[ LEGAL SPECIFICATION // 01 ]DATA GOVERNANCELGPD & GDPR INVARIANTS

Privacy Policy & Data Governance

Architectural declaration regarding the collection, transmission, and retention of telemetry and communication data across this engineering portfolio.

OPERATOR: VINICIUS PONTUAL / ZANVEXIS
LAST AUDITED: SEPTEMBER 2026 // ZERO TRACKER MANIFEST
Third-Party Ads0 (Zero)
Tracking CookiesNone
Form TransitTLS Encrypted
JurisdictionBR / Global

01. Core Data Invariant: Zero Invalidation

This website serves as an institutional technical monograph and engineering portfolio. It is explicitly designed without commercial adtech networks, behavioral surveillance pixels, or cross-site tracking scripts.

We do not monetize visitor attention, sell contact metadata to brokerages, or build profiling graphs based on page dwell time. You inspect the engineering dossiers, review the architecture, and close the session without residual footprint.

“Defensive software engineering begins with data minimization. The most secure data point is the one never collected in the first place.”

02. Information Ingestion & Processing Scope

We categorize ingested data into two strict, isolated categories:

// A. Voluntarily Submitted Dispatch DataWhen submitting an inquiry via the Contact Terminal, the user explicitly transmits: Entity/Name, Return Channel (Email, Telegram handle, or Phone), Inquiry Category, and Message Payload. This information is consumed strictly to evaluate and respond to the technical inquiry.

// B. Serverless Edge Infrastructure TelemetryHosting infrastructure (such as Vercel Edge networks) processes standard ephemeral HTTP request metadata (IP address, user-agent string, requested URI) exclusively to negotiate TLS handshakes, prevent DDoS attempts, and route traffic safely. These transient logs are not joined with identity vectors.

03. Form Transmission & Relayer Architecture

When an inquiry is dispatched from the `/contato` route:

  • Serverless Action Isolation: Form inputs are processed via Next.js Server Actions on a server-side runtime, never directly exposed to client browser evaluation.
  • Telegram Bot Gateway Relay: Payloads are formatted into a structured administrative notification and routed over HTTPS/TLS to our private Telegram monitoring bot.
  • No Public Exposure: Submission payloads are never written to public databases, client-side local storage, or indexable search registries.

04. Retention Schedule & Deletion Rights

Inquiries that do not materialize into an active client engagement, engineering partnership, or contract are purged periodically.

Pursuant to the Brazilian General Data Protection Law (LGPD - Lei nº 13.709/2018) and the European General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), you maintain non-negotiable rights over your submitted data:

Statutory RightScope & Execution
Right of AccessRequest confirmation and a copy of any communication history stored in our channels.
Right to ErasureDemand immediate and complete destruction of your transmitted contact data and conversation logs.
Right to RectificationUpdate or amend outdated entity credentials or operational details.

To exercise these statutory rights, transmit an explicit request to zanvexistech@gmail.com with the subject line [DATA ERASURE REQUEST]. All verified claims execute within 48 business hours.

06. Data Controller & Governance Identity

CONTROLLER: Vinicius Pontual / Zanvexis Technologies
HEADQUARTERS: São Paulo, SP — Brazil
GOVERNANCE EMAIL: zanvexistech@gmail.com
FRAMEWORKS: LGPD (Art. 7º, V) // GDPR (Art. 6(1)(b) - Legitimate Interest & Contract Inquiries)