1. Introduction
This Privacy Policy ("Policy") governs how CINCO TI COMERCIO E SERVICOS LTDA ("Cinco TI", "we", "our" or "us") — a Brazilian private limited company registered under CNPJ 08.307.867/0001-04, with principal offices at Avenida Edvaldo Pereira Paiva, 1000, Praia de Belas, Porto Alegre, Rio Grande do Sul, Brazil — collects, processes, stores, and discloses personal information through the website available at www.5ti.site and any related digital services (collectively, the "Site").
By visiting or using our Site, submitting any form, or otherwise engaging with our services, you acknowledge that you have read and understood this Policy. If you do not agree with any provision herein, please discontinue your use of the Site and refrain from submitting personal information.
Cinco TI acts as the controller of personal data collected through the Site, meaning we determine the purposes and means of processing your information. Where we engage external service providers to process data on our behalf, those parties act as processors and are contractually bound to respect confidentiality and security standards consistent with applicable law.
This Policy applies to all visitors, prospective customers, existing clients, suppliers, and any other individuals whose personal data we process in connection with our website and commercial activities related to the supply of IT infrastructure equipment, enterprise hardware, professional services, and related solutions.
2. Information We Collect
We collect personal information through several distinct channels and mechanisms. The nature and volume of data we hold about any individual depends on how that person interacts with us.
2.1 Information you submit directly
When you complete any contact, quotation request, or inquiry form on our Site, or when you contact us by email or telephone, you may provide:
- Identification data: full name, job title, and the name of your organization.
- Contact data: business or personal email address, telephone number (including WhatsApp), and postal address.
- Commercial data: the products or services you are inquiring about, technical specifications, budget indications, or project timelines you choose to share.
- Communications content: the body of messages, attachments, or supporting documents you send to us.
- Tax identification: when required to issue quotations or invoices under Brazilian law, we may request your CPF (individual taxpayer ID) or CNPJ (business taxpayer ID).
Providing this information is voluntary, but without the minimum details necessary to identify you and understand your request, we may not be able to respond adequately.
2.2 Information collected automatically
When you browse our Site, certain technical information is collected automatically by our web servers and third-party analytics tools, including:
- Device and browser data: IP address (truncated where anonymization is applied), browser type and version, operating system, screen resolution, and device type.
- Usage data: pages visited, time spent on each page, clickstream data, referring URLs, search terms used to find our Site, and the actions you take (such as form interactions).
- Geolocation data: country and approximate city inferred from your IP address. We do not collect precise GPS coordinates.
- Cookie and tracker identifiers: unique identifiers placed in your browser to enable analytics, session continuity, and, where applicable, advertising attribution. See Section 4 for full details.
2.3 Information from third-party sources
We may receive limited additional information about prospective business customers from publicly available commercial sources — such as the Receita Federal's CNPJ registry, LinkedIn, or publicly accessible company websites — in order to contextualize an inbound inquiry or to carry out legitimate B2B prospecting activities. We rely on our legitimate commercial interests as the legal basis for this activity and ensure the information involved is limited to professional rather than sensitive personal data.
3. How We Use Your Information
We process your personal information only where we have an identified legal basis to do so under the LGPD and GDPR. The following table summarizes the principal processing activities and the corresponding legal bases.
| Purpose | Legal Basis (LGPD / GDPR) |
|---|---|
| Responding to contact form submissions, quotation requests, and support queries | Performance of a pre-contractual or contractual relationship; Legitimate interest |
| Sending order confirmations, invoices, and transactional communications | Performance of contract; Legal obligation (NF-e issuance requirements) |
| Analyzing Site usage to improve content, navigation, and user experience | Legitimate interest; Consent (where cookies require it) |
| Running Google Ads campaigns and measuring advertising performance | Consent (via cookie consent mechanism) |
| Sending commercial communications about products, promotions, and technology updates | Consent; Legitimate interest (existing business contacts) |
| Complying with tax, accounting, and legal obligations under Brazilian law | Legal obligation (SPED, Receita Federal, BACEN rules) |
| Fraud prevention, information security, and abuse detection | Legitimate interest; Legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interest; Legal obligation |
We will never use your personal data for purposes that are incompatible with those listed above without notifying you and, where required, obtaining fresh consent. We do not sell your personal data to third parties under any circumstances.
4. Cookies & Tracking Technologies
Our Site uses cookies — small text files stored in your browser — and similar technologies such as web beacons and local storage objects. Some of these are essential for the Site to function; others help us understand how visitors use the Site or enable advertising features. Where non-essential cookies are used, we request your consent before placing them.
| Category | Purpose | Examples | Consent required? |
|---|---|---|---|
| Strictly necessary | Enable core Site functionality including security, session management, and form submission handling. The Site cannot function properly without these. | Session cookies, CSRF protection tokens | No (exempted) |
| Analytics & performance | Collect aggregated data about how visitors interact with the Site — which pages are most visited, how long users stay, and where they navigate next — allowing us to improve content and layout. | Google Analytics 4 (_ga, _gid, _gat) | Yes |
| Advertising & remarketing | Used by Google Ads to record when a user has seen or clicked an ad and to attribute conversions, measure campaign effectiveness, and show relevant ads on the Google network. | Google Ads (_gcl_au), Floodlight, GCLID | Yes |
| Functional / preferences | Remember choices you make — such as language preference or previously viewed categories — to personalize your experience on return visits. | Preference cookies | Yes |
Managing your cookie preferences
You can withdraw or adjust your cookie consent at any time by clicking the "Cookie Settings" link in our Site footer. Additionally, most browsers allow you to block or delete cookies through their built-in settings menus. Please be aware that disabling non-essential cookies will not affect your access to the Site's core content, but may reduce the personalization features available to you.
For Google Analytics specifically, you can opt out across all sites using the Google Analytics Opt-out Browser Add-on (available at tools.google.com/dlpage/gaoptout). For advertising preferences, visit adssettings.google.com or the Network Advertising Initiative opt-out page at optout.networkadvertising.org.
5. Sharing With Third Parties
We do not sell, rent, or trade your personal data. We share information only in the specific, limited circumstances described below, and only to the extent strictly necessary for the described purpose.
5.1 Service providers and data processors
We engage trusted third-party companies to help us operate the Site and deliver our services. These providers process data on our behalf and under our documented instructions, in accordance with data processing agreements:
- Google LLC — analytics (Google Analytics 4), advertising (Google Ads), workspace productivity tools (Google Workspace), and cloud hosting infrastructure (Google Cloud Platform). Google is certified under the EU–US Data Privacy Framework and implements Standard Contractual Clauses for international transfers.
- Hosting and infrastructure providers — web hosting and content delivery networks used to serve the Site. These providers process server log data including IP addresses solely for security and operational purposes.
- CRM and email platforms — where we use software tools to manage customer communications and contact records. These tools are configured with data minimization in mind and do not grant providers the right to use customer data for their own commercial purposes.
- Accounting and tax compliance software — used to issue NFe (electronic invoices) and maintain records required by Brazilian fiscal law. These systems necessarily handle identification and transactional data.
5.2 Authorized technology partners and distributors
Cinco TI operates as an authorized reseller and channel partner for brands including Lenovo, Dell, HP, Cisco, and others. In cases where a product quotation or technical requirement must be escalated to a manufacturer or distributor — for example, to obtain special pricing, arrange extended warranties, or coordinate enterprise deployment — we may share your organization's name, contact details, and the relevant technical specifications with that partner. We will inform you when this is necessary and will not share your data beyond what is required to fulfill your request.
5.3 Legal and regulatory disclosure
We may disclose your personal information to government authorities, regulatory bodies, or law enforcement agencies when required to do so by applicable Brazilian law (including demands from the Receita Federal, the ANPD, or competent courts), or when we have a good-faith belief that disclosure is necessary to protect the rights, property, or safety of Cinco TI, our customers, or third parties.
5.4 Corporate transactions
In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, your personal data may be transferred to the successor entity, subject to the same protections and obligations described in this Policy. We will notify affected data subjects before their data becomes subject to a different privacy policy.
6. Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following retention periods apply as a general guideline:
- Contact form and inquiry data: retained for up to 5 years from the date of the last interaction, to allow us to reference historical communications in the event of a follow-up order, warranty claim, or dispute.
- Customer transactional records (invoices, purchase orders, contracts): retained for a minimum of 5 years following the tax year of the transaction, in compliance with Brazilian tax law (CTN, Art. 173) and the requirements of SPED fiscal records. In certain cases involving litigation or regulatory audits, records may be held for up to 10 years.
- Analytics data: aggregated and anonymized usage statistics are retained indefinitely for trend analysis. Google Analytics data at the session level is retained for 14 months under our current configuration before automatic deletion.
- Marketing communications data: contact details used for commercial communications are retained until you withdraw consent or exercise your right to erasure, or for a maximum of 3 years from the last engagement, whichever comes first.
- Server logs: raw access logs containing IP addresses and request metadata are retained for 90 days for security and abuse-detection purposes, then permanently deleted.
When the applicable retention period expires and no overriding legal obligation prevents deletion, we securely erase or irreversibly anonymize the data so that it can no longer be attributed to any identifiable individual.
7. Data Security
Cinco TI implements a layered set of technical and organizational security measures designed to protect personal data against unauthorized access, accidental loss, alteration, and unlawful disclosure. As a technology company that specializes in enterprise IT infrastructure, information security is core to our operations — not an afterthought.
- Encryption in transit: all data exchanged between your browser and our Site is encrypted using TLS 1.2 or higher. Our domain enforces HTTPS with HSTS preloading.
- Access controls: access to systems holding personal data is restricted on a need-to-know basis. Administrative accounts require multi-factor authentication, and access privileges are reviewed quarterly.
- Vendor security assessments: third-party processors are evaluated for security compliance before engagement, and data processing agreements specify binding security obligations.
- Incident response: we maintain a documented data breach response procedure. In the event of a confirmed breach likely to result in risk to data subjects, we will notify the Brazilian ANPD (National Data Protection Authority) within 72 hours and notify affected individuals without undue delay, as required by LGPD Art. 48.
- Employee training: all staff with access to personal data receive periodic training on data protection obligations and secure data-handling practices.
No transmission of data over the internet can be guaranteed as entirely secure. While we take every reasonable precaution, we cannot provide an absolute guarantee against all possible security risks. If you believe your data has been compromised in connection with our services, please contact us immediately at contato@5ti.site.
8. Your Rights
Depending on your location and applicable law, you have the following rights with respect to your personal data. Brazilian residents are protected by the LGPD (Lei 13.709/2018); residents of the European Economic Area and the United Kingdom are protected by the GDPR and UK GDPR respectively. We honor these rights regardless of your jurisdiction.
👁️ Right of Access
You may request a copy of the personal data we hold about you, along with information about how it is being used, the categories of data held, and with whom it has been shared.
✏️ Right to Correction
If any personal data we hold about you is inaccurate, incomplete, or outdated, you have the right to request that we correct or update it without undue delay.
🗑️ Right to Erasure
You may request the deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent, or where we have no overriding legitimate interest or legal obligation to retain it.
⏸️ Right to Restrict Processing
In certain circumstances — such as where you contest the accuracy of data or have objected to processing pending our assessment — you may request that we temporarily suspend active processing of your information.
📦 Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you may request that we provide your data in a structured, commonly used, machine-readable format so that you can transfer it to another controller.
🚫 Right to Object
You have the right to object at any time to processing based on our legitimate interests, including profiling, and to object to the use of your data for direct marketing purposes. In the latter case, we will cease processing immediately upon receipt of your request.
🔔 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal was made.
🏛️ Right to Lodge a Complaint
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Brazilian ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd, or with your local supervisory authority if you are located in the EU.
How to exercise your rights
To exercise any of the rights described above, please send a written request by email to contato@5ti.site with the subject line "Data Subject Rights Request". Please include your full name, the email address associated with your contact history with us, and a clear description of the right you wish to exercise. We will respond within 15 business days for LGPD requests and within 30 calendar days for GDPR requests. Where a request is complex or numerous, we may extend this period by an additional 30 days, in which case we will notify you of the extension and the reasons for it.
We may need to verify your identity before processing certain requests to ensure that we do not disclose or delete another person's data. We will never charge a fee for handling a rights request unless it is manifestly unfounded or excessive, in which case we will explain our reasoning before proceeding.
9. Children's Privacy
Our Site and services are directed exclusively toward business professionals and corporate entities. We do not knowingly collect, solicit, or process personal information from individuals under the age of 18. The products and services we offer — enterprise servers, networking equipment, managed IT services, and related B2B solutions — are not designed for or marketed to minors.
If we become aware that we have inadvertently received personal information from a person under 18, we will take prompt steps to delete that information from our systems. If you are a parent or guardian and believe your child has provided personal information to us, please contact us at contato@5ti.site and we will investigate and act accordingly.
10. Changes to This Policy
We review and update this Privacy Policy periodically to reflect changes in our practices, the services we offer, the technologies we use, and developments in applicable privacy law. When we make material changes — that is, changes that could meaningfully affect how we process your personal data or the rights available to you — we will update the "Last updated" date at the top of this page and, where we have your contact details and the change is significant, notify you by email.
Minor editorial or clarificatory changes (such as correcting typographical errors, improving the clarity of existing language, or reorganizing sections without changing their substance) will be published on this page without individual notification, but the updated date will always reflect the most recent revision.
We encourage you to review this Policy periodically. Your continued use of the Site after any modification constitutes your acknowledgment of the updated Policy. If you do not agree with the changes, you should discontinue using the Site and may request deletion of your personal data as described in Section 8.
11. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy, the way we handle your personal data, or your rights as a data subject, please reach out to us through any of the channels listed below. We are committed to addressing your concerns promptly and transparently.
- Company
- CINCO TI COMERCIO E SERVICOS LTDA
- CNPJ
- 08.307.867/0001-04
- Address
- Avenida Edvaldo Pereira Paiva, 1000
Praia de Belas, Porto Alegre — RS, Brazil - Privacy email
- contato@5ti.site — please use the subject line "Privacy / Data Protection" to ensure your message reaches the right person promptly.
- Business hours
- Monday to Friday, 08:00–18:00 BRT (UTC-3). We aim to acknowledge all privacy-related inquiries within 2 business days.