Privacy Policy

Latest version: August 14, 2026.

This document, hereinafter referred to as the “Privacy Policy”, details how CHEESECAKE LABS SOFTWARE S/A., a private legal entity, registered with the CNPJ/MF under No. 19.384.141/0001-83, having its headquarters established at Avenida Desembargador Vitor Lima, nº 260, room 1002, 10th floor, Madison Center Building, Trindade, Florianópolis/SC, CEP 88040-400, Brazil (“CHEESECAKE LABS”, “we” or “us”), collects, stores, uses and shares the personal data of users of its solutions, as well as of its clients, business partners and job candidates.


This Privacy Policy applies to cheesecakelabs.com and its subdomains, to our marketing, sales and recruiting activities, and to the personal data we handle as a controller. When we process personal data on behalf of a client while delivering design and software engineering services, we act as a processor: in that case the client determines the purposes of the processing, the client’s own privacy notice applies to the individuals concerned, and our services agreement and data processing terms govern what we may do with the data.

1. Definitions


For the purposes of reading and interpreting this document, the terms listed will have the meaning in accordance with applicable data protection law, set out below:


User

Any natural or legal person, whether a visitor, customer, business partner or job candidate, who provides User Data to CHEESECAKE LABS or interacts with its websites and service platforms.


User Data

Data identifying a specific user, subdivided, for the purposes of this document, into: personal data (such as, but not limited to: name, ID, CPF, email address, residential or business address, telephone, job title and employer); navigation data (such as, but not limited to: IP address, device and browser type, login and access password when necessary, pages viewed and length of stay on the CHEESECAKE LABS website) and financial data (bank account information, billing details, credit card data).


Processing

Any operation carried out with personal data, including collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation, modification, communication, transfer, diffusion or extraction.


Controller and Processor

The Controller is the party that decides why and how personal data is processed. The Processor (operator) processes personal data on behalf of, and under the instructions of, the Controller. CHEESECAKE LABS acts as Controller for the data described in this Policy, and as Processor for personal data handled inside client projects.


Cookies

Files automatically created and stored on the devices (computers, mobile devices, etc.) of Users when accessing websites on the Internet, and which store data identifying the device and navigation.

2. Personal data we collect


2.1. Data you provide to us. We collect the data you choose to submit, including when you: complete a contact, proposal or newsletter form; subscribe to our content; take an assessment or download material we publish; apply for a job; or engage with us as a client, supplier or partner. This typically includes name, email address, telephone, company, job title, the content of your message and, for commercial relationships, contractual and billing information.


2.2. Data collected automatically. When you browse our website we collect basic information on access pattern, device type, browser, approximate location derived from IP address, referring page, pages viewed and interactions, through cookies and similar technologies as described in Section 5.


2.3. Data from other sources. We may receive data about you from business partners, referral sources, event organisers, publicly available sources and professional networks, where those sources are permitted to share it with us.


2.4. Sensitive data. We do not intentionally collect sensitive personal data (such as data revealing racial or ethnic origin, religious belief, political opinion, health, biometric or genetic data) through our website or marketing channels. Please do not include such data in messages you send us.

3. Collection


3.1. CHEESECAKE LABS only collects User Data for legitimate purposes and seeks to maintain its practices in compliance with all current laws and regulations and Regulatory Authorities, both national and international.


3.2. The collection of User Data can be carried out in the following ways:

(a) Manual and voluntary: upon completion of forms by the User himself (example: filling in data such as name, CPF and address when registering a new client); (b) Automated via software: when basic information on access pattern, device type and other information not directly identifiable is collected in an automated way and stored on the User’s side and also communicated to our suppliers, which can be stored and processed on both communication sides.

4. Purpose and legal bases


4.1. The purpose of using user data at CHEESECAKE LABS is due both to the execution of design and software engineering services, as well as the improvement and creation of services and dissemination of content promoted by CHEESECAKE LABS itself. We process personal data for the following purposes, each supported by a legal basis under the LGPD and, where applicable, the GDPR:


  • Responding to enquiries, preparing proposals and negotiating agreements. Legal basis: preliminary procedures related to a contract, and our legitimate interest in developing our business;
  • Delivering and managing our services, including project planning, billing and improving development deadlines for digital product creation through design and software engineering. Legal basis: performance of a contract;
  • Improvement of services: user data is used to improve performance, content layout, among others. Legal basis: legitimate interest, and consent where non-essential cookies are involved;
  • Periodic sending of advertising and information material from CHEESECAKE LABS to the email address registered by each User, in order to keep them updated on the solutions offered by CHEESECAKE LABS, as well as the main news of the digital market through our specialists. Legal basis: consent, or legitimate interest in relation to existing clients, always with the ability to unsubscribe;
  • Recruiting and evaluating job candidates. Legal basis: preliminary procedures related to a contract, and consent where we keep a candidate profile for future openings;
  • Credit protection, anti-fraud, information security and risk assessment: user data is used to add value to the protection of our services and customers, making the environment safer. Legal basis: credit protection and legitimate interest;
  • Complying with legal, tax, accounting and regulatory obligations. Legal basis: compliance with a legal or regulatory obligation;
  • Establishing, exercising or defending legal claims. Legal basis: regular exercise of rights in proceedings.


4.2. The purpose for using bank details: we use this data to facilitate payment processing and to comply with tax and accounting obligations.


4.3. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal. Where we rely on legitimate interest, you may object to the processing as described in Section 11.

5. Cookies and similar technologies


5.1. We use cookies, tags, pixels and similar technologies to operate our website, remember your preferences, understand how our content performs and support our marketing. They fall into the following categories:


  • Strictly necessary: required for the website to function, to balance load and to keep it secure. These cannot be switched off;
  • Performance and analytics: help us understand which pages are visited and how our content is used, so we can improve it;
  • Functionality: remember choices such as language and region;
  • Marketing and advertising: help us measure campaigns and present relevant content on our website and on third-party platforms.


5.2. Where the law requires it, non-essential cookies are only placed after you give consent, and you can change or withdraw that choice at any time through the cookie settings available on our website.


5.3. You can also block or delete cookies through your browser settings. Disabling certain cookies may affect the functionality of parts of our website.

6. How we share personal data


6.1. We do not sell personal data in exchange for money. We share personal data only as described below, and only to the extent necessary:


  • Service providers and subprocessors acting on our instructions, including cloud hosting and infrastructure providers, CRM and marketing automation platforms (such as HubSpot and Attio), recruiting platforms, analytics providers, communication and productivity tools, artificial intelligence tools as described in Section 7, and payment and banking service providers;
  • Professional advisers, such as legal, accounting, audit and insurance advisers, under professional confidentiality obligations;
  • Clients and business partners, where sharing is necessary to deliver or support a project you are involved in;
  • Corporate transactions: in connection with a merger, acquisition, investment or sale of assets, subject to appropriate confidentiality protections;
  • Public authorities, regulators and courts, where required by law, regulation or a valid legal request, or to protect our rights and the safety of others.


6.2. We require our service providers to process personal data only on our documented instructions, to keep it confidential and to apply appropriate security measures. The examples above are illustrative rather than exhaustive; you may request further information about the providers involved in a specific processing activity using the contact details in Section 14.


6.3. Some of the advertising and analytics technologies described in Section 5 may qualify as a “sale”, “sharing”, “targeted advertising” or “cross-context behavioural advertising” under certain United States state privacy laws. You can opt out at any time through the cookie settings on our website or by contacting us.

7. Use of artificial intelligence


7.1. We use artificial intelligence tools to support and accelerate the delivery of our design and software engineering services, and to support internal work such as research, drafting, code assistance and analysis.


7.2. These tools are contracted under business and enterprise agreements which provide that the data we submit is not used to train the providers’ models, and which are subject to confidentiality, security and data processing terms consistent with this Policy and with applicable law.


7.3. Output produced with the support of these tools is reviewed by our team before it is used or delivered. We do not rely solely on automated processing, including profiling, to make decisions that produce legal effects concerning you or that similarly significantly affect you.


7.4. Where a client agreement establishes stricter rules on the use of artificial intelligence in a project, those rules prevail over this section for that project.

8. International transfers


8.1. CHEESECAKE LABS operates from Brazil and the United States, and works with clients, partners and service providers located in other countries. Your personal data may therefore be transferred to, stored in, and accessed from countries other than your own.


8.2. For transfers of personal data out of Brazil, we rely on one of the mechanisms permitted by the LGPD and by ANPD Resolution CD/ANPD No. 19/2024, such as the standard contractual clauses approved by the ANPD, an adequacy decision, or another instrument recognised by the authority.


8.3. For transfers of personal data out of the European Economic Area or the United Kingdom, we rely on an adequacy decision or on the standard contractual clauses approved by the European Commission, together with any additional measures the transfer requires.


8.4. You may request further information about the safeguards applied to a specific transfer using the contact details in Section 14.

9. Retention


9.1. We keep personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law.


9.2. In deciding how long to keep personal data, we consider: the duration of our relationship with you; the retention periods imposed by tax, accounting, labour and other applicable legislation; the limitation periods that apply to potential claims; and, where processing is based on consent, whether that consent has been withdrawn.


9.3. When personal data is no longer necessary, it is deleted or irreversibly anonymised. Marketing data is removed from our active lists as soon as you unsubscribe.

10. Security


10.1. We adopt technical and organisational measures designed to protect personal data against unauthorised access, accidental or unlawful destruction, loss, alteration, communication or any form of improper or unlawful processing. These include encryption of data in transit and at rest, access control on a need-to-know basis, logging and monitoring, secure development practices, assessment of our service providers, and periodic training of our team.


10.2. No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee absolute security.


10.3. In the event of a security incident that may result in relevant risk or damage, we will notify the competent authority and the affected data subjects within the timeframes and in the manner required by applicable law.

11. Your rights


11.1. Subject to the conditions of applicable law, you may ask us to: confirm whether we process data about you; access that data; correct incomplete, inaccurate or out-of-date data; anonymise, block or delete data that is unnecessary, excessive or processed in breach of the law; port your data to another provider; obtain information about the public and private entities with which we have shared your data; obtain information about the consequences of refusing consent; withdraw a consent you previously gave; and request the review of decisions taken solely on the basis of automated processing.


11.2. If you are in the European Economic Area or the United Kingdom, you may also request the restriction of processing, object to processing based on legitimate interest, and lodge a complaint with your local supervisory authority.


11.3. If you are a resident of a United States state with a comprehensive privacy law, you may also, to the extent that law applies: confirm whether we process your personal information and access it; obtain a copy in a portable format; correct it; request its deletion; opt out of the sale or sharing of personal information, of targeted advertising and of profiling with legal or similarly significant effects; limit the use of sensitive personal information; and appeal a decision we make about your request. We will not discriminate against you for exercising these rights.


11.4. To exercise any of these rights, write to info@cheesecakelabs.com. We may need to request additional information to confirm your identity before acting on a request, and we will respond within the timeframe established by the applicable law. An authorised agent may submit a request on your behalf where the law allows it, subject to proof of authorisation.


11.5. You also have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD) or with the data protection authority of your jurisdiction.

12. Children and adolescents


12.1. Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from children or adolescents. If you believe a minor has provided us with personal data, please contact us so that we can delete it.

13. Third-party websites


13.1. Our website and content may contain links to third-party websites, platforms and social networks. This Privacy Policy does not apply to them, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

14. Changes to this Policy and contact


14.1. We may update this Privacy Policy to reflect changes in our practices, in the services we offer or in applicable law. The version date shown alongside this document indicates when it was last revised. When a change is material, we will take reasonable steps to give notice before it takes effect.


14.2. For any question about this Policy, about how we handle personal data, or to reach the person responsible for data protection at CHEESECAKE LABS, contact us at info@cheesecakelabs.com or at one of our offices:


  • Florianópolis, Brazil. Avenida Desembargador Vitor Lima, nº 260, room 1002, 10th floor, Madison Center Building, Trindade, Florianópolis/SC, CEP 88040-400. Telephone +55 48 3206-5246;
  • San Francisco, United States. 391 Sutter St, Suite 704, San Francisco, CA. Telephone +1 415 286 3266.