Privacy & data protection

Privacy & Data Use Policy

This Policy explains how Trilha collects, uses, stores, shares and protects personal data on its website, in the Institutional Assessment and in contact channels. This English version is provided for convenience; in case of any discrepancy, the Portuguese version prevails.

Last updated: September 26, 2026 CNPJ 50.072.052/0001-41
01

Who is the data controller?

For personal data collected directly on this website and in the brand's digital experiences, the controller is Trilha Consultoria, a brand used by the legal entity registered in Brazil under CNPJ 50.072.052/0001-41, hereinafter simply “Trilha”.

Trilha determines the purposes and essential means of the processing carried out through these channels. In projects commissioned by clients, the roles of controller and processor may vary depending on the context and the applicable contract.

02

What does this Policy apply to?

This Policy applies to Trilha's institutional website and to the related digital interactions:

  • the short contact form;
  • the Institutional Assessment;
  • conversation requests and follow-up;
  • management of opportunities and relationships arising from these requests;
  • security, operation and administration of the platform.
03

What personal data may be processed?

ContextData
Direct contactname, organization, job title or role, email, mobile number when provided, contact preference and message.
Institutional Assessmentname, job title or role, organization, website, email (organizational or personal), CNPJ when provided, organizational context, goals, answers, comments and information voluntarily provided during the experience.
Trilha BenchmarkThe CNPJ looked up (public data about the organization); to look up more than one CNPJ, name and email; when registering for the benchmark, name, job title, email and stated priority; and, for usage control, a technical browser identifier, an encrypted (hashed) version of the IP address and the date and time of each lookup.
Source of the visitcampaign parameters (UTM), landing page and referring site, recorded with submitted forms to understand which channels bring in contacts.
Conversation requestname, organization, email, mobile number, preferred channel, contact time and optional message.
Security and operationstechnical information needed for the service to work and be protected, such as access logs, requests, technical identifiers, date and time and basic browser or device information when generated by the infrastructure.

Trilha Benchmark usage limits. The first lookup of a CNPJ is free. Looking up the same CNPJ again requires the “I'm not a robot” check (Google reCAPTCHA), and looking up other CNPJs requires a name and an email address, confirmed through a link sent to that address, with a limit of 10 CNPJs per day and a minimum 2-minute interval between lookups. These controls exist to prevent automated use and avoid overloading the public sources consulted. The name and email provided at this step are recorded as a prospect contact, do not subscribe you to marketing communications and may be used by Trilha to get in touch about your use of the tool. Anyone who asks to join the test list for the new international funding analysis authorizes, after confirming their email, updates about this analysis and an invitation to test it; you can leave the list at any time through the privacy contact.

Applications to the Trilha Network. On the About us page, professionals can apply to the Trilha Network by providing their name, email, phone number, LinkedIn, city, years of experience, areas of expertise, a message and a CV in PDF. This data is used only to assess participation in the network and to get in touch, based on the consent given in the form, which may be withdrawn at any time through the privacy contact. The CV is kept in a private storage area accessible only to Trilha, is not shared with third parties without authorization and is retained for up to 24 months after submission or until a deletion request. We recommend not including unnecessary sensitive data in your CV, such as health information, religion or personal documents.

Trilha follows the principle of necessity and seeks to limit collection to data compatible with each purpose.

04

What is the data used for, and which legal bases may apply?

The legal bases depend on the purpose and context. Applicable grounds include:

Responding to requests and starting a professional relationshippreliminary steps related to a possible engagement or provision of services, when requested by the data subject.
Providing the Institutional Assessmentfulfilling the user's request and delivering the chosen digital experience.
Maintaining security, preventing abuse and running the platformTrilha's legitimate interest, taking into account the impact on data subjects' rights and freedoms.
Meeting obligations and protecting rightscompliance with legal or regulatory obligations and the regular exercise of rights, where applicable.
Marketing communicationsonly when there is an appropriate legal basis and, where necessary, the data subject's specific consent, with the option to unsubscribe.

Submitting a contact form or requesting a conversation does not automatically subscribe you to marketing communications.

05

How is Institutional Assessment data used?

The answers are used to generate a preliminary assessment of institutional capacities and to organize signals and hypotheses that can be explored further later. This experience does not replace an in-depth institutional diagnostic.

Some information may be processed by methodology rules, automations and internal computing resources to structure the assessment. Trilha does not use the answers provided in this experience to automatically subscribe the data subject to marketing.

When you start the Assessment, your identification details and answers are saved at each step so you can resume later. If the assessment is left incomplete, Trilha may send a single reminder email. When you finish, the result is displayed on screen and sent to the email provided, with an access link: anyone who receives this link will be able to view the result, so share it only with people you choose.

Data and learnings may be used in aggregated or anonymized form to improve the methodology, provided they do not allow the data subject or their organization to be identified by reasonably available means.

06

Who can the data be shared with?

Trilha does not sell personal data. Data may be shared, to the extent necessary, with vendors that support the operation of the website and platform, such as hosting, database, authentication, infrastructure and security services.

Our infrastructure currently uses Vercel (hosting and cookieless audience metrics), Supabase (database and authentication), a transactional email provider (Resend) for results, confirmations and internal notices, a mobile notification service (Pushover) for internal alerts to the Trilha team about new contacts, and Google reCAPTCHA for the Trilha Benchmark “I'm not a robot” check, subject to Google's Privacy Policy and Terms. These vendors process data on Trilha's behalf to deliver the contracted technical services.

Data may also be shared when necessary to comply with a legal obligation, an order from a competent authority or the regular exercise of rights.

07

International data transfer

Some of the infrastructure vendors used by Trilha operate internationally. Because of this architecture, certain data may be transferred, stored or accessed outside Brazil, depending on the infrastructure and technical services used.

Where personal data is transferred internationally, Trilha seeks to adopt mechanisms and safeguards compatible with the LGPD and applicable regulations.

08

How long is data kept?

Data is kept for as long as necessary to fulfill the purposes described in this Policy, manage the relationship, preserve the traceability of interactions and comply with legal obligations or the regular exercise of rights.

When no longer needed, data may be deleted, anonymized or kept on a restricted basis where retention is permitted or required by law.

09

How is data protected?

Trilha adopts technical and administrative measures appropriate to the processing context to reduce the risk of unauthorized access, loss, alteration, disclosure or misuse of data.

Practices in place include separating public and private areas, authentication for administrative environments, restricted access to working data and server-side processing of methodology components.

10

Cookies and technical storage

The website does not use advertising or cross-site tracking cookies. Audience metrics (Vercel Web Analytics) and page performance metrics (Vercel Speed Insights) are aggregated, do not identify individuals and do not use cookies.

On the Trilha Benchmark, the website uses two essential technical cookies: trilha_vid, a random browser identifier used to apply lookup limits, and trilha_pass, which records access registration for up to 30 days. When the “I'm not a robot” check is displayed, Google reCAPTCHA may use its own cookies to work. The website also stores your language choice (trilha_lang) and whether the language was already selected automatically (trilha_auto).

The website uses your browser's local storage (localStorage and sessionStorage) for essential and convenience features: keeping the source of the visit (UTM) sent with forms, letting you resume an assessment in progress, keeping the benchmark unlocked and avoiding asking for the same details twice. This information stays in your browser and can be deleted at any time in its settings.

11

What are the data subjects' rights?

Under the LGPD, data subjects may request, as applicable to the processing:

  • confirmation that processing is taking place;
  • access to the data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
  • portability, where applicable;
  • deletion of data processed based on consent, where applicable;
  • information about data sharing;
  • withdrawal of consent, where consent is the legal basis for processing;
  • objection to processing in the cases provided for by law;
  • filing a complaint with Brazil's National Data Protection Authority (ANPD), where applicable.

Before fulfilling a request, Trilha may take proportionate measures to confirm the requester's identity.

12

Communications and marketing

Contacts made to respond to a request, carry out the Institutional Assessment, schedule a conversation or discuss a professional opportunity are communications related to the interaction requested by the data subject.

Inclusion in newsletters or recurring promotional communications is handled separately and, where it exists, there will be a simple way to unsubscribe.

13

Children, adolescents and sensitive data

Trilha's services are aimed at professionals and organizations and are not designed for the intentional collection of children's personal data.

The forms also do not request sensitive personal data. Please avoid entering sensitive information in open fields unless strictly necessary.

14

Changes to this Policy

This Policy may be updated to reflect changes in operations, services, infrastructure or applicable law. The current version will be available on this page, with the date of the latest update.

15

Contact for privacy and data protection matters

To exercise your rights or ask questions about the processing of personal data:

Trilha Consultoria
CNPJ (Brazilian registration) 50.072.052/0001-41
Email: mail.thiago@icloud.com