Privacy Policy
How we collect, use, share and protect your personal data
Last updated: July 16, 2026 · Version 2.2
This document has been drafted in compliance with the Brazilian General Data Protection Law (Law No. 13,709/2018 — LGPD), the European Union General Data Protection Regulation (Regulation (EU) 2016/679 — GDPR), the UK Data Protection Act 2018, the Brazilian Internet Civil Framework (Law No. 12,965/2014), and the guidance of the Brazilian Data Protection Authority (ANPD). The rights applicable to you depend on your jurisdiction of residence.
1. Data Controller Identification
This Privacy Policy describes how B2Tech ("B2Tech", "we", "us", "our") processes personal data collected through the websites b2tech.io and its subdomains (blog.b2tech.io and future courses.b2tech.io), as well as through contact forms, newsletter and other communication channels. By using our services, you acknowledge that you have read, understood and agreed to this Policy. Data controller:
- Legal name: BRACAIOLI TECNOLOGIA EMPREENDIMENTOS E NEGÓCIOS DIGITAIS LTDA (trade name Bracaioli Tech; B2Tech brand)
- Tax ID (CNPJ): 43.773.294/0001-05
- Address: Rua Rio de Janeiro, 243 — Room 802, Centro, Belo Horizonte/MG, 30160-040, Brazil
- Contact e-mail: [email protected]
- Data Protection Officer (DPO): Bruno Bracaioli — e-mail: [email protected]
2. Definitions
For the purposes of this Policy, the definitions from the LGPD (art. 5) and the GDPR (art. 4) apply:
- Personal data: information related to an identified or identifiable natural person.
- Sensitive personal data: data revealing racial or ethnic origin, religious beliefs, political opinion, union membership, health or sex life, genetic or biometric data when linked to a natural person.
- Data subject: the natural person to whom the personal data being processed refers.
- Controller: the natural or legal person who determines the purposes and means of the processing of personal data.
- Processor: the natural or legal person who processes personal data on behalf of the controller.
- Processing: any operation performed on personal data (collection, storage, use, sharing, deletion, etc.).
- Consent: a freely given, specific, informed and unambiguous indication by which the data subject agrees to the processing of their data for a specific purpose.
- Anonymisation: the use of reasonable technical means to render data unidentifiable in relation to a specific individual.
- ANPD: Brazilian National Data Protection Authority.
3. Personal Data We Collect
We collect only the data strictly necessary for the purposes described in this Policy. The categories of data processed are:
- Identification and contact data: name, e-mail address and, optionally, phone number, provided by you when filling out contact forms, newsletter or course registration.
- Content data: messages, questions or comments that you actively send to us.
- Navigation and technical data: IP address, browser type and version, operating system, screen resolution, language, pages visited, access time, referring URL and unique device identifiers.
- Cookies and similar technologies data: as described in section 10.
- Authentication data (future): when we launch the courses platform, we may collect username, password hash, lesson progress and preferences. Such data will be covered by an updated version of this Policy.
- We do not intentionally collect sensitive personal data. If you voluntarily send us such data, it will only be processed with your explicit consent or under other legal bases provided in art. 11 of the LGPD and art. 9 of the GDPR.
4. Sources of Data
We obtain your personal data from the following sources:
- Directly from you, when you fill in forms, send e-mails, subscribe to the newsletter or register for courses.
- Automatically, through cookies and similar technologies in your browser when you access our websites.
- From third-party providers of services essential to the operation (e.g., traffic analytics providers), as described in section 6.
5. Purposes and Legal Basis
All processing of personal data by us is grounded in at least one of the legal bases provided in art. 7 of the LGPD and, when applicable, in art. 6 of the GDPR. Purposes and legal bases are:
- Responding to contact messages — Pre-contractual steps (LGPD art. 7, V) / Legitimate interest (GDPR art. 6(1)(f)).
- Sending newsletter and marketing communications — Consent (LGPD art. 7, I / GDPR art. 6(1)(a)), revocable at any time.
- Operating and improving our websites (aggregate analytics) — Legitimate interest of the controller (LGPD art. 7, IX / GDPR art. 6(1)(f)), balanced in favour of data subject rights.
- Complying with legal and regulatory obligations — Compliance with legal obligation (LGPD art. 7, II / GDPR art. 6(1)(c)).
- Ensuring the security of the websites and preventing fraud — Legitimate interest (LGPD art. 7, IX / GDPR art. 6(1)(f)).
- Exercising or defending rights in judicial, administrative or arbitration proceedings — LGPD art. 7, VI / GDPR art. 6(1)(f).
- Operating the future courses platform (authentication, enrolment, lesson progress) — Performance of a contract (LGPD art. 7, V / GDPR art. 6(1)(b)).
6. Third-Party Sharing
We DO NOT sell personal data. We share data with processors strictly necessary to provide the service, all bound by contractual obligations of confidentiality and data protection. Current processors and partners are:
- Cloudflare, Inc. — hosting (Cloudflare Pages), CDN, DNS and attack protection. Data processed: IP, headers, access logs. Processing location: USA and global region.
- FormSubmit — service used to deliver contact and newsletter form submissions to our e-mail. Data processed: name, e-mail and message content.
- Google LLC (Google Analytics, when active) — aggregate traffic metrics and anonymous usage behaviour. Data processed: client identifiers, truncated IP, navigation events.
- Google LLC (Google AdSense, on the blog) — contextual ad display. Data processed: advertising cookies, IP, device identifiers.
- Pexels (Pexels GmbH) — royalty-free image supply for blog article illustrations; does not receive end-user data.
- Supabase, Inc. — encrypted OAuth token storage (refresh and access tokens) for the B2Tech AdConnect service; and, in the future, database, authentication and storage for the courses platform. Processing location: USA.
- Upstash, Inc. — transient cache of session and OAuth data for the B2Tech AdConnect service. Processing location: USA and global region.
- Public authorities, when required by law, court order, official investigation, or to defend the rights of B2Tech or third parties.
- In the event of merger, acquisition or corporate reorganisation, the data may be transferred to the succeeding entity, subject to compliance with this Policy.
7. International Data Transfers
Because we use global providers (Cloudflare, Google, FormSubmit, Supabase, Upstash), your data may be transferred to and stored on servers located outside Brazil and outside the European Union, including in the United States. We ensure that any international transfer complies with art. 33 of the LGPD and arts. 44-49 of the GDPR, through:
- Standard Contractual Clauses approved by the European Commission;
- Transfers to countries with an adequacy decision issued by the ANPD or the European Commission;
- Obtaining your specific consent, where applicable;
- Adoption of additional technical measures (encryption in transit and at rest, pseudonymisation) to protect your data against unauthorised access during transit.
- You have the right to request a copy of the safeguards adopted through the channel indicated in section 12.
8. Data Retention Period
We keep your personal data only for as long as necessary for the purposes for which it was collected, except where legal obligations require longer retention. General retention periods are:
- Contact form messages: up to 2 (two) years from the last contact, for after-sales service and relationship history.
- Newsletter subscription: while the data subject keeps active consent. After revocation, data is deleted within 30 days, except for opt-out records kept pursuant to LGPD art. 16.
- Access logs and technical data: 6 (six) months, in compliance with art. 15 of the Brazilian Internet Civil Framework.
- Data required by legal or regulatory obligation: for the specific period set by the applicable rule.
- Data related to the exercise of rights in proceedings: for as long as necessary for the proceedings and any applicable statute of limitations.
- Upon expiry of the retention period, data is securely deleted or irreversibly anonymised.
9. Information Security
We adopt reasonable technical and organisational measures to protect personal data against unauthorised access, destruction, loss, alteration, improper communication or dissemination, in accordance with art. 46 of the LGPD and art. 32 of the GDPR. Measures adopted include:
- Encryption in transit (TLS 1.3) in all communications with our websites;
- Encryption at rest in databases and storage;
- Access control based on the principle of least privilege;
- Strong authentication and credential rotation;
- Logging and monitoring of security events;
- Periodic vulnerability assessment and dependency updates;
- Staff training and accountability;
- Incident response plan and notification to the ANPD and affected data subjects in the event of a security incident involving relevant risk or harm, as required by LGPD art. 48 and GDPR arts. 33-34.
10. Cookies and Similar Technologies
We use cookies (small files stored on your browser) and similar technologies to operate the websites, analyse traffic and, where applicable, display advertising. Categories of cookies used:
- Strictly necessary cookies: essential for navigation and security (e.g., language preference, CSRF protection). Do not require consent.
- Performance and analytics cookies: measure aggregate site usage (pages visited, session duration). Require consent when carrying persistent identifiers.
- Functionality cookies: remember user preferences across visits.
- Advertising cookies (blog): used by the Google AdSense network to display contextual ads. Require consent.
- You can accept or refuse non-essential cookies at any time through the consent banner or your browser settings. Refusal does not prevent access to public areas of the websites, but may limit some functionality.
- To manage Google advertising preferences, visit: https://adssettings.google.com.
11. Your Rights as a Data Subject
The LGPD (art. 18) and the GDPR (arts. 15 to 22) grant you, as a data subject, the following rights, which you may exercise free of charge and at any time:
- Confirmation of the existence of processing of your personal data;
- Access to the personal data being processed;
- Correction of incomplete, inaccurate or outdated data;
- Anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- Portability of data to another service or product provider, subject to trade and industrial secrets;
- Deletion of personal data processed based on consent, subject to legal retention requirements;
- Information about public and private entities with whom we share your data;
- Information about the possibility of not providing consent and the consequences of refusal;
- Withdrawal of consent at any time, without prejudice to the lawfulness of processing carried out prior to the withdrawal;
- Objection to processing carried out under a legal basis not requiring consent, in cases of non-compliance with the LGPD/GDPR;
- Right not to be subject to decisions based solely on automated processing that significantly affect your interests (LGPD art. 20 / GDPR art. 22);
- Right to lodge a complaint with the ANPD (Brazil) or with the competent supervisory authority in your country (GDPR art. 77).
12. How to Exercise Your Rights
To exercise any of the rights listed in section 11, simply send a substantiated request to our DPO at [email protected] (with a copy to [email protected]), providing:
- Full name and means of contact;
- Clear description of the right you wish to exercise;
- Proof of identity (to prevent fraud and protect your own data); and
- Any supporting documents.
- We will respond to your request within 15 (fifteen) days as required by LGPD art. 19, and within 30 (thirty) days as required by GDPR art. 12, with a possible extension for equally justified complexity.
- Handling the request is free of charge, except for manifestly unfounded or excessive requests, for which a reasonable fee may be charged.
13. Protection of Minors
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children (under 12 years old in Brazil / under 16 years old in the EU under GDPR art. 8) or from adolescents without the specific and highlighted consent of at least one parent or legal guardian, as required by LGPD art. 14 and GDPR art. 8. If we become aware that we have collected data from a minor without proper consent, the data will be deleted immediately. Parents or guardians who identify such a situation should contact us via the channel in section 12 to request deletion.
14. Automated Decisions and Profiling
We currently do not make decisions based solely on automated processing of personal data that produce legal effects or significantly affect your interests. Should we begin such processing in the future (e.g., personalised course recommendations), we will notify you in advance of the criteria used and guarantee your right to:
- Obtain a clear explanation of the criteria and procedures used in the automated decision;
- Request human review of decisions based solely on automated processing that affect your interests, under LGPD art. 20 and GDPR art. 22.
15. Complaints and Supervisory Authorities
Without prejudice to your right to contact us directly (section 12), you may lodge a complaint with the competent supervisory authorities:
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD): https://www.gov.br/anpd/
- European Union — the data protection supervisory authority of your country of residence. Full list available at: https://edpb.europa.eu/about-edpb/board/members_en
- United Kingdom — Information Commissioner's Office (ICO): https://ico.org.uk/
16. Google User Data (B2Tech AdConnect)
Our B2Tech AdConnect server (mcp-googleads.b2tech.io, hosted at gamcp.b2tech.io) connects to your Google Ads accounts on your behalf through Google OAuth 2.0.
- Scope requested: https://www.googleapis.com/auth/adwords. This is the only scope the Google Ads API accepts; no read-only or narrower alternative exists. We request it to list campaigns, ad groups, keywords and ads; read performance and conversion reports; research keywords; and create or update Search campaigns, budgets, ads and extensions — always at your explicit request through the AI assistant.
- Data we store: the OAuth refresh and access tokens issued for your Google account, kept encrypted (refresh tokens in Supabase, transient cache in Upstash). In local mode the refresh token stays in a 0600 file on your own machine. We do not warehouse your Google Ads account contents; data is read on demand to fulfil each request.
- Limited Use: B2Tech AdConnect's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We use Google user data only to provide and improve the features above; we do not sell it; we do not use it for advertising; we do not transfer it except as necessary to operate the service or as required by law; and humans do not read this data except with your consent, for security/debugging, or where legally required.
- Revoking access: you can disconnect at any time at https://myaccount.google.com/permissions, which invalidates our stored tokens.
17. Google User Data (B2Tech TagBridge)
Our B2Tech TagBridge server (gtmmcp.b2tech.io) connects to your Google Tag Manager accounts on your behalf through Google OAuth 2.0.
- Scopes requested: https://www.googleapis.com/auth/tagmanager.readonly, tagmanager.edit.containers, tagmanager.edit.containerversions, tagmanager.publish, tagmanager.manage.accounts, tagmanager.manage.users and tagmanager.delete.containers (plus openid, userinfo.email and userinfo.profile for authentication). We request this set to list and audit accounts, containers, workspaces, tags, triggers and variables; create and edit those elements in a workspace; and create versions and publish them to the site — always at your explicit request through the AI assistant. Destructive actions (deleting elements, disabling built-in variables, publishing) require explicit confirmation.
- Data we store: the OAuth refresh and access tokens issued for your Google account, kept encrypted (refresh tokens in Supabase with AES-256-GCM, transient cache in Upstash). We do not warehouse the contents of your Google Tag Manager containers; data is read on demand to fulfil each request.
- Limited Use: B2Tech TagBridge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We use Google user data only to provide and improve the features above; we do not sell it; we do not use it for advertising; we do not transfer it except as necessary to operate the service or as required by law; and humans do not read this data except with your consent, for security/debugging, or where legally required.
- Revoking access: you can disconnect at any time at https://myaccount.google.com/permissions, which invalidates our stored tokens.
18. Changes to this Policy
This Policy may be updated from time to time to reflect changes in our services, legal requirements or best practices. The latest version will always be available at b2tech.io/pt/privacy (Portuguese) and b2tech.io/en/privacy (English), with the date of last update indicated. Material changes will be communicated with reasonable advance notice, by e-mail to newsletter subscribers or through a prominent notice on the website. Continued use of the services after publication of the new version constitutes acceptance of the changes, except where the law requires new consent.
19. Contact
If you have questions, requests or complaints regarding this Policy or the processing of your personal data, please contact us:
- Data Protection Officer (DPO): [email protected]
- General inquiries: [email protected]
- Postal address: Rua Rio de Janeiro, 243 — Room 802, Centro, Belo Horizonte/MG, 30160-040, Brazil