1. Our Privacy Commitment
Berghem – Smart Information Security specializes in application, infrastructure and payment security assessments, helping leaders build a secure digital world. Committed to ethics and transparency, we recognize the importance of protecting personal data. Acting as data Controller, we ensure that we collect, store and process information appropriately and transparently, in full compliance with the LGPD — Brazilian General Data Protection Law (Law No. 13,709/2018).
Data controller: Berghem Segurança da Informação Ltda., registered under CNPJ 47.860.245/0001-40, with registered office at [TODO: FULL REGISTERED ADDRESS], São Paulo/SP, Brazil.
Data Protection Officer (DPO): [TODO: DPO NAME] — contact: [email protected].
European Union operations: Berilo S.r.l., Bergamo, Italy — [TODO: VAT NUMBER AND REGISTERED ADDRESS], acting as controller for processing carried out in the EEA.
2. What data do we collect?
We collect information you provide voluntarily, as well as information gathered automatically as you browse our site:
- Data you provide: name, email address, phone number, job title, company name and the content of messages sent through our contact forms, emails or phone calls.
- Recruitment information (Work With Us): full name, email address, phone number, professional history (previous roles and experience), education, technical skills and links to professional social networks (such as LinkedIn).
- Automatically collected data: IP address, browser type, operating system, device information, pages visited, time spent on pages and navigation paths.
- Cookie data: session identifiers and preference settings used to optimize your experience (detailed in section 8).
Privacy note: we ask candidates not to include identity document numbers, photographs or sensitive data in résumés submitted for initial screening. If such information is sent spontaneously, it will not be considered in the initial evaluation.
3. Why do we use your data?
We process your data for legitimate, specific and explicit purposes:
- Enquiries and proposals: responding to enquiries, processing quotation requests and sending information about our cybersecurity services.
- Service delivery: performing contracts and providing information security consulting.
- Marketing communications: sending news, educational content, events and relevant commercial offers from Berghem.
- Recruitment: screening, assessing and selecting candidates who send us résumés.
- Site optimization: analyzing usage trends and browsing behavior to improve the performance and usability of our site.
- Security: ensuring site integrity, fraud protection and prevention of unauthorized access.
4. Which legal bases do we rely on?
Berghem processes personal data on valid legal bases as set out in the Brazilian General Data Protection Law (Law No. 13,709/2018). Each processing activity has a specific legal ground, as detailed below:
Consent (Art. 7, I of the LGPD)
We rely on this basis when you expressly authorize the processing of your data for specific purposes. It applies to:
- Marketing communications and newsletter: sending news, events and commercial offers from Berghem when you voluntarily subscribe through our forms. You may withdraw this consent at any time.
Performance of a contract (Art. 7, V of the LGPD)
We process your data when necessary to manage a contract with you or to carry out the steps preceding it. It applies to:
- Enquiries and proposals: processing quotation requests, responding to commercial enquiries and sending information about our cybersecurity services.
- Work With Us (recruitment): screening and reviewing résumés submitted voluntarily for our selection processes.
Legitimate interest (Art. 7, IX of the LGPD)
We process data based on our legitimate business interests, provided this does not infringe your fundamental rights and freedoms. It applies to:
- Site optimization: analyzing navigation metrics, usage patterns and visitor behavior to improve technical performance and user experience.
- Information security: monitoring access, preventing fraud and protecting our site infrastructure against cyber attacks.
5. Who do we share personal data with?
We do not sell your personal data. Information is shared strictly to fulfil the operational purposes described in this policy, limited to the following providers:
- IT and infrastructure suppliers: companies providing cloud hosting, cybersecurity and technical support services to ensure the stability and integrity of our platforms.
- Marketing automation and CRM tools: technology platforms used for customer relationship management, institutional communications, traffic analytics reporting and support for our legitimate marketing campaigns.
- Communication partners and agencies: specialist service providers engaged to manage, audit and optimize our advertising, educational content and corporate events.
- Public authorities or government bodies: where required by law, court order or to comply with regulatory obligations to which Berghem is subject.
6. How long do we keep your information?
We retain collected data only for as long as strictly necessary to meet its legal or operational purposes.
- Candidate résumés: kept for up to 12 months in our talent pool for future selection processes, unless the data subject requests deletion beforehand.
- Commercial contact data: kept for the duration of the pre-contractual or contractual relationship, or until deletion/withdrawal is formally requested.
- Application access logs (server logs): kept for the mandatory period of 6 months, in strict compliance with Article 15 of the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014), under the legal basis of compliance with a legal obligation (Art. 7, II of the LGPD).
- Statistical and navigation data (Google Analytics): kept for up to 14 months (as configured in Google Analytics 4) for metrics analysis, or until the user clears their browser cookies.
7. How do we keep your data secure?
Berghem gives absolute priority to data protection, implementing rigorous measures to ensure information is handled securely. We adopt internationally recognized standards and appropriate technical and administrative measures to mitigate the risk of unauthorized access, leakage or alteration of data.
8. Cookies
We use cookies to keep the site working (essential cookies). Analytics and marketing cookies (non-essential) are only written after your explicit choice in our consent banner — before that, the corresponding scripts are not loaded.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| _ga | Identifies unique users (Google Analytics 4) | 2 years | Analytics · consent only |
| _gid | Distinguishes user sessions (Google Analytics 4) | 24 hours | Analytics · consent only |
| _gat_UA-* | Throttles the request rate (Google Analytics 4) | 1 minute | Analytics · consent only |
| _clck | Persistent Microsoft Clarity identifier | 1 year | Analytics · consent only |
| _clsk | Groups the page views of one session (Microsoft Clarity) | 1 day | Analytics · consent only |
| MUID | Microsoft user identifier (Clarity) | 1 year | Analytics · consent only |
| berghem-cookie-consent | Records your consent choice (localStorage, not a cookie) | 12 months | Essential |
You can review or withdraw your choice at any time through the cookie preferences link in the footer, or clear the data directly in your browser settings. Data retention on our Google Analytics 4 property is set to 14 months.
9. Data subject rights
In strict compliance with Article 18 of the LGPD, Berghem ensures you can exercise your rights at any time. Upon request to our Data Protection Officer, you may ask for:
- Confirmation that processing exists and access to your data;
- Correction of incomplete, inaccurate or out-of-date data;
- Anonymisation, blocking or deletion of unnecessary data or data processed in breach of the law;
- Portability of your data to another service provider;
- Deletion of personal data processed on the basis of your consent;
- Information about the public and private entities with which we share data;
- Withdrawal of consent.
To exercise any of these rights, contact us directly at [email protected].
Data Protection Officer (DPO): [TODO: DPO NAME], appointed under Art. 41 of the LGPD. Official channel: [email protected].
10. International transfers and sub-processors
Part of the processing takes place outside Brazil. International transfers rely on Art. 33 of the LGPD (and, where applicable, Arts. 44-49 GDPR), supported by standard contractual clauses and the contractual security commitments of the providers listed below:
- Microsoft Azure (Azure Static Web Apps): hosting and execution of the website and the contact API — North Europe region (Ireland, EU).
- Google Analytics 4 (Google LLC / Google Ireland Ltd.): audience measurement, consent-gated — United States and European Union, under standard contractual clauses (SCCs) and the EU-US Data Privacy Framework.
- Microsoft Clarity (Microsoft Corporation): behavioral analytics, consent-gated — United States, under standard contractual clauses (SCCs).
- Cloudflare, Inc.: DNS, CDN and WAF — global network, processed at the edge closest to the visitor, under standard contractual clauses (SCCs).
- OIDC identity providers (Microsoft Entra ID, Google, LinkedIn): optional social sign-in for restricted areas of the site — United States and European Union. We receive only the business e-mail address and the name supplied by the provider.
We do not sell, rent or otherwise transfer personal data to third parties for those third parties' own purposes.
11. GDPR — rights of data subjects in the EEA
If you are in the European Economic Area, your personal data is processed by Berilo S.r.l. (Bergamo, Italy) as controller, and by Berghem Segurança da Informação Ltda. as joint controller for group-wide activities. In addition to the LGPD rights described in section 9, the General Data Protection Regulation (EU) 2016/679 gives you the following rights:
- Art. 15 — Access: confirmation of whether your data is processed and a copy of it.
- Art. 16 — Rectification: correction of inaccurate or incomplete data.
- Art. 17 — Erasure: deletion of your data ('right to be forgotten') where the conditions are met.
- Art. 18 — Restriction: restriction of processing while a dispute over accuracy or lawfulness is resolved.
- Art. 20 — Portability: receipt of your data in a structured, commonly used, machine-readable format, or its transmission to another controller.
- Art. 21 — Objection: objection to processing based on our legitimate interests, including profiling, and to direct marketing at any time.
- Art. 22 — Automated decisions: the right not to be subject to a decision based solely on automated processing that produces legal effects. We do not carry out such decision-making on this site.
Requests are handled free of charge within one month (Art. 12(3) GDPR). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand (Art. 7(3) GDPR). To exercise any of these rights, write to [email protected].
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For Berilo S.r.l. the competent authority is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it); you may alternatively complain to the authority of your habitual residence or place of work. In Brazil, the competent authority is the ANPD (www.gov.br/anpd).
12. Updates to this Privacy Policy
This policy may be updated periodically to reflect improvements to our internal processes or new legislative guidance. The date of the most recent version will always be shown at the top of this document.