Ce document n’est publié qu’en anglais. C’est la version anglaise qui fait foi.
Privacy Policy
Version 2026-09-02 · En vigueur depuis le 2 septembre 2026
This policy covers cactos.app, our marketing website. Each Cactos product — TimeLog included — runs on its own domain under its own privacy notice, because each one handles quite different data.
Notice at collection
The short version, so you do not have to take the long version on faith:
- This site has no accounts, no logins and no shopping basket. There is nothing here for you to fill in.
- Fonts are served from our own servers, so loading a page does not hand your IP address to a font CDN.
- Nothing optional runs until you say so. Analytics and advertising tags stay unloaded until you grant them, and refusing costs you exactly one click.
- We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we honour Global Privacy Control automatically.
- We do not use your data to make automated decisions about you.
Who is responsible
The controller of the personal data described here is Bruno Nunes Rosa Consultoria em Tecnologia da Informação Ltda. (“Cactos.app”, “we”, “us”), registered at Av. Paulista, 1636 — Bela Vista, São Paulo/SP, CEP 01310-200, Brazil, CNPJ 42.328.467/0001-05.
| Role | Contact |
|---|---|
| General enquiries | contato@cactos.app |
| Privacy and data rights | contato@cactos.app |
| Data Protection Officer / Encarregado (LGPD Art. 41) | Bruno Rosa (contato@cactos.app) |
| EU representative (GDPR Art. 27) | Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article. |
| UK representative (UK GDPR Art. 27) | Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article. |
| Swiss representative (revFADP Art. 14) | Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article. |
What we process, why, and on what basis
| Purpose | Data | Legal basis | Kept for |
|---|---|---|---|
| Serving the site and keeping it available and secure | IP address, user agent, requested URL and timestamp, in our hosting provider's server logs | Legitimate interest (GDPR Art. 6(1)(f); LGPD Art. 7(IX)) in operating a working, non-abused website | Up to 30 days, then deleted |
| Remembering your cookie choice | The consent record described in the Cookie Policy: an identifier, a timestamp, the categories you chose and how you chose them | Legal obligation to be able to evidence consent (GDPR Art. 6(1)(c) with Art. 7(1)); the cookie itself is strictly necessary and exempt from consent | 180 days, or until you withdraw |
| Understanding which pages are useful | Aggregate page-view counts; where a cookie-based tool is enabled, an analytics identifier | Consent (GDPR Art. 6(1)(a); LGPD Art. 7(I)) for anything cookie-based. Aggregate, cookieless counting relies on legitimate interest and sets nothing on your device | Per the tool listed in the Cookie Policy |
| Measuring and targeting advertising | Advertising identifiers set by the platforms named in the Cookie Policy | Consent (GDPR Art. 6(1)(a); LGPD Art. 7(I)). Off unless you switch it on | Per the tool listed in the Cookie Policy |
| Answering you when you get in touch | Your name, your email address, and whatever you choose to write to us | Steps taken at your request prior to a contract (GDPR Art. 6(1)(b)), or legitimate interest in replying to you | 2 years from our last exchange |
We do not collect special-category data on this site, and we do not ask for it. Please do not send us any.
Who else sees it
We keep the list of processors as short as the job allows. Today it is:
- Our hosting and CDN provider, which serves the site and keeps the server logs described above.
- Google LLC, where Google Analytics is enabled — and only after you have granted the analytics category.
- Meta Platforms, Inc., where the advertising pixel is enabled — and only after you have granted the marketing category.
- Our email provider, for messages you send us.
We do not sell personal data, and we do not share it for cross-context behavioural advertising as the CPRA defines that term. See the “Do Not Sell or Share” section below.
Where it goes
Some of the providers above are established outside Brazil and outside the EEA, principally in the United States. Where personal data is transferred there, we rely on the European Commission's Standard Contractual Clauses together with the provider's certification under the EU-US Data Privacy Framework, and on the equivalent mechanisms under the UK Addendum, the Swiss revFADP and LGPD Art. 33. You can ask us for a copy of the safeguards that apply to a given transfer.
Your rights
Write to contato@cactos.app and we will answer within one month (GDPR) or fifteen days (LGPD). Exercising any of these costs you nothing and we will not treat you differently for it.
- Confirmation that we process your data, and access to it.
- Correction of anything incomplete or inaccurate.
- Deletion, where we have no overriding basis to keep it.
- Restriction of processing, and objection to processing based on legitimate interest.
- Portability of data you gave us, in a machine-readable form.
- Withdrawal of consent at any time, without detriment — as easy to do as it was to give. The Cookie Policy has the button.
- Anonymisation, blocking or deletion of unnecessary or excessive data, and information about the public and private bodies we have shared data with (LGPD Art. 18).
- Under the CPRA: to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for asking.
If we get it wrong, you can complain to your supervisory authority: the ANPD in Brazil, your national data protection authority in the EEA, the ICO in the United Kingdom, or the FDPIC in Switzerland.
Do Not Sell or Share My Personal Information
This section is the notice required by the California Consumer Privacy Act as amended by the CPRA (§1798.135).
We do not sell personal information for money, and we do not share it for cross-context behavioural advertising. Should an advertising pixel ever be enabled on this site, the resulting transfer to that platform could qualify as “sharing” under the CPRA — which is exactly why it is off unless you switch it on, and why turning it back off is one click here:
We also honour the Global Privacy Control. If your browser or extension sends that signal, everything optional is switched off automatically on arrival and you are not asked again — you can still turn something on by hand if you want to.
The categories of personal information described in the table above are the same ones the CPRA covers: identifiers, internet activity, and — only if you write to us — the contents of your message. We do not knowingly collect the personal information of anyone under 16, and therefore do not sell or share it.
Children
This site is aimed at businesses, not children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us something, tell us and we will delete it.
Changes to this policy
This policy is versioned. The current version is 2026-09-02, effective 2 September 2026. When we change it in a way that affects what we do with your data, we bump that version — and because your cookie choice records the version it was made under, you will be asked again rather than silently carried over.