Introduction
META PLURAL COMERCIO E SERVICOS EM EQUIPAMENTOS DE AUDIO, VIDEO E INFORMATICA LTDA — registered under CNPJ 09.196.543/0001-09 and headquartered at Setor SHIS CL QI 11 Bloco P, S/N, Sala 201, Lago Sul, Brasília-DF — operates the website available at meta-us.site (the "Site") and delivers consulting and implementation services in artificial intelligence, data analytics, and digital transformation (collectively, the "Services").
We take the protection of personal data seriously. This Privacy Policy describes what personal information we collect when you interact with our Site and Services, the purposes for which that data is processed, the legal bases that authorize such processing, how long we retain it, with whom we may share it, and what rights you hold as a data subject.
This policy has been prepared in accordance with Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018) and reflects the principles of the European Union's General Data Protection Regulation (GDPR — Regulation EU 2016/679) where applicable to visitors located in or accessing the Site from the European Economic Area. It also meets the transparency requirements applicable to advertising landing pages under Google's advertising policies.
By using our Site or submitting information through any of our contact forms, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, you should discontinue use of the Site and may contact us to exercise any rights described herein.
Information We Collect
We collect personal data through several distinct channels. We only collect information that is necessary and proportionate to the purpose for which it is being processed. Below is a detailed breakdown of each category.
Information you provide directly — contact & inquiry forms
- Full name — used to address you personally and to identify the requesting party.
- Business email address — our primary channel for responding to your inquiry or scheduling a consultation.
- Phone number (optional) — provided at your discretion when you prefer a callback.
- Company name and role — helps us tailor our response to your organisation's context and scale.
- Message content — the details you share in the body of a contact or project-brief form, which may include business information or project requirements.
- Newsletter subscription consent — recorded with a timestamp when you opt in to receive our AI Insights newsletter or other communications.
Data collected automatically — technical & usage data
- IP address — collected at the server level and by analytics tools; used to infer approximate geographic location (country/city level) and to protect against fraudulent or abusive traffic.
- Browser type, version, and operating system — collected via HTTP headers and used for compatibility diagnostics and aggregate audience analysis.
- Device type — desktop, tablet, or mobile; used to understand how our Site renders across device classes.
- Pages visited, navigation path, and time spent on each page — collected via first- and third-party analytics cookies to understand content performance.
- Referring URL — the web address from which you arrived at our Site, used to measure the effectiveness of marketing channels.
- UTM parameters and ad-click identifiers — appended to URLs from paid campaigns (Google Ads, etc.) to attribute conversions to specific campaigns or ad groups.
- Form interaction data — fields focused, errors encountered, and submission timestamp; used to improve form usability.
Data from cookies and similar technologies
- First-party session and preference cookies — maintain your session state and remember any site preferences you configure.
- Google Analytics cookies (_ga, _gid, _gat) — anonymous identifiers used to aggregate traffic and behavioural statistics.
- Google Ads conversion cookies (AW-*) — record whether a visit or form submission resulted from a paid advertisement, linking ad spend to outcomes.
- Google Tag Manager container — manages the loading and sequencing of all tracking scripts without additional code changes.
We do not collect special category data (sensitive personal information such as health data, biometric data, racial or ethnic origin, political opinions, or trade-union membership) through any channel on this Site. We do not accept or process payment card information directly; any commercial transactions are handled by regulated payment processors.
How We Use Your Information
Every processing activity we undertake has a defined purpose and a corresponding legal basis under the LGPD and, where relevant, the GDPR. The table below maps each purpose to the data involved and the lawful basis we rely on.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to enquiries and scheduling consultations | Name, email, phone, message content, company | Consent / Legitimate Interest |
| Delivering and managing contracted Services | Name, email, company, project context | Contract Performance |
| Sending the AI Insights newsletter and related content | Name, email, subscription timestamp | Consent |
| Site analytics and performance measurement | IP (anonymised), device, pages visited, UTM data | Legitimate Interest |
| Advertising conversion tracking (Google Ads) | Click identifiers, IP, conversion event data | Consent |
| Fraud prevention and security monitoring | IP address, usage patterns, form submissions | Legitimate Interest |
| Compliance with legal obligations (tax, regulatory) | Contract and transaction-related data | Legal Obligation |
| Improving the Site and our service offerings | Aggregate analytics, form interaction data | Legitimate Interest |
Where we rely on legitimate interests as a legal basis, we have conducted a balancing assessment to confirm that our interests do not override your fundamental rights and freedoms. Where we rely on consent, you may withdraw that consent at any time without detriment by contacting us at contato@meta-us.site or by using the unsubscribe link in any email communication. Withdrawal of consent does not affect the lawfulness of processing that took place before the withdrawal.
Cookies & Tracking Technologies
Cookies are small text files placed on your device by your browser at the instruction of the website you visit. We also use similar technologies such as web beacons and tracking pixels. Below is a clear breakdown of the cookies active on this Site, grouped by function.
Managing your cookie preferences: When you first visit our Site, a consent banner provides you with the option to accept or reject non-essential cookies. You may change your preferences at any time by clicking the "Cookie Settings" link in the site footer. Additionally, most browsers allow you to block or delete cookies through their settings menus. Bear in mind that disabling analytics or advertising cookies will not prevent you from accessing any of our content, but it will affect our ability to measure site performance and campaign effectiveness.
You can also opt out of Google's measurement cookies across all websites by installing the Google Analytics Opt-out Browser Add-on, and manage personalised advertising preferences at Google Ads Settings.
Sharing With Third Parties
We do not sell, rent, or trade your personal data with third parties for their own marketing or commercial purposes. We share data only to the extent necessary to operate our Site and deliver our Services, and only with parties that maintain appropriate safeguards.
Service providers acting on our behalf (data processors)
- Google LLC (Google Analytics, Google Ads, Google Tag Manager) — receives anonymised analytics data and conversion signals. Google acts as a data processor under a Data Processing Addendum compliant with GDPR Standard Contractual Clauses and LGPD requirements. Google may transfer data to servers in the United States; such transfers are governed by the applicable SCCs.
- Email marketing platform — stores your name and email address for newsletter delivery on our behalf, under a data processing agreement. We will update this section with the specific platform name should it change.
- Web hosting and infrastructure provider — our Site is hosted on servers that may be located outside Brazil. Any such provider is required to maintain security standards no less rigorous than those described in Section 7 of this policy.
- CRM / project management tools — contact form submissions may be routed to an internal CRM system to manage follow-up. Access is restricted to authorised Meta Plural personnel.
Legal, regulatory, and safety disclosures
- We may disclose personal data to courts, law enforcement agencies, regulators (including Brazil's Autoridade Nacional de Proteção de Dados — ANPD), or other public authorities when required to do so by law, judicial order, or regulatory mandate.
- We may also share data where we believe in good faith that disclosure is necessary to protect our rights, prevent fraud, or respond to a credible safety threat.
Business transfers
- In the event of a merger, acquisition, restructuring, or sale of all or part of Meta Plural's business, personal data held by us may be transferred to the acquiring entity. We will notify you of any such change via the email address on file and will ensure the recipient entity is bound by terms at least as protective as this policy.
All third-party processors are contractually prohibited from using your data for any purpose beyond the specific service they provide to us. We conduct periodic reviews of our vendor data-processing agreements to confirm ongoing compliance.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. The criteria we use to determine retention periods are described below.
Enquiry and contact form data is retained for a period of 24 months from the date of your last interaction with us. After this period, records are reviewed: if no active or prospective business relationship exists, the data is securely deleted or irreversibly anonymised.
Active client data relating to contracted services — including project correspondence, briefs, and deliverables — is retained for the duration of the contract and for a further 5 years after contract termination, in line with Brazil's statute of limitations for commercial disputes (Código Civil, Art. 206, §5º, I) and general tax record-keeping requirements.
Newsletter subscriber data is retained for as long as your subscription remains active. If you unsubscribe, your email address is removed from active distribution lists within 10 business days. A suppression record (the email address only, flagged as unsubscribed) may be retained to honour your opt-out and prevent accidental re-addition.
Analytics data processed via Google Analytics is retained for 14 months within the Google Analytics platform, as configured by us. Raw server logs containing IP addresses are retained for no more than 90 days for security and diagnostic purposes.
Advertising conversion data (Google Ads) is retained in accordance with Google's standard data retention policies, which you can review at Google's Privacy & Terms portal. We retain aggregated campaign performance reports indefinitely as they no longer identify individuals.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Because we are a technology-focused organisation, security is not treated as a checkbox but as an ongoing practice.
Encryption in transit: All data exchanged between your browser and our Site is encrypted using TLS 1.2 or higher. We enforce HTTPS across the entire Site and use HSTS headers to prevent protocol downgrade attacks.
Access controls: Personal data stored in our systems is accessible only to authorised Meta Plural personnel on a need-to-know basis. We enforce role-based access controls and require strong, unique passwords combined with multi-factor authentication for all internal accounts that hold or process personal data.
Vendor security: We select service providers that hold recognised security certifications (such as ISO 27001 or SOC 2) or that provide contractual guarantees of equivalent standards. We include data security obligations in all data-processing agreements.
Security monitoring: We conduct periodic internal reviews of our data handling practices and technical configurations. Anomalous traffic patterns and potential intrusion attempts are monitored through our hosting infrastructure.
Data breach response: In the event of a personal data breach that is likely to result in risk to the rights and freedoms of individuals, we will notify the ANPD within the timeframe required by the LGPD (Art. 48), and will notify affected individuals without undue delay where legally required or where the risk to individuals is high. Notifications will describe the nature of the breach, the data affected, likely consequences, and measures taken or proposed to address it.
No security system is infallible. If you have reason to believe your data has been compromised or you identify a security vulnerability on our Site, please report it immediately to contato@meta-us.site.
Your Rights
Under the LGPD (Arts. 17–22) and, where applicable, the GDPR (Arts. 15–21), you hold the following rights with respect to your personal data. We are committed to responding to all verified requests within the timeframes required by law — no longer than 15 days under the LGPD, and one calendar month under the GDPR (extendable by a further two months for complex requests, with notice).
Right of Access & Confirmation
You may request confirmation of whether we process your personal data and, if so, obtain a copy of the specific data we hold about you, the purposes for which it is processed, and the recipients with whom it has been shared.
Right to Correction
You have the right to request correction of any inaccurate or incomplete personal data we hold. We will make corrections promptly and, where the data has been shared with third parties, will notify them of the correction where practicable.
Right to Deletion (Erasure)
You may request deletion of personal data processed on the basis of your consent, or data that is excessive, unnecessary, or processed in violation of the LGPD or GDPR. We will retain data where retention is required by law or to establish, exercise, or defend legal claims.
Right to Object & Restriction
You may object to the processing of your data where we rely on legitimate interests. You may also request that we restrict processing — for example, while we verify the accuracy of data you have contested — so that data is held but not actively used.
Right to Data Portability
You may request that we provide the personal data you submitted to us in a structured, commonly used, machine-readable format (such as CSV or JSON), or request that it be transmitted directly to another controller where technically feasible.
Right to Know About Sharing & Automated Decisions
You may request information about the public and private entities with which we share your data. We do not currently make solely automated decisions — including profiling — that produce legal or similarly significant effects. Should this change, we will update this policy and implement appropriate safeguards.
How to exercise your rights: Submit a written request to contato@meta-us.site with the subject line "Data Subject Request" and include sufficient information for us to verify your identity (e.g., the email address you used when contacting us and your full name). We do not charge a fee for reasonable requests. For requests that are manifestly unfounded or excessive, we reserve the right to charge a proportionate administrative fee or decline to act, explaining our reasoning in writing.
If you are located in Brazil and believe your rights under the LGPD have not been respected, you may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd. If you are in the European Economic Area, you have the right to lodge a complaint with your local supervisory authority.
Children's Privacy
Our Site and Services are directed exclusively at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. Our contact forms and newsletter subscription flow include a statement indicating that use is restricted to adults, and our advertising campaigns are configured to target adult audiences.
If we become aware that we have inadvertently collected personal data from a minor, we will delete that data as promptly as possible. If you are a parent or guardian and believe your child has submitted personal information to us, please contact us at contato@meta-us.site and we will act immediately.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, operational practices, or applicable law. When we make material changes — for example, introducing a new purpose for processing or engaging a new category of third-party processor — we will update the "Last updated" date prominently at the top of this page and, where you have provided us with an email address, we will notify you directly.
Minor editorial amendments, such as rewording for clarity without changing the substance of any processing activity, will be reflected by an updated date without direct notice. We encourage you to review this policy periodically to stay informed of how we protect your personal data.
The version of this policy published on this page on the date of your most recent interaction with our Site is the version that governs the processing of your data at that time. All prior versions are retained in our records and can be provided on request.
Contact & Data Controller Details
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please reach out to us directly. As both the data controller and operator of this Site, Meta Plural is the appropriate point of contact for all privacy-related matters.
Data Controller
META PLURAL COMERCIO E SERVICOS EM EQUIPAMENTOS DE AUDIO, VIDEO E INFORMATICA LTDA
CNPJ: 09.196.543/0001-09
Setor SHIS CL QI 11 Bloco P, S/N, Sala 201
Lago Sul, Brasília-DF, Brazil
Privacy Enquiries
Privacy & Data Protection Team
Email: contato@meta-us.site
Please use the subject line:
"Privacy Policy — [your request type]"
We aim to respond to all privacy-related enquiries within 5 business days, and to formally resolve data subject requests within the statutory deadline.
We take every privacy enquiry seriously. You will not be disadvantaged in any way for exercising your data protection rights or raising a concern with us.