Who We Are and Why This Policy Exists
Softplan Planejamento e Sistemas S/A ("Softplan", "we", "us", or "our") is a Brazilian technology company incorporated under CNPJ 82.845.322/0001-04, headquartered at Avenida Luiz Boiteux Piazza, 1302 — Lote 87/89, Cachoeira do Bom Jesus, Florianópolis, Santa Catarina, Brazil. Since 1990 we have built purpose-built software for public administration, justice, and urban-infrastructure management, serving more than 2,000 organisations and approximately 260,000 daily users across Brazil.
This Privacy Policy governs how we collect, use, store, protect, and disclose information about anyone who visits softplan.site, submits an enquiry through our contact forms, downloads our materials, or otherwise interacts with our digital properties. It applies equally to visitors located in Brazil (subject to the Lei Geral de Proteção de Dados Pessoais — Law 13.709/2018, the LGPD) and to those located in the European Economic Area or the United Kingdom (subject to the General Data Protection Regulation — GDPR and UK GDPR), as well as any other applicable jurisdiction.
We act as the data controller for all personal information processed in connection with our marketing website and communications. Where Softplan processes data on behalf of a client organisation using one of our licensed software products, a separate data-processing agreement governs that relationship, and the client organisation is the controller.
By continuing to use this site you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of the site and contact us at contato@softplan.site with any questions.
What Personal Data We May Process
We collect personal information through two broad channels: data you actively provide to us, and data generated automatically when you interact with our website. We only collect what is genuinely necessary for the purposes described below.
Data You Provide Directly
When you fill in our contact form, request a product demonstration, download a white paper or case study, or subscribe to our newsletter, you may submit some or all of the following:
- Full name — so we can address you correctly and personalise correspondence.
- Business email address — our primary channel for responding to your enquiry and sending requested materials.
- Telephone number — optionally provided, used only when you request a call-back or scheduling of a product demonstration.
- Organisation name and role — helps our team route your enquiry to the correct product specialist and understand the context of your needs.
- State or municipality — allows us to connect you with the regional representative best placed to assist you.
- Message content — the specific question, comment, or request you submit via the free-text field in any of our forms.
Never submit sensitive data through our contact forms. Our general-enquiry forms are not designed to receive data revealing racial or ethnic origin, health information, political opinions, religious beliefs, criminal records, biometric identifiers, or any other special-category data. Please limit submissions to business-relevant information only.
Data Collected Automatically
When you access softplan.site, our servers and third-party analytics tools automatically record certain technical information. This data is used in aggregate form to improve website performance and, where applicable, to measure the effectiveness of our digital-marketing campaigns:
- IP address — recorded at the server level and used for security monitoring and geolocation at country or region level. We do not attempt to identify individuals from IP addresses alone.
- Browser type and version, operating system, and device type — used to ensure the site renders correctly across different environments.
- Referring URL and on-site navigation path — tells us which pages attract the most interest and where visitors arrive from, helping us improve content relevance.
- Session timestamps and page-dwell time — aggregate engagement metrics used to prioritise content development and identify underperforming pages.
- Cookie identifiers and advertising click IDs — generated by Google Analytics and Google Ads (and, where active, LinkedIn Insight Tag) when you arrive via a tracked link; used to measure campaign performance and conversion rates. See Section 04 for full details.
- Form-interaction events — anonymised signals indicating whether a form was started, partially completed, or submitted; used to identify usability problems in our lead-capture flows.
The Purposes and Legal Bases for Processing
We process personal data only where we have a lawful basis for doing so. The table below sets out each processing purpose alongside the legal basis under the LGPD (Art. 7 or Art. 11) and the equivalent GDPR lawful basis (Art. 6).
Responding to Enquiries and Requests
When you submit a contact form or request a product demonstration, we use the information you provided — name, email, organisation, message content — to respond to your specific request, schedule a call or meeting with the appropriate Softplan specialist, and follow up if our initial response did not resolve your query. Legal basis: Legitimate interests (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) — we have a compelling legitimate interest in responding to businesses that have proactively reached out to us, and this interest is not overridden by your privacy rights given that you initiated the contact.
Sending Requested Marketing Materials
If you download a report, case study, or white paper, we may send you a single follow-up email containing related resources you are likely to find useful. We do not enrol you in ongoing email sequences without your express opt-in consent. Legal basis: Consent (LGPD Art. 7 I; GDPR Art. 6(1)(a)), which you may withdraw at any time by clicking the unsubscribe link in any communication or by emailing contato@softplan.site.
Newsletter and Product Updates
Where you explicitly subscribe to our newsletter, we will use your email address to send periodic updates about Softplan product releases, industry events, public-administration technology trends, and company news. Each email includes a one-click unsubscribe link. Legal basis: Consent (LGPD Art. 7 I; GDPR Art. 6(1)(a)).
Website Analytics and Performance
Automatically collected technical data is used in pseudonymised or aggregated form to measure site traffic, identify popular content, diagnose technical errors, and plan future site improvements. Legal basis: Legitimate interests (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) — maintaining a well-functioning, secure, and content-rich website serves both Softplan and site visitors.
Digital Advertising Measurement
We use Google Ads conversion tracking and, selectively, LinkedIn Insight Tag to measure whether visitors who clicked on one of our paid advertisements later submitted an enquiry or took another valuable action. This data informs our media spend allocation. Legal basis: Consent obtained via our cookie-consent mechanism (LGPD Art. 7 I; GDPR Art. 6(1)(a)). Where consent has not been granted, advertising tags are not fired.
Security and Fraud Prevention
Server logs, IP addresses, and behavioural signals are retained for a limited period to detect and respond to malicious bot traffic, denial-of-service attempts, form spam, and other security threats. Legal basis: Legitimate interests (LGPD Art. 7 IX; GDPR Art. 6(1)(f)).
We do not sell your personal data. We do not trade, sell, rent, or barter personal information to data brokers, advertising networks (other than as described in Section 04), or any other third party for their own commercial gain.
How We Use Cookies and Similar Technologies
Cookies are small text files placed on your device by a website to remember preferences and recognise return visits. We also use pixel tags (1×1 image beacons) and script-based tracking SDKs. On your first visit, a consent banner gives you granular control over which categories of cookie may be set. Your preference is stored and respected on every subsequent visit.
Cookie Categories We Use
Managing and Withdrawing Cookie Consent
You can review and change your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of any page. You may also instruct your browser to block all cookies or delete existing cookies; consult your browser's help documentation for instructions. Note that blocking strictly necessary cookies will impair the website's core functions.
For Google Analytics opt-out across all sites, you can install the Google Analytics Opt-out Browser Add-on. For interest-based advertising opt-out in Brazil, visit aboutads.info.
Do Not Track
Some browsers transmit a "Do Not Track" (DNT) signal. Our site currently does not alter its behaviour in response to DNT signals, given the absence of a uniform technical standard. We rely on our consent mechanism — described above — to ensure tracking only occurs where you have affirmatively agreed.
When and With Whom We Share Your Data
We do not disclose your personal information to third parties except in the circumstances described below. Any third party that processes data on our behalf does so under a written data-processing agreement that obligates them to handle data only as instructed, maintain appropriate security measures, and not use the data for their own purposes.
Service Providers and Sub-Processors
- Google LLC — provides Google Analytics, Google Ads, and Google Workspace (business email and document management). Covered by Google's EU Standard Contractual Clauses and Google's agreement with the Brazilian ANPD where applicable.
- LinkedIn Ireland Unlimited Company — provides the LinkedIn Insight Tag for B2B campaign measurement. Processing governed by LinkedIn's Data Processing Agreement.
- CRM and marketing-automation platform — enquiry data submitted via our contact forms flows into our CRM system (RD Station or equivalent) to enable structured follow-up by our sales team. Data is stored on servers located in Brazil.
- Hosting and CDN provider — our website infrastructure is hosted on cloud servers in Brazil (or behind a globally distributed CDN). Hosting providers access server logs for operational purposes only and under strict confidentiality obligations.
- Email delivery infrastructure — transactional and marketing emails are delivered via an authenticated mail-delivery service. Delivery logs (sent/opened/clicked events) are retained for up to 90 days for deliverability diagnostics.
Legal and Regulatory Disclosures
We may disclose personal data to courts, government authorities, regulatory bodies (including Brazil's Autoridade Nacional de Proteção de Dados — ANPD), or law-enforcement agencies where disclosure is required by applicable law, by a court order, or is reasonably necessary to: (a) comply with a legal obligation; (b) protect and defend Softplan's rights or property; (c) prevent or investigate possible wrongdoing; or (d) protect the personal safety of users or the public. We will, where legally permitted, notify the affected individual before making such a disclosure.
Business Transfers
If Softplan undergoes a merger, acquisition, reorganisation, or sale of all or a substantial part of its assets, personal data held by us may be transferred to the successor entity as part of that transaction. We will notify you via email and/or a prominent notice on this website before your data becomes subject to a materially different privacy policy, and you will retain the right to request deletion of your data at that time.
International Data Transfers
Softplan is headquartered in Brazil and processes data primarily within Brazil. Where data flows to service providers located outside Brazil (for example, to Google's infrastructure in the United States or the European Union), we ensure that adequate safeguards are in place — such as Standard Contractual Clauses approved by the European Commission, Google's ANPD-recognised framework, or equivalent mechanisms — in accordance with LGPD Chapter V and GDPR Chapter V requirements.
How Long We Keep Your Information
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, to comply with applicable legal and regulatory obligations, to resolve disputes, and to enforce our agreements. The specific retention periods we apply are:
- Contact-form enquiries: Data is retained in active CRM records for up to 24 months from last contact. If no commercial relationship develops, records are archived and then deleted. Active client records follow the contractual and statutory retention period applicable to that relationship (typically 5 years after contract end, in line with Brazilian civil and tax law).
- Email marketing lists: Retained until you unsubscribe or request deletion, after which your address is added to a suppression list for up to 3 years to prevent accidental re-subscription, then permanently deleted.
- Analytics data (Google Analytics): Retained in Google Analytics for 14 months, after which event-level data is automatically deleted by Google. Aggregated, anonymised reports may be retained indefinitely for historical benchmarking.
- Advertising-measurement cookies: Retained for up to 90 days from the ad interaction, in accordance with Google Ads and LinkedIn Insight Tag default settings.
- Server and security logs: Retained for a maximum of 90 days, after which they are automatically purged, unless a specific log line is preserved as evidence in connection with a confirmed security incident or legal proceeding.
- Data subject rights requests: Records of requests you make under Section 08 below — including proof of identity, the nature of the request, and our response — are retained for 5 years to demonstrate compliance and to handle any subsequent complaints or regulatory enquiries.
When a retention period expires, personal data is securely and irreversibly deleted or anonymised so that it can no longer be associated with an identifiable individual.
How We Protect Your Information
Information security is not an afterthought at Softplan — it is fundamental to our credibility as a provider of mission-critical software to government institutions. We apply a defence-in-depth approach to all systems that hold personal data, including this website and our CRM platform.
Technical Measures
- All data transmitted between your browser and our servers is encrypted using TLS 1.2 or TLS 1.3. Our site enforces HTTPS with HSTS headers to prevent downgrade attacks.
- Access to CRM data and form submissions is restricted to authorised Softplan employees on a role-based, least-privilege basis. Access credentials are protected by multi-factor authentication.
- Our hosting infrastructure undergoes regular vulnerability assessments and is patched promptly against known CVEs.
- Backups are encrypted at rest using AES-256 and stored in a geographically separate location from primary data.
- Web application firewall (WAF) and DDoS mitigation services protect the site against automated attacks and abusive traffic patterns.
Organisational Measures
- All staff with access to personal data complete annual data-protection training and are bound by confidentiality obligations in their employment contracts.
- We maintain an internal data-protection policy and incident-response plan that is reviewed and updated at least annually.
- Third-party vendors are assessed for security maturity before being onboarded and are subject to contractual security obligations.
Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, Softplan will notify the relevant supervisory authority (Brazil's ANPD and/or the relevant EU supervisory authority, as applicable) within 72 hours of becoming aware of the breach, as required by LGPD Art. 48 and GDPR Art. 33. Where the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay, providing a clear description of the nature of the breach and the steps we have taken in response.
Important reminder: No system connected to the internet can guarantee absolute security. While we invest significantly in protective measures, we encourage you to use a strong, unique password for any Softplan account and to contact us immediately at contato@softplan.site if you suspect any unauthorised access to your information.
Your Data-Protection Rights and How to Exercise Them
Depending on your location and the legal framework that applies to your data, you may hold some or all of the following rights. Brazilian residents are entitled to the rights set out in LGPD Art. 18; EEA and UK residents hold equivalent rights under GDPR Art. 15–22. We honour both sets of rights for all users regardless of location, to the extent technically and legally possible.
Right of Access
You may request a copy of all personal data we hold about you, together with information about the purposes for which it is processed, the categories of data, and any third parties it has been shared with.
Right of Correction
If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to have it corrected promptly. You may update your email subscription details directly via the link in any newsletter we send.
Right to Deletion (Erasure)
You may request that we delete your personal data where it is no longer needed for the original purpose, where you have withdrawn consent, or where processing is unlawful. We will comply unless we are required to retain the data by law.
Right to Object
You may object to processing carried out on the basis of legitimate interests at any time, including processing for direct marketing. Where you object to marketing, we will cease all marketing communications immediately.
Right to Restriction
You may ask us to restrict processing — for example, while you contest the accuracy of data we hold, or while we assess an objection you have raised. During restriction, we will store the data but not actively process it.
Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you may request a copy of your data in a structured, machine-readable format (CSV or JSON), suitable for transfer to another data controller.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. This includes email marketing and analytics cookies.
Right to Lodge a Complaint
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with Brazil's ANPD (gov.br/anpd) or, for EEA residents, with your local data-protection authority.
How to Submit a Rights Request
To exercise any of the rights above, please send a written request to contato@softplan.site with the subject line "Data Rights Request". Your request should include: your full name, the email address under which your data is held, a clear description of the right you wish to exercise, and — for access or deletion requests — a copy of a government-issued ID so we can verify your identity. We do not charge a fee for rights requests unless they are manifestly unfounded or repetitive.
We will acknowledge your request within 2 business days and provide a substantive response within 15 calendar days (extendable by a further 30 days where the request is complex, with prior notice to you), in line with LGPD Art. 18, §3 and GDPR Art. 12(3).
Our Site Is Not Directed at Children
Softplan's website and services are designed exclusively for business and government professionals. We do not knowingly collect, solicit, or process personal data relating to children under the age of 18. Our contact forms do not knowingly accept submissions from minors, and our marketing campaigns are targeted at corporate decision-makers, public administrators, and IT professionals.
If you are a parent or guardian and you believe that a child under 18 has submitted personal data to us without your consent, please contact us immediately at contato@softplan.site. Upon verification, we will delete that information promptly and take steps to prevent recurrence. LGPD Chapter II, Section III (Art. 14) provisions relating to children's data are respected in full.
How We Notify You of Updates
We review this Privacy Policy at least annually and whenever a material change in our data practices, applicable law, or guidance from supervisory authorities necessitates an update. The "Last updated" date at the top of this page always reflects the date of the most recent revision.
Where changes are material — for example, a new category of data being collected, a new third-party sub-processor with significant data access, or a change in the legal basis for processing — we will notify active newsletter subscribers by email at least 14 days before the change takes effect, and display a prominent notice on the site homepage. For non-material changes (corrections of grammar or typos, editorial clarifications that do not alter substance), no individual notification will be sent but the revision date will be updated.
Continued use of softplan.site after a material change has been communicated and has taken effect constitutes your acknowledgement of the updated policy. If the updated policy is not acceptable to you, please discontinue use of the site and contact us at contato@softplan.site to exercise your right to deletion.
Previous versions of this Privacy Policy are available on request — contact us using the details in Section 11.
Get in Touch About Your Privacy
If you have any questions, concerns, or comments about this Privacy Policy, about the way we handle your personal data, or if you wish to exercise a data-protection right, please contact us through any of the channels below. We are committed to resolving all privacy-related enquiries promptly and transparently.
Softplan Planejamento e Sistemas S/A
Responsible for the processing of personal data collected via softplan.site.
For complaints that you feel we have not adequately resolved, you retain the right to escalate your concern to the Autoridade Nacional de Proteção de Dados (ANPD), Brazil's national data-protection supervisory authority, at gov.br/anpd. EEA residents may contact their national supervisory authority — a full list is available at edpb.europa.eu.