1. Who is responsible
SANTOS E BARROSO LTDA, trading as Nauas Tech Tecnologia, at Rua Rio de Janeiro, Sala 08, Bairro 25 de Agosto, Cruzeiro do Sul — Acre, Brazil. Contact: consultoria@nauastech.com.br, +55 68 99203-3128.
Under the LGPD we are the controller of data belonging to our own customers, suppliers and job applicants — we decide why and how it is processed. We are a processor when we handle data on a customer's instructions: when we host their management system, or service the cameras in their building. In that second case the customer decides and we follow. The distinction matters, because it decides who answers for what. (Controller and processor map to the same terms in the GDPR.)
2. What we process, and why
Every item below exists for a working reason. We do not collect data "in case we need it later" — data kept without a purpose is nothing but stored risk.
| Context | Data | Purpose | Legal basis (LGPD) |
|---|---|---|---|
| Quote requested on the website or WhatsApp | Name, phone, e-mail, service address, what you need | Prepare the proposal and schedule the site survey | Pre-contractual steps |
| Customer under contract | Company or personal name, tax ID, address, contacts, billing details | Perform the contract, issue invoices, collect payment | Performance of a contract; legal obligation (tax) |
| Work order | Site address, technical notes, photographs of the site and equipment, date and time, signature on delivery | Evidence of the work performed, and the ability to check it later | Performance of a contract; legitimate interests |
| Client Portal | Tax ID or e-mail, password (hashed), access log | Give access to the company's own service history and invoices | Performance of a contract |
| Website | Pages visited and technical access data | Keep the site running and understand what people look for | Legitimate interests |
| Job applications | Whatever the applicant sends | Recruitment | Pre-contractual steps |
What we do not do: we do not sell personal data, we do not rent contact lists, we do not use one customer's records to market to another, and we do not process children's data — our services are addressed to businesses and to adults responsible for a property.
3. Camera footage: the sensitive part
An image of an identifiable person is personal data. That is as true of the camera in your shop as of the one in a public building — and it is where most suppliers get it wrong.
Footage on the customer's system
Recordings made by the system installed at your premises are yours. The recorder is yours, the footage is yours, and the controller of that data is your organisation — not Nauas Tech. We enter that system only when you ask us to: to install, adjust or repair. When we do:
- we access the minimum needed to resolve the ticket;
- we do not copy, export or retain your footage, unless you request it in writing and for a purpose you define;
- we change the factory password on handover and log the technical access in the work order;
- our staff sign confidentiality undertakings.
What we advise you to do
- Post a notice. A visible sign stating that the premises are monitored.
- Do not point cameras where they must not point — toilets, changing rooms, inside a neighbour's home, or further into the public street than necessary.
- Decide how many days footage is kept. That should be your decision, not a by-product of disk size.
- Control who can watch. A named user per person, not one password the whole department knows.
4. How long we keep data
| Data | Retention | Why |
|---|---|---|
| Quote that did not become a contract | 2 years | Resume the conversation; compare prices charged |
| Customer records and tax documents | 5 years after the relationship ends | Brazilian tax law and Consumer Protection Code periods |
| Work orders and site photographs | 5 years | Service warranty and proof of what was done |
| System access logs | 6 months minimum | Article 15 of the Brazilian Internet Civil Framework |
| Unsuccessful job applications | 1 year | Future vacancy — deleted afterwards |
Once the period ends, data is deleted or anonymised. The exception is data the law requires us to keep longer, or that is needed to exercise rights in legal proceedings — and in that case it is kept for that purpose only.
5. Who we share data with
- Our accountants — tax data, as a legal obligation.
- Public authorities — where the law requires it (tax authority, inspection, court order).
- Technology providers that run our systems (hosting, messaging, digital certification), always limited to what they need to deliver the service.
- Manufacturers, when equipment goes to warranty and the purchase must be identified.
Our servers are in Brazil. Some supporting services (such as message delivery) may process data abroad; where that happens we require safeguards compatible with the LGPD.
6. Your rights
Under the LGPD you may, at any time:
- confirm whether we process your data and obtain a copy of it;
- correct data that is wrong or incomplete;
- request anonymisation, blocking or deletion of unnecessary or excessive data;
- request portability to another supplier;
- be told who we shared it with;
- withdraw consent, where processing relies on it;
- object to processing you consider improper.
How to ask: write to consultoria@nauastech.com.br with the subject “LGPD — data subject request”, or message +55 68 99203-3128. We answer within 15 days. We will verify your identity before releasing any data — answering quickly to someone who is not the data subject would be the opposite of protecting it.
If your request concerns footage or data held inside a customer's own system, we will refer you to the correct controller and notify them — in that case we are a processor, and we cannot decide about data that is not ours.
7. How we protect it
- Named user accounts, with permissions per screen and per function — nobody sees what they do not need in order to work.
- Access logging: who signed in, when, and what they looked at.
- Passwords stored hashed; device biometrics as a second factor where available.
- HTTPS with TLS 1.2 and 1.3 only; TLS 1.0 and 1.1 disabled.
- Encrypted daily backups, with a rotation routine.
- All access revoked the same day someone leaves the team.
- Confidentiality undertakings signed by anyone with access to customer data.
None of this removes risk entirely — any supplier who promises that is not being straight with you. If an incident occurs with relevant risk, we notify the affected data subjects and the Brazilian data protection authority (ANPD), stating what happened, what has already been done and what we recommend.
8. Cookies
Our website uses the minimum: what is needed for it to work, and to remember your session when you sign in to the Client Area. We do not use advertising cookies or cross-site tracking. You may block cookies in your browser; the Client Area, however, needs the session cookie to know it is you.
9. Changes to this policy
When something material changes, the date at the top changes and the previous text is retained. Changes affecting your rights are communicated to active customers — changing quietly and claiming it was published is not acceptable.
10. Data protection contact
The channel for data protection matters is consultoria@nauastech.com.br, handled by the company's management, which performs the role of data protection officer before data subjects and the ANPD.
You may also complain directly to the ANPD — Autoridade Nacional de Proteção de Dados (gov.br/anpd). We would rather resolve it here, but that right is yours and does not depend on speaking to us first.
Rua Rio de Janeiro, Sala 08 — Bairro 25 de Agosto, Cruzeiro do Sul/AC, Brazil
consultoria@nauastech.com.br · +55 68 99203-3128
Version 1.0 — in force since 5 September 2026. Related: Compliance Policy and Code of Conduct · Warranty Policy (PT).