Introduction
CI&T Software S/A ("CI&T", "we", "us", or "our") is a global digital-transformation company registered under CNPJ 00.609.634/0001-46, with its principal offices at Estrada Giuseppina Vianelli di Napolli, 1455, Bloco C — Pavimento Superior, Polo II de Alta Tecnologia (Campinas), Campinas-SP, Brazil. This Privacy Policy governs the collection, use, storage, and disclosure of personal data that we process through this website and through any associated communication channels listed herein.
We are committed to transparent, responsible data handling in full compliance with Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13,709/2018), the European Union General Data Protection Regulation (GDPR — Regulation (EU) 2016/679), the California Consumer Privacy Act (CCPA) where applicable, and all other relevant privacy and data-protection legislation in the jurisdictions where we operate. This document is written in plain language so that visitors understand exactly how their information is handled before, during, and after any interaction with our web presence.
By accessing or using this website, you acknowledge that you have read, understood, and agree to the data practices described below. If you do not agree with any part of this policy, please discontinue use of the site. Where our legal basis for processing is your consent, you may withdraw that consent at any time without affecting the lawfulness of any processing carried out prior to withdrawal.
Scope of this policy: This policy applies exclusively to personal data processed via our public corporate website and direct communications made to CI&T Software S/A. It does not cover data processed on behalf of our clients as a data processor under separate data-processing agreements — those engagements are governed by the contracts and privacy notices relevant to the client relationship.
Information We Collect
We collect personal data only to the extent necessary to provide our services, respond to enquiries, maintain the security of our platform, and improve the quality of our digital presence. The categories below set out what we collect, why, and under which legal basis.
Information You Provide Directly
When you contact us through our published email address or telephone number, you may provide us with information that includes:
- Identity data: your full name, job title, and the name of the company or organisation you represent.
- Contact data: your business email address, telephone number, and mailing address.
- Communication content: the body of your message, any attachments you include, and the context of the enquiry — for example, a request for information about a specific service or a potential partnership.
- Professional background: information you voluntarily include about your role, project requirements, or technical environment when describing your business needs.
The legal basis for processing data you provide via direct contact is our legitimate interest (LGPD Art. 7, X; GDPR Art. 6(1)(f)) in responding to business enquiries, and, where we wish to send you ongoing marketing communications, your explicit consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
Information Collected Automatically
When you browse this website, our servers and third-party analytics tools automatically collect certain technical data. This includes:
- Log data: your IP address (truncated after collection where possible), browser type and version, operating system, the referring URL, pages visited, time and date of access, and time spent on each page.
- Device data: device type (desktop, tablet, mobile), screen resolution, and language settings.
- Analytics identifiers: anonymised or pseudonymised identifiers assigned by analytics platforms to distinguish unique sessions and returning visitors.
- Interaction data: click paths, scroll depth, and other behavioural signals that help us understand how visitors engage with our content.
This automatically collected data does not, in the ordinary course, identify you as a named individual. The legal basis for this processing is our legitimate interest in maintaining the security and functionality of our website and in understanding how our content is consumed. Where applicable regulations require consent for cookies or trackers prior to non-essential data collection, we rely on your freely given, specific, informed, and unambiguous consent obtained through our cookie-preference mechanism.
Information From Third-Party Sources
We may receive limited information about corporate contacts from reputable professional networking platforms or data-enrichment services when conducting outbound business development. Such information is limited to professional contact details in a business context and is always processed in accordance with this policy. We do not purchase consumer marketing lists or process sensitive personal categories of data through these channels.
How We Use Your Information
We process your personal data only for the specific, explicit, and legitimate purposes described below. We do not use your data for automated decision-making that produces legal or similarly significant effects, nor do we sell your personal information to third parties for their independent marketing purposes.
- Responding to enquiries: To read, assess, and reply to messages sent to our contact email address, including requests for information about our services, partnerships, media enquiries, and recruitment questions.
- Business development and relationship management: To track the history of communications with existing and prospective business partners and to follow up on expressions of interest in a timely and contextually relevant manner.
- Website analytics and improvement: To understand how visitors navigate our website, identify content that resonates, detect technical errors, and iteratively improve the site's performance, structure, and accessibility.
- Security monitoring: To detect and investigate suspicious access attempts, protect against denial-of-service attacks, and maintain the integrity of our systems and the confidentiality of information on them.
- Legal compliance and enforcement: To comply with applicable laws and regulations, respond to lawful requests from public authorities, enforce our terms of use, and protect our legal rights and those of our users.
- Marketing communications (consent-based): Where you have given explicit permission, to send you our thought-leadership content, event invitations, or updates about CI&T's service offerings. You may opt out of any such communication at any time by writing to us at the address in Section 11.
We apply the principle of purpose limitation: if we wish to use your data for a purpose materially different from those listed above, we will contact you in advance to explain the new purpose and, where required by law, seek fresh consent before proceeding.
Cookies & Tracking Technologies
Our website uses cookies — small text files stored in your browser — and analogous tracking technologies (local storage, session storage, and pixel tags) to distinguish you from other users, remember your preferences, and analyse site usage. Below is a breakdown of the categories we deploy.
Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be switched off. They are set in response to actions you take — such as setting your privacy preferences or loading secure content — and do not store any information that identifies you personally. No consent is required for these cookies, as they fall within the scope of legitimate interest under ePrivacy regulations.
Analytics & Performance Cookies
We use Google Analytics 4 (GA4) with IP anonymisation enabled to collect aggregated data about site usage. GA4 tracks page views, session duration, traffic sources, and user flow through the site. The data is processed by Google LLC under a data-processing agreement compliant with EU standard contractual clauses. We have configured GA4 to respect browser-level opt-out signals (Global Privacy Control) and to refrain from cross-site tracking. These cookies are only set with your prior consent where required by applicable law.
We may additionally use Google Tag Manager to manage our analytics and marketing tags in a controlled environment, limiting the number of third-party scripts that load without your consent.
Functional Cookies
Functional cookies allow the website to remember choices you make — such as your preferred language or cookie consent status — to provide a more personalised experience on subsequent visits. These cookies do not track your activity across other websites.
Marketing & Targeting Cookies
Where you provide consent, we may deploy cookies linked to Google Ads for remarketing and conversion-measurement purposes, enabling us to understand which of our online promotions lead to meaningful engagement with our business. These technologies may set identifiers that are shared with Google LLC. We do not use these cookies to build profiles of individuals based on sensitive characteristics or to engage in cross-context behavioural advertising beyond what is disclosed here.
Managing Your Cookie Preferences
You can review and adjust your cookie preferences at any time by clicking the "Cookie Preferences" link in our site footer. Additionally, you may configure your browser to block or delete cookies — instructions are available in your browser's help documentation. Please note that blocking certain cookies may impair some website functionality. You can also opt out of Google Analytics across all websites using the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.
Sharing With Third Parties
We do not sell, rent, or trade your personal data. We share data only in the limited circumstances described below, and always subject to appropriate contractual or regulatory safeguards.
Service Providers (Processors)
We engage carefully selected third-party vendors who process data solely on our documented instructions. These include:
- Hosting and infrastructure providers — cloud platforms that host this website and associated systems, operating under data-processing agreements with strict security requirements.
- Analytics providers — Google LLC (Google Analytics 4), operating under the Google Ads Data Processing Terms and EU standard contractual clauses.
- Email and communication tools — providers of business email and collaboration software used internally to manage and respond to enquiries.
- CRM and sales-enablement platforms — systems used by our business development teams to manage correspondence and follow-up with prospective partners, accessed only by authorised CI&T personnel.
Group Companies
CI&T Software S/A is the parent entity of a global group of affiliated companies. We may share certain contact and business data with our subsidiaries or parent entities for the purposes of centralised business operations, client servicing, and internal reporting. All such intra-group transfers are governed by binding corporate rules or equivalent safeguards.
Legal Obligations and Protection of Rights
We may disclose personal data when we reasonably believe disclosure is required or permitted by law — including in response to a court order, subpoena, or lawful request by a regulatory authority — or when necessary to protect the legal rights, property, or safety of CI&T, our personnel, website visitors, or the public.
Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction, personal data held by CI&T may be among the assets transferred to the acquiring entity. Where applicable, we will notify affected individuals and, where required by law, seek fresh consent before such a transfer takes effect.
International Data Transfers
CI&T operates globally, and some of our service providers are located outside Brazil or the European Economic Area. Where we transfer personal data internationally, we rely on appropriate transfer mechanisms recognised under applicable law — including EU Standard Contractual Clauses (SCCs), adequacy decisions, or LGPD-equivalent safeguards such as contractual clauses or the data subject's explicit consent. On request, we can provide details of the specific mechanisms applicable to any particular transfer.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, to satisfy our legal and contractual obligations, and to resolve any disputes that may arise. The following general retention periods apply:
- Business enquiry correspondence: Communications received via email or telephone are retained for up to 5 years from the date of last contact, after which they are securely deleted or irreversibly anonymised. This period reflects standard commercial practice for managing business relationships and potential contract disputes.
- Analytics data: Aggregated and anonymised website analytics data is retained for up to 26 months in Google Analytics, in line with GA4 default settings, after which it is automatically deleted at source. Raw session-level logs on our servers are purged after 90 days.
- Cookie consent records: Records of your cookie preferences are retained for up to 12 months, at which point your consent is refreshed through the on-site mechanism.
- Marketing lists (consent-based): Contact details used for marketing communications are retained for as long as your consent remains in force. On withdrawal of consent or unsubscribe, data is removed from active lists within 30 days and from backup archives within 90 days.
- Legal holds: Where data is subject to an active legal proceeding, regulatory investigation, or dispute, we will retain the relevant records beyond standard periods until the matter is fully resolved.
At the end of applicable retention periods, personal data is securely destroyed using methods appropriate to the medium (cryptographic erasure for cloud data; certified destruction for any physical records). We conduct periodic data-inventory reviews to identify and remove data that is no longer required.
Data Security
Protecting the personal data entrusted to us is a core operational commitment. We implement a layered security programme aligned with internationally recognised frameworks, including ISO/IEC 27001, NIST CSF, and SOC 2 Type II requirements applicable to our infrastructure. The technical and organisational measures we maintain include:
- Encryption in transit: All data exchanged between your browser and this website is protected by TLS 1.2 or higher. We enforce HSTS (HTTP Strict Transport Security) to prevent protocol downgrade attacks.
- Encryption at rest: Sensitive data stored on our systems is encrypted at rest using AES-256 or equivalent standards.
- Access controls: Access to systems containing personal data is restricted on a need-to-know basis using role-based access controls (RBAC), multi-factor authentication (MFA), and regular access-rights reviews.
- Network security: Our infrastructure is protected by firewalls, intrusion-detection systems, and continuous security monitoring by our dedicated information-security team.
- Vulnerability management: We conduct regular penetration testing, automated vulnerability scanning, and patch management to address known security weaknesses promptly.
- Employee training: All personnel with access to personal data undergo mandatory privacy and security training upon onboarding and annually thereafter.
- Incident response: We maintain a documented data-breach response plan. In the event of a breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority (ANPD in Brazil, the relevant lead supervisory authority in the EU) within 72 hours of becoming aware, and will notify affected individuals without undue delay where required by law.
While we apply industry-standard measures, no method of transmission over the internet or electronic storage is completely impervious to attack. We cannot guarantee absolute security, but we commit to responding swiftly, transparently, and responsibly to any security incident.
Your Rights
Depending on your country of residence, you hold a range of rights with respect to the personal data we process about you. We honour these rights in full, without requiring you to pay a fee, and will respond to all verified requests within the timeframe mandated by applicable law — generally 15 days under the LGPD and 30 days (extendable by a further 60 days where complex) under the GDPR.
Right of Access & Confirmation
You may request confirmation of whether we process your personal data and, if so, obtain a copy of the data we hold, the purposes for which it is processed, and the parties with whom it has been shared. (LGPD Art. 18, I–II; GDPR Art. 15)
Right to Correction
If any personal data we hold about you is inaccurate, incomplete, or outdated, you have the right to request that we correct or complete it promptly. (LGPD Art. 18, III; GDPR Art. 16)
Right to Deletion / Erasure
You may request the deletion of personal data we process based on your consent, or data that is unnecessary, excessive, or processed in violation of applicable law. Note that certain data may be retained to comply with legal obligations. (LGPD Art. 18, VI; GDPR Art. 17)
Right to Data Portability
Where technically feasible, you may request a copy of your personal data in a structured, commonly used, machine-readable format, and ask that we transmit it to another controller. (LGPD Art. 18, V; GDPR Art. 20)
Right to Object
You may object to the processing of your personal data where we rely on legitimate interest or the public interest as a legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. (LGPD Art. 18, IX; GDPR Art. 21)
Right to Restrict Processing
In certain circumstances — for example, while the accuracy of data is contested or an objection is being assessed — you may request that we restrict the processing of your data to storage only. (GDPR Art. 18; LGPD Art. 18, IV)
Right to Withdraw Consent
Where our legal basis for processing is your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. (LGPD Art. 8, §5; GDPR Art. 7(3))
Right to Lodge a Complaint
If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd, or with the supervisory authority competent in your EU member state, without prejudice to any other administrative or judicial remedy.
How to Exercise Your Rights
To submit a data-subject rights request, please send a written communication by email to contato@ciandt-us.site with the subject line "Data Subject Rights Request". Your message should include your full name, the email address you used to interact with us, the right(s) you wish to exercise, and sufficient detail for us to locate the relevant data. We may ask you to verify your identity before processing the request to ensure that personal data is not disclosed to unauthorised parties. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act, with written reasons provided.
Children's Privacy
This website is directed exclusively at professionals, business decision-makers, and organisations seeking information about technology and digital-transformation services. It is not intended for, nor does it knowingly address, individuals under the age of 18 (or the applicable age of digital consent in their jurisdiction).
We do not knowingly solicit, collect, or store personal data from minors. If you believe that a minor has submitted personal data to us without the consent of a parent or legal guardian, please contact us immediately at contato@ciandt-us.site. Upon verification, we will promptly delete such data from our records and, where applicable, report the occurrence to the relevant authorities.
This commitment is consistent with LGPD Art. 14, which imposes heightened obligations on the processing of personal data of children and adolescents, requiring that such processing be carried out in the best interests of the minor, with specific consent from a parent or legal guardian where applicable.
Changes to This Policy
The digital and regulatory landscape evolves continuously, and we review this Privacy Policy at least annually — and promptly whenever a material change occurs in how we collect or process data, or when required by changes in applicable law.
When we make changes, we will update the "Last updated" date displayed at the top of this page. Where changes are material — meaning they affect your rights, the categories of data we collect, our sharing practices, or our legal bases for processing — we will take additional steps to draw them to your attention. This may include displaying a prominent notice on this website for a period following the update, or sending a direct notification to individuals whose data we process and whose contact details we hold.
We encourage you to review this policy periodically. Your continued use of this website following the publication of a revised policy constitutes acceptance of those revisions, to the extent permitted by applicable law. Where consent is required for any new processing activity, we will seek it separately and will not rely on continued use as implicit consent.
Previous versions of this Privacy Policy are available on request by writing to our Data Protection contact below.
Contact & Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise your data-subject rights, wish to report a potential data security issue, or have concerns about how we handle your personal information, please reach out to us through the details below. We are committed to responding to all privacy-related communications promptly and with the seriousness they deserve.
CI&T Software S/A
Estrada Giuseppina Vianelli di Napolli, 1455
Bloco C — Pavimento Superior
Polo II de Alta Tecnologia (Campinas)
Campinas-SP, Brazil
CNPJ: 00.609.634/0001-46
Privacy & Data Protection enquiries:
contato@ciandt-us.site
Please mark the subject line of your email with "Privacy Policy Enquiry" or "Data Subject Rights Request" to ensure your message is routed to our data-protection team without delay. We aim to acknowledge all privacy-related communications within 5 business days and to provide a substantive response within the statutory timeframe applicable to your jurisdiction.
For complaints specifically addressed to Brazilian authorities, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) via gov.br/anpd. EU residents may contact the supervisory authority in their country of habitual residence, place of work, or the location of an alleged infringement of applicable data-protection law.