Introduction
This Privacy Policy explains how Certifee processes personal data from individuals who access and use the websitecertifee.com.br, fill out forms, request contact, ask for a quote, interact through WhatsApp, email or phone, access content, express interest in courses, training, consulting, audits, programs, protocols or other services, purchase open-enrollment courses or otherwise interact with Certifee through digital channels.
This policy applies to visitors, leads, customers, buyers, company representatives, students, individuals interested in open-enrollment courses, individuals interested in in-company training, professionals, managers, form users, checkout users, communication subscribers and other natural persons who interact with the website or with Certifee's digital channels.
Certifee operates mainly in Brazil in the field of consulting, auditing and training in food quality and food safety, covering areas such as food, feed, pet food, packaging, laboratories, transport, distribution, sustainability, due diligence, proprietary programs and risk solutions.
This policy was prepared with a focus on transparency, clarity and compliance with the Brazilian General Personal Data Protection Law, Law No. 13,709/2018, known as the LGPD.
Who controls the data
For purposes of this Privacy Policy, the controller of the personal data processed on the website is:
- Trade name
- Certifee
- Legal name
- CERTIFEE CONSULTORIA LTDA
- CNPJ
- 07.378.424/0001-33
- Domain
- certifee.com.br
- Address
- Rua Appel, 1639, Apt. 202, Nossa Senhora de Fátima, Santa Maria/RS, Postal Code 97015-030, Brazil
- Privacy email
- valesca@certifee.com.br
- Phone
- +5555991737022
Certifee is responsible for defining the purposes and essential means of processing personal data collected in the context of the website and the digital interactions described in this policy.
When this policy applies
This policy applies to the processing of personal data arising from interactions with Certifee's website and related digital features, including:
- access to institutional pages, areas of practice, consulting services, programs, protocols, clients, team, news and insights;
- searching, viewing and browsing open-enrollment course pages and in-company training pages;
- use of contact forms, commercial forms, quote request forms and message fields;
- interaction through the WhatsApp button, contact links, email or phone;
- buyer registration, cart, checkout, payment, order confirmation and basic order lookup;
- receipt of institutional, operational or commercial communications;
- browsing technical content, articles, informational materials and campaign pages;
- use of cookies, pixels, tags, analytics tools and similar technologies, when used;
- access to and operation of the administrative area by authorized users, when applicable.
This policy does not govern third-party websites, platforms, applications or services that have their own policies, even if they can be accessed through links or integrations available on Certifee's website.
What personal data may be collected
The personal data processed by Certifee may vary depending on how the user interacts with the website. Certifee seeks to process only data that is compatible with the stated purposes and necessary for service, relationship management, security, purchases, website operation and compliance with legal or contractual obligations.
Website browsing
When browsing the website, technical and usage data may be processed, such as:
- IP address;
- date and time of access;
- pages accessed;
- traffic source;
- browsing events;
- browser type;
- operating system;
- device type;
- online identifiers, when applicable;
- information about interactions with pages, buttons, searches, forms, cart and checkout;
- cookie preferences and records of consent or settings, when there is a cookie banner or cookie preference center.
This data may be used to keep the website running, improve performance, security and browsing experience, understand how pages are used, measure conversions and assess the effectiveness of content, campaigns and digital journeys.
Contact and quote request forms
When filling out forms on the website, the user may provide data such as:
- name;
- email;
- phone;
- company;
- job title or role, when there is a specific field;
- course, training, consulting, audit, program or service of interest;
- message submitted in a free-form field;
- other information voluntarily provided in the context of the request.
Free-form fields should be used only for information necessary to handle the requested service. The user should avoid entering excessive personal data, third-party data without authorization or sensitive data, unless that information is strictly necessary to analyze the request.
Open-enrollment courses and purchase flow
In the context of open-enrollment courses, cart, checkout, payment, confirmation and basic order lookup, data such as the following may be processed:
- buyer or participant name;
- email;
- phone;
- company, when applicable;
- CPF or CNPJ Brazilian tax identification number, when necessary for purchase, billing, identification, tax invoicing or fraud prevention;
- billing address, when applicable;
- course purchased or of interest;
- order data;
- purchase status;
- information necessary to confirm the order and provide related support;
- payment data processed by the payment gateway;
- technical records of the purchase flow.
Certain payment data may be processed directly by the payment gateway, according to the terms, policies and technical flows of the respective provider.
In-company training and consulting services
For requests related to in-company training, consulting, audits, advanced programs, protocols, sustainability, due diligence, risk solutions and other consulting services, the following data may be processed:
- requester's name;
- professional email;
- phone;
- company;
- job title or role;
- area of activity;
- reported need;
- course, service or topic of interest;
- message and context of the request;
- commercial information necessary to prepare a response, proposal, quote or continue the service process.
In B2B interactions, company data may be processed together with personal data of representatives, managers, buyers, technical contacts or other contact persons.
Support through WhatsApp, email or phone
When the user contacts Certifee through WhatsApp, email, phone or contact links available on the website, the following data may be processed:
- name;
- phone number;
- email;
- company;
- job title or role, when provided;
- content of messages;
- service history necessary to continue the conversation;
- information about courses, orders, quotes, services or related requests.
The use of WhatsApp and other communication platforms is also subject to those platforms' own terms and policies.
Commercial communications
Certifee may process contact data and preferences to send or direct communications related to:
- responses to requests made by the user;
- information about open-enrollment courses;
- in-company training;
- consulting, audits, programs, protocols and services;
- technical content, news, insights, events and institutional materials;
- confirmation of registration, purchase, order or service;
- commercial communications compatible with the relationship maintained with the data subject or with the preferences provided.
When applicable, the data subject may request to unsubscribe, object to receiving communications or change communication preferences.
Administrative area, when applicable
Authorized administrative users who access the website's internal tools may have data processed such as:
- name;
- email;
- access credentials;
- permission profile;
- login records;
- actions performed in the administrative panel;
- technical data necessary for security, internal audit and permission management.
The administrative area is intended for authorized persons and must be used according to the permissions granted and good security practices.
Cookies and similar technologies
The website may collect data through cookies, pixels, tags, local storage, device identifiers and similar technologies. These resources may record preferences, enable features, measure audience, analyze performance, measure conversions and support digital campaigns, according to the website configuration and the user's preferences.
The specific cookies section of this policy explains cookie types and management options.
Sensitive data
Certifee's website is not intended to intentionally collect sensitive personal data, such as data about health, racial or ethnic origin, religious belief, political opinion, union membership, genetic data, biometric data, sexual life or other data classified as sensitive under the LGPD.
The user should avoid sending sensitive data in free-form fields in forms, messages, WhatsApp or emails, unless such information is strictly necessary for the requested service. If sensitive data is sent spontaneously, Certifee may process it only to the extent necessary to analyze, respond, discard, protect rights or comply with applicable obligations.
Purposes of processing
Certifee may process personal data for the following purposes:
- to enable browsing and website operation;
- to respond to contacts, questions, requests and messages sent by the user;
- to send requested information about courses, training, consulting, audits, programs, protocols and services;
- to organize, qualify and respond to commercial or quote requests;
- to process purchases, registrations, payments, orders and confirmations related to open-enrollment courses;
- to enable buyer registration, cart, checkout, payment, confirmation and basic order lookup;
- to provide support before, during and after a purchase, registration or request;
- to maintain relationship records and history necessary to continue service;
- to send operational, institutional or commercial communications, when appropriate;
- to promote courses, training, content, events, services and opportunities compatible with the relationship maintained with the data subject;
- to improve website browsing, usability, performance and security;
- to perform technical SEO, access analysis, conversion measurement and assessment of digital campaigns;
- to measure interactions such as WhatsApp clicks, form submissions, course searches, checkout starts and completed purchases, when those measurements are configured;
- to protect the website against unauthorized access, fraud, incidents, abuse of features and improper use;
- to comply with legal, regulatory, tax, accounting, contractual and administrative obligations;
- to respond to requests from public authorities, when necessary;
- to exercise rights in administrative, judicial or arbitral proceedings;
- to maintain internal controls, technical records and documentation necessary for governance, security and compliance.
Legal bases
Certifee processes personal data based on the legal bases provided for in the LGPD, according to the context and purpose of the processing. The main legal bases that may be used are:
Performance of a contract or preliminary procedures
This basis may be used when processing is necessary to respond to a data subject's request, process a purchase, complete buyer registration, confirm an order, enable course registration, respond to a quote request or proceed with steps prior to contracting.
Compliance with a legal or regulatory obligation
This basis may be used when Certifee needs to retain or process data to comply with tax, accounting, regulatory, legal or administrative obligations, or legitimate requests from competent authorities.
Consent
Consent may be used in specific situations, such as the activation of certain non-essential cookies, receipt of commercial communications when required or other purposes that depend on the data subject's free, informed and unambiguous manifestation.
When processing depends on consent, the data subject may withdraw it through the channels provided, without affecting processing that was validly carried out before withdrawal.
Legitimate interest
Legitimate interest may be used for purposes compatible with the data subject's expectations and Certifee's activities, such as responding to contacts received, maintaining relationships with company representatives, improving the website, preventing fraud, ensuring security, analyzing metrics, measuring conversions, sending communications compatible with the existing relationship and protecting rights.
When applicable, Certifee seeks to assess the proportionality of the processing and adopt measures to reduce impacts on the data subject's privacy.
Regular exercise of rights
This basis may be used when processing is necessary to protect the rights of Certifee, its customers, users or third parties, including in administrative, judicial or arbitral proceedings.
Credit protection and fraud prevention, when applicable
In purchase, billing, identification, payment or prevention of improper website use operations, certain data may be processed for credit protection, fraud prevention, transaction validation, checkout security and protection of users and Certifee, according to applicable law and the flows of the providers involved.
Payments
Purchases of open-enrollment courses on the website may be processed by a payment gateway, such as PagBank, when the integration is active.
During payment, data necessary for the transaction may be processed, such as buyer identification, order data, amount, transaction status, payment method and information required for authorization, fraud prevention, confirmation, refund, billing or related support.
Certifee does not ask users to send full credit card details through contact forms, email, WhatsApp or free-form fields. Full card details and other sensitive payment information, when necessary for the transaction, must be entered and processed in the environment, components or technical flows of the payment gateway.
The payment gateway may act according to its own terms, privacy policies, security rules, regulatory requirements and anti-fraud procedures. The user should review the payment provider's policies to understand how data is processed in that environment.
Certifee may retain records related to the order, purchase confirmation, payment status, service and applicable legal, tax, accounting or contractual obligations.
International data transfer
Some technology providers used to operate the website, process payments, store data, send emails, measure audience, measure campaigns, maintain security or provide support may store or process personal data outside Brazil.
When international data transfers occur, they must take place in accordance with applicable law, contracts, terms of use, providers' privacy policies and appropriate data protection mechanisms.
Certifee seeks to use providers that adopt security and data protection practices compatible with the nature of the services provided.
Data retention and deletion
Personal data is kept for as long as necessary to fulfill the purposes described in this policy, handle requests, enable purchases, provide services, maintain operational records, comply with legal, tax, accounting, regulatory and contractual obligations, prevent fraud, strengthen security and exercise rights.
Retention periods may vary according to the data category, purpose and applicable obligations.
Contact data and requests
Data submitted through forms, WhatsApp, email or phone may be kept while necessary to respond to the request, continue the relationship, record service history, prepare proposals, handle commercial demands or protect rights.
Purchase and order data
Data related to purchases, registrations, orders, payments, confirmation, billing and support may be kept for the time necessary for contractual performance, buyer support, compliance with tax, accounting and regulatory obligations and the exercise of rights.
Marketing and communication data
Data used for commercial communications may be kept while there is an applicable legal basis, relationship with the data subject, compatible legitimate interest or valid consent, when required. The data subject may request to unsubscribe, object or change preferences.
Technical logs and security data
Technical logs, access data, event records and security information may be kept for the time necessary to protect the website, investigate incidents, prevent fraud, correct failures, preserve evidence and comply with applicable obligations.
Cookies
Cookies may have different retention periods according to their purpose and configuration. The user may delete cookies through the browser or adjust preferences in the cookie center, when available.
Administrative data
Administrative user data may be kept while access is necessary and, afterward, for the period necessary for security, auditing, accountability, incident investigation and exercise of rights.
When data is no longer necessary, Certifee may delete it, anonymize it or keep it in a restricted manner when there is a legal obligation, need to preserve rights, security, auditing, fraud prevention or another applicable legal basis.
Information security
Certifee adopts reasonable and proportional technical and organizational measures to protect personal data against unauthorized access, loss, alteration, improper disclosure, misuse or other forms of improper or unlawful processing.
These measures may include, as applicable:
- use of HTTPS and a security certificate on the website;
- access control for administrative environments;
- permission management by user profile;
- restriction of access to personal data only to authorized persons;
- use of technology providers necessary for website operation;
- technical best practices for development, hosting and operation;
- technical monitoring and failure verification, when applicable;
- protection against unauthorized access and improper use;
- technical records for security and auditing;
- incident review and adoption of corrective measures, when necessary.
Despite the measures adopted, no digital environment is absolutely immune to risks. For this reason, the user should also adopt good security practices, such as using protected devices, avoiding credential sharing, being cautious with suspicious messages and not sending sensitive information through inappropriate channels.
Data subject rights
Under the LGPD, the data subject may exercise rights related to the processing of personal data, subject to the applicable legal conditions. These rights include:
Confirmation of processing
The data subject may request confirmation as to whether Certifee processes their personal data.
Access to data
The data subject may request access to personal data processed by Certifee, subject to trade secrets, third-party information and applicable legal limits.
Correction
The data subject may request correction of incomplete, inaccurate or outdated data.
Anonymization, blocking or deletion
The data subject may request anonymization, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD, when applicable.
Portability
The data subject may request data portability to another service or product provider, subject to applicable regulation, technical feasibility and trade and industrial secrets.
Information about sharing
The data subject may request information about public and private entities with which Certifee has shared personal data, subject to applicable legal and commercial limitations.
Information about consent
When processing depends on consent, the data subject may request information about the possibility of not providing it and about the consequences of that decision.
Withdrawal of consent
When processing is based on consent, the data subject may withdraw it at any time, without affecting the validity of processing previously carried out on the basis of valid consent.
Objection to processing
The data subject may object to certain processing activities, especially when they understand that there is non-compliance with the LGPD or when processing is based on legitimate interest, subject to the applicable legal conditions.
Review of automated decisions
If decisions are made solely on the basis of automated processing of personal data and affect the data subject's interests, the data subject may request review under the LGPD. The section "Automated decisions" of this policy provides additional information about the website's current operation.
Petition to the ANPD
The data subject may file a petition with the Brazilian National Data Protection Authority, according to the channels and procedures made available by the competent authority.
How to exercise your rights
To exercise rights, the data subject should contact Certifee by email atvalesca@certifee.com.br, clearly indicating which right they wish to exercise and providing sufficient information for analysis of the request.
Certifee may request additional information to confirm the identity of the data subject or the legitimacy of the representative, in order to protect personal data against unauthorized access. Requests will be analyzed according to the LGPD, the nature of the request, available records and applicable legal obligations.
Commercial communications
Certifee may send communications by email, phone, WhatsApp or other channels provided by the data subject to:
- respond to requests made by the user;
- send information about courses, training, events, content, consulting, audits, programs, protocols and services;
- confirm registrations, purchases, orders or service requests;
- share technical content, news, insights and opportunities related to Certifee's activities;
- maintain relationships with customers, leads, buyers, company representatives and interested individuals.
Commercial communications will be sent according to the applicable legal basis, the context of the relationship and the data subject's preferences.
The data subject may request to unsubscribe, stop commercial communications, object to processing or change preferences through the mechanism provided in the communication, when available, or by email atvalesca@certifee.com.br.
Certifee may continue sending strictly operational or transactional communications, such as order confirmation, purchase information, requested support, legal obligations or notices necessary for service provision, even if the data subject chooses not to receive promotional communications.
Minors' data
Certifee's website is not directed to children. The courses, content and services are intended mainly for companies, managers, professionals, corporate buyers, students and individuals interested in technical topics related to food quality and food safety.
Certifee does not seek to intentionally collect personal data from children. Minors should use registration, purchase, enrollment or personal data submission features with the participation, knowledge or authorization of their legal guardian, when applicable.
If Certifee identifies improper processing of data from a child or adolescent, it may adopt measures to limit, delete or regularize the processing, according to applicable law and the best interests of the minor.
Third-party links and platforms
The website may contain links, buttons or integrations that direct the user to third-party platforms, such as WhatsApp, social networks, payment gateway, videos, maps, external content, partners or other digital environments.
These platforms may collect and process personal data according to their own terms of use, privacy policies, cookie policies and settings. Certifee does not fully control the privacy, security and cookie practices of these platforms.
Before using third-party services, users are advised to read the policies applicable to those environments.
Automated decisions
The website may use technical automations, browsing records, measurement tools, tags, pixels, cookies, conversion events and security mechanisms to improve the experience, measure performance, support campaigns, prevent fraud and operate features.
In the ordinary operation of the website, Certifee does not make automated decisions based exclusively on personal data that produce legal effects or relevant impacts on the data subject, unless such functionality is expressly disclosed through a dedicated channel or an update to this policy.
Updates to this policy
This Privacy Policy may be updated to reflect changes to the website, features, services, technologies used, providers, Certifee's internal practices or applicable law.
When there is a relevant update, Certifee may change the "Last updated" date and, when appropriate, provide additional notices on the website or through contact channels.
The most recent version of this policy will be available on the websitecertifee.com.br.
Contact channel
For questions, requests or exercise of rights related to privacy and personal data protection, contact Certifee through the channel below:
Privacy officer
CERTIFEE CONSULTORIA LTDA · CNPJ 07.378.424/0001-33
Last updated:
Back to top