Instituto i10
Privacy Policy — i10 Insights
This policy describes how Instituto i10 ("i10", "we") collects, uses, and protects personal data when you sign up for the i10 Insights newsletter or browse institutoi10.com.br/insights. We follow Brazil's LGPD (Law 13.709/2018) as our baseline; the policy is also designed to be compatible with GDPR principles.
What we collect
- Email address — when you subscribe to the newsletter. The only required data point.
- Chosen language (PT or EN) — to send content in the right language.
- IP address and User-Agent at signup — kept solely as a consent audit trail, as required by LGPD.
- Version of consent text you saw at signup.
Legal basis
We process your data based on free, informed, and unambiguous consent (LGPD Art. 7, I), obtained via a double opt-in flow: after signup, we send a confirmation email. Without confirmation, your data does not enter our active list.
How we use it
- Send the daily i10 Insights newsletter in your chosen language.
- Maintain consent audit trail per legal obligation.
- Aggregate, anonymous metrics (open rate, clicks) to improve content. We do not profile individuals.
Sharing
Your data is not sold, rented, or transferred to third parties for commercial purposes. We use the following processors, strictly necessary to deliver the service:
- Resend (transactional email) — US-based, standard contractual clauses.
- Vercel (hosting) — US-based, standard contractual clauses.
- Neon (Postgres database) — US-based, standard contractual clauses.
Your rights (LGPD Art. 18)
At any time you may:
- Confirm whether we process your data.
- Access and request a copy of the data we hold about you.
- Correct incomplete, inaccurate, or outdated data.
- Request permanent deletion of your data.
- Revoke consent — click "unsubscribe" in any email we send.
- Request data portability to another provider.
Contact — Data Protection Officer
To exercise any right or ask about our data handling, write to dpo@institutoi10.com.br. We respond within 15 business days.
Retention
We keep your email while you remain subscribed. Upon unsubscribe, we remove the email from the active list within 24 hours. The consent audit trail (text version, date, IP/UA at signup) is retained for 5 years after unsubscribe, per ANPD guidance for legal-proof purposes.
Updates
Last updated: April 26, 2026. We will notify you by email if there is a material change to this policy.