Privacy Policy
This Policy describes how we handle personal data on aisac.global. It is written to be read by people, not only by lawyers: this is an institutional site with no sign-up, no logged-in area and nothing sold directly.
1. Who the controller is
The controller of personal data processed on this site is B2 Tech, responsible for the AISAC brand and the ecosystem's domains.
Company registration (CNPJ):
Address:
Contact for privacy matters, including exercising your rights: bruno@b2tech.io.
2. Scope of this policy
This Policy covers the aisac.global site only. Other products and properties in the ecosystem are handled separately and, where applicable, have their own policies:
- AI Brain — a memory product with authentication and user data;
- AISAC Community — a community with sign-up and credentials;
- Workloop Spec — a public technical document.
Following a link from this site to any of them, or to any third-party site, means data handling is governed by that destination's policy.
3. Data we process
This site has no form, no login, no cart and no sign-up. In practice we process:
-
Aggregated navigation data, only if you consent to audience measurement:
pages viewed, language, device type, traffic source (including
utm_*campaign parameters present in the URL), button clicks and scroll depth. Your IP address is anonymised in the measurement tool. - Data you send us voluntarily, if you choose to write to the contact address: your email address and the content of your message.
- Technical logs from the hosting provider, generated automatically by any web server in order to deliver the page and protect the infrastructure from abuse.
We do not collect sensitive data, we do not build individual profiles, we do not sell data, and we do not use data from this site to train models.
4. Cookies and consent
This site uses no advertising cookies. Audience measurement loads only after your explicit consent: until you choose, no third-party script is injected into the page.
We use browser local storage for a single thing:
aisac_consent_v1— stores your choice about audience measurement, so we do not ask again on every visit. This is strictly necessary storage, used to honour your decision, and therefore does not itself require prior consent.
To withdraw consent, clear this site's data in your browser; the notice will appear again on your next visit. If you decline, no measurement is loaded and the site works in full.
5. Legal bases
Under Brazil's General Data Protection Law (LGPD, Law 13.709/2018) we rely on:
- Consent (art. 7, I) — for audience measurement;
- Legitimate interest (art. 7, IX) — to keep the site available, stable and secure;
- Preliminary procedures and performance of a contract (art. 7, V) — when you write to us and we reply.
For visitors in the European Economic Area or the United Kingdom, the corresponding GDPR bases are consent (art. 6(1)(a)) and legitimate interest (art. 6(1)(f)).
6. Sharing and processors
We do not sell or trade personal data. We rely on the following processors:
- Cloudflare — hosting, CDN and infrastructure protection for this site;
- Google Analytics — aggregated audience measurement, loaded only with consent;
- Google Fonts — delivery of the typefaces used on these pages.
We may also share data where required by law, by order of a competent authority, or where necessary to defend a claim in administrative, judicial or arbitral proceedings.
7. International transfers
The processors above are companies with global infrastructure, which may involve processing outside Brazil. Such transfers rely on the contractual and adequacy mechanisms those providers offer.
8. Retention
- Aggregated audience data: for the retention period configured in the measurement tool.
- Email messages: as long as needed to handle the matter and meet legal obligations.
- Provider technical logs: for the provider's own operational and security periods.
- Consent preference: in your browser, until you clear the site's data.
9. Your rights
The LGPD (art. 18) gives you the right to confirm whether processing exists, access your data, correct incomplete or outdated data, request anonymisation, blocking or deletion of unnecessary data, request portability, obtain information about sharing, withdraw consent and object to processing carried out on another legal basis.
To exercise any of them, write to bruno@b2tech.io. We may ask for additional information to confirm your identity before acting — that is a protection for you, not an obstacle. You may also lodge a complaint with Brazil's National Data Protection Authority (ANPD) or, where applicable, your local supervisory authority.
10. Security
The site is served over HTTPS only, with HSTS, a restrictive content security policy and headers protecting against framing and content-type sniffing. No system is immune to incidents; should a material security incident occur, we will notify data subjects and the competent authority as required by law.
11. Children
This site is aimed at a professional audience and is not directed at anyone under 18. We do not knowingly collect data from children or adolescents.
12. Changes
We may update this Policy to reflect changes to the site, to the tools it uses, or to the law. The effective date at the top indicates the current version. Material changes will be flagged on the page itself.
13. Contact
Questions about this Policy or about how your data is handled: bruno@b2tech.io.