INSTITUTIONAL INFORMATION
Privacy Policy
Processing of personal data on iN2's corporate website and exercise of rights in accordance with applicable law.
Last updated: 10/03/2026
Responsible and scope
The data controller for this institutional website is iN2, LLC, located at 7345 W Sand Lake RD, STE 210 Office 4761, Orlando, FL 32819, United States. Contact: support@in2.dev.
This policy covers in2.com.br and its language versions that present this document, the searching and reading of articles, and institutional contacts via email and WhatsApp. Personal data are information that identifies or may identify a person, including certain technical identifiers associated with browsing.
The processing of data in the Smartbis, WPP Marketing and Whatsplaid services is described in each platform's own documentation. If your request relates to one of these services, also consult the respective privacy policy.
Data and purposes
Requests to the server and to resource providers may involve IP address, date and time, requested pages, and technical information about the browser. Technical logs may be used for content delivery, failure diagnosis, and environment protection.
We also record the device, language, source of the visit and the received reference and campaign parameters. We use this information to understand accesses and distinguish visits by people from visits by bots. Approximate location can be estimated from the IP address; it does not correspond to the device's precise location.
The term searched on the blog is part of the URL and may appear in history, technical logs, and shared links. Do not enter passwords, documents, or sensitive data in the search field.
When contacting us, you provide your email and the information included in the message, intended for handling and recording your resolution. Provide only information necessary to the matter.
In WhatsApp support, your phone number, name or display name on the channel, message content and information necessary to respond to the request may be processed. Support may use artificial intelligence agents in different languages to interpret messages and formulate responses. Do not send passwords, financial data or unnecessary sensitive information.
The current version of the site does not offer visitor registration, comments, payment, or newsletter subscription. We may suggest a language based on the country estimated from the IP address. The selection is made by navigating between domains; accepting, declining, or closing the suggestion, or choosing a language in the selector, saves the preference in the cookie in2_lang_pref for 180 days, shared across iN2 subdomains. We do not request precise geolocation, identity documents, or financial data to read pages.
Legal basis and consent
Delivery of pages, content search and technical diagnostics: processing limited to site operation and security may rely on legitimate interest when that basis is accepted and the interests do not override the rights and freedoms of the visitor. The interest is to make requested content available and maintain a trustworthy environment; it is not authorization for unrestricted behavioral monitoring.
Service: a request related to a potential hiring may involve pre-contractual measures taken at your request. Questions and editorial corrections may involve legitimate interest in responding. Requests for rights and compliance with legally enforceable orders may be based on legal obligation; preservation necessary for the defense of rights uses the legal basis provided for that purpose in applicable law.
When processing depends on consent, that consent must be specific and may be withdrawn. Reading this policy or browsing the site does not constitute unrestricted authorization for new uses of data.
The legal basis is assessed per operation: we do not apply consent or legitimate interest indiscriminately to all data. When local law requires another requirement, including specific authorization, it must be observed. Refusal to provide optional data does not prevent viewing public content; the absence of information essential to a contact may prevent its resolution.
Recipients and external links
The hosting, storage and email infrastructure uses Amazon Web Services (AWS). Incoming messages are analyzed by iN2's internal team. The services involved may process the information necessary for page delivery, storage and communication.
Google Analytics (Google) receives technical information and browsing events for audience measurement. The page address provided by the integration uses the domain and path, without the search parameters. Google processes this information on its infrastructure, which may involve other countries, in accordance with its terms of service and privacy policies.
WhatsApp support involves the channel infrastructure and the AI resources used to process the conversation. These environments are distinct from simply reading the website. Processing a message to formulate a response does not, by itself, constitute authorization to use its content for training models.
Google Fonts (Google) provides fonts from the domains fonts.googleapis.com and fonts.gstatic.com; cdnjs (Cloudflare) delivers icon files; Amazon CloudFront (AWS), via the domain d2d1osjvfgxt39.cloudfront.net, delivers blog images. The browser connects to these services to request resources, transmitting IP, technical request characteristics and origin information according to the browser's policy. Sending a message to iN2 is not required for these requests to occur.
External resource providers also present information about data processing in their own policies. Access to sources, icons, or images does not require sending the content of your service messages to these providers.
To estimate the approximate location, the server may query FreeIPAPI and, if necessary, IPWho.is, sending the visitor's IP address. We do not send the content of support messages to these services.
Information may be made available to comply with a valid legal obligation or to defend rights, subject to an assessment of necessity and proportionality. If a corporate change involves data, the obligations of protection and transparency remain applicable; it does not, by itself, authorize new incompatible purposes.
External links lead to environments with their own policies. The parameter ref=iN2 indicates the institutional origin of the link, without by itself adding a personal identifier; the destination may process other visit data.
International transfers
The data controller is established in the United States. iN2 uses AWS infrastructure in Brazil, the United States, and Germany for data processing and storage, according to the operation and configuration of the services. This does not mean that every piece of data is necessarily replicated in all three countries or stored exclusively in the data subject's country of residence.
External resources such as fonts, icons, images, and communication also use the providers' own infrastructure. The location of these flows may differ from the AWS regions used by iN2; the delivery endpoint of a resource does not, by itself, determine where its records are stored.
A transfer subject to legal restrictions requires a valid mechanism in addition to the legal basis for processing. Depending on the jurisdiction, adequacy, approved contractual clauses, or another specific legal basis may be relevant. In Brazil, the LGPD and ANPD regulations apply; in the EEA and the United Kingdom, the respective transfer regimes apply. Merely reading the policy does not authorize a transfer that depends on specific consent.
You may request from the data controller information about destination countries, recipients, and safeguards applicable to the processing of your data.
Retention and security
The standard retention period for personal data covered by this policy is one year, including support conversations, access logs and backups. Data may be deleted earlier when no longer necessary or when a valid deletion request so requires.
A specific legal obligation, determination by an authority, or a justified need to defend rights may require retention for a different period. In such situations, retention is limited to the data and period necessary, and does not authorize new incompatible purposes.
Deletion takes into account active systems and backups, respecting retention periods and legal exceptions. Backups may remain until they are deleted within those periods, and will not be used for new purposes incompatible with the request.
The site uses HTTPS connection and protective measures against unauthorized queries and malicious content. No digital environment is free of risks. Suspected unauthorized access can be reported to support@in2.dev or to the data protection officer.
In the event of an incident, the data involved, possible consequences, containment and communication obligations must be assessed. When required by law, the authority and affected individuals will be informed within the applicable timeframes and conditions, without conditioning that communication on the filing of an individual complaint.
Rights and requests
Under applicable law, you may request information, access, rectification, deletion, restriction, portability, or objection and withdraw consent. Some rights depend on the legal basis, the circumstances, and legal exceptions.
Send your request to support@in2.dev or lgpd@josuegarcia.com.br. Specify the right you wish to exercise, the website or service involved, and the email or context needed to locate your data. You do not need to open an account, purchase a service, or use legal terminology to make a request.
Identity verification should be proportionate to the risk of disclosing or altering third-party information. Do not send identification documents proactively; if they are indispensable, their necessity and the appropriate means will be explained. Representatives may need to demonstrate authorization, in accordance with applicable law.
The exercise of rights is free of charge as a rule, except for justified legal exceptions. If the request cannot be fully fulfilled, the response must state the reasons and the available means of contestation. A request concerning data under the responsibility of a client company of a platform may need to be forwarded to that company, with appropriate assistance from iN2.
The response must comply with the applicable legal deadline. Brazil: confirmation and access may be provided immediately in a simplified format or through a full statement within up to 15 days, under the terms of the LGPD. EEA: the rule is one month, with a possible extension of up to two additional months under the conditions of the GDPR and with notice to the data subject. United Kingdom: observe the deadline and counting rules of the UK GDPR. California: verifiable requests for access, deletion, or correction under the CCPA are generally subject to a 45-calendar-day period, with a justified legal extension. These rules do not create a single deadline for all countries and rights.
Contacting iN2 does not prevent complaints to the competent authority or other legal remedies. We do not discriminate against the legitimate exercise of rights. Processing necessary for verification and response will not be used as authorization for marketing.
Brazil — LGPD
When applicable Law No. 13.709/2018, the rights include confirmation, access, correction, anonymization, blocking, deletion in the cases provided by law, portability, information about sharing and consent and its revocation. A request for review of solely automated decisions may also be made under the terms of the law and a petition may be submitted to the ANPD.
European Economic Area and United Kingdom
When the GDPR or UK GDPR applies, rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent may be exercised, subject to their conditions. Safeguards regarding solely automated decisions and the right to lodge a complaint with the competent supervisory authority, including the ICO in the United Kingdom, remain in place.
United States — state rights
State laws depend on their enforcement criteria, not only on iN2’s location. When CCPA, as amended by the CPRA, applies, California residents may exercise rights of notice, access, correction, deletion, limitation of certain uses of sensitive data, and opt out of sale or sharing, without discrimination. Authorized agents may submit requests in accordance with legal requirements.
The integration of this site does not configure advertising pixels or behavioral advertising campaigns. You may request clarifications about data sharing and exercise the rights of objection provided for in applicable law.
Other state laws may provide access, correction, deletion, portability, objection to specific uses, and appeal against the denial of a request. The request may be submitted through the channels indicated, including to contest a prior response.
Switzerland, Canada and Australia
Switzerland: when the Swiss Federal Data Protection Act applies, requests may be made regarding processing, rectification, erasure and other rights under the legal conditions, as well as communication to the FDPIC. Portability and safeguards related to automated decisions depend on the scenarios provided for in the legislation.
Canada: when PIPEDA or relevant provincial legislation applies, requests may be made for access, correction and explanations regarding use and disclosure, as well as challenges to practices and withdrawal of consent under the legal conditions. The general access timeframe under PIPEDA is 30 days, subject to permitted extensions. The competent authority may be federal or provincial.
Australia: where the Privacy Act and the Australian Privacy Principles apply, access and correction may be requested and a complaint about handling practices may be made, including to the OAIC. International data transfers must take into account obligations applicable to overseas recipients.
Mexico and other countries in Latin America
Mexico: when applicable under the LFPDPPP, rights of access, rectification, cancellation and opposition (ARCO) may be exercised, as well as the legal options of revocation of consent and limitation of use or disclosure.
Colombia: when applicable under Ley 1581 de 2012, the rights include access, updating, rectification, proof of authorization, information about use, access, and revocation or suppression in legal cases.
Argentina: when Ley 25.326 applies, rights of access, rectification, updating and deletion may be exercised. Uruguay: Ley 18.331 ensures access, rectification, updating, inclusion and deletion, according to its terms.
Chile: when Law 19.628 applies, you may exercise the rights of information, access, correction and deletion under the legal conditions. Additional rights arising from legislative changes after their entry into force and access to the competent authorities remain preserved.
Automated recommendations and decisions
The home page displays recent articles and the reading suggests other articles by category and publication date, without creating an individual reader profile for these recommendations. The search returns content according to the term you provide.
These editorial features do not constitute an exclusively automated decision intended to produce legal effects or similar impact on the visitor. AI features of the platforms are separate and subject to their own documentation. Publishing content about artificial intelligence does not authorize the use of its messages for model training.
Institutional service via WhatsApp may use AI to serve people from different countries and languages. Automated responses may contain errors and should be verified before making relevant decisions. You may request clarifications or a review of a response through institutional channels. These features do not remove your rights over data nor replace the data protection officer in privacy requests.
Minors and other regions
The website contains institutional content aimed at business activities. Do not send data of children or adolescents unless necessary and with an appropriate basis. If you identify improper processing, contact the data protection officer. If you are in a region not mentioned in this policy, you may exercise the rights afforded by applicable law through the same contact channels.
Contact and data controller
Institutional contact: support@in2.dev. Data protection officer: Josué Felipe Garcia. Data protection officer email: lgpd@josuegarcia.com.br.
For correspondence to the responsible party, use the iN2, LLC address provided above. Indicate the website or service involved and describe the request, avoiding unnecessary sensitive data.
Policy updates
The update date appears at the top of this page. Relevant changes will be communicated when required by law. If a new purpose depends on your consent, it will be requested separately; the publication of a new policy does not replace that choice. Mandatory warranties under applicable law prevail over provisions of this document that are incompatible.