globalatech
Product Why we exist Founding Program
Apply
  • Português
  • English
  • Español
GlobalaTech

Privacy Policy

Effective 11 August 2026 · version 3.0 · supersedes version 2.0 of 1 August 2026

  1. Who processes your data
  2. What this policy covers, and under which laws
  3. Data we collect
  4. Purposes and legal bases
  5. Cookies and local storage
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. Security
  10. Your rights as a data subject
  11. How to exercise your rights
  12. Children and adolescents
  13. What this policy does not yet cover
  14. Changes to this policy

1. Who processes your data

GLOBALATECH LTDA., registered under Brazilian company number (CNPJ) 68.518.193/0001-00, with its registered office in Itajaí, Santa Catarina, Brazil, is the controller of the personal data described in this policy — under art. 5, VI of Brazilian Law no. 13.709/2018 (the General Data Protection Law — LGPD) and art. 4(7) of Regulation (EU) 2016/679 (the GDPR).

We are a technology company for international logistics and we build the Freight Opportunity Engine, a commercial intelligence platform for freight forwarders. The full registered address is part of the public CNPJ record, which anyone can look up at the Brazilian Federal Revenue Service using the number above.

Data Protection Officer (DPO)

Our data protection officer, appointed under art. 41 of the LGPD, is Wellinton Aoki, who can be reached at dpo@globalatech.cloud.

Why a separate address. dpo@globalatech.cloud exists for data protection only. contato@globalatech.cloud remains the commercial channel — applications, product questions, outreach. The separation is deliberate: a data subject request should not queue behind a sales matter, nor be read by the people handling sales.

2. What this policy covers, and under which laws

This policy covers personal data processing carried out:

  • on the www.globalatech.cloud website, including the Founding Customer Program application form;
  • in assessing applications and running the Founding Customer Program selection process;
  • in the commercial outreach we send to professionals in the industry;
  • in providing the Freight Opportunity Engine to contracting companies.

2.1 Two laws, and when each one applies

The LGPD applies to all the processing described here: we are a Brazilian company processing data in Brazil.

The GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) applies when you are in the European Union or the European Economic Area at the time the data is collected, by virtue of its art. 3(2). We say this because it is our actual situation, not as a generic precaution: the product is offered to freight forwarders in Spain, and a Spanish visitor to this site is a data subject protected by the GDPR.

Where both laws apply to the same processing, we apply whichever rule gives you more protection. That is why the response time stated in section 11 is 15 days — the LGPD deadline, shorter than the GDPR's 30 — and why it applies to everyone.

Section 13 states, with the same clarity, what we have not yet done on the GDPR side.

An important distinction. For the data your company enters inside the Freight Opportunity Engine — your customer base, your contacts, your rates — GlobalaTech acts as a processor, handling it only on your company's instructions; your company is the controller of that data. It is not used for any purpose of our own and it does not train third-party artificial intelligence models.

3. Data we collect

3.1 Founding Customer Program application

When you complete the application form, we collect exactly the fields below, because they are what the assessment requires:

  • Company identification: legal company name, CNPJ (Brazil) or national tax ID (other countries), country, city and, if provided, website.
  • Contact person: full name, job title, work email and WhatsApp number.
  • Declared operational data: number of salespeople, modes operated, main trade lanes, CRM or spreadsheet currently in use, and the free-text answer about your motivation to take part.
  • Referral code, where the application comes through a founding customer.
  • Technical record of the submission: IP address and browser identification (user agent) at the time of sending. We keep these two items for security — they are what allows us to detect automated submission and abuse of the form.
  • Record of consent: the acceptance given in the form, with date and time.

The CNPJ or tax ID is mandatory for a specific reason: it is the key that prevents the same company from taking two seats at once and that underpins the program's referral rules.

3.2 Website browsing — the access log

The server that delivers the pages writes an access log, the standard record kept by any web server. Each line contains the source IP address, the date and time, the address of the page requested (including URL parameters, where present), the browser identification (user agent), the page you came from (referrer), the response code and how long we took to respond.

That log is written on our own server and kept for 180 days, as section 8 sets out. It serves security, fault diagnosis and the audience measurement described next.

Two servers, the same record. The pages of this site are delivered by one server; the application form is submitted to another, which hosts our administrative application (api.admin.globalatech.cloud). Both write the access log described above, with the same fields and the same 180-day retention. We state this explicitly because the address in your browser bar does not change when you submit the application — and, without this line, you would have no way of knowing that a second server was involved.

None of this passes through your device. The log is written on the server from the request your browser already has to make in order to receive the page. There is no cookie, pixel, third-party script or identifier stored on your device to produce it.

3.3 Audience measurement — what we do, and what deliberately cannot be known

From the access log we produce aggregated audience statistics. The result is a count per day × page × country × device type, with the number of page views, errors, average response time and, where present, the source domain and campaign parameters.

What underpins this processing is how your IP is used:

  1. the routine reads the log line;
  2. it resolves the IP to a country, in memory, using a geolocation database installed on our own server;
  3. it adds the visit to the corresponding bucket;
  4. it discards the IP. The IP does not reach the database, does not reach any intermediate file, and does not appear in any log of that routine.

The end product does not identify anyone: it contains “42 views of the pricing page from Spain on 10 August”, and it does not contain you.

To be honest about what the number is worth: the visitor count is an approximation computed within a single day and then discarded — it is not a count of unique people, and it does not recognise you from one day to the next. We also separate automated traffic (search engine crawlers and the like) into its own category, because without that the number would be fiction.

What we do not do, and could not do with this design: behavioural profiling, journeys across visits, time on page, scroll tracking, behavioural advertising, selling data, and any cross-referencing that links browsing to an identified person.

Transparency about the current state. The log described in 3.2 is already collected and retained. The routine that produces the aggregate is still being implemented; until it goes live, the log is used only for security and diagnostics. We are publishing this section ahead of that by choice: we would rather the policy describe the processing before it exists than have the site claim one thing while the system does another.

3.4 Use of the Freight Opportunity Engine

For users of the contracted platform, we process account data (name, work email, job title, access profile) and access and activity records, necessary for operation, auditing and support.

During the Founding Customer Program we also collect strictly aggregated usage telemetry per participating company — for example, the number of active users and the volume of activity in the period. This telemetry exists to assess the program's credit rules objectively. No customer name, rate, lane or contact from your operation is transmitted in these aggregates. The categories collected are listed in the program agreement.

3.5 Commercial outreach we initiate

When we contact a professional in the industry on our own initiative, we process name, job title, company and work email, obtained from public professional sources. The message always identifies who we are and how to ask us to stop — simply reply asking, or write to the channel in section 11, and the contact ends without your having to give a reason.

4. Purposes and legal bases

Each processing activity has a defined purpose and a corresponding legal basis. The LGPD column follows its arts. 7 and 11; the GDPR column follows its art. 6, and applies to you only under the conditions in section 2.1.

PurposeDataLegal basis — LGPDLegal basis — GDPR
Deliver the pages of the siteIP, user agent, page addressLegitimate interest (art. 7, IX)Art. 6(1)(f)
Security and fault diagnosisAccess logLegitimate interest (art. 7, IX)Art. 6(1)(f)
Measure audience in aggregate formCounts per day, page, country and deviceLegitimate interest (art. 7, IX)Art. 6(1)(f)
Assess the application and run the selection processAll form fieldsConsent (art. 7, I) and preliminary procedures related to a contract (art. 7, V)Art. 6(1)(a) and (b)
Communicate the decision and run activationContact person detailsPreliminary procedures and performance of a contract (art. 7, V)Art. 6(1)(b)
Prevent fraud and abuse of the formCNPJ/tax ID, IP, user agentLegitimate interest (art. 7, IX)Art. 6(1)(f)
Commercial outreach on our initiativeName, job title, company, work emailLegitimate interest (art. 7, IX), with a right to objectArt. 6(1)(f), with a right to object (art. 21(2))
Operate, maintain and support the platformAccount data and access recordsPerformance of a contract (art. 7, V)Art. 6(1)(b)
Assess program credits and referralsAggregated usage telemetryPerformance of a contract (art. 7, V)Art. 6(1)(b)
Platform access logsPlatform access logsCompliance with a legal obligation (art. 7, II, together with the Brazilian Internet Civil Framework)Art. 6(1)(c)
Defence in judicial, administrative or arbitral proceedingsAs necessaryRegular exercise of rights (art. 7, VI)Art. 6(1)(f)

Where processing relies on consent — today, the application — you may withdraw it at any time, free of charge, through the channel in section 11. Withdrawal does not affect the lawfulness of processing carried out beforehand, and it may mean the application cannot proceed.

Where processing relies on legitimate interest, you may object to it, also through the channel in section 11. We assess every objection and, where no overriding grounds exist, the processing stops.

5. Cookies and local storage

This website does not use cookies. We set no first-party or third-party cookies, and there are no analytics, advertising or cross-site tracking cookies. That is why there is no consent banner: there is nothing to consent to. The requirement for prior consent arises from reading or writing information on your device — and the measurement described in 3.3 writes nothing on your device, because it happens entirely on the server side.

The site uses two browser local storage keys, strictly functional, which never leave your device and do not identify anyone:

KeyTypeWhat it doesDuration
Opening animationsessionStorageShow the brand animation only once per session, rather than on every pageUntil you close the tab
WhatsApp buttonlocalStorageHighlight the contact button only on the first visitUntil you clear your browser data

You can delete both at any time through your browser settings, with no impact on how the site works.

No page on this site loads a third-party resource. Typefaces, icons and images are all served from our own domain. Up to the previous version of this policy the typefaces were loaded from Google's servers, which sent your IP address to that company on every page you opened; that dependency has been removed in the same revision that published this text.

6. Who we share data with

We do not sell personal data and we do not release it for third-party advertising. We share data only with providers acting as processors, following our instructions and under contractual confidentiality and security obligations. These are they, by name:

ProcessorWhat forData involvedWhere processed
HostingerInfrastructure: the server that delivers the website and runs our applicationThe website access log and the data passing through the applicationBrazil
ResendSending transactional email (application confirmation, decision, deadline reminders)Recipient name and email and message contentUnited States
SupabaseDatabase of the contracted platform and authentication of its usersThe platform data at rest, the account identifier and the access credentialUnited States
StripePayment processing, where activation or subscription charges applyBilling and payment data, handled directly by StripeUnited States

On Stripe, transparently: the gateway has been selected, but the billing integration is not yet in operation at this stage of the program. Until it is, none of your data passes through it. Card data is never stored on our servers — when billing goes live, it will be handled directly by the gateway.

We may also share data with public authorities where there is a legal request, court order or regulatory obligation, and with legal and accounting advisers where necessary for the regular exercise of rights.

This list is kept current. If a processor joins or leaves, it changes — and section 14 explains how you find out.

7. International transfers

The server that delivers this site and runs our application is in Brazil — and with it the access log of section 3.2, which does not leave the country. The other services in the table in section 6 process data in the United States, and that constitutes international transfer: Supabase (database and authentication of the contracted platform), Resend (transactional email) and Stripe (payment, where applicable).

The grounds for those transfers: under the LGPD, the necessity of performing a contract and preliminary procedures (art. 33, V and VI); under the GDPR, the transfer instruments each of those suppliers makes available in their respective data processing terms.

One transfer has ceased to exist. Up to version 2.0 of this policy, the typefaces were loaded from Google's servers, which sent every visitor's IP address to that company on every page — the most frequent transfer the site made, and for typographic convenience alone. The typefaces are now served from our own domain. The processing was eliminated, not merely disclosed.

8. How long we keep data

The two logs below are different things with different retention periods — the distinction matters, and the previous version of this policy did not draw it:

DataRetention period
Website and application-API access log (section 3.2)180 days from each line written, discarded automatically by the server itself. Art. 15 of the Brazilian Internet Civil Framework requires retention for at least 6 months; 180 days meets that floor without extending it. The durable record began on 9 August 2026 for the website and on 19 August 2026 for the application API; before those dates there is no history to provide.
Aggregated audience statistics (section 3.3)Indefinitely. This is data that is anonymised by construction — it relates to no identified or identifiable person — and therefore ceases to be personal data (art. 12 of the LGPD; recital 26 of the GDPR).
Access logs of the contracted platform6 months, under art. 15 of the Brazilian Internet Civil Framework.
Unsuccessful applicationUp to 24 months after the decision, to allow reassessment in later cohorts and to evidence the fairness of the selection process. It may be deleted earlier at the data subject's request.
Successful application and program historyFor the duration of the contractual relationship and for 5 years after it ends, in line with applicable limitation periods.
Credit, referral and billing records5 years after termination, as required by tax and accounting rules.
Commercial outreach contactUntil you object. Where you ask us to stop, we keep only the minimum needed to avoid contacting you again.
Aggregated platform usage telemetryDuring the program and for 12 months after it ends.

Once the period ends, data is deleted or anonymised, save for the mandatory retention grounds in art. 16 of the LGPD.

The decision history of the application funnel is kept immutable for audit integrity: it records who decided what, and when. An application may be declined or closed, but the record of the decision is not erased. If you exercise the right to deletion, personal data is removed or anonymised and the remaining record no longer identifies you.

9. Security

We apply technical and administrative measures appropriate to the nature of the data processed, including: TLS-encrypted traffic on all pages and API calls; passwords stored using a hash function; two-factor authentication on the administrative panel; per-company data isolation on the platform; access control by role and branch; rate limiting on public forms; and daily database backups.

No system is absolutely secure. In the event of a security incident that may create relevant risk or harm, we will notify affected data subjects and the Brazilian National Data Protection Authority, under art. 48 of the LGPD. Where the incident affects a data subject in the European Union, notification to the supervisory authority follows the 72-hour deadline in art. 33 of the GDPR.

In the interest of honesty: as of this date we do not hold ISO 27001 certification, a SOC 2 report or an independent third-party security audit. We describe above what we actually do, and we do not claim seals we do not have.

10. Your rights as a data subject

At any time and free of charge, you have the right to:

  • confirm whether we process your data and access it;
  • correct incomplete, inaccurate or outdated data;
  • request anonymisation, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • request restriction of processing in the cases set out in art. 18 of the GDPR — for example, while we examine the accuracy of your data or the merits of your objection;
  • request portability to another provider;
  • obtain information about who we share your data with;
  • be informed about the possibility of not consenting and the consequences of that;
  • withdraw consent;
  • object to processing based on legitimate interest — including, at any time and without having to give a reason, to commercial outreach;
  • not be subject to a decision based solely on automated processing that produces legal effects or significantly affects you, and to request a review of it.

You may also lodge a complaint with an authority:

  • with the Brazilian National Data Protection Authority (ANPD), in Brazil;
  • if you are in the European Union or the European Economic Area, with the supervisory authority of your Member State, under art. 77 of the GDPR — in Spain, the Agencia Española de Protección de Datos (AEPD).

Lodging a complaint does not depend on speaking to us first. We would rather resolve it directly, but the right is yours and does not require our agreement.

11. How to exercise your rights

Write to dpo@globalatech.cloud. No form and no set wording is needed: just describe what you want.

We respond within 15 days. That is the deadline in art. 19, II of the LGPD, shorter than the one in art. 12(3) of the GDPR, and we apply it to every request, wherever it comes from.

We may request additional information to confirm your identity before acting on the request — this protects you, so that nobody can obtain or delete your data by impersonating you. There is no charge.

12. Children and adolescents

The website and the platform are intended exclusively for professionals acting in the course of business. We do not direct our services to anyone under 18 and we do not knowingly collect data from children or adolescents. Where such processing is identified, the data will be deleted.

13. What this policy does not yet cover

This section exists because the alternative would be for you to find out on your own. We are an early-stage company, and there are data protection instruments we do not yet have. None of them prevents you from using the site; some matter if you are a European customer assessing a supplier.

What does not exist todayWhy it may matter to you
A Data Processing Agreement (DPA) of our ownThis is the document a European customer usually asks for in due diligence, governing processing between controller and processor. A privacy policy is not a substitute: they are different documents, with different parties and different obligations. We will enter into one on request.
Representative in the European Union (art. 27 GDPR)The GDPR requires the formal designation of an EU representative by a controller established outside the EU that offers goods or services to data subjects in the EU, subject to exceptions. It is a formal act, not website text, and it has not been done.
Record of processing activities (art. 30 GDPR; art. 37 LGPD)An internal document, not for publication, which an authority may demand. It has not been formalised.
Data protection impact assessment (DPIA)May be required depending on the processing. The processing described here involves no profiling, no automated decision with legal effect and no sensitive data, but the formal assessment has not been carried out.
Compliance with specific Spanish-American lawsMexico, Argentina, Colombia and Chile have their own data protection laws. This policy addresses the LGPD and the GDPR; the others will be handled case by case.

When this changes: the first three items will be resolved before the first European customer, or at the first due diligence that asks for a DPA — whichever comes first. Until then, we would rather say we do not have them than claim we do.

14. Changes to this policy

This policy may be revised to reflect changes in the service or in legislation. The effective date at the top of the page indicates the current version. Material changes that broaden the processing of personal data will be communicated by email to affected data subjects before they take effect.

GLOBALATECH LTDA. · CNPJ 68.518.193/0001-00 · Itajaí, Santa Catarina, Brazil · Data Protection Officer: Wellinton Aoki — dpo@globalatech.cloud

globalatech
From rate to opportunity.

Revenue Intelligence for freight forwarders. Born inside a real operation.

Opportunity Engine· our product

Product

OverviewFounding Program

Company

Why we existAbout usApply

Legal

PrivacyTerms of use

Language

PortuguêsEnglish (current)Español
© 2026 GlobalaTech. All rights reserved. · Itajaí, SC — Brazil