Privacy Policy

Last updated: March 30, 2026

This text is for information only. For legal matters, consult a qualified professional under Brazilian law.

1. Controller

The controller of personal data processed through this Site is the legal entity registered under Brazilian CNPJ 57.671.592/0001-90, brand O Augusto, website https://oaugusto.com.

2. Data-protection contact

To exercise your rights or ask about processing, contact: contato@oaugusto.com or use the contact form on the Site.

3. Data we process and why

Contact form: name, email, and message — to read, reply, and record your request. Abuse prevention (rate limiting): IP address and related HTTP metadata — to cap submissions per IP. Hosting and operation: IP, timestamps, technical logs — to run the Site securely and diagnose issues. Analytics and performance: aggregated or pseudonymous data (Vercel Analytics and Vercel Speed Insights) — to understand usage and improve performance. Theme preference: value in browser localStorage — to remember light/dark mode.

Legal bases under Brazilian law (LGPD) may include processing at your request, legitimate interests (e.g. communication and security), and performance of the service, as assessed for each activity.

4. Cookies and local storage

The Site may use cookies or similar technologies that are necessary for operation and, depending on configuration, analytics-related identifiers. You can manage cookies in your browser settings. Theme preference uses localStorage, not HTTP cookies.

5. Processors (sub-processors)

We use vendors that process personal data on our behalf under LGPD-aligned instructions, including: Vercel Inc. (hosting, app runtime, Analytics, Speed Insights) — processing may occur outside Brazil; Resend (transactional email for contact submissions; your email may be set as Reply-To); Upstash (rate limiting based on IP). See each vendor’s site for their policies.

6. International transfers

Some vendors may process data outside Brazil. Where required, we use appropriate safeguards under LGPD and related rules.

7. Retention

Contact messages: as long as needed to respond and, where applicable, document the request, then deletion or anonymisation subject to legal obligations. Rate-limit and security logs: limited periods per technical configuration. Analytics: per provider settings and our configuration (often aggregate).

8. Your rights (LGPD)

You may request: confirmation of processing; access; correction; anonymisation, blocking, or deletion where applicable; information on sharing; withdrawal of consent if processing is consent-based; objection to certain legitimate-interest processing where applicable. Contact us as in section 2 with enough information to verify your request securely.

9. Security

We apply reasonable technical and organisational measures to protect data, including HTTPS and rate limits on the contact endpoint.

10. Children

The Site is not directed at children under 16. Processing of minors’ data follows applicable legal requirements.

11. Changes

We may update this policy. The date at the top shows the last revision.