Struckel
  • About Struckel
  • Capabilities
    • Strategy & Management
    • Finance & Performance
    • Operational Excellence — Six Sigma
    • Technology & Digital
    • RADIAL — Marketing & Communication
  • Method
  • Insights
  • RADIAL
  • EN
    • PT
    • EN
    • ES
    • FR
  • Talk to us
STRUCKEL / LEGAL
01
PUBLIC DOCUMENT

Privacy and Data Protection Policy

How Struckel Consulting handles personal data on the website, in business enquiries and in interactions related to its services.

Last updatedAugust 16, 2026
Index
1Purpose and scope 2Who controls the data 3Data we may process 4Why we use data 5Legal grounds 6Sharing and service providers 7International transfers 8Retention and deletion 9Information security 10Your rights 11Children and teenagers 12Changes to this Policy
Identification
Struckel Consultoria

CNPJ 54.252.977/0001-25
Brasil

Privacy / data protectiondpo@struckel.com.br
Security / incidentsnoc@struckel.com.br
Contatocontato@struckel.com.br
1

Purpose and scope

This Policy describes the privacy practices for struckel.com.br and the electronic forms maintained by Struckel Consulting, Brazilian registration CNPJ 54.252.977/0001-25. It applies when a person visits the website, requests contact, asks for information or shows interest in consulting, training, projects or other Struckel solutions.

Specific proposals, contracts and projects may contain additional confidentiality and data protection provisions. Those provisions complement this Policy when applicable.

2

Who controls the data

For the processing described here, Struckel Consulting acts as controller when it determines the essential purposes and means of processing.

  • Identification: Struckel Consulting — CNPJ 54.252.977/0001-25.
  • Institutional and documentation contact: contato@struckel.com.br.
  • Privacy and data-subject requests: dpo@struckel.com.br.
  • Security and incident reports: noc@struckel.com.br.
3

Data we may process

Information you provide

  • Name, business e-mail, phone or WhatsApp, company, role and location.
  • Company registration or tax ID when provided to facilitate preparation of a proposal.
  • Industry, area of interest, desired timing, business context, challenge and other information voluntarily submitted in forms.
  • Messages and subsequent communications through corporate channels.

Technical and security information

  • IP address, request date/time, basic browser/device information and technical logs needed for operation and security.
  • Session identifiers and CSRF protection tokens used to secure forms.
  • Campaign/origin parameters (UTM) when they are present in the URL.
  • Anti-abuse verification signals when Cloudflare Turnstile is enabled.

Public forms do not request passwords, banking credentials, card data or complete personal documents. Please do not submit sensitive personal data or confidential information that is not necessary for an initial enquiry.

4

Why we use data

  • Respond to enquiries and understand the stated need.
  • Prepare initial assessment, lead qualification, proposal, quotation or routing to the appropriate team.
  • Take steps requested before a potential contract and continue commercial discussions.
  • Manage commercial or contractual relationships when applicable.
  • Protect the website and prevent abuse, fraud, spam and security incidents.
  • Maintain records needed for governance, audit, legal compliance and the establishment, exercise or defence of rights.
  • Improve website experience, content and performance using strictly necessary or properly authorised technical information.
5

Legal grounds

Depending on the context, processing may rely on steps requested before entering into a contract, performance of a contract, legitimate interests, compliance with legal obligations, exercise of legal rights and consent when consent is the appropriate basis.

Where consent is used, it may be withdrawn subject to applicable law without affecting previous lawful processing or retention supported by another lawful basis.

6

Sharing and service providers

Struckel limits sharing to what is needed to operate the website, communicate with interested parties, secure the infrastructure and deliver requested services. Providers may act as processors or independent controllers depending on the activity.

  • Hosting, infrastructure, security, DNS and anti-abuse providers.
  • Google Workspace, used for Struckel corporate e-mail infrastructure.
  • Cloudflare when security or Turnstile features are enabled.
  • Technical providers required to deliver libraries, fonts or website components.
  • Professional advisers, partners or suppliers involved in a proposal or project when necessary and compatible with the stated purpose.
  • Public authorities or third parties when required by law, valid order or the exercise of legal rights.

Struckel does not sell personal data to advertisers.

7

International transfers

Some technology and communication providers may process data in infrastructure located outside Brazil. Where international transfers occur, Struckel seeks to use providers and safeguards compatible with applicable data protection rules.

8

Retention and deletion

Data is kept for as long as needed for the purpose for which it was collected, ongoing negotiations or contracts, legal and regulatory duties, security, fraud prevention and the exercise of legal rights. When no longer required, information may be deleted, anonymised or retained where the law permits or requires.

9

Information security

Struckel applies technical and administrative measures appropriate to the website context, including HTTPS when correctly deployed, server-side validation, CSRF protection, honeypot, rate limiting, server-side e-mail credentials and optional Cloudflare Turnstile anti-abuse verification.

No environment is completely risk-free. Suspected vulnerabilities, exposure or incidents involving personal data may be reported to noc@struckel.com.br.

10

Your rights

Individuals may exercise rights available under applicable data protection law, including confirmation of processing, access, correction, information on sharing, deletion or restriction where appropriate, portability subject to regulation, objection, review of automated decisions when applicable and other statutory rights.

Requests may be sent to dpo@struckel.com.br. To protect the requester, Struckel may reasonably verify identity and authority before fulfilling a request.

11

Children and teenagers

The institutional website and commercial forms are not specifically directed to children. If processing involving children or teenagers is identified in a context requiring special protection, applicable legal safeguards will be observed.

12

Changes to this Policy

This Policy may be updated when the website, services, providers, data flows or applicable rules change. The current version is identified by the update date shown on this page.

Responsible channels

Direct channels for privacy and security.

Privacy / data protectiondpo@struckel.com.brSecurity / incidentsnoc@struckel.com.br
Struckel

Strategy, management and business transformation. From understanding the problem to implementing change.

Navigation
About Struckel Capabilities Method Insights
Ecosystem
RADIAL Technology & Digital Operational Excellence — Six Sigma
Contact
contato@struckel.com.br 19 98158-4033 Talk to us
Legal
Privacy & Data Protection Cookies Terms of Use
© 2026 Struckel Consulting. All rights reserved.
Strategy to transform. Management to execute.