Privacy Policy
This notice explains what personal data DufortService collects through this website, why, who else handles it, how long it is kept, and what you can ask us to do about it.
Who is responsible
Mauro Fiamma, working under the name DufortService, is the controller of the personal data collected through dufortservice.com.
Sorocaba (SP), Brazil
Email: [email protected]
Write to that address for anything in this notice, including any request about your own data. The studio works with clients in Brazil, in Europe and elsewhere.
Which law applies to you
Two sets of rules apply here, and which one you rely on depends on where you are.
If you are in the European Union or the European Economic Area, the EU General Data Protection Regulation (GDPR) applies to us, because we offer our services to people there — this is Article 3(2)(a) GDPR. This notice is written to meet Article 13 GDPR.
If you are in Brazil, the Lei Geral de Proteção de Dados (Law 13.709/2018, “LGPD”) applies, and this notice is written to meet it as well.
The two laws ask for much the same things, so what follows is true under both. Where they differ, the section on your rights says so.
What we collect, and why
When you send a project request
The contact form asks for your name and email address. Optionally, it asks for your phone number, the kind of work you are interested in, a description of your project, what you already have, what you would like to improve, your deadline and your budget range. You can also attach a file.
When the form is sent, we also record the date and time and the IP address the request came from.
We use this to read your request and reply with a proposal. The legal basis is Article 6(1)(b) GDPR: taking steps at your request before entering into a contract. The IP address is recorded to protect the form from abuse, which is our legitimate interest under Article 6(1)(f) GDPR.
Only your name, your email address and a description of the project are required. Without them we cannot reply. The optional fields simply help us understand the work before answering.
When you browse the site
Our hosting and security providers keep short technical logs — such as IP address, date and time, page requested and browser type — to keep the site running and to defend it from automated attacks. This is our legitimate interest under Article 6(1)(f) GDPR.
The interactive demos
The guided demos published on this site run entirely inside your browser. They use invented data, they send nothing to any server, and nothing you type into them is saved.
What we do not do
We use no analytics, no advertising and no tracking of any kind. We do not profile you and we take no automated decisions about you. We do not sell your data and we do not share it for anyone else’s marketing.
Cookies
This website sets no analytics or advertising cookies. One strictly necessary cookie, named __cf_bm, is set by Cloudflare, the service that protects the site from automated attacks. It expires within about half an hour and is not used to follow you across other websites.
Who else handles your data
We rely on a small number of service providers, which process data on our instructions:
- Kinsta — hosting of this website, where the site and your request are stored.
- Cloudflare — security and delivery of the site.
- Google (Gmail) — the mailbox that receives the notification of your request.
Your request is stored in this website’s own database, and a copy reaches our mailbox by email. Any file you attach is stored on the same hosting.
If you write to us from Europe
The studio is based in Brazil, so a request sent from the European Union reaches Brazil. On 26 January 2026 the European Commission decided that Brazil provides an adequate level of protection for personal data transferred from the EU to controllers subject to the LGPD. Your data therefore travels under that decision, and no further safeguard is required for it.
Some of the providers listed above may also process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards those providers publish, such as the European Commission’s standard contractual clauses.
How long we keep it
We keep project requests for 24 months from the day they reach us. After that the website deletes them by itself, together with any file attached to them — it is an automatic daily check, not something anyone has to remember to do.
If a request becomes a working relationship, the records of that work are kept for as long as the law requires business records to be kept, and they live in our accounting, not on this website. Technical logs are kept for a short period by the providers listed above.
Your rights
Whichever law applies to you, you can ask us to give you a copy of the data we hold about you, correct it if it is wrong, delete it, limit what we do with it, object to processing we base on legitimate interest, or hand your data to you in a portable format.
Under the GDPR these are Articles 15 to 22. Under the LGPD they are Article 18, which also lets you ask us to confirm whether we hold data about you at all, and to know with whom we have shared it.
Write to [email protected]. We answer within one month.
If you believe your data is being handled badly, you can also complain to a supervisory authority. In the European Union or the European Economic Area, that is the data protection authority of the country where you live or work. In Brazil, it is the Autoridade Nacional de Proteção de Dados (ANPD).
Changes to this notice
If we change how personal data is handled, this page is updated and the date below changes with it.
Last updated: 6 August 2026.