Effective 11 August 2026 · version 3.0 · supersedes version 2.0 of 1 August 2026
GLOBALATECH LTDA., registered under Brazilian company number (CNPJ) 68.518.193/0001-00, with its registered office in Itajaí, Santa Catarina, Brazil, is the controller of the personal data described in this policy — under art. 5, VI of Brazilian Law no. 13.709/2018 (the General Data Protection Law — LGPD) and art. 4(7) of Regulation (EU) 2016/679 (the GDPR).
We are a technology company for international logistics and we build the Freight Opportunity Engine, a commercial intelligence platform for freight forwarders. The full registered address is part of the public CNPJ record, which anyone can look up at the Brazilian Federal Revenue Service using the number above.
Our data protection officer, appointed under art. 41 of the LGPD, is Wellinton Aoki, who can be reached at dpo@globalatech.cloud.
Why a separate address. dpo@globalatech.cloud exists for data protection only. contato@globalatech.cloud remains the commercial channel — applications, product questions, outreach. The separation is deliberate: a data subject request should not queue behind a sales matter, nor be read by the people handling sales.
This policy covers personal data processing carried out:
The LGPD applies to all the processing described here: we are a Brazilian company processing data in Brazil.
The GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) applies when you are in the European Union or the European Economic Area at the time the data is collected, by virtue of its art. 3(2). We say this because it is our actual situation, not as a generic precaution: the product is offered to freight forwarders in Spain, and a Spanish visitor to this site is a data subject protected by the GDPR.
Where both laws apply to the same processing, we apply whichever rule gives you more protection. That is why the response time stated in section 11 is 15 days — the LGPD deadline, shorter than the GDPR's 30 — and why it applies to everyone.
Section 13 states, with the same clarity, what we have not yet done on the GDPR side.
An important distinction. For the data your company enters inside the Freight Opportunity Engine — your customer base, your contacts, your rates — GlobalaTech acts as a processor, handling it only on your company's instructions; your company is the controller of that data. It is not used for any purpose of our own and it does not train third-party artificial intelligence models.
When you complete the application form, we collect exactly the fields below, because they are what the assessment requires:
The CNPJ or tax ID is mandatory for a specific reason: it is the key that prevents the same company from taking two seats at once and that underpins the program's referral rules.
The server that delivers the pages writes an access log, the standard record kept by any web server. Each line contains the source IP address, the date and time, the address of the page requested (including URL parameters, where present), the browser identification (user agent), the page you came from (referrer), the response code and how long we took to respond.
That log is written on our own server and kept for 180 days, as section 8 sets out. It serves security, fault diagnosis and the audience measurement described next.
Two servers, the same record. The pages of this site are delivered by one server; the application form is submitted to another, which hosts our administrative application (api.admin.globalatech.cloud). Both write the access log described above, with the same fields and the same 180-day retention. We state this explicitly because the address in your browser bar does not change when you submit the application — and, without this line, you would have no way of knowing that a second server was involved.
None of this passes through your device. The log is written on the server from the request your browser already has to make in order to receive the page. There is no cookie, pixel, third-party script or identifier stored on your device to produce it.
From the access log we produce aggregated audience statistics. The result is a count per day × page × country × device type, with the number of page views, errors, average response time and, where present, the source domain and campaign parameters.
What underpins this processing is how your IP is used:
The end product does not identify anyone: it contains “42 views of the pricing page from Spain on 10 August”, and it does not contain you.
To be honest about what the number is worth: the visitor count is an approximation computed within a single day and then discarded — it is not a count of unique people, and it does not recognise you from one day to the next. We also separate automated traffic (search engine crawlers and the like) into its own category, because without that the number would be fiction.
What we do not do, and could not do with this design: behavioural profiling, journeys across visits, time on page, scroll tracking, behavioural advertising, selling data, and any cross-referencing that links browsing to an identified person.
Transparency about the current state. The log described in 3.2 is already collected and retained. The routine that produces the aggregate is still being implemented; until it goes live, the log is used only for security and diagnostics. We are publishing this section ahead of that by choice: we would rather the policy describe the processing before it exists than have the site claim one thing while the system does another.
For users of the contracted platform, we process account data (name, work email, job title, access profile) and access and activity records, necessary for operation, auditing and support.
During the Founding Customer Program we also collect strictly aggregated usage telemetry per participating company — for example, the number of active users and the volume of activity in the period. This telemetry exists to assess the program's credit rules objectively. No customer name, rate, lane or contact from your operation is transmitted in these aggregates. The categories collected are listed in the program agreement.
When we contact a professional in the industry on our own initiative, we process name, job title, company and work email, obtained from public professional sources. The message always identifies who we are and how to ask us to stop — simply reply asking, or write to the channel in section 11, and the contact ends without your having to give a reason.
Each processing activity has a defined purpose and a corresponding legal basis. The LGPD column follows its arts. 7 and 11; the GDPR column follows its art. 6, and applies to you only under the conditions in section 2.1.
| Purpose | Data | Legal basis — LGPD | Legal basis — GDPR |
|---|---|---|---|
| Deliver the pages of the site | IP, user agent, page address | Legitimate interest (art. 7, IX) | Art. 6(1)(f) |
| Security and fault diagnosis | Access log | Legitimate interest (art. 7, IX) | Art. 6(1)(f) |
| Measure audience in aggregate form | Counts per day, page, country and device | Legitimate interest (art. 7, IX) | Art. 6(1)(f) |
| Assess the application and run the selection process | All form fields | Consent (art. 7, I) and preliminary procedures related to a contract (art. 7, V) | Art. 6(1)(a) and (b) |
| Communicate the decision and run activation | Contact person details | Preliminary procedures and performance of a contract (art. 7, V) | Art. 6(1)(b) |
| Prevent fraud and abuse of the form | CNPJ/tax ID, IP, user agent | Legitimate interest (art. 7, IX) | Art. 6(1)(f) |
| Commercial outreach on our initiative | Name, job title, company, work email | Legitimate interest (art. 7, IX), with a right to object | Art. 6(1)(f), with a right to object (art. 21(2)) |
| Operate, maintain and support the platform | Account data and access records | Performance of a contract (art. 7, V) | Art. 6(1)(b) |
| Assess program credits and referrals | Aggregated usage telemetry | Performance of a contract (art. 7, V) | Art. 6(1)(b) |
| Platform access logs | Platform access logs | Compliance with a legal obligation (art. 7, II, together with the Brazilian Internet Civil Framework) | Art. 6(1)(c) |
| Defence in judicial, administrative or arbitral proceedings | As necessary | Regular exercise of rights (art. 7, VI) | Art. 6(1)(f) |
Where processing relies on consent — today, the application — you may withdraw it at any time, free of charge, through the channel in section 11. Withdrawal does not affect the lawfulness of processing carried out beforehand, and it may mean the application cannot proceed.
Where processing relies on legitimate interest, you may object to it, also through the channel in section 11. We assess every objection and, where no overriding grounds exist, the processing stops.
This website does not use cookies. We set no first-party or third-party cookies, and there are no analytics, advertising or cross-site tracking cookies. That is why there is no consent banner: there is nothing to consent to. The requirement for prior consent arises from reading or writing information on your device — and the measurement described in 3.3 writes nothing on your device, because it happens entirely on the server side.
The site uses two browser local storage keys, strictly functional, which never leave your device and do not identify anyone:
| Key | Type | What it does | Duration |
|---|---|---|---|
| Opening animation | sessionStorage | Show the brand animation only once per session, rather than on every page | Until you close the tab |
| WhatsApp button | localStorage | Highlight the contact button only on the first visit | Until you clear your browser data |
You can delete both at any time through your browser settings, with no impact on how the site works.
No page on this site loads a third-party resource. Typefaces, icons and images are all served from our own domain. Up to the previous version of this policy the typefaces were loaded from Google's servers, which sent your IP address to that company on every page you opened; that dependency has been removed in the same revision that published this text.
We do not sell personal data and we do not release it for third-party advertising. We share data only with providers acting as processors, following our instructions and under contractual confidentiality and security obligations. These are they, by name:
| Processor | What for | Data involved | Where processed |
|---|---|---|---|
| Hostinger | Infrastructure: the server that delivers the website and runs our application | The website access log and the data passing through the application | Brazil |
| Resend | Sending transactional email (application confirmation, decision, deadline reminders) | Recipient name and email and message content | United States |
| Supabase | Database of the contracted platform and authentication of its users | The platform data at rest, the account identifier and the access credential | United States |
| Stripe | Payment processing, where activation or subscription charges apply | Billing and payment data, handled directly by Stripe | United States |
On Stripe, transparently: the gateway has been selected, but the billing integration is not yet in operation at this stage of the program. Until it is, none of your data passes through it. Card data is never stored on our servers — when billing goes live, it will be handled directly by the gateway.
We may also share data with public authorities where there is a legal request, court order or regulatory obligation, and with legal and accounting advisers where necessary for the regular exercise of rights.
This list is kept current. If a processor joins or leaves, it changes — and section 14 explains how you find out.
The server that delivers this site and runs our application is in Brazil — and with it the access log of section 3.2, which does not leave the country. The other services in the table in section 6 process data in the United States, and that constitutes international transfer: Supabase (database and authentication of the contracted platform), Resend (transactional email) and Stripe (payment, where applicable).
The grounds for those transfers: under the LGPD, the necessity of performing a contract and preliminary procedures (art. 33, V and VI); under the GDPR, the transfer instruments each of those suppliers makes available in their respective data processing terms.
One transfer has ceased to exist. Up to version 2.0 of this policy, the typefaces were loaded from Google's servers, which sent every visitor's IP address to that company on every page — the most frequent transfer the site made, and for typographic convenience alone. The typefaces are now served from our own domain. The processing was eliminated, not merely disclosed.
The two logs below are different things with different retention periods — the distinction matters, and the previous version of this policy did not draw it:
| Data | Retention period |
|---|---|
| Website and application-API access log (section 3.2) | 180 days from each line written, discarded automatically by the server itself. Art. 15 of the Brazilian Internet Civil Framework requires retention for at least 6 months; 180 days meets that floor without extending it. The durable record began on 9 August 2026 for the website and on 19 August 2026 for the application API; before those dates there is no history to provide. |
| Aggregated audience statistics (section 3.3) | Indefinitely. This is data that is anonymised by construction — it relates to no identified or identifiable person — and therefore ceases to be personal data (art. 12 of the LGPD; recital 26 of the GDPR). |
| Access logs of the contracted platform | 6 months, under art. 15 of the Brazilian Internet Civil Framework. |
| Unsuccessful application | Up to 24 months after the decision, to allow reassessment in later cohorts and to evidence the fairness of the selection process. It may be deleted earlier at the data subject's request. |
| Successful application and program history | For the duration of the contractual relationship and for 5 years after it ends, in line with applicable limitation periods. |
| Credit, referral and billing records | 5 years after termination, as required by tax and accounting rules. |
| Commercial outreach contact | Until you object. Where you ask us to stop, we keep only the minimum needed to avoid contacting you again. |
| Aggregated platform usage telemetry | During the program and for 12 months after it ends. |
Once the period ends, data is deleted or anonymised, save for the mandatory retention grounds in art. 16 of the LGPD.
The decision history of the application funnel is kept immutable for audit integrity: it records who decided what, and when. An application may be declined or closed, but the record of the decision is not erased. If you exercise the right to deletion, personal data is removed or anonymised and the remaining record no longer identifies you.
We apply technical and administrative measures appropriate to the nature of the data processed, including: TLS-encrypted traffic on all pages and API calls; passwords stored using a hash function; two-factor authentication on the administrative panel; per-company data isolation on the platform; access control by role and branch; rate limiting on public forms; and daily database backups.
No system is absolutely secure. In the event of a security incident that may create relevant risk or harm, we will notify affected data subjects and the Brazilian National Data Protection Authority, under art. 48 of the LGPD. Where the incident affects a data subject in the European Union, notification to the supervisory authority follows the 72-hour deadline in art. 33 of the GDPR.
In the interest of honesty: as of this date we do not hold ISO 27001 certification, a SOC 2 report or an independent third-party security audit. We describe above what we actually do, and we do not claim seals we do not have.
At any time and free of charge, you have the right to:
You may also lodge a complaint with an authority:
Lodging a complaint does not depend on speaking to us first. We would rather resolve it directly, but the right is yours and does not require our agreement.
Write to dpo@globalatech.cloud. No form and no set wording is needed: just describe what you want.
We respond within 15 days. That is the deadline in art. 19, II of the LGPD, shorter than the one in art. 12(3) of the GDPR, and we apply it to every request, wherever it comes from.
We may request additional information to confirm your identity before acting on the request — this protects you, so that nobody can obtain or delete your data by impersonating you. There is no charge.
The website and the platform are intended exclusively for professionals acting in the course of business. We do not direct our services to anyone under 18 and we do not knowingly collect data from children or adolescents. Where such processing is identified, the data will be deleted.
This section exists because the alternative would be for you to find out on your own. We are an early-stage company, and there are data protection instruments we do not yet have. None of them prevents you from using the site; some matter if you are a European customer assessing a supplier.
| What does not exist today | Why it may matter to you |
|---|---|
| A Data Processing Agreement (DPA) of our own | This is the document a European customer usually asks for in due diligence, governing processing between controller and processor. A privacy policy is not a substitute: they are different documents, with different parties and different obligations. We will enter into one on request. |
| Representative in the European Union (art. 27 GDPR) | The GDPR requires the formal designation of an EU representative by a controller established outside the EU that offers goods or services to data subjects in the EU, subject to exceptions. It is a formal act, not website text, and it has not been done. |
| Record of processing activities (art. 30 GDPR; art. 37 LGPD) | An internal document, not for publication, which an authority may demand. It has not been formalised. |
| Data protection impact assessment (DPIA) | May be required depending on the processing. The processing described here involves no profiling, no automated decision with legal effect and no sensitive data, but the formal assessment has not been carried out. |
| Compliance with specific Spanish-American laws | Mexico, Argentina, Colombia and Chile have their own data protection laws. This policy addresses the LGPD and the GDPR; the others will be handled case by case. |
When this changes: the first three items will be resolved before the first European customer, or at the first due diligence that asks for a DPA — whichever comes first. Until then, we would rather say we do not have them than claim we do.
This policy may be revised to reflect changes in the service or in legislation. The effective date at the top of the page indicates the current version. Material changes that broaden the processing of personal data will be communicated by email to affected data subjects before they take effect.
GLOBALATECH LTDA. · CNPJ 68.518.193/0001-00 · Itajaí, Santa Catarina, Brazil · Data Protection Officer: Wellinton Aoki — dpo@globalatech.cloud