The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Privacy and data
LGPD privacy turned into management you can prove.
We prepare your company for certification of the ISO/IEC 27701 privacy management system. Since the 2025 revision, the standard no longer depends on being anchored to another one, which made it the document that answers clients and regulators directly when the subject is personal data.
The work starts from the mapping: where personal data enters, where it flows, who accesses it, and when it should be discarded. On top of that map, we compare what exists against what the standard requires, write the documentation, including the statement of applicability justifying each control, and implement it together with your team.
We will need access to the teams that process personal data, the documents you already have, and someone with the authority to approve policy. You receive the processing inventory by operation, the privacy policy, and, depending on the option, the complete document set, team training with records, and the evidence routine that keeps the audit from turning into a scramble.
If your choice includes audit support, we rehearse beforehand, with a readiness report, and stay at your side during the auditor's fieldwork, building the corrective action plan for whatever they flag. The accredited body always performs the audit and issues the certificate, and that is how it should be: the one who prepares you cannot be the judge.
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Data mapping
We find where personal data enters, where it travels, who accesses it and when it should be disposed of.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.