Skip to content
Smart Social
Solutions Cases Playbook Blog About Contact
EN Talk to us
Solutions Cases Playbook Blog About Contact Ler em português Talk to us

Legal · LGPD and GDPR

Privacy Policy

Last updated: 29 July 2026

Smart Social operates across 25+ countries and works with partners and clients based in the European Union. This policy covers both the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the EU General Data Protection Regulation (GDPR, Regulation 2016/679). Where the two differ, we apply the standard that gives you more protection.

1. Who controls your data

The controller of the personal data described in this policy is SMART SOCIAL NEGOCIOS DIGITAIS LTDA, a limited company registered in Brazil under CNPJ 31.626.665/0001-39, with its registered office at Rua Visconde de Pirajá 414, room 718, Ipanema, Rio de Janeiro, RJ, 22410-905, Brazil. Being the controller means we decide why and how your data is processed.

Smart Social has appointed a Data Protection Officer (Encarregado, under art. 41 of the LGPD): Luiz Felippe Correia de Almeida. The Encarregado is the person in charge of handling requests from data subjects and communications from supervisory authorities. To ask a question about this policy, exercise your rights, or reach the person responsible for data protection, write to dpo@smt.social.

2. What this policy covers

This policy applies to the personal data we collect through this website, through our commercial channels (email, Telegram, WhatsApp, LinkedIn and Instagram) and in the course of negotiating and running media campaigns with clients and partners.

It does not cover third-party sites we link to. Those run under their own policies.

3. What data we collect

We only collect what we need. Depending on how you reach us, that can include:

  • Identification and contact data you give us voluntarily: name, email address, company, Telegram handle, phone or WhatsApp number.
  • The content of your message: what you write in a contact form or send us over a commercial channel.
  • Professional data relevant to a commercial conversation: role, market, budget window, campaign requirements.
  • Basic technical and navigation data: pages visited, approximate region, browser and device type.

Most of this data comes directly from you. When we receive your data from a third party, such as a partner who refers you to us, we let you know the source the first time we contact you.

4. Why we use it

We do not sell or rent your personal data. Ever.

  • To answer you and run the commercial conversation you started.
  • To send you material you asked for, such as the LatAm Playbook.
  • To plan, execute and report media campaigns contracted by clients.
  • To comply with legal, tax and contractual obligations.
  • To protect our rights and prevent fraud or abuse.

5. Legal basis

Under the LGPD we rely on your consent (art. 7, I), the execution of a contract or preliminary steps at your request (art. 7, V), compliance with a legal obligation (art. 7, II) and our legitimate interest in running and defending our business (art. 7, IX).

Under the GDPR we rely on the equivalent grounds: consent (art. 6(1)(a)), contract (art. 6(1)(b)), legal obligation (art. 6(1)(c)) and legitimate interest (art. 6(1)(f)).

Where consent is the basis, you can withdraw it at any time. Withdrawing consent does not affect processing already carried out.

6. Who we share it with

We share personal data only with parties that need it to deliver what you asked for, and only to that extent:

  • Service providers that operate our infrastructure and communications, such as hosting, email, our form provider (Tally) and messaging tools. They act as processors, under contract, and cannot use your data for their own purposes.
  • Clients and partners, when the data is strictly necessary to run a contracted campaign.
  • Public authorities, when we are legally required to do so.

7. International transfers

We operate in 25+ countries, so your data may be processed outside your country of residence, including outside Brazil and outside the European Economic Area.

When we transfer personal data out of the EEA, we do it on a lawful transfer mechanism, such as an adequacy decision or the European Commission Standard Contractual Clauses. When we transfer out of Brazil, we follow the requirements of arts. 33 to 36 of the LGPD.

8. How long we keep it

We keep personal data only as long as the purpose that justified collecting it remains, or as long as a legal or contractual obligation requires.

Commercial contact data is kept for the duration of the relationship and for the period needed to defend our rights afterwards. Once the purpose ends, the data is deleted or anonymised.

9. Your rights

Under the LGPD (art. 18) and the GDPR (arts. 15 to 22), you can ask us to:

  • Confirm whether we process your data, and access it.
  • Correct data that is incomplete, inaccurate or out of date.
  • Anonymise, block or delete data that is unnecessary, excessive or processed unlawfully.
  • Port your data to another provider.
  • Withdraw consent, and know the consequences of doing so.
  • Know with whom we shared your data.
  • Object to processing based on legitimate interest, and request review of decisions taken solely by automated means.

We do not carry out automated decision-making that produces legal or similarly significant effects on you. If that ever changes, we will update this policy and explain the logic involved.

10. How to exercise them

Write to dpo@smt.social with the request and enough information for us to identify you. We answer within the legal deadline, and we do not charge for it.

If you are in the European Union, you also have the right to lodge a complaint with your local supervisory authority. If you are in Brazil, you can take it to the ANPD (Autoridade Nacional de Proteção de Dados).

11. Cookies

This site uses Google Tag Manager to load analytics and measurement tags that help us understand how the site is used; these may set cookies from Google.

The one exception is the contact and Playbook forms. They only load when you click to open them, and at that point our form provider (Tally) may set cookies needed to run the form. If you never open a form, nothing from the form provider loads.

You can block or delete cookies in your browser settings at any time.

12. Security

We apply technical and administrative measures to protect personal data against unauthorised access, loss and misuse, including access control, encryption in transit and least-privilege rules internally.

No system is immune. If an incident happens with a real risk to your rights, we notify you and the competent authority as the law requires.

13. Children

Our business is B2B and our services are aimed at companies and professionals. We do not knowingly collect data from children or adolescents. If you believe we have, write to us and we will delete it.

14. Changes to this policy

We may update this policy as our operation, our tooling or the law changes. The date at the top always shows the current version. Material changes get communicated through our usual channels.

15. Contact

Questions, requests or complaints about privacy: dpo@smt.social.

Smart Social

Global media hub. We connect brands, talent and platforms across 25+ countries, and we stand behind the delivery.

Solutions

iGaming Influencer Marketing at Scale Sports Sponsorships & Brand Ambassadors 360 Media: Beyond a Single Channel

Company

About Playbook Contact Privacy Policy Terms of Use Sitemap Links

Connect

Telegram LinkedIn Instagram

© 2026 Smart Social. All rights reserved.

Made by Ghost Lab7