Privacy Policy

This translation is provided for convenience. In case of any divergence, the Portuguese version prevails.

Privacy and Personal Data Protection Policy, ECM Tech Center

Version: 1.1, August 2026
Last updated: 16/08/2026

This Policy has been prepared in compliance with Law No. 13.709/2018 (Lei Geral de Proteção de Dados Pessoais, Brazilian General Data Protection Law, LGPD), the Marco Civil da Internet (Brazilian Internet Civil Framework, Law No. 12.965/2014), Decree No. 7.962/2013 and the guidelines of the Autoridade Nacional de Proteção de Dados (Brazilian National Data Protection Authority, ANPD).


1. DATA CONTROLLER

ECM Tech Center
CNPJ: 36.736.997/0001-90
Data Protection Officer (DPO) e-mail: Contact@ecmtechcenter.com (or Contact@ecmtechcenter.com while a dedicated address is not active)
Address: Rua Mimoso, 42, AP 01, Campo Grande - MS, CEP 79.044-042

The Data Protection Officer (Encarregado de Dados, DPO), required by art. 41 of the LGPD for operations involving large-scale processing of sensitive data, will be formally appointed and reported to the ANPD when the volume of operations so requires. For this initial phase, the contact channel above handles privacy requests.


2. DATA WE COLLECT AND WHY

ECM Tech Center collects only the data strictly necessary to provide its services (data minimization principle, art. 6, III, of the LGPD):

Data category Examples Purpose Legal basis (LGPD art. 7)
Identification Name, CPF, CNPJ Issuing invoices (NF), customer identification Performance of contract (item V)
Contact Phone/WhatsApp, e-mail Communication about the service/order Performance of contract (item V)
Address Postal code (CEP), full street address Shipping and return of modules Performance of contract (item V)
Module technical data Brand, model, part number, DTC Diagnosis and repair Performance of contract (item V)
Vehicle data Make, model, year, license plate (optional) Confirming compatibility Legitimate interest (item IX)
Browsing data IP, cookies, pages visited Website operation, traffic analysis Legitimate interest (item IX) / Consent (item I) for analytics
Service history Previous service orders Warranty support, recurrences Performance of contract (item V) / Legal obligation (item II)

We do not collect: health data, biometric data, data on political, religious or ethnic affiliation, or any sensitive categories set out in art. 11 of the LGPD.

We do not collect data from persons under 18 years of age. Our services are intended exclusively for professionals and companies in the automotive sector. If we identify that data from a minor has been inadvertently provided, we will delete it immediately.


3. HOW WE USE THE DATA

3.1 For the performance of service and sales contracts

We use your data to: perform the diagnosis and repair of the module, communicate the status of the service order, issue the technical report and invoice, handle shipping and return logistics, and process payment with our partner platforms.

3.2 For compliance with legal obligations

Tax data (CNPJ, CPF, address) is kept for the minimum period required by federal tax legislation, generally 5 (five) years as provided in Decree-Law No. 486/1969 and the rules of the Receita Federal do Brasil (Brazilian Federal Revenue Service).

3.3 For the legitimate interest of ECM Tech Center

We use anonymized browsing data for the continuous improvement of the website and performance analysis. We use service history to identify recurring defect patterns in certain module models, which improves the technical quality of future repairs. Before any new use based on legitimate interest, we carry out a balancing test (LIA, Legitimate Interest Assessment) to verify that the use does not override the rights of the data subject.

3.4 For commercial communications (with consent)

We send information about new services, promotions or technical content only to customers who have expressly consented at the time of registration. Consent may be withdrawn at any time through the contact channel, free of charge.


4. DATA SHARING

ECM Tech Center does not sell or share personal data with third parties for commercial purposes. Data is shared only in the following strictly necessary situations:

  • Carriers and Correios: name and address of the recipient, exclusively for delivery purposes;
  • Payment platforms: data required to process the transaction (name, CPF/CNPJ), via an encrypted channel; the platforms act as data processors under art. 39 of the LGPD;
  • Public and judicial authorities: when required by law, court order or regulation of a competent authority, under art. 7, II, of the LGPD;
  • Google LLC (Google Analytics): anonymized browsing data, under Google's privacy policy. This transfer involves a flow of data outside Brazil (art. 33 of the LGPD) and is carried out on the basis of recognized adequacy or standard contractual clauses.

5A. INTERNATIONAL CUSTOMERS: DATA PROTECTION LEGISLATION

ECM Tech Center serves customers all over the world. Depending on the country of residence, specific data protection laws may apply:

European Union, GDPR (EU Regulation 2016/679): due to the extraterritorial scope provided for in art. 3 of the GDPR, customers residing in the EU are entitled to exercise the rights of access, rectification, erasure, portability and objection through the same channels as this Policy. ECM Tech Center responds to these requests within 30 calendar days.

California (USA), CCPA: customers residing in California may request information about the data collected and its deletion. ECM Tech Center does not sell personal data. Requests should be made through the privacy channel of this Policy.

Other countries: ECM Tech Center applies the LGPD safeguards as a minimum standard and respects local data protection laws to the extent of their recognized extraterritorial application.


5. INTERNATIONAL DATA TRANSFER

The website uses Google Analytics, whose servers are located in the United States. This transfer is carried out on the basis of art. 33, item I or V, of the LGPD (a country with an adequate level of protection recognized by the ANPD, or the adoption of contractual safeguards). The transferred data is anonymized before sending and does not allow individual identification of the visitor. We do not carry out any other international transfers of identifiable personal data.


6. COOKIES AND TRACKING TECHNOLOGIES

6.1 What cookies are

Cookies are small text files stored on your device when you access the website. We use the following types:

Essential cookies (no opt-out option): necessary for the shopping cart, login session and checkout processing to work. Disabling them prevents use of the store.

Analytics cookies (Google Analytics, opt-out available): collect browsing data in anonymized form (pages visited, session duration, traffic source). They do not identify the user individually. You can disable them through Google's opt-out mechanism at tools.google.com/dlpage/gaoptout.

Preference cookies: store your language, region and layout choices to improve your experience on subsequent visits.

6.2 Cookie management

When you access the website for the first time, a cookie banner allows you to accept or decline non-essential cookies. You can change your preferences at any time through your browser settings. Disabling essential cookies impairs the operation of the store.


7. DATA RETENTION AND DELETION

Category Retention period Legal basis
Tax data (invoice, CPF/CNPJ, address) 5 years after the transaction Tax legislation (Decree-Law 486/1969)
Service order and technical report data 5 years after the service is closed Statute of limitations (CDC art. 27 / CC art. 205)
Browsing data (analytics) 26 months (Google Analytics default) Legitimate interest; configurable by the user
Marketing data (e-mail, WhatsApp) Until consent is withdrawn LGPD art. 8, §5
Job applicant data (if any) 12 months Legitimate interest

At the end of the period, the data is deleted or irreversibly anonymized.


8. RIGHTS OF THE DATA SUBJECT

Under arts. 17 to 22 of the LGPD, you have the following rights, which may be exercised at any time through the privacy contact channel:

  • Confirmation and access (art. 18, I and II): to know whether we process your data and to receive a complete copy;
  • Correction (art. 18, III): to update incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion (art. 18, IV): for data processed on the basis of consent or legitimate interest;
  • Portability (art. 18, V): to receive your data in a structured and interoperable format;
  • Information about sharing (art. 18, VII): to know with which third parties your data has been shared;
  • Withdrawal of consent (art. 18, IX): to withdraw consent for commercial communications, free of charge;
  • Objection (art. 18, §2): to contest processing based on legitimate interest when it is detrimental to the data subject;
  • Review of automated decisions (art. 20): to request human review of any decision made solely by an algorithm that affects the data subject.

Response time: up to 15 (fifteen) business days from receipt of the request, under art. 19 of the LGPD.

How to exercise your rights: send an e-mail to Contact@ecmtechcenter.com with the subject "LGPD Rights: [your full name]", stating the right you wish to exercise and the data that identifies your relationship with ECM Tech Center.


9. DATA SECURITY

ECM Tech Center adopts appropriate technical and organizational measures to protect personal data, including: SSL/TLS encryption on all transmissions, access control through individual credentials, storage on servers with physical and logical access control, and an internal policy of minimum necessary access (need-to-know basis).


10. SECURITY INCIDENT NOTIFICATION

In the event of a security incident that may result in significant risk or harm to data subjects (leak, unauthorized access, destruction or loss of data), ECM Tech Center will:

  1. Notify the ANPD within 72 (seventy-two) hours of becoming aware of the incident, under art. 48 of the LGPD and CD/ANPD Resolution No. 15/2024;
  2. Notify the affected data subjects within a reasonable time, with information on the nature of the incident, the data involved, the measures taken and the contact channels for clarification.

11. USER COMMITMENT

By using the website and channels of ECM Tech Center, the user undertakes to:

  • Provide true, complete and up-to-date information;
  • Not commit acts contrary to the law, public order or good morals;
  • Not introduce or spread viruses, malware or any malicious code;
  • Not carry out social engineering attacks, phishing or unauthorized access attempts.

12. EXTERNAL LINKS

The website may contain links to third-party platforms (Correios tracking, payment platforms, Google Maps, etc.). ECM Tech Center has no control over the privacy practices of these sites and recommends that the user read their respective policies before interacting with them.


13. SUPERVISORY AUTHORITY

The national authority responsible for overseeing compliance with the LGPD is the Autoridade Nacional de Proteção de Dados (ANPD), headquartered in Brasília/DF. Data subjects may contact the ANPD at gov.br/anpd to exercise their rights or file complaints, without prejudice to the available judicial remedies.


14. CHANGES TO THIS POLICY

This Policy may be updated periodically to reflect operational, legal or regulatory changes. The current version will always be available on the website with the date of the last update. Changes that involve new data processing on a basis different from the original will be communicated to data subjects with at least 10 (ten) days' notice.


ECM Tech Center, ecmtechcenter.com
For privacy matters: Contact@ecmtechcenter.com