Section 01
Introduction
Daniel Krom Antonio Desenvolvimento Ltda ("we", "us", or "the Company"), registered under CNPJ 67.992.803/0001-40, headquartered at Rua Geralda Francisca de Jesus, 10, Residencial Morada do Sol, Regente Feijó – SP, Brazil, operates the website and digital services available at kromtech.site. We develop software, web systems, and technology solutions for business clients across Brazil and internationally.
This Privacy Policy explains what personal data we collect when you visit our website or interact with us, why we collect it, how we process and protect it, and what rights you hold regarding your own information. It applies to all visitors and contacts regardless of your country of residence, and is written to satisfy the requirements of Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018) and, where applicable, the General Data Protection Regulation (GDPR — Regulation EU 2016/679).
By accessing this website and voluntarily providing your contact information, you acknowledge that you have read and understood the practices described below. If you do not agree with any part of this policy, please discontinue use of the site and contact us directly by email if you have questions.
Plain-language summary: We collect only the data we genuinely need to operate our business and respond to enquiries. We do not sell your personal data, we do not share it with advertisers for behavioural targeting, and we give you clear tools to access, correct, or delete what we hold.
Section 02
Information We Collect
We collect information in two distinct ways: data you provide to us voluntarily, and data collected automatically as you browse our website.
Information you provide directly
When you use any contact channel listed on this website — including sending an email to contato@kromtech.site or reaching out via a third-party messaging platform — you may share personal data such as:
- Your full name and professional title
- Your business or personal email address
- Your telephone or WhatsApp number, if you choose to include it
- The name and sector of your company or organisation
- A description of your project requirements or enquiry
- Any other information you voluntarily include in your message
Providing this information is entirely voluntary. You choose what to share, and you can always contact us with less information — though this may limit our ability to respond fully to your enquiry.
Information collected automatically
When you visit our website, our servers and analytics tools automatically record certain technical data that is standard practice across the modern web. This may include:
- Your IP address and approximate geographic location (country or region level)
- Browser type, version, and operating system
- The URL of the page you visited and the referring URL (the page that linked you here)
- Date, time, and duration of your visit
- Pages viewed and navigation path through the site
- Device type (desktop, tablet, mobile) and screen resolution
- Interaction events such as clicks, scrolls, and time spent on sections
This technical data is collected primarily through cookies and analytics scripts (see Section 04 below). In isolation, most of this data does not directly identify you as an individual, but in combination or linked to contact data it may constitute personal data under the LGPD and GDPR, and we treat it accordingly.
Section 03
How We Use Your Information
We process personal data only for specific, legitimate, and clearly defined purposes. We do not process your data in ways that are incompatible with the purposes listed below:
- Responding to enquiries: When you contact us, we use the information you provide to understand your needs and reply in a timely and relevant manner. This is the primary reason most visitors share data with us.
- Business development and follow-up: If you have expressed interest in our development or consulting services, we may follow up regarding your project — always with the option to opt out of further communication.
- Improving our website and services: Aggregate and anonymised usage data helps us understand which pages and content are most useful, how visitors navigate the site, and where we can improve the experience.
- Security and fraud prevention: We monitor server logs and traffic patterns to detect and respond to potential security threats, malicious activity, or abuse of our systems.
- Legal compliance: We may process and retain certain data to fulfil obligations under Brazilian tax law, commercial law, and any applicable sector regulations, or to respond to lawful requests from competent public authorities.
- Measuring advertising effectiveness: If you arrive at our site via a Google Ads campaign, we use anonymised conversion data to measure whether our advertising is reaching relevant audiences. No individual user profile is built for retargeting without your explicit consent.
The legal basis for processing enquiry data is legitimate interest and the performance of pre-contractual steps at your request (LGPD Art. 7, II and IX; GDPR Art. 6(1)(b) and (f)). The legal basis for analytics and advertising measurement is consent, obtained via our cookie banner where applicable.
Section 04
Cookies & Tracking Technologies
Our website uses cookies — small text files stored in your browser — and similar technologies such as local storage and pixel tags. Below is a straightforward explanation of what we use and why.
Strictly necessary cookies
These cookies are essential for the website to function correctly. They do not collect personal data for marketing or analytics purposes and cannot be switched off. They include session identifiers, security tokens, and preferences you have set (such as accepting this privacy notice).
Analytics cookies
We use Google Analytics (with IP anonymisation enabled) to understand how visitors interact with our site in aggregate. Google Analytics places cookies that track page views, session duration, traffic sources, and navigation paths. The data is processed by Google LLC on our behalf under a data-processing agreement. We have configured this integration to avoid sending personally identifiable information to Google, and we do not enable Google Signals or cross-device tracking without explicit consent. You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on.
Advertising & conversion cookies
If you arrive via a Google Ads campaign, Google may place a conversion-tracking cookie so we can measure whether our ads lead to meaningful contact. This cookie does not identify you personally and expires within 90 days. We do not use this data to build individual advertising profiles.
Managing your cookie preferences
You can control or delete cookies at any time through your browser settings. Most browsers allow you to block all third-party cookies, clear existing cookies on exit, and receive a notification before any new cookie is placed. Disabling analytics or advertising cookies will not affect your ability to browse our website, but it will reduce the data available to us for improving the site. For detailed instructions specific to your browser, visit allaboutcookies.org.
Section 05
Sharing With Third Parties
We do not sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes. We may share data with the following categories of recipients, and only to the extent necessary:
- Service providers and technology partners: We use a limited number of third-party platforms to operate our business — including cloud hosting infrastructure, email delivery services, and web analytics. These providers act as data processors on our behalf and are contractually bound to process your data only according to our instructions, to maintain appropriate security measures, and to delete or return data when the engagement ends.
- Google LLC: As described in Section 04, Google receives anonymised analytics and advertising measurement data. Google's privacy practices are governed by its Privacy Policy. Transfers of data to Google's infrastructure outside Brazil are covered by standard contractual clauses and Google's compliance with applicable data protection frameworks.
- Legal and regulatory authorities: We may disclose personal data to Brazilian courts, the Autoridade Nacional de Proteção de Dados (ANPD), tax authorities, or other competent bodies where required by law, a court order, or a legitimate regulatory request. We will notify you of any such disclosure to the extent permitted by law.
- Business transfers: In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data held by us may be transferred to the successor entity. We will notify affected individuals before their data is transferred and becomes subject to a different privacy policy.
In all cases of data sharing, we apply the principle of data minimisation — sharing only what is strictly necessary for the stated purpose — and we ensure appropriate contractual safeguards are in place.
Section 06
Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. The following guidelines inform our retention decisions:
- Enquiry and contact data: Messages and contact details received via email are retained for up to 24 months from the date of last meaningful communication. If a project engagement follows, related correspondence is retained for the duration of the engagement plus five years to satisfy commercial and contractual record-keeping requirements under Brazilian law.
- Analytics data: Aggregated, anonymised website usage data processed through Google Analytics is retained for 14 months within the Google Analytics platform, after which it is automatically deleted. This data does not include personally identifiable information.
- Server logs: Technical server access logs (IP addresses, request timestamps) are retained for up to 90 days for security monitoring purposes, then deleted automatically.
- Advertising conversion data: Conversion event data associated with Google Ads campaigns is retained within Google's systems for up to 90 days, consistent with the cookie lifespan described in Section 04.
- Legal hold: Notwithstanding the above, we may retain data for a longer period where required by a specific legal obligation, an ongoing dispute, or a regulatory investigation. In such cases, access to the data is restricted to only those who need it for the legal purpose.
When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised. We do not archive personal data simply because storage is cheap — we apply deliberate, documented retention rules.
Section 07
Data Security
Protecting the personal data entrusted to us is a core operational responsibility. As a software development company, we apply the same engineering rigour to our own data security that we bring to client projects. Our measures include:
- All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher. The padlock icon in your browser confirms this connection is secure.
- Our hosting infrastructure is provided by reputable cloud providers with ISO 27001 certification and physical security controls including access restrictions, CCTV, and redundant power systems.
- Access to contact and enquiry data is limited to company principals and authorised staff with a documented need. We do not grant broad access to third-party contractors.
- We keep software, server operating systems, and content management tools patched and updated on a regular cycle to reduce exposure to known vulnerabilities.
- Email communications containing sensitive project information are handled through accounts with two-factor authentication enabled.
Despite these measures, no transmission over the internet or electronic storage method is perfectly secure. If you believe your personal data has been compromised in connection with our systems, please contact us immediately at contato@kromtech.site. In the event of a confirmed data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority (ANPD, and where applicable the relevant EU supervisory authority) within the timeframes required by law, and will communicate directly with affected individuals without undue delay.
Section 08
Your Rights
Under the LGPD and, where applicable, the GDPR, you hold a meaningful set of rights over your personal data. We take these rights seriously and have straightforward processes to honour them. Your rights include:
Right of Access
You may request confirmation of whether we hold personal data about you and, if so, a copy of that data along with information about how it is processed.
Right to Correction
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it without undue delay.
Right to Deletion
You may ask us to delete personal data we hold about you, particularly where consent was the legal basis for processing. We will comply unless legal retention obligations apply.
Right to Object
You may object to the processing of your personal data where we rely on legitimate interest as our legal basis. We will assess and respect your objection unless we can demonstrate compelling grounds.
Right to Restrict Processing
In certain circumstances — for example, where accuracy is contested or an objection is pending — you may request that we restrict the processing of your data to storage only.
Right to Portability
Where processing is based on consent or contract and is carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
Right to Withdraw Consent
Where we process data on the basis of your consent (e.g., analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint
If you believe your rights have not been respected, you may lodge a complaint with Brazil's ANPD (gov.br/anpd) or, for EU residents, with your local data protection supervisory authority.
To exercise any of the above rights, please send a written request to contato@kromtech.site with the subject line "Data Subject Request". Please include enough information for us to verify your identity and locate your data — we will never ask for more than is necessary. We aim to respond to all verified requests within 15 business days in line with LGPD requirements (and within one calendar month for requests governed by the GDPR, with the possibility of a two-month extension where complexity warrants it).
Section 09
Children's Privacy
Our website and services are directed exclusively at businesses, professionals, and adult individuals seeking software development or technology consulting services. We do not knowingly collect, process, or store personal data from children under the age of 13, or from minors under 18 where parental or guardian consent is required under applicable law.
If you believe a child has provided us with personal information without appropriate consent, please contact us immediately at contato@kromtech.site. Upon verification, we will promptly delete that information from our records. We do not use personal data of minors for any commercial or marketing purpose whatsoever.
Section 10
Changes to This Policy
We review this Privacy Policy at least annually and whenever there is a material change to our data processing practices, a new legal obligation, or a significant update to the tools and third-party services we use. When we make changes, we update the "Last updated" date at the top of this page.
For changes that are material — meaning they significantly affect how we collect or use your personal data, or that reduce your rights — we will take additional steps to bring them to your attention. This may include a prominent notice on our homepage for a period following the update. We encourage you to review this page periodically to stay informed.
Continued use of our website after a policy update constitutes acceptance of the revised terms, to the extent permitted by applicable law. If you do not agree with a material change, you may exercise your rights as described in Section 08 or cease using our site and request deletion of your data.
Section 11
Contact Us
If you have questions about this Privacy Policy, wish to exercise your data subject rights, or want to report a concern about how we handle personal information, please reach out through the details below. We are committed to responding promptly and resolving any issues in good faith.
Daniel Krom Antonio Desenvolvimento Ltda
CNPJ: 67.992.803/0001-40
Rua Geralda Francisca de Jesus, 10
Residencial Morada do Sol
Regente Feijó – SP, Brazil
Privacy & data protection enquiries:
contato@kromtech.site
Please include "Privacy Policy" or "Data Subject Request" in your subject line so your message reaches the right person without delay.