1. Who We Are and Our Role in Data Processing
Meta3 is a technology company specializing in the creation, modernization, documentation, governance, and evolution of software systems and technological environments. Our operational fronts include legacy systems modernization, custom software development, ERP evolution, SaaS solutions, regulatory compliance adaptations, critical systems governance, living documentation, applied artificial intelligence, Web3, smart contracts, tokenization, and technology-as-a-service.
Meta3 also develops and operates Meta3AI, a platform, methodology, and set of reusable assets focused on transforming complex technological environments into traceable knowledge, actionable decisions, and low-risk execution. Meta3AI is not an isolated AI tool; it is an integrated offering from Meta3 combining advanced software, software engineering, methodology, technical curation, governance, and applied intelligence.
For the purposes of this Policy, Meta3 acts as a Controller when determining the purposes and means of processing personal data collected through its own channels (such as our website, contact forms, cookies, B2B communications, and institutional relationships). In projects contracted by our clients, Meta3 acts as a Processor, processing personal data on behalf of and under the explicit instructions of the client. When Meta3 merely develops, documents, modernizes, or provides technical tools for a client to process their own data, the client remains solely responsible for defining the purposes and legal bases applicable to their technical environment.
2. Scope of this Policy
This Policy applies to personal data processed by Meta3 arising from: access to our institutional website; submission of contact forms; requests for proposals, meetings, materials, or commercial information; subscriptions to events, newsletters, or communications; relationships with clients, prospective clients, partners, and suppliers; and interactions via email, phone, messaging applications, social networks, or other digital channels managed by Meta3.
This Policy does not replace agreements, data protection addenda, confidentiality terms, security policies, or specific contracts signed with clients, suppliers, or partners. In case of data processing within client projects, the specific contractual terms and conditions shall prevail, in full compliance with applicable privacy regulations.
3. Personal Data Collected
Meta3 may collect personal data directly provided by the data subject, received during commercial interactions, or generated from website navigation.
- Identification and contact data: name, company, job title, department, professional email, phone number, city, and state.
- Commercial relationship data: areas of interest, history of interactions, requests, meetings, proposals, messages sent, participation in events, and communication preferences.
- Technical navigation data: IP address, date and time of access, pages visited, referral source, browser, device type, operating system, cookie identifiers, and interaction metrics.
- Data processed in the context of projects: when necessary for contract execution, and pursuant to a specific agreement, Meta3 may have access to data, documents, databases, logs, tickets, integrations, source code, technical artifacts, or environments provided by the client. In these cases, the scope and boundaries of the processing will be defined by the contract, access controls, and instructions of the client.
Meta3 does not request sensitive personal data through its institutional website. If a user spontaneously provides such information in open text fields, Meta3 will delete, anonymize, or process it only if there is an appropriate legal basis and justified need.
4. Purposes of Processing
Meta3 may process personal data to: respond to requests submitted through the website; contact individuals interested in our products, services, partnerships, or content; schedule meetings, demonstrations, or commercial presentations; prepare proposals; analyze user interest in Meta3 solutions; send institutional, technical, or commercial materials; share content related to Meta3's fields of expertise; improve website navigation, structure, and usability; analyze access metrics and performance; manage relationships with clients, partners, and suppliers; prevent fraud, abuse, unauthorized access, or security incidents; comply with legal, regulatory, or contractual obligations; protect and exercise Meta3's rights; and execute contracts, support services, modernization, documentation, diagnostics, or other contracted services.
In the context of client projects, Meta3 limits data processing strictly to the scope necessary to deliver the contracted service, observing principles of necessity, security, confidentiality, traceability, and segregation of access.
5. Legal Bases Used
The processing of personal data by Meta3 is grounded in the legal bases provided by privacy regulations (including LGPD and GDPR), according to the specific purpose. The main legal bases utilized include: execution of a contract or preliminary procedures; legitimate interest; consent, when necessary; compliance with a legal or regulatory obligation; and regular exercise of rights.
When Meta3 processes personal data on behalf of clients, the definition of the legal basis is the responsibility of the client controller, depending on the context and purpose of the processing.
When processing is based on consent, the data subject may revoke it at any time, subject to applicable legal consequences and limitations.
6. Commercial Communications and B2B Relationships
Meta3 may use professional contact details to send communications related to its activities, including technical articles, institutional updates, invitations to meetings or events, product information, and updates on modernization, governance, living documentation, artificial intelligence, Web3, and regulatory compliance.
The data subject may opt-out of receiving these communications at any time by using the unsubscribe link provided in the communication or by contacting us directly through the channels indicated in this Policy.
9. International Transfer of Data
Certain tools used by Meta3 (such as hosting, email, analytics, CRM, cloud storage, and automation services) may involve processing personal data outside of Brazil or the EU.
In such cases, Meta3 takes reasonable measures to ensure that international transfers observe legal frameworks, utilizing standard contractual clauses and technical and organizational security measures to protect the transferred data.
10. Security, Confidentiality, and Governance
Meta3 implements technical and administrative security measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, unauthorized disclosure, or any other form of unlawful processing.
These measures include access controls, restricted permissions, segregated environments, cybersecurity best practices, internal logs, confidentiality agreements, and regular reviews of security policies and suppliers.
In projects involving access to client systems, codebases, databases, or documentation, Meta3 observes the principles of necessity, confidentiality, and segregation, ensuring information is handled strictly for the contracted purpose.
11. Retention and Elimination of Data
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, in compliance with applicable legal bases.
Meta3 may retain personal data as long as a commercial, contractual, or institutional relationship exists with the data subject or their company; as needed to respond to requests; to comply with legal or regulatory obligations; to protect the rights of Meta3 or third parties; or for audit, governance, and safety purposes.
Once data is no longer required, it will be securely deleted, anonymized, or archived in accordance with applicable laws.
12. Rights of Data Subjects
Under privacy regulations, data subjects have the right to request: confirmation of processing; access to personal data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or elimination of unnecessary or non-compliant data; data portability; information about sharing; information about the consequences of withholding consent; and revocation of consent.
Meta3 may request additional information to verify the identity of the requester before disclosing any data. Requests related to data processed by Meta3 on behalf of clients will be forwarded to the respective client controller.
13. Data of Children and Adolescents
Meta3's institutional website is not directed at children or adolescents. We do not knowingly collect personal data from children or adolescents. If we identify that such data has been collected inadvertently, we will take immediate steps to delete it.
14. Automated Decisions
Meta3 does not use automated decision-making or profiling systems that produce legal or significant effects on data subjects through its institutional website. If such technologies are implemented in the future, we will update this Policy and comply with all regulatory requirements.
15. Privacy by Design and Continuous Improvement
Meta3 incorporates privacy, security, and data protection best practices into the development, modernization, documentation, and governance of all our technical solutions, observing principles of necessity, access limitation, and confidentiality.
In client projects involving data structures or integrations, Meta3 can assist in mapping data flows and identifying compliance gaps, without replacing the client's legal responsibility for defining their own privacy policies and governance decisions.
16. User Responsibilities
By using Meta3's website, the user declares that all provided information is accurate, complete, and up-to-date. The user is responsible for not submitting, in contact forms, third-party data without authorization, sensitive personal data, or confidential information irrelevant to the contact.
17. Third-Party Links
Our website may contain links to third-party sites or services. Meta3 does not control and is not responsible for the privacy practices, security measures, or content of these external websites. We encourage users to read the privacy policies of any third-party sites they visit.
18. Privacy Channel
For questions, requests, or to exercise your privacy rights, please contact Meta3 using the details below:
- Privacy Channel: comercial@meta3.com.br
- Company: Meta3
- Corporate Name: Meta3 Serviços e Tecnologias em Informação Ltda
- CNPJ: 05.492.013/0001-49
- Address: Rua Tenente Brito Melo, 427, Barro Preto, Belo Horizonte/MG, 10th floor
19. Changes to this Policy
Meta3 may update this Privacy Policy periodically to reflect changes in our practices, technologies, or legal obligations. The most current version will always be available on our website.
Last updated: 07/2026