1. Who we are
Korvantis is a software engineering company working with critical systems, data, artificial intelligence and digital marketing. We are the controller of the personal data processed through this website and the applications we operate.
For anything related to this policy, including exercising your rights, write to contato@korvantis.io.
2. Data we collect
We collect only what we need to answer enquiries, run the site and deliver our services.
- Data you provide: name, email, company and the content of the message sent through the contact form.
- Browsing data: pages visited, time on page, traffic source, device and browser type, collected in aggregate by our analytics tool.
- Technical data: server access logs, used to diagnose failures and prevent abuse.
- Data from client accounts on third-party platforms, when the client authorises our access, as described in section 6.
3. How we use the data
We process personal data for the following purposes:
- Replying to enquiries, proposals and information requests.
- Delivering, maintaining and improving the services we are hired for.
- Understanding how the site is used and improving its content.
- Complying with legal and regulatory obligations.
- Preventing fraud, abuse and security incidents.
4. Legal bases
We process personal data under the Brazilian General Data Protection Law (Law 13.709/2018) and, where applicable, the European Union General Data Protection Regulation.
The bases we rely on are performance of a contract and pre-contractual steps, compliance with a legal obligation, consent for analytics cookies, and legitimate interest for the security and improvement of our services.
5. Cookies and analytics
We use Google Analytics to understand in aggregate how the site is used. Measurement is configured with IP anonymisation and advertising signals turned off, so this data is not used to advertise to you.
You can block cookies in your browser settings. The site works normally without them.
6. Use of Google APIs and Google Ads
Korvantis builds and operates its own applications that connect to Google APIs, including the Google Ads API, to create and manage marketing campaigns in Google Ads on behalf of clients who authorise that access.
Access is granted by the Google Ads account holder through Google's authorisation flow (OAuth). We request only the permissions needed for the functions listed below, and access can be revoked at any time in the client's Google Account settings.
- Creating, reviewing and adjusting campaigns, ad groups, ads and budgets.
- Reading performance metrics for reporting and campaign optimisation.
- Generating keyword, targeting and budget recommendations.
7. Limits on data received from Google APIs
Information obtained through Google APIs is used only for the purposes described in the previous section, within the account that granted access. We do not sell this data, do not use it for our own advertising, do not transfer it to third parties outside the cases described in this policy, and do not use it to train generalised artificial intelligence models.
The use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
To request deletion of data obtained through this integration, write to contato@korvantis.io.
8. Sharing with third parties
We do not sell personal data. We share data only with providers that support our operation, and only as far as needed:
- Our infrastructure and website hosting provider.
- Google, as the provider of the analytics tool and the advertising APIs described above.
- An internal service that receives and organises messages sent through the contact form.
- Public authorities, where there is a legal obligation or court order.
9. International transfers
Some of the providers above process data outside Brazil. In those cases the transfer relies on the safeguards required by applicable law, such as standard contractual clauses.
10. How long we keep data
We keep contact messages for as long as needed to carry the commercial conversation, and for the period in which they may be required as evidence of a contractual relationship. Data from client accounts on third-party platforms is kept while the service and the access authorisation last.
Once the purpose ends, data is deleted or anonymised, unless the law requires us to keep it longer.
11. Security
We apply technical and organisational measures to protect data, such as encrypted traffic, access restricted by person and purpose, and activity logging. No system is fully immune to incidents, but we keep processes to detect, respond to and report security events.
12. Your rights
At any time you can request:
- Confirmation that we process your data, and access to it.
- Correction of incomplete, inaccurate or outdated data.
- Anonymisation, blocking or deletion of unnecessary data or data processed unlawfully.
- Portability of your data to another provider.
- Information about who we share your data with.
- Withdrawal of consent, where processing is based on it.
13. Children's data
Our services are aimed at companies and are not intended for people under 18. We do not knowingly collect data from children.
14. Changes to this policy
We may update this policy to reflect changes in our services or in the law. The date of the last revision is shown at the top of this page.
15. Contact
Questions and requests about personal data can be sent to contato@korvantis.io. We reply within 15 days.