Privacy Policy
Last updated: September 2026
1. Who Controls Your Data
Current structure (as of [date]): IdeeLab is operated by Patricia Hamilton Silva dos Reis an individual (persona física) based in Mexico, registered for consulting services activity under RFC HASP840519AI5.
Contact for any privacy question, regardless of which entity currently applies: hello@ideelab.com
2. What We Collect
| Data | Collected via | Purpose |
|---|---|---|
| Name, email | Website forms, the IdeeLab Scan, intake, checkout | Communication, service delivery, billing |
| Business information (idea, market, budget, team size, industry vertical) | Scan, intake forms | Delivering Sprints, Regulatory Readiness engagements, Beauty Expansion Sprint, and Scan results |
| Payment information | Hotmart, Gumroad (third-party processors) | Processing payments — we do not store full card details ourselves |
| Usage data (pages visited, Scan answers, email opens) | Website analytics, email platform | Improving the Services, personalizing follow-up |
3. Legal Basis for Processing
We rely on different legal bases depending on the situation, consistently with GDPR (Spain/EU), LGPD (Brazil), and the Mexican LFPDPPP:
- Consent — when you submit the Scan, subscribe to emails, or otherwise actively provide information
- Contract performance — delivering a Sprint, Sprint Pro, Regulatory Readiness engagement, or Beauty Expansion Sprint you’ve paid for
- Legitimate interest — basic website analytics, fraud prevention, and direct communication about services you’ve already engaged with
If you are located in Brazil, we process your data under the equivalent legal bases recognized by the LGPD (Lei Geral de Proteção de Dados). If you are located in Mexico, processing is based on your consent as required under the LFPDPPP (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), disclosed through this policy acting as our Aviso de Privacidad.
4. Third-Party Processors
We use the following third-party services, each processing data under their own privacy terms:
- Anthropic (Claude API) — for AI-assisted analysis; business information you share for a Sprint may be processed by this API. [Confirm current data handling/retention terms directly with Anthropic’s business terms before finalizing this section.]
- Notion — workspace delivery and storage of your deliverables
- Make.com — workflow automation (e.g. routing Scan results)
- Hotmart / Gumroad — payment processing
- [Email platform name] — newsletters and nurture sequences
5. International Data Transfers
IdeeLab operates across Brazil, Mexico, and — from Q1 2027 — Spain. If you are located in one of these markets, or in India, Kenya, or Nigeria as we expand, your data may be transferred to and processed in a different country than the one you’re in, including the country where our infrastructure providers (Anthropic, Notion, Make.com) operate.
This section specifically needs real legal attention before publishing:
- GDPR restricts transfers of EU-origin personal data outside the EU/EEA without appropriate safeguards (adequacy decisions, Standard Contractual Clauses, or equivalent) — relevant once the Spain SL exists and processes EU client data.
- LGPD has its own international transfer framework (Article 33), requiring similar safeguards for data leaving Brazil.
- Mexican LFPDPPP requires that international transfers be disclosed in the Aviso de Privacidad (this document) and, in most cases, consented to.
6. Data Retention
We retain your data for as long as necessary to deliver the Services and comply with legal obligations (e.g. tax/invoicing records under Mexican, and later Spanish, requirements). Scan responses and intake data not converted to a paid engagement are retained for [12 months], unless you’ve opted into ongoing email communication.
7. Your Rights
Your specific rights, and the authority you can complain to, depend on where you’re located. All three frameworks are addressed below — this section should not be shortened to a single generic list, since the actual rights and mechanics differ.
If you are in Spain or the EU (GDPR)
You have the right to: access the personal data we hold about you; rectification of inaccurate data; erasure (“right to be forgotten”); restriction of processing; data portability; and objection to processing based on legitimate interest. You also have the right to lodge a complaint with Spain’s data protection authority, the Agencia Española de Protección de Datos (AEPD), at aepd.es.
If you are in Brazil (LGPD)
You have the right to: confirmation that we process your data; access; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; portability; information about entities we’ve shared your data with; and revocation of consent. You also have the right to file a complaint with Brazil’s data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
If you are in Mexico (LFPDPPP)
Under Mexican law, your rights are known as ARCO rights: Acceso (access to your data), Rectificación (correction of inaccurate data), Cancelación (deletion, subject to legal retention requirements), and Oposición (objection to specific uses of your data). To exercise ARCO rights, contact hello@ideelab.com directly.
Important, current note on Mexican enforcement: Mexico’s data protection regulator, INAI, was dissolved by a December 2024 constitutional reform. Enforcement of the LFPDPPP (the law governing data held by private parties like IdeeLab) now falls under the Secretaría Anticorrupción y Buen Gobierno (SABG). If you wish to escalate a complaint beyond contacting us directly, this is the current authority.
Confirm this is still accurate at the time of publishing, given how recently this transition happened.
Everyone
To exercise any of these rights regardless of location, contact hello@ideelab.com. We will confirm your identity before acting on a request and respond within the timeframe required by the applicable law.
8. Cookies
Our website uses cookies for basic functionality and analytics. [Add specific cookie categories and a cookie consent banner once the live site’s actual analytics/marketing tools are finalized — this needs to satisfy GDPR’s cookie-consent requirements specifically, which are stricter than Brazilian or Mexican practice.]
9. Children’s Privacy
Our Services are intended for business use by adults (18+) and are not directed at children. We do not knowingly collect data from anyone under 18.
10. Changes to This Policy
We’ll update the “Last updated” date above and, for material changes, notify active users via email.
11. Contact
Questions about this Privacy Policy, or to exercise your rights under GDPR, LGPD, or the LFPDPPP: hello@ideelab.com
Notes for legal review
What the live site actually does, so the open sections above can be written against facts rather than assumptions:
- Analytics load only after consent. Google Tag Manager (GTM-M3Z335ML) is injected by our own script only when a visitor presses Accept on the cookie banner; GA4 (G-ZMYP0XMB19) is configured inside that container. Google Consent Mode v2 is set to denied by default, and ad_storage / ad_user_data / ad_personalization stay denied even after Accept — we request analytics_storage only. Declining, or ignoring the banner, means no analytics cookies are written at all.
- Cookies actually set: ideelab_consent (our own choice-remembering cookie, first-party, 12 months, no personal data) and, only after Accept, Google Analytics' _ga and _ga_ZMYP0XMB19 (first-party, 13 months by our container setting). No advertising, remarketing or social pixels are installed.
- Consent can be withdrawn at any time through the “Cookie settings” link in the footer of every page.
- Processors the site itself uses, beyond the list in section 4: Google (Tag Manager and Analytics 4, after consent), Tally (the IdeeLab Scan form), Make.com (scoring the Scan and sending results), Zoho Mail (email and results delivery), Calendly (call booking), Gumroad (checkout), and the site host. Hotmart is listed in section 4 but is not connected for launch — it was for the Brazilian market, which moves with PT-BR in 2027.
- Section 7 of the source document gave hello@ideelab.io as the address for ARCO requests. Corrected to hello@ideelab.com here, since .io is not a domain we operate — worth checking the same typo has not travelled into other documents.
- Section 4 still says “[Email platform name]”. The Spanish version of this policy already names Zoho, which matches what is set up — the same edit applies here.