Introduction
CESAR — Centro de Estudos e Sistemas Avançados do Recife (CNPJ 01.203.327/0001-23), headquartered at Rua Bione, 220, Bairro do Recife, Recife-PE, Brazil — operates the website cesar-us.site and a portfolio of technology, education, and innovation services. We act as the data controller for all personal data processed through this website and, where separately contracted, as a data processor on behalf of our institutional and corporate partners.
This Privacy Policy applies to every visitor, prospective student, partner, job applicant, or other individual whose personal data we receive through this website, through our contact and enrollment forms, or through direct communications with our team. It has been drafted to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR), Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018), and applicable guidance from the Autoridade Nacional de Proteção de Dados (ANPD).
By using our website or submitting any form on it, you acknowledge that you have read and understood this policy. If you do not agree, please refrain from providing personal data to us; however, note that some features of the site require data submission to function correctly.
Information We Collect
We collect personal data only to the extent necessary for the specific purpose being served. The categories of data we collect fall into two broad groups: data you provide directly, and data collected automatically when you browse our site.
2.1 Data You Provide Directly
- Contact form submissions. When you send us a message via the site's contact form, we collect your full name, email address, phone number (if supplied), company or institution name (if supplied), and the content of your message. This data is used solely to respond to your inquiry.
- Course and program inquiries. If you express interest in a CESAR Education program, we collect your name, email, professional background, and area of interest in order to provide accurate information and, where consented, to follow up by email or phone.
- Partnership and business-development requests. Organizations wishing to partner with CESAR Solutions or CESAR Ventures may submit a structured proposal form capturing the company name, contact person's name, email, phone number, sector, and a brief description of the proposed engagement.
- Newsletter subscriptions. If you subscribe to our newsletter or communications list, we collect your email address. You may unsubscribe at any time through the link included in every email we send.
- Recruitment applications. Job applicants provide a résumé/CV, cover letter, and contact details. This data is processed separately under our recruitment privacy notice, which is provided at the point of application.
2.2 Data Collected Automatically
- Usage and log data. Our web servers automatically record your IP address (anonymized where technically feasible), browser type and version, operating system, referring URL, pages visited, time on page, and the date and time of each request. This information is used for security monitoring and aggregate performance analysis.
- Cookies and similar technologies. We use first-party and third-party cookies, web beacons, and tracking pixels. A detailed description of each category, including how to manage your preferences, is provided in Section 4 below.
- Analytics data. We use Google Analytics 4 to understand how visitors interact with our content. This service processes anonymized identifiers and behavior signals — it does not, by default, collect your name or contact details. See Section 4 for more detail.
We never purchase, rent, or acquire personal data from third-party data brokers. Every piece of personal information we hold about you was provided by you directly or generated through your interaction with our website.
How We Use Your Information
We rely on one or more of the following legal bases for each processing activity: your freely given, specific, and informed consent; the performance of a contract (or steps taken at your request before entering a contract); compliance with a legal obligation; or our legitimate interests, where those interests are not overridden by your rights and freedoms.
- Responding to inquiries. We use the information submitted through our contact, enrollment, and partnership forms to respond accurately and promptly. Legal basis: legitimate interest / performance of pre-contractual steps.
- Service delivery. When you enroll in a program or commission a project through CESAR Solutions, we use your data to deliver, administer, and support that service, including billing and communications. Legal basis: performance of a contract.
- Marketing communications. With your prior consent, we send newsletters, event invitations, and relevant updates about CESAR's education programs and innovation ecosystem. You may withdraw consent at any time. Legal basis: consent.
- Website analytics and improvement. Anonymized behavioral data helps us identify usability issues, optimize content, and prioritize feature development. Legal basis: legitimate interest (we take steps to minimize privacy impact through IP anonymization and data aggregation).
- Advertising measurement. We use Google Ads conversion tracking to measure the effectiveness of our paid advertising campaigns. This involves placing a cookie on your device when you click an ad and later complete a conversion action. Legal basis: consent (managed through our cookie consent banner).
- Security and fraud prevention. Server log data and IP addresses are used to detect and prevent unauthorized access, denial-of-service attacks, and other malicious activity. Legal basis: legitimate interest / legal obligation.
- Legal compliance. We may process and retain data as required by Brazilian tax, accounting, or labor law, or in response to lawful requests from public authorities. Legal basis: legal obligation.
We do not use your personal data for automated decision-making or profiling in ways that produce legal or similarly significant effects on you without your explicit consent.
Cookies & Tracking Technologies
Cookies are small text files stored on your device when you visit a website. We use cookies for three distinct purposes: to keep the site functioning correctly, to understand aggregate usage patterns, and — with your consent — to measure the performance of our advertising campaigns.
4.1 Strictly Necessary Cookies
These cookies are required for the website to operate and cannot be switched off. They are typically set in response to actions you take, such as submitting a form or setting privacy preferences. No consent is required for this category.
4.2 Analytics Cookies
We deploy Google Analytics 4 (GA4) with IP anonymization enabled. GA4 uses a first-party cookie (_ga and related cookies) to distinguish unique sessions over time. The data collected — including pages viewed, session duration, device type, and referral source — is aggregated and does not identify you by name or email. Retention is set to 14 months on the Google servers. You may opt out globally by installing the Google Analytics Opt-out Browser Add-on.
4.3 Advertising & Measurement Cookies
With your explicit consent (captured through our cookie consent banner on first visit), we place a Google Ads conversion tag that allows us to record when a user who clicked one of our ads subsequently completed an inquiry form. This tag may also support remarketing lists. The data processed is pseudonymous and governed by Google's own privacy policies. You may manage your Google Ads settings at adssettings.google.com.
4.4 Managing Your Cookie Preferences
You can review and update your cookie preferences at any time by clicking the "Cookie Settings" link in the site footer. You may also control cookies through your browser settings — most browsers allow you to block, delete, or be notified before a cookie is set. Note that disabling certain cookies may affect how parts of the website function.
We do not use cross-site tracking or fingerprinting technologies, and we do not sell cookie-derived data to any third party for advertising purposes on their own platforms.
Sharing With Third Parties
CESAR does not sell, rent, or trade personal data. We share data only in the limited circumstances described below, and only with parties who are contractually bound to handle it in a manner consistent with this policy and applicable law.
- Service providers (data processors). We engage trusted vendors to help us operate: cloud hosting and infrastructure (servers located in Brazil and/or the EU); email delivery platforms; customer relationship management (CRM) software; and analytics tools. These vendors access personal data only as necessary to provide their service to us and may not use it for their own purposes.
- Google LLC. As described in Section 4, Google processes anonymized analytics and, where consented, advertising-measurement data on our behalf. Google is certified under the EU–US Data Privacy Framework. Data may be transferred to and processed in the United States subject to Standard Contractual Clauses (SCCs) and/or equivalent LGPD transfer mechanisms.
- Academic and government partners. CESAR collaborates with federal and state research agencies (such as FACEPE, CNPq, and FINEP), universities, and industry partners. Where a collaboration involves sharing participant data, we will obtain your separate consent and provide a specific data-sharing notice at the time.
- Legal and regulatory disclosure. We may disclose personal data to public authorities, courts, or law-enforcement agencies when required by Brazilian law or a lawful judicial order. We will notify you of such disclosure unless legally prohibited from doing so.
- Corporate restructuring. In the event of a merger, acquisition, or transfer of all or a substantial part of CESAR's activities, personal data may be transferred as part of that transaction. We will notify affected individuals before such a transfer takes place and, where required, seek fresh consent.
Data Retention
We retain personal data for no longer than is necessary to fulfil the purpose for which it was collected, to comply with our legal obligations, and to resolve any disputes or enforce our agreements. Our standard retention periods are:
- Contact form and general inquiry data. Retained for up to 24 months from the date of last interaction, after which records are deleted unless a contract has been entered into.
- Contracted service and enrollment data. Retained for 5 years from the conclusion of the service or program, in accordance with Brazilian accounting and tax requirements (Lei nº 10.406/2002 and applicable tax regulations).
- Marketing consent records. Email address and consent timestamp are retained for the duration of the subscription plus 3 years, to demonstrate valid consent should it be required.
- Web server logs. Retained for 6 months for security-monitoring purposes, then deleted.
- GA4 analytics data. Aggregated session data is retained for 14 months within the Google Analytics platform, as configured in our property settings.
- Recruitment data. Retained for 12 months following the conclusion of the selection process, or longer if required by labor law, allowing us to contact suitable candidates about future opportunities (with your consent).
At the end of the applicable retention period, personal data is either permanently deleted or anonymized so that it can no longer be linked to an identifiable individual.
Data Security
CESAR takes the security of personal data seriously and implements technical and organizational measures proportionate to the risks involved. Key safeguards include:
- Encryption in transit. All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. Our site enforces HTTPS sitewide.
- Access controls. Personal data held in our systems is accessible only to staff and contractors who require it to perform their role. Access is governed by role-based permission policies and reviewed periodically.
- Infrastructure security. Our hosting infrastructure is managed by ISO 27001-certified cloud providers. We apply security patches promptly and conduct regular vulnerability assessments.
- Incident response. We maintain a documented data-breach response procedure. Should a breach occur that is likely to result in a risk to individuals' rights and freedoms, we will notify the ANPD within 72 hours of becoming aware of it (as required by the LGPD) and will inform affected individuals without undue delay.
- Staff training. All CESAR employees who handle personal data receive data-protection training as part of onboarding and on a recurring annual basis.
While we apply industry-standard safeguards, no method of transmission over the internet is 100% secure. We encourage you to contact us promptly at contato@cesar-us.site if you have reason to believe that your interaction with us has been compromised.
Your Rights
Under the LGPD and, where applicable, the GDPR, you hold a set of meaningful rights over your personal data. CESAR is committed to honoring these rights promptly and without charge. Below is a plain-language summary of each right and what it means in practice.
Right of Access
You may request a copy of the personal data we hold about you, along with information about how and why we process it, and with whom it has been shared.
Right to Correction
If any information we hold about you is inaccurate, incomplete, or out of date, you have the right to request that we correct or update it without delay.
Right to Deletion
You may request that we delete your personal data. We will comply unless we are required to retain it by law or to fulfil a contractual obligation to you.
Right to Data Portability
You may ask us to provide your personal data in a structured, commonly used, machine-readable format for transfer to another organization, where this is technically feasible.
Right to Object
You may object at any time to our processing of your personal data for direct marketing purposes. You also have the right to object to processing based on our legitimate interests, on grounds relating to your particular situation.
Right to Restriction
In certain circumstances — for example, while we verify the accuracy of contested data — you may request that we restrict processing to storage only, without further use.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
Right Not to Be Profiled
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you, unless you have given explicit consent.
How to Exercise Your Rights
Submit your request by email to contato@cesar-us.site with the subject line "Data Subject Request." Please include your full name, the email address used when contacting us, and a description of the right you wish to exercise. We may ask you to confirm your identity before processing the request. We will respond within 15 business days (as required by the LGPD) or within one calendar month (GDPR), and will explain clearly if any extension is required.
If you believe your rights have not been adequately addressed, you have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd, or, for EU residents, with your national supervisory authority.
Children's Privacy
This website and our services are directed at adults and, in the context of education, at individuals aged 16 and above. We do not knowingly collect personal data from children under the age of 16 (or under 13 in jurisdictions where that age threshold applies).
Where a processing activity may involve minors — for example, a school-partnership program or a youth-oriented innovation initiative — we require verified parental or guardian consent prior to collecting any data from the minor, and we apply heightened data-minimization standards to such data.
If you believe that a child under 16 has submitted personal data to us without appropriate parental consent, please contact us immediately at contato@cesar-us.site. We will investigate and delete the data as promptly as possible.
Changes to This Policy
The regulatory and technical landscape around data privacy continues to evolve, and we review this policy at least once per year — or sooner following any material change to our services, data processing activities, or applicable legal requirements.
When we make changes, we will update the "Last updated" date at the top of this page. If a change is material — meaning it significantly affects your rights or the way we handle your data — we will notify you by posting a prominent notice on the homepage and, where we hold your email address under a current communication relationship, by sending a direct notification.
Your continued use of the website after the effective date of a revised policy constitutes your acknowledgment of the changes. We encourage you to review this page periodically so you are always aware of our current practices.
Contact & Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise one of your rights, or have a concern about how your data is being handled, please reach out to us directly. We take all privacy inquiries seriously and will respond within the timescales set out in Section 8.
Get in Touch
Our team is available to address your privacy questions and data-subject requests. For formal legal notices, please use the postal address below and mark your correspondence "Privacy — Legal Notice."
CNPJ 01.203.327/0001-23
Recife – PE, Brazil