Introduction
Cloudvault Soluções em Backup e Armazenamento Ltda ("Cloudvault", "we", "our", or "us"), registered under CNPJ 67.991.602/0001-29, with registered offices at Alameda Rio Negro, 967, Conj. 231, Alphaville Centro Industrial e Empresarial, Barueri – SP, Brazil, operates the website and related services available at hadcloud.site and its subdomains.
We take the protection of your personal data seriously. This Privacy Policy explains, in plain language, exactly what personal information we collect when you interact with our website and services, the purposes for which we process it, how long we keep it, and the rights you can exercise over it. Our practices are designed to comply with Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018), the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679), and all other applicable privacy laws.
By browsing our website or reaching us through any channel listed on it, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of our services and contact us so we can address your concerns.
Legal basis for processing (LGPD / GDPR): We process personal data only when we have a legitimate legal basis to do so — primarily your consent, the performance of a contract, compliance with a legal obligation, or our legitimate interests in operating a secure and functional business. The specific basis for each type of processing is identified in the sections below.
Information We Collect
We collect personal data in two principal ways: information you provide to us voluntarily, and information collected automatically when you use our website. We deliberately limit collection to what is strictly necessary for the purposes described in this policy.
2.1 Information You Provide Directly
When you contact us by email, phone, WhatsApp, or through any other direct communication channel listed on this website, you may share:
- Identity data: your full name and, where relevant, your job title or company name.
- Contact data: email address, telephone number, and any postal address you choose to provide.
- Message content: the substance of your enquiry, including any attachments or documents you voluntarily send to us.
- Commercial data: details about the services you are interested in, your company's size or infrastructure, and any technical requirements you describe.
You are never obligated to provide personal information to browse this website. Providing contact details is entirely voluntary; however, without them we cannot respond to your enquiry or provide the requested service information.
2.2 Information Collected Automatically
When you visit our website, our hosting infrastructure and third-party analytics tools automatically record certain technical data. This may include:
- Log data: IP address, browser type and version, operating system, referral URL, pages visited, date and time of access, and the duration of your session.
- Device data: device type, screen resolution, language settings, and time zone.
- Interaction data: scroll depth, click patterns, and navigation paths through the site — collected in aggregated or pseudonymous form via analytics tools.
- Cookie data: identifiers stored on your device to recognise returning visitors and measure the effectiveness of our content. See Section 4 for full details.
Where technically feasible, this data is processed in anonymised or aggregated form so that it cannot be linked back to a specific individual. Where it constitutes personal data under applicable law, we treat it accordingly.
2.3 Data We Do Not Collect
We do not knowingly collect sensitive personal data such as biometric information, health records, racial or ethnic origin, political opinions, religious beliefs, or financial account credentials. We also do not collect data from children under 16 without verifiable parental consent (see Section 9). If you accidentally send us sensitive data, please notify us immediately so we can delete it securely.
How We Use Your Information
Every processing activity we carry out has a clear purpose and a lawful basis. We never use your data in ways that are incompatible with the purpose for which it was originally collected. The table below summarises our principal uses:
- Responding to enquiries: When you contact us, we use your name, email address, and message content to reply and, where applicable, to route your enquiry to the appropriate member of our team. Legal basis: performance of pre-contractual steps at your request (LGPD Art. 7, II; GDPR Art. 6(1)(b)).
- Service delivery and account management: If you become a client, we process your data to deliver contracted backup and cloud storage services, manage your service configuration, issue invoices, and provide technical support. Legal basis: contract performance (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
- Service improvement and analytics: Aggregated and pseudonymised usage data helps us identify which features are most useful, detect technical errors, and improve the performance of our website and infrastructure. Legal basis: legitimate interests (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
- Marketing communications: With your explicit prior consent, we may send you news about Cloudvault services, industry insights, or promotional information. You can withdraw consent at any time by emailing contato@hadcloud.site. Legal basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)).
- Legal and compliance obligations: We may be required to retain or disclose certain data to comply with applicable Brazilian law (e.g. the Código Civil, tax regulations) or in response to a valid order from a competent authority. Legal basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
- Security and fraud prevention: Log and device data is used to detect suspicious activity, prevent unauthorised access, and protect the integrity of our cloud infrastructure and your stored data. Legal basis: legitimate interests and legal obligation.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without your prior knowledge and, where required, your explicit consent.
Cookies & Tracking Technologies
Our website uses cookies — small text files stored on your device — and similar technologies such as web beacons and local storage objects. Some of these are essential to the functioning of the site; others help us understand how visitors use it so we can continually improve the experience.
When you first visit the site, we display a cookie consent banner that allows you to accept all cookies, reject non-essential cookies, or adjust your preferences by category. Your choice is respected immediately and stored so you are not prompted again on subsequent visits. You may change your preferences at any time via the cookie settings link in the website footer.
4.1 Categories of Cookies We Use
| Category | Purpose | Examples | Duration | Consent required? |
|---|---|---|---|---|
| Strictly Necessary | Enable core website functions such as security, session management, and cookie preference storage. The site cannot function properly without these. | Session ID, cookie consent record | Session / up to 12 months | No — essential |
| Analytics & Performance | Collect anonymised data on page views, session duration, and navigation paths to help us understand website usage and improve content. | Google Analytics 4 (_ga, _gid) | Up to 2 years | Yes |
| Functional | Remember user preferences (language, region) to personalise the browsing experience on return visits. | Language preference cookies | Up to 12 months | Yes |
| Marketing & Advertising | Track visits from advertising campaigns (e.g. Google Ads) to measure conversion rates and the effectiveness of our promotional activity. | Google Ads (_gcl_au, gclid) | Up to 90 days | Yes |
4.2 Google Analytics
We use Google Analytics 4 (GA4), operated by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). GA4 collects pseudonymous usage data and transmits it to Google servers, which may be located in the United States or other countries. We have enabled IP anonymisation so that your full IP address is never stored by Google on our behalf. We have also concluded a Data Processing Agreement with Google in line with GDPR Article 28 requirements.
You may opt out of Google Analytics tracking across all websites by installing the Google Analytics opt-out browser add-on.
4.3 Managing Your Cookie Preferences
In addition to our on-site consent tool, you can manage cookies through your browser settings. Most modern browsers allow you to block cookies, delete existing cookies, or be alerted when a new cookie is set. Please note that disabling certain cookies may affect the functionality of our website. For guidance, visit your browser's help section.
Sharing With Third Parties
Cloudvault does not sell, rent, or trade your personal data to any third party for their own commercial purposes. We share data only in the limited, specific circumstances described below, and always with appropriate contractual protections in place.
- Service providers (data processors): We engage carefully vetted technology vendors to help us operate our business — including cloud infrastructure providers, email delivery services, analytics platforms, and cybersecurity tools. These companies process your data only on our documented instructions and are prohibited from using it for any other purpose. All sub-processors are bound by data processing agreements that impose the same privacy and security obligations we uphold ourselves.
- Corporate group: Where Cloudvault operates within a corporate group structure, data may be shared between affiliated entities for internal administrative purposes, always subject to this privacy policy.
- Legal authorities: We may disclose personal data if required to do so by Brazilian law, court order, or any other competent regulatory authority. We will, to the extent permitted by law, notify you before making any such disclosure.
- Business transfers: In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the acquiring entity. We will notify affected individuals before their data is transferred and becomes subject to a different privacy policy.
- Professional advisors: Our lawyers, accountants, and auditors may access limited personal data as necessary to provide their services, and are bound by professional confidentiality obligations.
5.1 International Data Transfers
Some of our service providers are located outside Brazil or the European Economic Area. When we transfer personal data internationally, we do so only to countries that offer an adequate level of protection, or by implementing appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms recognised by Brazil's National Data Protection Authority (ANPD).
Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, to comply with our legal obligations, or to resolve disputes and enforce our agreements. Once data is no longer required, it is securely deleted or irreversibly anonymised.
- Enquiry and contact data: Records of communications from prospective clients are retained for up to 24 months after the last interaction, unless a commercial relationship subsequently develops, in which case the client data retention period applies.
- Client and contractual data: Data processed in the course of delivering our backup and storage services is retained for the duration of the contract plus 5 years, in accordance with Brazilian civil and tax law requirements (notably the Código Civil and Lei nº 9.430/1996).
- Marketing data: Records of consent for marketing communications and any associated email addresses are retained until you withdraw consent or for 3 years after the last engagement, whichever occurs first.
- Website log data: Server logs containing IP addresses and access information are retained for up to 12 months for security monitoring purposes, as permitted under Brazil's Marco Civil da Internet (Law No. 12,965/2014).
- Cookie-derived analytics data: Aggregated analytics data is retained for up to 26 months, in line with Google Analytics default settings, after which it is automatically purged.
At the end of any applicable retention period, data is permanently deleted from our systems and those of our sub-processors, or rendered irrecoverably anonymous, using methods appropriate to the sensitivity of the data.
Data Security
Protecting the personal data entrusted to us is central to everything we do — it is, after all, the very foundation of our cloud backup and storage business. We apply a layered security model to safeguard your information against unauthorised access, alteration, disclosure, or destruction.
- Encryption in transit: All data transmitted between your browser and our servers is protected using TLS 1.2 or higher. Our website enforces HTTPS across all pages with HTTP Strict Transport Security (HSTS) headers.
- Encryption at rest: Personal data stored on our systems and within our cloud infrastructure is encrypted using AES-256 standards, ensuring that data is unreadable even if storage media were physically compromised.
- Access controls: Access to personal data is strictly limited to authorised Cloudvault personnel who need it to perform their job functions. All staff with data access undergo regular privacy and security training and are bound by confidentiality obligations.
- Infrastructure security: Our cloud infrastructure is hosted in ISO 27001-certified data centres with physical security controls, redundant power supplies, and 24/7 monitoring.
- Vulnerability management: We conduct regular security assessments, penetration tests, and patch our systems promptly upon the discovery of any vulnerability.
- Incident response: We maintain a documented data breach response plan. In the event of a breach likely to result in risk to individuals, we will notify the relevant authority (ANPD in Brazil, the competent supervisory authority in the EU) within 72 hours of becoming aware, and will notify affected individuals without undue delay, as required by law.
While we implement robust technical and organisational measures, no system connected to the internet is entirely immune to risk. We encourage you to protect your own devices and to contact us immediately at contato@hadcloud.site if you suspect any unauthorised access to your data.
Your Rights
Under the LGPD and, where applicable, the GDPR, you have a comprehensive set of rights over your personal data. We are committed to honouring these rights promptly and without unnecessary bureaucracy. The rights available to you are:
Request confirmation of whether we hold data about you, and obtain a copy of that data together with information about how it is used.
Ask us to correct any inaccurate or incomplete personal data we hold about you. We will act on corrections without delay.
Request that we delete your personal data where it is no longer necessary, where consent has been withdrawn, or where processing is unlawful.
Object to the processing of your data for direct marketing purposes or where we rely on legitimate interests as our legal basis.
Receive your personal data in a structured, machine-readable format, or have it transmitted directly to another controller where technically feasible.
Request that we restrict processing of your data — for example, while a correction request is being verified or an objection is being assessed.
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
File a complaint with Brazil's ANPD (gov.br/anpd) or, for EU residents, your local data protection supervisory authority, if you believe your rights have been violated.
How to Exercise Your Rights
To exercise any of the rights listed above, please send a written request to contato@hadcloud.site, clearly stating the right you wish to exercise and providing sufficient information for us to identify you (such as the name and email address you used when contacting us). You will not need to pay a fee in normal circumstances.
We will respond to all legitimate requests within 15 business days under the LGPD, and within one calendar month under the GDPR, with the possibility of a two-month extension in cases of particular complexity, of which we will notify you. If we are unable to comply with a request — for example because we are legally obligated to retain the data — we will explain our reasons clearly.
Identity verification: To protect your privacy, we may ask you to verify your identity before we action any data rights request. This is to ensure that personal data is not disclosed to, or modified by, anyone other than the individual to whom it belongs.
Children's Privacy
Cloudvault's services are directed exclusively at businesses and adult professionals. Our website and services are not intended for, nor directed at, individuals under the age of 16 years.
We do not knowingly collect personal data from minors. If we become aware that we have inadvertently received personal information from a person under the age of 16 without verifiable parental or guardian consent, we will take immediate steps to delete that data from our systems. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at contato@hadcloud.site so we can investigate and remedy the situation promptly.
Changes to This Policy
As our services evolve and applicable laws are updated, we may revise this Privacy Policy from time to time. The "Last updated" date at the top of this page will always reflect the date of the most recent revision, and significant changes will be communicated to you directly where we hold your contact details.
We encourage you to review this page periodically to stay informed about how we are protecting your data. For material changes that affect your rights or our processing activities, we will provide a prominent notice on our website and, where applicable, seek your renewed consent before the changes take effect.
Continued use of our website or services after any updated version of this policy is posted constitutes your acknowledgment of the changes. Prior versions of this policy are available on request.
Contact & Data Protection Officer
If you have any questions, concerns, or requests relating to this Privacy Policy or to the way we handle your personal data, please reach out to us using the details below. We aim to acknowledge all privacy-related enquiries within 2 business days and to resolve them fully within the statutory timeframes.
Cloudvault Soluções em Backup e Armazenamento Ltda
CNPJ: 67.991.602/0001-29Alameda Rio Negro, 967, Conj. 231
Alphaville Centro Industrial e Empresarial
Barueri – SP, Brazil
Privacy & Data Protection enquiries:
contato@hadcloud.site
If you are located in the European Union and have a complaint that you feel has not been adequately addressed by us, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu. If you are located in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.