Privacy Policy
Last updated:Jul 31, 2026 Version: 1.0
This Policy describes how we process personal data on the website https://doo.is. It is designed to meet the requirements of both Regulation (EU) 2016/679 (GDPR) and Brazilian Law No. 13,709/2018 (LGPD).
1. Who is the controller
The controller of personal data processed on this website is:
DOOIS WEB LTDA. CNPJ 19.306.994/0001-05 Av. São Carlos, 2205, CEP 13560-011, São Carlos, SP, Brazil Email: [email protected]
2. Representative in the European Union
Pursuant to Article 27 GDPR, we have designated as our representative in the European Union:
Doois KvK 96942223 Prins Hendrikstraat 1, 5611 HH Eindhoven, The Netherlands Email: [email protected]
Data subjects in the European Union may contact either the representative or the controller directly.
3. Privacy contact
All requests concerning personal data, including the exercise of data subject rights, should be sent to [email protected]. This is the official monitored channel for that purpose.
4. Scope of this Policy
This Policy applies exclusively to personal data we process as a controller in connection with the website https://doo.is and the communications arising from it.
It does not apply to personal data we process on behalf of clients within contracted projects. In those cases we act as a processor under the client’s documented instructions, and the applicable privacy policy is that of the client, in its capacity as controller.
5. Personal data we collect
5.1 Contact form
Name, email, phone (optional), company (optional), website (optional), and any information you choose to include in the project description.
5.2 Careers form
Name, email, phone (optional), LinkedIn profile, and area of interest. This form does not accept attachments. Any additional data available on your public LinkedIn profile is accessed by us in that context.
5.3 Email correspondence
Content, addresses, and metadata of messages exchanged with us following your initial contact.
5.4 Marketing communications
Email address and sending and engagement history, where you have expressly opted in.
5.5 Technical data and access logs
IP address, date and time of access, requested resource, response code, user agent, and referrer, automatically recorded by our servers and network protection layer.
5.6 Usage and measurement data
Website usage data collected through cookies and similar technologies, only with your consent. See section 7.
We do not collect special categories of data (Article 9 GDPR) or sensitive personal data (Article 5, II LGPD) through this website, and we ask that you do not include such data in the free text fields of our forms.
6. Purposes and legal bases
| Processing | Purpose | GDPR legal basis | LGPD legal basis |
|---|---|---|---|
| Contact form | Respond to the enquiry, assess feasibility, and conduct commercial discussions | Art. 6(1)(b), pre-contractual steps | Art. 7, V |
| Lead management after initial contact | Commercial follow-up and record of the relationship | Art. 6(1)(f), legitimate interest | Art. 7, IX |
| Careers form | Assess the application and run the selection process | Art. 6(1)(b), pre-contractual steps | Art. 7, V |
| Retaining applications for future roles | Consider the candidate in later processes | Art. 6(1)(a), consent | Art. 7, I |
| Marketing communications | Sending Doois content and updates | Art. 6(1)(a), consent | Art. 7, I |
| Access logs and network protection | Security, integrity, availability, and abuse prevention | Art. 6(1)(f), legitimate interest | Art. 7, IX |
| Anti-fraud protection of forms (reCAPTCHA) | Prevent automated submissions and abuse | Art. 6(1)(f), legitimate interest | Art. 7, IX |
| Cookies and audience measurement | Understand website usage and improve it | Art. 6(1)(a), consent | Art. 7, I |
| Compliance with legal obligations | Tax, accounting, and regulatory requirements | Art. 6(1)(c) | Art. 7, II |
Where processing relies on legitimate interest, we carry out the balancing assessment required by Article 6(1)(f) GDPR and Article 10 LGPD. You may request information about that assessment through the channel in section 3.
7. Cookies and similar technologies
7.1 Strictly necessary cookies
Used for the basic operation of the website, including storing your consent choices and securing the forms. These do not require consent.
7.2 Measurement and analytics cookies
We use Google Analytics 4 and PostHog to understand how the website is used. These cookies and equivalent technologies are activated only after your consent, given through the consent panel displayed on first visit. No measurement tag fires before that.
We do not use session recording. We do not use social media or advertising pixels or tags.
7.3 Managing consent
The full list of cookies, including name, purpose, origin, and duration, is available in the cookie preferences panel, accessible at any time through the permanent link in the website footer.
You may change or withdraw your consent at any time through that panel, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Your browser also allows you to block or delete cookies. Doing so may affect parts of the website.
8. Who we share data with
We do not sell personal data and we do not disclose it to third parties for advertising purposes.
We rely on the following processors, under executed data processing agreements:
| Processor | Service | Role |
|---|---|---|
| Google Ireland Limited | Google Workspace (corporate email), Google Analytics 4, Google Tag Manager, reCAPTCHA | Correspondence, audience measurement, anti-fraud protection |
| PostHog | Product analytics, European Union instance | Website usage measurement |
| Cloudflare | Network protection, attack mitigation, content delivery | Security and performance |
The website infrastructure runs on private servers located in the Netherlands. Marketing communications are sent through a Doois in-house system, with no third-party intermediary.
We may also disclose personal data where required by law, court order, or request from a competent authority, and to our legal and accounting advisers where necessary for the defence of legal claims.
9. International transfers
Doois operates in Brazil and in the Netherlands. Personal data collected through this website may be transferred between the two jurisdictions in the ordinary course of our operations.
These transfers are covered by the reciprocal adequacy decisions adopted in January 2026: European Commission Implementing Decision (EU) 2026/179, recognising Brazil as a third country providing an adequate level of protection under Article 45 GDPR, and ANPD Resolution CD/ANPD No. 32/2026, recognising the European Union as providing an adequate level of protection under Article 33, I LGPD.
Should either decision be suspended or repealed, we will implement alternative transfer mechanisms and update this Policy.
10. How long we keep data
| Category | Retention period |
|---|---|
| Commercial contact and lead data | 24 months from last contact |
| Job applications, open and role-specific | 4 weeks after the selection process closes; up to 12 months with the candidate’s express consent |
| Email correspondence | For the duration of the relationship and any legally applicable retention periods |
| Server access logs | 30 days |
| Google Analytics 4 (user-level data) | 2 months |
| PostHog | 2 months |
| Cookie consent records | 2 months |
| Marketing mailing list | Until consent is withdrawn, followed by deletion of the record |
Once these periods expire, data is deleted or irreversibly anonymised, except where retention is required to comply with a legal or regulatory obligation, or for the establishment, exercise, or defence of legal claims.
11. Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, role-based access control, network perimeter protection, and restriction of access to form submissions to the commercial team responsible for handling them.
No system is entirely secure. In the event of a security incident likely to result in significant risk to data subjects, we will notify the competent authorities and affected individuals within the timeframes and conditions set out in Articles 33 and 34 GDPR and Article 48 LGPD.
12. Use of data in artificial intelligence
Personal data collected through this website is not used to train, fine-tune, or evaluate artificial intelligence models, whether our own or those of third parties.
We do not carry out automated decision-making producing legal effects or similarly significantly affecting data subjects, including automated screening of job applicants.
13. Your rights
You have the right to:
- obtain confirmation that processing takes place and access your data;
- have incomplete, inaccurate, or outdated data corrected;
- request erasure of your data, within the limits of the law;
- request restriction of processing;
- object to processing based on legitimate interest;
- receive your data in a structured, commonly used format and request its portability;
- withdraw consent at any time, without affecting the lawfulness of prior processing;
- be informed about the parties with whom we share your data;
- be informed about the possibility of withholding consent and the consequences of doing so;
- not be subject to decisions based solely on automated processing with significant effects.
These rights derive from Articles 15 to 22 GDPR and Article 18 LGPD.
How to exercise them: send your request to [email protected]. We may request additional information to verify your identity, used solely for that purpose.
Response time: we respond without undue delay and in any event within one month, extendable by a further two months for complex requests, with prior notice to you (Article 12 GDPR). Requests for confirmation of processing and access made under the LGPD are answered in simplified format immediately, or by a complete statement within 15 days (Article 19 LGPD)
Exercising these rights is free of charge.
14. Complaints to supervisory authorities
If you believe the processing of your data infringes applicable law, you may lodge a complaint with:
- the Autoriteit Persoonsgegevens (Netherlands), or the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement, under Article 77 GDPR;
- the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil.
We encourage you to contact us first at [email protected], but this is not a precondition for exercising that right.
15. Minors
This website is intended for a professional audience and is not directed at minors. We do not knowingly collect data from children or adolescents. If we identify that we have received such data, we will delete it. If you are a legal guardian and believe a minor has provided us with data, contact [email protected].
16. External links and services
The website contains links to third-party platforms, including LinkedIn, Instagram, and WhatsApp. Following those links places you under the privacy policies of those platforms, over which we have no control. WhatsApp contact is initiated by you through an external link; from that point, processing of the conversation data is also governed by the platform’s terms.
17. Changes to this Policy
We may update this Policy to reflect changes in our operations, the technology we use, or applicable law. The date of the last update appears at the top of the document. Material changes will be prominently notified on the website.
18. Governing law
This Policy is governed by Brazilian law and by European Union law applicable to the processing of data of subjects located in the European Economic Area, without prejudice to the rights afforded to you by the law of your country of residence.