Spotlight

Privacy Policy

Last updated: April 2026

This Privacy Policy describes how YAITEC Solutions collects, uses, and protects your personal data in compliance with the Brazilian General Data Protection Law (LGPD — Law 13.709/2018).

1

Who We Are

YAITEC Solutions is a technology company specializing in artificial intelligence solutions, software development, and digital consulting.
Contact: contato@yaitec.com
Website: https://www.yaitec.com
Data Protection Officer (DPO): contato@yaitec.com

2

Data We Collect

Contact Form (/contact): Name, email, message.

Newsletter: Email address.

Careers Form (/carreiras): Name, email, phone (optional), position, seniority, LinkedIn URL (optional), resume file (PDF/DOC/DOCX).

Cookies and Browsing Data: Pages visited, time on page, device type, browser, approximate location (city/country). Collected via Google Analytics 4 and Google Ads only after your explicit consent through our cookie banner.

Security Data: Cloudflare Turnstile CAPTCHA tokens for spam prevention (essential cookies, no consent required).

3

Purpose of Data Processing

  • Respond to your contact requests and inquiries
  • Send newsletter communications (only with your consent)
  • Process job applications and conduct recruitment
  • Analyze website usage to improve our services
  • Display relevant advertisements (only with your consent)
  • Prevent spam and ensure website security
4

Legal Basis

We process your data based on the following legal bases under Article 7 of the LGPD:

  • Consent (Art. 7, I): Newsletter subscription, analytics and marketing cookies, career form submission
  • Legitimate Interest (Art. 7, IX): Responding to contact form inquiries, website security
  • Pre-contractual Measures (Art. 7, V): Processing job applications at your request
5

Data Sharing

We do not sell your personal data. We may share data with the following service providers, strictly for the purposes described:

  • Google LLC: Analytics (GA4) and advertising (Google Ads) — only after your consent via cookie banner
  • Cloudflare: Security (Turnstile CAPTCHA) — essential service, no consent required

These providers have their own privacy policies and comply with applicable data protection regulations.

6

Cookies

Our website uses cookies organized in three categories:

  • Strictly Necessary: Essential for the site to work (security, session). Always active.
  • Analytics: Google Analytics 4 — helps us understand how visitors use the site. Requires your consent.
  • Marketing: Google Ads — enables relevant ad display and remarketing. Requires your consent.

You can manage your cookie preferences at any time by clicking the cookie icon at the bottom left of the page, or via the "Manage preferences" option in the cookie banner. Analytics and marketing cookies are blocked by default until you give consent (Google Consent Mode v2).

7

Your Rights

Under the LGPD (Articles 17-22), you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Portability: Request transfer of your data to another service provider
  • Revocation: Withdraw your consent at any time
  • Information: Know which entities your data has been shared with
  • Objection: Object to data processing that violates the LGPD
8

How to Exercise Your Rights

To exercise any of the rights listed above, send an email to:

contato@yaitec.com

Please include your full name and a description of your request. We will respond within 15 business days.

9

Data Retention

  • Contact form data: Retained for up to 12 months after the last interaction
  • Newsletter subscriptions: Retained until you unsubscribe
  • Career applications: Retained for up to 12 months after the position is filled, then deleted
  • Analytics data: Retained for 14 months (Google Analytics default)
  • Cookie preferences: Retained for 12 months
10

Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page indicates when the latest revision was made. We recommend reviewing this page periodically.

11

Third-Party Integrations: Google APIs

Some optional features of YAITEC Solutions integrate with Google APIs (specifically Google Calendar) to enable scheduling capabilities in our WhatsApp chatbot. This section describes how we access, use, and protect your Google data when you choose to enable this integration. YAITEC Solutions' use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Google API Scopes Accessed

  • userinfo.email — to identify which Google account is connected to our scheduling system. The email is displayed in the WhatsApp Manager settings interface so users can confirm which Google Calendar is linked.
  • calendar.freebusy — to check your calendar availability (free/busy intervals only) and present open time slots to clients requesting appointments via WhatsApp. We do not read the content of events — only the busy/free intervals.
  • calendar.events.owned — to create appointment events on calendars you own when a client confirms a scheduling request through the WhatsApp chatbot. We limit to owned calendars — never shared or secondary calendars.

Storage and Security

  • Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with unique initialization vectors (IV) per token
  • All communication between our servers and Google APIs is transmitted over HTTPS (TLS)
  • Only the scheduling subsystem accesses Google Calendar data — no other part of the application reads or stores calendar information

Data Retention

  • Google OAuth tokens are stored only while the integration is active — immediately deleted when the user disconnects
  • No calendar event data is stored locally; events are created directly on Google Calendar via the API
  • Availability queries are performed in real-time — no calendar data is cached

Limited Use — Data We Will NOT Access or Share

  • Google user data is NOT sold to third parties
  • Google user data is NOT used for advertising, marketing, or analytics
  • Google user data is NOT used to train generalized machine learning models
  • No human reviews Google Calendar content unless explicitly requested by the user for support purposes

Revocation

  • You can disconnect Google Calendar from the application settings at any time — all tokens are immediately deleted from our database
  • You can also revoke access directly at myaccount.google.com/permissions
  • After disconnection, no Google data remains in our systems
12

Contact

If you have any questions about this Privacy Policy or about how we handle your data, please contact us:

YAITEC Solutions

Email: contato@yaitec.com

WhatsApp: +55 11 94255-6621

Website: www.yaitec.com

This policy is governed by the Brazilian General Data Protection Law (LGPD — Law 13.709/2018). For complaints, you may also contact the National Data Protection Authority (ANPD) at www.gov.br/anpd.

Chatbot
Chatbot

Yalo Chatbot

Hello! My name is Yalo! Feel free to ask me any questions.

Get AI Insights Delivered

Subscribe to our newsletter and receive expert AI tips, industry trends, and exclusive content straight to your inbox.

By subscribing, you authorize us to send communications via email. Privacy Policy.

You're In!

Welcome aboard! You'll start receiving our AI insights soon.