Brazil Privacy Policy (LGPD)
Last updated: 17 August 2026
This Brazil Privacy Addendum supplements our Global Privacy Policy where Brazil’s Lei Geral de Proteção de Dados Pessoais (LGPD) applies.
Controller
GLOBAL TRADING INNOVATIONS LIMITEDtrading as VUNRO
Unit B, 3/F., Kai Wan House
146 Tung Choi Street
Kowloon, Mongkok
Hong Kong
Privacy email: support@getvunro.com
Information, purposes and legal grounds
The Global Privacy Policy describes the identity and contact, commercial and order, payment-confirmation, account and communications, device, network, cookie, marketing-choice, fraud, security and privacy-request information we process; its sources; recipients; purposes; and retention criteria.
Depending on the activity, we process personal data to perform a contract or requested pre-contract steps; comply with legal or regulatory obligations; exercise rights in claims, disputes and chargebacks; pursue proportionate legitimate interests such as security, fraud prevention, service improvement and essential measurement after considering necessity and fundamental rights; or with consent for non-essential cookies, personalised advertising and direct marketing.
Consent can be withdrawn through a free and facilitated process. We do not intentionally collect sensitive personal data. Any necessary sensitive-data processing uses an Article 11 ground. The store is not directed to children, and any child-data processing must observe the child’s best interests and applicable consent rules.
International transfers
Information may be processed in Hong Kong, the United States and other countries where disclosed processors operate. International transfers use a valid LGPD Article 33 route. Where contractual safeguards are used, applicable arrangements incorporate ANPD-approved standard clauses or another approved or permitted mechanism. You may ask for information about the safeguard relevant to your data.
Retention
We use the periods or criteria in the Global Privacy Policy. Processing ends when its purpose is achieved, the information is no longer necessary, the applicable period expires, valid consent is withdrawn, or the ANPD requires termination. Data is then deleted or anonymised within applicable technical limits unless Article 16 permits continued storage.
Your LGPD rights
Subject to the LGPD, you may request confirmation; access; correction; anonymisation, blocking or deletion of unnecessary, excessive or unlawful data; portability when regulated and applicable; deletion of consent-based data subject to lawful retention; recipient information; information about refusing consent and its consequences; revocation of consent; opposition to unlawful non-consensual processing; and review of solely automated decisions that affect your interests.
We provide simplified confirmation or access immediately where feasible, or a complete statement within 15 days where Article 19 requires it, subject to lawful verification and exceptions.
How these privacy request forms work
The form sends the email address, request type and legal regime to Avada, our privacy-request form provider. As part of the same deliberate submission, it also sends the same request to VUNRO's Cloudflare-hosted fallback for secure logging and Freshdesk case handling. This fallback send happens for every deliberate submission and is not conditional on Avada confirming or failing delivery. Cloudflare Turnstile processes security signals to protect the form from automated abuse; VUNRO does not use those signals for advertising.
Avada may separately create its own request record and send a confirmation or identity-verification message. The request is reviewed manually. Submitting it does not instantly export, correct or delete data, show request history, or complete a sale or sharing opt out.
Request record retention: Security HMAC rate records are kept for no more than 2 hours. Semantic deduplication and delivery metadata are kept for no more than 30 days. Encrypted actionable request data held by Cloudflare is erased promptly after confirmed delivery to Freshdesk or an audited manual handoff; unresolved requests remain encrypted until handled. A Freshdesk compliance case may be kept for up to 6 years after closure where needed for legal, regulatory, dispute or audit purposes, and is deleted sooner when no longer needed.
Submit a privacy request
These controls create a request with our privacy-service provider. We may ask for information reasonably necessary to verify identity for access, correction or deletion. You can also email support@getvunro.com.
Access or receive a copy
Ask whether we hold information about you and request a copy where applicable.
Correct information
Ask us to correct inaccurate or incomplete account information.
View existing requests
Ask to view privacy requests associated with your email address.
Delete information
Ask us to delete eligible information. Legal, security and transaction records may need to be retained.
Contact and ANPD
Controller
GLOBAL TRADING INNOVATIONS LIMITEDtrading as VUNRO
Unit B, 3/F., Kai Wan House
146 Tung Choi Street
Kowloon, Mongkok
Hong Kong
Privacy email: support@getvunro.com
Please contact VUNRO first. If you remain dissatisfied, you may petition Brazil’s National Data Protection Authority (ANPD).