1 · Who is the controller
Rota do Sol is an international cultural platform led by Neta Honorata Maíta. The controller of the personal data processed through this website is the Rota do Sol project, operating in Brazil (Brasília · DF) with an active bridge in the United Kingdom (Bristol · London).
The address rotadosolestacaobr@gmail.com concentrates institutional contact and also serves as the channel for the Data Protection Officer (DPO).
2 · What data we collect
We collect only what is necessary to sustain the project's mission. Data may be provided directly by you, for example, when writing to us, making a donation or expressing interest as an investor, or collected automatically by your browser.
- Contact data: name, email, phone, country, message.
- Donation data: name, email and transactional data processed by providers (PayPal, Wise, Revolut, Pix institutions). We do not store card numbers.
- Browsing data: truncated IP, device type, browser, pages visited, language and referrer. Used in aggregated form.
- Cookies and identifiers: see Cookie Policy.
3 · How we use the data
Data is processed to reply to your contact, process and record donations, issue institutional receipts upon request, communicate project updates, keep the site functional and secure, and comply with legal and accounting obligations.
We do not use personal data for behavioural advertising, automated risk profiling or automated decisions with significant effects over the data subject.
4 · Legal bases
We process data based on: consent (art. 7, I LGPD; art. 6(1)(a) GDPR) for communications and analytical cookies; performance of pre-contractual steps and contracts (art. 7, V LGPD; art. 6(1)(b) GDPR) for donations and partnerships; compliance with legal obligations (art. 7, II LGPD; art. 6(1)(c) GDPR) and legitimate interest (art. 7, IX LGPD; art. 6(1)(f) GDPR) for site security and fraud prevention.
6 · International transfers
Rota do Sol operates between Brazil and the United Kingdom. Data may therefore be transferred internationally, for example, when using providers based in the EU, UK or United States. Such transfers comply with art. 33 LGPD and equivalent safeguards (standard contractual clauses, adequacy decisions or specific consent).
7 · Retention
We retain data for the period required by the declared purpose or by law (typically up to 5 years for financial and tax records). After that period, data is anonymised or securely deleted.
8 · Your rights
As a data subject, you may at any time: confirm processing; access your data; correct incomplete or out-of-date data; request anonymisation, blocking or deletion; request portability; withdraw consent; and object to processing based on legitimate interest.
To exercise any right, write to rotadosolestacaobr@gmail.com. We reply within 15 business days.
9 · Security
We adopt technical and organisational measures proportionate to the risks: traffic served over HTTPS/TLS, hosting with standard hardening, least-privilege principle for administrative access, regular backups and periodic dependency review.
No measure eliminates risk entirely. In case of a high-risk incident, we will notify data subjects and the relevant authority within legal deadlines.
10 · Children and adolescents
The site is not directed at users under the age of 16. We do not knowingly request or collect children's data. If you become aware of any improper collection, please write to us so we can remove it immediately.
11 · Changes to this policy
We may update this document to reflect legal, technical or operational changes. The last update date is shown at the top of the page. Material changes will be communicated through institutional channels.