Privacy Policy for the Ducke Website
Last updated: 15 August 2026.
1. Controller
RCI Consultoria Ltda., CNPJ 51.768.490/0001-01, with registered office at Rua Doutor Querubino Soeiro, 760, Sala 02, Centro, Leme/SP, CEP 13610-080, is responsible for decisions regarding personal data processed on its institutional website, in commercial contacts, in account administration, billing, support, and the security of its own operations.
2. Scope
This Policy explains how Ducke processes data of visitors, prospects, customer representatives, suppliers, and users who interact with the website. The processing of data entered by customers in Ducke CRM is also explained in the CRM Privacy Policy and in the contractual data processing annex.
3. Data that may be processed
Identification and contact data, such as name, phone number, company, job title, city, and information provided in the message.
Commercial and contractual data, such as interest, plan, proposal, acceptance, service history, payment, and support.
Technical and browsing data, such as IP address, date and time, pages accessed, browser, device, security logs, and cookie preferences.
Data submitted spontaneously in attachments, meetings, demos, or requests. Avoid sending sensitive or excessive data when it is not necessary.
4. Purposes and legal bases
Data may be used to respond to requests, present a demo or proposal, carry out pre-contractual procedures, formalize and perform contracts, provide support, issue invoices and tax documents, prevent fraud, protect environments, comply with legal or regulatory obligations, and exercise rights. Where appropriate, Ducke may process data for legitimate relationship management and service improvement, after assessing necessity, impact, and the data subject's expectations. Consent will be used when it is the appropriate basis and may be withdrawn.
5. Commercial communications
Communications related to a request, account, or contract are sent to fulfill the request itself or to perform the existing relationship. Optional marketing will be separate and will allow opposition or unsubscribe through a simple mechanism. Withdrawing marketing consent does not prevent messages necessary for security, billing, support, or contract performance.
6. Sharing
Ducke may share only necessary data with providers of hosting, cloud, communication, payment, tax issuance, support, security, analytics, e-signature, and professional services subject to protection duties. It may also share when there is a legal obligation, a valid order, a corporate transaction with safeguards, or a need to exercise rights. Personal data is not sold.
7. International transfers
Some providers may process or store data outside Brazil. In such cases, Ducke will adopt a mechanism permitted by law, appropriate contractual and technical measures, and transparency consistent with the operation. The current list of relevant suppliers should remain available in the privacy or contracting area.
8. Retention and disposal
Data will be kept for as long as necessary for the stated purpose, the contractual relationship, support, security, and legal or rights-exercise deadlines. Once the need ends, data will be deleted, anonymized, or kept in a restricted manner when there is a basis for retention. Backups follow controlled cycles and must not be used for new purposes.
9. Security
Ducke adopts administrative and technical controls proportionate to the risk, including access management, authentication, logging, updates, infrastructure protection, continuity, and incident response. No environment is immune to risk; therefore, controls are reviewed and relevant incidents are handled in accordance with applicable law and regulation.
10. Data subject rights
The data subject may request confirmation and access, correction, information about sharing, anonymization, blocking or deletion of unnecessary or improperly processed data, portability when regulated, opposition, withdrawal of consent, and review of exclusively automated decisions, within legal limits. Ducke may request information to confirm identity and security. Requests may be made through the privacy form available on the website or via WhatsApp +55 19 93300-5586. It is also possible to petition the competent authority.
11. Children and adolescents
The website and business services are not directed at children. If data of children or adolescents is necessary in a specific project, processing will depend on a dedicated assessment, reinforced protection measures, and observance of the best interests of the child; indiscriminate submission through general forms is not authorized.
12. Cookies, AI, and automated decisions
Choices regarding non-essential cookies are managed in the Preference Center. When artificial intelligence features are used in support, analysis, or automation, the purpose, data involved, provider, and need for human review must be consistent with the information presented. Ducke will not adopt an exclusively automated decision with significant effect without providing the required information and rights.
13. Changes and contact
This Policy may be updated, with indication of the new date. Material changes will be highlighted or communicated appropriately. Questions may be sent through the privacy form or via WhatsApp +55 19 93300-5586.
Privacy form — data subject rights
Use this form to request confirmation, access, correction, and other rights set out in the Policy. The request generates an internal protocol and is forwarded to contato@ducke.com.br. You may also use WhatsApp +55 19 93300-5586.