Introduction
RADIX ENGENHARIA E DESENVOLVIMENTO DE SOFTWARE S/A ("Radix", "we", "our" or "us") is a Brazilian engineering and technology company providing advanced digital solutions — including industrial automation, data engineering, artificial intelligence, and custom software development — to clients across the energy, oil & gas, utilities, and infrastructure sectors worldwide.
We are committed to protecting the privacy and security of everyone who interacts with our website, our services, and our communications. This Privacy Policy explains what personal data we collect, for what purposes, and on what legal basis; how we store, protect, and share it; how long we keep it; and what rights you have over your own information.
This Policy applies to the website operated at radixeng.site and to any related online platforms, digital assets, or communications channels managed by Radix. It covers data subjects located anywhere in the world, with particular attention to the requirements of Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Law 13.709/2018) and the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), as well as applicable international privacy standards.
By accessing this website or submitting any form hosted on it, you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, please discontinue use of the site and contact us directly to discuss alternative means of engaging with Radix.
Information We Collect
We collect personal data only to the extent strictly necessary to deliver our services and communicate with you effectively. The categories of information we process are described below.
A. Information You Provide Directly
When you fill out a contact form, request a proposal, register for a webinar, or send us an email, you may provide:
- Identity data: full name, job title, professional role.
- Contact data: corporate or personal email address, telephone number, company name.
- Message content: the free-text content of your enquiry, project description, or feedback.
- Professional context: the industry sector, size, or technical environment you describe in your message — used solely to route your enquiry to the right Radix team.
Submission of these forms is entirely voluntary. You are not legally required to provide any information to browse the public content of this website.
B. Data Collected Automatically
When you visit our website, our servers and third-party analytics services automatically collect technical information, including:
- Device & browser data: IP address (anonymised where possible), browser type and version, operating system, screen resolution, and language preference.
- Usage data: pages visited, time spent on each page, referring URL, outbound links clicked, scroll depth, and navigation path through the site.
- Session identifiers: anonymous identifiers assigned by analytics tools to group actions within a browsing session, without identifying you personally.
- Approximate geolocation: country and city derived from your IP address — not precise GPS-level location.
This technical data is used exclusively for website performance analysis, security monitoring, and improving user experience. We do not build individual behavioural profiles for sale or use this data to make automated decisions about you.
C. Data From Third-Party Sources
On occasion, Radix may receive business contact information from professional networking platforms (such as LinkedIn), industry directories, or referral partners where you have indicated professional interest in the types of services we provide. When we do so, we rely on a legitimate interest basis and always provide you with a clear route to unsubscribe or request deletion at the first point of contact.
How We Use Your Information
We process personal data only when we have a valid legal basis to do so. The table below maps each purpose to the relevant legal basis under both the LGPD and the GDPR.
Purposes and Legal Bases
- Responding to contact form submissions and email enquiries. Legal basis: legitimate interest (LGPD Art. 7, VI; GDPR Art. 6(1)(f)) and, where pre-contractual steps are involved, performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
- Sending requested proposal documents, white papers, or event invitations. Legal basis: consent given at the time of request (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
- Marketing communications about Radix services, case studies, or industry events, sent only when you have explicitly opted in or where existing business relationship and legitimate interest apply. You may unsubscribe at any time. Legal basis: consent or legitimate interest.
- Website analytics and performance monitoring, used to identify technical errors, measure content effectiveness, and improve navigation. Legal basis: legitimate interest, subject to your cookie preferences.
- Compliance with applicable law, including responding to lawful requests from courts, regulators, or public authorities. Legal basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
- Prevention of fraud and ensuring the security of our systems. Legal basis: legitimate interest.
We do not use your personal data for automated profiling or decision-making that produces legal or similarly significant effects on you, nor do we sell personal data to any third party under any circumstances.
Cookies & Tracking Technologies
Our website uses cookies — small text files stored on your device — and similar technologies such as web beacons and pixel tags. Some are essential for the site to function; others require your consent and are only activated after you make a choice via our cookie consent banner.
| Category | Purpose | Consent Required? | Retention |
|---|---|---|---|
| Strictly Necessary | Session management, security tokens, and load-balancing required for the site to operate correctly. Cannot be disabled without breaking core functionality. | No — essential | Session or up to 12 months |
| Analytics & Performance | Google Analytics 4 (anonymised IP) tracks aggregate page views, traffic sources, and user journeys to help us improve site structure and content quality. No personally identifiable data is stored. | Yes | Up to 26 months |
| Marketing & Advertising | Google Ads conversion tags and remarketing pixels allow us to measure the effectiveness of paid campaigns and, with your consent, to show relevant Radix content to visitors who have previously browsed our site. | Yes | Up to 90 days |
| Functional / Preferences | Stores your cookie consent choice, language preference, and any form auto-fill settings so you are not asked repeatedly. | No — functional | Up to 12 months |
Managing Your Cookie Preferences
You can change or withdraw your consent at any time by clicking the "Cookie Settings" link in the footer of any page, or by adjusting the privacy settings in your browser. Most modern browsers allow you to block or delete cookies via their Settings or Preferences menus. Please note that disabling non-essential cookies will not affect your ability to read content on this site, but some interactive features may become unavailable.
For detailed information on Google Analytics data practices, visit policies.google.com/privacy. To opt out of Google Analytics across all websites, you may install the Google Analytics Opt-out Browser Add-on.
Sharing With Third Parties
Radix does not sell, rent, or trade personal data. We share data with third parties only in the limited circumstances described below, and only with service providers who are contractually bound to process it strictly on our behalf and in accordance with this Policy.
- Cloud infrastructure and hosting providers — Our website is hosted on servers located in Brazil and/or the European Union. Hosting providers process technical and log data as data processors under a Data Processing Agreement (DPA) with Radix.
- Analytics platforms — Google LLC processes anonymised usage data on our behalf under a DPA. Google Analytics is configured with IP anonymisation enabled, meaning no full IP address is stored.
- Email and CRM platforms — Messages you send via contact forms may pass through a third-party email delivery or CRM platform. These providers act solely as processors and are prohibited from using the data for any other purpose.
- Legal and regulatory authorities — We may disclose personal data when required to do so by applicable law, court order, or request from a competent regulatory authority (such as Brazil's Autoridade Nacional de Proteção de Dados — ANPD), provided we are legally permitted to notify you of such a disclosure.
- Corporate transactions — In the event of a merger, acquisition, or sale of assets, personal data held by Radix may be transferred to a successor entity, subject to equivalent privacy protections and prior notice to affected individuals where legally required.
Where data is transferred to countries outside Brazil or the European Economic Area that do not offer an equivalent level of data protection, Radix implements appropriate safeguards — including Standard Contractual Clauses (SCCs) approved by the European Commission and contractual measures consistent with LGPD Chapter V — to ensure your information remains protected.
Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our standard retention guidelines are as follows:
- Contact form enquiries and pre-sales correspondence: retained for up to 3 years from the date of last meaningful interaction, after which they are securely deleted or anonymised unless a contract was formed.
- Active client records: retained for the duration of the engagement plus 5 years, consistent with Brazilian civil liability limitation periods and applicable fiscal regulations.
- Marketing consent records: retained until you withdraw consent, plus an additional 2 years to evidence compliance if required by regulators.
- Website server logs and IP addresses: retained for up to 6 months for security and fraud prevention purposes, then deleted.
- Aggregated and anonymised analytics data: retained indefinitely, as it no longer constitutes personal data.
When the retention period expires, data is either permanently deleted using industry-standard secure deletion procedures or irreversibly anonymised so that it can no longer be linked to any individual.
Data Security
Radix applies technical and organisational measures appropriate to the nature of the data and the risks involved in its processing. As an engineering company, security is embedded into our operational culture — not treated as an afterthought. Key measures include:
- Encryption in transit: all data transmitted between your browser and our servers is protected by TLS 1.2 or higher (HTTPS). Contact form submissions are encrypted end-to-end before storage.
- Access controls: personal data is accessible only to Radix personnel who genuinely need it to fulfil their duties, enforced via role-based access control and multi-factor authentication on internal systems.
- Regular security assessments: our systems undergo periodic vulnerability scans and penetration testing conducted by qualified security professionals.
- Incident response: in the event of a personal data breach that poses a risk to affected individuals, Radix will notify the relevant supervisory authority (ANPD and/or national DPAs as applicable) within the timeframes prescribed by law, and will notify affected individuals directly where legally required.
- Vendor due diligence: all third-party data processors are assessed for adequate security practices before engagement and are bound by DPAs requiring equivalent technical safeguards.
While we implement these protections diligently, no method of electronic transmission or storage is 100% secure. If you have any reason to believe that your interaction with us has been compromised, please contact us immediately at contato@radixeng.site.
Your Rights
Depending on your location and the applicable data protection law (LGPD, GDPR, or other relevant legislation), you have the following rights with respect to the personal data we hold about you. These rights are not absolute — some are subject to conditions, exemptions, or overriding legal obligations — but we will always respond to any exercise of rights promptly and transparently.
Right of Access
You may request a copy of the personal data we hold about you, along with information about how and why we process it.
Right to Rectification
If any data we hold is inaccurate or incomplete, you may ask us to correct or update it at any time.
Right to Erasure
You may request deletion of your personal data where there is no compelling reason for us to continue processing it, subject to our legal retention obligations.
Right to Object
You may object to processing based on our legitimate interests or for direct marketing purposes. Where marketing is concerned, we will always honour your objection immediately.
Right to Restrict Processing
In certain circumstances, you may ask us to pause processing of your data — for example, while the accuracy of the data is being verified.
Right to Data Portability
Where processing is based on your consent or a contract, you may request that we provide your data in a structured, commonly used, machine-readable format.
Right to Withdraw Consent
Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to Lodge a Complaint
You have the right to complain to a supervisory authority. In Brazil: ANPD (gov.br/anpd). In the EU: your national Data Protection Authority.
How to Exercise Your Rights
To submit a data subject request, please send an email to contato@radixeng.site with the subject line "Data Subject Request". Please include your full name, the email address you used when contacting Radix, and a clear description of the right you wish to exercise. We may request additional information to verify your identity before processing the request — this is purely a security measure to prevent unauthorised disclosure.
We will acknowledge receipt within 5 business days and aim to fulfil all requests within 15 days, consistent with LGPD Article 19 requirements. Where a request is complex or we have received a high volume, we may extend this period by a further 15 days with prior notification and explanation.
Children's Privacy
The Radix website and our services are directed exclusively at businesses and professionals operating in industrial and technology sectors. We do not intentionally collect, process, or store personal data relating to children under the age of 16 (or such higher age as applicable local law prescribes).
If we become aware that personal data belonging to a child has been submitted to us, we will take immediate steps to delete it and, where required by law, to notify the relevant supervisory authority. If you believe a child has submitted personal information through our website, please contact us immediately at contato@radixeng.site.
Changes to This Policy
Data protection law evolves, and so do our practices. We review this Privacy Policy at least annually and update it whenever we make significant changes to our data processing activities, introduce new services, or in response to regulatory guidance or legal amendments.
When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify registered contacts by email or via a notice on our website prior to the changes taking effect. For minor editorial or clarifying amendments, we will update the page without separate notification.
We encourage you to review this Policy periodically. Continued use of this website after any published changes constitutes acceptance of the revised terms. If you disagree with a material change, you may exercise your rights as described in Section 08, including requesting deletion of your data.
Previous versions of this Policy are available on request by emailing contato@radixeng.site.
Contact & Data Protection Officer
Questions, concerns, or requests related to this Privacy Policy or to your personal data should be directed to the Radix privacy team. We take every enquiry seriously and will respond within the timeframes set out in Section 08.
You are welcome to use email for all data protection matters. If you require written correspondence for legal or regulatory purposes, please address it to our registered office below and mark the envelope "Data Protection — Confidential."
Company & Contact Details
RADIX ENGENHARIA E DESENVOLVIMENTO DE SOFTWARE S/A
Registered Address Rua do Passeio, 38, Sala 1401 Setor 2
Centro, Rio de Janeiro – RJ
Brazil
Privacy & Data Protection contato@radixeng.site
Please use the subject line "Privacy Policy Enquiry" or "Data Subject Request" as appropriate so your message reaches the right team without delay.
If you are not satisfied with the response you receive from us, you have the right to escalate your complaint to Brazil's national supervisory authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd. EU-based residents may escalate to their national Data Protection Authority as listed at edpb.europa.eu.