Legal & Compliance

Privacy Policy

At Hydraware, we are committed to handling your personal data with transparency, security and respect. This Policy explains what information we collect, why we collect it, how we protect it, and what rights you hold over it.

Last updated: 18 July 2025 Applies under GDPR & Brazil's LGPD

Introduction

This Privacy Policy is published by HW DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS LTDA, registered under CNPJ 68.398.483/0001-68, with registered offices at Rua Doutor Arlindo Luz, 540, Sala 01, Centro, Ourinhos – SP, Brazil, trading as Hydraware (hereafter "Hydraware", "we", "our" or "us").

We develop and license software solutions for water utility management and related infrastructure sectors. In delivering these services and maintaining our institutional website at hydraware.com.br, we inevitably process certain personal data belonging to visitors, prospective clients, and other individuals who interact with us.

This Policy applies to all personal data processed through our website and any related digital communications. It has been drafted in compliance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais — LGPD, Law No. 13,709/2018) and, where applicable to data subjects located in the European Economic Area or United Kingdom, the General Data Protection Regulation (GDPR, Regulation EU 2016/679). It also satisfies the transparency requirements expected by advertising partners, including Google.

By browsing this website, you acknowledge that you have read and understood the practices described below. If you do not agree with any part of this Policy, you should discontinue use of the website and contact us via the details in Section 11 to discuss how we may still be able to assist you.

Information We Collect

We collect personal data only to the extent necessary to operate our website, respond to enquiries and improve the experience we offer. The categories of information we may process are described below.

2.1 Information You Provide Directly

When you reach out to us through contact channels listed on this site — such as emailing us at [email protected] or calling us directly — you may voluntarily share personal details including your name, professional title, company name, email address, telephone number, and the content of your message. We use this information solely to respond to your enquiry and, where appropriate, to follow up regarding services that may be relevant to you.

2.2 Data Collected Automatically

When you visit our website, our servers and third-party analytics tools automatically record certain technical information about your visit. This includes:

  • IP address — used to understand geographic distribution of visitors and to detect abusive activity.
  • Browser type and version — so we can ensure optimal compatibility and display.
  • Operating system — to understand the environments in which our site is accessed.
  • Pages visited and navigation path — to identify which areas of our site are most useful and to detect technical errors.
  • Time and date of your visit and session duration — to understand usage patterns.
  • Referring URL — to understand how visitors find us, including through search engines or advertising campaigns.
  • Device identifiers and screen resolution — to enable responsive rendering and analytics segmentation.

This information is aggregated or pseudonymised wherever possible and is not used to identify you in isolation unless there is a specific legitimate reason to do so, such as detecting a security threat.

2.3 Cookies and Similar Technologies

We use cookies and similar tracking technologies (including pixels and local storage) to operate certain features of this website and to gather analytics data. Full details are provided in Section 4.

How We Use Your Information

We process personal data only where we have a lawful basis for doing so. The table below summarises our key processing activities, together with the purpose and legal basis that applies under the LGPD and the GDPR.

  • Responding to enquiries and sales conversations: When you contact us, we use the information you provide to reply promptly and accurately. Lawful basis: performance of pre-contractual steps (LGPD Art. 7, II; GDPR Art. 6(1)(b)) and legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
  • Operating and improving our website: We analyse aggregated traffic data to identify content that is useful to visitors, to resolve technical errors, and to improve navigation and page performance. Lawful basis: legitimate interest in maintaining an effective public-facing presence.
  • Measuring the effectiveness of advertising campaigns: Where you arrive at our site via a paid advertisement, we may record the source of the visit and aggregate conversion metrics to assess campaign performance. No individual profile is built without consent. Lawful basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)) for personalised measurement; legitimate interest for aggregated reporting.
  • Ensuring website security and preventing abuse: We monitor access logs to detect bot activity, brute-force attempts and other security threats. Lawful basis: legitimate interest in protecting our digital infrastructure and users.
  • Complying with legal and regulatory obligations: We may retain or disclose data where required by applicable law, a court order, or a competent regulatory authority. Lawful basis: legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).

We do not sell your personal data to any third party, nor do we use it for automated individual decision-making or profiling that produces legal or similarly significant effects.

Cookies & Tracking Technologies

Cookies are small text files placed on your device when you visit a website. They serve different purposes depending on their type. Below is an overview of the cookies we use and why.

4.1 Strictly Necessary Cookies

These cookies are required for the website to function. They enable core features such as page navigation, load balancing across servers, and security protections against cross-site request forgery. Because they are essential, they do not require your consent. Disabling them may mean that certain parts of the site do not work correctly.

4.2 Analytics & Performance Cookies

We use Google Analytics 4 (GA4) to collect aggregated data about how visitors interact with our website — including which pages are most visited, average session duration, and traffic sources. GA4 uses first-party cookies and, where applicable, behavioural modelling to respect user privacy choices. Data collected by GA4 is processed by Google on our behalf in accordance with Google's data processing terms. IP addresses are anonymised before storage. You may opt out of GA4 tracking by installing the Google Analytics Opt-out Browser Add-on or by adjusting your cookie preferences.

4.3 Advertising Cookies

If we run campaigns through Google Ads, a Google conversion tracking cookie may be placed on your device when you click one of our advertisements. This cookie expires after 30 days and does not collect personally identifiable information. It enables us to measure whether a click on our ad resulted in a visit to our website. The cookie is set only with your consent where such consent is required.

4.4 Managing Your Cookie Preferences

You can control cookies through your browser settings, allowing you to block or delete cookies at any time. Please note that blocking certain cookies may degrade your experience on our site. For detailed guidance on managing cookies in the most popular browsers, visit allaboutcookies.org. You can also use Google's Ads Settings to opt out of interest-based advertising.

Sharing With Third Parties

We do not sell, rent or trade your personal data. We share information only in the limited circumstances described below, and always subject to contractual safeguards that require third parties to protect your data with standards equivalent to our own.

  • Technology and hosting providers: Our website is hosted on infrastructure operated by third-party cloud or hosting providers. These providers may process certain technical data (such as server logs) in order to deliver the hosting service. They act as data processors on our behalf and are bound by data processing agreements.
  • Analytics service providers: As described in Section 4, we use Google Analytics to understand website traffic. Google processes data as a data processor under a signed Data Processing Addendum. GA4 data is retained within Google's infrastructure in accordance with Google's privacy and security standards.
  • Advertising partners: If you interact with an advertisement we have placed through Google Ads, Google may use cookies and conversion data as described in Section 4.3. Hydraware does not share your name, email address or any direct identifier with Google for advertising purposes.
  • Legal and regulatory authorities: We may disclose personal data to courts, law enforcement agencies, regulatory bodies or government authorities when required to do so by applicable law, or when disclosure is necessary to protect the rights, property or safety of Hydraware, our users, or the public.
  • Professional advisors: In the course of running our business, we may share information with legal counsel, auditors or accountants who are bound by professional confidentiality obligations.
  • Business transfers: In the event of a merger, acquisition, corporate restructuring or sale of all or part of our business, personal data may be transferred to the acquiring entity as part of that transaction, subject to confidentiality commitments and the continuation of equivalent privacy protections.

No personal data is transferred outside of Brazil or the European Economic Area unless an adequate level of protection is ensured through standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms recognised under the LGPD and the GDPR.

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our general retention guidelines are as follows:

  • Correspondence and contact records: Emails and enquiries received from potential or existing clients are retained for up to 5 years from the date of the last interaction, to support client relationships and to comply with applicable commercial and tax record-keeping requirements under Brazilian law.
  • Server and access logs: Technical server logs, including IP addresses and request metadata, are retained for 6 months for security monitoring purposes, after which they are automatically deleted or anonymised.
  • Analytics data: Aggregated Google Analytics data is retained according to our GA4 configuration, set to 14 months of user-level data, after which it is automatically expired. Aggregate, non-personal reporting may be retained indefinitely.
  • Advertising conversion data: Google Ads conversion data is retained for the period configured in our Google Ads account, typically 90 days, in line with standard campaign attribution windows.
  • Legal compliance records: Where we are required by law to retain records (such as tax documents, contract records or civil liability data), we retain such records for the periods prescribed by Brazilian law — generally between 5 and 10 years depending on the category.

Once data reaches the end of its retention period, it is securely deleted, anonymised, or archived in a form that no longer allows identification of the individual. If you would like specific information about how long your data will be retained, please contact us at [email protected].

Data Security

Hydraware takes the security of personal data seriously. We implement technical and organisational measures appropriate to the nature and sensitivity of the data we process, including the following:

  • Encrypted data in transit: All data transmitted between your browser and our servers is protected using TLS (Transport Layer Security), ensuring that communication cannot be intercepted in plain text.
  • Access controls: Access to personal data is restricted to employees and contractors who have a legitimate operational need. Access permissions are reviewed regularly and revoked upon changes in role or employment.
  • Vendor due diligence: We select third-party technology providers that demonstrate compliance with internationally recognised security standards, and we require contractual commitments regarding data security as part of our procurement process.
  • Regular security assessments: We periodically review our systems and procedures to identify and address potential vulnerabilities, in line with industry best practices for software development and web operations.
  • Incident response procedures: We maintain internal procedures for responding to personal data breaches. In the event of a breach that is likely to result in a risk to individuals' rights, we will notify the relevant supervisory authority (the Autoridade Nacional de Proteção de Dados — ANPD — in Brazil, or the applicable EU/UK authority) and affected individuals within the timeframes required by law.

Notwithstanding these measures, no method of electronic transmission or storage is completely infallible. We cannot guarantee absolute security, but we commit to responding promptly and responsibly to any incident that may affect the confidentiality, integrity or availability of your personal data.

Your Rights

Depending on your country of residence, you may have a number of rights regarding the personal data we hold about you. Under the LGPD (Art. 18) and the GDPR (Arts. 15–22), these include the following:

Right of Access

Request confirmation of whether we process your personal data and, if so, obtain a copy of that data together with details of how it is used.

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you, without undue delay.

Right to Erasure

Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or where processing was based on consent you have since withdrawn.

Right to Object

Object to the processing of your data where we rely on legitimate interest as our legal basis, including for direct marketing purposes (to the extent we engage in it).

Right to Data Portability

Receive a copy of the personal data you have provided to us in a structured, commonly used and machine-readable format, and transmit that data to another controller where technically feasible.

Right to Restriction

Request that we restrict the processing of your data in certain circumstances — for example, while you contest the accuracy of the data or while an objection is being assessed.

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint

File a complaint with the ANPD (Brazil) or your national data protection supervisory authority (EU/UK) if you believe your rights have not been respected.

How to Exercise Your Rights

To exercise any of the rights listed above, please send a written request by email to [email protected] with the subject line "Data Subject Request". Include your full name, a description of your request, and sufficient information for us to verify your identity. We will acknowledge receipt within 5 business days and respond substantively within 30 days (or within the period prescribed by the applicable law). In complex cases, we may extend this period by a further 30 days, informing you of the extension in advance.

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we reserve the right to charge a reasonable administrative fee or decline to act on the request, providing reasons for our decision.

Children's Privacy

Our website and services are directed exclusively at businesses and professionals operating in the water utility, sanitation and public infrastructure sectors. We do not knowingly market to, or collect personal data from, individuals under the age of 18.

If you are a parent or guardian and believe that a child under the age of 18 has provided us with personal information without appropriate consent, please contact us immediately at [email protected]. Upon verification, we will take prompt steps to delete that information from our records and, where applicable, to notify any third-party processors who may have received it.

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, the services we offer, applicable law, or guidance issued by supervisory authorities. When we make material changes — that is, changes that meaningfully affect your rights or how we process your data — we will update the "Last updated" date at the top of this page and, where appropriate, bring the changes to your attention through a notice on our website.

We encourage you to review this Policy each time you visit our website to remain informed about how we protect your data. Your continued use of the website following the posting of an updated Policy constitutes your acknowledgement of the changes. If you disagree with the revised terms, you should stop using the website and may contact us to request deletion of any personal data we hold about you, subject to our legal retention obligations.

Previous versions of this Policy are available upon request by contacting us at the details below.

Contact & Data Controller

Hydraware is the data controller responsible for the personal data described in this Policy. If you have questions, concerns or requests relating to this Policy or to the way we process your personal data, please use the contact details below. We are committed to working constructively with you to resolve any concerns and to demonstrating our accountability under applicable data protection law.

Data Controller

Legal name: HW DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS LTDA
CNPJ: 68.398.483/0001-68
Rua Doutor Arlindo Luz, 540, Sala 01, Centro, Ourinhos – SP, Brazil

We aim to respond to all privacy-related enquiries within 5 business days of receipt. For formal Data Subject Access Requests, our response window is 30 days from the date of a verified request, as set out in Section 8 of this Policy.