Privacy Policy
Last updated: July 11, 2026
1. Introduction and scope
Mestry's Tecnologia ("Mestry's", "we", "us") is a Brazilian company based in São Paulo, specialized in custom software development. This policy applies to visitors of our website, prospective clients who contact us, and active clients.
This policy is primarily governed by the LGPD. For data subjects located in the European Economic Area, the United Kingdom, or an equivalent jurisdiction (for example, when we offer or monitor services directed at that audience), we also apply, where relevant, the principles and rights set out in the GDPR, as detailed throughout this document.
2. Controller and Data Protection Officer (DPO)
Controller: Mestry's Tecnologia, São Paulo/SP, Brazil. For GDPR purposes, Mestry's also acts as the "controller" of personal data processed through this website.
Data Protection Officer (DPO): in compliance with Article 41 of the LGPD and, where applicable, Article 37 of the GDPR, we provide the channel privacidade@mestrys.com.br for any matter related to personal data.
3. Data we collect
We may collect the following categories of data:
- Contact data: name, email, company, and message provided voluntarily through the contact form.
- Browsing data: IP address, device type, pages visited, and interactions with the site, collected via cookies and analytics tools.
- Project delivery data: information shared by clients under development contracts (processed under the specific contract).
4. Legal bases (Article 7 of the LGPD and Article 6 of the GDPR)
We process data based on:
- Consent of the data subject when submitting the contact form;
- Performance of a contract or pre-contractual steps at the data subject's request;
- Legitimate interest for browsing analysis, security, and service improvement, always respecting the data subject's rights and freedoms;
- Compliance with a legal or regulatory obligation when applicable.
Under the GDPR, these bases correspond to consent (Art. 6(1)(a)), performance of a contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), and compliance with a legal obligation (Art. 6(1)(c)). We do not process special categories of data (GDPR Art. 9 / sensitive data under the LGPD) through this website.
5. Purposes of processing
- Respond to contact and quote requests;
- Deliver and improve contracted services (development, support, and maintenance);
- Send institutional communications when authorized;
- Analyze site performance and improve the user experience;
- Prevent fraud and abuse, and keep our systems secure.
6. Sharing with third parties
We do not sell personal data. We share information only with service providers strictly necessary for operations (for example, hosting providers, transactional email, and analytics), always under contract and confidentiality obligations compatible with the LGPD.
An up-to-date list of subprocessors can be requested through the DPO channel.
7. Retention and deletion
We keep personal data for as long as needed to fulfill the stated purposes or legal obligations. After that period, data are securely deleted or anonymized, except where the law provides otherwise.
8. International data transfers
Our service providers (for example, hosting and cloud infrastructure) may process data on servers located outside Brazil, including outside the European Economic Area. When that happens, we seek adequate safeguards such as standard contractual clauses, adequacy decisions, or equivalent mechanisms recognized under the LGPD (Art. 33) and the GDPR (Chapter V), so that the level of protection described in this document is maintained.
9. Data subject rights (LGPD and GDPR)
You may, at any time, request:
- Confirmation that processing exists;
- Access to your data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data under the LGPD ("right to be forgotten" under the GDPR);
- Restriction of and objection to processing (GDPR);
- Data portability;
- Information about public and private entities with which the data have been shared;
- Not to be subject to automated decisions that produce legal effects or significantly affect you, without the possibility of human review;
- Withdrawal of consent.
Requests should be sent to the DPO through the channel listed in section 2. We will respond within the applicable legal timeframe (Arts. 18 and 19 of the LGPD; Arts. 12 to 22 of the GDPR). GDPR data subjects also have the right to lodge a complaint directly with the data protection authority of their country of residence, place of work, or place of the alleged infringement.
10. Security measures
We adopt reasonable technical and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration, or any form of inadequate or unlawful processing. These include:
- Encryption in transit (HTTPS/TLS);
- Access control based on least privilege and periodic reviews;
- Logging and monitoring of security events;
- Ongoing team training on data protection best practices.
No system is 100% immune to incidents. We continually strengthen our controls and recommend that data subjects also follow good security practices.
12. Security incidents
In the event of a security incident that may pose a relevant risk or harm to data subjects, we will notify Brazil's National Data Protection Authority (ANPD) and affected data subjects within the timeframes and in the manner required by the LGPD. When the GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of the incident (GDPR Art. 33) and, when the risk to data subjects is high, the affected data subjects directly (GDPR Art. 34).
13. Changes to this policy
This policy may be updated periodically. We will publish the current version on this page with the last-updated date highlighted at the top.
14. Contact the DPO
Questions, requests, or complaints related to personal data may be sent to privacidade@mestrys.com.br. If you are not satisfied with our response, you may also lodge a complaint with Brazil's National Data Protection Authority (ANPD) or, where applicable, the data protection authority of your habitual residence, place of work, or place of the alleged infringement under the GDPR. See also our Terms of Use.
