This website is a digital property managed, operated and optimized by TiMo Midia Ltda, registered with CNPJ under number 62.179.475/0001-44, with registered office at Rua Ana de Carvalho Silveira, nº 287, Bairro Silveira, Belo Horizonte/MG, CEP 31.140-440 (“TiMo Midia”).
Transparency is a fundamental pillar of our operation. This document describes how we collect, use and protect your personal data.
Laws and regulatory references considered (as applicable): LGPD and Marco Civil da Internet (Brazil), Ley 25.326 (Argentina), Ley 1581 (Colombia), LFPDPPP (Mexico), CCPA/CPRA and other state laws (USA), PIPEDA (Canada) and APPI (Japan), among others.
1. IDENTIFICATION OF CONTROLLER AND CONTACT
This website is a digital property managed, operated and optimized by:
TiMo Midia Ltda., registered with CNPJ under number 62.179.475/0001-44
Address: Rua Ana de Carvalho Silveira, nº 287, Bairro Silveira, Belo Horizonte/MG, CEP 31.140-440 (“TiMo Midia”).
Data Protection Officer/DPO (Privacy Channel): TiMo Midia Compliance Team
Email: [email protected]
2. WHO THIS POLICY APPLIES TO (SCOPE)
This Policy applies to the processing of personal data:
a) in the context of this domain (website) and the technologies used therein; and
b) when applicable, in the context of digital properties and advertising inventories operated/monetized by the TiMo Network.
It covers activities such as: security, measurement, fraud prevention and invalid traffic, performance improvement, delivery and verification of advertising (including programmatic) and user service.
This Policy may be supplemented by specific notices (e.g.: banner/cookie preference center). In case of conflict, the specific notice of the website/environment in which you are will prevail.
3. IMPORTANT DEFINITIONS
- Personal data: information that identifies or may identify a person, directly or indirectly.
- Sensitive personal data: data about racial/ethnic origin, health, biometrics, political opinion etc. (when applicable).
- Processing: any operation with data (collection, use, storage, sharing etc.).
- Cookies/similar technologies: cookies, pixels, web beacons, SDKs, tags and identifiers used for operation, measurement, security and advertising.
- Programmatic advertising: automated buying and selling of advertising inventory, using technology for delivery, measurement and control (e.g.: fraud prevention, frequency, reporting).
4. ROLES AND RESPONSIBILITIES (CONTROLLER/PROCESSOR/INDEPENDENT CONTROLLERS)
4.1. Role of TiMo Midia
TiMo Midia acts as a controller especially for purposes related to:
- operation and maintenance of the website;
- security and stability;
- fraud prevention and invalid traffic;
- measurement and aggregated reporting; and
- advertising monetization (when applicable).
4.2. Partners and vendors
Certain vendors and technology partners (including advertising and measurement providers) may act:
- as PROCESSORS (processing data on behalf of TiMo Midia); and/or
- as INDEPENDENT CONTROLLERS (processing data for their own purposes, in accordance with their policies).
Relevant example: Google and advertising/measurement services may process data in accordance with their own rules. For transparency about the Google ecosystem on partner sites, consult:
https://policies.google.com/technologies/partner-sites
5. WHAT DATA WE COLLECT
5.1. Automatic collection (logs and technical data)
For website operation, security, measurement and advertising, we automatically collect information such as:
- IP address;
- online identifiers and/or cookie identifiers (when applicable and according to your choice);
- browser type and version;
- internet service provider (ISP);
- date and time of access;
- referral and exit pages;
- information about clicks, events and navigation (e.g.: ad impressions, interactions, loading events);
- technical device information (e.g.: operating system, language, resolution, user agent);
- security and integrity indicators (e.g.: signals associated with fraud, bots, invalid traffic).
This data is used for system administration, security, fraud prevention and analysis/reporting (including aggregated). When possible, we seek to use data in aggregated form and/or with identification minimization.
5.2. Data provided by you
When you contact us, we may collect:
- name, email, telephone (if provided);
- message content and attachments sent;
- data necessary to validate your request (e.g.: proof of identity, when necessary).
5.3. Sensitive Data and Children/Adolescents
Our services are not directed to minors under 18 years of age and we do not intentionally collect personal data from minors. If we identify inadvertent collection, we will adopt reasonable measures for deletion.
We do not request sensitive data as a rule. If, by exception, such data is sent by you (e.g., in contact/communication), we process it only for the purpose of providing service and with applicable safeguards.
6. HOW WE USE DATA (PURPOSES)
We use personal data and navigation data for:
a) operating, maintaining and improving website functionality;
b) ensuring security, stability and technical integrity;
c) detecting, mitigating and preventing fraud, bots and invalid traffic;
d) measuring audience and performance (including through aggregated statistics);
e) delivering, measuring and optimizing advertising (including programmatic);
f) limiting ad frequency and improving relevance (when applicable and permitted);
g) responding to requests, support and communications;
h) complying with legal/regulatory obligations and safeguarding rights of TiMo Mídia and third parties.
7. LEGAL BASES (ACCORDING TO PURPOSE AND JURISDICTION)
Processing may occur on the basis of one or more legal grounds, as applicable:
- Consent (e.g., advertising/personalization cookies, when required);
- Compliance with legal or regulatory obligation;
- Contract execution/preliminary procedures (e.g., requested service);
- Regular exercise of rights (legal proceedings and protective measures);
- Legitimate interest (e.g., security, fraud prevention, service improvement, measurement), with balancing assessment and transparency measures.
Note: in certain jurisdictions, specific advertising practices and/or use of cookies/identifiers require prior, express and informed authorization. In such cases, we will operate with appropriate consent/opt-out mechanisms.
8. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies, pixels, tags and similar technologies for website functionality, measurement, security and advertising.
8.1. Cookie Categories
a) Necessary Cookies
Essential for functionality, security, stability and abuse prevention.
b) Performance/Measurement Cookies
Help understand how the website is used and improve performance, with statistics and reports (whenever possible, in aggregated form).
c) Advertising/Marketing Cookies
Used to deliver, measure and optimize ads, potentially involving advertising personalization when applicable and permitted.
8.2. How to Manage Preferences
- Banner/Preference Center: when available, you can accept, refuse or adjust categories.
- Browser/Device: you can block or delete cookies in your browser settings.
When disabling cookies, some functionalities may be affected and your experience may be degraded.
9. PROGRAMMATIC ADVERTISING, GOOGLE (AD MANAGER/ADX) AND CONSENT MODE
9.1. Google Ad Manager and Google AdX
TiMo Mídia uses ad technology platforms, including Google Ad Manager and Google Ad Exchange (AdX), and may operate as a partner in the Google ecosystem (e.g., MCM/AdX), as applicable.
9.2. Google Consent Mode (Consent Mode v2) and Consent Signals
When applicable, we use Google Consent Mode to adjust tag behavior according to your choice, including the signals:
- ad_storage (storage for advertising);
- analytics_storage (storage for measurement/analytics);
- ad_user_data (sending/use of user data for advertising purposes);
- ad_personalization (personalization of ads).
9.3. Operation with Consent Refusal and “Cookieless Pings”
If you refuse certain consents, tags may operate with restrictions (for example, without cookies for that purpose) and send only signals/pings with storage limitations. In such scenarios, certain providers may use data in aggregated form and/or statistical modeling for reports and measurement, without equivalent to full use of identifiers/cookies for personalized advertising.
9.4. Transparency Regarding Google Partners
For details on how Google may process data on partner sites, please consult:
https://policies.google.com/technologies/partner-sites
9.5. Cookies and Third-Party Technologies
Other advertising technology and measurement partners may use cookies/IDs on this site for:
- campaign measurement;
- ad verification;
- security and fraud prevention;
- reporting, frequency capping and (when applicable) personalization.
TiMo Mídia does not directly control third-party technologies, which may process data according to their own policies.
10. DATA SHARING (CATEGORIES OF RECIPIENTS)
We may share data, to the extent necessary and according to your choice/settings, with:
- hosting providers, infrastructure, security and technical support;
- measurement and analytics tools;
- advertising technology partners (AdTech), including ad management, delivery and verification platforms;
- fraud prevention and invalid traffic service providers;
- consulting and audit services (when necessary, with safeguards);
- public authorities and competent bodies, upon legal obligation, court order or valid request.
Important Note (USA/California and other jurisdictions):
The sharing of identifiers and browsing data with advertising partners may be interpreted as “sale” and/or “sharing” for behavioral advertising under certain local laws. Where applicable, we provide opt-out mechanisms through cookie preferences, browser settings and/or contact channel.
11. INTERNATIONAL DATA TRANSFER
Due to global operations and the use of technology providers and partners, data may be processed and stored outside the user’s country of residence.
Where applicable, we adopt safeguards for international transfers, including:
- transfer to countries/organizations with an adequate level of protection; and/or
- contractual clauses and mechanisms recognized under applicable standards (in Brazil, in accordance with ANPD regulations on international transfers and standard contractual clauses).
12. DATA RETENTION AND DELETION
We retain personal data and browsing records for the time necessary to:
- fulfill the purposes of this Policy;
- meet legal/regulatory obligations;
- enable audits and security analyses;
- prevent fraud and safeguard rights.
After the necessary period, data will be deleted or anonymized, when technically feasible and compatible with legal obligations.
Brazil (when applicable): we observe minimum record retention periods provided for in the Internet Civil Rights Framework and other applicable rules, especially for application access logs.
13. RIGHTS OF DATA SUBJECTS (PRIVACY) AND RESPONSE TIMEFRAMES
You may exercise your rights free of charge by emailing [email protected]. For your security, we may request additional information to verify your identity and validate your request.
Rights generally provided for (varying by jurisdiction): confirmation/processing, access, correction/rectification, anonymization/blocking/deletion, portability, objection, withdrawal of consent, information on sharing and review of automated decisions (when applicable).
13.1. Response timeframes by jurisdiction (operational reference)
- Brazil (LGPD): simplified format, when possible, immediately; and, upon clear and complete declaration, within 15 days from the request, observing trade/industrial secrets.
- Argentina (Ley 25.326): access within 10 business days; rectification/update/deletion within 5 business days (observing legal requirements). Free access may have a minimum interval of 6 months, unless legitimate interest exists.
- Colombia (Ley 1581): inquiries within 10 business days (extendable by up to 5 business days, with justification); claims within 15 business days (extendable by up to 8 business days, with justification).
- Mexico (LFPDPPP): decision within 20 days (from receipt); if granted, execution/implementation within 15 days after notification of the response (timeframes may vary according to applicable rules and exceptions).
- USA (CCPA/CPRA and state laws): generally, response within 45 calendar days for verified requests, with possibility of extension as permitted.
- Canada (PIPEDA): response within 30 calendar days, with possibility of extension in specific circumstances and notice to the data subject.
- Japan (APPI): response within a reasonable timeframe, in accordance with legal requirements, including rights of disclosure, correction and cessation of use when applicable.
Note: timeframes may vary depending on the nature and complexity of the request, need for verification, legal retention exceptions and exceptions provided for by law. We will always strive to respond within applicable legal timeframes.
14. USA – RIGHT TO OPT-OUT (“DO NOT SELL OR SHARE”) AND BEHAVIORAL ADVERTISING
Where applicable (e.g., California residents and other jurisdictions with specific rules), you may:
- opt out of allowing “sale/sharing” of data for behavioral advertising;
- limit the use/disclosure of sensitive information (when applicable);
- request access, correction and deletion as permitted.
You may exercise these rights:
a) through the cookie preference center/button (when available); and/or
b) by emailing [email protected].
15. DIGITAL ACCESSIBILITY (BRAZIL)
In compliance with Brazilian inclusion legislation and aiming for accessibility, we seek to maintain our interfaces aligned with international best practices and, when applicable, to ABNT NBR 17225:2025 and WCAG 2.2 AA guidelines.
Accessibility commitments (objectives):
- Keyboard navigation (without “focus traps”) and visible focus;
- Responsive design with preservation of content/function on small screens (e.g., 320px CSS);
- Use of appropriate semantics (headings, lists, tables) for assistive technologies.
16. INFORMATION SECURITY
We adopt reasonable technical and organizational measures to protect data against unauthorized access, destruction, loss, alteration, communication, or improper dissemination. We seek to align our controls with recognized best practices and, when applicable, with international security and privacy standards (e.g., ISO/IEC 27001 and 27701).
Despite our efforts, no environment is completely free from risks. Should we identify relevant incidents, we will adopt containment and communication measures as required by applicable legislation.
17. UPDATES TO THIS POLICY
This Policy may be updated at any time to reflect operational, regulatory, or technological changes. We recommend periodic review.
The “Last updated” date at the top of the document indicates when the most recent version became effective.
18. HOW TO CONTACT US
To exercise rights, clarify doubts, or submit requests:
Email: [email protected]
Address: Rua Ana de Carvalho Silveira, nº 287, Bairro Silveira, Belo Horizonte/MG, CEP 31.140-440, Brasil.