Data controller
Kasnol Consultoria em Tecnologia da Informação LTDA, registered under CNPJ no. 66.958.891/0001-00, headquartered in Valinhos/SP, Brazil, is the controller of the personal data collected through this website (kasnol.com.br) and its associated channels (email, WhatsApp and contact forms).
For the purposes of the GDPR, Kasnol acts as data controller in relation to the data processed in the activities described in this policy.
Definitions
To make this document easier to read, we adopt the following definitions, aligned with applicable law:
- Personal data
- Any information relating to an identified or identifiable natural person.
- Sensitive personal data
- Data on racial or ethnic origin, religious belief, political opinion, health, sex life, genetic or biometric data, among others.
- Data subject
- The natural person to whom the processed personal data relates.
- Processing
- Any operation with personal data — collection, use, storage, sharing, deletion, among others.
- Controller
- The party that decides on the purposes and means of processing personal data.
- Processor
- The party that processes personal data on behalf of and according to the controller's instructions.
- ANPD
- The Brazilian National Data Protection Authority, the competent authority in Brazil.
Scope and Kasnol's roles
This policy applies to visitors of the Kasnol website and to anyone who contacts us through our channels, whether data subjects in Brazil (LGPD) or in the European Economic Area (GDPR).
It is important to distinguish two distinct roles that Kasnol performs:
- As controller — in relation to the data of this website and the business-relationship, marketing and support activities described in this policy, Kasnol defines the purposes and means of processing.
- As processor — in delivering consulting, governance and PMO projects, Kasnol may process personal data on behalf of its clients, following the instructions and purposes they define. Such processing is governed by the respective services agreement and/or data processing agreement, not by this policy.
Data we collect
We collect the minimum data necessary for the purposes of this policy:
- Data you provide — when filling in the contact form or writing to us: name, company/role, email, phone (optional) and the message content.
- Technical and browsing data — collected automatically for the operation and security of the site, such as IP address, session identifiers, device and browser type, and access logs.
- Communication data — the history of interactions you initiate with us via email, WhatsApp or LinkedIn.
We do not intentionally collect sensitive personal data. Please do not include information of that nature in free-text fields.
Purposes and legal bases
Each processing of personal data has a specific purpose and a legal basis underpinning it, as set out in the table below:
| Purpose | Legal basis (LGPD) | Legal basis (GDPR) |
|---|---|---|
| Respond to your contact and conduct commercial discussions | Pre-contractual procedures at the data subject's requestArt. 7, V | Pre-contractual measuresArt. 6(1)(b) |
| Assess feasibility and send related commercial proposals | Legitimate interestArt. 7, IX | Legitimate interestsArt. 6(1)(f) |
| Operate, maintain and protect the site against fraud and abuse | Legitimate interestArt. 7, IX | Legitimate interestsArt. 6(1)(f) |
| Comply with legal, tax and regulatory obligations | Compliance with a legal obligationArt. 7, II | Legal obligationArt. 6(1)(c) |
| Exercise rights in judicial, administrative or arbitration proceedings | Regular exercise of rightsArt. 7, VI | Legitimate interestsArt. 6(1)(f) |
| Send unsolicited marketing communications (where applicable) | ConsentArt. 7, I | ConsentArt. 6(1)(a) |
Where processing relies on legitimate interest, we first carry out an assessment that balances that interest against your rights and expectations. You may request information about this assessment through the channels in section 13.
Cookies and tracking technologies
This site currently uses only strictly necessary storage — language and theme preferences and session identifiers for security and operation. These resources do not require consent, as they are indispensable to providing the service you request.
We do not use tracking, advertising or behavioral profiling cookies.
Should we adopt analytics or marketing tools that are not strictly necessary in the future, we will display a cookie notice to obtain your prior consent and update this policy. You can also manage and block cookies in your browser settings.
Data sharing
We do not sell personal data. Sharing only occurs when necessary and with the following categories of recipients:
- Processors — suppliers that process data on our behalf and under our instructions, such as email and productivity providers, hosting and infrastructure, databases and communication tools, always under contractual obligations of confidentiality and security.
- Business partners — when strictly related to a service you engage, and under contractual instruments ensuring data protection.
- Authorities — when required by law, regulation or order of a competent authority.
International data transfers
Some of our processors may process data on servers located outside Brazil or the European Economic Area. When this happens, we ensure the transfer is supported by an adequate legal mechanism:
- Under the LGPD — through the bases of art. 33, in particular the adoption of the standard contractual clauses approved by the ANPD (Resolution CD/ANPD no. 19/2024) or an adequacy decision, where recognized.
- Under the GDPR — through an adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses (art. 46).
We require such suppliers to provide a level of protection equivalent to that established in applicable law. Contracts with suppliers located abroad already incorporate the applicable standard contractual clauses.
Retention and disposal
We keep personal data only for as long as necessary to fulfill the purposes and applicable legal obligations, observing the following indicative criteria:
| Category | Retention period |
|---|---|
| Contacts with no commercial follow-up | Up to 5 years after the last contact, unless there is new interaction |
| Commercial and contractual relationship | During the relationship and for applicable legal and limitation periods (as a rule, 5 years) |
| Access logs | For the period required by law and by technical security needs |
| Tax and regulatory obligations | For the specific statutory retention periods |
Once the period ends, data is deleted or anonymized, except where there is a legal duty of retention.
Data subject rights
At any time, and free of charge, you may exercise the following rights:
- Confirmation and access — to know whether we process your data and to access itLGPD 18, I–IIGDPR 15
- Correction — to update incomplete, inaccurate or outdated dataLGPD 18, IIIGDPR 16
- Anonymization, blocking or deletion — of unnecessary, excessive or non-compliant dataLGPD 18, IVGDPR 17–18
- Deletion of data processed under consentLGPD 18, VIGDPR 17
- Portability — to receive your data in a structured format or transmit it to another providerLGPD 18, VGDPR 20
- Information on sharing — to know with which entities we share your dataLGPD 18, VII
- Withdrawal of consent — where processing is based on itLGPD 18, IXGDPR 7(3)
- Objection — to object to processing based on legitimate interestLGPD 18, §2GDPR 21
- Review of automated decisionsLGPD 20GDPR 22
- Complaint to the authority — to the ANPD in Brazil, or the competent supervisory authority in the EUGDPR 77
Kasnol does not make solely automated decisions that produce legal effects or significantly impact data subjects.
To exercise your rights, use the channels in section 13. We may request information to confirm your identity. We will respond as quickly as possible — for confirmation and access, immediately in a simplified format or within 15 days in full form (LGPD); under the GDPR, without undue delay and within 1 month, extendable depending on complexity.
Information security
We adopt technical and organizational measures proportional to the risks to protect data against unauthorized access, loss, alteration or improper disclosure, including:
- Encryption in transit (TLS) and access controls based on the principle of least privilege;
- Environment segregation, audit logs and monitoring;
- Privacy by design and by default in the conception of processes and systems;
- Security and confidentiality assessment of suppliers.
No method of transmission or storage is entirely secure; we work continuously to mitigate risks and improve our controls.
Security incidents
In the event of a security incident that may pose relevant risk or harm to data subjects, we will notify the ANPD and the affected data subjects within the legal period — as a rule, 3 business days from awareness of the incident in Brazil; under the GDPR, notification to the authority occurs within 72 hours. We will adopt mitigation measures and keep a record of incidents.
Data Protection Officer (DPO) and support channel
To exercise rights, clarify questions or report incidents relating to personal data, use the channel below. We will respond within the periods set by applicable law.
Data Protection Officer
Point of contact between you, Kasnol and the ANPD.
Updates to this policy
This policy may be updated to reflect legal, regulatory or practice changes. The current version is always the one published on this page, with the effective date shown at the top. Material changes will be flagged prominently.
Version 1.0 — effective since 2026-05-25.