Privacy Policy

At Mosten, protecting your personal data is not a checkbox — it is a core commitment. This policy explains exactly what we collect, why we collect it, how we use it, and the rights you hold over your own information.

Mosten Negócios & Tecnologia Ltda CNPJ 67.201.640/0001-30 Last updated: 18 June 2025

Introduction

This Privacy Policy governs the collection, processing, storage, and sharing of personal data by Mosten Negócios & Tecnologia Ltda ("Mosten", "we", "our", or "us"), a company incorporated in Brazil under CNPJ 67.201.640/0001-30, with registered offices at Rua Visconde do Rio Branco, 02, Floors 1, 6 and 10 — Centro, Santos-SP, Brazil. It applies to all personal data processed through our website at mosten.site, our subpages, contact forms, email communications, and any other digital touchpoints we operate.

Mosten provides technology-driven business process outsourcing (BPO), workforce allocation, and AI-powered operational solutions to companies across Brazil and internationally. In the course of delivering our services and maintaining our online presence, we inevitably handle personal data belonging to website visitors, prospective clients, current clients, and business partners.

We are committed to handling that data with full respect for your privacy, in compliance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados — LGPD, Law 13,709/2018), the European Union's General Data Protection Regulation (GDPR, Regulation 2016/679) where applicable, and all other relevant privacy legislation. If you have questions at any point, our contact details are set out in Section 11.

By using our website, submitting a contact form, or otherwise engaging with us digitally, you acknowledge that you have read and understood this policy. This policy does not form a contract; it is a transparency notice and a statement of your legal rights.

Information We Collect

We collect personal data only to the extent necessary for the specific purposes described in this policy. The information we may process falls into two broad categories: data you provide directly, and data collected automatically when you interact with our website.

2.1 Data You Provide Directly

When you fill in our contact or enquiry forms, request a consultation, subscribe to our newsletter, or send us an email, you may provide:

  • Identification data: your full name and job title.
  • Contact data: your business or personal email address, telephone number, and the name of your company or organisation.
  • Message content: the text of any enquiry, description of your business needs, or other information you freely include in a form submission or email.
  • Newsletter preference data: your email address and any topic preferences you select when subscribing to our updates.
  • Meeting or call data: notes, recordings (where legally permitted and you have been notified), and follow-up action items from discovery calls or consultations you schedule with us.

You are never required to submit personal data to browse our website. Providing data via a form is entirely voluntary; however, without it we may be unable to respond to your enquiry or provide the service you are requesting.

2.2 Data Collected Automatically

When you visit mosten.site, certain technical data is collected automatically by our servers and third-party analytics services:

  • Log data: your IP address (which may be anonymised or truncated), browser type and version, operating system, referring URL, pages viewed, time spent on each page, and the date and timestamp of your visit.
  • Device identifiers: approximate geolocation derived from IP (city/country level only — not precise GPS coordinates), screen resolution, and device category (desktop, tablet, mobile).
  • Behavioural analytics: click events, scroll depth, form interaction patterns, and other aggregate engagement signals collected via analytics platforms (see Section 4).
  • Advertising interaction data: if you arrive at our site via a paid advertisement (such as Google Ads), certain parameters indicating ad campaign, keyword, and click source may be logged to measure campaign effectiveness. This data is used only in aggregate and is never used to identify individuals for direct marketing without consent.
  • Cookie data: data stored in cookies and similar technologies placed on your device (see Section 4 for full details).

2.3 Legal Basis for Processing

Under both the LGPD and the GDPR we must identify a valid legal basis for every processing activity. We rely on the following bases:

Processing Activity Legal Basis (LGPD) Legal Basis (GDPR)
Responding to contact form submissions Legitimate Interest / Contract Art. 6(1)(b) / (f)
Sending newsletters (opted-in) Consent Art. 6(1)(a)
Analytics & site performance Legitimate Interest Art. 6(1)(f)
Advertising measurement cookies Consent Art. 6(1)(a)
Legal obligation (tax, accounting records) Legal Obligation Art. 6(1)(c)
Fraud prevention & security Legitimate Interest Art. 6(1)(f)

Where we rely on legitimate interest, we have conducted a balancing test and concluded that our interests do not override your fundamental rights. You may request a copy of our legitimate-interest assessment by contacting us at the address in Section 11.

How We Use Your Information

We use the data we collect for specific, explicit, and legitimate purposes. We do not process your personal data in ways that are incompatible with the purposes for which it was originally collected. Our uses include:

  • Responding to enquiries and proposals: When you submit a contact form or reach us by email, we use your name, email address, phone number, and message content solely to respond to your request, schedule follow-up calls, and provide the information or services you have asked about.
  • Delivering newsletters and updates: If you have subscribed to our communications, we use your email address to send periodic insights, company news, and information about our services. Every message contains a clear, one-click unsubscribe link.
  • Managing client and prospect relationships: Contact and business data may be stored in our CRM system to maintain a record of interactions, track service engagements, and ensure continuity of the commercial relationship.
  • Website operation and improvement: Automatically collected technical data helps us diagnose errors, optimise page performance, understand which content is most valuable to visitors, and make informed decisions about site structure and accessibility.
  • Marketing campaign measurement: Aggregate analytics and conversion data from advertising platforms (such as Google Ads) allow us to understand the return on investment of our campaigns and improve ad targeting. We do not build individual advertising profiles or sell data for any purpose.
  • Security and fraud prevention: Log and IP data is retained for a limited period to detect and investigate suspicious activity, protect against attacks on our infrastructure, and comply with lawful requests from competent authorities.
  • Legal and regulatory compliance: We may process and retain certain data to fulfil tax obligations, respond to official enquiries from Brazilian public authorities (e.g. Receita Federal, ANPD), and enforce our contractual rights where necessary.
We never sell your personal data. We do not trade, rent, auction, or otherwise transfer personal information to third parties for their own marketing or profiling purposes. Full stop.

Cookies & Tracking Technologies

Our website uses cookies — small text files stored on your device — and comparable technologies such as pixel tags and local storage. We categorise these into four types, as described below.

Strictly Necessary Cookies

These cookies are essential for the website to function. They enable core features such as security, network management, and page navigation. Because they are technically required, they are placed without requiring your consent. They do not collect information that could be used for marketing.

Performance & Analytics Cookies

We use Google Analytics 4 (GA4) to collect anonymised information about how visitors use our site — pages visited, session duration, geographic region (country level), and traffic source. GA4 is configured with IP anonymisation enabled, meaning your full IP address is never stored by Google. The data is aggregated and cannot be used to identify you personally. A consent prompt is displayed on first visit; analytics cookies are placed only if you accept.

Advertising & Measurement Cookies

If you arrive via a Google Ads campaign, Google's conversion tracking tag may set a cookie to record that a visit followed an ad click. This allows us to measure which ad creatives and keywords generate genuine interest. We do not use this data for cross-site behavioural advertising or audience profiling. These cookies are placed only upon your explicit consent via our cookie consent banner.

Functional Cookies

Certain preference settings — such as your cookie consent choice — are stored in a first-party cookie so we do not ask you again on every visit. These cookies expire after 12 months.

Cookie Name Provider Purpose Expiry
_ga Google Analytics Distinguishes unique users by assigning a randomly generated number as a client identifier 2 years
_ga_* Google Analytics Maintains session state for GA4 2 years
_gcl_au Google Ads Stores and tracks conversions from Google Ads campaigns 90 days
mosten_cc Mosten (first-party) Records your cookie consent preferences 12 months

Managing Your Cookie Preferences

You may withdraw or adjust your consent at any time by clicking the "Cookie Preferences" link in our site footer. You can also block or delete cookies via your browser settings — most modern browsers offer this under "Privacy", "Security", or "Site settings". Please note that disabling certain cookies may affect website functionality. For Google's specific opt-out tools, visit tools.google.com/dlpage/gaoptout (Analytics) or adssettings.google.com (Ads).

Sharing With Third Parties

We share personal data with external parties only to the extent strictly necessary for us to operate our business and deliver our services. We do not share data with third parties for their independent commercial use. The categories of recipients are:

5.1 Service Providers (Data Processors)

We engage carefully selected technology vendors who process data on our behalf, under written data processing agreements that bind them to the same standards this policy establishes. Current categories include:

  • Cloud hosting and infrastructure: Our website is hosted on servers operated by reputable cloud providers in Brazil or in jurisdictions that offer an adequate level of data protection. Server logs and form submissions reside in these environments.
  • CRM and sales tooling: Contact data submitted via our forms may be stored in a CRM platform to manage prospect and client relationships. Access is restricted to authorised personnel only.
  • Email delivery: Newsletter and transactional email messages are routed through a professional email delivery service. This service handles your email address for delivery purposes only and does not use it for any other purpose.
  • Analytics platforms: As noted in Section 4, Google Analytics 4 processes aggregated, anonymised visit data on our behalf.
  • Advertising measurement: Google Ads conversion tracking processes limited interaction data for campaign measurement. Please review Google's Privacy Policy at policies.google.com/privacy for details.
  • Accounting and legal advisors: We may share information with our external accountants, auditors, or legal counsel to the extent required for them to provide their services, under strict confidentiality obligations.

5.2 Legal Requirements and Law Enforcement

We may disclose personal data to competent public authorities — including the Brazilian National Data Protection Authority (ANPD), Receita Federal, or courts — when required to do so by applicable law, court order, or regulatory demand. In all cases we will, where legally permissible, seek to notify the data subject before disclosure and limit the scope of any disclosure to the minimum necessary.

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of Mosten's business assets, personal data held by us may be transferred to the acquiring entity as part of that transaction. We will notify you via a prominent notice on our website and, where required by law, seek your consent before any such transfer takes place.

5.4 International Transfers

Some of our service providers — notably Google — are headquartered outside Brazil and may process data in the United States or other countries. Where data is transferred outside Brazil, we ensure adequate safeguards are in place in accordance with LGPD Article 33, including standard contractual clauses, adequacy decisions, and/or binding corporate rules, as appropriate.

Data Retention

We do not keep personal data for longer than is necessary for the purpose for which it was collected, or as required to meet legal, regulatory, or contractual obligations. Our general retention periods are:

Data Category Retention Period Reason
Contact form submissions (no contract) 24 months Time needed to follow up and assess commercial opportunity
Active client contact data Duration of contract + 5 years Contractual relationship and statute of limitations
Newsletter subscribers (opted-in) Until unsubscribe + 1 year Consent record and dispute resolution
Server access logs 6 months Security monitoring and incident investigation
Analytics data (GA4) 14 months GA4 default configured retention window
Invoice and financial records 10 years Brazilian tax and commercial law obligation
Consent records 5 years after last interaction Demonstrating compliance with LGPD and GDPR

At the end of the applicable retention period, personal data is either securely deleted, anonymised (so it can no longer be associated with any individual), or, where deletion is temporarily not technically feasible (e.g., backup media), restricted so it cannot be accessed or used until permanent deletion is possible.

Data Security

We implement a layered set of technical and organisational security measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, or unlawful processing. Our measures include, but are not limited to:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HSTS to prevent downgrade attacks.
  • Access controls: Access to systems containing personal data is restricted on a need-to-know basis. Multi-factor authentication (MFA) is required for all staff accessing production environments.
  • Vendor due diligence: Before engaging any third-party processor, we assess their security certifications (e.g., ISO 27001, SOC 2) and contractual data protection commitments.
  • Regular security assessments: We conduct periodic vulnerability scans and internal security reviews. Any vulnerabilities identified are remediated in accordance with a severity-based schedule.
  • Incident response: We maintain a documented data breach response procedure. In the event of a breach that is likely to result in risk to your rights and freedoms, we will notify the ANPD and, where required, affected individuals, within the timeframes established by the LGPD.
  • Staff training: All Mosten personnel who handle personal data receive regular training on data protection principles and their obligations under this policy and applicable law.

Despite these measures, no method of transmission over the internet and no method of electronic storage is completely secure. We therefore cannot guarantee absolute security, but we commit to acting promptly and responsibly if any incident occurs.

Your Rights

Depending on your location and the applicable law, you have a number of rights in relation to personal data we hold about you. These rights are available to all individuals under the LGPD, and to residents of the European Economic Area and United Kingdom under the GDPR and UK GDPR respectively. We honour these rights regardless of your location.

Right of Access

You may request a copy of the personal data we hold about you, including information about how it is used, where it came from, and with whom it has been shared.

Right to Rectification

If any of the personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct or complete it without undue delay.

Right to Erasure

You may ask us to delete your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent, or where processing was unlawful. This right is subject to legal retention obligations.

Right to Restriction

You can ask us to restrict how we use your data while a dispute about its accuracy or the lawfulness of processing is being resolved, or while you wait for us to respond to an objection.

Right to Data Portability

Where processing is based on your consent or a contract, you have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller.

Right to Object

You have the right to object at any time to processing based on legitimate interest, and to object unconditionally to processing for direct marketing purposes. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Right to Withdraw Consent

Where we rely on consent as the legal basis, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. For newsletters, simply use the unsubscribe link in any email.

Right to Lodge a Complaint

If you believe we have mishandled your personal data, you have the right to lodge a complaint with the Brazilian ANPD (anpd.gov.br) or, if located in the EU/EEA, with your local supervisory authority. We ask that you contact us first so we can try to resolve the issue.

How to Exercise Your Rights

To exercise any of the rights described above, please contact us in writing at contato@mosten.site with the subject line "Data Subject Request". We will acknowledge your request within 5 business days and respond in full within 15 business days (extendable to 30 days in complex cases, with notification). We may need to verify your identity before processing any request in order to protect against fraudulent claims.

No fee applies to exercising any of the above rights in the ordinary course. If a request is manifestly unfounded or excessive (for example, repetitive requests designed to generate cost), we reserve the right to charge a reasonable administrative fee or to decline the request, explaining our reasons.

Children's Privacy

Our website and services are directed exclusively at business professionals and organisations. We do not knowingly solicit, collect, or process personal data from individuals under the age of 18. Our website is not designed to be accessed by or appeal to children, and our contact forms, subscription lists, and commercial materials are all directed at adults acting in a professional capacity.

If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete that data from our records. If you are a parent or guardian and you believe your child has submitted data to us, please contact us immediately at contato@mosten.site and we will act without delay.

Changes to This Policy

Privacy law evolves, and so do our services and the technologies we use. We may update this policy from time to time to reflect changes in how we process data, to comply with new legal requirements, or to improve the clarity of our disclosures. All changes will be published on this page.

When we make material changes — for example, introducing a new purpose for processing your data or adding a new category of third-party recipient — we will provide prominent notice on our website and, where we hold your email address, notify you directly before the change takes effect. Where required by law, we will seek your renewed consent.

The "Last updated" date at the top of this policy indicates when the most recent revision was made. We recommend revisiting this page periodically. Continued use of our website after an update constitutes acknowledgement (but not necessarily consent, which is sought separately where required) of the revised policy.

Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy or to the personal data we hold about you, please reach out to us. We take all data protection enquiries seriously and will respond promptly.

Mosten Negócios & Tecnologia Ltda

Rua Visconde do Rio Branco, 02 — Floors 1, 6 & 10, Centro, Santos-SP, Brazil
CNPJ: 67.201.640/0001-30

We aim to respond to all data protection enquiries within 5 business days. For formal data subject rights requests, our full response will be provided within the statutory timeframe (15 business days under the LGPD, 30 calendar days under the GDPR) from the date we receive sufficient information to identify you and understand your request.

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd, or with your local supervisory authority if you are resident in the EU/EEA.