Privacy and data protection
Privacy Policy
This document explains which personal data DMX collects, why it collects them, with whom it shares them, how long it keeps them and how you exercise your rights as a data subject. Written to be read — not to be accepted without reading.
Table of contents — 18 sections
- 01 Who processes your data
- 02 Data Protection Officer (DPO)
- 03 Who this applies to
- 04 Data we collect
- 05 Purposes and legal bases
- 06 Cookies and tracking
- 07 Who we share with
- 08 International transfer
- 09 Retention period
- 10 Information security
- 11 Your rights
- 12 How to exercise your rights
- 13 Automated decisions
- 14 Children and adolescents
- 15 Security incidents
- 16 Data in client projects
- 17 Changes to this policy
- 18 Contact and ANPD
DMX builds platforms that process critical data from agricultural, environmental and regulatory operations. Handling data with rigor is part of our work — and it also applies to the data we receive from you. This policy describes, in plain language, how that happens.
01 Who processes your data
The controller of the personal data processed through this website is:
- Legal name
- DMX Design e Desenvolvimento Ltda.
- CNPJ
- 21.946.075/0001-30
- Address
- Av. Nossa Sra. de Fátima, 240, 4º andar — Vila Israel, Americana/SP, Brazil
- General e-mail
- contato@dmxdesign.com.br
- Phone / WhatsApp
- (19) 99921-4663
- Website
- dmxdesign.com.br
Throughout this document, “DMX”, “we” and “our” refer to this company. “You” and “data subject” refer to the natural person to whom the personal data relate.
02 Data Protection Officer (DPO)
In compliance with art. 41 of the LGPD (Brazilian General Data Protection Law), DMX maintains a channel to receive communications from data subjects and from the National Data Protection Authority (ANPD).
Data Protection Officer channel
privacidade@dmxdesign.com.br
You may also send requests by mail to the address indicated in
section 01, addressed to the Personal Data Protection Officer.
03 Who this policy applies to
This policy applies to the processing of personal data of:
- Visitors to this website, including those who fill out contact forms or strategic diagnosis request forms;
- Representatives of clients and prospective clients with whom DMX interacts in the course of its business activities;
- Suppliers, partners and service providers, with respect to the data of their representatives;
- Job applicants, when they submit a résumé through DMX channels.
This policy does not apply to the processing of data that DMX carries out as a processor, on behalf and by order of its clients, within the platforms it develops and maintains. That scenario is addressed in section 16.
04 Personal data we collect
4.1. Data you provide to us
When you fill out the strategic diagnosis request form or contact us through our channels, we collect:
- Full name;
- Corporate e-mail;
- Phone / WhatsApp;
- Company and job title;
- Main challenge selected and, when filled in, the free-text field of context about your operation;
- Consent record: date, time and content of the text accepted.
We do not request sensitive data. We ask that you do not include in the free context field any information about health, racial or ethnic origin, religious belief, political opinion, union membership, genetic or biometric data, sex life or sexual orientation — nor confidential data of your company. For confidential technical discussions, we sign an NDA before the conversation.
4.2. Data collected automatically
As you browse this website, we collect, through our own and third-party technologies:
- IP address and access logs
- IP address, date and time of each access to the application, kept under the terms of art. 15 of Law No. 12.965/2014 (Brazilian Internet Civil Framework).
- Device and browser data
- Type and version of browser, operating system, screen resolution and configured language.
- Source and campaign data
-
Source page and referral URL (referrer), as well as the campaign parameters
present in the access address:
utm_source,utm_medium,utm_campaign,utm_termandutm_content. - Page interaction data
- Pages visited, time spent, scroll depth, button clicks and form completion steps.
- Cookie and advertising identifiers
- Identifiers stored on your device by the tools described in section 06.
4.3. Data from public and third-party sources
To qualify business opportunities, we may supplement the information you provided with data from public and professional sources — such as your company's institutional website, professional social networks and public CNPJ databases. We use only professional-context data, under the legal basis of legitimate interest.
05 Purposes and legal bases
The LGPD requires that all processing have a defined purpose and a specific legal basis (arts. 6 and 7). The table below shows this correspondence.
| Purpose | Data used | Legal basis |
|---|---|---|
| Respond to your diagnosis request and conduct the business contact | Name, e-mail, phone, company, job title, challenge and context | Art. 7, I |
| Technically prepare the conversation and direct you to the appropriate specialist | Company, job title, challenge, context and data from public sources | Legitimate interest Art. 7, IX |
| Perform contracts, issue proposals, invoices and billing | Identification and contact data of representatives | Contract performance Art. 7, V |
| Send marketing communications, technical content and event invitations | Name, e-mail and company | Art. 7, I — revocable at any time |
| Measure audience, understand traffic sources and improve the website | Browsing data, analytics cookies and campaign parameters | Art. 7, I |
| Serve and measure ads and remarketing | Cookie identifiers and advertising identifiers | Art. 7, I |
| Ensure website security, prevent fraud and form abuse | IP, access logs and technical device data | Legitimate interest Art. 7, IX |
| Keep records of access to the application | IP, date and time of access | Legal obligation Art. 7, II — Internet Civil Framework, art. 15 |
| Comply with tax, accounting and regulatory obligations | Contractual and billing data | Legal obligation Art. 7, II |
| Exercise rights in judicial, administrative or arbitration proceedings | Data strictly necessary to the case | Exercise of rights Art. 7, VI |
| Evaluate job applications | Data from the résumé submitted | Art. 7, I |
Swipe the table sideways to see all columns.
When processing is based on legitimate interest, DMX assesses in advance whether the purpose is legitimate, whether the processing is necessary and whether your expectations and fundamental rights are preserved. You may request information about this assessment through the Data Protection Officer channel.
07 Who we share your data with
DMX does not sell personal data and does not transfer them to third parties for those third parties' own use. Sharing occurs only with processors who provide services to us, under contract and instruction, and in the legal cases below.
| Recipient | Role | Data | Location |
|---|---|---|---|
| Pipedrive | CRM — management of the commercial relationship and contact history | Name, e-mail, phone, company, job title, challenge, context and source | European Union / United States |
| Google (Analytics 4, Tag Manager and Fonts) | Audience measurement, tag management and font delivery | Browsing data, cookie identifiers and IP | United States / Ireland |
| Meta Platforms | Ad serving and measurement, remarketing | Cookie identifiers and browsing events | United States / Ireland |
| Cloud infrastructure provider | Hosting of the website and application environments | All data transmitted to the website, including access logs | Brazil and/or United States, according to the contracted region |
| Corporate e-mail provider | E-mail communication with data subjects and clients | Message content and contact data | United States / Brazil |
| Legal and accounting advisors | Compliance with legal obligations and defense of rights | Contractual and billing data | Brazil |
| Public authorities | Compliance with a court order, request from a competent authority or legal obligation | Strictly the data required | Brazil |
Swipe the table sideways to see all columns.
In the event of corporate reorganization, merger, acquisition or sale of assets, personal data may be transferred to the successor, who will be subject to this policy. We will notify data subjects whenever there is a relevant change in the purpose of the processing.
08 International data transfer
Some of our suppliers are based in or operate servers outside Brazil. This constitutes an international data transfer, permitted by arts. 33 to 36 of the LGPD.
In these situations, we adopt at least one of the following safeguards:
- Transfer to countries or bodies with an adequate level of protection recognized by the ANPD;
- Entering into specific or standard contractual clauses for data protection with the supplier;
- Verification of the supplier's certifications, policies and technical measures before contracting;
- Specific and prominent consent of the data subject, when it is the only applicable basis.
You may request information about the safeguards adopted for a specific supplier through the Data Protection Officer channel.
09 How long we keep your data
We keep personal data only for as long as necessary to fulfill the stated purposes, observing the legal time limits.
| Category | Period | Criterion |
|---|---|---|
| Access logs of the application | 6 months | Minimum period under art. 15 of the Brazilian Internet Civil Framework |
| Leads that did not become clients | Up to 24 months after the last contact | Typical maturation period for technology decisions in agribusiness; renewed with each new interaction |
| Marketing communications base | Until consent is withdrawn | Immediate deletion or anonymization after the unsubscribe request |
| Contractual and tax data | 5 years after the end of the contract | Statute of limitations and tax and accounting obligations |
| Consent records | 5 years after withdrawal | Evidence of LGPD compliance before the ANPD |
| Applicant résumés | 12 months | Consideration in future selection processes; extendable with new consent |
Swipe the table sideways to see all columns.
Once the period ends, the data are securely deleted or anonymized irreversibly, in which case they cease to be personal data and may be kept for statistical purposes.
10 Information security
DMX adopts technical and administrative measures to protect personal data against unauthorized access, loss, alteration and improper disclosure. Among them:
- Encryption in transit via TLS on all pages and form submissions;
- Role-based access control, granted under the principle of least privilege;
- Multi-factor authentication in corporate systems and cloud environments;
- Segregation of environments for development, staging and production;
- Audit logging of accesses and changes to databases;
- Supplier assessment and data protection clauses in contracts;
- Backup routine and restoration tests;
- Periodic training of the team in data protection and security.
No security measure is absolute. If you identify a vulnerability on this website or on any DMX platform, write to privacidade@dmxdesign.com.br. We analyze every communication received in good faith and take no measures against those who report responsibly.
11 Your rights as a data subject
Art. 18 of the LGPD guarantees you the rights below, exercisable free of charge and at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before it, nor does it prevent the retention of data whose keeping is required by law or necessary for the exercise of rights.
12 How to exercise your rights
- Send your request to privacidade@dmxdesign.com.br, describing which right you wish to exercise.
- We confirm receipt and, if necessary, request additional information to confirm your identity — an essential step so as not to disclose data to the wrong person.
- We respond within 15 days from receipt, the period under art. 19, II of the LGPD. For requests to confirm existence or for simplified access, we respond immediately, in a simplified format, when possible.
- If the request cannot be fulfilled, we inform you of the reasons of fact or law that justify the denial.
To speed up handling
Provide the full name and the e-mail you used when contacting DMX, the right you wish to exercise and, if you know it, the channel through which your data were collected (website form, event, referral). You do not need to justify the request.
13 Automated decisions and profiles
DMX does not make decisions solely by automated means that produce legal effects or significantly impact your interests.
We use automated rules only to organize service — for example, to direct your request to the specialist with the appropriate technical profile, based on the job title and challenge you provided. All commercial and technical evaluation is conducted by people. Should there be any automated decision with a relevant effect, you may request review under the terms of art. 20 of the LGPD.
14 Data of children and adolescents
This website and DMX's services are intended for professionals and organizations, not for those under 18 years of age. We do not intentionally collect data from children or adolescents.
If we identify or are informed that we have received data from minors without the specific and prominent consent of at least one of the parents or legal guardian — a requirement of art. 14 of the LGPD —, we will delete such data. Communications to this effect should be sent to the Data Protection Officer channel.
15 Security incidents
DMX maintains a response plan for incidents involving personal data. Upon confirming the occurrence of an incident that may result in relevant risk or harm to data subjects, we will notify the ANPD and the affected data subjects within a reasonable time, in accordance with art. 48 of the LGPD, informing:
- the nature of the personal data involved;
- the information about the affected data subjects;
- the technical and security measures adopted to protect the data;
- the risks related to the incident;
- the reasons for any delay in the communication;
- the measures adopted or that will be adopted to reverse or mitigate the effects.
16 Data processed in client projects
In developing and maintaining platforms for its clients, DMX acts as a processor (art. 5, VII of the LGPD): it processes personal data on behalf of and according to the instructions of the client, who is the controller of that data.
In this scenario:
- Processing is governed by the contract and the data processing agreement signed with the client, not by this policy;
- DMX does not use this data for its own purposes, does not commercialize it and does not transfer it to third parties without the controller's authorization;
- The team's access is restricted to what is strictly necessary to perform the service, logged and revoked at the end of the activity;
- Preferably, we work in the client's own repository and cloud account, so that code, infrastructure and data remain under the client's control;
- Once the contract ends, the data are returned or deleted as instructed by the controller.
If you are a user of a platform developed by DMX and wish to exercise rights over your data, the request should be addressed to the controlling organization of that platform. We can guide you on the correct routing, if you prefer to write to us first.
17 Changes to this policy
This policy may be updated to reflect legislative changes, ANPD guidance, new services or new suppliers. With each revision, we change the version number and the last updated date shown at the top of this page.
In the event of a relevant change in the purposes or legal bases of the processing, we will notify data subjects through the available contact channels and, when the legal basis is consent, we will request a new expression of it.
We recommend consulting this page periodically.
18 Contact and National Authority
Questions, requests and complaints about privacy and data protection should be addressed to the Data Protection Officer channel:
DMX Design e Desenvolvimento
Personal Data Protection Officer
privacidade@dmxdesign.com.br
Av. Nossa Sra. de Fátima, 240, 4º andar — Vila Israel, Americana/SP, Brazil
You may also file a complaint with the National Data Protection Authority (ANPD), the body responsible for enforcing compliance with the LGPD, through the website gov.br/anpd. Even so, we prefer to resolve the matter directly with you — our channel is open.
Governing law and jurisdiction
This policy is governed by Brazilian law, in particular by Law No. 13.709/2018 (LGPD) and by Law No. 12.965/2014 (Brazilian Internet Civil Framework). The courts of the District of Americana, State of São Paulo, are elected to settle disputes arising from it, without prejudice to the jurisdictions provided by law in favor of the data subject or the consumer.
Want to exercise a right or ask a question?
A single channel answers everything related to personal data at DMX — and answers within 15 days, as the law requires.
- Free request, with no need for justification
- Response within 15 days — art. 19, II of the LGPD
- Unsubscribe from communications processed immediately