Privacy

What is collected

Reading this site is measured in one way and no other: Cloudflare Web Analytics counts page views. It sets no cookie, records nothing that identifies or follows you, and is not advertising. There is no fingerprinting and no cross-site tracking. Every font and every other asset is served from this domain; the single exception is that one measurement script, which loads from Cloudflare.

If you register for access to the data pages, two fields are collected: your name and your email address. They are used to give you access and to verify that the address is yours. They are never sold, never used for advertising, and never passed to anyone except the two service providers named below, which store the record and deliver the code.

Consent, and what is recorded with it

When you submit the form, the time, the originating IP address and the version of the form text you agreed to are stored alongside your registration. That record exists so that the consent can be shown to have been given against specific wording on a specific date.

Newsletter consent is a separate, unticked checkbox. Access does not depend on it, and declining it changes nothing about your access.

What that consent covers: an email when a new analysis is published and when a new dataset goes up, and nothing else. No advertising, and nothing on behalf of anyone else. It is sent through Resend, the same provider that delivers the access code, from an address on this domain. Every message carries a one-click unsubscribe link, and unsubscribing takes effect at the next send whether you tell Resend or tell us.

These messages carry no open tracking and no click tracking. There is no invisible image that reports back when a message is opened, and links in them are the plain address they appear to be rather than a redirect that records the click. The site itself is measured the same way — cookielessly — and the newsletter does not become the exception to it.

Who processes it, and where

Two providers handle registration data, and no others. Cloudflare stores the record — your name, your email, and the consent details below — in its database service. Resend delivers the access code, which means your email address is passed to Resend each time a code is requested. Neither is permitted to use the data for anything else.

Both process the data outside Brazil: the database this site uses runs in eastern North America, and Resend operates from the United States. Under the LGPD that is an international transfer, and it rests on the same consent you give at the form — which is why the form says what the data is for before you submit it. If you would rather your data not leave Brazil, do not register; every page except the data pages is open without it, and the chart images with their full signature blocks are open to everyone.

The only measurement on this site is Cloudflare Web Analytics, run by Cloudflare — the provider already named above, not a new one. It reports page views and aggregate figures: which pages are opened, the approximate country a visit comes from, and the site it was referred from, with no cookie and nothing that identifies you. No advertising network or cross-site tracking service processes anything from this site.

Cookies, and the two that exist

This site sets two cookies and no others. Neither is an advertising or analytics cookie, and neither is shared with anyone. The page-view measurement described above uses no cookie of any kind, which is why this count is still two and not more.

The first records how many data pages have been opened, so that the free allowance can be counted. It holds a list of dates and page paths and nothing else — no identifier, no address, nothing that names a person. It is signed so that it cannot be edited, and it expires after thirty days. Clearing it resets the count, which is a limitation we accept rather than close: closing it would require fingerprinting the browser, and this site does not do that.

The second exists only after registration. It holds a random value that identifies the session and nothing that can be read out of it; the server stores only a hash of that value. It expires after ninety days.

Lawful basis

Registration data is processed on the basis of your consent, given at the form (LGPD art. 7, I). Newsletter messages rest on a separate consent, given separately. Withdrawing either consent is a request like any other and is handled through the contact below.

Retention

Registration data is kept while the registration stands, and is deleted on request. Access codes are deleted or marked spent within minutes of being issued and are never stored in a readable form. Consent records are kept for as long as the registration they belong to, because a consent record that outlives its registration serves nobody and a consent record that dies before it is no evidence at all.

Your rights

Under the LGPD you may request confirmation that your data is processed, access to it, correction of it, its deletion, its portability, and information about who it has been shared with. Requests are answered through the contact below.

Controller and encarregado

The controller of this data is Rodrigo Trindade de Menezes, who is also the encarregado (data protection officer) for the purposes of LGPD article 41.

Requests under any of the rights above — confirmation, access, correction, deletion, portability, or withdrawal of consent — go to privacidade@teiten.lat, and are answered within the period the law allows.