Legal & Compliance

Privacy Policy

GLCTech Tecnologia Last updated: July 8, 2025 LGPD Compliant
At GLCTech, we value your privacy and are committed to protecting the personal information you share with us. This Policy explains how we collect, use and protect your data, in accordance with applicable data protection law — including the UK/EU GDPR and Brazil's LGPD (General Data Protection Law — Law No. 13.709/2018) — depending on your location.
Section 01

Data Collection

We collect personal information you voluntarily provide through forms, business contacts and interactions with our content. The data collected may include:

  • Full name and identification details
  • Corporate or personal e-mail address
  • Company name and job title/role
  • Phone number and WhatsApp
  • Technical information about your IT infrastructure (when voluntarily provided)

We may also automatically collect browsing data such as IP address, browser type and pages visited, for the purpose of improving user experience and usage analysis.

Section 02

Use of Information

The information collected is used exclusively for the following purposes:

  • Contacting you and providing the services requested
  • Sending institutional, technical and promotional communications
  • Improving the user experience with our services and website
  • Preparing personalized commercial proposals
  • Complying with legal and regulatory obligations
We do not use your data for purposes other than those listed above without your express consent.
Section 03

Data Sharing

GLCTech does not share, sell or rent your personal data to third parties, except in the following situations:

  • When necessary to perform the contracted services (e.g. technology partners such as Kaspersky, Veeam)
  • When required by a competent legal or regulatory authority
  • To protect the rights and property of GLCTech or our clients

Any third parties with whom we may share data are required to handle your information with the same level of security and confidentiality that we apply.

Section 04

Information Security

We adopt technical and administrative measures consistent with market security standards to protect your data against:

  • Unauthorized access
  • Accidental loss or destruction of data
  • Theft or misuse of information
  • Leaks and security incidents

As a company specialized in IT security and monitoring, we apply internally the same best practices we recommend to our clients.

UK clients: a standard Data Processing Agreement (DPA) covering the scope of processing, sub-processors, security measures and data return/deletion on termination is available on request — ask your account manager before signing a service agreement. Our incident response process targets notification of affected clients and, where required, the Information Commissioner's Office (ICO), within 72 hours of a qualifying breach becoming known to us, in line with UK GDPR Article 33. See our Trust & Compliance Centre for full detail.
Section 05

Your Rights (GDPR/LGPD)

In accordance with applicable data protection law, you may, at any time, request:

  • Confirmation of whether your data is being processed
  • Access to the personal data collected about you
  • Correction of incomplete, inaccurate or outdated data
  • Anonymization, blocking or deletion of unnecessary data
  • Deletion of your personal data, where applicable by law
  • Portability of your data to another service provider
  • Information on who your data has been shared with
  • Withdrawal of consent at any time

To exercise any of these rights, please contact us through the channels below.

Section 06

Contact

If you have any questions, requests, or wish to exercise your data protection rights, please contact our data protection team:

São Paulo, Brazil (Group HQ) · Salford, UK (GLCTech Sec)
Section 07

Updates to this Policy

This Privacy Policy may be updated periodically to reflect legal, operational or service-related changes. We recommend reviewing it periodically.

Last updated: July 8, 2025. Should any material changes occur, we will notify registered data subjects by e-mail.