Cookies Policy
dibis-it.consulting
1. Introduction
This Cookies Policy explains how dibis-it.consulting (“Company,” “we,” “us,” or “our”) uses cookies and similar tracking technologies on our website and digital services. This policy should be read together with our Privacy Policy and complies with:
- Brazilian Laws: Brazilian General Data Protection Law (LGPD – Law 13.709/2018) and the Brazilian Internet Civil Rights Framework (Marco Civil da Internet – Law 12.965/2014)
- European Laws: General Data Protection Regulation (GDPR – EU Regulation 2016/679) and the ePrivacy Directive (Directive 2002/58/EC)
Website: dibis-it.consulting
Last Updated: 25.01.2024
2. What Are Cookies?
Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit our website. They help us recognize your device and store information about your preferences and actions on our site.
Similar Technologies we use include:
- Web beacons: Small graphic images that track website usage
- Pixel tags: Code snippets that collect information about user interactions
- Local storage: Browser-based storage for website data
- Session storage: Temporary storage that expires when you close your browser
3. Types of Cookies We Use
3.1 Essential Cookies
Purpose: Necessary for basic website functionality and security
Legal Basis:
- LGPD: Legitimate interest (Article 7, IX)
- GDPR: Legitimate interest (Article 6(1)(f))
Duration: Session or up to 1 year
Examples:
- Authentication and login status
- Shopping cart functionality (for e-commerce clients)
- Security tokens and CSRF protection
- Load balancing and server routing
- Cookie consent preferences
3.2 Performance and Analytics Cookies
Purpose: Help us understand how visitors use our website
Legal Basis:
- LGPD: Consent (Article 7, I)
- GDPR: Consent (Article 6(1)(a))
Duration: Up to 2 years
Examples:
- Google Analytics tracking
- Page load times and performance metrics
- Error reporting and debugging
- User journey analysis
- Website optimization data
Third-Party Services Used:
- Google Analytics: Web traffic analysis
- Google Tag Manager: Tag and code management
- Hotjar: User behavior analytics (when applicable)
3.3 Functional Cookies
Purpose: Remember your preferences and provide enhanced features
Legal Basis:
- LGPD: Consent (Article 7, I)
- GDPR: Consent (Article 6(1)(a))
Duration: Up to 1 year
Examples:
- Language preferences
- Region/location settings
- Accessibility preferences
- Form auto-fill information
- Customized interface settings
3.4 Marketing and Advertising Cookies
Purpose: Deliver relevant advertisements and measure campaign effectiveness
Legal Basis:
- LGPD: Consent (Article 7, I)
- GDPR: Consent (Article 6(1)(a))
Duration: Up to 2 years
Examples:
- Behavioral targeting data
- Advertising campaign tracking
- Social media integration cookies
- Retargeting and remarketing pixels
- Conversion tracking
Third-Party Advertising Services:
- Google Ads: Online advertising platform
- Facebook Pixel: Social media advertising tracking
- LinkedIn Insight Tag: Professional network advertising
- Email marketing platforms: Campaign tracking cookies
4. Legal Basis for Cookie Processing
4.1 Consent-Based Cookies (GDPR Article 6(1)(a) / LGPD Article 7, I)
For non-essential cookies, we obtain your explicit, informed, and freely given consent before placing them on your device. Under European law, consent must be:
- Specific: Clear about what you’re consenting to
- Informed: You understand what data is processed and why
- Freely given: You can refuse without consequence
- Withdrawable: You can withdraw consent at any time
4.2 Legitimate Interest Cookies (GDPR Article 6(1)(f) / LGPD Article 7, IX)
Essential cookies are processed based on our legitimate interest in providing secure and functional website services. We conduct legitimate interest assessments to ensure our interests don’t override your privacy rights. This includes cookies necessary for:
- Website security and fraud prevention
- Basic functionality and navigation
- Legal compliance and record-keeping
- Service delivery and technical operations
5. How We Obtain Consent
5.1 Cookie Consent Banner (GDPR & ePrivacy Compliance)
When you first visit our website, we display a cookie consent banner that:
- Clearly explains our use of cookies before any non-essential cookies are placed
- Provides links to this Cookies Policy
- Allows you to accept or decline non-essential cookies
- Offers granular consent options for different cookie categories
- Does not use pre-ticked boxes or cookie walls
- Allows continued browsing without consent to non-essential cookies
5.2 Consent Management (GDPR Article 7)
Our consent management system:
- Records consent: Documentation of when, how, and what you consented to
- Allows withdrawal: Easy mechanism to withdraw consent at any time
- Provides evidence: Clear records of your consent choices
- Respects preferences: Honors “Do Not Track” browser signals
- Regular review: Periodic re-confirmation for ongoing consent
5.3 European Standards Compliance
We follow European standards including:
- TCF v2.2 (Transparency and Consent Framework)
- IAB Europe guidelines
- ePrivacy Directive requirements for terminal equipment access
- GDPR Article 25 privacy by design principles
6. Your Rights Under GDPR and LGPD
6.1 European Users (GDPR Rights)
If you are located in the European Union/EEA, you have the following rights:
Right of Access (Article 15): Request information about cookie data processing
Right to Rectification (Article 16): Correct inaccurate cookie preference data
Right to Erasure (Article 17): Request deletion of cookie data
Right to Restrict Processing (Article 18): Limit cookie data processing
Right to Data Portability (Article 20): Receive cookie preference data in a portable format
Right to Object (Article 21): Object to cookie processing based on legitimate interests
Right to Withdraw Consent (Article 7(3)): Withdraw cookie consent at any time
Right to Lodge a Complaint: File complaints with your local Data Protection Authority
6.2 Brazilian Users (LGPD Rights)
If you are located in Brazil, you have the following rights under LGPD Article 18:
Right of Access (I): Confirmation of processing and access to cookie data
Right to Rectification (III): Correct incomplete or inaccurate data
Right to Erasure (VI): Request deletion of unnecessary data
Right to Portability (V): Receive data in a structured format
Right to Object (VII): Object to processing based on legitimate interest
Right to Information (II): Understand how cookie data is used
Right to Withdraw Consent: Revoke consent for cookie processing
6.3 Managing Cookie Preferences
You can control cookies through:
Our Cookie Preference Center:
- Access through the cookie banner or website footer
- Enable/disable specific cookie categories
- View detailed information about each cookie type
- Update preferences at any time
- Download your consent history
Browser Settings:
- Block all cookies or specific types
- Delete existing cookies
- Set notifications for new cookies
- Configure privacy settings
6.4 Browser-Specific Instructions
Google Chrome:
- Click Menu (three dots) → Settings
- Go to Privacy and Security → Cookies and other site data
- Choose your preferred cookie settings
Mozilla Firefox:
- Click Menu → Settings
- Go to Privacy & Security
- Under Cookies and Site Data, choose your settings
Safari:
- Go to Safari → Preferences
- Click Privacy tab
- Choose your cookie preferences
Microsoft Edge:
- Click Menu (three dots) → Settings
- Go to Cookies and site permissions
- Manage cookie settings
6.5 Impact of Disabling Cookies
Essential Cookies: Disabling may prevent proper website functionality, security features, and service delivery.
Performance Cookies: Disabling may limit our ability to improve website performance and user experience.
Functional Cookies: Disabling may require you to re-enter preferences and settings on each visit.
Marketing Cookies: Disabling may result in less relevant advertising but will not affect core website functionality.
7. International Data Transfers
7.1 Cross-Border Cookie Data Transfers
When cookie data is transferred outside Brazil or the European Economic Area (EEA), we ensure adequate protection through:
For European Users (GDPR Chapter V):
- Adequacy decisions by the European Commission
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs) for multinational companies
- Certification schemes and approved codes of conduct
For Brazilian Users (LGPD Chapter VII):
- Adequacy decisions by Brazilian authorities (ANPD)
- Standard contractual clauses approved by ANPD
- International cooperation agreements
- LGPD compliance commitments from all partners
7.2 Data Processing Locations
Cookie data may be processed in:
- Brazil: Preferred location for Brazilian users
- European Union/EEA: Adequate protection for EU users
- United States: With appropriate safeguards (SCCs, adequacy frameworks)
- Other countries: Only with adequate protection measures
7.3 Transfer Impact Assessments
We conduct Transfer Impact Assessments (TIAs) to evaluate:
- Legal protections in destination countries
- Technical and organizational safeguards
- Risks to data subject rights and freedoms
- Additional measures needed for protection
8. Service-Specific Cookie Usage
8.1 Legal Services Website
For our legal consulting pages, we use:
- Security cookies for protected client portals
- Session cookies for secure document access
- Functional cookies for legal research tools
- Analytics cookies to improve service delivery
8.2 Software Development Portfolios
Development showcase pages may include:
- Performance cookies to optimize loading times
- Functional cookies for interactive demos
- Analytics cookies to track project interest
- Marketing cookies for lead generation
8.3 SEO and Digital Marketing Tools
Our SEO service pages use:
- Analytics cookies for comprehensive website analysis
- Marketing cookies for campaign demonstration
- Performance cookies for real-time data display
- Functional cookies for client dashboard access
8.4 Cloud Services Portals
Client cloud service dashboards include:
- Essential cookies for secure authentication
- Functional cookies for personalized interfaces
- Performance cookies for system monitoring
- Security cookies for access control
8.5 E-commerce Demonstration Sites
Sample e-commerce platforms may use:
- Shopping cart cookies for functionality demos
- Personalization cookies for user experience
- Analytics cookies for performance metrics
- Marketing cookies for conversion tracking
9. Cookie Data Retention
9.1 Retention Periods
Session Cookies: Deleted when you close your browser
Persistent Cookies:
- Essential cookies: Up to 1 year
- Performance cookies: Up to 2 years (or shorter based on consent)
- Functional cookies: Up to 1 year
- Marketing cookies: Up to 2 years (or shorter based on consent)
9.2 Retention Principles (GDPR Article 5(1)(e) / LGPD Article 6, V)
We apply data minimization and storage limitation principles:
- Cookies are kept only as long as necessary for their purpose
- Regular review and deletion of expired cookies
- Automatic deletion upon consent withdrawal
- Compliance with statutory retention requirements
9.3 Automatic Deletion
Cookies are automatically deleted when:
- Their expiration date is reached
- You clear your browser data
- You withdraw consent through our preference center
- You use browser privacy/incognito mode
- We no longer have a legal basis for processing
10. Updates to This Cookies Policy
10.1 Policy Changes
We may update this policy to reflect:
- New cookie technologies or practices
- Changes in European or Brazilian legal requirements
- Updates to third-party services
- Improvements to user controls
- Regulatory guidance from authorities
10.2 Notification of Changes (GDPR Article 14 / LGPD Article 9)
Material changes will be communicated through:
- Email notification to registered users (30 days advance notice)
- Website banner notifications for all visitors
- Updated consent banners requiring new consent
- Direct communication for significant changes affecting your rights
Minor updates will be reflected in the “Last Updated” date at the top of this policy.
11. Technical Implementation
11.1 Cookie Security (GDPR Article 32 / LGPD Article 46)
We implement security measures for cookie data:
- Secure flag for HTTPS-only transmission
- HttpOnly flag to prevent JavaScript access
- SameSite attribute for CSRF protection
- Encryption for sensitive cookie data
- Regular security assessments and penetration testing
11.2 Privacy by Design (GDPR Article 25)
Our cookie implementation follows privacy by design principles:
- Proactive measures to prevent privacy breaches
- Privacy as default setting for non-essential cookies
- Full functionality with privacy protection
- End-to-end security throughout data lifecycle
- Visibility and transparency in all processing operations
11.3 Consent Technical Standards
Our consent management follows:
- TCF v2.2 (Transparency and Consent Framework)
- IAB Europe guidelines for digital advertising
- GDPR Article 7 requirements for consent validity
- ePrivacy Directive terminal equipment access rules
- W3C web standards for accessibility
12. Definitions
Cookie: Small text file stored on your device by websites you visit
Data Controller: Entity determining purposes and means of cookie data processing (dibis-it.consulting)
Data Processor: Entity processing cookie data on behalf of the controller
Data Subject: Individual whose personal data is processed through cookies
First-Party Cookie: Set directly by our website domain
Third-Party Cookie: Set by domains other than our website
Session Cookie: Temporary cookie deleted when browser closes
Persistent Cookie: Remains on device until expiration or manual deletion
Tracking: Monitoring user behavior across websites or sessions
Consent: Freely given, specific, informed, and unambiguous agreement to cookie processing
Legitimate Interest: Legal basis for processing when balanced against data subject rights
Personal Data: Any information relating to an identified or identifiable individual
This Cookies Policy complements our Privacy Policy and General Terms and Conditions. For comprehensive information about our data practices, please review all three documents.
Multi-Jurisdictional Compliance: This policy is designed to comply with both Brazilian (LGPD, Marco Civil da Internet) and European (GDPR, ePrivacy Directive) laws. Where requirements differ, we apply the most protective standard to ensure comprehensive compliance.
Language Note: This English version is provided for convenience. Portuguese and other local language versions may be available and shall prevail in case of any discrepancies in their respective jurisdictions.