Legal & Compliance

Privacy Policy

We are committed to handling your personal data with care, transparency, and respect. This policy explains exactly what we collect, why we collect it, and what rights you hold under Brazilian and European data-protection law.

Last updated: 30 June 2025  ·  Adilson Correia Sociedade Individual de Advocacia  ·  CNPJ 62.902.157/0001-60

1. Introduction

Adilson Correia Sociedade Individual de Advocacia ("we," "us," or "the firm"), registered under CNPJ 62.902.157/0001-60 and headquartered at Avenida Vicente Machado, 219, Conjunto 23, 2nd Floor, Edifício Geneve, Centro, Curitiba – PR, Brazil, operates this website as an informational resource about our legal services.

We take your privacy seriously. This Privacy Policy describes how we collect, process, store, and protect personal data obtained when you visit our website or otherwise interact with us. It is designed to comply with Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13.709/2018) and, where applicable, the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), as well as any other data-protection legislation that may apply to our activities.

By using this website you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of the site.

This website is purely informational. We do not operate an online portal, collect payment information, or enable self-service account creation. Personal data is received only through direct contact and through the analytics tools described below.

2. Information We Collect

We collect the minimum personal data necessary to operate a professional law-firm website and to communicate with people who reach out to us. We do not sell, rent, or trade personal data under any circumstances. The categories of data we may collect include:

Information you provide directly

When you contact us by email, telephone, or post, you voluntarily share information such as your name, email address, telephone number, and the content of your message. In a legal services context this may also include a brief description of your matter or legal query. We collect only what you choose to provide, and we use it solely to respond to your enquiry or to fulfil any engagement we may subsequently enter into.

Information collected automatically

When you visit our website, certain technical and behavioural data is collected automatically by the server and by third-party analytics tools (see Section 4 for full details):

  • IP address and approximate geolocation derived from it (country/city level only)
  • Browser type and version, operating system, and device type
  • Referring URL (the address of the page that linked you to our site)
  • Pages visited, time on page, and navigation path through the site
  • Date and time of each request to our server
  • Cookie identifiers and similar tracking signals (described in detail in Section 4)

This data is collected in aggregate and is used to understand how visitors use our website, to measure the effectiveness of any advertising campaigns, and to maintain the security and technical performance of our infrastructure. Wherever possible, IP addresses are anonymised before being stored.

Information from third-party sources

We do not routinely receive personal data about you from third-party sources. Should we obtain any referral data from professional partners (for example, a fellow attorney who refers a matter to us), we handle that data with the same care described in this policy and inform you promptly that we hold it.

3. How We Use Your Information

We process personal data only when there is a clear legal basis to do so. Under the LGPD those bases include legitimate interest, the performance of a contract (or pre-contractual steps), compliance with a legal obligation, and — in limited cases — your explicit consent. Under the GDPR the same categories apply. We set out below the specific purposes for which we process data, together with the applicable legal basis:

  • Responding to enquiries and providing legal services: When you contact us to discuss a legal matter, we use the information you provide to evaluate your enquiry, carry out any necessary conflict-of-interest checks, and communicate with you. Legal basis: performance of a contract or pre-contractual steps; legitimate interest of the firm.
  • Website analytics and performance: Automatically collected browsing data helps us understand which content is useful, identify technical errors, and improve the site. Legal basis: legitimate interest, subject to your cookie preferences.
  • Advertising measurement: If you arrive at our site via an online advertisement (including Google Ads), we measure the effectiveness of those campaigns using aggregated, anonymised metrics. Legal basis: legitimate interest; consent where required by applicable law.
  • Legal and regulatory compliance: As a law firm registered with the Brazilian Bar Association (OAB), we are subject to professional-conduct rules, anti-money-laundering obligations, and tax-reporting requirements that may necessitate the retention or disclosure of certain records. Legal basis: compliance with a legal obligation.
  • Security and fraud prevention: Log and access data is reviewed to detect, investigate, and prevent unauthorised access, abuse, or technical attacks on our infrastructure. Legal basis: legitimate interest.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. We do not use contact information to send you unsolicited marketing communications.

4. Cookies & Tracking Technologies

Cookies are small text files placed on your device when you visit a website. We use a minimal set of cookies and comparable technologies to keep the site functional and to gather anonymised usage statistics. We do not use cookies to build personal profiles or to serve you behavioural advertising beyond basic campaign attribution.

Strictly necessary cookies

These cookies are essential for the website to load and function correctly — for example, to remember your cookie consent preference so that you are not shown the notice on every page. They cannot be disabled without breaking core site functionality. No personal data is transmitted to third parties through these cookies.

Analytics cookies

We use Google Analytics to gather aggregated, anonymised data about how visitors use our website. Google Analytics places cookies on your device (typically named _ga, _ga_*) that collect information including pages viewed, session duration, and the broad geographic origin of visitors. We have configured Google Analytics with IP anonymisation enabled, meaning the final octet of your IP address is masked before being stored. The data collected is used solely to improve our website and is not shared with any other party. Google's own privacy policy applies to data Google processes as a data processor on our behalf; you can review it at policies.google.com/privacy.

Advertising and conversion cookies

If we run advertising campaigns through Google Ads, Google may place a conversion cookie on your device when you click one of our advertisements. This cookie tells us whether a visit resulted in a meaningful engagement (such as reaching our contact page), helping us measure campaign effectiveness. These cookies do not reveal your identity to us and do not track your browsing on other websites for the purpose of serving you adverts elsewhere.

Managing your cookie preferences

You can control cookies through our cookie consent banner, which appears on your first visit. You may also configure your browser to block or delete cookies at any time; consult your browser's help documentation for instructions. Disabling analytics or advertising cookies will not impair your ability to access any part of this website. To opt out of Google Analytics specifically across all websites, you may install the Google Analytics Opt-out Browser Add-on.

5. Sharing With Third Parties

We do not sell, rent, trade, or otherwise commercially exploit your personal data. We share data only in the limited circumstances described below, and only to the extent strictly necessary for each purpose:

  • Service providers acting as data processors: Certain third-party companies provide technical infrastructure we rely upon — including web hosting, email delivery, and analytics platforms (notably Google LLC). Each of these parties processes data on our behalf, subject to contractual obligations that restrict their use of the data to the services they provide us. They may not use your data for their own purposes.
  • Legal and regulatory authorities: We will disclose personal data to courts, law-enforcement agencies, regulators (including the OAB), or other authorities when we are legally required to do so, or when disclosure is necessary to protect the rights, property, or safety of the firm, its attorneys, or others.
  • Professional advisers: Accountants, auditors, and insurance providers who advise the firm may have access to client information strictly as necessary for their advisory role, and are themselves bound by professional confidentiality obligations.
  • Business transfers: In the unlikely event of a restructuring or transfer of the firm's practice, client records may be transferred to a successor entity, subject to the same confidentiality obligations and in compliance with applicable law. Affected individuals will be notified in advance.

Where personal data is transferred to countries outside Brazil or the European Economic Area — for example, to Google's servers — we rely on approved mechanisms such as the European Commission's Standard Contractual Clauses, or equivalent safeguards recognised under the LGPD, to ensure that your data continues to receive an adequate level of protection.

6. Data Retention

We keep personal data for as long as is necessary for the purposes described in this policy, and for as long as required by applicable professional and legal obligations. Specific retention periods are as follows:

  • Pre-engagement enquiries (emails and telephone notes that did not lead to a formal instruction): retained for up to 24 months from the date of last contact, after which they are securely deleted.
  • Client files and matter records: Brazilian civil and professional rules require law firms to retain client files for a minimum of five years after conclusion of a matter. Where longer periods are mandated by specific statutes (for example, in tax or corporate matters), we retain records accordingly — typically up to 10 years.
  • Accounting and fiscal records: Retained for the period required by Brazilian tax law, which is generally five years.
  • Website analytics data: Aggregated and anonymised analytics data is retained in our Google Analytics account for 26 months, consistent with Google's default retention setting and our own analytics needs. Raw server logs containing IP addresses are retained for no longer than 12 months.
  • Cookie consent records: Logged for a maximum of 12 months to demonstrate compliance with applicable rules.

At the end of the applicable retention period, personal data is either securely deleted or irreversibly anonymised. Physical documents are shredded; digital records are deleted using methods that prevent recovery.

7. Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • TLS/HTTPS encryption for all data transmitted between your browser and our website, ensuring that any information you send us — including email enquiries — cannot be intercepted in transit
  • Access controls that restrict internal access to personal data to the attorney and staff members who have a legitimate need for it in connection with their duties
  • Password policies and, where available, multi-factor authentication for systems that hold personal data
  • Regular review of our data-handling practices and vendor relationships to ensure continued compliance with applicable standards
  • Physical security measures at our office premises, including controlled access to areas where confidential files are stored

Despite these safeguards, no method of electronic transmission or storage is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (ANPD in Brazil; the competent DPA in the EU) within the timeframe required by law, and we will inform you directly where the breach is likely to result in a high risk to you personally.

If you have reason to believe that your personal data has been compromised through any interaction with our firm, please contact us immediately at [email protected] so that we can investigate and take appropriate action.

8. Your Rights

Depending on your country of residence and the legal basis under which we process your data, you hold a number of rights regarding your personal information. We honour these rights under both the LGPD and the GDPR. Your key rights are:

Right of Access

Request a copy of the personal data we hold about you, together with information about how and why it is processed.

Right to Correction

Ask us to correct any inaccurate or incomplete personal data we hold about you without undue delay.

Right to Erasure

Request deletion of your personal data where there is no compelling reason for continued processing — subject to our legal retention obligations.

Right to Object

Object at any time to processing based on legitimate interest, including for analytics purposes, where your particular situation justifies it.

Right to Restriction

Request that we restrict processing of your data — for example, while you contest its accuracy or pending the outcome of an objection.

Right to Portability

Receive personal data you have provided to us in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible.

Right to Withdraw Consent

Where processing is based on your consent (such as non-essential cookies), withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.

Right to Lodge a Complaint

File a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil, or with the competent supervisory authority in your EU Member State, if you believe we have infringed applicable data-protection law.

To exercise any of these rights, please contact our Data Protection Officer (see Section 11). We will respond to all verifiable requests within 15 business days, or within the period prescribed by applicable law. We may need to verify your identity before processing your request — this is to ensure we do not disclose personal data to someone who is not entitled to receive it. We will not charge a fee for legitimate requests unless they are manifestly unfounded or excessive.

Please note that certain rights are subject to limitations. For example, we may be unable to delete data that we are legally required to retain, or that is necessary to defend or exercise a legal claim. In such cases we will explain the reason clearly and in writing.

9. Children's Privacy

This website is intended solely for adults. Our legal services are not directed at children, and we do not knowingly collect personal data from any person under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take prompt steps to delete that data from our records.

If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at the address set out in Section 11 so that we can investigate and take appropriate remedial action.

In the context of legal matters that involve children — for example, family law proceedings — any personal data relating to minors is handled with heightened care, strict access controls, and the greatest degree of professional discretion, in accordance with the applicable legal framework and the firm's ethical obligations to the court.

10. Changes to This Policy

We review this Privacy Policy periodically and update it whenever our data-handling practices change, when new laws come into force, or when the services provided through this website are materially altered. Any revised version of this policy will be published on this page with an updated "Last updated" date at the top.

Where changes are significant — for example, if we begin processing personal data for a new purpose, or if we introduce a new category of data collection — we will take additional steps to bring the changes to your attention, such as by displaying a notice prominently on the homepage for a reasonable period.

We encourage you to revisit this page periodically to stay informed about how we protect your data. Your continued use of this website after the publication of any revised policy constitutes your acceptance of the changes, to the extent permitted by applicable law. If you do not agree with the revised terms, please discontinue use of the site.

11. Contact & Data Controller

The data controller responsible for your personal data is:

Adilson Correia Sociedade Individual de Advocacia

CNPJ: 62.902.157/0001-60
Registered address: Avenida Vicente Machado, 219, Conjunto 23, 2nd Floor, Edifício Geneve, Centro, Curitiba – PR, Brazil
Email (privacy enquiries & rights requests): [email protected]
Responsible person: Dr. Adilson Correia (Data Protection Officer)

All privacy-related correspondence — including requests to exercise your rights, complaints, or queries about how we handle your data — should be directed to the email address above. Please mark the subject line clearly as "Privacy Request" or "Data Protection Enquiry" so that your message is routed promptly to the responsible person. We aim to acknowledge all requests within two business days and to respond substantively within 15 business days, or within the period prescribed by the law that applies to your request.

If you are based in the European Union and wish to file a complaint with a supervisory authority, you may do so with the data-protection authority in the EU Member State where you live, work, or where the alleged infringement took place. A complete list of EU supervisory authorities is maintained by the European Data Protection Board at www.edpb.europa.eu. In Brazil, complaints may be directed to the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.