1. Who the data controller is
The controller of personal data processed on this website is FactoryMind Ltda., a company incorporated in Brazil under company registration (CNPJ) number 51.891.888/0001-30, registered office at Avenida Eng. Luiz Carlos Berrini, 1.748, conjunto 1710, Cidade Monções, São Paulo, SP, 04571-000, Brazil.
FactoryMind has staff and clients operating in Miami, London, Lisbon and São Paulo. Personal data may therefore be accessed by our team outside your country of residence, always on the conditions described in section 6.
2. What data we collect
We collect only what we need to reply to you and hold a qualified commercial conversation. We do not buy lists, we do not enrich your data from third-party databases and we do not run cross-site behavioural tracking.
2.1 Data you give us
When you complete one of the forms on this site, we collect:
- Name and title. To know who we are speaking with and at what level the decision sits.
- Work email. The only channel through which we reply.
- Company (AI Inception form). To prepare the conversation and check for conflict of interest with current clients.
- Sector, scale of operation and number of sites in scope (AI Inception form). Used solely to size the scope and route the right technical competence.
- Free-text description of the stuck decision. Text you write. Treat it as you would an email: do not include confidential information, trade secrets, third-party personal data or any special category data.
We also record, alongside the submission, the originating page and the page language, for campaign attribution and internal routing.
2.2 Technical access data
Like any website, our hosting servers log technical access data, including IP address, date and time, browser and operating system type, and the page requested. These logs exist for security, abuse prevention and fault diagnosis.
2.3 Data we do not collect
We do not collect phone numbers, revenue figures, headcount, national identification numbers, financial data, precise location data or any special category of personal data. If you send any of these unprompted in the free-text field, we will delete it as soon as we identify it.
3. What we use the data for
- Replying to your request and scheduling the conversation you asked for.
- Preparing the executive session or the scope and fee proposal.
- Assessing fit with our service profile, which includes declining projects when we are not the right choice.
- Meeting legal and regulatory obligations and defending legal claims.
- Website security and fraud and abuse prevention.
What we do not do: we do not sell, rent or transfer your data. We do not add you to a marketing email cadence without an explicit request. We do not use your data to train artificial intelligence models. We do not make automated decisions producing legal effects concerning you.
4. Legal bases for processing
| Processing | Legal basis (GDPR / UK GDPR) | Legal basis (LGPD) |
|---|---|---|
| Replying to a request submitted through a form | Art. 6(1)(b) pre-contractual steps and Art. 6(1)(f) legitimate interests | Art. 7, V and Art. 7, IX |
| Technical access logs | Art. 6(1)(c) legal obligation and Art. 6(1)(f) | Art. 7, II and Art. 7, IX |
| Sending informational material you requested | Art. 6(1)(a) consent | Art. 7, I |
| Retaining data to defend legal claims | Art. 6(1)(f) | Art. 7, VI |
Where processing rests on legitimate interests, we assess the impact on your rights beforehand and limit use to what is strictly necessary. You may object to that processing at any time, as set out in section 8.
5. Cookies and local storage
This site uses no tracking cookies, installs no advertising pixels and integrates no behavioural analytics tools.
The only item written to your browser is a functional language preference, under the fm_lang key in localStorage, with the value pt or en. It exists so the site does not push you back to the auto-detected language on every visit. It is not a cookie, it is never sent to any server, it does not identify you, and you can clear it from your browser at any time with no loss of functionality.
If we ever adopt analytics or any tracking technology, this policy will be updated before adoption and a consent mechanism will be presented to you.
6. Third parties and international transfers
We share data only with processors strictly necessary to run the site and handle enquiries, all contractually bound to process it on our instructions:
| Processor | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | Page hosting, content delivery network and abuse protection | Technical access data |
| Google LLC (Google Fonts) | Delivering the site typefaces | IP address and browser request data |
| Google LLC (Google Workspace) | Receiving, recording and answering your request. Form content is emailed to our team and logged in an internal control spreadsheet | Form content |
This is the complete list. We use no other processor, no marketing automation platform and no third-party form service. If this list changes, this policy is updated before the change takes effect.
Some of these processors are established outside the European Economic Area and the United Kingdom, notably in the United States. Those international transfers rely on Arts. 44 to 49 of the GDPR and Art. 33 of the LGPD, supported by standard contractual clauses and the safeguards set out in the respective data processing agreements.
On typefaces, transparency matters: loading this site makes your browser request files from Google servers, which receive your IP address. If you prefer to avoid that disclosure, a third-party request blocker prevents the call, and the site remains fully legible with your system fonts.
7. How long we keep data
- Enquiry with no commercial follow-up: up to 24 months after the last contact, the window in which the conversation can still usefully resume. Deleted thereafter.
- Enquiry that progressed to proposal or contract: for the duration of the relationship and, once ended, for the applicable limitation and tax record-keeping periods.
- Technical access logs: 6 months, or longer under a court order.
- Language preference: stays in your browser only, under your control.
8. Your rights
Under the GDPR and UK GDPR (Arts. 15 to 22) and the LGPD (Art. 18), you may at any time request:
- Confirmation that we process your data, and access to it.
- Rectification of incomplete, inaccurate or outdated data.
- Erasure, anonymisation or blocking of data that is unnecessary, excessive or processed unlawfully.
- Portability of your data to another service provider.
- Restriction of processing, in the cases the regulation provides.
- Information about the entities we share your data with.
- Withdrawal of consent, where consent is the basis.
- Objection to processing based on legitimate interests.
We answer requests within 15 days of receipt, applying the stricter Brazilian deadline to everyone rather than the one-month GDPR window. If we need an extension we will tell you, with reasons, before the deadline expires. We may ask for additional information solely to confirm your identity and avoid improper disclosure to a third party.
If you are not satisfied with our response, you may complain to the supervisory authority of your country of residence, or, in Brazil, to the Autoridade Nacional de Proteção de Dados.
9. Information security
We apply technical and organisational measures proportionate to the risk: the site is served over HTTPS only, access to contact data is restricted on a need-to-know basis, corporate accounts require two-factor authentication, access to personal data is logged, and we maintain an internal incident response policy.
No measure removes risk entirely. In the event of a security incident presenting significant risk to your rights, we will notify you and the competent authority within the statutory deadlines, describing what happened, which data was affected and what we did about it.
10. Children and young people
This site addresses professionals in a corporate context and is not directed at anyone under 18. We do not knowingly collect data about children or young people. If we identify inadvertent collection, we delete it immediately.
When we serve education institutions, processing of student data happens under our contract with the institution, which acts as controller and we as processor, on documented instructions and under a specific data processing agreement. That processing is governed by the contract and by the institution’s own privacy policy, not by this one.
11. Data protection officer and how to reach us
FactoryMind Ltda. has appointed a data protection officer under Art. 41 of the Brazilian LGPD, who also serves as the point of contact for GDPR and UK GDPR purposes. To exercise your rights, ask about this policy, request the named list of processors or report an incident, contact:
- Data protection officer: Renato Fumagalli
- Email: privacy@factorymind.com.br
- Postal address: Avenida Eng. Luiz Carlos Berrini, 1.748, conjunto 1710, Cidade Monções, São Paulo, SP, 04571-000, Brazil
Identify yourself and describe the request clearly. We reply through the same channel, within the deadline in section 8.
12. Changes to this policy
We may update this document to reflect changes in our operation, our technology or the law. The version in force is always the one published on this page, with the version number and effective date at the top. Changes that reduce your rights or materially widen processing purposes will be communicated by email, with reasonable notice, to anyone in active contact with us.
Independently of any interim change, this policy undergoes a full scheduled review every three years. The next is due in August 2029. Until a replacement is published on this page, the version above remains in force: a privacy policy does not lapse on a deadline.
A note on why this page is long
We sell data governance to clients operating in regulated environments. Publishing a vague policy about our own data would contradict what we ask of them. If anything here is unclear, write to us and we will rewrite it.
Talk to a partner