10. Cookie list and duration
The current cookie inventory should be displayed in the preference panel or a supplementary table and, whenever technically available, include: name, provider, domain, category, purpose, duration, type and third-party status.
Cookies may be session-based, removed when the browser closes, or persistent for a defined period. Tectril will seek to adopt durations compatible with purpose and periodically scan for obsolete items.
11. Data collected
Depending on the technology used, processing may include cookie or session identifiers, IP address, access date and time, pages visited, navigation source, interaction events, browser type and version, operating system, language, screen resolution and approximate location derived from IP.
Tectril should apply data minimization and avoid collecting excessive or sensitive data through cookies unless there is a specific need, an appropriate legal basis and enhanced safeguards.
12. Sharing and third parties
Cookie-derived information may be made available to providers supporting hosting, security, analytics, forms, maps, videos, communications, performance or other active website features. These providers must act within contracted purposes and legally applicable responsibilities.
The mere presence of a well-known service does not mean it is active. The final provider list must correspond to integrations actually identified in the published environment.
13. International transfers
Some technology providers may process or store data outside Brazil. Where an international transfer of personal data occurs, Tectril will use mechanisms allowed by the LGPD and applicable regulations, together with contractual and security measures proportionate to risk.
Specific information about countries, providers or mechanisms should be updated when such transfers are identified.
14. Security and retention
Tectril adopts reasonable security measures to reduce risks of unauthorized access, destruction, loss, alteration, disclosure or improper processing. No technology, however, completely eliminates risks inherent to digital environments.
Consent, preference and security records will be kept for the time necessary to demonstrate compliance, meet obligations, prevent fraud or exercise rights, subject to retention and disposal policies.