried out on the basis of valid consent.

Objection to processing

The data subject may object to certain processing activities, especially when they understand that there is non-compliance with the LGPD or when processing is based on legitimate interest, subject to the applicable legal conditions.

Review of automated decisions

If decisions are made solely on the basis of automated processing of personal data and affect the data subject's interests, the data subject may request review under the LGPD. The section "Automated decisions" of this policy provides additional information about the website's current operation.

Petition to the ANPD

The data subject may file a petition with the Brazilian National Data Protection Authority, according to the channels and procedures made available by the competent authority.

How to exercise your rights

To exercise rights, the data subject should contact Certifee by email atvalesca@certifee.com.br, clearly indicating which right they wish to exercise and providing sufficient information for analysis of the request.

Certifee may request additional information to confirm the identity of the data subject or the legitimacy of the representative, in order to protect personal data against unauthorized access. Requests will be analyzed according to the LGPD, the nature of the request, available records and applicable legal obligations.

Commercial communications

Certifee may send communications by email, phone, WhatsApp or other channels provided by the data subject to:

  • respond to requests made by the user;
  • send information about courses, training, events, content, consulting, audits, programs, protocols and services;
  • confirm registrations, purchases, orders or service requests;
  • share technical content, news, insights and opportunities related to Certifee's activities;
  • maintain relationships with customers, leads, buyers, company representatives and interested individuals.

Commercial communications will be sent according to the applicable legal basis, the context of the relationship and the data subject's preferences.

The data subject may request to unsubscribe, stop commercial communications, object to processing or change preferences through the mechanism provided in the communication, when available, or by email atvalesca@certifee.com.br.

Certifee may continue sending strictly operational or transactional communications, such as order confirmation, purchase information, requested support, legal obligations or notices necessary for service provision, even if the data subject chooses not to receive promotional communications.

Minors' data

Certifee's website is not directed to children. The courses, content and services are intended mainly for companies, managers, professionals, corporate buyers, students and individuals interested in technical topics related to food quality and food safety.

Certifee does not seek to intentionally collect personal data from children. Minors should use registration, purchase, enrollment or personal data submission features with the participation, knowledge or authorization of their legal guardian, when applicable.

If Certifee identifies improper processing of data from a child or adolescent, it may adopt measures to limit, delete or regularize the processing, according to applicable law and the best interests of the minor.

Third-party links and platforms

The website may contain links, buttons or integrations that direct the user to third-party platforms, such as WhatsApp, social networks, payment gateway, videos, maps, external content, partners or other digital environments.

These platforms may collect and process personal data according to their own terms of use, privacy policies, cookie policies and settings. Certifee does not fully control the privacy, security and cookie practices of these platforms.

Before using third-party services, users are advised to read the policies applicable to those environments.

Automated decisions

The website may use technical automations, browsing records, measurement tools, tags, pixels, cookies, conversion events and security mechanisms to improve the experience, measure performance, support campaigns, prevent fraud and operate features.

In the ordinary operation of the website, Certifee does not make automated decisions based exclusively on personal data that produce legal effects or relevant impacts on the data subject, unless such functionality is expressly disclosed through a dedicated channel or an update to this policy.

Updates to this policy

This Privacy Policy may be updated to reflect changes to the website, features, services, technologies used, providers, Certifee's internal practices or applicable law.

When there is a relevant update, Certifee may change the "Last updated" date and, when appropriate, provide additional notices on the website or through contact channels.

The most recent version of this policy will be available on the websitecertifee.com.br.

Contact channel

For questions, requests or exercise of rights related to privacy and personal data protection, contact Certifee through the channel below:

Privacy officer

CERTIFEE CONSULTORIA LTDA · CNPJ 07.378.424/0001-33

Last updated:

Back to top