Thiago Labs
ProjectsSolutionsAbout
Talk to me
ProjectsSolutionsAboutTalk to me
LanguagePT

Legal document · PT-BR reference

Privacy Policy

How Thiago Labs handles information across this site and its contact flow.

Last updated September 6, 2026

On this page

  1. How to read this policy
  2. Who controls the processing
  3. Data we process
  4. How collection works
  5. Purposes
  6. Legal bases considered
  7. Discover and automated processing
  8. Sharing and providers
  9. International transfers
  10. Retention
  11. Security
  12. Your rights
  13. Cookies and local storage
  14. Updates and contact

How to read this policy

This Privacy Policy explains how Thiago Labs processes personal data on thiagolabs.com.br, Discover and the contact form. It applies to browsing and requests made through the site; project proposals and contracts may contain additional rules without reducing statutory rights.

Who controls the processing

Thiago Labs is the trade name used by 65.054.720 Thiago de Souza Rodrigues, CNPJ 65.054.720/0001-85. Thiago de Souza Rodrigues is the controller for the processing described here. No physical address is published in this document.

Contact: thiago@thiagolabs.com.br.

Data we process

Data you send

Name; email and/or phone; company or brand; project summary; selected solution or mode; language and source path. The system also records that the Privacy Policy version was shown at submission.

Discover data

Answers about structure, content, goals, visual direction, complexity and urgency, together with the recommendation and its confidence, signals and reasons.

Generated and technical data

Submission ID, public reference, timestamps, delivery statuses and Resend message identifiers. For abuse prevention, the server turns the available IP identifier into an HMAC hash; the raw IP is not a lead field. The honeypot is used to reject spam and is not persisted as a lead.

How collection works

The form sends the fields you complete to the server. Discover uses deterministic browser rules and temporarily stores state in sessionStorage; a context summary may accompany the form. External services open only when you choose their links. The site uses aggregated navigation and event measurement without form fields or directly identifying details.

Purposes

  • reply, understand the project and prepare contact or a proposal;
  • send a confirmation and an internal notification;
  • record the request, reference and delivery results;
  • prevent spam, fraud and abusive automation;
  • protect the site, comply with law and exercise rights.

Legal bases considered

PurposeBasis considered
Reply and evaluate a requestPre-contractual steps requested by the data subject (LGPD art. 7, V).
Request communicationsMeasures requested by the visitor.
Security and abuse preventionLegitimate interest, with necessity and proportionality.
Legal duties and auditA concrete legal duty or exercise of rights, where applicable.

Discover and automated processing

Discover compares answers with deterministic product rules and gives an initial indication among GO, EXPERIENCE and SCALE, or no sufficient recommendation. It is not presented as AI, does not decide a contract, price or deadline and does not replace human analysis. Where applicable, you may request information and review of an automated decision.

Sharing and providers

Operational processing uses Supabase for lead and rate-limit records, Resend for internal and visitor emails, Vercel for hosting, API execution and aggregated navigation/event measurement, and WhatsApp/Meta only when you open the conversation link. Sora and Inter are downloaded at build time through next/font/google and served by this site; the visitor's browser does not request Google Fonts. There is no data sale or commercialization in the current site. Each provider has its own policies.

International transfers

Infrastructure and communication services may process data outside Brazil. Specific locations and contractual instruments are not confirmed in the project; applicable LGPD safeguards must be observed.

Retention

No fixed period is implemented. Data is kept only as needed for the request, legal duties and rights, then deleted or anonymized when applicable. An internal schedule with objective periods remains to be defined.

Security

Server-only Supabase credentials, RLS and RPC access controls, input validation, HMAC-based rate limiting, idempotency and anti-spam controls are used. They reduce risk but are not an absolute security guarantee.

Your rights

You may request confirmation and access, correction, anonymization, blocking or deletion where applicable, portability under regulation, sharing information, consent withdrawal, objection and review of automated decisions. Contact thiago@thiagolabs.com.br; identity confirmation may be required.

Cookies and local storage

The site does not use confirmed analytics or marketing cookies. Discover uses sessionStorage for answers and context until the session or form submission.

Updates and contact

This policy may be updated prospectively. Effective and last updated: September 6, 2026.

For Brazil, the Portuguese version is the editorial reference to the extent permitted by law. Contact: thiago@thiagolabs.com.br.

Thiago Labs

Web development · Digital products

Solutions

ProjectsSolutionsAbout

Talk to me

thiago@thiagolabs.com.brWhatsApp
instagramgithublinkedin
© 2026 Thiago Labs. · CNPJ 65.054.720/0001-85
Privacy PolicyTerms of Use