1. Commitment to Privacy
Data privacy, confidentiality, and technical information security are fundamental values across my professional work. This Privacy Policy clearly outlines how personal data is collected, processed, protected, and retained when you browse perciocastelo.com.br and its integrated technical utilities.
All data processing activities strictly adhere to the principles of purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, and non-discrimination, as mandated by Article 6 of the Brazilian General Data Protection Law (LGPD) and the European GDPR.
2. Data Controller Information
For the purposes of data protection regulations, the Data Controller responsible for decisions concerning your personal data is:
- Individual / Controller: Percio Castelo (sr00t3d)
- Profession: Linux Infrastructure Consultant, SysAdmin & DevSecOps Engineer
- Official Privacy & DPO Contact: [email protected]
- Location: Federative Republic of Brazil
3. Data Collection, Purpose & Lawful Bases
I operate under a strict data minimization philosophy: only data strictly necessary for secure website functionality and user-requested interactions is gathered. The breakdown below outlines our processing activities:
| Feature / Module | Data Collected | Specific Purpose | Lawful Basis (LGPD / GDPR) |
|---|---|---|---|
Contact Form (sendmail.php) |
Name, email address, optional phone number, optional website URL, and your message description. | Responding to user inquiries, technical questions, project scoping, and preliminary consulting discussions. | Steps prior to entering into a contract at the request of the data subject (LGPD Art. 7, V / GDPR Art. 6(1)(b)) and Consent (LGPD Art. 7, I). |
Blog Comments (blog-comments.php) |
Display name, email address (optional), and comment message. | Facilitating community technical discussions on published articles. Email addresses are hashed via a one-way MD5 algorithm to query public profile avatars on Gravatar (Automattic Inc.) and are never displayed publicly. | Consent upon submitting a comment (LGPD Art. 7, I / GDPR Art. 6(1)(a)) and Legitimate Interest in technical exchange (LGPD Art. 7, IX). |
Voluntary Donations (doar.html / Stripe) |
Donation amount, currency, and payment card details. | Processing voluntary financial contributions. This website does not store credit card numbers, CVVs, or bank credentials: checkout is executed directly by Stripe Inc.'s PCI-DSS Level 1 infrastructure. IP addresses are temporarily recorded in local SHA-256 hashed files for anti-fraud rate limiting (10 requests/min, expiring in 10 minutes). | Execution of voluntary donation and Legitimate Interest in fraud prevention and security (LGPD Art. 7, IX & Art. 11, II, "g" / GDPR Art. 6(1)(f)). |
| Anti-Bot Security (Cloudflare Turnstile) | Interaction telemetry, HTTP headers, and non-intrusive browser cryptographic challenges. | Defending the portal against automated spam bots, distributed denial-of-service (DDoS) attacks, and credential stuffing, without invasive third-party ad tracking. | Legitimate interest in ensuring network security and service availability (LGPD Art. 7, IX / GDPR Art. 6(1)(f)). |
Audience Metrics (Google Analytics / tracking.js) |
Pseudonymous device identifiers, pages viewed, session duration, browser family, and client-side click events (data-track). |
Understanding which technical articles are most helpful, identifying broken links, and improving UX navigation. Operates with IP anonymization enabled. | Legitimate Interest in improving technical content and user experience (LGPD Art. 7, IX / GDPR Art. 6(1)(f)). |
4. Cookie Policy & Local Storage (HTML5 localStorage)
Cookies are small text files placed on your browser to record settings or session tokens. I maintain a minimal cookie footprint:
-
Strictly Necessary Technical Cookies: A transient session cookie (
PHPSESSID) is generated solely when interacting with the contact form modal to ensure request authenticity and prevent duplicate submissions. This cookie expires immediately once you close your browser. -
Performance & Analytics Cookies: Google Analytics 4 cookies (
_ga,_ga_*) are utilized to measure overall site traffic in an aggregated and pseudonymous manner. -
HTML5 Local Storage (localStorage):
site_lang_pref_v1: remembers your language choice (pt-BRoren) across page visits so the site preserves your reading preference.sr00t3d_tracking_events: a local circular buffer (capped at 300 entries) in your browser that tracks navigation engagement without sending raw event logs to external tracking databases.
Managing Cookies: You can configure your browser to block or alert you about cookies at any time through your browser's privacy settings (Google Chrome, Mozilla Firefox, Microsoft Edge, or Apple Safari). Please note that disabling essential cookies may impact the interactivity of the contact form.
5. Third-Party Data Sharing
I do not sell, rent, trade, or monetize your personal data with third-party data brokers or targeted ad networks under any circumstance.
Data is shared strictly with essential infrastructure service providers necessary to operate this site, under robust data processing agreements:
- Cloudflare, Inc.: Global CDN perimeter security, TLS termination, and Turnstile anti-bot verification;
- Stripe, Inc.: Payment processing and secure card tokenization for voluntary donations;
- Zoho Corporation: Secure SMTP transactional email relaying with TLS encryption;
- Automattic Inc. (Gravatar): Querying public user avatars based on one-way email hashes for approved blog comments;
- Google LLC: Aggregate, anonymized traffic measurement through Google Analytics 4;
- Legal & Judicial Authorities: Strictly when compelled by a valid court order or statutory requirement under applicable Brazilian law.
6. International Data Transfers
Because our infrastructure partners (including Cloudflare, Stripe, and Google) maintain globally distributed networks, certain operational data may be processed on servers located in the United States or the European Union.
In such cases, international transfers comply with Article 33 of the LGPD and Chapter V of the GDPR, relying on Standard Contractual Clauses (SCCs) and rigorous security certifications providing protection equivalent to Brazilian and European standards.
7. Technical Security Safeguards
As an active DevSecOps and Blue Team security practitioner, I enforce comprehensive technical and operational safeguards:
- Encryption in Transit: Mandatory HTTPS enforced through modern TLS 1.3 ciphers and HTTP Strict Transport Security (HSTS);
- Hardened Content Security Policy (CSP): Strict directives configured in Nginx to block unauthorized script execution and prevent Cross-Site Scripting (XSS);
- Defensive HTTP Headers: Active security headers across all endpoints (
X-Content-Type-Options: nosniff,X-Frame-Options: SAMEORIGIN,Referrer-Policy: strict-origin-when-cross-origin); - Database Isolation: The SQLite comment database is kept in a protected directory outside direct public reach, accessed exclusively through PDO prepared statements with strict parameter binding to eliminate SQL injection vulnerabilities;
- Backend Rate Limiting: Native PHP mechanisms enforce rate limits on sensitive endpoints to prevent brute-force attacks and abuse.
8. Data Retention & Deletion Schedule
Personal data is retained only for the duration necessary to satisfy the purpose for which it was gathered:
- Contact Messages: Retained in a secure inbox for as long as necessary to address your technical inquiry or maintain a business conversation, and deleted periodically thereafter;
- Blog Comments: Maintained publicly alongside the article as part of the technical dialogue, and permanently removed upon request from the commenter;
- Transaction & Rate-Limiting Logs: Temporary hashed IP logs for Stripe transactions are automatically purged after 10 minutes;
- Server Access Logs: Retained under strict confidentiality for 6 months to comply with Article 15 of the Brazilian Civil Rights Framework for the Internet.
9. Your Rights as a Data Subject
Under the LGPD (Article 18) and GDPR (Articles 15 through 22), you hold enforceable rights regarding your personal information, accessible free of charge at any time:
- Confirmation & Access: Confirm whether your data is being processed and request a copy of it;
- Rectification: Request the correction of incomplete, inaccurate, or outdated data;
- Anonymization, Blocking, or Erasure: Request the removal or anonymization of unnecessary, excessive, or unlawfully processed data;
- Revocation of Consent: Withdraw your consent at any time for activities based on consent (such as blog comments);
- Information on Sharing: Inquire about any public or private entities with whom data has been shared.
10. Data Protection Officer (DPO) & Contact Channel
To exercise your rights under this Privacy Policy or applicable data protection regulations, or to submit questions about how your information is handled, contact the Data Protection Officer directly:
Data Protection Officer (DPO)
Name: Percio Castelo
Direct Privacy Inquiries: [email protected]
Online Form: Privacy Contact Form
Legitimate requests will be processed promptly and responded to within the statutory timeframe of 15 days in accordance with ANPD guidance.
11. Policy Revisions
This Privacy Policy may be updated periodically to reflect evolving legal standards or technical changes to the site. The "Last Updated" date at the top of this document indicates when revisions take effect.