Saltar para o conteúdo
Cactos.app

Este documento é publicado apenas em inglês. A versão inglesa é a que prevalece.

Privacy Policy

Versão 2026-09-02 · Em vigor desde 2 de setembro de 2026

This policy covers cactos.app, our marketing website. Each Cactos product — TimeLog included — runs on its own domain under its own privacy notice, because each one handles quite different data.

Notice at collection

The short version, so you do not have to take the long version on faith:

  • This site has no accounts, no logins and no shopping basket. There is nothing here for you to fill in.
  • Fonts are served from our own servers, so loading a page does not hand your IP address to a font CDN.
  • Nothing optional runs until you say so. Analytics and advertising tags stay unloaded until you grant them, and refusing costs you exactly one click.
  • We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we honour Global Privacy Control automatically.
  • We do not use your data to make automated decisions about you.

Who is responsible

The controller of the personal data described here is Bruno Nunes Rosa Consultoria em Tecnologia da Informação Ltda. (“Cactos.app”, “we”, “us”), registered at Av. Paulista, 1636 — Bela Vista, São Paulo/SP, CEP 01310-200, Brazil, CNPJ 42.328.467/0001-05.

RoleContact
General enquiriescontato@cactos.app
Privacy and data rightscontato@cactos.app
Data Protection Officer / Encarregado (LGPD Art. 41)Bruno Rosa (contato@cactos.app)
EU representative (GDPR Art. 27)Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article.
UK representative (UK GDPR Art. 27)Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article.
Swiss representative (revFADP Art. 14)Not appointed — Cactos.app is established in Brazil and has not designated a representative under this article.

What we process, why, and on what basis

PurposeDataLegal basisKept for
Serving the site and keeping it available and secureIP address, user agent, requested URL and timestamp, in our hosting provider's server logsLegitimate interest (GDPR Art. 6(1)(f); LGPD Art. 7(IX)) in operating a working, non-abused websiteUp to 30 days, then deleted
Remembering your cookie choiceThe consent record described in the Cookie Policy: an identifier, a timestamp, the categories you chose and how you chose themLegal obligation to be able to evidence consent (GDPR Art. 6(1)(c) with Art. 7(1)); the cookie itself is strictly necessary and exempt from consent180 days, or until you withdraw
Understanding which pages are usefulAggregate page-view counts; where a cookie-based tool is enabled, an analytics identifierConsent (GDPR Art. 6(1)(a); LGPD Art. 7(I)) for anything cookie-based. Aggregate, cookieless counting relies on legitimate interest and sets nothing on your devicePer the tool listed in the Cookie Policy
Measuring and targeting advertisingAdvertising identifiers set by the platforms named in the Cookie PolicyConsent (GDPR Art. 6(1)(a); LGPD Art. 7(I)). Off unless you switch it onPer the tool listed in the Cookie Policy
Answering you when you get in touchYour name, your email address, and whatever you choose to write to usSteps taken at your request prior to a contract (GDPR Art. 6(1)(b)), or legitimate interest in replying to you2 years from our last exchange

We do not collect special-category data on this site, and we do not ask for it. Please do not send us any.

Who else sees it

We keep the list of processors as short as the job allows. Today it is:

  • Our hosting and CDN provider, which serves the site and keeps the server logs described above.
  • Google LLC, where Google Analytics is enabled — and only after you have granted the analytics category.
  • Meta Platforms, Inc., where the advertising pixel is enabled — and only after you have granted the marketing category.
  • Our email provider, for messages you send us.

We do not sell personal data, and we do not share it for cross-context behavioural advertising as the CPRA defines that term. See the “Do Not Sell or Share” section below.

Where it goes

Some of the providers above are established outside Brazil and outside the EEA, principally in the United States. Where personal data is transferred there, we rely on the European Commission's Standard Contractual Clauses together with the provider's certification under the EU-US Data Privacy Framework, and on the equivalent mechanisms under the UK Addendum, the Swiss revFADP and LGPD Art. 33. You can ask us for a copy of the safeguards that apply to a given transfer.

Your rights

Write to contato@cactos.app and we will answer within one month (GDPR) or fifteen days (LGPD). Exercising any of these costs you nothing and we will not treat you differently for it.

  • Confirmation that we process your data, and access to it.
  • Correction of anything incomplete or inaccurate.
  • Deletion, where we have no overriding basis to keep it.
  • Restriction of processing, and objection to processing based on legitimate interest.
  • Portability of data you gave us, in a machine-readable form.
  • Withdrawal of consent at any time, without detriment — as easy to do as it was to give. The Cookie Policy has the button.
  • Anonymisation, blocking or deletion of unnecessary or excessive data, and information about the public and private bodies we have shared data with (LGPD Art. 18).
  • Under the CPRA: to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for asking.

If we get it wrong, you can complain to your supervisory authority: the ANPD in Brazil, your national data protection authority in the EEA, the ICO in the United Kingdom, or the FDPIC in Switzerland.

Do Not Sell or Share My Personal Information

This section is the notice required by the California Consumer Privacy Act as amended by the CPRA (§1798.135).

We do not sell personal information for money, and we do not share it for cross-context behavioural advertising. Should an advertising pixel ever be enabled on this site, the resulting transfer to that platform could qualify as “sharing” under the CPRA — which is exactly why it is off unless you switch it on, and why turning it back off is one click here:

We also honour the Global Privacy Control. If your browser or extension sends that signal, everything optional is switched off automatically on arrival and you are not asked again — you can still turn something on by hand if you want to.

The categories of personal information described in the table above are the same ones the CPRA covers: identifiers, internet activity, and — only if you write to us — the contents of your message. We do not knowingly collect the personal information of anyone under 16, and therefore do not sell or share it.

Children

This site is aimed at businesses, not children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us something, tell us and we will delete it.

Changes to this policy

This policy is versioned. The current version is 2026-09-02, effective 2 September 2026. When we change it in a way that affects what we do with your data, we bump that version — and because your cookie choice records the version it was made under, you will be asked again rather than silently carried over.