Introduction
OESP MIDIA E TRANSPORTES S.A (CNPJ 02.688.912/0001-23), headquartered at Avenida Professor Celestino Bourroul, 100, 4th Floor — Prédio Industrial, Limão, São Paulo-SP, Brazil ("we," "our," or "the Company"), operates the institutional website at which you are presently reading this document. We are a media and transport services company with a longstanding presence in the Brazilian market, committed to conducting our digital operations with transparency and respect for every visitor's privacy.
This Privacy Policy describes the types of information we may collect from you when you access this website; the purposes for which we collect and process that information; the legal bases we rely on under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13,709/2018) and, where applicable, the European Union's General Data Protection Regulation (GDPR — Regulation 2016/679); and the choices and rights available to you as a data subject.
By continuing to browse this website, you acknowledge that you have read and understood the practices described below. If you disagree with any aspect of this policy, please discontinue use of the site and contact us using the details provided in Section 11 so we may address your concerns directly.
This is a purely informational, institutional website. We do not operate an e-commerce platform, we do not process payments, and we do not administer user accounts. The scope of personal data processing described in this policy is accordingly limited — and intentionally so.
Information We Collect
We collect only the minimum amount of personal data necessary to operate this website effectively and respond to any business enquiries directed to us. The categories below describe what we collect, how, and why.
2.1 Information You Provide Directly
When you contact us — for example, by sending an email to [email protected] or by telephoning the numbers published on this site — you voluntarily provide us with personal information such as your name, email address, telephone number, the name of your organisation, and the substance of your enquiry. We collect only what you choose to share with us in that communication.
- Full name and job title (where provided in business correspondence)
- Email address and telephone number used to initiate contact
- Company or organisation name, where relevant to a commercial enquiry
- The content of any message, query or feedback you send us
2.2 Information Collected Automatically
When you visit our website, our servers and third-party analytics tools automatically collect certain technical and behavioural data. This data is used in aggregate to understand how visitors interact with our pages and to maintain the performance and security of the site. It may include:
- Internet Protocol (IP) address (collected in truncated or anonymised form wherever possible)
- Browser type, version and language preference
- Operating system and device type (desktop, tablet, mobile)
- The pages you visit, the sequence in which you visit them, and the time spent on each page
- The URL of the webpage that referred you to our site, and the URL you navigate to upon leaving
- Date, time and duration of your session
- Click-stream data and interaction patterns (scrolling depth, link clicks)
2.3 Cookies and Similar Technologies
We use cookies, pixel tags, and local storage to enhance site functionality and gather the analytics data described above. A detailed explanation of the specific cookies we deploy — and how to manage your preferences — is provided in Section 4 of this policy.
2.4 Data We Do Not Collect
We do not collect, and this site is not designed to collect, sensitive personal data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data, health information, or financial account details. We do not operate user accounts and therefore hold no login credentials for visitors.
How We Use Your Information
We process personal data only for specific, legitimate purposes and only to the extent necessary to accomplish each purpose. The table below outlines each processing activity alongside its legal basis under the LGPD and, where relevant, the corresponding GDPR basis.
3.1 Responding to Enquiries and Correspondence
When you reach out to us via email or telephone, we use the information you provide solely to understand and respond to your enquiry — whether it concerns our services, a commercial proposal, a press matter, or a request relating to your privacy rights. The legal basis for this processing is the legitimate interest of both parties in having that communication addressed (LGPD Art. 7, X; GDPR Art. 6(1)(f)), and, where a pre-contractual or contractual relationship is involved, the necessity to take steps at your request (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
3.2 Website Operation, Security and Performance
Technical data collected automatically is used to ensure the website loads correctly across different devices and browsers, to diagnose and resolve server errors, to detect and prevent fraudulent or abusive traffic, and to maintain the integrity and security of our web infrastructure. The legal basis is our legitimate interest in operating a secure and functional digital presence (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
3.3 Analytics and Website Improvement
Aggregated, pseudonymised analytics data allows us to understand which sections of the site are most useful to visitors, to identify navigation paths that may create confusion, and to prioritise improvements. We rely on legitimate interest as the basis for this processing, and we configure our analytics tools to minimise the identifiability of individual users wherever possible (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
3.4 Legal and Regulatory Compliance
We may process personal data when necessary to comply with a legal obligation applicable to us — for example, retaining commercial correspondence for the period required by Brazilian civil and tax law, or responding to lawful requests from courts, regulatory authorities, or law enforcement agencies (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
3.5 What We Do Not Do
We do not sell your personal data. We do not use personal data collected through this website to build individual profiles for targeted advertising. We do not make solely automated decisions (including profiling) that produce legal or similarly significant effects on individuals.
Cookies & Tracking Technologies
Cookies are small text files stored on your device by your browser when you visit a website. They allow the site to remember certain information about your visit, improving both functionality and the quality of data available to us for site improvement. We use three broad categories of cookies on this website.
| Category | Examples | Purpose | Duration |
|---|---|---|---|
| Session cookies, CSRF tokens, cookie-consent preference cookie | Required for basic site operation. Without these the site cannot function correctly. These are placed automatically and cannot be disabled. | Session or up to 12 months for preference storage | |
| Google Analytics 4 (_ga, _ga_*, _gid) | Collect anonymised data on how visitors use the site — pages visited, session duration, device type — allowing us to improve content and navigation. | Up to 24 months (_ga); 24 hours (_gid) | |
| Google Ads conversion cookie (_gcl_au), Google tag (gtag.js) | Measure the effectiveness of any advertising campaigns we run, attributing conversions to specific ad interactions. No personal profile is built for retargeting purposes on this site. | Up to 90 days |
4.1 Google Analytics
We use Google Analytics 4, a service provided by Google LLC (and, for users in the European Economic Area, by Google Ireland Limited). Google Analytics collects information about your use of this site and reports it back to us in aggregate, anonymised form. We have enabled IP anonymisation so that the final octet of your IP address is masked before any data is stored by Google. We do not use the User-ID feature or link Analytics data to any personally identifiable information we hold. For more information on how Google processes analytics data, see policies.google.com/privacy. You may opt out of Google Analytics tracking globally by installing the Google Analytics Opt-out Browser Add-on.
4.2 Google Ads
If you arrive at this website after clicking one of our advertisements served through Google Ads, a conversion cookie may be placed on your device to help us measure whether the ad resulted in a meaningful action — such as visiting a particular page. This cookie does not identify you personally and is not used to build a remarketing audience. Google's advertising policies and opt-out mechanisms can be found at adssettings.google.com.
4.3 Managing Your Cookie Preferences
You can control and delete cookies through your browser settings at any time. Most browsers allow you to refuse new cookies, delete existing cookies, or receive a warning before a cookie is stored. Please note that disabling analytics or advertising cookies will not diminish your ability to use this institutional site; however, it will limit our ability to understand how the site is being used and to measure the performance of any advertising we run.
Commonly used browser cookie controls can be found at: Chrome — chrome://settings/cookies; Firefox — about:preferences#privacy; Safari — Preferences › Privacy; Edge — edge://settings/content/cookies. Third-party opt-out tools are also available at aboutads.info/choices (DAA) and youronlinechoices.eu (EDAA).
Sharing With Third Parties
We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes. We share personal data only in the circumstances described below, and always subject to appropriate contractual safeguards.
5.1 Service Providers (Data Processors)
We engage a limited number of carefully selected third-party companies that process personal data on our behalf and under our documented instructions. These include:
- Web hosting and infrastructure provider — stores website files and serves pages to visitors. Access to logs containing IP addresses is strictly limited to support and security purposes.
- Google LLC — provides Google Analytics 4 and Google Ads measurement services. Data shared with Google is governed by Google's own privacy policy and the Data Processing Agreement we maintain with Google as a controller.
- Email service provider — routes correspondence sent to our published email addresses through secure mail infrastructure.
Each of these providers acts as a data processor and is contractually prohibited from using the personal data we share with them for any purpose other than the service they are contracted to deliver.
5.2 Legal Obligations and Protection of Rights
We may disclose personal data if we believe in good faith that such disclosure is necessary to comply with a legal obligation; to protect and defend the rights, property, or safety of OESP MIDIA E TRANSPORTES S.A, our employees, or members of the public; or to detect, prevent, or otherwise address fraud, security incidents, or technical problems.
5.3 Business Transfers
In the event of a merger, acquisition, corporate restructuring, or sale of all or a substantial portion of our assets, personal data held by us may be transferred to the acquiring entity. Should such a transaction occur, we will take reasonable steps to notify affected individuals and to ensure that any transferee agrees to process personal data in a manner consistent with this policy.
5.4 International Transfers
Some of our service providers — notably Google — operate infrastructure in countries outside Brazil. Where personal data is transferred internationally, we ensure that appropriate safeguards are in place, including standard contractual clauses recognised by the Brazilian National Data Protection Authority (ANPD) and/or the European Commission, or that the recipient country has been determined to provide an adequate level of data protection. Specifically, transfers to Google's services are governed by Google's standard contractual clauses and its status as a certified participant in recognised international transfer frameworks.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes described in this policy, or as required by applicable law. The following retention periods apply to the main categories of data we hold:
- Business correspondence and enquiry records — retained for five years from the date of last meaningful contact, in line with the general limitation period under the Brazilian Civil Code (Lei 10,406/2002, Art. 206). Where a commercial or contractual relationship arises from an enquiry, records may be retained for the full duration of the relationship plus five years thereafter.
- Web server access logs (including IP addresses and request data) — retained for a maximum of 12 months, in accordance with the minimum retention period required by Brazil's Marco Civil da Internet (Law 12,965/2014, Art. 13).
- Google Analytics data — session and event data is retained within Google Analytics for 14 months, after which it is automatically deleted at the property level. Aggregated reports derived from this data may be retained indefinitely as they do not contain personal information.
- Cookie-consent records — retained for a period not exceeding three years, to demonstrate compliance with applicable consent requirements.
When personal data is no longer required for the purposes for which it was collected and no legal obligation requires its further retention, we securely delete or anonymise it. Anonymised data — from which it is no longer possible to identify any individual — falls outside the scope of data protection law and may be retained and used indefinitely for statistical and business-improvement purposes.
Data Security
OESP MIDIA E TRANSPORTES S.A implements technical and organisational security measures commensurate with the risks presented by the personal data processing activities described in this policy. These measures are designed to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure, or unlawful access.
The specific safeguards we maintain include:
- Transport Layer Security (TLS/HTTPS) — all data transmitted between your browser and our web server is encrypted in transit using current TLS protocols, preventing interception by third parties.
- Access controls — access to systems holding personal data is restricted to authorised personnel on a need-to-know basis, and is protected by strong authentication requirements.
- Email security — our mail infrastructure employs SPF, DKIM, and DMARC protocols to reduce the risk of phishing and spoofing attacks targeting our domain.
- Regular security review — we periodically review the security of our website infrastructure, update software components promptly when security patches are released, and assess the security practices of any third-party processors we engage.
- Incident response — we maintain documented procedures for identifying, containing, and reporting security incidents. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the ANPD and, where required, affected data subjects within the legally mandated timeframes.
No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data using commercially reasonable means, we cannot guarantee absolute security. If you have reason to believe that your interaction with us has been compromised, please contact us immediately at [email protected].
Your Rights
Under the LGPD (Chapter III) and, where applicable, the GDPR (Chapter III), you have a number of rights with respect to the personal data we hold about you. We take these rights seriously and are committed to facilitating their exercise without unnecessary delay and at no cost to you. The rights available to you include:
You have the right to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data along with information about how it is processed. This is sometimes called a Subject Access Request (SAR).
If personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it. We will act on such requests promptly, and inform any processors who hold the data of the correction where feasible.
In certain circumstances — for example where we have relied on consent and you withdraw it, or where processing was unlawful — you may request that we erase personal data we hold about you. We will honour such requests unless retention is required by law.
You may object to our processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format so it can be transmitted to another controller.
You may request that we temporarily restrict our processing of your personal data in certain circumstances — for example, while the accuracy of data you have contested is being verified — rather than erasing it outright.
How to Exercise Your Rights
To exercise any of the rights described above, please send a written request to [email protected] with the subject line "Data Subject Rights Request." Please include your full name and sufficient detail to allow us to identify the personal data concerned. We will acknowledge your request within 48 business hours and provide a substantive response within 15 calendar days. Where the complexity or volume of your request requires additional time, we will notify you and explain the reason for the extension.
If you believe that we have failed to address your concerns adequately, or that our processing of your personal data infringes applicable law, you have the right to lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD, at www.gov.br/anpd). EU residents may also contact the data protection supervisory authority of the EU Member State in which they reside.
Children's Privacy
This website is directed exclusively at business professionals and adults making commercial or informational enquiries about OESP MIDIA E TRANSPORTES S.A's services. We do not knowingly collect personal data from individuals under the age of 18. Our site does not feature content designed to attract children, and we do not market any products or services to minors.
If you are a parent or guardian and become aware that a child under your care has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon verification, we will take prompt steps to delete the relevant data from our records and from any processors who may hold it on our behalf.
In the event that any future service requires the collection of data from individuals under 18, we will implement the additional parental consent mechanisms mandated by LGPD Article 14 and will update this policy accordingly in advance of any such activity.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, in the services we provide, or in applicable law. When we do so, we will revise the "Last updated" date displayed prominently at the top of this page. Where changes are material — meaning they significantly affect your rights or the way in which we process your personal data — we will take reasonable steps to bring them to your attention, which may include displaying a notice on the homepage or other prominent location on the site.
We encourage you to review this policy periodically. Your continued use of this website following the posting of any revised version constitutes acknowledgment of the updated terms. If any change reduces your rights or increases our ability to use your data in ways you find objectionable, please contact us and we will discuss your concerns before you decide whether to continue using the site.
Previous versions of this policy can be made available upon written request to [email protected], subject to reasonable time and administrative constraints.
The most material change from previous versions of this policy relates to the adoption of Google Analytics 4 and the associated updates to the cookies table in Section 4. We have also expanded Section 8 (Your Rights) to more clearly describe how data subjects may exercise rights under both the LGPD and, where relevant, the GDPR.
Contact & Data Protection Officer
OESP MIDIA E TRANSPORTES S.A is the controller of the personal data processed in connection with this website. If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to raise a concern about how we handle your personal data, please contact us using any of the details below.
OESP MIDIA E TRANSPORTES S.A — Data & Privacy Contact
Under the LGPD (Art. 41), controllers are required to appoint a Data Protection Officer (Encarregado de Proteção de Dados). Our designated officer can be reached through the email address above; please mark the subject line of your message with "DPO — Encarregado" to ensure it is routed correctly. The identity and contact details of our officer have been registered with the ANPD in accordance with applicable guidelines.
We value your trust and will treat every privacy enquiry with the diligence and confidentiality it deserves. Should you remain unsatisfied after engaging with us directly, you retain the right — described in full in Section 8 — to escalate your complaint to the ANPD or the relevant EU supervisory authority without any restriction or penalty.