Data controller
- Controller
- HS Group Ltda. (HenSistemas)
- CNPJ
- 36.838.123/0001-43
- Address
- Rua Aderson Bezerro, 315, Jardim Roseira, Ibitinga, SP, 14940-844, Brazil
- sales@hensistemas.com
- Telephones
- +55 16 98127-6516 · +55 11 3197-2522
As of this review, HenSistemas has not appointed a person as its data protection officer (the “encarregado” of Article 41 of the LGPD). The channel of communication with data subjects and with the Brazilian National Data Protection Authority (ANPD) is the email address above, which takes any question about this policy or about your rights.
Purposes, legal bases and retention
This site processes personal data in four situations, and only those four. The first three happen whenever somebody writes to HenSistemas, subscribes to the instrumentation notes or simply opens a page; the fourth — advertising — is off by default and only comes into existence once the visitor has expressly accepted it. Each has its own legal basis, among those of Article 7 of the LGPD, and its own period.
| Purpose | Legal basis (LGPD) | Retention |
|---|---|---|
| Answering a quote request or a contact message | Preliminary procedures related to a contract, at the request of the data subject (Art. 7, V), and the legitimate interest of the controller in replying to whoever writes (Art. 7, IX) | For as long as the inquiry is being handled and the reply may have to be accounted for; the public link to the request stops working 90 days after it was sent |
| Sending the instrumentation notes (newsletter), with double opt-in | Consent of the data subject (Art. 7, I) | Until the subscriber leaves the list or asks for deletion; the unsubscribe link is in every message and on the newsletter page |
| Measuring the audience of the site to learn which pages are useful | Legitimate interest of the controller in understanding the use of its own site, measured in aggregate and without identifying people (Art. 7, IX) | Detailed record 90 days; aggregated daily totals 25 months |
| Advertising and campaign measurement through the Meta Pixel — optional, and off by default | Consent of the visitor (Art. 7, I), asked for before anything is stored on or read from the device | Exists only after acceptance: the choice is kept in this browser for 180 days and the cookies Meta sets last up to 90 days. HenSistemas keeps no data of its own from this processing |
Quote requests and contact messages
When you send a quote request or a contact message, what is stored is what you typed into the form:
- Name; company, telephone and country, which are optional fields; email address; the message you wrote.
- The channel you prefer to be answered on (email or WhatsApp) and the language the page was in.
- For quote requests, the list of references and quantities you had gathered, with the product title and variant as they stood when you sent it.
- The consent text you accepted and the moment you accepted it — the record of what you agreed to, stored verbatim.
- A reference code for the request, the date it was sent and the first page of the site visited in that browser tab — or the page of the form, when that first page cannot be recorded.
- The source, medium and campaign of the link that brought you, accepted only from a known list of names, and the domain — never the full address — of the site you came from.
- If the link that brought you carried a click identifier of an ad or of a social network (gclid, gbraid, wbraid, msclkid, fbclid or li_fat_id), the request keeps only the source and the medium it stands for — source “google” and medium “cpc” for a Google ad, for instance — and never its value or the name of the identifier. A page of this site opened in another tab from another page of the site is recorded as internal navigation.
To that the sales team adds its own work on the request: the status of the inquiry — new, in progress, answered, won, lost, closed or unwanted — and internal notes, in free text, about the request and about the conversation that followed. They are written by the team, never by the person who sent the form, and they exist only inside the administration area: they never appear on the public link to the request and are never passed to a third party. Like any other data in this processing, they can be accessed and corrected under the rights described below.
The IP address is not stored anywhere in this processing. It is read by the network when the form is sent, turned into a cryptographic digest in memory so that repeated submissions can be limited, and discarded: no table of this site has a column to hold it. It is also passed to Cloudflare in the anti-robot validation request, which is what lets that check tell a person from an automated program; there it is handled by Cloudflare, as a processor, for that purpose alone.
Filling in the form is voluntary, but without a name, an email address and a message no reply is possible. On submission the request is recorded and an internal message carrying it is sent to the mailboxes HenSistemas designates to handle it; no copy goes to any third party for its own use. That internal message stays in the site’s sending queue, carrying the content of the request, so that it can be sent again if delivery fails; the queue is not purged automatically, so the copy is kept for the same period as the request — for as long as the inquiry is being handled. When a request is deleted, at the data subject’s request or by decision of the team, the internal messages tied to it are deleted in the same operation.
Every request gets a link of its own, carrying a long random code, where the sender can see its status and its lines. That link stops working 90 days after the request was sent and never shows contact details.
Newsletter
Subscription to the instrumentation notes uses double opt-in: after giving the address you receive a message with a link, and only following it makes the subscription active. An address that never confirms receives nothing.
- The email address and the language chosen.
- The status of the subscription and the dates of subscription, confirmation and unsubscription.
- The consent text accepted and the moment it was accepted.
- The form it was subscribed from and the same sanitized attribution described above.
You may leave the list at any time through the link in every message, with no reason given. It takes effect immediately and the record is kept only so that nothing is sent again.
If you would rather have full deletion than a simple unsubscription, ask for it at the contact address: the subscriber record is deleted and, with it, any messages still queued for that address. All that remains is an internal audit line recording that the operation happened and who performed it, without the address.
Audience measurement
We count visits to learn which pages are useful. The measurement is the site’s own and stays in its database, on Cloudflare servers in North America; it is aggregated, it uses no cookies, it stores no IP address, it follows nobody between sites and it is shared with nobody. There is no way to link a visit to a quote request, a contact message or a subscription.
What carries that measurement on the device is a random identifier held in the session storage of the browser tab, which disappears when the tab is closed. The full list of what is measured, what is discarded and how long it is kept is in this section and in the cookies and similar technologies policy.
- Measured: the page, reduced to a normalized address from a closed list; the language; the country reported by the network; whether the device is mobile or desktop; relevant clicks; the search term, truncated and cleaned; and the origin of the visit reduced to a domain.
- Not measured: the IP address, the full browser identification, any name, address or free text, the full address you came from, and any parameter of the address.
- Pages whose link carries a code — the page of a request and the newsletter confirmation and unsubscribe pages — do not even load the measurement script.
- Automated browsers, such as search robots and audit tools, are not counted, and neither is the browser of anyone who has opened the administration area, which is marked by the hen.analytics.measure.v1 entry.
- The detailed record is deleted after 90 days, once it has become daily totals that are kept for 25 months and no longer contain the tab identifier.
Because it identifies nobody, this measurement cannot find or delete one particular person’s visit: nothing links it to them. Anyone who would rather not be counted at all can block, with a browser content blocker, what the site sends to the /api/events address, losing no feature of the site.
Optional product history
If you turn on product history, the site stores in this browser the references of the last eight products viewed and the date of each visit, for up to 30 days; the permission itself also expires after 30 days. It uses local storage (hen.recent-products.v1 and hen.recent-products.consent.v1), without creating an account or following browsing on other sites. To display the list, the references are sent to the site’s catalog to obtain current information; no history profile is created on the server. You can clear the history, or turn it off and erase it, under “History” at the bottom of the public pages. The history does not travel from one device to another.
Advertising and campaign measurement
Besides the site’s own measurement described above, the site can load the Meta Pixel to measure how Facebook and Instagram advertising performs. It is a separate processing, optional and off by default: it only comes into existence when, at the same time, an administrator enables it in the administration area with a valid identifier and the visitor expressly accepts it on the page itself. As of the last review of this policy, it was switched off.
Acceptance is asked for in a notice shown on the page, with two equivalent buttons — accept advertising or reject advertising. Before acceptance nothing is requested from Meta: no script, no tracking image, no early connection to its domain. The choice is kept in the local storage of this browser for 180 days, under the entry “hen.marketing-consent.v1”, and can be reviewed at any time through the advertising preferences button.
Withdrawing acceptance takes effect immediately: the revocation instruction is sent to Meta, anything still queued is discarded, the script is removed from the page, the _fbp and _fbc cookies are deleted from this site’s domain and the page is reloaded so that none of Meta’s code stays in memory. A rejection also applies to the other tabs open at the same time. An acceptance is tied to the identifier that was active when it was given: if that identifier is changed or disabled, the acceptance no longer holds and the question is asked again — a rejection, by contrast, still holds.
- Where it may run: the home page, the root of the product type axis, the category pages of the three axes, product pages, the brand index and the brand pages, the blog with its categories and articles, and the “About HenSistemas” page.
- Where it never runs: the administration area, the quote and contact pages, the search, the newsletter page, the roots of the applications and measurements axes, the error pages, these four legal pages, and any address carrying a code — the page of a request and the newsletter confirmation and unsubscribe pages. The exclusions for addresses carrying a code are exactly those of the site’s own measurement.
- The integration also refuses to start if the address of the page, or the address the visitor came from, carries a fragment or a parameter outside the known list (utm_source, utm_medium, utm_campaign, utm_content, utm_term and fbclid): that is what stops Meta’s script from reading anything unforeseen out of the address.
- What is reported: the page view and, on a product page, the view of that product identified by its public reference. No form values, no advanced matching of personal data and no conversion events are sent — a quote request, a contact message or a subscription is never reported to Meta.
The legal basis for this processing is the consent of the visitor, given expressly and prominently (Articles 7, I, and 8 of the LGPD). It is not the legitimate interest that supports audience measurement: without acceptance nothing runs, and withdrawing acceptance is as easy as giving it.
Meta is the controller of the processing it carries out on the data it receives this way — in particular to link it to an account and to measure and target its advertising — and that processing is governed by Meta’s privacy policy, at www.facebook.com/privacy/policy/. The _fbp and _fbc cookies that result are set by Meta and last up to 90 days; rejecting deletes them from this site’s domain. HenSistemas keeps no data of its own from this integration and has no way of linking what Meta receives to a request, a contact message or a subscription.
Sharing and processors
Data is not sold or rented. Apart from the advertising and video cases — where, and only if the visitor accepts advertising or clicks to play a video, Meta or Google receive browsing data and also handle it for their own purposes, as controllers — nothing is shared with third parties for their own purposes. Everything else is handled by those who provide the technical services that make the site work, as processors and on the instructions of HenSistemas:
| Who | What for | Where |
|---|---|---|
| Cloudflare | Hosting of the site, database of requests and subscriptions, storage of images, documents and backups, sending of the site’s email messages, and anti-robot verification of the forms (Turnstile) | Cloudflare’s global network, which serves each visit from the nearest point; the database and the file storage are on servers in eastern North America |
| Providers of the destination mailboxes | Receipt and keeping of the internal messages sent by the forms, in the mailboxes HenSistemas designates to handle them | Set by each email provider |
| GitHub | Running the daily backup routine of the database: the file passes through the routine’s temporary machine and is deleted at the end of each run | GitHub’s infrastructure, as GitHub sets it |
| Meta | Advertising pixel, on the content pages listed in the section on advertising and only if the visitor accepts it: it receives the browsing data of that visit and handles it for its own purposes, as a controller and not as a processor | Determined by Meta in its own privacy policy (www.facebook.com/privacy/policy/), including processing outside Brazil |
| Google (YouTube) | Player of the videos on product pages, loaded only when the visitor clicks to play: it receives the technical data of the connection, such as the IP address and the browser, and handles it for its own purposes, as a controller | Determined by Google in its own privacy policy (policies.google.com/privacy), including processing outside Brazil |
Data may also be disclosed to public authorities where a legal rule or a court order requires it.
The anti-robot verification of the forms is run by Cloudflare at the moment of submission and exists only to tell a person from an automated program. It builds no profiles and is not used for advertising.
International data transfer
The data this site processes is held on servers outside Brazil: the database of requests and subscriptions, the file storage and the backups are on Cloudflare servers in eastern North America, and each visit is served by Cloudflare’s global network from the point nearest to whoever is visiting. The mailboxes that receive the site’s messages and, when the visitor accepts advertising or plays a video, Meta and Google may also process data outside Brazil.
There is therefore an international transfer of personal data. It rests on the cases set out in Article 33 of the LGPD — in particular the contractual safeguards the providers offer for the protection of the data they process and, for a quote request or a contact message, the need to carry out preliminary procedures related to a contract at the data subject’s request — and on the security measures described in this policy. You can ask for information about those safeguards at the contact address.
Security
The site is served only over an encrypted connection. Access to the administration area is restricted to authorized people and protected by authentication; exports and queries in that area are written to an audit trail that stores no contact details.
The database is copied every day to a Cloudflare backup store with no public access, and each copy is kept for about 30 days before it is deleted. Data deleted from the site may therefore still exist in the backups during that period, used for nothing but restoring the site after a failure.
Public forms are protected by anti-robot verification and by submission limits. Even so, no transmission over the Internet is entirely free of risk; in the event of a security incident that may cause relevant risk or harm to data subjects, HenSistemas notifies the ANPD and the data subjects affected, as Article 48 of the LGPD requires.
Your rights
As a data subject you may exercise at any time the rights set out in Article 18 of the LGPD:
- Confirmation and access
- Confirm whether we process data about you and access it, with a copy.
- Correction
- Correct incomplete, inaccurate or out-of-date data.
- Anonymization, blocking or deletion
- Ask for data that is unnecessary, excessive or processed in breach of the LGPD to be anonymized, blocked or deleted.
- Portability
- Ask for your data to be transferred to another provider of a service or product, on express request, as the ANPD’s regulations provide.
- Deletion of data processed on consent
- Ask for the data processed on the basis of your consent — the newsletter subscription and the acceptance of advertising — to be deleted, except where Article 16 of the LGPD allows it to be kept.
- Information on sharing
- Find out which public and private entities your data has been shared with.
- Information on consent
- Be told that you may refuse consent and what follows from refusing: declining the newsletter or advertising prevents no other use of the site.
- Withdrawal of consent
- Withdraw the consent given at any time, free of charge and easily, without affecting what was processed before.
- Objection
- Object to processing carried out on a basis other than consent, where it breaches the LGPD.
To exercise any of these rights, write to sales@hensistemas.com or to Rua Aderson Bezerro, 315, Jardim Roseira, Ibitinga, SP, 14940-844, Brazil, saying which right you wish to exercise. It is free of charge. Confirmation that data is processed and access to it are given in simplified form straight away, or by a clear and complete statement within 15 days of the request (Article 19 of the LGPD); where another request cannot be met straight away, you receive a reply giving the reasons (Article 18, § 4). Proof of the identity of the person asking may be requested where there is reasonable doubt.
You also have the right to petition about your data before the Brazilian National Data Protection Authority (ANPD, www.gov.br/anpd) and before consumer protection bodies. Anyone using the site from outside Brazil exercises the same rights through the same channels.
Automated decisions and minors
No decision affecting the interests of the data subject is taken solely on the basis of automated processing of personal data, including profiling (Article 20 of the LGPD).
The site is aimed at professionals and is not intended for children or adolescents. No data about them is knowingly collected; where any is found, the record is deleted.
Changes to this policy
This policy may be updated whenever the processing described here or the applicable law changes. The version in force is the one published on this page, carrying the review date shown at the top.