ATA
Menu
Legal /

Privacy Policy

Last updated: 2026-04-11

Advanced Tracking Academy ("we", "us", or "our") is committed to handling personal data responsibly. This policy explains how we collect, use, store, share, and protect personal data when you visit our website or contact us.

Questions or rights requests: [email protected]

1. Who controls your data

Advanced Tracking Academy

Av Beira Mar 03 — Maxaranguape — RN 59580000 — Brazil

[email protected]

2. Privacy contact and LGPD channel

For privacy matters — including data subject requests — contact us at [email protected]. This email is our designated communication channel with data subjects and the ANPD. If we later appoint a separate Encarregado / DPO, we will update this section. ATA currently relies on the ANPD communication-channel position available to small processing agents.

3. What personal data we collect

Depending on how you interact with our website, we may collect:

  • Identity and contact data — name, email address, optional phone if a future public form includes it
  • Technical and device data — IP address, browser type, OS, device type, language, screen/viewport, timezone
  • Website and attribution data — page URL, referrer, UTM parameters, click identifiers, cookie identifiers
  • Consent records — consent status, timestamp, policy version, privacy-choice history
  • Security and diagnostic data — access logs, error logs, anti-abuse records

4. Purposes, legal bases, and retention

Purpose Data used Legal basis Retention
Operate the website, prevent abuse, secure systems IP address, request logs, browser/device info, error logs Legitimate interests (security & reliability); legal obligations 30 days default; up to 90 days for security/legal reasons
Remember and demonstrate privacy choices Consent categories, timestamp, policy version, browser/server identifiers Legal obligation (accountability); consent is the basis for optional categories themselves Device-side token: 6 months; server-side evidence: 5 years
Measure website analytics Page URL, referrer, _ga, session IDs, UTM params, device/browser info Consent (where required for non-essential analytics) Raw identifiers: 90 days server-side; browser cookie duration per vendor
Measure ad performance and attribution _fbp, _fbc, _gcl_aw, _ttp, click IDs, UTM params, referrer Consent; US state law may treat this as "sharing" / targeted advertising subject to opt-out Raw identifiers: 90 days server-side; browser cookie duration per vendor
Respond to contact or access requests Name, email, request details, submission metadata Pre-contractual steps; legitimate interests in administering the request 12 months after last meaningful interaction if no customer relationship begins
Honor opt-outs and suppression requests Minimum data to record the choice (email, timestamp, scope) Legal obligations; legitimate interests in honoring privacy choices As long as needed to honor the request and avoid re-contact
Comply with law and defend claims Correspondence, request records, compliance logs Legal obligations; legitimate interests in compliance and legal defense As long as reasonably necessary for the relevant obligation or claim

5. Cookies and tracking technologies

We may use cookies, tags, pixels, and server-side tracking tools. Where required by law, non-essential technologies activate only after consent. See our Cookie Policy for the full inventory and controls.

6. How we share personal data

We may share data with service providers that help us operate the website and measure performance. Depending on the live stack, these may include:

  • Hosting and infrastructure (Cloudflare Pages)
  • Google Tag Manager, GA4, Google Ads
  • Stape (server-side tagging and consent-evidence infrastructure)
  • Meta Ads
  • TikTok Ads
  • Webhook and automation tools used to route form submissions (n8n)

We do not sell personal data for money. Some privacy laws (CCPA/CPRA) treat advertising attribution disclosures as "sharing" or targeted advertising. Where that applies, we provide the relevant controls.

7. International data transfers

ATA is based in Brazil. Some providers may process data in other countries. When a transfer requires a safeguard under applicable law, ATA relies on a valid mechanism, which may include:

  • Brazil-EU adequacy (recognized January 2026) where applicable
  • ANPD standard contractual clauses or other lawful LGPD transfer safeguards
  • European Commission or UK-approved contractual safeguards

You may request more information about the safeguards relevant to your data by emailing us.

8. US state privacy and Global Privacy Control

If applicable US state privacy law applies to your interaction with ATA, and ATA uses advertising or attribution tools those laws treat as "sale", "sharing", or targeted advertising, you may have the right to opt out. ATA honors the Global Privacy Control (GPC) browser signal as an opt-out of sale/sharing for US users. Use the "Privacy Settings" link in the footer to manage your choices at any time.

9. Profiling and automated processing

ATA may use limited automated processing to associate visits with campaigns, measure performance, and detect abuse. This may be considered profiling under some laws. ATA does not use solely automated decision-making to produce legal or similarly significant effects about you.

10. How long we keep data

We keep personal data only as long as necessary. Our operational baseline:

  • Consent evidence: 5 years
  • Raw attribution identifiers: 90 days
  • Security and diagnostic logs: 30 days default
  • Contact and request records: 12 months after last meaningful interaction
  • Suppression and opt-out records: as long as needed to honor the choice

11. Your rights

Depending on your location, your rights may include: access, correction, deletion or anonymization, restriction, objection, withdrawal of consent, information about sharing and transfers, opt-out of sale/sharing/targeted advertising, and the right to lodge a complaint with a supervisory authority (including the ANPD). To exercise any right, email [email protected].

12. Children

Our website is not directed to children. We do not knowingly collect personal data from children. If we learn a child has submitted data, we will review it against applicable rules (LGPD Art. 14, GDPR Art. 8) and take appropriate steps including deletion or guardian authorization where required.

13. Security

We use technical and organizational measures including encryption in transit, access controls, least-privilege access, provider-side safeguards, and logging. No method is completely secure. If we identify an incident involving personal data, we will assess it and notify as required by applicable law.

14. Changes to this policy

We may update this policy from time to time. When we do, we update the "Last updated" date at the top of this page.

15. Contact

Advanced Tracking Academy

[email protected]

Av Beira Mar 03 — Maxaranguape — RN 59580000 — Brazil