Privacy Policy
This policy describes how personal data is processed on this site, in accordance with Law No. 13.709/2018 (the Brazilian General Data Protection Law, LGPD).
1. Who processes the data
The party responsible for processing the personal data collected on this site is Gabriel Cordeiro Grisostolo, a lawyer enrolled with the Brazilian Bar Association, Paraná Section (OAB/PR), under no. 136.464, practicing in Curitiba, Paraná. Contact for data-protection matters: contato@grisostolo.com.
2. What data is collected
This site is informational and has no registration form, login, or restricted area. Personal data reaches us only when you choose to get in touch:
- Scheduling: when you book a conversation through the embedded calendar, the data you provide (name, email, chosen time, and any answers) is collected and processed by the Calendly platform, a processor engaged for this purpose.
- Direct contact: when you write by email or WhatsApp, you provide whatever data you decide to include in your message.
- Technical data: the server hosting the site records access information, such as IP address, date, time, and browser type, for the time necessary to operation and security.
This site does not use its own advertising-tracking cookies or behavioral-profiling tools. The embedded calendar and the typographic fonts loaded from external services may set their own cookies, subject to the respective providers' policies. On your first visit, an informational notice about the use of these necessary cookies is displayed.
3. Why the data is used
The data is used solely to respond to your contact, to schedule and hold the requested conversation and, where an engagement follows, to provide legal services and comply with legal and regulatory obligations.
There is no use for advertising, no sale or transfer of data to third parties, and no automated decision producing effects on you.
4. Legal bases
Processing is grounded, as the case may be, on the data subject's consent, on the performance of a contract or of preliminary procedures related to it, on compliance with a legal or regulatory obligation, and on the regular exercise of rights, under article 7 of Law No. 13.709/2018.
5. Professional secrecy
Information transmitted in the context of a consultation or a professional relationship is protected by the lawyer's professional secrecy, provided for in the Statute of the Legal Profession (Law No. 8.906/94) and in the OAB Code of Ethics and Discipline, a protection that adds to the safeguards of data-protection law.
6. Sharing
The data may be accessed by processors strictly necessary to the operation of the site and of the service, such as the hosting provider and the scheduling platform. It may also be shared where there is a legal determination, court order, or request from a competent authority.
Some of these processors are based abroad: the hosting provider, the scheduling platform (Calendly), and the typographic-font provider (Google) may process, in the United States, the data strictly necessary for each function, such as the IP address and the data you provide when scheduling. These international transfers occur only to the extent necessary for those purposes and comply with articles 33 to 36 of Law No. 13.709/2018. The same applies to messages sent to the contact email, which pass through a forwarding service and the mailbox provider.
7. Retention
The data is kept for the time necessary to the purposes above and to the applicable legal periods, especially those concerning document retention and the statute of limitations, and is then deleted or anonymized.
8. Your rights
Under article 18 of Law No. 13.709/2018, you may request confirmation of the existence of processing, access to the data, correction of incomplete or outdated data, anonymization, blocking or deletion of unnecessary data or data processed in noncompliance, portability, information about sharing, and withdrawal of consent.
The request may be made through the email indicated in item 1 and will be answered within the periods set by law.
9. Security
Reasonable technical and administrative measures are adopted to protect the data against unauthorized access, loss, or destruction, including encrypted traffic (HTTPS) across the entire site.
10. Updates
This policy may be revised at any time. The date of the last update is indicated below.
Last updated: August 15, 2026.