Privacy Policy
MMO Tech Solutions is committed to handling your personal data with full transparency and in strict accordance with applicable law — including Brazil's Lei Geral de Proteção de Dados (LGPD) and the European General Data Protection Regulation (GDPR). This policy explains exactly what we collect, why we collect it, and how you can exercise your rights at any time.
Last updated: 14 July 2025Introduction
MMO TECH SOLUTIONS LTDA ("MMO Tech", "we", "us", or "our") operates the website getmmousa.com and provides technology distribution, infrastructure, managed IT, and cybersecurity services to corporate and institutional clients. We are registered under CNPJ 68.424.147/0001-42 and headquartered at Alameda Xavier da Costa, 1A, Lote 1A Quadra 1, Condomínio Aldeia do Frota, Pirenópolis — GO, Brazil.
This Privacy Policy describes how we process personal data obtained through visits to our website, interactions with our online communications, and direct business engagements. It applies to all individuals who access getmmousa.com regardless of their country of residence, and should be read alongside our Terms of Use.
The legal bases on which we rely to process personal data vary by activity and include: performance of a contract or pre-contractual measures at your request; compliance with a legal obligation; our legitimate interests (where these are not overridden by your rights); and, where required, your freely given, specific, and informed consent. Each processing purpose is linked to its legal basis in Section 3 below.
If you are located in the European Economic Area, the United Kingdom, or Brazil, you have specific statutory rights regarding your personal data. Those rights are explained in full in Section 8. We take them seriously and have dedicated processes in place to respond within the timeframes required by law.
Information We Collect
We collect personal data only to the extent necessary to provide our services, respond to enquiries, and improve the performance of our website. The categories of data we process are described below.
Data you provide directly
When you reach out to us by email or phone, or when you engage with us as a prospective or current client, you may provide personal data including your name, job title, company name, business email address, phone number, and any information you choose to include in the body of your message. We do not operate online registration forms or account portals — any direct communication is through the contact details listed on our Contact page.
Data collected automatically
Our web server and analytics tools collect certain technical data each time someone visits getmmousa.com. This may include:
- Your IP address and approximate geographic location derived from it (city or region level — not street-level precision).
- Browser type and version, operating system, and device type (desktop, mobile, tablet).
- Pages visited, time spent on each page, scroll depth, and the URL of the page that referred you to our site.
- Date and time of each request and HTTP response codes.
- Session identifiers stored in first-party cookies (see Section 4 for full cookie details).
Data from third-party sources
We may receive aggregated, non-personal demographic and interest data from advertising platforms such as Google Ads and Meta Ads Manager to help us understand the effectiveness of our campaigns. Where such data includes any identifiers that could be linked to an individual, it is processed under the applicable platform's terms and subject to this Policy.
We do not purchase, rent, or trade personal data lists, and we do not obtain personal data from data brokers.
How We Use Your Information
The personal data we collect is used strictly for the following purposes. We have identified the legal basis applicable to each:
- Responding to business enquiries and pre-sales conversations — when you contact us, we use the information you provide to reply, answer your questions, and move forward with any service engagement. Legal basis: legitimate interests (responding to a potential client) and, where applicable, pre-contractual measures.
- Delivering contracted services — if we enter into a service agreement with you or your organisation, we process relevant contact and company data to perform that contract, issue invoices, and fulfil our obligations. Legal basis: performance of a contract.
- Website analytics and improvement — automatically collected technical data is used to understand how visitors navigate our site, identify pages that may have usability issues, and improve overall site performance. Legal basis: legitimate interests; consent where required by local law for non-essential cookies.
- Advertising measurement — we use anonymised or aggregated conversion data shared by advertising platforms to assess the return on our marketing spend and optimise ad targeting. Legal basis: legitimate interests; consent for cookie-based tracking.
- Legal and regulatory compliance — we retain certain records to meet obligations under Brazilian tax law, corporate law, and other applicable regulations. Legal basis: compliance with a legal obligation.
- Prevention of fraud and abuse — server log data may be reviewed where we suspect unauthorised access, automated scraping, or other misuse of our website. Legal basis: legitimate interests; legal obligation where reporting is required.
We do not use your personal data for automated individual decision-making or profiling that produces legal or similarly significant effects.
Cookies & Tracking Technologies
Cookies are small text files placed on your device by a website you visit. We use a carefully selected set of cookies to keep the site functional, measure performance, and — where you have consented — to support advertising effectiveness. We do not use cookies to build personal profiles for sale to advertisers.
| Category | Purpose | Examples | Consent required? |
|---|---|---|---|
| Strictly Necessary | Enable core site functions (navigation, security, session integrity). The site cannot operate properly without these. | Session cookie, CSRF token | No |
| Analytics & Performance | Measure page views, traffic sources, and user behaviour to improve site performance. Data is aggregated and pseudonymised. | Google Analytics 4 (_ga, _gid) | Yes |
| Advertising & Measurement | Track campaign conversions and help advertising platforms attribute visits to specific ads. | Google Ads (_gcl_au), Meta Pixel | Yes |
| Functional / Preference | Remember user preferences such as language or region selection to improve the browsing experience. | lang, region_pref | Yes |
When you first visit our website, a cookie consent banner gives you the ability to accept or decline non-essential cookies. You may change your preferences at any time by clearing your browser cookies and revisiting the site, or by adjusting your browser settings. Most modern browsers allow you to refuse new cookies, delete existing cookies, and receive warnings before cookies are stored. Note that disabling certain cookies may affect the functionality or appearance of parts of our website.
For Google Analytics, we have enabled IP anonymisation (IP masking) so that your full IP address is never stored by Google's servers. We do not share analytics data with any third party other than the analytics provider itself, and we do not permit Google to use our analytics data for its own advertising products.
Other tracking technologies
In addition to cookies, our advertising partners may use pixel tags (tiny transparent images embedded in page content) to confirm that a page was loaded or that a specific action was completed. These pixels share limited technical data — typically an event type and a timestamp — with the relevant platform. No individually identifying information is transmitted without your consent.
Sharing With Third Parties
MMO Tech does not sell, lease, or trade your personal data. We share data with third parties only in the limited circumstances described here:
- Technology and hosting providers — our website is hosted on infrastructure provided by reputable cloud providers. These parties act as data processors under our instruction and are contractually bound by data processing agreements that prohibit them from using your data for their own purposes.
- Analytics and advertising platforms — Google LLC (Google Analytics and Google Ads) and Meta Platforms, Inc. receive pseudonymised data through cookies and pixels on the basis described in Section 4. Both companies are certified under applicable data transfer frameworks and maintain their own privacy policies.
- Professional advisers — our legal, accounting, and auditing advisers may access limited personal data where necessary to provide their services. All are bound by professional confidentiality obligations.
- Law enforcement and regulatory authorities — we may disclose personal data where required to do so by Brazilian law, court order, or other valid legal process, or where we reasonably believe disclosure is necessary to protect the safety, rights, or property of any person.
- Business transfers — in the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data held by MMO Tech may be transferred to the successor entity, subject to the same protections described in this Policy. We will notify affected individuals through our website or directly as required by law.
Where personal data is transferred outside Brazil or the EEA, we apply appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or transfer mechanisms recognised by Brazil's Autoridade Nacional de Proteção de Dados (ANPD).
Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. The following general retention periods apply:
- Business enquiry records (emails, contact information from prospective clients): retained for up to 24 months from last meaningful contact. If no engagement follows, data is securely deleted or anonymised at the end of this period.
- Client contract data: retained for the duration of the contract plus 5 years thereafter, to comply with Brazilian civil and commercial law obligations, tax record requirements, and applicable statutes of limitation.
- Website analytics data: Google Analytics retains raw event data for 14 months by default. Aggregated, anonymised reports derived from this data may be kept indefinitely as they no longer constitute personal data.
- Server log files: retained for up to 90 days for security and troubleshooting purposes, then automatically purged.
- Cookie consent records: retained for 12 months from the date of consent, then renewed.
- Tax and financial records: retained for the period mandated by Receita Federal do Brasil (currently 5 years, extendable in cases of active audit).
At the end of any applicable retention period, personal data is either securely deleted using methods that prevent reconstruction, or anonymised so that it can no longer be linked to an identifiable individual.
Data Security
Protecting the confidentiality and integrity of personal data is fundamental to how we operate — both as a matter of legal duty and as a reflection of our professional values as a technology company. We implement the following technical and organisational measures:
- All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HSTS (HTTP Strict Transport Security) to prevent downgrade attacks.
- Access to systems containing personal data is governed by role-based access controls and protected by multi-factor authentication (MFA). Only personnel with a legitimate business need are granted access.
- Our hosting infrastructure is subject to regular vulnerability assessments and patching cycles. We apply security updates promptly following responsible disclosure or vendor publication.
- Internal privacy and security awareness training is conducted for all staff who handle personal data, with refresher training at least annually.
- We maintain an incident response procedure that includes containment, assessment, internal escalation, and — where required by LGPD Article 48 or GDPR Article 33 — notification to the relevant supervisory authority and affected individuals within the legally mandated timeframes.
No transmission over the internet and no data storage system can be guaranteed to be 100% secure. While we apply industry-standard controls, we cannot warrant absolute security. If you become aware of any security vulnerability related to our website or services, please contact us immediately at [email protected] so we can investigate and respond appropriately.
Your Rights
Depending on your country of residence and the legal framework that applies to your data, you hold a number of enforceable rights regarding how we process your personal information. Under Brazil's LGPD (Articles 17–22) and the European GDPR (Articles 15–22), those rights include the following:
01 Right of Access
You can request confirmation of whether we hold personal data about you and, if so, obtain a copy of that data along with information about how it is processed.
02 Right to Correction
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it without undue delay.
03 Right to Deletion
Also known as the "right to be forgotten," you may request that we delete personal data about you where it is no longer necessary, where consent is withdrawn, or where it has been processed unlawfully — subject to legal retention obligations.
04 Right to Restriction
You may ask us to restrict processing of your data in certain circumstances — for example, while the accuracy of data you have disputed is being verified.
05 Right to Object
Where we rely on legitimate interests as our legal basis, you have the right to object. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
06 Right to Portability
In cases where processing is based on your consent or a contract and is carried out by automated means, you can request your data in a structured, commonly used, machine-readable format to transfer to another controller.
07 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
08 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant supervisory authority. In Brazil, this is the ANPD (Autoridade Nacional de Proteção de Dados). In EU member states, contact your national data protection authority.
How to exercise your rights
To exercise any of the rights described above, please send a written request to [email protected] with the subject line "Data Rights Request." Include enough information for us to verify your identity (for example, your full name and the email address associated with any previous correspondence) and specify clearly which right(s) you wish to exercise and the data to which your request relates. We will acknowledge your request within 48 hours and respond substantively within 15 days, extendable to 30 days in complex cases — in either case consistent with LGPD and GDPR timeframes. We do not charge a fee for reasonable requests.
Children's Privacy
The website getmmousa.com is a corporate information site intended exclusively for business professionals, potential partners, and institutional clients. It is not directed at, and is not intended to be used by, individuals under the age of 18. We do not knowingly collect or process personal data from minors.
If you are a parent or guardian and you believe that a minor has provided personal data to us — for example, through an email enquiry — please contact us at [email protected] and we will take prompt steps to delete that information from our records.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable legal requirements. When we make material changes, we will revise the "Last updated" date at the top of this page. For significant changes — particularly those that affect how we use data already in our possession — we will take additional steps to notify affected individuals directly where we hold valid contact details and where required to do so by law.
We encourage you to review this page periodically. Your continued use of getmmousa.com after any changes have been published constitutes acceptance of the updated Policy, to the extent permitted by applicable law. Previous versions of this Policy are available on request.
Contact & Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to raise a concern about how your personal data has been handled, please contact us using the details below. We are committed to resolving privacy-related concerns promptly and fairly.
Condomínio Aldeia do Frota
Pirenópolis — GO, Brazil
Please mark the subject line of your email as "Privacy Enquiry" or "Data Rights Request" to ensure your message reaches the appropriate team member without delay. We aim to acknowledge all privacy-related emails within two business days.