LGPD · Brazil's Law 13,709/2018
Privacy Policy
This is a translation of the Portuguese version; in case of any discrepancy, the Portuguese version prevails. Read the Portuguese version.
This policy describes how No Vuln (Brazilian company registration, CNPJ 48.992.864/0001-63) collects, uses, stores and protects personal data. It applies to visitors to novuln.com.br and to clients who hire our services.
Last updated: 2026-09-28
1. Data controller
Legal name: No Vuln Tecnologia LTDA
Company registration (CNPJ): 48.992.864/0001-63
Address: Brazil
Contact (Data Protection Officer — “Encarregado” under the LGPD): [email protected]
For any request regarding your personal data — access, correction, deletion, portability, withdrawal of consent — use the email above. We respond within 15 business days (LGPD Art. 19).
2. What data we collect
2.1. Through the contact form
- Name — so we know how to address you
- Email — to reply to your inquiry and send a proposal
- Company — to understand the context of the scope
- Phone / WhatsApp — required, so we can follow up quickly
- System URL (optional) — address of the system to be assessed
- Main stack (optional) — technology used, to size the scope
- Message (optional) — a description of what you need
2.2. Automatically, while you browse
- IP address — for anti-spam rate limiting
- Anonymous browsing data — pages visited, reading time, device, browser, approximate country (via Vercel Analytics and Google Analytics 4, both with IP anonymization)
- Performance metrics — load times and errors (Vercel Speed Insights)
2.3. What we do NOT collect
- Sensitive personal data (health, biometrics, religion)
- Data from minors
- Browsing history outside our domain
- Identity documents (such as Brazil's CPF or RG) — never requested through the form
3. Why we collect it (legal bases)
Each type of collection above has a specific legal basis under LGPD Art. 7:
- Contact form: consent (Art. 7, I) + performance of a contract (Art. 7, V)
- IP-based rate limiting: legitimate interest in protecting the service (Art. 7, IX)
- Cookieless analytics (Vercel Analytics and Speed Insights): legitimate interest in improving the site (Art. 7, IX) — no cookies or individual identifiers
- Cookie-based analytics (Google Analytics 4 and Microsoft Clarity): consent (Art. 7, I), obtained through the cookie banner before any identifiable data is collected
4. Processors and data sharing
We share only strictly necessary data with the following processors (LGPD Art. 5, VII and Art. 39):
| Processor | What it receives | Purpose |
|---|---|---|
| Vercel (hosting) | Access logs, metrics | Site hosting and CDN |
| Resend (email) | Contact form content | Delivering your message to our inbox |
| Google Analytics 4 | Anonymous browsing events | Traffic analysis (with IP anonymization) |
| Microsoft Clarity | Anonymous browsing sessions | Heatmaps and UX analytics |
We do not sell, rent or transfer personal data to third parties for marketing purposes.
International transfer: Vercel, Resend, Google Analytics 4 (Google) and Microsoft Clarity (Microsoft) have infrastructure outside Brazil and may process the data above in other countries. This international transfer follows LGPD Art. 33 and ANPD Resolution No. 19/2024, with contractual safeguards equivalent to those required by the LGPD.
5. Cookies
The site uses three categories of cookies:
- Essential — for basic functionality (session, security). They don't require consent.
- Analytics — Google Analytics 4 and Microsoft Clarity. These scripts load in “denied” mode by default (Google Consent Mode v2): no cookies and no individual identifiers until you accept in the banner. They only collect (always anonymous) browsing data after consent.
- Marketing — we don't currently use any.
You can withdraw your consent at any time by clicking “Manage cookies” in the footer.
6. How long we keep it
| Type | Retention |
|---|---|
| Contact form messages | 5 years (statute of limitations for commercial claims) |
| Contract data (clients) | 5 years after the contract ends |
| Access logs | 6 months |
| Browsing analytics | 14 months (GA4 default setting) |
7. Your rights (LGPD Art. 18)
You may, at any time, request:
- Confirmation that we process your data
- Access to your data
- Correction of incomplete, inaccurate or outdated data
- Anonymization, blocking or deletion of unnecessary data
- Portability of your data to another provider
- Deletion of data processed based on your consent
- Information about the processors we share data with
- Withdrawal of consent
To exercise any of these rights, email [email protected]. We respond within 15 business days.
8. Data subjects outside Brazil (including under the GDPR)
If you are located outside Brazil — including in the European Union, where the General Data Protection Regulation (GDPR) may apply — you have the following rights regarding your personal data:
- Access — confirm whether we process your data and obtain a copy of it
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your data deleted
- Objection — object to processing based on our legitimate interest (see section 3); for analytics, you can also opt out at any time under “Manage cookies”
- Portability — receive your data or have it transferred to another provider
- Complaint — lodge a complaint with your local data protection authority
To exercise these rights, use the same channel: [email protected]. We respond within the same period described in section 7.
The legal bases are those described in section 3. No Vuln is based in Brazil: your data is handled by our team and by the processors listed in section 4 (Vercel, Resend, Google Analytics 4 and Microsoft Clarity), for the purposes described there and for the retention periods in section 6.
9. Data security
As a penetration testing company, we take this section seriously. We have adopted the following technical and administrative measures:
- HTTPS / TLS 1.3 on all traffic
- HSTS enabled with preload
- Anti-spam rate limiting on the form (3 submissions / IP / hour)
- Anti-bot honeypot
- Input sanitization (HTML stripping, URL validation)
- CSP headers, X-Frame-Options, X-Content-Type-Options
- NDA before any technical conversation with clients
- Annual pentest of our own infrastructure
- Incident response plan (LGPD Art. 48)
In the event of a security incident affecting personal data, we will notify Brazil's National Data Protection Authority (ANPD) within 3 business days, as required by ANPD Resolution No. 15/2024, and the affected data subjects within a compatible timeframe, as required by LGPD Art. 48.
10. Responsible disclosure
Found a vulnerability on novuln.com.br? Report it following our disclosure policy at /.well-known/security.txt (RFC 9116). Researchers who follow the policy are covered by safe harbor.
11. Changes to this policy
This policy may be updated from time to time. Substantial changes will be announced on the site (banner), and the date of the last update will always be shown at the top of this page. Continuing to use the site after a change means you accept the updated version.
12. Governing law and venue
This policy is governed by Brazilian law, in particular Law 13,709/2018 (LGPD) and the Brazilian Internet Civil Framework (Marco Civil da Internet, Law 12,965/2014). Venue: the courts of the judicial district (Comarca) of São José do Rio Preto, State of São Paulo, Brazil.